GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 12-Sep-2025 08:31:06 JST Kevin Beaumont Kevin Beaumont

    I’ll say the elephant in the room - due to the sheer amount of Salesforce customers who have been hit, and that Salesforce is a fully SaaS service - Salesforce should have detected and been more proactive about all of their customer’s data being stolen. https://databreaches.net/2025/09/11/exclusive-high-end-fashion-retailers-gucci-balenciaga-brion-and-alexander-mcqueen-hit-by-salesforce-attacks/

    In conversation about a month ago from cyberplace.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: databreaches.net
      Exclusive: High-end fashion retailers Gucci, Balenciaga, Brion, and Alexander McQueen hit by Salesforce attacks
      Those readers who aren't A-listers (including yours truly) may never have heard of Kering , but you may have heard of their high-end fashion brands: Gucci. Yves
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 12-Sep-2025 08:31:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Snowflake did a really good job with their post incident review of the Snowflake Heist, where their SaaS service got pillaged.

      Out of it they tightened MFA enforcement, Oauth changes, proactive monitoring etc.

      Salesforce and Salesloft need to do the same. They also need better threat intel as the LAPSUS kids were quite openly talking about what they were doing.

      In conversation about a month ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 12-Sep-2025 08:34:08 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The Snowflake heist thread, for reference: https://cyberplace.social/@GossiTheDog/112536407633131499

      In conversation about a month ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Kevin Beaumont (@GossiTheDog@cyberplace.social)
        from Kevin Beaumont
        Very big cyber incident playing out at Snowflake, who describe themselves as “AI Data Cloud”. They have a free trial where anybody can sign up and upload data… and they have. Threat actors have been scraping customer data using a tool called rapeflake, for about a month.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 12-Sep-2025 08:36:01 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Also, deleted all your data from SaaS platforms before you leave. https://infosec.exchange/@badsamurai/115188274209312838

      In conversation about a month ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        B'ad Samurai 🐐 (@badsamurai@infosec.exchange)
        from B'ad Samurai 🐐
        @GossiTheDog@cyberplace.social as it turns out, organizations who *used to* use Drift and cancelled their contracts, found their instances were never fully decom'd, but instead migrated to a free plan and the data plumbing was all still intact. So that's neat.
    • Embed this notice
      Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Friday, 12-Sep-2025 09:23:42 JST Jake Hildreth (acorn) :blacker_heart_outline: Jake Hildreth (acorn) :blacker_heart_outline:
      in reply to
      • da_667
      • John Timaeus

      @johntimaeus @da_667 @GossiTheDog if you get hired at the right one, you can work at all three

      In conversation about a month ago permalink
    • Embed this notice
      da_667 (da_667@infosec.exchange)'s status on Friday, 12-Sep-2025 09:23:43 JST da_667 da_667
      in reply to

      @GossiTheDog also, they're hiring for security staff, and paying pretty well to boot. I know I saw at least one entry for a sr. security engineer in linkedin recently.

      In conversation about a month ago permalink
    • Embed this notice
      John Timaeus (johntimaeus@infosec.exchange)'s status on Friday, 12-Sep-2025 09:23:43 JST John Timaeus John Timaeus
      in reply to
      • da_667

      @da_667 @GossiTheDog

      Are the jobs at Salesforce, Snowflake, or LAPSUS?
      Asking for a friend.

      In conversation about a month ago permalink
    • Embed this notice
      John Timaeus (johntimaeus@infosec.exchange)'s status on Friday, 12-Sep-2025 09:24:10 JST John Timaeus John Timaeus
      in reply to
      • Jake Hildreth (acorn) :blacker_heart_outline:
      • da_667

      @horse @da_667 @GossiTheDog

      Like sub-contracting, only without the contract?

      In conversation about a month ago permalink
    • Embed this notice
      fuzzyfuzzyfungus (fuzzyfuzzyfungus@cyberplace.social)'s status on Friday, 12-Sep-2025 09:26:55 JST fuzzyfuzzyfungus fuzzyfuzzyfungus
      in reply to

      @GossiTheDog It's minor compared to hospital ransomware and industrial disruption; but I have to wonder if someone is combing through those fashion brand sales data right now because that product category is basically ground zero for "I have disposable income that I may be spending on my not-spouse". It'd be a real pain vs. a single large payout from some sleazy IR bagman; but quite low risk and sophistication.

      In conversation about a month ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.