GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Chris Wysopal (weld@infosec.exchange)

  1. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 04-Dec-2025 02:16:16 JST Chris Wysopal Chris Wysopal

    🚨 Critical React + Next.js RCE Alert 🚨
    New flaws in the React Server Components “Flight” protocol (CVE-2025-55182 & CVE-2025-66478) allow unauthenticated remote code execution on default installations.

    Attackers only need one malicious HTTP request to take over a server.

    Wiz reports 39% of cloud environments are vulnerable.

    If you're running:
    • React 19.0–19.2
    • Next.js 14.3.0-canary, 15.x, 16.x (App Router)
    • Any framework bundling react-server (Redwood, Waku, Vite/Parcel RSC plugins, etc.)

    👉 You are likely exposed. Patch immediately.

    Updates now available:
    React 19.0.1 / 19.1.2 / 19.2.1
    Next.js 14.3.0-canary.88 / 15.0.5+ / 16.0.7

    Full RCE. Remote. Unauthenticated. Near-100% exploit reliability.

    Patch today. Do not wait.

    In conversation about 21 days ago from infosec.exchange permalink
  2. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Wednesday, 09-Jul-2025 00:25:59 JST Chris Wysopal Chris Wysopal

    The EU Product Liability Directive will take effect Dec 2026. Software, firmware, applications, AI systems, and will now be subject to the same strict liability regime as traditional physical goods. Cybersecurity vulnerabilities will be considered product defects. Analysis by Reed Smith LLP: https://www.lexology.com/library/detail.aspx?g=bbef1939-2af0-465a-8b8f-c1ff3ebe9118

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/818/294/861/034/457/original/f994ba35fdeda2cd.png
    2. Domain not in remote thumbnail source whitelist: www.lexology.com
      The new EU Product Liability Directive: Implications for software, digital products, and cybersecurity
      The EU has adopted Directive 2024/2853 (the “Product Liability Directive” or “PLD”), which will take effect on December 9, 2026. This new Directive…
  3. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Monday, 14-Apr-2025 04:48:36 JST Chris Wysopal Chris Wysopal

    Palo Alto crosswalk buttons apparently hacked to imitate Musk, Zuckerberg voices saying some wild things. https://www.paloaltoonline.com/technology/2025/04/12/silicon-valley-crosswalk-buttons-apparently-hacked-to-imitate-musk-zuckerberg-voices/

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.paloaltoonline.com
      Silicon Valley crosswalk buttons apparently hacked to imitate Musk, Zuckerberg voices
      from Zoe Morgan
      Crosswalk buttons along the mid-Peninsula appear to have been hacked, so that when pressed, voices professing to be Mark Zuckerberg or Elon Musk begin speaking.
  4. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 05-Dec-2024 01:46:23 JST Chris Wysopal Chris Wysopal

    Message security reminder:

    Text Messages sent between Apple and Android devices are not end to end encrypted.

    Use a secure messaging app. I recommend Signal.

    In conversation about a year ago from infosec.exchange permalink
  5. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 05-Dec-2024 01:27:00 JST Chris Wysopal Chris Wysopal

    It took massive Chinese telco infiltration but now the US Govt gets it

    2015: "We cannot stop what we cannot see," Rep Mike McCaul

    2024: "Encryption is your friend, whether it's on text messaging or if you have the capacity to use encrypted voice comms." Jeff Greene, CISA

    In conversation about a year ago from infosec.exchange permalink
  6. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Tuesday, 26-Nov-2024 21:18:27 JST Chris Wysopal Chris Wysopal

    There is a Tesla #cybertruck at Black Hat MEA but unfortunately you can’t hack it. There is a semi you can hack in the truck hacking area. #cybersecurity

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/549/170/793/053/803/original/fa7a863e4ded0b81.jpeg
  7. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 21-Nov-2024 01:13:57 JST Chris Wysopal Chris Wysopal

    After 18 yrs as Veracode's CTO I have transitioned to Chief Security Evangelist. I'm excited to have more time to engage developers at meetups & conferences. You'll still see me at all the cybersecurity cons. This & the future of AppSec w/Jens Wessling & Alan Shimel: https://techstrong.tv/videos/interviews/the-evolution-of-application-security-integration-with-veracodes-jens-wessling-and-chris-wysopal

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: techstrong.tv
      The Evolution of Application Security Integration with Veracode's Jens Wessling and Chris Wysopal - Techstrong TV
      Veracode recently announced the appointments of Jens Wessling as Chief Technology Officer (CTO). Jens succeeds Veracode co-founder Chris Wysopal in the role, while Chris assumes the position of Chief Security Evangelist.In this joint interview with Jens and Chris, the two discuss the biggest change in application security over the past 20 years, which is how much it’s now integrated with the software development lifecycle.
  8. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 21-Nov-2024 00:43:21 JST Chris Wysopal Chris Wysopal
    • Defcon

    It was so great to be part of this amazing panel this year at ⁦@Defcon - Bricked & Abandoned: How To Keep IoT From Becoming An IoTrash. https://securityboulevard.com/2024/11/def-con-32-bricked-abandoned-how-to-keep-iot-from-becoming-an-iotrash/

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: securityboulevard.com
      DEF CON 32 - Bricked & Abandoned: How To Keep IoT From Becoming An IoTrash
      from @securityblvd
      Authors/Presenters: Paul Roberts, Chris Wysopal, Cory Doctorow, Tarah Wheeler, Dennis Giese Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink
  9. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 07-Dec-2023 17:06:27 JST Chris Wysopal Chris Wysopal

    Breaking: Aliens have finally contacted us, and guess what? They want us to update our antivirus software!

    In conversation Thursday, 07-Dec-2023 17:06:27 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/533/930/143/177/241/original/940d2c329dffa5ff.jpeg
  10. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Saturday, 07-Oct-2023 02:28:54 JST Chris Wysopal Chris Wysopal

    What gets collected gets stolen and resold. Information wants to be freely available for a price. https://cyberscoop.com/23andme-user-data-theft/

    In conversation Saturday, 07-Oct-2023 02:28:54 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cyberscoop.com
      DNA testing service 23andMe investigating theft of user data
      from AJ Vicens
      A member of an online forum where stolen data is bought and sold claims to be selling a large trove of user data obtained from 23andMe.
  11. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Saturday, 24-Dec-2022 03:46:03 JST Chris Wysopal Chris Wysopal

    "Computer scientists from Stanford University have found that programmers who accept help from AI tools like Github Copilot produce less secure code than those who fly solo."

    Looks like there will be a market for AI vuln remediation!

    https://www.theregister.com/2022/12/21/ai_assistants_bad_code/

    In conversation Saturday, 24-Dec-2022 03:46:03 JST from infosec.exchange permalink
  12. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Thursday, 22-Dec-2022 03:40:35 JST Chris Wysopal Chris Wysopal

    Social media is metastasizing and I am here for it.

    I was there for BBSes.
    I was there for IRC.
    I was there for AOL chat.
    I was there for Facebook.
    Yeah didn't like Myspace.
    I was there for Twitter.
    I am here for private Slack
    Now I am here for Mastodon.

    In conversation Thursday, 22-Dec-2022 03:40:35 JST from infosec.exchange permalink
  13. Embed this notice
    Chris Wysopal (weld@infosec.exchange)'s status on Friday, 11-Nov-2022 11:53:12 JST Chris Wysopal Chris Wysopal

    It's been amazing seeing a whole community that has built up over 10+ years migrate to a new platform. The sentiment I have seen and heard repeated is that people have 1/10th the followers and have more engagement (I know that word). This can only mean goodness.

    In conversation Friday, 11-Nov-2022 11:53:12 JST from infosec.exchange permalink

User actions

    Chris Wysopal

    Chris Wysopal

    Co-founder/CTO Veracode. Former L0pht security researcher. Builds tools to find vulnerabilities in code at scale. Twitter: @weldpond

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          22956
          Member since
          11 Nov 2022
          Notices
          13
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.