That one CVE you deprioritized because CVSS said 6.5? Turns out there's a public exploit and it's being actively used. What CVE burned you this year?
infosec
New, from me: The Kimwolf Botnet is Lurking in Corporate, Govt. Networks
A new Internet-of-Things botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf’s ability to scan the local networks of compromised systems for other IoT devices to infect makes it a sobering threat to organizations, and new research reveals Kimwolf is surprisingly prevalent in government and corporate networks.
https://krebsonsecurity.com/2026/01/kimwolf-botnet-lurking-in-corporate-govt-networks/
But they were almost recommending that people use the Google Authenticator app... 😶🌫️
🇧🇷🇵🇹 Os colegas implantaram TOTP como segundo fator de autenticação nas máquinas virtuais do centro de dados! 👏
Mas estavam quase recomendando que a galera usasse o aplicativo Google Authenticator... ⛈️
#InfoSec #TOTP #security #segurança #BigTech #cloud #nuvem
A startup is putting military-style drones in high school ceilings. Ceiling-mounted. Charging. Waiting. And when something happens, a pilot in Austin, Texas, decides whether to deploy pepper gel on your kid's school. I'm not saying the problem isn't real. It absolutely is. But read that back.... in schools. We've taken a Ukrainian battlefield tactic against Russian soldiers and ported it to Deltona High School in Florida. The co-founder literally said the idea came from watching drone videos of the war in Ukraine. The chief pilot described it as "cheating in a video game after you die." These are children.
Here's what's not in the headline:
🔒 The drones use an encrypted connection — but the article notes they're potentially vulnerable to cyberattack. A compromised drone in a crowded hallway isn't a security tool; it's a weapon pointed in the wrong direction.
⚖️ Mithril reserves the right to act independently during an attack, without waiting for law enforcement. A private company operating remotely is making use-of-force decisions at a school.
💰 Florida and Georgia approved $500K+ each for this. A group of Texas parents raised $200K more. That's real money going to ceiling drones instead of mental health services, counselors, or de-escalation programs.
The ACLU said it plainly: when force becomes a zero-risk remote action, it gets overused. Axon tried a Taser drone for schools in 2022, and its own ethics board killed it. Mithril is picking up where that got dropped.
I teach cybersecurity. I've spent years in boardrooms helping organizations think through risk. And the risk calculus here isn't just about whether the drone works. It's about what we're normalizing when we turn schools into drone-monitored combat zones and call it progress.
"This is the future," said the sheriff's captain.
I hope not.
#SchoolSafety #Cybersecurity #Leadership #security #privacy #cloud #infosec
New blog post!
This is the longest one in quite a while.
Last year, I held a presentation about the basics of Active Directory pentesting, focusing on "quick wins", easy to exploit vulnerabilities with huge impact.
I turned that presentation into a blog post.
The result is a surface-level overview of some of the most severe Active Directory vulnerabilities.
I hope it can be useful for aspiring pentesters and Active Directory admins alike.
https://ti-kallisti.com/general/ms/ad-basics.html
#redteam #pentesting #infosec #ActiveDirectory #sysadmin #Microsoft #Windows
In an effort to create and provide better articles on my blog, especially those related to cybersecurity and tech, I want to get your feedback on what type of articles y’all would like to see.
So, let me know below the types, series, etc. that I can write about.
Feel free to share to help spread across the #fediverse.
⋅ Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers
− https://cybersecuritynews.com/signal-confirms-targeted-phishing-attacks/
⋅ Scandale de babyphones vidéo : un chercheur français découvre plus d'un million d'appareils totalement exposés
New, from me: Who Operates the Badbox 2.0 Botnet?
The cybercriminals in control of Kimwolf -- a disruptive botnet that has infected more than 2 million devices -- recently shared a screenshot indicating they'd compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software that comes pre-installed on many Android TV streaming boxes. Both the FBI and Google say they are hunting for the people behind Badbox 2.0, and thanks to bragging by the Kimwolf botmasters we may now have a much clearer idea about that.
https://krebsonsecurity.com/2026/01/who-operates-the-badbox-2-0-botnet/
Back on my boring post grind to document my learning.
New #Blog post going through a #TryHackMe challenge. This time detecting two different attack types with snort!
https://ligniform.blog/posts/snort-live-attacks/
💜 🌱
If you appreciate the under reported #InfoSec & #DataPrivacy news articles I share every week, please support what I do by signing up for my newsletter. https://sherpaintelligence.substack.com
Starting today, February 1st, I am relaunching the newsletter with additional content and posts each weekday.
I am really proud of the content I provide. Subscribers make my work possible.
Please share with your network!
Sherpa Intelligence: Your Guide Up a Mountain of Information
Normalmente, é com WebGL que conseguem extrair dados infalíveis de identificação da sua máquina. No mínimo, deve ser essa a ideia, e o #Librewolf até consegue simular alguns dados para evitar a exposição, mas, assim, não dá pra confiar nesse site se já parte pra esse lado: como dizem mais ou menos assim (com eufemismo aqui), mal cumprimentou e já quer me levar pra cama? Nem os bancos que tenho usado são tão abusados! É :ciladaBino: !
#NoScript #Privacidade #InfoSec #Shopee
🚨 Beware! Hackers are now sending phishing emails from “no-reply@google.com” by abusing Google’s OAuth apps & notification system. These legit-looking emails can trick even tech-savvy users! 🕵️♂️ Always double-check links & sender details. Stay safe online! 🔐 #CyberSecurity #PhishingAlert #Google #InfoSec #StaySafe #TechRadar
https://github.com/macports/macports-ports/pull/32895
GitHub Continuous Integration checks passed OK!
It's up to someone else with commit access to merge it.
#ZMap #MacPorts #NetworkScanning #Security #infosec #OpenSource
THIS is how Google Maps wants to "calibrate"??
Oh HELL NO!
I'm giving you GPS and I can do the figure 8 sillyness if I need to but give you access to my *camera* to take pics and send them to Google???
Are people really doing this shit?!
AMERICAN PANOPTICON
The #Trump admin is pooling #data on Americans. Experts fear what comes next.
by Ian Bogost & Charlie Warzel
If you were tasked with building a #panopticon, your design might look a lot like the #information stores of the US federal govt—a collection of large, complex agencies, each making use of enormous volumes of data provided by or collected from #citizens.
#law #privacy #InfoSec #AmericanAutocracy #tech #DOGE #Musk #surveillance
https://www.theatlantic.com/technology/archive/2025/04/american-panopticon/682616/?gift=guxsrl_dAdXUP9zqbQPWxc3WqSyzCi3gasJ-au_BC9g&utm_source=copy-link&utm_medium=social&utm_campaign=share
It still seems hard to believe, but in the last #Congress, the #House #Republican majority formally launched an #impeachment inquiry against Joe #Biden. The endeavor never made any sense, but the underlying allegation was that the Democratic president was somehow the beneficiary of a weird #bribery scheme.
#law #Constitution #EmolumentsClause #ForeignAsset #Compromised #NationalSecurity #InfoSec #Trump #crypto #grift
https://www.msnbc.com/rachel-maddow-show/maddowblog/trumps-controversial-meme-coin-contest-proves-predictably-profitable-p-rcna203293
WRT #Discord, there's an effectively unsolvable conundrum we can't really face, folks. We'd all like the high moral standards that are found in the #OpenSource community, when done right: nobody screwing each other over for their PII, and other forms of leverage (walled-garden lock-in). Geeks get this, normies don't. (This gulf is very hard to cross, IMHO, without resorting to actual educational curriculum explaining it in schools.)
But then we have conflicting desires: we *also* want the buttery smoothness to a secure messaging ecosystem - total convenience, total functionality, *complete with a level-playing-field, "Net Neutral" infrastructure to run it on*, with no lobbied government or tech-bro interference skewing the traffic rules (QOS Rules). Good luck with that one, without strong gov't control, and solid grassroots lobbying behind it.
Lets be honest: #Signal is so great *because tens of millions of dollars were charitably spent on it*. Moxie didn't do his genius work *for free*. Where are tens of millions of *more* dollars going to come from, to make a Discord alternative? Would that be nowhere? Look, there's no quick and easy answers to Discord enshittifying. I've looked at #XMPP, #Matrix, #Deltachat, #Discourse, #Flarum, #PHPBB, #Zulip, #Mattermost, etc. and *each has its warts*. You'll dislike each of them, for different reasons. Each paints itself into a different corner. *There were no tens of millions of dollars upfront, at an early design phase, overlooked by qualified Computer Scientists, to prevent this, in each and every case.* #IRC doesn't bear mention in this comparison. None is the perfect replacement or answer. *None had those tens of millions of dollars which Signal had.*
Alas, they don't stand a chance to be the all-singing, all-dancing solutions that the techbros can finance, *along with their predictable, rotten lack of a moral compass to accompany the slickness.* Every non-geek teenager will side with the techbros, owing to 1) convenience, and 2) that's where their friends are, *which mean the world to a teenager*.
So in summary, we are doomed by our own psychological limitations, as a demographic. The psychological predators - the techbros - can't help but prey on the normies, and the normies can't help but turn to the predators, who at least offer convenience, if no other thing. And the geeks who have a moral compass stand in the middle, ignored by-and-large, feeling anxious and powerless, not having any tens of millions of dollars behind their altruism.
This has to be a #DOGE Easter Egg.
#IRS “improperly” [accidentally-on-purpose] disclosed #confidential #immigrant tax data to #DHS
The #tax agency only recently discovered the “mistake” & is working with other federal agencies on a response.
#law #privacy #immigration #InfoSec #Trump
https://www.washingtonpost.com/business/2026/02/11/immigrants-irs-dhs-tax-data/
#tech #dev #security #cybersecurity #InfoSec #Vercel #breach #OAuth #AI
#Whistleblower details how #DOGE may have taken sensitive #NLRB data
In the first days of March, a team of advisers from #Trump's new Department of Government Efficiency initiative arrived at the Southeast Washington, DC, headquarters of the National Labor Relations Board.
The small, independent federal agency investigates & adjudicates complaints about unfair #labor practices.
#law #InfoSec #privacy #NationalSecurity #Musk
https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security
Senior #State Department official sought internal communications with #journalists, #European officials, & Trump #critics
#Trump appointee Darren Beattie requested records regarding a large list of high-profile names, organizations, & #RightWing buzzwords for a “#TwitterFiles” style document dump about alleged conservative censorship.
#law #FirstAmendment #FreeSpeech #FreePress #privacy #InfoSec #democracy #RevengePolitics
https://www.technologyreview.com/2025/05/01/1115988/senior-state-department-official-sought-internal-communications-with-journalists-european-officials-and-trump-critics/
Have you ever tried to dictate someone a private IPv4 address in French 🇫🇷 ?
I'm now pretty certain that whoever said "Let's use 192.168... subnets for this" did that to annoy - or as a gigantic prank. And I salute you for it.
Hundred four twenty twelve, hundred sixty eight...
#infosec #sysadmin #itsupport #french
A centralized intelligence database on all Americans is not inherently legal.
It likely breaks the Privacy Act of 1974, the Foreign Intelligence Surveillance Act (FISA), the 1st, 4th and 5th Amendments.
This must be stopped. Contact your Senators and Representative and ask them to stop it. I use @5calls to call mine.
https://newrepublic.com/post/195904/trump-palantir-data-americans
The Russians aren't coming, they are already here. Without most anyone realizing, they've created an entire malicious adtech industry whose story is just as complex as the Chinese organized crime we're now realizing from their ventures into pig butchering.
VexTrio is just one Russian organized crime group in the malicious adtech world, but they are a critical one. They have a very "special" relationship with website hackers that defies logic. I'd put my money on a contractual one. all your bases belong to russian adtech hackers.
Today we've released the first piece of research that may eventually prove whether I am right. This paper is hard. i've been told. I know. We've condensed thousands of hours of research into about 30 pages. @briankrebs tried to make the main points a lot more consumable -- and wrote a fabulous complimentary article : read both!
There's so much more to say... but at the same time, between ourselves and Brian, we've released a lot of lead material ... and there's more to come. I've emphasized the Russian (technically Eastern European) crime here, but as Brian's article points out there is a whole Italian side too. and more.
We've given SURBL, Spamhaus, Cloudflare, Domain Tools, several registrars, and many security companies over 100k domains. They are also posted on our open github.
Super thanks to our collaborators at Qurium, GoDaddy Sucuri Security, and elsewhere.
#threatintel #scam #tds #vextrio #cybercrime #cybersecurity #infosec #dns #infoblox #InfobloxThreatIntel #malware #phishing #spam
https://krebsonsecurity.com/2025/06/inside-a-dark-adtech-empire-fed-by-fake-captchas/

🎸 🏳️🌈 ⁂
🐦🔥nemo™🐦⬛ 🇺🇦🍉