GNU social JP
  • FAQ
  • Login
GNU social JPใฏๆ—ฅๆœฌใฎGNU socialใ‚ตใƒผใƒใƒผใงใ™ใ€‚
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)

  1. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 15-Oct-2025 02:50:09 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • 7666

    @7666 I wasn't implying that you were lying. I was asking because I am not an actual CISSP.

    In conversation about 2 days ago from infosec.exchange permalink
  2. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 15-Oct-2025 02:49:35 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • 7666

    @7666 But are you an actual CISSP?

    In conversation about 2 days ago from infosec.exchange permalink
  3. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 15-Oct-2025 02:49:20 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    Yeah, I'm a CISSP: Certified Information Security Shit Poster.

    In conversation about 2 days ago from infosec.exchange permalink
  4. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Saturday, 11-Oct-2025 05:11:15 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    RE: https://infosec.exchange/@da_667/115351550577837727

    Phishing testing as it's implemented is checkbox wanker bullshit and I love any time people help other people fuck with it.

    In conversation about 6 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      da_667 (@da_667@infosec.exchange)
      from da_667
      How to tell a phishing exercise domain is a phishing exercise domain: The SSL certificate specifies a Subject Alternative Names list that is a fucking novel.
  5. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Friday, 10-Oct-2025 16:13:07 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • darf :BlobhajMlem:

    @darfplatypus

    In conversation about 6 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/348/009/504/316/529/original/84ecaab201e93d8c.jpg
  6. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Friday, 10-Oct-2025 16:13:06 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • darf :BlobhajMlem:

    @darfplatypus https://pewpew.gayint.org ?

    In conversation about 6 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: blog.gayint.org
      Pew Pew Pew Pew
      Real time view of the cyber pewpews.
  7. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Friday, 10-Oct-2025 16:13:06 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • darf :BlobhajMlem:

    @darfplatypus

    In conversation about 6 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/348/018/018/250/905/original/1fbba76ccf566efd.png
  8. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 08-Oct-2025 13:01:07 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    My partner bought a dog treat bag and it came with a training clicker. I wouldn't even think twice about it if it weren't for this lovely, educational place. But you better believe I'm taking this thing to conferences to see who responds to it.

    In conversation about 8 days ago from infosec.exchange permalink
  9. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 08-Oct-2025 00:55:57 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    • Matthew Lyon

    @mattly Feels weirdly similar to another ongoing discourse in tech... ๐Ÿค”

    In conversation about 9 days ago from infosec.exchange permalink
  10. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 08-Oct-2025 00:02:15 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    Example eleventy billion that we could easily get rid of most phishing, and therefore most breaches, simply by going back to plain text email.

    https://blog.talosintelligence.com/too-salty-to-handle-exposing-cases-of-css-abuse-for-hidden-text-salting/

    In conversation about 9 days ago from infosec.exchange permalink
  11. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Tuesday, 07-Oct-2025 03:43:13 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    • Matthew Lyon

    @mattly :dumpster_fire_gif: :coolhhHHAAAHHH: :dumpster_fire_gif:

    In conversation about 10 days ago from infosec.exchange permalink
  12. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Tuesday, 07-Oct-2025 03:39:18 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    I'm still waiting to have someone explain to me how the security controls, processes, and procedures are somehow different for emails composed by an LLM vs by a human. I simply don't understand why I'm supposed to give a fuck about AI-assisted phishing.

    In conversation about 10 days ago from infosec.exchange permalink
  13. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Tuesday, 07-Oct-2025 03:38:43 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    • Matthew Lyon

    @mattly Oh. Oh no. That sounds like a horrible thing that shouldn't exist.

    In conversation about 10 days ago from infosec.exchange permalink
  14. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Friday, 03-Oct-2025 02:14:26 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    Fedi in a nutshell.

    In conversation about 14 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/633/166/683/362/048/original/786976e3fa8f58db.png
  15. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Thursday, 02-Oct-2025 03:11:54 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    Not sure how I'll top last year's pumpkin in both spookiness and confusion of the neighbors.

    #directoryTraversalMemes

    In conversation about 15 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/300/220/713/677/847/original/5e857bebf6cafca0.png
  16. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Sunday, 28-Sep-2025 03:09:45 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • Bill

    @Sempf

    ๐ŸŽถ The best part of waking up
    Is screaming What The Fuck ๐ŸŽถ

    In conversation about 19 days ago from infosec.exchange permalink
  17. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Friday, 26-Sep-2025 06:43:10 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    A backdoored MCP? I'm shocked. Shocked! Well, not that shocked.

    https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft

    Since version 1.0.16, it's been quietly copying every email to the developer's personal server. I'm talking password resets, invoices, internal memos, confidential documents - everything.

    In conversation about 20 days ago from infosec.exchange permalink
  18. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Friday, 26-Sep-2025 04:43:46 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    RE: https://infosec.exchange/@cR0w/115231558276357271

    And now we have a watchTowr write-up. :dumpster_fire_gif: :blobcatpopcorn: :dumpster_fire_gif:

    https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/

    I also appreciate them publishing it despite the conclusion. It's insightful despite not reaching their research goal, and they don't make wild speculations like some researchers tend to.

    In conversation about 21 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      sp00ky cR0w ๐Ÿด (@cR0w@infosec.exchange)
      from sp00ky cR0w ๐Ÿด
      Looks like the advisory from Fortra is live. It was 404 when I posted the CVE yesterday. https://www.fortra.com/security/advisories/product-security/fi-2025-012

  19. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Thursday, 25-Sep-2025 04:07:44 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด

    It's not imposter syndrome if your entire field is ineffective.

    In conversation about 22 days ago from infosec.exchange permalink
  20. Embed this notice
    sp00ky cR0w ๐Ÿด (cr0w@infosec.exchange)'s status on Wednesday, 24-Sep-2025 22:11:00 JST sp00ky cR0w 🏴 sp00ky cR0w ๐Ÿด
    in reply to
    • CatSalad๐Ÿˆ๐Ÿฅ— (D.Burch) :blobcatrainbow:

    @catsalad Junior analyst halfway through their first Major Incident.

    In conversation about 22 days ago from infosec.exchange permalink
  • Before

User actions

    sp00ky cR0w 🏴

    sp00ky cR0w ๐Ÿด

    Just another analyst chasing squirrels and pretending to know things.Anything stupid I say can and should be blamed on #AI. I mean, I don't intentionally use AI products, but if the AI snakeoilers can take credit for the things other people produce, they can also take the blame.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          161036
          Member since
          18 Aug 2023
          Notices
          316
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP็ฎก็†ไบบ. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.