<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Berlin Senate employee executed a command that a website politely asked him to execute.]]></title><description><![CDATA[<p>Berlin Senate employee executed a command that a website politely asked him to execute. The page looked like a “verify you are human” check. It instructed to open Windows Terminal/PowerShell, paste a command and press Enter. This is what appears to lead catastrophic results. Attackers hacked the systems and exfiltrated 1.44 million, 5.8 TB. Including personnel records, applications, internal documents, emergency plans and other sensitive material.</p>]]></description><link>https://forum.fedi.dk/topic/db93a0bd-1a94-4138-8a11-b532f0780536/berlin-senate-employee-executed-a-command-that-a-website-politely-asked-him-to-execute.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 21 Sep 2026 23:51:07 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/db93a0bd-1a94-4138-8a11-b532f0780536.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Sep 2026 08:25:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Berlin Senate employee executed a command that a website politely asked him to execute. on Thu, 10 Sep 2026 10:15:06 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@dandels">@<span>dandels</span></a></span> <span><a href="https://mastodon.social/@LukaszOlejnik" rel="nofollow noopener">@<span>LukaszOlejnik</span></a></span> My workaround is to disable Win+R (which has an unfortunate side-effect of not allowing you to type a folder name to Explorer's address bar) and to remove PowerShell/Terminal/Command Prompt links from Win+X menu.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/jernej__s/statuses/117246217847078096</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/jernej__s/statuses/117246217847078096</guid><dc:creator><![CDATA[jernej__s@infosec.exchange]]></dc:creator><pubDate>Thu, 10 Sep 2026 10:15:06 GMT</pubDate></item><item><title><![CDATA[Reply to Berlin Senate employee executed a command that a website politely asked him to execute. on Thu, 10 Sep 2026 09:09:43 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@dandels">@<span>dandels</span></a></span> <span><a href="https://mastodon.social/@LukaszOlejnik">@<span>LukaszOlejnik</span></a></span> At least one can stop some things by enforcing constrained language mode. Not sure it would have helped with that payload, though.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/schrotthaufen/statuses/117245960737727956</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/schrotthaufen/statuses/117245960737727956</guid><dc:creator><![CDATA[schrotthaufen@mastodon.social]]></dc:creator><pubDate>Thu, 10 Sep 2026 09:09:43 GMT</pubDate></item><item><title><![CDATA[Reply to Berlin Senate employee executed a command that a website politely asked him to execute. on Thu, 10 Sep 2026 08:59:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/troed%40swecyb.com">@<span>troed</span></a></span> <span><a href="https://mastodon.social/@LukaszOlejnik">@<span>LukaszOlejnik</span></a></span> there’s a term for the growing blasé attitude that develops from having to do this constantly however - “approval fatigue”. This leads to ‘rubber stamping’ where a user will just do the task of clicking or in this case Ctrl-C/Ctrl-V and not expect anything to happen.<br />macOS is borderline insane with this now: an example is you have to approve an app to read a directory, and it’s per-directory. Secure perhaps but my goodness it’s bloody annoying and exhausting.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/richrockster/statuses/117245919833289200</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/richrockster/statuses/117245919833289200</guid><dc:creator><![CDATA[richrockster@mastodon.social]]></dc:creator><pubDate>Thu, 10 Sep 2026 08:59:19 GMT</pubDate></item><item><title><![CDATA[Reply to Berlin Senate employee executed a command that a website politely asked him to execute. on Thu, 10 Sep 2026 08:36:33 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@LukaszOlejnik" rel="nofollow noopener">@<span>LukaszOlejnik</span></a></span> Not something that anyone has ever paid me to configure, but I suspect that disabling PowerShell for regular AD users is really not made to be the easy default that it likely should be.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/dandels/statuses/117245830347749755</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/dandels/statuses/117245830347749755</guid><dc:creator><![CDATA[dandels@infosec.exchange]]></dc:creator><pubDate>Thu, 10 Sep 2026 08:36:33 GMT</pubDate></item><item><title><![CDATA[Reply to Berlin Senate employee executed a command that a website politely asked him to execute. on Thu, 10 Sep 2026 08:36:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/lukaszolejnik%40mastodon.social">@<span>LukaszOlejnik</span></a></span> Teaching people that it's normal to have to click on unintended things to be able to see the intended thing wasn't very smart.</p><p>*) cookie popup<br />*) are you human popup<br />*) this website isn't secure popup</p>]]></description><link>https://forum.fedi.dk/post/https://swecyb.com/users/troed/statuses/117245828188491285</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://swecyb.com/users/troed/statuses/117245828188491285</guid><dc:creator><![CDATA[troed@swecyb.com]]></dc:creator><pubDate>Thu, 10 Sep 2026 08:36:00 GMT</pubDate></item><item><title><![CDATA[Reply to Berlin Senate employee executed a command that a website politely asked him to execute. on Thu, 10 Sep 2026 08:35:09 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@LukaszOlejnik" rel="nofollow noreferrer noopener">@<span>LukaszOlejnik</span></a></span> I understand not every computer user figures out what terminal is. But it's organization's fault they:</p><ul><li>Allow regular users to access terminal;</li><li>Has no rate limiting and observability whatsoever to allow this large exfiltration to happen.</li></ul><p>Gross mismanagement <img class="not-responsive emoji" src="https://social.gyt.is/fileserver/01JNNHZAEKNYYV1T3F8AK09MXB/emoji/original/01KSYFHD68CSWFJ6A9P6K6FXY1.png" title=":blobcat_thisisfine:" /></p>]]></description><link>https://forum.fedi.dk/post/https://social.gyt.is/users/gytisrepecka/statuses/01M2579PZ3FTSZTXPFPACNDTQR</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.gyt.is/users/gytisrepecka/statuses/01M2579PZ3FTSZTXPFPACNDTQR</guid><dc:creator><![CDATA[gytisrepecka@social.gyt.is]]></dc:creator><pubDate>Thu, 10 Sep 2026 08:35:09 GMT</pubDate></item></channel></rss>