Joshua Small
jsmall@infosec.exchange
Posts
-
View post
I've published some tools relevant to the recent Netscaler vulnerability. https://github.com/technion/netscaler_scanner/
-
View post
Time for a hill to die on: it makes no logical sense to say "two unknown cves in citrix". The whole definition of a cve is as a constant public identifier of a specific vulnerability. If you cannot give me a cve number there is no new cve - just an exploit with no published information. Its like saying there are two new words in the official English dictionary, but no dictionary is allowed to document them.
-
View post
I am staring down a so called security experts report from someone that has apparently never heard of TLS which I can summarise as "buy NordVPN or all your traffic can be intercepted". This sort of "I still think Firesheep works" type of expert needs more shaming.
-
View post
Microsoft's latest advisory has a bunch of slop related typos. Really the part that worries me is the take away from these sort of write ups is "Buy Nord VPN" or some stupid shit when Device Code phishing and Clickfix 100% do not care.
-
View post
Synergy Wholesale's SSL purchase form sure is something else.
-
View post
Are there any Ruby people with views on [CVE-2026-66066] ? The official release uses wording like "In a default configuration" but as far as I can see the exploit is down to using a specific method storing and user uploaded images and then doing something specific with them? Image manipulation has always been a huge attack surface, it's the sort of thing I always would have put in its own backend or container.
-
View post
Telstra Custdata logon (business DNS management) calling themselves "Multifactor" on an email magic link logon.
-
View post
One of the ways the security landscape has changed - which I haven't seen discussed - is that URL blocklists seem a lot easier for attackers to evade. I had a Clickfix incident three days ago. I used a https://app.any.run/ sandbox to replicate that loading the site, which was full of hidden online casino SEO spam, delivered a password stealer. Reported to Google Safebrowse, Fortigate, Palo Alto, Microsoft. Today the URL has absolutely 0 flags on Virustotal.
-
View post
What in hell is this Microsoft will the pilot group be included or exlcuded?
-
View post
The update to Microsoft's certification credentials is basically just a big removal of everything not AI related. For example, they've replaced "Microsoft Certified: Azure Security Engineer Associate" with "Microsoft Certified: Cloud and AI Security Engineer Associate (Exam SC-500)" and "Microsoft 365 Certified: Administrator Expert" with "Microsoft 365 Certified: AI Services Administrator Associate (Exam AB-650)". There's a whole bunch of st...
-
View post
@filippo@abyssdomain.expert We've seen this for a while with Powershell scripts but I'm amazed someone wrote a bash version.