Exciting! MLS e2ee messaging with fingerprints in Bluesky bios (to prevent silent bindings) and pre-keys in PDS.
Kinda wish the key was published in the DID document though, especially if one day plc.directory will become a tlog. (Basically free KT!)
www.germnetwork.com/blog/integra...
28.07.2025 18:09 β π 58 π 21 π¬ 6 π 1
Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years
βAll of the knowledge to generate the exploit already exists on the internet. AI could even build it for you,β the researcher told 404 Media.
New from 404 Media: we spoke to the researcher who found hackers can remotely trigger brakes on American trains. Says was ignored for years, DHS confirmed. "All of the knowledge to generate the exploit already exists on the internet, AI could even build it for you." www.404media.co/hackers-can-...
15.07.2025 02:04 β π 177 π 48 π¬ 6 π 15
Just to clear up some misinfo, a BGP hijack was not the cause of Cloudflare DNS going down today.
At 21:51 UTC, Cloudflare (AS13335) withdrew both 1.1.1.0/24 and 1.0.0.0/24 for an unknown reason.
I suspect AS4755 was always announcing 1.1.1.0/24, when CF went away, it leaked a bit (%2).
15.07.2025 00:14 β π 25 π 11 π¬ 4 π 4
Activision pulls Call of Duty game after PC players are hacked
Call of Duty: Remote Code Execution
Activision has pulled a Call of Duty game after multiple reports of PC players having their computers hacked. An old insecure version of the game was reportedly uploaded to the Microsoft Store π¬ www.theverge.com/news/702255/...
09.07.2025 09:35 β π 76 π 10 π¬ 2 π 6
161. The Court's Disastrous Ruling in the Third-Country Removal Case
The majority did not just greenlight an especially odious immigration policy without any explanation; it did so in a case in which the government defied the district courtβtwiceβwith no consequence.
Todayβs unsigned, unexplained #SCOTUS ruling clearing the way for removals of migrants to third countries without any additional process is a disasterβnot just on the merits, but because of the government misbehavior that it not only refuses to punish, but effectively rewards.
Me, via βOne Firstβ:
23.06.2025 21:59 β π 9351 π 3481 π¬ 583 π 320
[TLS] Photosynthesis, an update to Merkle Tree Certificates
Photosynthesis combines the Static CT API with the ideas in Merkle Tree Certificates.
Here's something I am very excited about: Photosynthesis! π±βοΈ
A proposal to have CAs run transparency logs and make X.509 certificates out of Merkle Tree inclusion proofs.
This is similar to how CT would have worked in an ideal world, and it solves the problem of PQC sizes in logs and handshakes.
20.06.2025 19:11 β π 39 π 11 π¬ 1 π 0
this is actually how my cursed Online brain read the post
21.08.2023 02:50 β π 804 π 175 π¬ 16 π 2
Democratizing Detection Engineering at Block: Taking Flight with Goose and Panther MCP
A comprehensive overview of how Block leverages Goose and Panther MCP to democratize and accelerate security detection engineering.
Most engineers arenβt taught how to write secure code or catch threats after deploy.
Detection engineering used to be limited to experts. Now anyone can do it with prompts, Goose, and the Panther MCP server. πͺ
block.github.io/goose/blog/2...
02.06.2025 22:07 β π 10 π 5 π¬ 0 π 0
Vanta bug exposed customers' data to other customers | TechCrunch
The compliance company said the customer data exposure was caused by a product change.
New, by me: Compliance startup Vanta said it's fixing a bug that exposed some customer data to other Vanta customers.
One Vanta customer told us that they were notified that some of their data was pulled out of their Vanta instance "into other customersβ instances."
02.06.2025 17:17 β π 14 π 6 π¬ 2 π 1
Our latest investigationβ¦
31.05.2025 21:13 β π 156 π 55 π¬ 7 π 0
Probe Found Security Lapses Led to US Contractorβs Data Breach
Failures in cybersecurity practices at a software company that helps federal agencies manage investigations and FOIA requests allowed two convicted hackers to delete databases, according to internal d...
SCOOP: In Feb, federal agencies "lost" many #FOIA requests but you probably had no idea. It turns out that the FOIAs disappeared due to an "insider threat attack" by 2 employees at a software company who were previously convicted of hacking into the State Dept
π§΅
π www.bloomberg.com/news/article...
21.05.2025 13:17 β π 523 π 328 π¬ 24 π 31
DHI
New: Docker Hardened Images π
β
Non-root by default
β
SLSA Level 3 compliant
β
SBOMs, VEX, provenance β all signed
β
Built-in to Docker Hub
π http://spklr.io/63323CAqR
#Docker #DevSecOps #SoftwareSupplyChain #Containers #CloudNative #DockerHardenedImages
19.05.2025 13:12 β π 5 π 3 π¬ 0 π 1
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server micahflee.com/ddosecrets-p...
19.05.2025 16:54 β π 138 π 79 π¬ 6 π 12
Branch Privilege Injection: Exploiting Branch Predictor Race Conditions β Computer Security Group
Time to update microcode on your Intel processors (gen >9)
new speculative prediction bug lets you capture /etc/shadow with 99% reliability. They didn't make anything like it work on AMD or ARM, yet...
comsec.ethz.ch/research/mic...
www.intel.com/content/www/...
github.com/intel/Intel-...
13.05.2025 16:56 β π 2 π 3 π¬ 0 π 0
Despite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logs
Despite their misleading marketing, TeleMessage, the company that makes a modified version of Signal used by senior Trump officials, can access plaintext chat logs from its customers.
In this post I ...
Despite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logs. My findings are based on TM SGNL's source code, and they are corroborated by hacked data micahflee.com/despite-misl...
06.05.2025 20:00 β π 783 π 332 π¬ 23 π 89
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. βI would say the whole process took about 15-20 minutes,β the hacker said micahflee.com/the-signal-c...
04.05.2025 22:05 β π 1841 π 878 π¬ 37 π 87
PhD Timeline xkcd.com/3081
25.04.2025 15:32 β π 60711 π 20857 π¬ 610 π 840
π§΅ THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures Iβve ever read.
He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords
Media's coverage wasn't detailed enough so I dug into his testimony:
18.04.2025 00:10 β π 14177 π 7493 π¬ 334 π 1032
Turning the Security Flywheel
This post explores the "flywheel" concept and its application to security, demonstrating how to create self-reinforcing cycles that improve effectiveness.
www.philvenables.com/post/turning...
08.03.2025 15:44 β π 5 π 3 π¬ 0 π 1
Safe.eth on X: "Investigation Updates and Community Call to Action" / X
Investigation Updates and Community Call to Action
New details on the ByBit/Safe{Wallet} breach, and uhhh wow, some really silly blunders on the DPRK side. They still succeeded which is the most upsetting part of all of this. Let's bully some threat actor tradecraft! Aπ§΅
x.com/safe/status/...
06.03.2025 17:21 β π 23 π 12 π¬ 1 π 2
Security engineering should be embedded in engineering teams, doing joint engineering work.
Security engineering that operates as its own isolated team is an organizational artifact of a companyβs βweβll bolt on security laterβ culture.
25.02.2025 20:24 β π 161 π 23 π¬ 10 π 1
The executive response to Copilot products consistently violating data security policies and development requirements causing escalations every release was to just stop having the escalation meetings for a while
I am not even exaggerating
08.02.2025 00:33 β π 131 π 36 π¬ 5 π 3
On the other hand, it will be redundant to all the other actual vulnerabilities in the EOL version which have actual quantifiable severities.
24.01.2025 16:56 β π 0 π 0 π¬ 0 π 0
Yep, basically!
24.01.2025 16:33 β π 0 π 0 π¬ 0 π 0
CVE Website
I guess we're creating vulnerabilities about the potential for vulnerabilities now and classifying them as high severity π©
www.cve.org/CVERecord?id...
24.01.2025 16:07 β π 0 π 0 π¬ 2 π 0
Exploring the Kubernetes API Server Proxy
First blog post of the new year and this is one I've been meaning to write up for a while which is some details on #Kubernetes API Server proxy feature and how it might be possible to use some known weaknesses in it to escalate your privileges in a cluster.
raesene.github.io/blog/2025/01...
18.01.2025 12:54 β π 24 π 14 π¬ 0 π 0
Internet trends, as seen by the Cloudflare global network.
Ruby and Rails hacker working at Shopify, living in Seattle
At Block, we believe open source is at the heart of innovation and community empowerment. Our vision is to nurture a diverse and vibrant open source ecosystem that removes barriers to technology and fosters economic opportunities for all.
Cybersecurity reporter at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net
Uni, Minuet cat born on March 27, 2020π―π΅
https://youni.store
Investigative Reporter, Bloomberg News. "FOIA terrorist." Band Tshirt hoarder. Subscribe to my newsletter, FOIA Files. Opinions are mine.
jasonleopold@protonmail.com
Signal: JasonLeopold.666
https://www.bloomberg.com/account/newsletters/foia-files
Distributed Denial of Secrets is a 501(c)(3) journalist non-profit devoted to the free transmission of data in the public interest. We publish and archive leaks.
DDoSecrets.com
LibraryOfLeaks.org
DonorBox.org/ddosecrets
Member of https://lockdown.systems/ collective making @cyd.social β writing at https://micahflee.com β author of HACKS, LEAKS, AND REVELATIONS https://hacksandleaks.com β signal: micah.01
An unofficial bot of The Seattle Times
rss: https://www.seattletimes.com/seattle-news/feed/
maintainer: @anotherseattleite.bsky.social
Nonprofit aquarium committed to Inspiring Conservation of Our Marine Environment. Join us in protecting our one world oceanβfrom the Salish Sea to the Coral Triangle.
The Ocean Pavilion is now open! Visit our expanded campus today.
25+ years at @CNBC and @NBCNews / @WSJ alum / board member, NY City Center & Sag Harbor Cinema
Guided by the vision of Rick Steves, we see travel as a powerful way to understand our world. European travel tips, inspiration, and information.
#KeepOnTravelin
PARODY. All of the popular films and series not coming to Disney+ or anywhere else. Intern @straycunt.bsky.social tweets signed as KH.
Guidebook author, TV & radio host, business owner, Lutheran, and NORML Board Member. Fanatically positive and militantly optimistic.
https://static.macmillan.com/static/holt/robin/
Scale access securely and automatically
Robust Open Online Safety Tools (ROOST) is a new non-profit entity providing open source, accessible, high-quality, transparent safety tools for digital organizations of all kinds.
roost.tools
@ksvesq.bsky.socialβs husband; father of daughters; professor @georgetownlaw.bsky.social; #SCOTUS nerd @CNN.com
Bio: www.law.georgetown.edu/faculty/stephen-i-vladeck
"One First" Supreme Court newsletter: stevevladeck.com
Book: tinyurl.com/shadowdocketpb