That whole GitHub breach sure got quiet fast.
Notices by :rainbowCrow: (cr0w@infosec.exchange), page 3
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 06:47:34 JST
:rainbowCrow:
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 05:51:29 JST
:rainbowCrow:
Reminder: Security companies exist to protect the wealthy. Community protects community.
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 00:55:57 JST
:rainbowCrow:
@darfplatypus It's not. I'm a dummy and not blissful.
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 00:55:56 JST
:rainbowCrow:
@tehfishman @darfplatypus Okay but also see
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:04 JST
:rainbowCrow:
@christopherkunz @wdormann Here's a new one to take a look at. I haven't gone through it and can't vouch for its legitimacy, but y'all know what you're doing more than I do anyway: https://github.com/Vanquishermacdetach/CVE-2026-41089-509
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 03-Jun-2026 12:52:29 JST
:rainbowCrow:
RE: https://infosec.exchange/@cR0w/116682616422398554
I think what bugs me about this is:
- They don't care.
- It's clearly intentional.
- We all know nothing will change.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Saturday, 30-May-2026 02:08:34 JST
:rainbowCrow:
The amount of bluetooth shit being added to critical infrastructure systems in this the year of our cryptid 2026 is extremely concerning.
In conversation from infosec.exchange permalink -
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Saturday, 23-May-2026 07:55:37 JST
:rainbowCrow:
@nyanbinary Ask CatSalad. They figured it out.
In conversation from infosec.exchange permalink -
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 22-May-2026 04:19:04 JST
:rainbowCrow:
EITW ../ in Trend Micro Apex One. :brdAlert:
https://success.trendmicro.com/en-US/solution/KA-0023430
CVE-2026-34926
TrendAI has released updates to Apex One (on-premise), Apex One as a Service and Vision One - Standard Endpoint Protection (SEP) to resolve multiple vulnerabilities.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 21-May-2026 00:12:31 JST
:rainbowCrow:
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.
I know people here probably don't want to rehash the disclosure discussion for the 683,547,329th time, but fuck Microsoft and this passive aggressive bullshit trying to frame their own interests as "best practices" in a vuln mitigation publication. Your shit is getting torn apart. Act like you've been there before because we all know you have.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
In conversation from infosec.exchange permalink -
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 23:55:42 JST
:rainbowCrow:
In conversation from infosec.exchange permalink -
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 06:51:23 JST
:rainbowCrow:
https://gptzero.me/news/investigations/ey
Ernst & Young (EY) Canada published a cybersecurity report on loyalty program safeguards. We chased down every citation. Most were hallucinated.
Shocked. Shocked! Well, not that shocked.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 04:21:10 JST
:rainbowCrow:
:exclamation_rainbow: catte.exe has encountered an error
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 19-May-2026 06:24:19 JST
:rainbowCrow:
RE: https://infosec.exchange/@briankrebs/116597569851456486
BRB, I need more popcorn for that screenshot alone. :blobcatpopcorn:
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 15-May-2026 07:37:34 JST
:rainbowCrow:
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┳┻|
┻┳|
┻┳|
┻┳|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┳┻|
┻┳|
┻┳|
┻┳|
┳┻|
┻┳|
┻┳|
┳┻|
┳┻|
┻┳|
┳┻|
┻┳|
┳┻| _ The reason so many
┻┳| •.•) orgs are pushing AI is
┳┻|⊂ノ to blame it for their vulns
┻┳| instead of taking responsibility.In conversation from infosec.exchange permalink -
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 12-May-2026 23:38:48 JST
:rainbowCrow:
I don't know, I'm beginning to think the bans are not really about security... :brdThink:
https://therecord.media/fcc-pushes-ban-on-updates-to-foreign-routers-drones-2029
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 12-May-2026 04:31:21 JST
:rainbowCrow:
Current status
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 12-May-2026 00:09:36 JST
:rainbowCrow:
RE: https://infosec.exchange/@cR0w/116534744285328166
points to the overpromise / underdeliver of Mythos melting a glacier to find nothing of significance in curl
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 08-May-2026 14:02:12 JST
:rainbowCrow:
ipv6 is a cop send toot
In conversation from infosec.exchange permalink -
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 08-May-2026 07:02:32 JST
:rainbowCrow:
I'm a little concerned about the general tech attitude towards the Mozilla bug findings. Yes, I'm an AI hater, so add that to the biases, but that's not really the point here.
People seem excited about the fact that Mythos was used to find a bunch of security bugs in Firefox, which is cool:
https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
However, the general attitude seems to be that devs can keep pushing for more new things because some AI system will catch the bugs for them. But to me, there should be more concern about how there were so many previously unknown unfixed bugs in Firefox to begin with. These findings should be a cause for concern and give pause to evaluate how so many security bugs make it to prod. And I'm not just talking about Firefox, everyone should be learning from each other in this space.
If nothing else, people celebrating the LLM-fueled bug findings should be recognizing just how much harm the whole Move Fast and Break Shit approach really creates rather than allowing the LLMs to be the excuse to move faster and break more shit.
In conversation from infosec.exchange permalink