GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by :rainbowCrow: (cr0w@infosec.exchange), page 4

  1. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 08-May-2026 06:41:54 JST :rainbowCrow: :rainbowCrow:

    Vercel networks in case anyone wants to block them for whatever reasons you might have today.

    76.76.21.0/24
    66.33.60.0/24
    64.29.17.0/24
    64.239.123.0/24
    64.239.109.0/24
    216.230.86.0/24
    216.230.84.0/24
    216.198.79.0/24
    216.150.16.0/24
    216.150.1.0/24
    198.169.2.0/24
    198.169.1.0/24
    155.121.0.0/16
    143.13.0.0/16

    In conversation about 3 months ago from infosec.exchange permalink
  2. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 06-May-2026 02:32:56 JST :rainbowCrow: :rainbowCrow:

    Cloudflare is protecting a booter. Then rather than stop the criminals from leveraging Cloudflare infra, they sold their protection to the victim. How is this even legal? We all know it's been happening at smaller scale but even with a high profile extended attack like Ubuntu has been dealing with, their response is "LOL. Fuck you. Pay me."

    #fuckCloudflare

    In conversation about 3 months ago from infosec.exchange permalink
  3. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Sunday, 03-May-2026 01:58:09 JST :rainbowCrow: :rainbowCrow:

    AI in a nutshell.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/500/735/892/070/678/original/98ebcc5ff93eb77b.png
  4. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Sunday, 03-May-2026 01:38:56 JST :rainbowCrow: :rainbowCrow:

    It's wild how many dudes out there followed this exact life path:

    Computers are my whole personality.

    Gaming is my whole personality.

    4chan is my whole personality.

    Guns are my whole personality.

    Blockchain is my whole personality.

    Bitcoin is my whole personality.

    NFTs are my whole personality.

    Tax evasion

    Owning the libs is my whole personality.

    Flag code violations.

    Defending billionaires is my whole personality.

    Civil rights are bad, actually.

    Defending AI is my whole personality.

    I am very smart.

    It's like an entire generation of American men.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.smart.it
      Web Agency Bologna: Siti Web, Software, Digital Marketing - Smart.it
      La tua web agency a Bologna per siti web, applicativi software, SEO e Social Media Marketing, Digital Marketing, sistemi integrati... Tecnologia e comunicazione online su misura per te!
  5. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 01-May-2026 13:33:56 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • da_667
    • Chilly :donor: 🛡️ :gayint: :ifin:
    • Cindʎ Xiao 🍉

    @cxiao @chillybot @da_667 Pretty sure we're all catte around here at this point. :catte:

    In conversation about 3 months ago from infosec.exchange permalink
  6. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 29-Apr-2026 04:45:53 JST :rainbowCrow: :rainbowCrow:

    RE: https://swecyb.com/@orlysec/116483284337537623

    LMFAOOOOOOOOO

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      O RLY CYBER (@orlysec@swecyb.com)
      from O RLY CYBER
      (wiz.io) Critical RCE Vulnerability in GitHub's Git Infrastructure Discovered via AI-Augmented Reverse Engineering Critical RCE vulnerability (CVE-2026-3854) in GitHub's git infrastructure allowed authenticated users to execute arbitrary commands on backend servers via a single git push. Affects GitHub.com and GitHub Enterprise Server (GHES), enabling cross-tenant exposure or full server compromise. In brief - Wiz Research discovered CVE-2026-3854, a critical injection flaw in GitHub's X-Stat protocol, enabling RCE on GitHub.com and full compromise of GHES instances. GitHub patched the issue within hours, highlighting risks in multi-service architectures and AI-augmented vulnerability research. Technically - The flaw (CVE-2026-3854) exploited unsanitized semicolons in git push options to inject arbitrary fields into the X-Stat header, overriding security-critical metadata (e.g., rails_env, custom_hooks_dir). This enabled sandbox bypass, hook directory redirection, and malicious hook injection via path traversal. On GHES, it granted full server access; on GitHub.com, RCE on shared storage nodes. Discovery leveraged AI-augmented reverse engineering tools like IDA MCP for binary analysis. Source: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 #Cybersecurity #ThreatIntel
  7. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Saturday, 25-Apr-2026 04:00:38 JST :rainbowCrow: :rainbowCrow:

    RE: https://flipboard.com/@themirror/the-mirror-sl5qf4b2z/-/a-B5jPPrhfQF65kR0D0kTx_g%3Aa%3A1643597903-%2F0

    hashtag team elephant

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: ic-cdn.flipboard.com
      Millionaire trophy hunter, 75, trampled to death by angry elephants during African hunt | Flipboard
      mirror.co.uk - A millionaire trophy hunter has been killed by a herd of five angry elephants while hunting antelope. Vineyard owner Ernie Dosio was trampled to death …
  8. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 22-Apr-2026 11:23:25 JST :rainbowCrow: :rainbowCrow:

    OH from my partner in the other room, who is not in IT: Teams is not a document repository!

    It's not just nerds fighting that shit. 😆

    In conversation about 3 months ago from infosec.exchange permalink
  9. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 10-Apr-2026 11:01:04 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Bill

    @Sempf Yeah, that's a no for me. My risk models remain unchanged.

    He is right that AI gives us the catalyst and the tools.

    In conversation about 4 months ago from infosec.exchange permalink
  10. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 10-Apr-2026 11:01:02 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Bill
    • Scott Francis

    @darkuncle @Sempf Easier for attackers means a potentially higher likelihood of occurrence, but it does not change the severity of impact. And while the likelihood does theoretically impact the risk score, for at least some orgs, it's minimal to no change when your adversaries are at the top of the field already. The rising tide of AI may be lifting all attackers' boats, but the high water mark remains the same, despite the industry continuously claiming a tsunami is coming. I just don't see it.

    In conversation about 4 months ago from infosec.exchange permalink
  11. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 10-Apr-2026 11:01:01 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Bill
    • Scott Francis

    @Sempf @darkuncle

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/376/222/614/757/363/original/982e07b57a96e438.png
  12. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 03-Apr-2026 16:18:02 JST :rainbowCrow: :rainbowCrow:

    Computers are fucking stupid.

    In conversation about 4 months ago from infosec.exchange permalink
  13. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 02-Apr-2026 08:48:11 JST :rainbowCrow: :rainbowCrow:

    Happy International Birds Day :brdKnife:

    In conversation about 4 months ago from infosec.exchange permalink
  14. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 02-Apr-2026 01:26:02 JST :rainbowCrow: :rainbowCrow:

    Cisco listed by Shinyhunters.

    3 breaches (UNC6040, Salesforce Aura, and AWS accounts). Total over 3M Salesforce records containing PII, Github repositories, AWS buckets and other internal corporate data have been compromised.

    #ransomware

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/329/624/350/052/724/original/36b83f1d4228af88.png
  15. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Friday, 27-Mar-2026 01:25:54 JST :rainbowCrow: :rainbowCrow:

    You know what would be cool? If people would acknowledge that Microsoft has no fucking idea how their own shit works and stop giving them the benefit of the doubt, especially with things like consent and AI.

    In conversation about 4 months ago from infosec.exchange permalink
  16. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 26-Mar-2026 04:36:53 JST :rainbowCrow: :rainbowCrow:

    allowing html emails is still the largest risk that pretty much every org is intentionally accepting send toot

    In conversation about 4 months ago from infosec.exchange permalink
  17. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 24-Mar-2026 09:08:34 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Cat 🐈🥗 (D.Burch)
    • InsiderTreat

    @InsiderTreat @catsalad What do you mean? Isn't that how ops usually work?

    In conversation about 4 months ago from infosec.exchange permalink
  18. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 24-Mar-2026 09:08:33 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Cat 🐈🥗 (D.Burch)
    • InsiderTreat

    @InsiderTreat @catsalad

    stares into mirror

    Am I CatSalad?

    In conversation about 4 months ago from infosec.exchange permalink
  19. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Tuesday, 24-Mar-2026 09:08:32 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • Cat 🐈🥗 (D.Burch)
    • InsiderTreat

    @InsiderTreat @catsalad

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/280/648/890/227/389/original/dc9ca429b782dbf9.png
  20. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Monday, 23-Mar-2026 09:41:08 JST :rainbowCrow: :rainbowCrow:
    in reply to
    • da_667
    • Scott Wilson 🌈

    @scottwilson @da_667 There is but I can't find it right now. That means we need moar. :catte:

    In conversation about 4 months ago from infosec.exchange permalink
  • After
  • Before

User actions

    :rainbowCrow:

    :rainbowCrow:

    Analyst

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          161036
          Member since
          18 Aug 2023
          Notices
          475
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.