GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Kevin Beaumont (gossithedog@cyberplace.social)

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:45:33 JST Kevin Beaumont Kevin Beaumont
    in reply to
    • Stu Tomlinson

    @nosnilmot more work to be done on that 😅

    In conversation about an hour ago from cyberplace.social permalink
  2. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:45:08 JST Kevin Beaumont Kevin Beaumont
    in reply to
    • 波鉄 (Hatetsu)

    @HaTetsu I think many of them are scraping the RSS feed tbh (add .rss to a username gives you an RSS feed, but it doesn’t include non-public toots)

    In conversation about an hour ago from cyberplace.social permalink
  3. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:32:36 JST Kevin Beaumont Kevin Beaumont
    in reply to

    And yes, this was (and is) a supply chain attack - just everybody was too busy wacking off about GenAI and react2shell to notice.

    In conversation about 2 hours ago from cyberplace.social permalink
  4. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:30:50 JST Kevin Beaumont Kevin Beaumont
    in reply to

    Also, long time followers may remember this one playing out in real time over the last few weeks - I just tooted about it in Follower mode to stop threat intel companies scraping the toots 🤣

    In conversation about 2 hours ago from cyberplace.social permalink
  5. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:28:18 JST Kevin Beaumont Kevin Beaumont
    in reply to

    Impacted boxes have things like FatBeehive and other tools installed, there’s hunting guides in that blog.

    Notepad++ author really good btw, quick turn around.

    In conversation about 2 hours ago from cyberplace.social permalink
  6. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:20:05 JST Kevin Beaumont Kevin Beaumont
    in reply to

    I did have a thread on this at the time but I think it auto deleted, whoops. It was being used for entry into telcos and financial services in East Asia anyhoo.

    In conversation about 2 hours ago from cyberplace.social permalink
  7. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:14:00 JST Kevin Beaumont Kevin Beaumont

    Notepad++ have released a new version to fix the auto update process being hijacked https://notepad-plus-plus.org/news/v889-released/

    I reported the vulnerability, it is being hijacked by threat actors in China. https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9

    In conversation about 2 hours ago from cyberplace.social permalink

    Attachments



  8. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:13:59 JST Kevin Beaumont Kevin Beaumont
    in reply to

    I hadn’t put the full details in the blog at the time, but the Notepad++ updater didn’t check if the update package was valid in any way - it just executed it. Also the update process used TLS.. but didn’t validate the session, so it could be hijacked to change the download.

    In conversation about 2 hours ago from cyberplace.social permalink
  9. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 04:39:41 JST Kevin Beaumont Kevin Beaumont

    There’s one very crucial detail about the ‘react2shell’ stuff and the level of threat it does or doesn’t pose, which I’ve decided to sit on while the entire industry sets itself on fire about it.

    In conversation about 3 hours ago from cyberplace.social permalink
  10. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 03:42:39 JST Kevin Beaumont Kevin Beaumont

    RE: https://masto.ai/@phoronix/115690887166897257

    “Platinum Members of the new Agentic AI Foundation include Amazon Web Services, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI.”

    Linux Foundation’s decided to guzzle the AI money.

    In conversation about 4 hours ago from cyberplace.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: s3.masto.ai
      Phoronix (@phoronix@masto.ai)
      from Phoronix
      Attached: 1 image Linux Foundation's Newest Endeavor: The Agentic AI Foundation The Linux Foundation today announced it's formed another foundation under its growing umbrella that extends well beyond the traditional "Linux" landscape: the Agentic AI Foundation... https://www.phoronix.com/news/Linux-Foundation-Agentic-AI
  11. Embed this notice
    Matt Nordhoff (mnordhoff@infosec.exchange)'s status on Tuesday, 09-Dec-2025 20:20:06 JST Matt Nordhoff Matt Nordhoff

    time.cloudflare.com suddenly 5-10 ms off the real time in the eastern US.

    I'd guess probably something boring, like network asymmetry near the top of the tree (bottom of the tree?).

    (When the service was new, the accuracy was routinely worse than this.)

    In conversation about 12 hours ago from infosec.exchange permalink Repeated by GossiTheDog

    Attachments


  12. Embed this notice
    Mastodon (mastodon@mastodon.social)'s status on Tuesday, 09-Dec-2025 19:45:25 JST Mastodon Mastodon

    Elon Musk and X are once again proving why institutions should never rely on corporate-owned, centrally-controlled social media platforms to reach their people.

    https://www.bbc.com/news/articles/c0589g0dqq7o

    In conversation about 12 hours ago from mastodon.social permalink Repeated by GossiTheDog
  13. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Dec-2025 18:55:56 JST Kevin Beaumont Kevin Beaumont
    in reply to
    • Metacurity

    @metacurity *in Korea

    In conversation about 13 hours ago from cyberplace.social permalink
  14. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Dec-2025 05:51:51 JST Kevin Beaumont Kevin Beaumont

    If you're into reverse engineering malware, this might tickle your fancy: a511be5164dc1122fb5a7daa3eef9467e43d8458425b15a640235796006590c9

    Entry via a supply chain attack, sideloads off a legit AV product, remote access trojan, drops FatBeehive.

    #threatintel

    In conversation about a day ago from cyberplace.social permalink
  15. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Dec-2025 05:21:48 JST Kevin Beaumont Kevin Beaumont

    Somebody put offroad cars into Microsoft Flight Simulator 2024, much dumb fun was had just now in Canada. #GossiAirways

    In conversation about a day ago from cyberplace.social permalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/115/685/797/317/257/899/original/8eed866b8aafc6df.png
  16. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 23:54:04 JST Kevin Beaumont Kevin Beaumont
    in reply to
    • Tod Beardsley
    • Adrian Sanabria

    @sawaba @todb yeah, the fixed version cited was released months ago

    In conversation about a day ago from cyberplace.social permalink
  17. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 23:24:25 JST Kevin Beaumont Kevin Beaumont
    in reply to
    • Tod Beardsley

    @todb they say it's the same vulnerability in the write up though, they just forgot to include the full scope as I read it. Ultimately doesn't really matter now, just curious - I don't think they realised it was triggerable via tika-core, which is where they fixed it but forgot to scope.

    In conversation about a day ago from cyberplace.social permalink
  18. Embed this notice
    cR0w h0 h0 (cr0w@infosec.exchange)'s status on Monday, 08-Dec-2025 23:23:09 JST cR0w h0 h0 cR0w h0 h0
    in reply to
    • Andrew Golding

    @huronbikes It's almost like vibe-coding an entire class of product was a bad idea.

    In conversation about a day ago from infosec.exchange permalink Repeated by GossiTheDog
  19. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 22:12:37 JST Kevin Beaumont Kevin Beaumont

    @tonanio cool. Go do that somewhere else.

    In conversation about a day ago from cyberplace.social permalink
  20. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 17:52:04 JST Kevin Beaumont Kevin Beaumont

    @tonanio why are you telling me what to toot?

    In conversation about 2 days ago from cyberplace.social permalink
  • Before

User actions

    Kevin Beaumont

    Kevin Beaumont

    Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.I have Direct Messages disabled - you can send them, but I will never receive them.

    Tags
    • (None)

    Following 0

      Followers 1

      • caiden block

      Groups 0

        Statistics

        User ID
        38360
        Member since
        24 Nov 2022
        Notices
        3495
        Daily average
        3

        Feeds

        • Atom
        • Help
        • About
        • FAQ
        • TOS
        • Privacy
        • Source
        • Version
        • Contact

        GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

        Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.