@32x33 Can't breach a system that's blue screened. Checkmate haters.
Notices by cR0w :cascadia: (cr0w@infosec.exchange)
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 14-May-2025 02:09:49 JST cR0w :cascadia:
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 14-May-2025 01:25:55 JST cR0w :cascadia:
WTF? I hate phishing training so much.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 14-May-2025 01:25:54 JST cR0w :cascadia:
@badsamurai Hell yes. Let's add some more headers:
X-ThreatSim-ID
X-ThreatSim-Header
X-Phishtest
X-PhishMe
X-PhishMeTracking
X-PHISH -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 13-May-2025 20:00:27 JST cR0w :cascadia:
@mttaggart @catsalad Counterpoint: :blobcatyes:
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Saturday, 10-May-2025 07:01:33 JST cR0w :cascadia:
Friday EOD 8-K 😆
On May 5, 2025, Global Crossing Airlines Group Inc. (the “Company”) learned of unauthorized activity within its computer networks and systems supporting portions of its business applications, which the Company determined to be the result of a cybersecurity incident.
https://www.sec.gov/ix?doc=/Archives/edgar/data/1846084/000095017025068004/jetmf-20250505.htm
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 09-May-2025 12:35:11 JST cR0w :cascadia:
Holy shit, Seagate, you okay?
This is the reference in the CVE: https://xxx/
sev:CRIT 10.0 - AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Issue in my product in blah version x on y allows bad person to break
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 07-May-2025 06:11:25 JST cR0w :cascadia:
@ryanc @0xabad1dea Or needlepoint. I like that quote a lot.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 07-May-2025 00:55:13 JST cR0w :cascadia:
Partner: Hey you're on that furry website all the time, maybe you can tell me what this means.
Me: What furry site? I don't go to furry sites.
Partner: The one with the tooting and stuff.
Me: Mastodon? The fediverse is not a furry websi- ... Yeah, okay. What's the question?
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 06-May-2025 11:51:05 JST cR0w :cascadia:
@Viss Our best local place was out of a trailer and shut down and everyone was bummed, but then they opened up a brick and mortar store. I haven't been there yet but I'm excited for them.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 06-May-2025 11:51:04 JST cR0w :cascadia:
@darfplatypus @Viss It makes me nervous that they'll lose what made it so good but still optimistic. I think people are making that transition better than they used to.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 06-May-2025 04:06:26 JST cR0w :cascadia:
Public disclosure of a few command injection vulns in Rundeck 5.8.0 and 5.11.1 ( which is the latest version on the Rundeck site ) and IDK, probably others.
https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 06-May-2025 04:06:25 JST cR0w :cascadia:
Bug bounties. lol.
Edit to fix the markdown from the copy / paste.
- February 04, 2025: Initial contact attempt by ERNW via Mail stating it cannot accept the terms and conditions of HackerOne .
- February 10, 2025: Contact attempt by ERNW.
- February 11, 2025: Contact attempt by ERNW.
- February 11, 2025: PagerDuty Security Team states only reports via HackerOne are accepted.
- February 12, 2025: ERNW states it cannot accept the terms and conditions.
- February 14, 2025: Contact attempt by ERNW.
- February 26, 2025: Contact attempt by ERNW.
- March 04, 2025: Contact attempt by ERNW.
- March 27, 2025: Contact attempt by ERNW.
- May 05, 2025: Contact attempt by ERNW stating that the disclosure timeline is exceeded. Public Disclosure by ERNW.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Saturday, 03-May-2025 05:29:30 JST cR0w :cascadia:
So is the DoJ going to "find" that Chris Krebs has been collaborating with CN or UA?
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Saturday, 03-May-2025 05:29:28 JST cR0w :cascadia:
@adisonverlice Notes written in red crayon with his name spelled wrong.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Saturday, 03-May-2025 05:29:27 JST cR0w :cascadia:
@adisonverlice I imagine "evidence" will look something like this.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 02-May-2025 12:56:26 JST cR0w :cascadia:
@grey @darfplatypus I know. He already doxxed himself.
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 02-May-2025 12:56:26 JST cR0w :cascadia:
How I picture y'all.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 02-May-2025 12:56:24 JST cR0w :cascadia:
@i0null @darfplatypus We can all be raccoons.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 02-May-2025 06:36:58 JST cR0w :cascadia:
@GossiTheDog those low-bid outsourced service desks though
In conversation from infosec.exchange permalink -
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Thursday, 01-May-2025 22:44:14 JST cR0w :cascadia:
In conversation from infosec.exchange permalink Attachments