Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Kevin Beaumont

@GossiTheDog@cyberplace.social
mastodon 4.7.3
  • Open on cyberplace.social

Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.

I have Direct Messages disabled - you can send them, but I will never receive them.

76763 Followers
790 Following
50 Posts
Joined November 22, 2022
My website:
https://doublepulsar.com
Github:
https://github.com/GossiTheDog
Signal:
GossiTheDog.1337
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1d ago
Guys predicting their own divorce
279
1
98
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 10h ago
Replying to
Preorder your Surface laptop even though we can’t spell our own product name
15
1
5
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 16h ago
Boosted by @trending@homestead.social
PC sales have fallen over 20% this quarter worldwide across all companies, declines prior quarter too, IDC expect costs to rise massively from here onwards and material impacts to PC sales into the future. https://www.idc.com/resource-center/press-releases/idc-pc-tracker-3q26/
idc.com
26
0
37
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 3d ago
Boosted by @gvenema@fairmove.net
RE: https://cyberplace.social/@GossiTheDog/117393814293721056 Fun one - over half of the CVEs added to CISA KEV are over a year old, ie issued a year or more ago. There’s this whole narrative around how GenAI will find zero day vulns and the apocalypse is coming. Slight issue - almost all incidents are caused by orgs not patching. Basically at all. The cybersecurity industry never solved that.. and doesn’t even understand it is the case.
Open quoted post
Quoting
Kevin Beaumont
@GossiTheDog@cyberplace.social
@christopherkunz@chaos.social I still run firmware fingerprint scanning across the internet and regularly find US federal agencies that are over a year behind with updates on CISA KEV
Open quoted post
110
7
111
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 4d ago
Boosted by @gvenema@fairmove.net
Israeli Finance Minister Bezalel Smotrich: “The thorough cleansing that we are carrying out now in southern Lebanon is unprecedented. They have nowhere to return to… the world isn’t stopping us.”
145
0
254
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1d ago
Boosted by @trending@homestead.social
I dunno if people remember the ransomware economy thread I had on Twitter years ago, but one of the things I covered is all the “ransomware recovery” vendors who secretly pay ransomware groups and pretend they magically decrypt the data. They’re middle men for crime basically. Anyway, one cybersecurity vendor (MonsterCloud) has finally had an arrest over it. Thread follows. https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/amp/
Ransomware recovery CEO charged over secret ransom payments
bleepingcomputer.com

Ransomware recovery CEO charged over secret ransom payments

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.

18
0
23
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Boosted by @kcarruthers@infosec.exchange
Replying to
148
0
77
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 4d ago
RE: https://fedi.computernewb.com/@vncresolver/117388191765651830 Space year 2026 Time to put your Windows 98 PC on the Internet, install VNC - nothing can go wrong.
Open quoted post
Quoting
VNC Resolver
@vncresolver@fedi.computernewb.com
IP/Port: 117.56.54.77:5900 Hostname: 117-56-54-77.hinet-ip.hinet.net Client Name: pcx ( 10.7.191.11 ) - service mode Location: Taipei, Taiwan, TW 🇹🇼 ASN: AS4782 Data Communication Business Group VNC Password: 1234 ID: 54721689 Added to DB: 05/08/2025, 05:36:51 AM (UTC) Last seen: 07/29/2026, 09:31:15 PM (UTC) https://computernewb.com/vncresolver/browse#id/54721689
Open quoted post
42
0
14
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Boosted by @trending@homestead.social
RE: https://mastodon.social/@zackwhittaker/117344795797870712 Once a year I publish a blog about how Citrix is very unserious when it comes to security but I think I might go apocalyptic this year. I don’t know if the story will come out about this one but governments etc have been hacked using this one, Citrix knew, and they just tried to hide it. Again.
192
0
159
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Boosted by @kcarruthers@infosec.exchange
RE: https://infosec.exchange/@BleepingComputer/117366111236940677 Big ransomware group ran by a *checks notes* 16 year old teen.
51
0
30
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Citrix patches are out on the main support site now. You will need to check every box after patching for webshells. Citrix are locking the script behind an NDA as apparently they’re from 1996… hopefully one of the NCSCs publishes a script again as the NDA thing is crap. To be clear patching alone doesn’t remove the backdoors being placed.
81
13
46
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this: https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771 You may notice it matches the hunting hints earlier in this thread. Guess who found it first :annoyingdog: It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.
Taking 'execute logging' a bit too literally - CVE-2026-88771
cert.europa.eu

Taking 'execute logging' a bit too literally - CVE-2026-88771

Taking 'execute logging' a bit too literally - CVE-2026-88771

66
4
43
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
If anybody wants a smile btw, a MS employee told me they believe this Mastodon thread and my blog cost them over a billion dollars. I think it’s firmly on Microsoft’s shoulders, the rollout of Recall and Copilot+ PC was just a series of own goals. They had huge expectations for it in terms of consumer demand and just.. didn’t think it through on many levels.
97
5
35
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Netscaler CVEs are out: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 Patch isn’t yet through QA at Citrix still, been a week :02angery: The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained. It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September. Probably nation state aligned as well resourced, espionage rather than teens.
support.citrix.com

Loading...

65
14
47
1
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
/tmp/not_a_good_sanitation Threat actor is correct #PitScaler
48
3
16
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
#PitScaler is under mass exploitation, seeing it spray and pray now. I’ve done some firmware version scanning, fewer than 10% of boxes are patched as of an hour ago.
39
0
17
1
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
RE: https://mastodon.social/@404mediaco/117344659806515505 The Onion became real life around 2016 didn’t it
Open quoted post
Quoting
404 Media
@404mediaco@mastodon.social
OpenAI has thousands and thousands of contractors helping improve the company's AI models. Multiple contractors have been fired for using AI to train the AI. https://www.404media.co/people-training-openais-ai-fired-for-using-ai-to-train-the-ai/
Open quoted post
47
1
28
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop. E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either. https://github.com/murrez/CVE-2026-88772
GitHub

GitHub - murrez/CVE-2026-88772: CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS probe. CTX697096; active exploitation reported. https://pocbit.

CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS probe. CTX697096; active exploitation...

35
4
10
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Police turned up at my door earlier and I was like, did I annoy people with the NSA toot.
28
1
7
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
And also buy a better product.
30
3
2
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1d ago
in 'who have I annoyed this week' LinkedIn intelligence
1
0
0
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
Microsoft has confirmed they’ve dropped the Copilot+ PC brand, after it flopped due to the botched launch of Microsoft Recall. https://www.windowscentral.com/microsoft/windows-11/the-copilot-pc-brand-is-dead-microsoft-and-pc-makers-quietly-pull-back-on-tarnished-windows-11-ai-pc-branding
Microsoft backs away from Copilot PC branding as OEMs abandon the label
Windows Central

Microsoft backs away from Copilot PC branding as OEMs abandon the label

In a new interview, Microsoft Surface CVP confirms that its new Surface PCs are no longer called Copilot+ PCs, but will still support all Copilot+ features.

42
7
30
2
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
RE: https://techhub.social/@Techmeme/117353706002267129 They know this language is C level exec porn. $$$$$$$$$
Open quoted post
Quoting
Techmeme
@Techmeme@techhub.social
Sources: Anthropic dedicated nearly a third of its IPO prospectus to detailing "risk factors", including that its AI may pose "existential risks to humanity" (Financial Times) https://www.ft.com/content/c7685a7e-7745-4cbc-8053-4958d0ea449b?accessToken=zwAAAaDr2OW6kdPHaFp-d0VMvNOAU0lY0OpEmw.MEUCIQDri8jri2FtGIfJjPkxOZ5_1_ZIU_6mV2XSWAkmAyHGCQIgNTptc_pqS1KKFIP7hi0m8Qv5D4KIbxvhaHO4CGCedXQ&segmentId=e95a9ae7-622c-6235-5f87-51e412b47e97&shareId=21e300e9-e2ac-440e-a832-3462c6e1ca1b&shareType=enterprise&syn-25a6b1a6=1 http://www.techmeme.com/260929/p7#a260929p7
Open quoted post
23
4
8
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Boosted by @MaryAustinBooks@mstdn.social
Pass the bong.
38
0
10
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 3d ago
Replying to on chaos.social
@christopherkunz@chaos.social I still run firmware fingerprint scanning across the internet and regularly find US federal agencies that are over a year behind with updates on CISA KEV
3
0
1
1
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Boosted by @trending@homestead.social
RE: https://neuromatch.social/@jonny/117352647701407496 Some wild stuff going on in these toots, apparently Meta’s position on AI security is
Open quoted post
Quoting
jonny (nonvenomous)
@jonny@neuromatch.social
RE: https://neuromatch.social/@jonny/117339825958098508 OK! Meta evaluated this as intended behavior, not applicable for a bug bounty, so therefore responsible disclosure no longer applies so here goes: any process run within the VM can access the socket that provides inference with no attribution mechanism. This includes raw inference  with arbitrary system and user prompts, as well as the ability to spawn agents with a toolset labeled as being for the "spaces" feature, which we will come back to. This amounts to a horizontally contagious token and information harvesting bug being labeled as intended behavior. Splitting details into new thread below
Open quoted post
20
0
31
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Me now that cybersecurity is fixed
29
0
6
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
On the Citrix Netscaler thing https://cyberplace.social/@GossiTheDog/117340102817280417
cyberplace.social

Kevin Beaumont: "@campuscodi@mastodon.social it’s not Citrix doing…" - Cyberplace

23
15
11
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
A few years ago @SwiftOnSecurity@infosec.exchange informed me about the Pregnant Clippy fanfic and this is equally cursed.
13
1
1
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
One of the NCSCs need to make a script for #PitScaler detection btw as the Citrix one is incomplete (it doesn’t check for suid on /bin/sh etc etc) and it’s locked behind support obscurity. Some really big orgs are backdoored after patching still.
14
1
4
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Don’t worry there’s also undisclosed FortiGate vulns too.
16
16
4
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off.
12
1
10
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
An interesting one is they’re saying Kiteworks MFT isn’t vulnerable - but it runs with Kiteworks Core, which is vulnerable. If anybody is interested Core is a closed box Linux system, so no third party agents. It is a bit confusing as they’re saying there’s no known vulnerability, but they’re still advising customers to switch off boxes tomorrow for 6 hours. Which is.. very strange. I guess we wait to see what, if anything, threat actor does.
12
1
1
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
Also - running the checks in the NetScaler console misses prior semi successful attempts as it relies on logs not being rotated on the box — and the activity is several weeks old now due to Citrix taking so long to disclose it. It should find the known webshells, but not RCE. The webshells are unique per box. The attackers also ran anti forensics commands - they set up crontab jobs to delete artefacts.
8
10
1
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
The script Citrix supply only really works for failed persistent attempts if logs aren’t rotated out. And given the activity started weeks ago, they have. If you have logs in a SIEM look for base64 strings after the User-Agent field (no space) and loglines for “pitboss” followed by the string IFS (so pitboss*IFS) or pitboss*b64decode.
8
12
6
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
9
1
1
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
@campuscodi@mastodon.social it’s not Citrix doing the notification, and they’re not saying to take offline. They haven’t actually told customers anything. It’s coming from gov circles. Vuln is real though, I checked.
7
1
3
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
CISA have added the Netscaler vulns to CISA KEV, US agencies have 3 days to do forensics on every device (a requirement). The forensics script is locked behind a fake NDA by the vendor for reasons unknown.
6
1
3
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
For the record - I’d shut down Kiteworks servers full stop temporarily, not for 6 hours on Saturday, until the situation becomes clear. Chances are that law enforcement is monitoring the extortion group and knows when they plan to smash and grab. Obviously, that timing is out the window now due to the public report - the threat actor will start to smash and grab now. Monitor the amount of outbound network traffic from Kitework boxes for very high volumes.
8
7
6
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
Some orgs have started taking their Kiteworks boxes offline
7
1
2
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
Shodan dork: http.favicon.hash:-1215318992 https://beta.shodan.io/search/facet?query=http.favicon.hash%3A-1215318992&facet=ssl.cert.subject.cn @shodan@mastodon.shodan.io
Shodan Facet Analysis
beta.shodan.io

Shodan Facet Analysis

2,614 results found for search query: http.favicon.hash:-1215318992

6
9
1
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
@wdormann@infosec.exchange I’d point you to the checker script but it makes you accept an NDA before you run it, lol
3
2
0
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 2w ago
Replying to
@tehfishman@ioc.exchange @snkhan@infosec.exchange @chronovore@infosec.exchange in theory.. but the messaging about “potential zero day” from them and law enforcement informing them suggests to me it’s actually law enforcement intercepting the threat actors comms.
0
1
0
0
Open post
Kevin Beaumont @GossiTheDog@cyberplace.social
· 1w ago
Replying to
For the record - I wasn’t in trouble with the law, a family member died. I didn’t realise police turning up to announce that was a real thing, I thought it was a movie thing. It was a bit of a confusing conversation as it basically went like: Them: hello Me: hello! Have I annoyed the NSA? Them: what? No. Can I come in? Me: should I get the orange jump suit for over tooting? Them: …what Me: did somebody die? Them: …can I come in?
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:44:43 UTC