When you fix one thing and the next thing you know you're the SME.
Notices by cR0w :cascadia: (cr0w@infosec.exchange), page 3
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 10-Jan-2025 03:23:19 JST cR0w :cascadia:
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Thursday, 09-Jan-2025 05:38:53 JST cR0w :cascadia:
@screaminggoat Oh yeah, I already have that one. I saw another post about this issue and then happened across this gif for a different chat so I threw it up here because it felt relatable. Thanks though.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Thursday, 09-Jan-2025 05:38:53 JST cR0w :cascadia:
Trying to get vuln details from a vendor despite it being labeled as exploited in the wild
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Thursday, 09-Jan-2025 05:38:52 JST cR0w :cascadia:
@screaminggoat Is this a random guess or...
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 08-Jan-2025 07:46:54 JST cR0w :cascadia:
Living off the Land
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 08-Jan-2025 04:16:56 JST cR0w :cascadia:
How is it that this industry is so full of "the only thing that will stop a bad guy with AI is a good guy with AI" takes? Meanwhile, "advanced" persistent teens are running circles around modern enterprise security systems with ../ and command injection. Fuck. If it weren't for the physical systems that real people rely on to survive being connected to vulnerable networks, I would be so gone.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 07-Jan-2025 07:00:14 JST cR0w :cascadia:
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Monday, 06-Jan-2025 23:15:54 JST cR0w :cascadia:
TCP fragmentation
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Saturday, 04-Jan-2025 09:07:04 JST cR0w :cascadia:
@mattly "Last updated on..."
What was updated?
... the last updated date?
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Friday, 03-Jan-2025 04:03:12 JST cR0w :cascadia:
@catsalad I would like to be angel investor for this particular meowing artificial intelligence project.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Thursday, 02-Jan-2025 13:06:53 JST cR0w :cascadia:
@Mike_Enos @hacks4pancakes Ashley Madison was my final "Well, I guess literally no one gives a fuck" moment. It's when I shifted from caring about the immediately impacted individuals to the downstream impacts only.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Saturday, 28-Dec-2024 07:18:50 JST cR0w :cascadia:
Heads-up if you're working on CVE-2024-3393:
PAN changed the advisory so that the required configuration for exposure is now:
Both of the following must be true for PAN-OS software to be affected:
- Either a DNS Security License or an Advanced DNS Security License must be applied.
- DNS Security logging must be enabled.
Instead of this:
DNS Security logging must be enabled for this issue to affect PAN-OS software.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Wednesday, 25-Dec-2024 04:47:09 JST cR0w :cascadia:
POV: Watching an 0day PoC video while the vendor claims there is no known vulnerability in their product.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 24-Dec-2024 23:38:20 JST cR0w :cascadia:
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 24-Dec-2024 06:54:45 JST cR0w :cascadia:
Soon...
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 24-Dec-2024 04:47:26 JST cR0w :cascadia:
@GossiTheDog Isn't that what CSI:Cyber tried to do?
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Monday, 23-Dec-2024 22:44:35 JST cR0w :cascadia:
There are multiple CVEs in this advisory for SHARP routers, but CVE-2024-46873 ( CVSS3 9.8 ) sure sounds like a bugdoor to me. I wonder if the US will ban SHARP routers too. 🤔
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Monday, 23-Dec-2024 01:31:40 JST cR0w :cascadia:
2025 CVEs gonna read like
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Monday, 23-Dec-2024 01:31:40 JST cR0w :cascadia:
Are we doing 2025 predictions yet?
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Sunday, 22-Dec-2024 02:56:08 JST cR0w :cascadia:
"Okay class, today we are going to talk about Tor."