//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
ProfilePosts









Loading...
If you have a Fortinet firewall, it's time to stop and change your passwords. Intruders somehow gained access to around 75,000 Fortinet firewall devices and stole credentials belonging to major corporations across 194 countries, in some cases leading to full network compromise.
Thank you @jessicalyons.bsky.social & @theregister.com for letting me call ShinyHunters scumbags 😂
4d
1mo
"I'm concerned about what they are leaving behind: What type of C2 on a sleep cycle is still lingering in these environments?" TrendAI VP Tom Kellermann told me in an exclusive interview about the never-before-seen campaign.
Turns out Gemini makes a perfect hacking partner.
An npm-slop package “mouse5212-super-formatter” targeting Claude users and acting as a stealer reached 676 downloads before being removed from the registry - and after making a major vibe coding blunder.
Data theft and extortion group ShinyHunters exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the University of Nottingham, across 300 vulnerable instances, beginning in May.
The “jailbreak” that prompted the Trump administration to block Anthropic’s most advanced models was a three-word prompt: “Fix this code.” That's according to Luta Security CEO @k8em0.bsky.social - the only outside expert to read the research paper on the guardrail bypass that prompted the ban.
1mo
26d
24d
“At first, yes, this means more patches and thus more work for admins,” @dustinchilds.bsky.social told me. “The goal over time would be to eliminate as many as possible, and, over time, that monthly number goes down.”
"A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak gets," GitGuardian researcher Guillaume Valadon told me.
9d
5d
Nightmare Eclipse, the prolific bug hunter and possibly disgruntled ex-Microsoft employee, released another 0-day - this one is No. 7 - just hours after Microsoft's Patch Tuesday security updates. www.theregister.com/security/202...
Massive password-stealing attack hits 75k Fortinet firewalls
Jessica Lyons
Why are you even reading this?! Rotate your passwords!!
www.theregister.com
Allan “Ransomware Sommelier” Liska
1mo
1mo
10d
Jessica Lyons
Jessica Lyons
Jessica Lyons
Other than Instructure execs - maybe?
www.theregister.com
Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data
Jessica Lyons
Jessica Lyons
Jessica Lyons
Jessica Lyons
Jessica Lyons
Exclusive: Just in time for the Trump-Xi summit
Chinese spy group caught lurking in Poland, Asia networks
www.theregister.com
Script kiddies these days
www.theregister.com
Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token
University of Nottingham is first of many, Shiny tells The Reg
www.theregister.com
According to the one person who actually read the research paper
www.theregister.com
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher
Hey, Gemini, how much can we earn from one pump-and-dump cycle?
www.theregister.com
A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
www.theregister.com
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
Angry bug hunter with Microsoft beef drops new Windows 0-day
Revenge is a dish best served code
www.theregister.com
Palo Alto Networks found and fixed 75 flaws this month, up from its usual five
www.theregister.com
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits