GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)

  1. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Wednesday, 17-Jun-2026 08:05:33 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    • Catalin Cimpanu
    • Lorenzo Franceschi-Bicchierai
    • Mathew J. Schwartz
    • Jon Greig
    • amvinfe

    NEW by me:

    One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.

    Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.

    Data leaks followed.

    https://databreaches.net/2026/06/16/one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid/

    #NovoNordisk #FulcrumSec #TheUSERS007 #hackandleak #extortion #AI #databreach #infosec #cybersecurity

    @campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe

    In conversation about 3 days ago from infosec.exchange permalink

    Attachments


  2. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Tuesday, 02-Jun-2026 02:31:14 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    • Kevin Beaumont
    • Zack Whittaker

    #Microsoft walks back its threat to pursue those who don't disclose responsibly as criminals. They don't apologize, but merely "clarify" their position in a post on X.com today. Since their statement doesn't seem to be on their blog, I am linking to x.com:

    https://x.com/msftsecresponse/status/2061293718942908925

    This is the type of threat to researchers that @zackwhittaker and I had been looking at in our survey on threats to journalists and researchers. It was impressive to see all of the experts like @GossiTheDog speaking up to slam Microsoft for their blog post of May 27.

    Confronted with overwhelming criticism by the security community, Microsoft stepped back.

    #responsibledisclosure #Microsoft

    In conversation about 18 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://X.com/

  3. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Tuesday, 19-May-2026 00:52:45 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    • POLITICO
    • Zack Whittaker
    • Mathew J. Schwartz
    • Jon Greig
    • The Guardian
    • AJ Vicens
    • Lorenz (Lolo)
    • pressfreedom

    RE: https://infosec.exchange/@amvinfe/116592954548436698

    I seem to be making even more enemies than usual for my refusal to simply parrot or repeat what is being claimed by experts who aren't willing to back up their assertions or claims with any actual data, when asked.

    I hope even more journalists do what we are supposed to do -- dig in, investigate, and report, noting critical gaps in evidence when experts aren't citing evidence in making claims.

    We do not have a well-informed public when journalists just repeat what experts say. They may give us good quotes or "exclusives," about criminal gangs or cybercrime, but where is the data to support their claims?

    Smearing me -- or trying to -- because I keep asking for evidence is its own attempt at censoring a free press.

    #cybercrime #journalism #ShinyHunters #pressfreedom #defamation

    @euroinfosec @politico @zackwhittaker @L0renz_H @guardian @PierluigiPaganini @jgreig @aj_vicens
    @pressfreedom

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      amvinfe (@amvinfe@infosec.exchange)
      from amvinfe
      Attached: 1 image 𝐒𝐢𝐧𝐜𝐞 𝐖𝐡𝐞𝐧 𝐃𝐢𝐝 𝐀𝐬𝐤𝐢𝐧𝐠 𝐟𝐨𝐫 𝐄𝐯𝐢𝐝𝐞𝐧𝐜𝐞 𝐁𝐞𝐜𝐨𝐦𝐞 “𝐃𝐞𝐟𝐞𝐧𝐝𝐢𝐧𝐠 𝐂𝐫𝐢𝐦𝐢𝐧𝐚𝐥𝐬”? Dissent responded harshly to these accusations, firmly rejecting any insinuation of collusion with criminal groups. The journalist pointed out that every time she asks for evidence to support certain claims, she is labeled “criminal-friendly” or accused of being a mouthpiece for cybercriminals, simply for refusing to uncritically accept statements lacking public verification. https://www.suspectfile.com/since-when-did-asking-for-evidence-become-defending-criminals/ #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #ShinyHunters
  4. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Tuesday, 05-May-2026 21:37:35 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    in reply to
    • funnymonkey

    @funnymonkey Thanks for the kind words.

    Someone commented on my Instructure post with a comment as "Sysadmin." They wrote:

    "Are you effin kidding me! We got an Email from Instructure saying we were impacted and now we have to inform all the students and families in our district.

    Why do these ShinyHunters keep attacking the edtech sector?? PowerSchool, infinite campus and now this.

    It’s only a Sunday night and law enforcement has still done nothing about these hackers. Regulators really need to hold these companies accountable for poor security practices."

    They raise valid points.

    #edtech #EduSec #cybersecurity #vendor #supplychain #databreach #hackandleak

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.this.it
      Progetti architettura e servizi tecnici per immobili
      Consulenza tecnica di architettura ed ingegneria per progettazione, ristrutturazione di immobili, pratiche edilizie, perizie. Investimenti, valorizzazione e trasformazione di immobili
  5. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Friday, 17-Apr-2026 10:24:30 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    • Catalin Cimpanu
    • Zack Whittaker
    • funnymonkey
    • Mathew J. Schwartz
    • Doug Levin
    • Mark Keierleber 🚴‍♂️🎸
    • Jon Greig
    • JayeLTee

    NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and https://infosec.exchange/@mikaelthalen@mastodon.social -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at https://databreaches.net/2026/04/16/p3-advertised-20-years-and-0-security-breaches-you-can-guess-what-happened-next/

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: files.mastodon.social
      Mikael Thalen (@mikaelthalen@mastodon.social)
      114 Posts, 66 Following, 723 Followers · Tech Reporter at Straight Arrow News
    2. Domain not in remote thumbnail source whitelist: databreaches.net
      P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.
      Introduction P3 Global Intel advertises itself as a "fully integrated and state-of-the-art tip acquisition and tip management solution that has quickly become t
  6. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Thursday, 09-Apr-2026 00:27:41 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    If you were or are a federal employee or are a family member of one, you might want to read this and share it with others who might be concerned:

    Trump’s Personnel Agency Is Asking for Federal Workers’ Medical Records

    https://kffhealthnews.org/news/article/trump-opm-federal-workers-medical-records-privacy/view/republish/

    #privacy #healthsec #workplace #infosec

    In conversation about 2 months ago from infosec.exchange permalink
  7. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Friday, 20-Mar-2026 04:29:59 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    Cyberattack leaves drivers with required breathalyzer test systems in 46 states unable to start their vehicles:

    https://wgme.com/news/local/cyberattack-leaves-maine-drivers-with-breathalyzer-test-systems-unable-to-start-vehicles-oui-intoxalock

    #intoxalock #cyberattack #DDoS

    In conversation about 3 months ago from infosec.exchange permalink
  8. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Sunday, 21-Dec-2025 02:05:17 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    in reply to
    • Zack Whittaker
    • Ryan Castellucci (they/them) :nonbinary_flag:

    @ryanc If you felt you were on the receiving end of a suggested "or else," I would treat that as a threat. Let's see if Zack agrees.

    @zackwhittaker

    In conversation about 6 months ago from infosec.exchange permalink
  9. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Monday, 08-Dec-2025 01:34:54 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    When I get mad at #USPol stuff, I try to remind myself of all the good people in this country.

    A woman who is a dog-sitter mentioned to her clients that she was collecting donations for the local shelter. Within days, here's what her living room looked like.

    Bless her and the donors.

    #DogsofMastodon #AdoptDontShop

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/678/908/499/775/515/original/c64ead074781bf6b.jpg
  10. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Saturday, 06-Dec-2025 00:46:24 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    OT. I really shouldn't laugh, but I can't stop laughing over this one:

    "Donald Trump wax statue pulled from museum after being punched too many times"

    https://dangerousminds.net/weird-news/donald-trump-wax-statue-pulled-museum-punched/

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/667/572/716/314/555/original/432097472a7e31ea.jpg
    2. Domain not in remote thumbnail source whitelist: cdn1.dangerousminds.net
      Donald Trump statue removed being punched too many times
      from @DangerMindsBlog
      A wax statue of Donald Trump has been pulled from a museum in San Antonio, Texas, after the lifelike copy of the President sustained one too many punches.
  11. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Saturday, 22-Nov-2025 00:17:39 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    Alleged Scattered Spider members Thalha Jubair and Owen Flowers who are both charged with the TransportForLondon cyberattack, pleaded not guilty in Southwark Crown Court in London today. The judge has set a trial date of June 8, 2026 for them, and they continue to be detained on remand.

    Flowers is also charged with conspiring to damage the network of SSM Health Care Corporation and attempting to do the same to Sutter Health, both U.S. healthcare entities. He pleaded not guilty to those charges, too.

    Jubair also faces an additional charge of not providing his password to investigators when they seized his devices.

    #ScatteredSpider #databreach #ransom #cybersecurity

    In conversation about 7 months ago from infosec.exchange permalink
  12. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Saturday, 01-Nov-2025 01:28:15 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    • Catalin Cimpanu
    • Zack Whittaker
    • Mathew J. Schwartz
    • JayeLTee

    Remember that frustrating situation where some of us couldn't get a vendor to respond to notifications that court-sealed records and sensitive files were exposed? One entity eventually reached the vendor by phone and was so angry at their response that they wound up canceling their account with them.

    Yesterday, I finally reached the second court entity. They, too, wound up telling the vendor to take the share down.

    How many other clients may still have exposed data because the vendor tells clients that everything's fine when it isn't? I don't know. If you know any entity using Software Unlimited Corp software (not Software Unlimited Inc, but Software Unlimited CORP), you may want to point them to my coverage:

    Original Report:
    https://databreaches.net/2025/10/13/months-after-being-notified-a-software-vendor-is-still-exposing-confidential-and-sealed-court-records/

    Today's Update:
    https://databreaches.net/2025/10/31/how-many-courts-have-had-sealed-and-sensitive-files-exposed-by-one-vendors-error/

    #dataleak #vendor #incidentresponse #cybersecurity #SoftwareUnlimitedCorp #FTC #govsec

    @zackwhittaker @euroinfosec @campuscodi @JayeLTee

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Today’s Award for the Silliest Theory of the Computer Fraud and Abuse Act
      Orin Kerr, a law professor and former attorney in the DOJ who worked in the computer crimes division, has a commentary on a lawsuit involving CFAA claims that's
    2. No result found on File_thumbnail lookup.
      How many courts have had sealed and sensitive files exposed by one vendor’s error?
      DataBreaches recently reported that researchers had discovered two courts had sealed filings and court records exposed, but the vendor responsible wasn't respon
  13. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Friday, 31-Oct-2025 22:48:19 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    It's #Halloween, so it's time for my annual tradition of posting the picture of my front porch after my daughter surprised me by decorating it for me while I was away.

    Hope everyone gets to enjoy some candy today!

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/469/050/558/597/561/original/26c7dd02378dea7d.jpg
  14. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Tuesday, 14-Oct-2025 05:37:19 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    • BrianKrebs
    • Catalin Cimpanu
    • Kevin Beaumont
    • Zack Whittaker
    • Mathew J. Schwartz
    • The Record Media

    NEW, by me, the one some of you have been asking about:

    Months After Being Notified, a Software Vendor is Still Exposing Confidential and Sealed Court Records

    https://databreaches.net/2025/10/13/months-after-being-notified-a-software-vendor-is-still-exposing-confidential-and-sealed-court-records/

    I don't usually ask for boosts, but if you are in a position to help spread the word about this vendor and that its clients need to check their security, that would be great.

    #dataleak, #incidentresponse, #infosecurity, #cybersecurity, #SoftwareUnlimitedCorp #FBI #CISA

    @zackwhittaker @euroinfosec @campuscodi @therecord_media @GossiTheDog @briankrebs

    In conversation about 8 months ago from infosec.exchange permalink
  15. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Thursday, 09-Oct-2025 20:19:47 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    According to a new state auditor's report, nearly a third of Mississippi's state agencies fail cybersecurity requirements

    Media coverage: https://vicksburgnews.com/shad-whites-office-finds-nearly-a-third-of-state-agencies-fail-cybersecurity-requirements/

    Direct link to state report: https://www.osa.ms.gov/sites/default/files/osa/files/reports/252025%20Review%20of%20Mississippi%20Enterprise%20Security%20Program%20Compliance%20%28Cybersecurity%29.pdf

    #Audit #cybersecurity #govsec #Mississippi #ComplianceTech

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: vicksburgnews.com
      Direct to consumer wine shipping now available in Mississippi - Vicksburg Daily News
      from Alyssa Lick
      Mississippi legalizes direct-to-consumer wine shipments starting July 1, 2025, expanding access for residents and wineries alike.

  16. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Sunday, 05-Oct-2025 05:36:37 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    NEW: Just days before its data might be leaked, Qantas Airways obtained a permanent injunction

    https://databreaches.net/2025/10/04/just-days-before-its-data-might-be-leaked-qantas-airways-obtained-a-permanent-injunction/

    #injunction #censorship #pressfreedom #Qantas #Salesforce #databreach

    In conversation about 9 months ago from infosec.exchange permalink
  17. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Saturday, 27-Sep-2025 05:27:45 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    Two teens have been arrested by Dutch authorities on espionage-related charges. They were allegedly recruited --and paid -- by pro-Russian hackers on Telegram to carry a wi-fi sniffer near areas that included embassies near the Hague, Europol, and Eurojust.

    As part of their coverage of the story, the NL Times reports:

    The father (of one of the boys) said his son is a diligent student, plays hockey, and works part-time in a supermarket. “He doesn’t go out, and shows no inclination to explore the world. We raise our children to handle everyday risks, but nothing like this. Who could have anticipated it?”

    #espionage #recruitment #Telegram

    In conversation about 9 months ago from infosec.exchange permalink
  18. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Monday, 22-Sep-2025 04:48:14 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    NEW: When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on

    Others seem to have interpreted their "goodbye" message differently than I had. Were they lying or did people just not understand a significant statement in their message?

    And while headlines focus on them hitting a bank, I think we need to take a closer look at their attacks on the aviation sector.

    https://databreaches.net/2025/09/21/when-goodbye-isnt-the-end-scattered-lapsus-hunters-hack-on/

    #databreach #ScatteredSpider #ShinyHunters #LAPSUS$ #CollinsAerospace #airlines #airports

    In conversation about 9 months ago from infosec.exchange permalink
  19. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Friday, 19-Sep-2025 08:18:29 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:
    in reply to
    • Kevin Beaumont

    @GossiTheDog Was he ever in a juvie facility or did they just send him home each time because he was a minor?

    IntelBroker got into a diversion program at one point. It didn't stick, obviously, but do you know if either of these teens was ever in any kind of diversion program or getting any supervision?

    In conversation about 9 months ago from infosec.exchange permalink
  20. Embed this notice
    Dissent Doe :cupofcoffee: (pogowasright@infosec.exchange)'s status on Thursday, 18-Sep-2025 06:47:21 JST Dissent Doe  :cupofcoffee: Dissent Doe :cupofcoffee:

    "The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

    [...]

    In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

    ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

    Read more of Lawrence Abrams' great reporting on Bleeping Computer:
    https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/

    #Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.bleepstatic.com
      ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
      from @BleepinComputer
      The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.
  • Before

User actions

    Dissent Doe  :cupofcoffee:

    Dissent Doe :cupofcoffee:

    Blogger/journalist at databreaches.net and pogowasright.org. As a retired healthcare professional, breaches in the healthcare sector are my priority.The header pic is Indy, a Siberian husky we rescued in 2016 after I read how nobody wanted her because she was so difficult. She is now living her best life and is a mushball with me.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          216210
          Member since
          21 Nov 2023
          Notices
          61
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.