GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by BrianKrebs (briankrebs@infosec.exchange)

  1. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 22-Jul-2026 21:10:19 JST BrianKrebs BrianKrebs

    New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps

    The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

    https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/

    #smarttv #lg #residentialproxies #spur #security

    In conversation about 15 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/960/971/646/815/691/original/30bd820e2705eae2.png
  2. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 22-Jul-2026 02:44:52 JST BrianKrebs BrianKrebs

    Banks can now get access to insider trading information, straight from the POTUS's mouth. For a fee, of course. Axios reports Trump Media has already signed several customers ahead of the Aug. 1 launch, including financial news organizations and high-frequency trading firms.

    https://www.axios.com/2026/07/16/truth-social-license-data-wall-street

    A letter from Sen. Mark Warner (D-Va) to the financial services industry urges banks to reject Truth Social's new service that would offer advance access to the president's posts on the platform.

    "In a letter to the presidents of Bank Policy Institute, Securities Industry and Financial Markets Association, Managed Funds Association, Financial Services Forum, Principal Traders Group, and American Bankers Association, Sen. Warner wrote, “I write regarding Trump Media & Technology Group’s (TMTG) announcement that it will begin offering financial institutions and other users the option of paying TMTG for prioritized delivery of posts from President Trump (and other Truth Social accounts as determined by TMTG). This arrangement presents a serious risk to market integrity, creates a clear and unacceptable pathway for corruption, and undermines public confidence in the fair dissemination of market-moving government information – a crucial factor in maintaining stable and trustworthy financial markets.”

    "Sen. Warner explained that, according to TMTG, the Truth API will provide select paying customers with advance access to posts from top Truth Social accounts, a list that includes the president’s, faster than regular users receive push notifications or can manually monitor Truth Social. Trump Media has said the service is specifically designed for organizations “most impacted by the cost of a delay in information,” including algorithmic trading firms, and customers have already signed up for the service, which it has reportedly offered for $100,000 per month."

    https://www.warner.senate.gov/wp-content/uploads/2026/07/260721.Warner_Finance_Truth_API_letter.pdf

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments


  3. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Monday, 20-Jul-2026 21:54:26 JST BrianKrebs BrianKrebs

    Just tasted my breakfast from a few hours ago reading this. I'm getting lots more spam that encourages me to try this or that AI prompt to brighten my day, ease my workload, help me finish a project. This one encourages me to have a blessed day and to try this Neville prompt today!

    Just FYI, the Neville prompt is based on the teachings of Neville Goddard, who Wiki describes as a Barbadian writer, speaker and mystic in the New Thought movement ((February 19, 1905 – October 1, 1972)).. He grew up in Barbados and moved to the United States as a young adult. He taught self-help methods for meditation, self-hypnosis and manifestation. He authored 14 books and delivered over 300 lectures.

    https://en.wikipedia.org/wiki/Neville_Goddard

    This Goddard guy seems like a bit of a quack, but his teachings seem to fit well with the ethos of AI, and making one's own god. From Wiki:

    "Goddard's philosophy centers on the power of the "Human Imagination," which he identified as the divine spark or "God" described in religious texts.[15] He taught that the external world is a projection of an individual's internal mental state, a concept often summarized by his phrase "everyone is you pushed out."[

    In conversation about 17 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/952/357/092/453/517/original/b057c8cad91def4e.png
  4. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Saturday, 18-Jul-2026 02:30:29 JST BrianKrebs BrianKrebs

    Noticed the abysmal indoor air quality as measured this morning by gadget we bought after last year's wildfire smoke turned the sky a Blade Runner orange for several days. Visibility outside is next to nil right now from all the wildfire smoke. So I dug out the box fan filter contraption I built last year. It's bulky as all get-out, but it brought the air quality to excellent throughout the house in about an hour.

    Last year instructions for building these things were all over the Internet. But really, all you need is a big square cheapo plastic box fan that you duct tape down on top of a cube of large HVAC filters. Total cost (depending on the thickness of the filters you opt for) should be ~$30-60. We used huge 4-inch thick HVAC filters, so the cost was a little more for ours.

    https://www.youtube.com/watch?v=DXya56NIaVM

    In conversation about 20 days ago from infosec.exchange permalink
  5. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 17-Jul-2026 09:26:38 JST BrianKrebs BrianKrebs

    Thanks to AI eating the supply chain, hosting a website has gotten a LOT more expensive than in years past. One wonders what's going to happen to bajillions of small hosting companies that are profitable as long as all their equipment isn't 2-10 times more expensive than it used to be. For now, they're just passing the costs on to their customers. But my guess is the hosting industry is headed for a wave of consolidation and/or bankruptcies.

    https://topsitehosters.com/blog/why-your-hosting-is-getting-more-expensive/

    In conversation about 21 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/931/275/694/307/231/original/c50a1a0999968f1d.png
  6. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 15-Jul-2026 06:11:52 JST BrianKrebs BrianKrebs

    Hey Windows (ab)users, Microsoft has a big present for you: Today they released software updates to plug at least 570 security holes in their Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Ah, but there's a catch: AI is also speeding up the discovery of workable exploits.

    https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/

    #windows #patchtuesday #zeroday #microsoft #ai

    In conversation about 23 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/919/968/406/790/977/original/fc4ae2dc286fbee0.png
  7. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 15-Jul-2026 05:21:57 JST BrianKrebs BrianKrebs
    in reply to
    • Molly White

    After our story the other day about two far-right conspiracy theorists and convicted felons who were running an offensive cybersecurity company called IRIS C2, many readers asked how exactly these clowns Jacob Wohl and Jack Burkman are making money?

    https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/

    Burkman has a consulting firm that has been sought out by a number of criminals who are seeking pardons from the POTUS. Yesterday, metro.co.uk ran a story saying an American rapper who goes by the name "Boosie Badazz" is suing Burkman and Wohl after paying $600,000 for a presidential pardon from Donald Trump that never materialized.

    "Boosie, 43, whose real name is Torence Hatch, faced sentencing for possessing a firearm as a felon and hoped that a presidential pardon would wipe his criminal record clean.

    "He allegedly sought the help of two far-right political operatives and lobbyists at JM Burkman & Associates, who allegedly claimed they had strong connections within Trump’s inner circle."

    https://metro.co.uk/2026/07/13/american-rapper-paid-trump-450-000-pardon-never-came-29128723/

    This tracks with a March 31 story from journalist @molly0xfff which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a “presidential pardon to avert a miscarriage of justice” on behalf of the accused hacker, who has not yet been convicted.

    https://www.citationneeded.news/issue-103/

    In conversation about 23 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: metro.co.uk
      Metro – Metro.co.uk: News, Sport, Showbiz, Celebrities from Metro
      Metro.co.uk: News, Sport, Showbiz, Celebrities from Metro


  8. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Tuesday, 14-Jul-2026 13:54:42 JST BrianKrebs BrianKrebs
    in reply to

    Alarum Technologies, the publicly traded Israeli company responsible for the NetNut residential proxy service, says it's investigating claims that NetNut is linked to the Popa botnet and nonconsensual installations of proxy software. The statement tries to assure investors that the company is taking the findings seriously. The funny part is it concludes by encouraging concerned investors to email the company at a domain that was recently seized by the FBI and has no ability to accept incoming email.

    https://finance.yahoo.com/technology/articles/alarum-technologies-provides-further-regarding-120000252.html

    In conversation about 24 days ago from infosec.exchange permalink
  9. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Tuesday, 14-Jul-2026 13:54:42 JST BrianKrebs BrianKrebs
    in reply to

    Youch. Alarum Technologies (NASDAQ: ALAR) had one of its best trading days of the year on June 15, right after the company announced to investors that revenue had increased 64 percent. The stock has been on a downward trajectory ever since. On June 18, we ran a story that cited research from 3 different security firms linking Alarum and its widely-resold NetNut residential proxy service to a 4 year-old botnet called Popa, which was often installed on user devices without consent.

    Since late last week, when the FBI and industry partners seized NetNut's website and hundreds of domains used to control the Popa botnet, Alarum's stock price has been in a freefall, currently hovering at less than a third of its June 15 high. The stock has fallen again in trading today, likely because the FBI just seized Alarum's domain name as well.

    July 2: https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/

    June 18: https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/

    In conversation about 24 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/879/022/051/113/813/original/c1c4a25caa9d7938.png

    2. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
      For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded…
  10. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Tuesday, 14-Jul-2026 13:54:42 JST BrianKrebs BrianKrebs

    New, breaking: FBI Seizes NetNut Proxy Platform, Popa Botnet

    "The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims."

    https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/

    #popa #botnet #cybercrime #residentialproxies #netnut

    In conversation about 24 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/852/050/134/013/337/original/39427d204c026361.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/852/050/170/923/410/original/8692a2f18de0e840.png
    3. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      FBI Seizes NetNut Proxy Platform, Popa Botnet
      The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly…
  11. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Monday, 13-Jul-2026 03:27:59 JST BrianKrebs BrianKrebs

    After trying trying and failing so many times I can't remember, I finally got the intro and basic chords to go along with the constant E-minor/A major baseline in the epic Doors song Riders on the Storm. I can do the tinkling raindrop bit in the right hand that meanders down the keyboard in the Dorian scale at speed, but not yet at the same time as the baseline. But I'm going to play the hell out of the part I do know today, lol.

    Ray Manzarek on how he came up with the basics of the song:

    https://www.youtube.com/watch?v=3deQXzV-qTk

    In conversation about a month ago from infosec.exchange permalink
  12. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Saturday, 11-Jul-2026 08:36:11 JST BrianKrebs BrianKrebs
    in reply to

    What might end up mattering more than who gets to the "singularity" or quantum leap first is market share, and one thing we've seen reliably from China is they are very good at securing market share through govt subsidies and flooding the market with cheaper alternatives. The sticker shock that organizations investing in AI are now feeling is a result of AI companies finally charging something approximating their real costs to provide the service. Meanwhile, Chinese AI companies can continue to subsidize the cost of their tokens probably indefinitely.

    In conversation about a month ago from infosec.exchange permalink
  13. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Saturday, 11-Jul-2026 00:38:18 JST BrianKrebs BrianKrebs

    It doesn't take a genius to figure out that a lot of companies smarting from the increasing costs of AI tokens might start to look for cheaper alternatives, and that those alternatives increasingly are going to come from our adversaries.

    As we start to care more about our software supply chain risks, seems like it's also getting more challenging for organizations to understand the provenance of the AI code they are relying on. From a CNBC story about how lawmakers are trying to figure out how to curb the growing adoption of Chinese AI models by homegrown companies:

    "Cursor, which will be acquired by Elon Musk's SpaceX for $60 billion, built its Composer 2 model using Chinese AI model Kimi, which was developed by Moonshot AI."

    https://www.cnbc.com/2026/07/08/chinese-ai-models-probe-us-lawmakers.html

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: image.cnbcfm.com
      Lawmakers probe growing use of Chinese AI models in U.S. companies
      from https://www.facebook.com/CNBC
      An ongoing House Committee investigation is probing the risks involved in the rise of AI built in China.
  14. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 10-Jul-2026 04:53:58 JST BrianKrebs BrianKrebs
    • Catalin Cimpanu

    Feels like all of us (even people w/out a car) need to pay way more attention to the WTAF new rules affecting EU and US folk, requiring all new cars to include a driver monitoring camera aimed at your face.

    "Glance at your phone, your kids in the back seat, or the radio for too long, and the car will flash a warning light and sound an alert," reads a recent post from Allaboutcookies.org.

    https://allaboutcookies.org/eu-mandatory-distracted-driver-system

    First spotted this story in the Risky Business newsletter yesterday and have been reading as much as I can about it ever since. https://risky.biz/RBNEWS587/

    Risky's @campuscodi writes the new regulation has entered into effect in the EU on Monday and will enter into effect next year in the US. In the EU, the new camera requirement is part of the block's second General Safety Regulation (GSR2), a broader swath of new safety rules introduced for the auto industry and designed to improve road safety.

    https://www.inkl.com/news/new-eu-car-safety-rules-take-effect-7-july-how-your-car-could-monitor-you

    https://www.gadgetreview.com/federal-surveillance-tech-becomes-mandatory-in-new-cars-by-2027

    This is some next level Orwellian shit. My dreams of one day replacing one of our cars with an electric vehicle just got much darker.

    In conversation about a month ago from infosec.exchange permalink

    Attachments



  15. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 10-Jul-2026 01:20:10 JST BrianKrebs BrianKrebs

    Someone asked me recently to name the craziest thing that's ever happened to me. I had to really think about this, having been the recipient of multiple swatting attacks, doxings, several record-smashing ddos campaigns, sex toys, weapons and giant bags of shit showing up at our doorstep for years. Even had a guy send $1200 worth of pure heroin to our house in a failed bid to frame me with narcotics possession.

    Honestly, the weirdest thing I experienced in my work happened in May 2013. On that day, apropos of nothing, the reclusive lady renting the townhouse across the street from us came over to our lawn dressed to kill -- -- wearing a black skirt, pressed white shirt and a mask -- and carrying a saw. After she moved out of the camera's lowermost frame, she proceeded to cut down a pretty huge pine tree in our front yard. I can only surmise that she did this because a small portion of the tree was dead on account of it being crowded by an unkempt shrub next door.

    Mind you, the only interaction I had with this lady previously was watching her stand in the parking lot in flowing robes and screaming at guests parking where they shouldn't.

    I never got the full story about what her deal was, because she split the neighborhood not long after that. But I still refer to her as "that hacker lady," because she literally hacked down my tree.

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/890/865/941/964/765/original/0a541e11e643b75d.png
  16. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Thursday, 09-Jul-2026 23:30:38 JST BrianKrebs BrianKrebs

    Important story from Wired: A government report claims DOGE didn’t access sensitive systems. It also says the agency deleted records that would show if they had.

    From the story:

    "In April 2026, though, the Government Accountability Office (GAO)—a federal agency within the legislative branch that performs audits and investigations for Congress— published its own report about DOGE’s access to the NLRB’s systems, titled “National Labor Relations Board Detailees Did Not Access IT Systems Between April 16 and July 25, 2025.” The report conspicuously only covers the time period immediately following Berulis’ complaint, and does not address any DOGE activity before that point."

    "But nested in the footnotes of the report is another revelation: In August 2025, shortly after DOGE members left the NLRB but before the GAO’s investigators “requested to observe the systems,” the agency “deleted the team member accounts for system access after the agreement to detail DOGE team staff had expired.” Basically, this means that the digital records of what data and systems DOGE members accessed and when had been eliminated, leaving the GAO no way to confirm what NLRB staff told their investigators."

    https://www.wired.com/story/federal-investigators-say-certain-doge-records-were-deleted/ (paywall)

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.wired.com
      Federal Investigators Say Certain DOGE Records Were Deleted
      from Vittoria Elliott
      A government report claims DOGE didn’t access sensitive systems. It also says the agency deleted records that would show if they had.
  17. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 08-Jul-2026 21:38:56 JST BrianKrebs BrianKrebs

    New, by me: Felons, Fraudsters Flog Offensive Cybersecurity Startup

    A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

    https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/

    #c2iris #irisc2 #cybersecurity #maga

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/884/373/970/896/838/original/0e1f84d5004c2cde.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/884/374/731/237/154/original/0b0561f07f46f58e.png
  18. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Tuesday, 07-Jul-2026 01:26:20 JST BrianKrebs BrianKrebs
    • Jcrabapple :virginia_badge:

    @jcrabapple Meh. Microsoft, like all other big companies, will respond to legal process. Given that Microsoft's recent operating systems basically require you to log in to their cloud at startup, this is not particularly surprising to me.

    And if motivated to pursue a threat actor who is actively harming their customers, Microsoft can tell a great deal about users. As can Google, or FB/Meta. I always said that if just two of those companies decided to find someone responsible for something, they probably could if they shared information.

    In conversation about a month ago from infosec.exchange permalink
  19. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 03-Jul-2026 01:34:27 JST BrianKrebs BrianKrebs

    The email provider Securence (US Internet, now owned by a joint venture between T-Mobile and KKR) has disabled its administrative portal for a week now, although email is still flowing. The company won't say the cause or share much about what's happening. Believe me, I've tried.

    This is the same company that published more than a decade's worth of customer (and internal company) emails in plain text on the web a couple years back.

    https://krebsonsecurity.com/2024/02/u-s-internet-leaked-years-of-internal-customer-emails/

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/851/147/194/605/619/original/d969c87f7db48f49.png
  20. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 03-Jul-2026 00:47:11 JST BrianKrebs BrianKrebs

    If you're a Chrome (ab)user and you see that little "relaunch to update" tab appear in the upper right corner of the browser, just know that there's at least 382 security fixes waiting for you.

    https://www.heise.de/en/news/Google-Chrome-Large-update-closes-hundreds-of-security-vulnerabilities-again-11350087.html

    https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html

    In conversation about a month ago from infosec.exchange permalink
  • Before

User actions

    BrianKrebs

    BrianKrebs

    Independent investigative journalist. Covers cybercrime, security, privacy. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter, '95-'09. Signal: briankrebs.07 krebsonsecurity @ gmail .comLinkedin: https://www.linkedin.com/in/bkrebs

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          21764
          Member since
          9 Nov 2022
          Notices
          667
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.