@mattly Did you tell them that it wouldn't be as fun that way or what?
Notices by cR0w (cr0w@infosec.exchange)
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 12-Jun-2026 06:47:29 JST
cR0w
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 12-Jun-2026 06:41:10 JST
cR0w
Like, have y'all tried just not being so vulnerable? Maybe try that and see if the breaches stop.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 10-Jun-2026 09:48:12 JST
cR0w
While it's fun making fun of AI failures, be sure to attribute the failures to the orgs and people responsible, especially when talking to people outside of this bubble. We can't let them keep getting away with blaming it all on AI growing pains and not the intentional business decisions that enabled the failures.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 10-Jun-2026 08:02:18 JST
cR0w
If you have any Palo Alto GlobalProtect portals, maybe take a look for successful authentications from AS215540, especially 92.118.112.230, 89.185.80.144, or 89.185.80.183.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 09-Jun-2026 09:40:17 JST
cR0w
It's not arson, we're vibe hunting for dinner.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 06:51:55 JST
cR0w
@GossiTheDog I already grabbed that but it's funny how quiet it's been since that listing was published. I'm still hammering it to try to get people to give a fuck about VS Code extensions but it isn't working.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 06:47:34 JST
cR0w
That whole GitHub breach sure got quiet fast.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 05:51:29 JST
cR0w
Reminder: Security companies exist to protect the wealthy. Community protects community.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 00:55:57 JST
cR0w
@darfplatypus It's not. I'm a dummy and not blissful.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 00:55:56 JST
cR0w
@tehfishman @darfplatypus Okay but also see
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:04 JST
cR0w
@christopherkunz @wdormann Here's a new one to take a look at. I haven't gone through it and can't vouch for its legitimacy, but y'all know what you're doing more than I do anyway: https://github.com/Vanquishermacdetach/CVE-2026-41089-509
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 03-Jun-2026 12:52:29 JST
cR0w
RE: https://infosec.exchange/@cR0w/116682616422398554
I think what bugs me about this is:
- They don't care.
- It's clearly intentional.
- We all know nothing will change.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Saturday, 30-May-2026 02:08:34 JST
cR0w
The amount of bluetooth shit being added to critical infrastructure systems in this the year of our cryptid 2026 is extremely concerning.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Saturday, 23-May-2026 07:55:37 JST
cR0w
@nyanbinary Ask CatSalad. They figured it out.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 22-May-2026 04:19:04 JST
cR0w
EITW ../ in Trend Micro Apex One. :brdAlert:
https://success.trendmicro.com/en-US/solution/KA-0023430
CVE-2026-34926
TrendAI has released updates to Apex One (on-premise), Apex One as a Service and Vision One - Standard Endpoint Protection (SEP) to resolve multiple vulnerabilities.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Thursday, 21-May-2026 00:12:31 JST
cR0w
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.
I know people here probably don't want to rehash the disclosure discussion for the 683,547,329th time, but fuck Microsoft and this passive aggressive bullshit trying to frame their own interests as "best practices" in a vuln mitigation publication. Your shit is getting torn apart. Act like you've been there before because we all know you have.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
In conversation from infosec.exchange permalink -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 23:55:42 JST
cR0w
In conversation from infosec.exchange permalink -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 06:51:23 JST
cR0w
https://gptzero.me/news/investigations/ey
Ernst & Young (EY) Canada published a cybersecurity report on loyalty program safeguards. We chased down every citation. Most were hallucinated.
Shocked. Shocked! Well, not that shocked.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 04:21:10 JST
cR0w
:exclamation_rainbow: catte.exe has encountered an error
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 19-May-2026 06:24:19 JST
cR0w
RE: https://infosec.exchange/@briankrebs/116597569851456486
BRB, I need more popcorn for that screenshot alone. :blobcatpopcorn:
In conversation from infosec.exchange permalink Attachments