GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by :rainbowCrow: (cr0w@infosec.exchange), page 3

  1. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 06:47:34 JST :rainbowCrow: :rainbowCrow:

    That whole GitHub breach sure got quiet fast.

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 05:51:29 JST :rainbowCrow: :rainbowCrow:

    Reminder: Security companies exist to protect the wealthy. Community protects community.

    In conversation about 2 months ago from infosec.exchange permalink
  3. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 00:55:57 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • darf :BlobhajMlem:

    @darfplatypus It's not. I'm a dummy and not blissful.

    In conversation about 2 months ago from infosec.exchange permalink
  4. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 05-Jun-2026 00:55:56 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • tehfishman
    • darf :BlobhajMlem:

    @tehfishman @darfplatypus Okay but also see

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/585/830/542/598/original/77f748a637f0db2b.png
  5. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:04 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Dr. Christopher Kunz
    • Will Dormann

    @christopherkunz @wdormann Here's a new one to take a look at. I haven't gone through it and can't vouch for its legitimacy, but y'all know what you're doing more than I do anyway: https://github.com/Vanquishermacdetach/CVE-2026-41089-509

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - Vanquishermacdetach/CVE-2026-41089-509: CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)
      CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL) - Vanquishermacdetach/CVE-2026-41089-509
  6. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 03-Jun-2026 12:52:29 JST :rainbowCrow: :rainbowCrow:

    RE: https://infosec.exchange/@cR0w/116682616422398554

    I think what bugs me about this is:

    • They don't care.
    • It's clearly intentional.
    • We all know nothing will change.
    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      care.it
      This domain may be for sale!
    2. No result found on File_thumbnail lookup.
      cR0w (@cR0w@infosec.exchange)
      from cR0w
      :dumpster_fire_gif: :blobcatpopcorn: :dumpster_fire_gif: https://www.kb.cert.org/vuls/id/615987 >CVE-2026-10629 Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no ESP-encapsulated SIP traffic was detected during subsequent signaling such as INVITE, MESSAGE, BYE, and UPDATE. This pattern persisted across devices, operating systems, and network conditions, indicating a deliberate network configuration rather than a transient issue. >Per 3GPP TS 33.203 and GSMA IR.92, SIP signaling between the UE and P-CSCF must be protected using IPsec ESP following IMS AKA authentication, with negotiation occurring during registration. The absence of this protection allows attackers to manipulate SIP signaling undetected, enabling call hijacking, spoofing, denial-of-service, and misrouting of emergency calls. >Verizon initially acknowledged the issue and stated that integrity support would be available upon request and extended broadly later in the year. However, the company has since ceased participation in coordination, including follow-up discussions and draft review, and has not provided verifiable evidence of mitigation. As remediation remains unconfirmed, this disclosure proceeds to inform users of an ongoing security exposure. >Independent verification would require observation of successful SIP security negotiation, ESP-protected traffic, or official confirmation from Verizon.
  7. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Saturday, 30-May-2026 02:08:34 JST :rainbowCrow: :rainbowCrow:

    The amount of bluetooth shit being added to critical infrastructure systems in this the year of our cryptid 2026 is extremely concerning.

    In conversation about 2 months ago from infosec.exchange permalink
  8. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Saturday, 23-May-2026 07:55:37 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • nyanbinary

    @nyanbinary Ask CatSalad. They figured it out.

    In conversation about 2 months ago from infosec.exchange permalink
  9. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 22-May-2026 04:19:04 JST :rainbowCrow: :rainbowCrow:

    EITW ../ in Trend Micro Apex One. :brdAlert:

    https://success.trendmicro.com/en-US/solution/KA-0023430

    CVE-2026-34926

    TrendAI has released updates to Apex One (on-premise), Apex One as a Service and Vision One - Standard Endpoint Protection (SEP) to resolve multiple vulnerabilities.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  10. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 21-May-2026 00:12:31 JST :rainbowCrow: :rainbowCrow:

    Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.

    I know people here probably don't want to rehash the disclosure discussion for the 683,547,329th time, but fuck Microsoft and this passive aggressive bullshit trying to frame their own interests as "best practices" in a vuln mitigation publication. Your shit is getting torn apart. Act like you've been there before because we all know you have.

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585

    In conversation about 2 months ago from infosec.exchange permalink
  11. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 23:55:42 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Soatok Dreamseeker
    • IFIN - The Independent Federated Intelligence Network

    @soatok Hey @ifin what's your email address?

    In conversation about 2 months ago from infosec.exchange permalink
  12. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 06:51:23 JST :rainbowCrow: :rainbowCrow:

    https://gptzero.me/news/investigations/ey

    Ernst & Young (EY) Canada published a cybersecurity report on loyalty program safeguards. We chased down every citation. Most were hallucinated.

    Shocked. Shocked! Well, not that shocked.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  13. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 20-May-2026 04:21:10 JST :rainbowCrow: :rainbowCrow:

    :exclamation_rainbow: catte.exe has encountered an error

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/455/784/197/696/146/original/ce8c4e52fd5b56e4.png
  14. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 19-May-2026 06:24:19 JST :rainbowCrow: :rainbowCrow:

    RE: https://infosec.exchange/@briankrebs/116597569851456486

    BRB, I need more popcorn for that screenshot alone. :blobcatpopcorn:

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      BrianKrebs (@briankrebs@infosec.exchange)
      from BrianKrebs
      Attached: 1 image New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history. https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
  15. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 15-May-2026 07:37:34 JST :rainbowCrow: :rainbowCrow:

    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┳┻|
    ┻┳|
    ┻┳|
    ┻┳|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┳┻|
    ┻┳|
    ┻┳|
    ┻┳|
    ┳┻|
    ┻┳|
    ┻┳|
    ┳┻|
    ┳┻|
    ┻┳|
    ┳┻|
    ┻┳|
    ┳┻| _ The reason so many
    ┻┳| •.•) orgs are pushing AI is
    ┳┻|⊂ノ to blame it for their vulns
    ┻┳| instead of taking responsibility.

    In conversation about 3 months ago from infosec.exchange permalink
  16. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 12-May-2026 23:38:48 JST :rainbowCrow: :rainbowCrow:

    I don't know, I'm beginning to think the bans are not really about security... :brdThink:

    https://therecord.media/fcc-pushes-ban-on-updates-to-foreign-routers-drones-2029

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cms.therecord.media
      FCC pushes ban on security updates for foreign-made routers, drones to 2029
      The router deadline, originally slated for March 1, 2027, has been pushed back to at least January 1, 2029, according to the announcement from the FCC’s Office of Engineering and Technology (OET).
  17. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 12-May-2026 04:31:21 JST :rainbowCrow: :rainbowCrow:

    Current status

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/557/597/314/351/684/original/1e1b9448750cf871.png
  18. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 12-May-2026 00:09:36 JST :rainbowCrow: :rainbowCrow:

    RE: https://infosec.exchange/@cR0w/116534744285328166

    points to the overpromise / underdeliver of Mythos melting a glacier to find nothing of significance in curl

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      cR0w (@cR0w@infosec.exchange)
      from cR0w
      I'm a little concerned about the general tech attitude towards the Mozilla bug findings. Yes, I'm an AI hater, so add that to the biases, but that's not really the point here. People seem excited about the fact that Mythos was used to find a bunch of security bugs in Firefox, which is cool: https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/ However, the general attitude seems to be that devs can keep pushing for more new things because some AI system will catch the bugs for them. But to me, there should be more concern about how there were so many previously unknown unfixed bugs in Firefox to begin with. These findings should be a cause for concern and give pause to evaluate how so many security bugs make it to prod. And I'm not just talking about Firefox, everyone should be learning from each other in this space. If nothing else, people celebrating the LLM-fueled bug findings should be recognizing just how much harm the whole Move Fast and Break Shit approach really creates rather than allowing the LLMs to be the excuse to move faster and break more shit.
  19. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 08-May-2026 14:02:12 JST :rainbowCrow: :rainbowCrow:

    ipv6 is a cop send toot

    In conversation about 3 months ago from infosec.exchange permalink
  20. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 08-May-2026 07:02:32 JST :rainbowCrow: :rainbowCrow:

    I'm a little concerned about the general tech attitude towards the Mozilla bug findings. Yes, I'm an AI hater, so add that to the biases, but that's not really the point here.

    People seem excited about the fact that Mythos was used to find a bunch of security bugs in Firefox, which is cool:

    https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/

    However, the general attitude seems to be that devs can keep pushing for more new things because some AI system will catch the bugs for them. But to me, there should be more concern about how there were so many previously unknown unfixed bugs in Firefox to begin with. These findings should be a cause for concern and give pause to evaluate how so many security bugs make it to prod. And I'm not just talking about Firefox, everyone should be learning from each other in this space.

    If nothing else, people celebrating the LLM-fueled bug findings should be recognizing just how much harm the whole Move Fast and Break Shit approach really creates rather than allowing the LLMs to be the excuse to move faster and break more shit.

    In conversation about 3 months ago from infosec.exchange permalink
  • After
  • Before

User actions

    :rainbowCrow:

    :rainbowCrow:

    Analyst

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          161036
          Member since
          18 Aug 2023
          Notices
          475
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.