Peter Girnus's Avatar

Peter Girnus

@gothburz.bsky.social

Sr. Threat Researcher @theZDI πŸ₯·πŸ»πŸ›‘οΈπŸ‘¨πŸΌβ€πŸ’»Hunts for 0-days and #security threats in the wild 🎯 News πŸ“° Memes 😏 Books πŸ“š Games πŸ‘Ύ opinions my own πŸ’­ #infosec

78 Followers  |  1 Following  |  728 Posts  |  Joined: 15.11.2024  |  1.5202

Latest posts by gothburz.bsky.social on Bluesky

Post image

Justi autem in perpetuum vivent et apud Dominum est merces eorum β€” Wisdom 5:16

04.06.2025 02:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image 26.05.2025 18:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image 03.05.2025 16:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

"It is evening in the soul... when the light of this world fades and a man is indrawn and rests" β€” Meister Eckhart, Sermon 38

19.04.2025 17:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🚨Patch up your Kubernetes installs.

⚠️ Affected @kubernetesio versions:
< v1.11.0
v1.11.0 - 1.11.4
v1.12.0

🦠Vulnerabilities 
CVE-2025-1974
CVE-2025-1097Β 
CVE-2025-1098Β 
CVE-2025-24514
CVE-2025-24513

25.03.2025 16:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Rare urgent advisory from @Meta 🚨⚠️ CVE-2025-27363: FreeType flaw risks millions. Remote code execution possible on major platforms. Patch urged as exploitation rises. Severity: 8.2/10. Affects versions pre-2.13.3. Update now! 

13.03.2025 13:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

RIP $TSLA... πŸ’₯πŸš—πŸ“‰

10.03.2025 21:05 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Snack Makers Are Removing Fake Colors From Processed Foods - Slashdot "PepsiCo is launching a new product, Simply Ruffles Hot &amp; Spicy, which uses natural ingredients like tomato powder and red chile pepper instead of artificial dyes," reports Bloomberg. But it's part of a larger trend: In one of the final acts of President Joe Biden's administration, the U.S. Fo...
09.03.2025 00:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Snack makers are shifting away from artificial colors in processed foods. PepsiCo's new Simply Ruffles product uses natural ingredients like tomato powder. This change aligns with a trend following the FDA's ban on Red No. 3 due to health concerns.

09.03.2025 00:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
iPhone 16e review: The most expensive cheap iPhone yet The iPhone 16e rethinksβ€”and prices upβ€”the basic iPhone.
08.03.2025 02:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The iPhone 16e: the priciest budget phone! πŸ’Έ It boasts a solid display, performance, and battery life but ditches fun features like MagSafe and Dynamic Island. πŸ–οΈ Apple’s strategy? Hike prices while streamlining production. Great for profitsπŸ“±πŸ˜¬ @arstechnica

08.03.2025 02:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Medusa Ransomware Claims 40+ Victims in 2025 Symantec found that Medusa has listed almost 400 victims on its data leaks site since early 2023, demanding ransom payments as high as $15m

🚨Medusa #ransomware claims 40+ victims in 2025, including a US healthcare org hit in Jan. @Symantec reports nearly 400 victims since 2023, with ransom demands up to $15M. True victim count likely higher. From @InfosecurityMag πŸ‘‰

07.03.2025 11:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Ransomware gang encrypted network from a webcam to bypass EDR The Akira ransomware gang was spotted using an unsecured webcam to launch encryption attacks on aΒ victim's network, effectively circumventing Endpoint Detection and Response (EDR), which was blocking the encryptor in Windows.
07.03.2025 10:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

🚨Akira ransomware gang used an unsecured webcam to deploy a Linux encryptor, bypassing EDR and encrypting network shares via SMB 🀯. Highlights need for broader device monitoring beyond Windows endpoints. From @BleepinComputer

07.03.2025 10:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Ethereum private key stealer on PyPI downloaded over 1,000 times A malicious Python Package Index (PyPI)Β  package named "set-utils" has been stealing Ethereum private keys through intercepted wallet creation functions and exfiltrating them via the Polygon blockchain.

🚨@BleepinComputer: @Ethereum key stealer hits PyPI as "set-utils", downloaded 1K+ times! @billtoulas
Β warns blockchain devs to stay vigilant. #crypto

06.03.2025 23:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Ransomware gang encrypted network from a webcam to bypass EDR The Akira ransomware gang was spotted using an unsecured webcam to launch encryption attacks on aΒ victim's network, effectively circumventing Endpoint Detection and Response (EDR), which was blocking the encryptor in Windows.
06.03.2025 23:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

🚨 Akira ransomware exploited an unsecured webcam (yes this is an initial security vector and one reason why #Pwn2Own has IoT cameras as a target category) to encrypt a network, bypassing EDR. @BleepinComputer reports rapid attack from initial access to encryption in hours. 🀯 #Ransomware

06.03.2025 23:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Microsoft says malvertising campaign impacted 1 million PCs ​Microsoft has taken down an undisclosed number of GitHub repositories used in a massive malvertising campaign that impacted almost one million devices worldwide.

@Microsoft takes down massive malvertising campaign hit ~1M PCs via GitHub repos. Malware stole system data & dropped payloads. Tracked as Storm-0408.πŸ’½πŸ›‘οΈ via @BleepingComputer

06.03.2025 22:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Jenkins Security Advisory 2025-03-05 Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software

@jenkinsci releases Jenkins Security Advisory 2025-03-05

06.03.2025 20:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

🩹SMR-MAR-2025: @SamsungMobile releases patches for flagship model phones πŸ“± make sure to apply the latest patch in order to secure your @Samsung devices.

https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03

06.03.2025 18:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks Over 37,000 internet-exposed VMware ESXi instances are vulnerable to CVE-2025-22224, a critical out-of-bounds write flaw that is actively exploited in the wild.
06.03.2025 17:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Over 37,000 VMware ESXi servers are vulnerable to a critical flaw (CVE-2025-22224) that is being actively exploited, prompting urgent updates and mitigation efforts from affected organizations. From @BleepinComputer @billtoulas

06.03.2025 17:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Attackers Targeting Japanese Firms with Cobalt Strike Attackers are actively exploiting an RCE flaw in Windows PHP-CGI implementations to target Japanese firms, deploying Cobalt Strike for persistence
06.03.2025 17:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

A sophisticated cyber-intrusion campaign πŸ₯· has been reported, targeting various Japanese sectors πŸ‡―πŸ‡΅πŸŽ― by exploiting a remote code execution flaw to gain access, deploying Cobalt Strike 🦠for persistent control, while engaging in credential theft and lateral movement

06.03.2025 17:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

🚨@BleepinComputer: BadBox malware 🦠 disrupted on 500K Android devices! @billtoulas reports.

05.03.2025 17:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Exclusive: Nvidia and Broadcom testing chips on Intel manufacturing process, sources say Chip designers Nvidia and Broadcom are running manufacturing tests with Intel , two sources familiar with the matter told Reuters, demonstrating early confidence in the struggling company's advanced production techniques.

πŸ”¬πŸš€@NVIDIA & @Broadcom are testing chips with @Intel's 18A process, showing confidence in Intel's manufacturing comeback. Details from @Reuters πŸ‘‰

04.03.2025 20:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

So many security advisories going out! 🀯 Including VMWare, HUAWEI, Paragon, and Mozilla. Here is what the vulnerability landscape looks like. Lots of Injection and Memory Corruption issues across all of these advisories.

04.03.2025 18:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Microsoft unveils finalized EU Data Boundary Some may have second thoughts about going all-in with an American vendor, no matter where their data is stored

Microsoft finalizes EU Data Boundary, keeping EU customer data local per regulations. Some still wary of US vendor ties. @TheRegister reports. πŸ”’πŸ‡ͺπŸ‡Ί

03.03.2025 22:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Polish space agency confirms cyberattack Officials vow to uncover who was behind it

Polish Space Agency (@POLSA_GOV_PL) hit by cyberattack, systems secured. Officials probe culprits amid tensions with Moscow. @TheRegister reports. πŸš€πŸ”’

03.03.2025 19:02 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Post image

Hackers exploit ClickFix to deploy NetSupport RAT via fake CAPTCHAs, tricking users into running malicious PowerShell. @TheHackersNews πŸ€πŸš¨πŸ’» https://thehackernews.com/2025/03/hackers-use-clickfix-trick-to-deploy.html

03.03.2025 18:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@gothburz is following 1 prominent accounts