GNU social JP
  • FAQ
  • Login
GNU social JPใฏๆ—ฅๆœฌใฎGNU socialใ‚ตใƒผใƒใƒผใงใ™ใ€‚
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)

  1. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Friday, 12-Dec-2025 04:19:03 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    in reply to
    • BrianKrebs
    • cR0w h0 h0

    @cR0w @briankrebs I knew what it was going to be, and I clicked through the warning anyway.

    In conversation about 4 days ago from infosec.exchange permalink

    Attachments


  2. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Wednesday, 03-Dec-2025 12:44:24 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller

    In conversation about 12 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/653/570/757/983/866/original/895733c57308b148.png
  3. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Friday, 28-Nov-2025 05:24:43 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    A comic that I will think about every day for the rest of my life, probably.

    (Sauce: https://analognowhere.com/_/ogmxha/ )

    In conversation about 18 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/622/617/983/766/219/original/37ef1f33e1673ca2.png
    2. Domain not in remote thumbnail source whitelist: analognowhere.com
      wisdom of the pentium-m man
  4. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 22-Nov-2025 01:26:15 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    a friendly reminder about how the digital world is held together

    In conversation about 24 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/588/012/569/403/295/original/c66c22da37758c11.png
  5. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 08-Nov-2025 12:22:37 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    you still have time to push to prod today.

    In conversation about a month ago from infosec.exchange permalink
  6. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Thursday, 21-Aug-2025 09:48:26 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Me upon reading some headlines about the AI bubble bursting.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/063/375/672/557/557/original/32bf8b87a701a88e.jpg
  7. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Wednesday, 20-Aug-2025 06:17:13 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    in reply to
    • Cat ๐Ÿˆ๐Ÿฅ— (D.Burch) :blobcatrainbow:
    • Chilly :donor: ๐Ÿ›ก๏ธ :fedora:
    • cR0w h0 h0
    • RootWyrm ๐Ÿ‡บ๐Ÿ‡ฆ:progress:
    • TerrorflonTrout :bc: he/him

    @rootwyrm @cR0w @TeflonTrout @catsalad @chillybot

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/057/137/638/001/478/original/2b1954a33a3c61c4.webp
  8. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Wednesday, 23-Jul-2025 11:06:15 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Big Endian was invented because someone really needed to know, right away, whether a number was positive or negative.

    Little Endian was invented because someone really needed to know, right away, whether a number was even or odd.

    This is how I'm going to explain "why is endianness a thing" to people that are new to binary stuff from now on.

    In conversation about 5 months ago from infosec.exchange permalink
  9. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 14-Jun-2025 03:54:33 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Meanwhile, in the industrial security space:

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/676/152/671/483/743/original/4158da57980ab0db.png
  10. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 24-May-2025 03:34:22 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    • Krypt3ia
    • Patrick C Miller :donor:

    @krypt3ia @patrickcmiller the only defense against malware with ai is goodware with you know what i give up.

    In conversation about 7 months ago from infosec.exchange permalink
  11. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 17-May-2025 11:00:25 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    A password consisting only of lowercase L's, uppercase i's, the number 1 and the | pipe..

    I|l11IllIIllIlIlII|

    ...technically satisfies all password requirements.

    In conversation about 7 months ago from infosec.exchange permalink
  12. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Wednesday, 14-May-2025 02:52:37 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller Haha I was investigating this this morning.

    I had a business in Indiana and it got a phishing email with proper dkim/dmarc stuff. The business email address was unique/serves as a breach canary, so I was trying to figure out if Indiana got popped or if govdelivery[.]com was misconfigured/got popped...

    In conversation about 7 months ago from infosec.exchange permalink
  13. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Friday, 09-May-2025 02:01:24 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    in reply to
    • Ryan Castellucci :nonbinary_flag:

    @ryanc A few years back I bought a bunch of these. Super duper helpful. We find all sorts of crazy pinouts on industrial products. My favorite to date is a GE thing that output +24v on pin 5 (usually a ground pin on db9), meant for powering a handheld programmer device.

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/473/276/261/242/258/original/47b4741afe3ac041.png
  14. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 03-May-2025 13:30:48 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Ah, US healthcare: where determining whether insurance covers a doctor visit takes longer than the doctor visit itself. And the answer they give is: "it depends..."

    I enjoy that we call these insurance people who look up the coverage "advocates". Advocates for whom, I wonder.

    In conversation about 8 months ago from infosec.exchange permalink
  15. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Thursday, 01-May-2025 10:31:33 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    • Ian Campbell

    @neurovagrant

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/423/542/389/058/707/original/d17163447aeb2a24.png
  16. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Friday, 21-Mar-2025 16:11:54 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Pretty sure I heard someone say 'phemails' to refer to phishing emails earlier today, so now all I've got is this image in my head.

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/196/496/742/456/936/original/9073e917faf9e20a.png
  17. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Sunday, 09-Mar-2025 13:34:09 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    That ESP32 thing has a CVE: CVE-2025-27840: https://nvd.nist.gov/vuln/detail/CVE-2025-27840 .

    And, pretty much everything all of the well-known infosec people have been saying is correct: physical access required (or, high privileges and high attack complexity; the score is kinda 'wrong' in some sense because it is combining two exploitation vectors but I think it gets across the point: this is not wormable and is not exploitable via wireless, at least not on its own. and if your threat model allows for physical access but still treats this as a big deal somehow, go home, your threat model is drunk).

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      NVD - CVE-2025-27840
  18. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Friday, 31-Jan-2025 05:35:35 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:
    in reply to
    • da_667

    @da_667 the safety word is banana

    In conversation about 11 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/913/974/150/658/934/original/d30464ff723f9373.png
  19. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Friday, 31-Jan-2025 05:35:35 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    The Year of the Snake, you say?

    In conversation about 11 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/913/963/134/151/772/original/fa1817a2a2fcd3cb.png
  20. Embed this notice
    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy: (reverseics@infosec.exchange)'s status on Saturday, 25-Jan-2025 09:16:43 JST K. Reid Wightman :verified: 🌻 :donor: :clippy: K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Welp, I guess I'm doing The Thing.

    In conversation about 11 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/885/063/970/923/588/original/9be6936e82eb6db5.png
  • Before

User actions

    K. Reid Wightman :verified: 🌻 :donor: :clippy:

    K. Reid Wightman :verified: ๐ŸŒป :donor: :clippy:

    Tinker, Sailor, Biker, HiI do industrial security research for a living, mostly looking for #vulnerabilities in all of the wrong places. I like reverse engineering how PLC logic systems function under the hood, learning how safety instrument protocols work, and figuring out what malicious threat groups are doing and can do with access to such systems. A long time ago, I invented the term 'foreverday' to describe unfixable vulnerabilities.Occasionally I analyze #industrial #malware, too, and on very rare occasions encounter threat groups that actually write malicious logic to do the vile things that I like to learn about. I work for a little startup in the space called Dragos. In my spare time I enjoy long distance #bicycling, #sailing, and doting on our #pets.I used to have an account on :birdsite:, however I haven't used it in a while and you should no longer assume that it's under my control.Trying not to be one of the 80% that can be moved in either direction.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          79443
          Member since
          23 Dec 2022
          Notices
          48
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP็ฎก็†ไบบ. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.