GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by leakix (leakix@mastodon.social)

  1. Embed this notice
    leakix (leakix@mastodon.social)'s status on Thursday, 13-Nov-2025 01:30:29 JST leakix leakix

    🚨 New plugin: WatchGuardFireboxPlugin (CVE-2025-59396).

    WatchGuard Firebox default credentials allow administrative SSH access. CVE rejected by NVD: "Not a security vulnerability".

    Results: https://leakix.net/search?q=%2Bplugin%3AWatchGuardFireboxPlugin&scope=leak

    In conversation about 18 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/537/484/262/516/697/original/cb86a42d6c8b56e2.png

  2. Embed this notice
    leakix (leakix@mastodon.social)'s status on Saturday, 26-Jul-2025 01:27:42 JST leakix leakix
    in reply to
    • Kevin Beaumont
    • The Shadowserver Foundation

    @GossiTheDog @shadowserver let us know if you want to share paths. We'll share with them and you and release the info publicly.

    In conversation about 4 months ago from mastodon.social permalink
  3. Embed this notice
    leakix (leakix@mastodon.social)'s status on Friday, 25-Jul-2025 19:23:14 JST leakix leakix
    • Kevin Beaumont

    @GossiTheDog https://www.youtube.com/watch?v=myY-4YsWTAM

    In conversation about 4 months ago from mastodon.social permalink

    Attachments

    1. RSA 2025
      from UwU Underground - Topic
      Provided to YouTube by DistroKidRSA 2025 · UwU Underground · UwU UndergroundRSA 2025℗ UwU CrewReleased on: 2025-04-29Auto-generated by YouTube.
  4. Embed this notice
    leakix (leakix@mastodon.social)'s status on Thursday, 17-Jul-2025 17:01:47 JST leakix leakix
    in reply to
    • Kevin Beaumont

    @GossiTheDog 😇 sure does work. Any take-down requests yet ? 🤔

    In conversation about 5 months ago from mastodon.social permalink
  5. Embed this notice
    leakix (leakix@mastodon.social)'s status on Saturday, 08-Mar-2025 01:21:19 JST leakix leakix
    • Kevin Beaumont

    🚨 Detection for Cisco ASA CVE-2020-3259 has been added.
    ~2.5k vulnerable instances still found on a 5 years old vulnerability allowing for session hijacking and credentials stealing.

    Source: https://cyberplace.social/@GossiTheDog/111848755813858062
    Thanks: @GossiTheDog
    Query: +plugin:CiscoASAPlugin

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/114/122/042/530/002/085/original/0470099141c63880.png
    2. Domain not in remote thumbnail source whitelist: cyberplace.social
      Kevin Beaumont (@GossiTheDog@cyberplace.social)
      from Kevin Beaumont
      Attached: 1 image 🚨 patch your Cisco AnyConnect boxes 🚨 For a 2020 vulnerability. Really. Lots of ransomware cases coming in for Cisco AnyConnect/ASA recently and finally we know how - CVE-2020-3259 It was a vuln which allowed a CitrixBleed style memory dump, found by a Russian research org now under US sanctions. Ransomware operators have an exploit. Sadly it looks like many orgs never patched. https://www.truesec.com/hub/blog/akira-ransomware-and-exploitation-of-cisco-anyconnect-vulnerability-cve-2020-3259 #threatintel
  6. Embed this notice
    leakix (leakix@mastodon.social)'s status on Wednesday, 15-Jan-2025 04:26:50 JST leakix leakix
    • Kevin Beaumont

    @GossiTheDog Oh great, are the Greet Admins of Mastodon going to ban Google from their instance ?

    Sorry, sorry, the salt went off :)

    In conversation about 11 months ago from mastodon.social permalink
  7. Embed this notice
    leakix (leakix@mastodon.social)'s status on Tuesday, 07-Jan-2025 23:30:33 JST leakix leakix

    ⚠️ During our scans we found ~70K applications exposing their VSCode SFTP config.

    These are often critical and can include FTP/SSH credentials.

    You can check this out here: https://leakix.net/search?q=%2Bplugin%3AVsCodeSFTPPlugin&scope=leak

    #cybersecurity #vscode #vulnerability

    In conversation about 11 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/787/504/537/165/227/original/f5f9618f63970052.png
    2. Domain not in remote thumbnail source whitelist: leakix.net
      Search results for +plugin:VsCodeSFTPPlugin
  8. Embed this notice
    leakix (leakix@mastodon.social)'s status on Thursday, 07-Mar-2024 07:04:53 JST leakix leakix

    ⚠️We added detection for compromised #TeamCity instances:

    1711 vulnerable instances were found during our last scan, 1442 show clear signs of rogue user creation.

    If you were/are still running a vulnerable system, assume compromise.

    In conversation Thursday, 07-Mar-2024 07:04:53 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/051/001/394/483/538/original/f8b577352a3d8ccb.png

    2. https://files.mastodon.social/media_attachments/files/112/051/001/815/461/897/original/73f6354cb2a32c23.png
  9. Embed this notice
    leakix (leakix@mastodon.social)'s status on Thursday, 07-Mar-2024 04:38:45 JST leakix leakix

    ⚠️⚠️⚠️ We are seeing massive exploitation of #TeamCity CVE-2024-27198.

    Hundreds of users are created for later use across the Internet.

    In conversation Thursday, 07-Mar-2024 04:38:45 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/050/410/103/980/644/original/0ecc0bf011476f6f.png

    2. https://files.mastodon.social/media_attachments/files/112/050/410/528/959/901/original/472b054e3a774b14.png

User actions

    leakix

    leakix

    Maintaining and reporting for LeakIX.We are NOT affiliated with any ransomware campaign.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          236999
          Member since
          20 Jan 2024
          Notices
          9
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.