Elektrine lite

← Feed

:CrowHeartRainbow:

cR0w@infosec.exchange

<p>Analyst</p>

Posts

  • View post

    :brdScream2: :oh_no_bubble:

  • View post

    Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳 https://www.cve.org/CVERecord?id=CVE-2026-92931 sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

  • View post

    Still my favorite coin. #teamOrca

  • View post

    More old vulns finally getting CVEs but a couple perfect 10s in a tool to allow AI agents to make trades on your behalf is just too... expected. Vibe-Trading is an open-source research workspace for turning finance questions into runnable analysis. It connects natural-language prompts to market-data loaders, strategy generation, backtest engines, reports, exports, and persistent research memory. It is designed for research, simulation, and backtesting — and, when you choose, autonomous trading...

  • View post

    RE: https://mastodon.social/@campuscodi/117377454167316988 Gonna be fun when Ivanti and Citrix and Palo and Fortinet and Cisco and F5 all keep their gov contacts because they&#39;re &quot;PQC Ready&quot; but keep getting popped by URI encoding and BoFs from 20 years ago, not to mention all the TAGs they can&#39;t be bothered to boot from their own networks, making that PQC essentially pointless against the majority of threats.

  • View post

    RE: https://flipboard.com/@theseattletimes/tech-news-goc90q5pz/-/a-pHHWW4X9TSm3q4Mxb_c9HA%3Aa%3A2857557016-%2F0 Fuck that guy.

  • View post

    Go hack some AI SOC shit. https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7 Three functions in services/actions build CrowdStrike Real-Time Response (RTR) command strings by string interpolation, with no escaping, from caller-supplied parameters. The resulting command string is sent to the CrowdStrike Falcon agent and executed on the target endpoint as the EDR agent&#39;s privilege (SYSTEM/root).

  • View post

    RE: https://mastodon.bsd.cafe/@stefano/117354014226641780 Sure glad I moved my main workstation to Debian. :brdAngry: CVE-2024-5256 CVE-2024-5809 CVE-2025-2181 CVE-2025-2210 CVE-2025-2212 CVE-2025-3820 CVE-2025-3823 CVE-2025-3862 CVE-2025-3983 CVE-2025-3992 CVE-2025-4006 CVE-2025-4010 CVE-2025-4013 CVE-2025-4016 CVE-2026-10007 CVE-2026-100079 CVE-2026-2313 CVE-2026-4319 CVE-2026-4334 CVE-2026-4596 CVE-2026-5294 CVE-2026-5301 CVE-2026-5308 CVE-2026-5310 CVE-2026-5311 CVE-2026-5325 CVE-2026-533...

  • View post

    @Viss@mastodon.social @ai6yr@m.ai6yr.org @kajer@infosec.exchange I expect this one is just another bad Cyber Security something something acronym but I still noped out as soon as I had the screenshot.

  • View post

    Oh fuck that job.

  • View post

    sev:CRITs in Dayforce Payroll. Go patch and protect that shit before your pay gets fucked. https://cert.pl/en/posts/2026/09/CVE-2026-73640/

  • View post

    Reminder: It&#39;s a good idea to limit ingress to your routers&#39; BGP service to your known peers. Please don&#39;t leave it open to the whole Internet.

  • View post

    Patch your fruity phones, there&#39;s another EITW 0day. https://support.apple.com/en-us/149226 Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

  • View post

    I don&#39;t know how many of you have public call centers, but you might want to figure out how to deal with AI agents &quot;calling on behalf of&quot; human employees or customers or similar. I&#39;ve seen it a ton lately and it&#39;s creepy as Hell. They&#39;re aggressive and weird ( negative ).

  • View post

    RE: https://infosec.exchange/@ajn142/117349300525417657 When the puppygirl polycule finds a new top.

  • View post

    Of all the bullshit I expected from the current US regime, going from cops threatening dogs with their 9mm to cops threatening dogs with their 9cm was not on that list.

  • View post

    bong rip hold hold ... hold exhale Fuck a non profit GAYINT should be a church.

  • View post

    Yet another sign I need to log off for a while: My truck rolled from 11111 to 11112 miles and I was temporarily confused why it wasn&#39;t 100000.

  • View post

    @hrbrmstr@mastodon.social At least I&#39;m not digging into 0day and making people work over the weekend. 😅

  • View post

    ANNOUNCING The CrowdStrike Cyber Superintelligence Lab

  • View post

    RE: https://cyberplace.social/@GossiTheDog/117343821114841048 I&#39;m not under NDA and don&#39;t use Citrix so if anyone wants to send it to me, I&#39;m more than happy to post it for you. Without naming the source, obviously.

  • View post

    You nerds are all right. :heart_pride:

  • View post

    RE: https://infosec.exchange/@cR0w/117309634264998866 Hire me and it&#39;s a 2-for-1 deal. I come with my own accountabillabuddy.

  • View post

    It&#39;s 08:00 on Monday and my work buddy has had enough. Same, TBH. #dogsOfMastodon

  • View post

    It&#39;s been a while since I had to get a new job. Am I supposed to send the dog pic bribes with the resume or how does that work these days?

  • View post

    @elebertus@eigenmagic.net That&#39;s kind of what I figured based on the struggles everyone else is having to find jobs.

  • View post

    Hey, so, anyone out there looking to hire a remote nerd? I&#39;ve spent the past 4-5 years doing threat hunting, detection engineering, threat intel, and incident response for large US West utilities. Gotta be full WFH though due to health reasons. Non-LinkedIn, non-ghost job links appreciated. Edit to add that I did a bit of vuln management too. That&#39;s something that I think you can ask fellow fedi friends about since I was sharing so much of it here for a while. #getFediHired

  • View post

  • View post

    RE: https://infosec.exchange/@kajer/117322455423025585 hashtag threat intel

  • View post

    RE: https://infosec.exchange/@nyanbinary/117322397007013550 LET US BLOCK BY ASN YOU FUCKING COWARDS