:CrowHeartRainbow:
cR0w@infosec.exchange
<p>Analyst</p>
Posts
-
View post
:brdScream2: :oh_no_bubble:
-
View post
Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳 https://www.cve.org/CVERecord?id=CVE-2026-92931 sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
-
View post
Still my favorite coin. #teamOrca
-
View post
More old vulns finally getting CVEs but a couple perfect 10s in a tool to allow AI agents to make trades on your behalf is just too... expected. Vibe-Trading is an open-source research workspace for turning finance questions into runnable analysis. It connects natural-language prompts to market-data loaders, strategy generation, backtest engines, reports, exports, and persistent research memory. It is designed for research, simulation, and backtesting — and, when you choose, autonomous trading...
-
View post
RE: https://mastodon.social/@campuscodi/117377454167316988 Gonna be fun when Ivanti and Citrix and Palo and Fortinet and Cisco and F5 all keep their gov contacts because they're "PQC Ready" but keep getting popped by URI encoding and BoFs from 20 years ago, not to mention all the TAGs they can't be bothered to boot from their own networks, making that PQC essentially pointless against the majority of threats.
-
View post
RE: https://flipboard.com/@theseattletimes/tech-news-goc90q5pz/-/a-pHHWW4X9TSm3q4Mxb_c9HA%3Aa%3A2857557016-%2F0 Fuck that guy.
-
View post
Go hack some AI SOC shit. https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7 Three functions in services/actions build CrowdStrike Real-Time Response (RTR) command strings by string interpolation, with no escaping, from caller-supplied parameters. The resulting command string is sent to the CrowdStrike Falcon agent and executed on the target endpoint as the EDR agent's privilege (SYSTEM/root).
-
View post
RE: https://mastodon.bsd.cafe/@stefano/117354014226641780 Sure glad I moved my main workstation to Debian. :brdAngry: CVE-2024-5256 CVE-2024-5809 CVE-2025-2181 CVE-2025-2210 CVE-2025-2212 CVE-2025-3820 CVE-2025-3823 CVE-2025-3862 CVE-2025-3983 CVE-2025-3992 CVE-2025-4006 CVE-2025-4010 CVE-2025-4013 CVE-2025-4016 CVE-2026-10007 CVE-2026-100079 CVE-2026-2313 CVE-2026-4319 CVE-2026-4334 CVE-2026-4596 CVE-2026-5294 CVE-2026-5301 CVE-2026-5308 CVE-2026-5310 CVE-2026-5311 CVE-2026-5325 CVE-2026-533...
-
View post
@Viss@mastodon.social @ai6yr@m.ai6yr.org @kajer@infosec.exchange I expect this one is just another bad Cyber Security something something acronym but I still noped out as soon as I had the screenshot.
-
View post
Oh fuck that job.
-
View post
sev:CRITs in Dayforce Payroll. Go patch and protect that shit before your pay gets fucked. https://cert.pl/en/posts/2026/09/CVE-2026-73640/
-
View post
Reminder: It's a good idea to limit ingress to your routers' BGP service to your known peers. Please don't leave it open to the whole Internet.
-
View post
Patch your fruity phones, there's another EITW 0day. https://support.apple.com/en-us/149226 Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
-
View post
I don't know how many of you have public call centers, but you might want to figure out how to deal with AI agents "calling on behalf of" human employees or customers or similar. I've seen it a ton lately and it's creepy as Hell. They're aggressive and weird ( negative ).
-
View post
RE: https://infosec.exchange/@ajn142/117349300525417657 When the puppygirl polycule finds a new top.
-
View post
Of all the bullshit I expected from the current US regime, going from cops threatening dogs with their 9mm to cops threatening dogs with their 9cm was not on that list.
-
View post
bong rip hold hold ... hold exhale Fuck a non profit GAYINT should be a church.
-
View post
Yet another sign I need to log off for a while: My truck rolled from 11111 to 11112 miles and I was temporarily confused why it wasn't 100000.
-
View post
@hrbrmstr@mastodon.social At least I'm not digging into 0day and making people work over the weekend. 😅
-
View post
ANNOUNCING The CrowdStrike Cyber Superintelligence Lab
-
View post
RE: https://cyberplace.social/@GossiTheDog/117343821114841048 I'm not under NDA and don't use Citrix so if anyone wants to send it to me, I'm more than happy to post it for you. Without naming the source, obviously.
-
View post
You nerds are all right. :heart_pride:
-
View post
RE: https://infosec.exchange/@cR0w/117309634264998866 Hire me and it's a 2-for-1 deal. I come with my own accountabillabuddy.
-
View post
It's 08:00 on Monday and my work buddy has had enough. Same, TBH. #dogsOfMastodon
-
View post
It's been a while since I had to get a new job. Am I supposed to send the dog pic bribes with the resume or how does that work these days?
-
View post
@elebertus@eigenmagic.net That's kind of what I figured based on the struggles everyone else is having to find jobs.
-
View post
Hey, so, anyone out there looking to hire a remote nerd? I've spent the past 4-5 years doing threat hunting, detection engineering, threat intel, and incident response for large US West utilities. Gotta be full WFH though due to health reasons. Non-LinkedIn, non-ghost job links appreciated. Edit to add that I did a bit of vuln management too. That's something that I think you can ask fellow fedi friends about since I was sharing so much of it here for a while. #getFediHired
- View post
-
View post
RE: https://infosec.exchange/@kajer/117322455423025585 hashtag threat intel
-
View post
RE: https://infosec.exchange/@nyanbinary/117322397007013550 LET US BLOCK BY ASN YOU FUCKING COWARDS