Weird they're showing Swan Lake on Fox right now
Notices by boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Friday, 06-Jun-2025 07:22:00 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 29-May-2025 00:44:27 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Without full PCAP + emulated router profiles, this would've stayed hidden. Check your ASUS routers for SSH on TCP/53282 NOW.
Technical deep-dive: https://www.labs.greynoise.io//grimoire/2025-03-24-ayysshush/
๐ Executive summary: https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers
4/4 -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 29-May-2025 00:44:27 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Because it's configured through official ASUS settings, the backdoor persists in NVRAM even after patching. No malware dropped, logging disabled = nearly invisible.
This was caught by GreyNoise's AI tool ("Sift") analyzing just 3 HTTP requests out of 23+ billion.
3/4In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 29-May-2025 00:44:27 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
The tradecraft suggests an advanced, well-resourced adversary.
What makes this scary: Attackers chain authentication bypasses + CVE-2023-39780 to gain access, then enable SSH on port 53282 with their own public key.
2/4In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 29-May-2025 00:44:18 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
๐จ BREAKING: GreyNoise discovered a sophisticated backdoor campaign compromising ~9,000 ASUS routers worldwide. Unlike typical malware attacks, this operation uses the router's own legitimate features to create persistent backdoors that survive firmware updates and reboots.
1/4In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Sunday, 11-May-2025 05:13:27 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Citizen Released After Mysterious Detention by Security Forces
https://www.sfgate.com/bayarea/article/santa-cruz-woman-freed-ice-detention-20318272.php
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 01-May-2025 05:06:58 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
@mttaggart Fedi is still very (very) confusing + off-putting for the vast majority of folks who want to connect in a social network-style.
It could really do with a "one app" + "one big honkin server" flavor, which is what Bluesky sadly could have been.
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Tuesday, 29-Apr-2025 20:01:41 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Bluesky being down *again* is pretty amusing.
In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Tuesday, 29-Apr-2025 02:05:17 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
๐จ We have a detection up for SAP NetWeaver CVE-2025-31324 Unauthenticated File Upload Attempt
I can confirm we have had hits on it before the tag being published (we're working on a retro-hunt).
These IPs were seen making the attempts over the weekend:
98.84.54.227
67.205.148.188
85.90.245.101
89.117.19.46
172.105.246.67
212.56.35.88This is the tag:
https://viz.greynoise.io/tags/sap-netweaver-cve-2025-31324-unauthenticated-file-upload-attempt?days=30In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Saturday, 19-Apr-2025 21:29:27 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
I'm starting to get the impression y'all might be trying to tell us (i.e., U.S.) somethingโฆ
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 17-Apr-2025 03:28:06 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Gotta hand it to @GossiTheDog โฆ def knows how to steal content super well.
In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 17-Apr-2025 03:19:35 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
@hacks4pancakes wld have been great if he attributed it to me. not surprised tho.
In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Wednesday, 16-Apr-2025 19:19:51 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Tuesday, 25-Mar-2025 06:38:32 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
You'll be shockedโฆ*shocked*, I sayโฆto hear that I have thoughts about "The Signal Heard Round the World" โ https://47-watch.com/blog/posts/2025/2025-03-24-signal-heard-round-the-world/
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Saturday, 22-Mar-2025 01:13:20 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Never once before 2017 did I even remotely consider we'd (the U.S.) be the Centauri.
The IRL equivalent of "And All My Dreams, Torn Asunder" is happening live, right in front of us all.
In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 20-Mar-2025 11:30:51 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
I am SO SORRY folks. But Amerika is now one of the most dangerous places to travel to.
PLEASE STAY AWAY.
A decent % of us are gonna try to reclaim what we once were.
It won't be pretty or speedy.
JustโฆPLEASEโฆstay where you are. We cannot protect you. Our leaders hate you.
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 13-Mar-2025 20:20:34 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
โPeople Are Scaredโ: Inside CISA as It Reels From Trumpโs Purge
โYou've got a lot of people who are looking over their shoulder as opposed to looking at the enemy right now,โ
โMost people are โฆ doing the work of 2+ full-time [staffers].โ
America is going *great*.
In conversation from mastodon.social permalink -
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Saturday, 01-Mar-2025 23:44:31 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
DOGE Staffer Exposed for Posting Government Work on Public GitHub, Including Employee Union Tracking Tools
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Monday, 17-Feb-2025 12:41:28 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
Since I (a) needed to play with the Asahi Linux install I did yesterday on the old M1 Mini and (b) haven't used the ESC POS printer in a while, and (c) am still not up to much physical activity, I wired up the RSS feed of the POTUS blatherings I had Inoreader make for me so there's a physical record of the inanity.
Pretty sure this is a sign I'm nearing the breaking point.
In conversation from mastodon.social permalink Attachments
-
Embed this notice
boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ (hrbrmstr@mastodon.social)'s status on Thursday, 13-Feb-2025 07:31:00 JST boB Rudis ๐บ๐ฆ ๐ฌ๐ฑ ๐จ๐ฆ
This "unitary executive" BS is getting tiresome.
47 Watch has added 1 new executive order โ https://47-watch.com/executive-orders/2025-02-12-one-voice-for-americas-foreign-relations/ โ and it is yet-another doozy. Sufficiently so, that it warranted a short blog with a potential scenario https://47-watch.com/blog/posts/2025/2025-02-12-one-loud-obnoxious-voice/
In conversation from mastodon.social permalink Attachments