Remote
Kevin Beaumont
@GossiTheDog@cyberplace.social
Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.
I have Direct Messages disabled - you can send them, but I will never receive them.
76763 Followers
790 Following
50 Posts
Joined November 22, 2022
Guys predicting their own divorce
Open post
Replying to
Preorder your Surface laptop even though we can’t spell our own product name
15
1
5
0
Open post
Boosted by @trending@homestead.social
PC sales have fallen over 20% this quarter worldwide across all companies, declines prior quarter too, IDC expect costs to rise massively from here onwards and material impacts to PC sales into the future.
https://www.idc.com/resource-center/press-releases/idc-pc-tracker-3q26/
26
0
37
0
Open post
Boosted by @gvenema@fairmove.net
RE: https://cyberplace.social/@GossiTheDog/117393814293721056
Fun one - over half of the CVEs added to CISA KEV are over a year old, ie issued a year or more ago.
There’s this whole narrative around how GenAI will find zero day vulns and the apocalypse is coming. Slight issue - almost all incidents are caused by orgs not patching. Basically at all.
The cybersecurity industry never solved that.. and doesn’t even understand it is the case.
Open quoted post
Quoting
@christopherkunz@chaos.social I still run firmware fingerprint scanning across the internet and regularly find US federal agencies that are over a year behind with updates on CISA KEV
Open quoted post 110
7
111
0
Open post
Boosted by @gvenema@fairmove.net
Israeli Finance Minister Bezalel Smotrich: “The thorough cleansing that we are carrying out now in southern Lebanon is unprecedented. They have nowhere to return to… the world isn’t stopping us.”
145
0
254
0
Open post
Boosted by @trending@homestead.social
I dunno if people remember the ransomware economy thread I had on Twitter years ago, but one of the things I covered is all the “ransomware recovery” vendors who secretly pay ransomware groups and pretend they magically decrypt the data. They’re middle men for crime basically.
Anyway, one cybersecurity vendor (MonsterCloud) has finally had an arrest over it. Thread follows.
https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/amp/
18
0
23
0
Open post
Open post
RE: https://fedi.computernewb.com/@vncresolver/117388191765651830
Space year 2026
Time to put your Windows 98 PC on the Internet, install VNC - nothing can go wrong.
Open quoted post
Open quoted post
Quoting
IP/Port: 117.56.54.77:5900
Hostname: 117-56-54-77.hinet-ip.hinet.net
Client Name: pcx ( 10.7.191.11 ) - service mode
Location: Taipei, Taiwan, TW 🇹🇼
ASN: AS4782 Data Communication Business Group
VNC Password: 1234
ID: 54721689
Added to DB: 05/08/2025, 05:36:51 AM (UTC)
Last seen: 07/29/2026, 09:31:15 PM (UTC)
https://computernewb.com/vncresolver/browse#id/54721689

42
0
14
0
Open post
Boosted by @trending@homestead.social
RE: https://mastodon.social/@zackwhittaker/117344795797870712
Once a year I publish a blog about how Citrix is very unserious when it comes to security but I think I might go apocalyptic this year.
I don’t know if the story will come out about this one but governments etc have been hacked using this one, Citrix knew, and they just tried to hide it. Again.
192
0
159
0
Open post
Boosted by @kcarruthers@infosec.exchange
RE: https://infosec.exchange/@BleepingComputer/117366111236940677
Big ransomware group ran by a *checks notes* 16 year old teen.
51
0
30
0
Open post
Replying to
Citrix patches are out on the main support site now.
You will need to check every box after patching for webshells. Citrix are locking the script behind an NDA as apparently they’re from 1996… hopefully one of the NCSCs publishes a script again as the NDA thing is crap.
To be clear patching alone doesn’t remove the backdoors being placed.
81
13
46
0
Open post
Replying to
Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this:
https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
You may notice it matches the hunting hints earlier in this thread. Guess who found it first
It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.
66
4
43
0
Open post
Replying to
If anybody wants a smile btw, a MS employee told me they believe this Mastodon thread and my blog cost them over a billion dollars.
I think it’s firmly on Microsoft’s shoulders, the rollout of Recall and Copilot+ PC was just a series of own goals. They had huge expectations for it in terms of consumer demand and just.. didn’t think it through on many levels.
97
5
35
0
Open post
Replying to
Netscaler CVEs are out:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Patch isn’t yet through QA at Citrix still, been a week
The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.
It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.
Probably nation state aligned as well resourced, espionage rather than teens.
65
14
47
1
Open post
Open post
Replying to
#PitScaler is under mass exploitation, seeing it spray and pray now.
I’ve done some firmware version scanning, fewer than 10% of boxes are patched as of an hour ago.
39
0
17
1
Open post
RE: https://mastodon.social/@404mediaco/117344659806515505
The Onion became real life around 2016 didn’t it
Open quoted post
Quoting
OpenAI has thousands and thousands of contractors helping improve the company's AI models. Multiple contractors have been fired for using AI to train the AI.
https://www.404media.co/people-training-openais-ai-fired-for-using-ai-to-train-the-ai/
Open quoted post 47
1
28
0
Open post
Replying to
There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop.
E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either.
https://github.com/murrez/CVE-2026-88772
35
4
10
0
Open post
Replying to
Police turned up at my door earlier and I was like, did I annoy people with the NSA toot.
28
1
7
0
Open post
Replying to
And also buy a better product.
30
3
2
0
Open post
in 'who have I annoyed this week' LinkedIn intelligence
1
0
0
0
Open post
Replying to
Microsoft has confirmed they’ve dropped the Copilot+ PC brand, after it flopped due to the botched launch of Microsoft Recall. https://www.windowscentral.com/microsoft/windows-11/the-copilot-pc-brand-is-dead-microsoft-and-pc-makers-quietly-pull-back-on-tarnished-windows-11-ai-pc-branding
42
7
30
2
Open post
RE: https://techhub.social/@Techmeme/117353706002267129
They know this language is C level exec porn. $$$$$$$$$
Open quoted post
Quoting
Sources: Anthropic dedicated nearly a third of its IPO prospectus to detailing "risk factors", including that its AI may pose "existential risks to humanity" (Financial Times)
https://www.ft.com/content/c7685a7e-7745-4cbc-8053-4958d0ea449b?accessToken=zwAAAaDr2OW6kdPHaFp-d0VMvNOAU0lY0OpEmw.MEUCIQDri8jri2FtGIfJjPkxOZ5_1_ZIU_6mV2XSWAkmAyHGCQIgNTptc_pqS1KKFIP7hi0m8Qv5D4KIbxvhaHO4CGCedXQ&segmentId=e95a9ae7-622c-6235-5f87-51e412b47e97&shareId=21e300e9-e2ac-440e-a832-3462c6e1ca1b&shareType=enterprise&syn-25a6b1a6=1
http://www.techmeme.com/260929/p7#a260929p7
Open quoted post 23
4
8
0
Open post
Open post
Replying to on chaos.social
@christopherkunz@chaos.social I still run firmware fingerprint scanning across the internet and regularly find US federal agencies that are over a year behind with updates on CISA KEV
3
0
1
1
Open post
Boosted by @trending@homestead.social
RE: https://neuromatch.social/@jonny/117352647701407496
Some wild stuff going on in these toots, apparently Meta’s position on AI security is
Open quoted post
Quoting
RE: https://neuromatch.social/@jonny/117339825958098508
OK! Meta evaluated this as intended behavior, not applicable for a bug bounty, so therefore responsible disclosure no longer applies so here goes:
any process run within the VM can access the socket that provides inference with no attribution mechanism. This includes raw inference with arbitrary system and user prompts, as well as the ability to spawn agents with a toolset labeled as being for the "spaces" feature, which we will come back to.
This amounts to a horizontally contagious token and information harvesting bug being labeled as intended behavior.
Splitting details into new thread below
Open quoted post 20
0
31
0
Open post
Replying to
Me now that cybersecurity is fixed
29
0
6
0
Open post
Replying to
On the Citrix Netscaler thing https://cyberplace.social/@GossiTheDog/117340102817280417
23
15
11
0
Open post
Replying to
A few years ago @SwiftOnSecurity@infosec.exchange informed me about the Pregnant Clippy fanfic and this is equally cursed.
13
1
1
0
Open post
Replying to
One of the NCSCs need to make a script for #PitScaler detection btw as the Citrix one is incomplete (it doesn’t check for suid on /bin/sh etc etc) and it’s locked behind support obscurity. Some really big orgs are backdoored after patching still.
14
1
4
0
Open post
Replying to
Don’t worry there’s also undisclosed FortiGate vulns too.
16
16
4
0
Open post
Replying to
The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off.
12
1
10
0
Open post
Replying to
An interesting one is they’re saying Kiteworks MFT isn’t vulnerable - but it runs with Kiteworks Core, which is vulnerable.
If anybody is interested Core is a closed box Linux system, so no third party agents.
It is a bit confusing as they’re saying there’s no known vulnerability, but they’re still advising customers to switch off boxes tomorrow for 6 hours. Which is.. very strange.
I guess we wait to see what, if anything, threat actor does.
12
1
1
0
Open post
Replying to
Also - running the checks in the NetScaler console misses prior semi successful attempts as it relies on logs not being rotated on the box — and the activity is several weeks old now due to Citrix taking so long to disclose it.
It should find the known webshells, but not RCE. The webshells are unique per box. The attackers also ran anti forensics commands - they set up crontab jobs to delete artefacts.
8
10
1
0
Open post
Replying to
The script Citrix supply only really works for failed persistent attempts if logs aren’t rotated out. And given the activity started weeks ago, they have.
If you have logs in a SIEM look for base64 strings after the User-Agent field (no space) and loglines for “pitboss” followed by the string IFS (so pitboss*IFS) or pitboss*b64decode.
8
12
6
0
Open post
Replying to
@campuscodi@mastodon.social it’s not Citrix doing the notification, and they’re not saying to take offline. They haven’t actually told customers anything. It’s coming from gov circles. Vuln is real though, I checked.
7
1
3
0
Open post
Replying to
CISA have added the Netscaler vulns to CISA KEV, US agencies have 3 days to do forensics on every device (a requirement). The forensics script is locked behind a fake NDA by the vendor for reasons unknown.
6
1
3
0
Open post
Replying to
For the record - I’d shut down Kiteworks servers full stop temporarily, not for 6 hours on Saturday, until the situation becomes clear.
Chances are that law enforcement is monitoring the extortion group and knows when they plan to smash and grab. Obviously, that timing is out the window now due to the public report - the threat actor will start to smash and grab now.
Monitor the amount of outbound network traffic from Kitework boxes for very high volumes.
8
7
6
0
Open post
Replying to
Some orgs have started taking their Kiteworks boxes offline
7
1
2
0
Open post
Replying to
Shodan dork: http.favicon.hash:-1215318992
https://beta.shodan.io/search/facet?query=http.favicon.hash%3A-1215318992&facet=ssl.cert.subject.cn @shodan@mastodon.shodan.io
6
9
1
0
Open post
Replying to
@wdormann@infosec.exchange I’d point you to the checker script but it makes you accept an NDA before you run it, lol
3
2
0
0
Open post
Replying to
@tehfishman@ioc.exchange @snkhan@infosec.exchange @chronovore@infosec.exchange in theory.. but the messaging about “potential zero day” from them and law enforcement informing them suggests to me it’s actually law enforcement intercepting the threat actors comms.
0
1
0
0
Open post
Replying to
For the record - I wasn’t in trouble with the law, a family member died. I didn’t realise police turning up to announce that was a real thing, I thought it was a movie thing.
It was a bit of a confusing conversation as it basically went like:
Them: hello
Me: hello! Have I annoyed the NSA?
Them: what? No. Can I come in?
Me: should I get the orange jump suit for over tooting?
Them: …what
Me: did somebody die?
Them: …can I come in?
0
1
0
0


