buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
abucci@bucci.onl
Admin account
@abucci@buc.ci

Search results for tag #spam

AodeRelay boosted

[?]Peter N. M. Hansteen » 🌐
@pitrh@mastodon.social

Apparently a new campaign in progress, preserved message nxdomain.no/~peter/wankstortio

I almost missed it because the message is in the graphic nxdomain.no/~peter/wankstortio and with mail client in dark mode the diversion text was displayed black on dark grey.

Fun fact: last hop before reaching here was a antispamcloud.com host

Not storyworthy in itself, so linking to my 2022 piece nxdomain.no/~peter/despicable_ will do (w/links)

    AodeRelay boosted

    [?]Graham Perrin » 🌐
    @grahamperrin@mastodon.bsd.cafe

    How We’re Keeping Reddit Real and Safe in the AI Era

    redditinc.com/news/how-were-ke

    ― Blocking 23 million spam views per day before they ever reach a human user.

    ― Catching ~25K net new spammy posts and comments a day.

    ― Reducing spam exposure for our users by ~20% from January to March 2026, relative to the prior three months and an additional 10–15% drop in overall spam account exposure.

    ― Revoking nearly 2M inauthentic votes per day over the last three months.

      [?]Stefan Bohacek » 🌐
      @stefan@stefanbohacek.online

      It looks like whoever is behind this has finally come for one of my sites. Manually blocking datacenter IPs has worked for a while, but it seems like the traffic is now coming either from residential IPs, or the IPs are just getting spoofed.

      Real conundrum. I didn't want to have to set up Cloudflare for the site, and I have to wonder how good they are at catching this anyway, but it might just come to that.

      Anyone else has been dealing with this?

        AodeRelay boosted

        [?]Clayton Hove » 🌐
        @adtothebone@universeodon.com

        “Ahh… Hello Kitty, the other-other white meat.” — Reynard

          AodeRelay boosted

          [?]iX Magazin » 🌐
          @iX_Magazin@social.heise.de

          Proxmox Mail Gateway 9.1 erleichtert Kampf gegen Spam und verschlüsselt Backups

          Das neue Proxmox Mail Gateway will mehr Komfort beim Mail-Handling bieten und die Möglichkeit, ihre Backups zu verschlüsseln.

          heise.de/news/Proxmox-Mail-Gat

          AodeRelay boosted

          [?]securityskeptic :donor: :verified: » 🌐
          @securityskeptic@infosec.exchange

          Cybercrime Reported in May 2026

          Interisle's monthly report on cybercrime activity (phishing, malware, spam) for the month of May 2026 revealed a 27% increase in phishing reported compared to April and a 35% increase in spam. While malware reported in May decreased 17% compared to April, it still represents an 11% increase over the monthly average for the 12 -month period.

          interisle.substack.com/p/cyber

            AodeRelay boosted

            [?]ltning » 🌐
            @ltning@pleroma.anduin.net

            ai / llm [SENSITIVE CONTENT]To imagine that in so many companies there are people who plug an #LLM into yet another application and decide "this is so important we have to email *all our users* about it!"

            I'm so sick of it.

            #Spam #Idiocracy #AI

              AodeRelay boosted

              [?]The Spamhaus Project » 🌐
              @spamhaus@infosec.exchange

              ❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.

              The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:

              ✉️ Here's an example:
              "Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."

              At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.

              This also appears to line up with what @zackwhittaker TechCrunch Security Editor identified last week:
              mastodon.social/@zackwhittaker

              ....although the activity we’re seeing appears to stretch back several months.

              Takeaway: automated notification systems should not allow this level of customization.

              Microsoft has been informed of this abusive activity.

                AodeRelay boosted

                [?]The New Oil » 🤖 🌐
                @thenewoil@mastodon.thenewoil.org

                AodeRelay boosted

                [?]Tommaso Gagliardoni » 🌐
                @tomgag@infosec.exchange

                Dear spammer: when dealing with automated marketing campaign, AI is not just your friend, it is also my friend. And I also have another good friend: GDPR. I am taking great delight in automating GDPR requests that border legal threats against your undesired email campaign. This typically escalates quickly from "canned AI response" to "automated AI response trying to do damage mitigation" to "concerned human replying apologetically because its AI agent alerted them that someone with a lawyer is genuinely angry". Ah, the little joys of life!

                Your business does not deserve to exist. What you call "your job" is parasitic. Do you think your mom would be proud of you?

                  AodeRelay boosted

                  [?]bbₜᵤₓᵢ » 🌐
                  @tux@burningboard.net

                  ein neuer Spambot , muss das sein? 😫

                  Screenshot einer Liste von fünf Fediverse-Profilen zu Hashtags wie #fediforum und #activitypub unter der Domain tags.pub. Angezeigt werden jeweils ein Icon, das vollständige Handle sowie die Anzahl der Follower (zwischen 18 und 26).

                  Alt...Screenshot einer Liste von fünf Fediverse-Profilen zu Hashtags wie #fediforum und #activitypub unter der Domain tags.pub. Angezeigt werden jeweils ein Icon, das vollständige Handle sowie die Anzahl der Follower (zwischen 18 und 26).

                    AodeRelay boosted

                    [?]Aurin Azadî :mastodon: » 🌐
                    @atarifrosch@fedifreu.de

                    Sind irgendwo gerade .com-Domains im Sonderangebot? Spammer haben die grad als Wegwerf-Domains für Mailspam.

                      [?]Andrew 🌻 Brandt 🐇 » 🌐
                      @threatresearch@infosec.exchange

                      An unknown threat actor is abusing a remote management tool called as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.

                      The lures employ a variety of tropes, including bogus event invitations and business invoices/bills.

                      TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including and to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.

                      This is my first post at the @huntress blog: huntress.com/blog/tiflux-rmm-i

                        AodeRelay boosted

                        [?]Peter N. M. Hansteen » 🌐
                        @pitrh@mastodon.social

                        We are very close to a new OpenBSD release. "You Have Installed OpenBSD. Now For The Daily Tasks." nxdomain.no/~peter/openbsd_ins can help you prepare for the upgrade.

                        If you are using exim as your MTA (or any other non-base system MTA), "OpenSMTPD Is The Mail Server For The Future" nxdomain.no/~peter/time_for_op contains useful pointers for a better mail future.

                          AodeRelay boosted

                          [?]Peter N. M. Hansteen » 🌐
                          @pitrh@mastodon.social

                          AodeRelay boosted

                          [?]Peter N. M. Hansteen » 🌐
                          @pitrh@mastodon.social

                          OpenSMTPD Is The Mail Server For The Future nxdomain.no/~peter/time_for_op Migrating to OpenSMTPD from exim on OpenBSD was joyfully painless and smooth.

                            [?]Holger » 🌐
                            @homawida@troet.cafe

                            Warum bekommt man Spammails in denen nichts drin steht?
                            Kann auch nichts anklicken.

                            Ich pranger das an ! 👆

                              [?]heise online » 🌐
                              @heiseonline@social.heise.de

                              „Irreführende Praxis“: Google bestraft „Back-Button-Hijacking“ als Spam

                              Google geht künftig gegen Webseiten vor, die den Zurück-Button des Browsers manipulieren. Ab Mitte Juni drohen Betreibern manuelle Spam-Maßnahmen.

                              heise.de/news/Irrefuehrende-Pr

                                [?]Grant » 🌐
                                @gsymon@mstdn.social

                                @haubles @stux

                                1/4

                                I’m looking for a little help about dealing with the seemingly mass attack of Russian bots. What's the best way of handling this?

                                I report this Russian propaganda as 'Something Else' and bookmark a post, so that I can later see if the account is still running, then I block the account. I also leave the checkbox on, for the server itself to receive my report

                                Many accounts are not suspended

                                  [?]Truth & Answers » 🌐
                                  @collective_truth@mastodon.social

                                  @_elena Translation inside is a real game changer + step up.

                                  But people who don't make or see the point in replying limits it all.

                                  Using all levels of people / energy here 👍

                                  rather than feel depth is a kind of liability or time-drag, seeing people as kind of for it.

                                  I prefer the less defensive "show me what you got" usage instead of looking for perfection or short text.

                                  Sincerity (people who critique) and can also look the same if not given time / care ur side ⚠️

                                    AodeRelay boosted

                                    [?]Peter N. M. Hansteen » 🌐
                                    @pitrh@mastodon.social

                                    AodeRelay boosted

                                    [?]Paul Chambers🚧 » 🌐
                                    @paul@oldfriends.live

                                    My cache all email got some spam/phishing email with the link url being a github.io url.

                                    I am wondering if something scraped my Mastodon instance and misidentified the account, which doesn't have an email account created, as an email address. How do I report this to ?

                                    mail-auth-service-source dot github dot io/srf-client_id-REDACTED?emp=redacted@oldfriends.live is the link

                                    Mail Service

Message delivery has been temporarily suspended for redacted@oldfriends.live due to a pending verification.

Messages affected: 5

Re-authenticate to restore delivery and view held messages:

                                    Alt...Mail Service Message delivery has been temporarily suspended for redacted@oldfriends.live due to a pending verification. Messages affected: 5 Re-authenticate to restore delivery and view held messages:

                                      [?]Nonya Bidniss » 🌐
                                      @Nonya_Bidniss@infosec.exchange

                                      Here's a head-shake worthy from overnight if anyone wants to play with the scammer:

                                      I'm Jeff Bezos,
                                      The CEO of Amazon, it's on this note that I'm informing the world of my intention to give out my Fortune of $124 Billion of my wealth to the lucky ones around the country and world at large.
                                      Congratulations, your name and details were randomly selected from some Google business contact listing as one of the beneficiaries of this
                                      charity project. each person would be awarded $1,200,000,00
                                      [link to a cnbc story, jeff-bezos-says-he-plans-to-give-away-most-of-his-124-billion-fortune]
                                      DONATION CODE: G506328
                                      Contact how to proceed.
                                      Email: mrjeffbezos87 (at) gmail dot com

                                        AodeRelay boosted

                                        [?]securityskeptic :donor: :verified: » 🌐
                                        @securityskeptic@infosec.exchange

                                        Words Commonly Found in Spam Domains

                                        In a previous post, Interisle looked at the practice of embedding brand strings in domain names used for phishing and spam. Today, we’ll provide a summary of words that we most often find in domains used to spam.'

                                        interisle.substack.com/p/words

                                          1 ★ 0 ↺

                                          [?]Anthony » 🌐
                                          @abucci@buc.ci

                                          Should I click the "Update payment details" link in the "Payment Declined" email from hokpjubswctfnf.46903405027342@33ucek.c7qp5x.ra7x5j.us? It's possible I forgot to update my account information with 33ucek.c7qp5x.ra7x5j.us Inc. Who can remember so many accounts anyway?


                                            1 ★ 0 ↺

                                            [?]Anthony » 🌐
                                            @abucci@buc.ci

                                            My spam folder has taken on a special, highly-focused quality.

                                            I'm not sure how Layla and May001 snuck past SpamAssassin but the assassin is being re-trained.


                                            Screen capture of a list of spam emails. Most have SpamAssassin's "*****SPAM*****" subject followed by either "Let's start getting to know each other." or some academic-spam title about editorial boards or journals.

                                            Alt...Screen capture of a list of spam emails. Most have SpamAssassin's "*****SPAM*****" subject followed by either "Let's start getting to know each other." or some academic-spam title about editorial boards or journals.

                                              0 ★ 0 ↺

                                              [?]Anthony » 🌐
                                              @abucci@buc.ci

                                              Grace and Scarlett would also like to "get to know each other.". What the heck list did I end up on?


                                                0 ★ 0 ↺

                                                [?]Anthony » 🌐
                                                @abucci@buc.ci

                                                Since November 28th of this year I've received 22 spam emails with the same title "Let's start getting to know each other." (with the period at the end) from senders with names like Ellie, Emily, Harper, Olivia, and Aria. I haven't been able to find information about an ongoing scam like this. Has anyone else been seeing this one?

                                                (I'm not asking for advice about dealing with spam. SpamAssassin has this one well in hand. I'm just curious if anyone else has been seeing spam like this).


                                                  3 ★ 3 ↺

                                                  [?]Anthony » 🌐
                                                  @abucci@buc.ci

                                                  This is a long time coming. I've been posting about the decline of arXiv's CS category for a long time now, and even had a few conversations with someone I know who works there about it. Personally, I think the slop started in 2018--prior to generative AI slop--when the CS category at arXiv began the unsustainable exponential growth in submissions that has continued till today. An increasing number of what amounted to corporate whitepapers and other marketing materials were being posted on arXiv to give them the appearance of scientific credibility. There was a fairly clear arXiv-to-Nature pipeline. Citation counts were pumped as some of the scientometric services count arXiv "articles" as citations, and some researchers adopted the bad scholarly habit of citing arXiv preprints instead of the final publication. It was and still is a mess. My understanding is that arXiv was meant as a place for people to put high-quality but pre-publication articles, but at least in the CS category it's drifted quite far from that.

                                                  I gather they've finally taken this measure because of the preponderance AI-generated slop, but with any luck these other issues will improve too. The arXiv press release states “Review/survey articles or position papers submitted to arXiv without this documentation will be likely to be rejected and not appear on arXiv” so it does sound like they are acknowledging the other problems and intend to enforce their rules more strictly in the future.

                                                  "arXiv says it will no longer accept Computer Science papers that are still under review due to the wave of AI-generated ones it has received."
                                                  From https://infosec.exchange/users/josephcox/statuses/115486903712973154


                                                    5 ★ 2 ↺

                                                    [?]Anthony » 🌐
                                                    @abucci@buc.ci

                                                    I am using Google Classroom, and Gmail is marking all email notifications from my Google classroom as spam. It's email generated by one Google product going into another Google product. What on earth is happening to flag the notification as spam?

                                                    This post is not an invitation to scold me for using Google products or to suggest alternatives. It is also not a request for technical support.