@nosnilmot more work to be done on that 😅
Notices by Kevin Beaumont (gossithedog@cyberplace.social)
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:45:33 JST
Kevin Beaumont
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:45:08 JST
Kevin Beaumont
@HaTetsu I think many of them are scraping the RSS feed tbh (add .rss to a username gives you an RSS feed, but it doesn’t include non-public toots)
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:32:36 JST
Kevin Beaumont
And yes, this was (and is) a supply chain attack - just everybody was too busy wacking off about GenAI and react2shell to notice.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:30:50 JST
Kevin Beaumont
Also, long time followers may remember this one playing out in real time over the last few weeks - I just tooted about it in Follower mode to stop threat intel companies scraping the toots 🤣
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:28:18 JST
Kevin Beaumont
Impacted boxes have things like FatBeehive and other tools installed, there’s hunting guides in that blog.
Notepad++ author really good btw, quick turn around.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:20:05 JST
Kevin Beaumont
I did have a thread on this at the time but I think it auto deleted, whoops. It was being used for entry into telcos and financial services in East Asia anyhoo.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:14:00 JST
Kevin Beaumont
Notepad++ have released a new version to fix the auto update process being hijacked https://notepad-plus-plus.org/news/v889-released/
I reported the vulnerability, it is being hijacked by threat actors in China. https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 06:13:59 JST
Kevin Beaumont
I hadn’t put the full details in the blog at the time, but the Notepad++ updater didn’t check if the update package was valid in any way - it just executed it. Also the update process used TLS.. but didn’t validate the session, so it could be hijacked to change the download.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 04:39:41 JST
Kevin Beaumont
There’s one very crucial detail about the ‘react2shell’ stuff and the level of threat it does or doesn’t pose, which I’ve decided to sit on while the entire industry sets itself on fire about it.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Dec-2025 03:42:39 JST
Kevin Beaumont
RE: https://masto.ai/@phoronix/115690887166897257
“Platinum Members of the new Agentic AI Foundation include Amazon Web Services, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI.”
Linux Foundation’s decided to guzzle the AI money.
-
Embed this notice
Matt Nordhoff (mnordhoff@infosec.exchange)'s status on Tuesday, 09-Dec-2025 20:20:06 JST
Matt Nordhoff
time.cloudflare.com suddenly 5-10 ms off the real time in the eastern US.
I'd guess probably something boring, like network asymmetry near the top of the tree (bottom of the tree?).
(When the service was new, the accuracy was routinely worse than this.)
In conversation from infosec.exchange permalink Repeated by GossiTheDog Attachments
-
Embed this notice
Mastodon (mastodon@mastodon.social)'s status on Tuesday, 09-Dec-2025 19:45:25 JST
Mastodon
Elon Musk and X are once again proving why institutions should never rely on corporate-owned, centrally-controlled social media platforms to reach their people.
In conversation from mastodon.social permalink Repeated by GossiTheDog -
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Dec-2025 18:55:56 JST
Kevin Beaumont
@metacurity *in Korea
In conversation from cyberplace.social permalink -
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Dec-2025 05:51:51 JST
Kevin Beaumont
If you're into reverse engineering malware, this might tickle your fancy: a511be5164dc1122fb5a7daa3eef9467e43d8458425b15a640235796006590c9
Entry via a supply chain attack, sideloads off a legit AV product, remote access trojan, drops FatBeehive.
In conversation from cyberplace.social permalink -
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Dec-2025 05:21:48 JST
Kevin Beaumont
Somebody put offroad cars into Microsoft Flight Simulator 2024, much dumb fun was had just now in Canada. #GossiAirways
In conversation from cyberplace.social permalink Attachments
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 23:54:04 JST
Kevin Beaumont
@sawaba @todb yeah, the fixed version cited was released months ago
In conversation from cyberplace.social permalink -
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 23:24:25 JST
Kevin Beaumont
@todb they say it's the same vulnerability in the write up though, they just forgot to include the full scope as I read it. Ultimately doesn't really matter now, just curious - I don't think they realised it was triggerable via tika-core, which is where they fixed it but forgot to scope.
In conversation from cyberplace.social permalink -
Embed this notice
cR0w h0 h0 (cr0w@infosec.exchange)'s status on Monday, 08-Dec-2025 23:23:09 JST
cR0w h0 h0
@huronbikes It's almost like vibe-coding an entire class of product was a bad idea.
In conversation from infosec.exchange permalink Repeated by GossiTheDog -
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 22:12:37 JST
Kevin Beaumont
@tonanio cool. Go do that somewhere else.
In conversation from cyberplace.social permalink -
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 08-Dec-2025 17:52:04 JST
Kevin Beaumont
@tonanio why are you telling me what to toot?
In conversation from cyberplace.social permalink