GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Chester Wisniewski (chetwisniewski@securitycafe.ca)

  1. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 28-Mar-2025 06:35:05 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Mike Sheward

    @SecureOwl They did the same thing when they bought Symantec. They only want the Fortune 1000, everyone else can pound sand. Odd strategy. We had customers telling us (Sophos) that Symantec wouldn't even accept their POs as they were too small and unwanted.

    In conversation about a month ago from securitycafe.ca permalink
  2. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 01-Feb-2025 11:05:07 JST Chester Wisniewski Chester Wisniewski

    Is it just me or is it strange to put tariffs on Canada for "fentanyl and the immigrants" when it is the US CBPs job to... You know, keep out the fentanyl and the immigrants?

    In conversation about 3 months ago from securitycafe.ca permalink
  3. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Sunday, 19-Jan-2025 10:49:41 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Adrianna Tan

    @skinnylatte Tell me more about the ones you like? I think I mostly get the HK-style ones here in Vancouver as well...

    In conversation about 4 months ago from securitycafe.ca permalink
  4. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Thursday, 16-Jan-2025 10:05:28 JST Chester Wisniewski Chester Wisniewski
    • Kevin Beaumont

    @GossiTheDog Are they Fortiproxy? That was affected.

    In conversation about 4 months ago from gnusocial.jp permalink
  5. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Thursday, 16-Jan-2025 09:29:00 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Kevin Beaumont

    @GossiTheDog 0-day confirmed https://www.csoonline.com/article/3802722/fortinet-confirms-zero-day-flaw-used-in-attacks-against-its-firewalls.html

    In conversation about 4 months ago from securitycafe.ca permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.csoonline.com
      Fortinet confirms zero-day flaw used in attacks against its firewalls
      The advisory from the cybersecurity company follows a report from security researchers who observed exploits in the wild in early December as part of a widespread campaign.
  6. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Wednesday, 01-Jan-2025 06:55:48 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Tim W RESISTS

    @tim Right, but for me to set up DNS on HE's servers it needs to see the delegation.

    In conversation about 4 months ago from securitycafe.ca permalink
  7. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Wednesday, 01-Jan-2025 06:52:15 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Tim W RESISTS

    @tim Strange thing was a local whois from my server showed the delegation, but Hurricane Electric's DNS service did not. It is possible HE checked as soon as I added the domain (race condition) and won't check for another 60 mins as a rate limiter?

    In conversation about 4 months ago from securitycafe.ca permalink
  8. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Wednesday, 01-Jan-2025 06:44:22 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Tim W RESISTS

    @tim Some sort of odd timer, might be an issue with Hurricane Electric. Exactly 60 minutes after purchase it recognized the delegation.

    In conversation about 4 months ago from securitycafe.ca permalink
  9. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Wednesday, 01-Jan-2025 06:38:07 JST Chester Wisniewski Chester Wisniewski

    I like my .ca domain names, but the provisioning is soooo slow. Every time I create a new domain, I want to USE it. The delegation seems to take hours to propagate sometimes, where a .com in 2024 seems almost instantaneous.

    In conversation about 4 months ago from securitycafe.ca permalink
  10. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 14-Dec-2024 04:58:57 JST Chester Wisniewski Chester Wisniewski
    • John Shier

    h/t to @johnshier

    In conversation about 5 months ago from securitycafe.ca permalink

    Attachments


    1. https://securitycafe.ca/system/media_attachments/files/113/647/101/876/080/146/original/d31deb7e93b36628.png
  11. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Thursday, 05-Dec-2024 05:18:40 JST Chester Wisniewski Chester Wisniewski

    Is it just me or should all journalists be seriously looking at the Fediverse as the only sensible home? Now with Threads being able to follow accounts here and Threads banning political and news content on their own platform, it seems like the perfect workaround. Add in a bridge to BSky and Bob's deep throat's uncle.

    In conversation about 5 months ago from securitycafe.ca permalink
  12. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 13-Jul-2024 04:15:44 JST Chester Wisniewski Chester Wisniewski

    What if AT&T had MFA enabled on their Snowflake... and were SIM swapped?

    In conversation about 10 months ago from securitycafe.ca permalink
  13. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 12-Jul-2024 02:47:48 JST Chester Wisniewski Chester Wisniewski
    • Catalin Cimpanu
    • Kevin Beaumont

    @GossiTheDog @campuscodi I did an analysis at RSA 6 years ago on who hosts the bad... https://youtu.be/FQLlt-7gsYI?si=iuXrCpLn1VVvgBfc

    In conversation about 10 months ago from securitycafe.ca permalink

    Attachments

    1. RSAC TV: Does Malware Have Citizenship? Who's Infecting Us and Does It Matter
      from RSA Conference
      Chester Wisniewski, Principal Research Scientist, SOPHOSWe often hear that malware attacks are characteristic of country Y and nation-state X. Some companies...
  14. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 22-Jun-2024 05:09:58 JST Chester Wisniewski Chester Wisniewski
    • Kevin Beaumont

    @GossiTheDog Yes, this happens a lot too.

    In conversation about 11 months ago from gnusocial.jp permalink
  15. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 21-Jun-2024 20:41:32 JST Chester Wisniewski Chester Wisniewski
    • Kevin Beaumont

    @GossiTheDog we see the same last I checked. You don't need to believe me either, but I believe it is true.

    In conversation about 11 months ago from securitycafe.ca permalink
  16. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 14-Jun-2024 08:28:25 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Kevin Beaumont

    @GossiTheDog This whole thing feels like a desperate ploy to explain to people why they should throw out their PCs to get a new one with an "NPU". Don't want, don't need. They have to include something that "requires" it, even though as already proven, it isn't even needed for this.

    In conversation about a year ago from securitycafe.ca permalink
  17. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 17-May-2024 21:03:05 JST Chester Wisniewski Chester Wisniewski
    • Kevin Beaumont
    • Corey Quinn

    @GossiTheDog @Quinnypig Everyone gives me the side eye for running my own mail server, IRC, nextcloud, etc. I have seen this play before and it ends in tears. Trust no one.

    In conversation about a year ago from securitycafe.ca permalink
  18. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Sunday, 21-Apr-2024 08:21:00 JST Chester Wisniewski Chester Wisniewski
    in reply to
    • Techmeme

    @Techmeme Hadn't this already been debunked?

    In conversation about a year ago from securitycafe.ca permalink
  19. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 27-Jan-2024 06:20:06 JST Chester Wisniewski Chester Wisniewski
    • Kevin Beaumont
    • metlstorm

    @GossiTheDog @metlstorm I'm surprised this was effective considering many more ransomware crews are doing "remote ransomware", effectively running the encryption on an unprotected device and connecting to the shares over the network. Would work against Netware shares as well as anything else...

    In conversation about a year ago from securitycafe.ca permalink
  20. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 27-Jan-2024 04:30:26 JST Chester Wisniewski Chester Wisniewski

    Looks like Lush Cosmetics were victims of Akira as they have appeared on their leak site. Akira has exploited unpatched Cisco ASA VPNs in the past, wondering if the same here? They use them according to Shodan data.

    In conversation about a year ago from securitycafe.ca permalink
  • Before

User actions

    Chester Wisniewski

    Chester Wisniewski

    Director, Global Field CISO at Sophos, frequent speaker and press go to. Said opinions are mine, not the company.Co-host of the Security Take(s) Two (@securitytaketwo) podcast.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          139937
          Member since
          26 Jun 2023
          Notices
          29
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.