//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
ProfilePosts









Loading...
If you have a Fortinet firewall, it's time to stop and change your passwords. Intruders somehow gained access to around 75,000 Fortinet firewall devices and stole credentials belonging to major corporations across 194 countries, in some cases leading to full network compromise.
The “jailbreak” that prompted the Trump administration to block Anthropic’s most advanced models was a three-word prompt: “Fix this code.” That's according to Luta Security CEO @k8em0.bsky.social - the only outside expert to read the research paper on the guardrail bypass that prompted the ban.
Data theft and extortion group ShinyHunters exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the University of Nottingham, across 300 vulnerable instances, beginning in May.
An npm-slop package “mouse5212-super-formatter” targeting Claude users and acting as a stealer reached 676 downloads before being removed from the registry - and after making a major vibe coding blunder.
"A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak gets," GitGuardian researcher Guillaume Valadon told me.
Thank you @jessicalyons.bsky.social & @theregister.com for letting me call ShinyHunters scumbags 😂
“At first, yes, this means more patches and thus more work for admins,” @dustinchilds.bsky.social told me. “The goal over time would be to eliminate as many as possible, and, over time, that monthly number goes down.”
4d
6d
10d
25d
1mo
1mo
1mo
Why are you even reading this?! Rotate your passwords!!
www.theregister.com
Massive password-stealing attack hits 75k Fortinet firewalls
According to the one person who actually read the research paper
www.theregister.com
University of Nottingham is first of many, Shiny tells The Reg
www.theregister.com
Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token
Script kiddies these days
www.theregister.com
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
www.theregister.com
Other than Instructure execs - maybe?
www.theregister.com
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data
Palo Alto Networks found and fixed 75 flaws this month, up from its usual five
www.theregister.com
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Nightmare Eclipse, the prolific bug hunter and possibly disgruntled ex-Microsoft employee, released another 0-day - this one is No. 7 - just hours after Microsoft's Patch Tuesday security updates. www.theregister.com/security/202...
Jessica Lyons
Jessica Lyons
Jessica Lyons
Jessica Lyons
Jessica Lyons
Allan “Ransomware Sommelier” Liska
Jessica Lyons
11d
Angry bug hunter with Microsoft beef drops new Windows 0-day
Revenge is a dish best served code
www.theregister.com
Jessica Lyons
"I'm concerned about what they are leaving behind: What type of C2 on a sleep cycle is still lingering in these environments?" TrendAI VP Tom Kellermann told me in an exclusive interview about the never-before-seen campaign.
1mo
Exclusive: Just in time for the Trump-Xi summit
www.theregister.com
Chinese spy group caught lurking in Poland, Asia networks
Jessica Lyons
Turns out Gemini makes a perfect hacking partner.
26d
Hey, Gemini, how much can we earn from one pump-and-dump cycle?
www.theregister.com
A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets
Jessica Lyons