Kevin Beaumont
GossiTheDog@cyberplace.social
<p>Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.</p><p>I have Direct Messages disabled - you can send them, but I will never receive them.</p>
Posts
-
View post
A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing. They paid him $5000 and told nobody about it. https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
-
View post
no
-
View post
PC sales have fallen over 20% this quarter worldwide across all companies, declines prior quarter too, IDC expect costs to rise massively from here onwards and material impacts to PC sales into the future. https://www.idc.com/resource-center/press-releases/idc-pc-tracker-3q26/
-
View post
Guys predicting their own divorce
-
View post
in 'who have I annoyed this week' LinkedIn intelligence
-
View post
I dunno if people remember the ransomware economy thread I had on Twitter years ago, but one of the things I covered is all the “ransomware recovery” vendors who secretly pay ransomware groups and pretend they magically decrypt the data. They’re middle men for crime basically. Anyway, one cybersecurity vendor (MonsterCloud) has finally had an arrest over it. Thread follows. https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/amp/
-
View post
RE: https://cyberplace.social/@GossiTheDog/117393814293721056 Fun one - over half of the CVEs added to CISA KEV are over a year old, ie issued a year or more ago. There’s this whole narrative around how GenAI will find zero day vulns and the apocalypse is coming. Slight issue - almost all incidents are caused by orgs not patching. Basically at all. The cybersecurity industry never solved that.. and doesn’t even understand it is the case.
-
View post
Israeli Finance Minister Bezalel Smotrich: “The thorough cleansing that we are carrying out now in southern Lebanon is unprecedented. They have nowhere to return to… the world isn’t stopping us.”
-
View post
RE: https://fedi.computernewb.com/@vncresolver/117388191765651830 Space year 2026 Time to put your Windows 98 PC on the Internet, install VNC - nothing can go wrong.
-
View post
Well done to Microsoft for having two different mobile apps called Copilot which do different things.
-
View post
RE: https://infosec.exchange/@BleepingComputer/117366111236940677 Big ransomware group ran by a *checks notes* 16 year old teen.
-
View post
RE: https://circumstances.run/@davidgerard/117356555017512210 Congrats on inventing Drunk Clippy.
-
View post
RE: https://techhub.social/@Techmeme/117353706002267129 They know this language is C level exec porn. $$$$$$$$$
-
View post
NSA you might want to do forensics on 103.41.70.207,vdicorp.nsa.gov
-
View post
RE: https://neuromatch.social/@jonny/117352647701407496 Some wild stuff going on in these toots, apparently Meta’s position on AI security is
-
View post
RE: https://mastodon.social/@zackwhittaker/117344795797870712 Once a year I publish a blog about how Citrix is very unserious when it comes to security but I think I might go apocalyptic this year. I don’t know if the story will come out about this one but governments etc have been hacked using this one, Citrix knew, and they just tried to hide it. Again.
-
View post
RE: https://mastodon.social/@404mediaco/117344659806515505 The Onion became real life around 2016 didn’t it
-
View post
There are rumours swirling for the past week behind the scenes that there are two actively exploited zero days in Citrix Netscaler. The rumours have now broken containment to Reddit. FWIW I’ve been trying to get Citrix to talk about it, they won’t.
-
View post
Great news everybody, cyber folks can retire to McDonalds now because a guy who has one job as a data inputter has discovered a GitHub list of AI slop tools. Cyber is solved!
-
View post
Signal have rolled out an update to all users that stops Microsoft Recall from capturing Signal conversations. I’ve tested this and it works. Brilliant work by the @signalapp@mastodon.world team. 💪 They call on Microsoft to build better, as there was no standardised way as an app developer to do this. Because Signal is open source, now app developers have a template to protect their users from Windows. https://signal.org/blog/signal-doesnt-recall/
-
View post
Pass the bong.
-
View post
If you use KiteWorks I suggest you temporarily remove internet access now. https://www.heise.de/en/news/Imminent-Zero-Day-Attack-KiteWorks-Urges-Customers-to-Shut-Down-Servers-11466375.html
-
View post
BBC News has 4 YouTube videos up in the past day about OpenAI hacking “governments”, with approaching a million views. If you want to know the technical details of this elite frontier AI hacking - these are examples of the actual OpenAI agent requests. It’s really dumb shit. The story here is OpenAI are utterly incompetent at cybersecurity, as are their victims.
-
View post
Running a Mastodon server is becoming increasingly problematic due to GenAI. There’s multiple different things happening, including but not limited to: - very aggressive scraping of user content and block evasion, with the resource costs that come with it - AI agents aggressively trying to register accounts and evade restrictions - rising cost of RAM - Mastodon is memory hungry, RAM is really expensive now It’s odd to experience first hand, it’s like being consumed by.. a void.
-
View post
Elsevier got hacked and their website replaced with a LAPSUS$ ransomware group portal.
-
View post
Spotted a threat actor doing this. If you use GitHub Free, you can spin up Windows desktops with up to 32 core CPUs and 1.2tb of bandwidth using GitHub Code Spaces. Connect using RDP. There’s no card payment details needed and no know your customer checks. https://github.com/ItzLevvie/dind
-
View post
This will go well.
-
View post
Ed Sheeran saying he won’t speak out about a genocide because there are children in the audience is a choice, and not a very good one. https://www.bbc.co.uk/news/articles/c3vgyn49y4l7o
-
View post
If you use MoveIT Transfer I recommend upgrading to 2025.1.6 or 2026.0.4 ASAP. They don’t appear to have issued any CVEs or advisories but I can see they’ve patched some serious security issues.
-
View post
Me and Ciaran have had enough of the frontier AI fear uncertainty and doubt, I think it’s safe to say.