Kevin Kosh's Avatar

Kevin Kosh

@kidko92.bsky.social

PR elder, cybersecurity roadie, proud papa of 2 boys, accomplished wiseacre, Multiversal social entity.

48 Followers  |  219 Following  |  51 Posts  |  Joined: 13.09.2023
Posts Following

Posts by Kevin Kosh (@kidko92.bsky.social)

NEW POD TIME! ๐Ÿšจ GitLabโ€™s explosive look at North Koreaโ€™s โ€œContagious Interviewโ€ APT operation, a fresh batch of already-exploited Ivanti and Dell zero-days, and thoughts on addictive AI coding agents affecting human purpose. (Presented by @tlpblack.bsky.social)

LISTEN pod.link/1414525622

20.02.2026 21:49 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Wynn Resorts confirms data stolen after ShinyHunters threats : Security pros question assurances as company offers staff credit monitoring

No Wynn situation: Resort org confirms breach of staff data, "confirms" bad guys have deleted, tacitly confirms that it paid the ransom. Skepticism ensues. www.theregister.com/2026/02/25/w...

25.02.2026 14:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Marquis sues firewall provider SonicWall, alleges security failings with its firewall backup led to ransomware attack | TechCrunch Fintech giant Marquis is suing its firewall provider SonicWall, claiming that an earlier breach with SonicWall allowed hackers to deploy ransomware on Marquis' network.

Marquis de Shade: the claim of SonicWall's culpability in breach related ransomware attacks gets spicier with a formal lawsuit techcrunch.com/2026/02/24/m...

24.02.2026 16:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ShinyHunters allegedly drove off with 1.7M CarGurus records : Latest in a rash of grab-and-leak data incidents

Car-Gru: Here's the plan. I target the car company. I breach the car company. I grab the car company data. I sit on the data until Feb 20th. www.theregister.com/2026/02/18/s...

18.02.2026 21:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence Vulnerability intelligence company VulnCheck has raised $25 million in Series B funding to meet demand for its solutions.

Cut the Check!: vuln management platform snags new funding www.securityweek.com/vulncheck-ra...

18.02.2026 12:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Password managers' promise that they can't see your vaults isn't always true Contrary to what password managers say, a server compromise can mean game over.

Some...shall pass: Researchers find that the chances of compromising a password manager isn't high, but it's not "zero". arstechnica.com/security/202...

18.02.2026 12:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Canada Goose investigating as hackers leak 600K customer records ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data. Canada Goose told BleepingComputer ...

Silly Goose: Shinyhunters squawking about 600K cust records from premium outerwear brand. Vendor claims no evidence of compromise, and that the gaggle of data likely was migrated from an external source. www.bleepingcomputer.com/news/securit...

17.02.2026 13:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
New Data Tool Helps Orgs Prioritize Exploited Flaws Smarter KEV Collider combines data from multiple open source vulnerability frameworks to help cybersecurity teams assess which issues need their attention first.

Vuln prioritization continues to be a massive hurdle.
@darkreading.bsky.social explores how our KEVology report + KEV Collider tool help solve "triage fatigue" by turning CISA KEV into an actionable roadmap.

Thanks for the deep dive, @robertlemos.bsky.social!

www.darkreading.com/threat-intel...

10.02.2026 15:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
LLMs Hijacked, Monetized in 'Operation Bizarre Bazaar' LLMs and MCPs have been hijacked at scale and the unauthorized access sold for profit in Operation Bizarre Bazaar.

How Bizarre, How Bazaar...: Researchers reveal the workings and monetization of a campaign that focuses mainly on self-hosted LLM infrastructure, going after LLMs and MCPs. www.securityweek.com/llms-hijacke...

30.01.2026 12:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Fintech firm Marquis blames hack at firewall provider SonicWall for its data breach | TechCrunch The fintech giant said it plans to "seek recoupment of any expenses" from its firewall provider SonicWall after a 2025 data breach exposed customer firewall configurations.

...tear down this Wall!: Finserv firm evaluating ways to open up a path to "seek compensation" from firewall vendor related to a late 2025 breach, where the vendor had seemingly kept the true extent of the breach...walled off. techcrunch.com/2026/01/29/f...

30.01.2026 12:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch TechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user's approximate geographic location. Under Armour confirmed some sensitive informati...

Armour piercing: actor claims to have gotten Under fitness retailer's defenses and stolen PII on 72M customers. Company is "aware" of the claims. techcrunch.com/2026/01/22/u...

22.01.2026 17:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Grubhub confirms hackers stole data in recent security breach Food delivery platform Grubhub has confirmed a recent data breach after hackers accessed its systems, with sources telling BleepingComputer the company is now facing extortion demands.

Git your Grub-by hands off...: Food delivery co delivers news of a breach, but leaves mystery meat details absent including connections to the Salesforce driven attacks. www.bleepingcomputer.com/news/securit...

16.01.2026 13:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Petco confirms security lapse exposed customersโ€™ personal data | TechCrunch The pet company has published almost no details about what happened, who was affected, and what personal data was exposed.

Wagging the Dog: Petco discloses that an app "setting" allowed certain data to get off the leash.
techcrunch.com/2025/12/05/p...

05.12.2025 15:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

This Gov & Beyond episode, the team hosts Breaking Defenseโ€™s Publisher and Managing Director, David Smith, and the publicationโ€™s Editor in Chief, Aaron Mehta to talk about what goes on in the largest news organization dedicated to defense.

Tune in here: w2comm.com/gov-beyond-d...

04.12.2025 15:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
โ€˜End-to-end encryptedโ€™ smart toilet camera is not actually end-to-end encrypted | TechCrunch Kohler, the makers of a smart toilet camera, can access customers' data stored on its servers, and can use customersโ€™ bowl pictures to train AI.

Encraption: It seems the end-to-end ass-et security claims of a smart toilet end at your own backend, and are worth pretty much what comes out. techcrunch.com/2025/12/03/e...

03.12.2025 20:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

W2 Communications was proud to serve as a sponsor of the SpaceNews' 2025 ICON Awards! Our team had a great time recognizing and celebrating the excellence and innovation of the space community over the past year. Congratulations to this year's honorees!

03.12.2025 18:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Communications programs are often measured by interview and coverage counts. Our new blog explains why securing these results requires methodically building relationships with journalists, and how communicators can establish these connections. w2comm.com/how-to-estab...

03.12.2025 15:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Fortinet Woes Continue With Another WAF Zero-Day Flaw A second zero-day vulnerability in Fortinet's web application firewall (WAF) line has raised more questions about the vendor's disclosure practices.

-net loss: Firewall vendor discloses 2nd zero day in less than a week, prompting questions of gross disclosure practices. www.darkreading.com/vulnerabilit...

20.11.2025 11:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐—œ๐—ป๐˜๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐—ถ๐—ป๐—ด... ๐˜๐—ต๐—ฒ ๐—˜๐—ฐ๐—ต๐—ผ ๐—”๐˜„๐—ฎ๐—ฟ๐—ฑ๐˜€! ๐Ÿ†โœจ

Itโ€™s about time that we recognize the excellent journalists who bring clarity to the fast-moving, complex world of the U.S. Public Sector- from Federal to State & Local to Education.

Stay tuned for more information coming soon! theechoawards.com

17.11.2025 14:54 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

You're good, but just a reminder.

11.11.2025 19:35 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Lawmakers say stolen police logins are exposing Flock surveillance cameras to hackers | TechCrunch Flock said around 3% of its law enforcement customers do not use multi-factor authentication, potentially leaving dozens of law enforcement agency accounts open to compromise and improper access.

Sheep: Police plate reader tech maker Flock reaches 97% MFA enablement after FTC accuses them of not being good shepherds of customer security with default controls. 3% have "reasons". Woof. techcrunch.com/2025/11/03/l...

06.11.2025 11:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Heed the call of the Tacos....

04.11.2025 14:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
F5 Says Nation-State Hackers Stole Source Code and Vulnerability Data F5 was recently targeted by state-sponsored threat actors who managed to steal sensitive information from the companyโ€™s systems.

Refresh...Refresh...Refresh: F5 reports that nation state actors maintained long-term, persistent access to systems that revealed source code, vuln data and even some customer config and implementation data www.securityweek.com/f5-blames-na...

16.10.2025 10:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

(Open) House Party: Envious of "party people"? Don't be. Partiful apparently lets you join, since location data of user-uploaded images is invitingly there for the taking... photos.https://techcrunch.com/2025/10/04/event-startup-partiful-wasnt-stripping-gps-locations-from-user-uploaded-photos/

16.10.2025 10:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SonicWall: 100% of Firewall Backups Were Breached SonicWall said the breach affected firewall configuration files for all customers using SonicWallโ€™s cloud backup service โ€” up from a previous 5% estimate.

SonicBoom: network security vendor's breach estimates shatter the sound (security) barrier, speeding from 5% to 100% of customers affected by a "cloud backup file incident"that exposed encrypted credentials and backup firewall configuration files. www.darkreading.com/cyberattacks...

10.10.2025 11:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Jaguar Land Rover Operations 'Severely Disrupted' by Cyberattack British automobile manufacturer Jaguar Land Rover (JLR) is scrambling to restore applications and operations that were impacted by a cyberattack.

One if by Land...: British automaker sees another significant ransomware attack, marking number two this year for the company, and the Jaguar maker is unable to outrun a significant operational outage. www.securityweek.com/jaguar-land-...

03.09.2025 10:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Dutch prosecution service attack keeps speed cameras offline : Who knew zero-days could be so useful to highway speedsters?

Screeching halt: speed cameras crash across the Netherlands due to a cyberattack on the Dutch Public Prosecution Service exploiting Citrix vulns. www.theregister.com/2025/08/15/c...

20.08.2025 13:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Nearly 2,000 MCP Servers Possess No Security Whatsoever Authentication in MCP โ€” the backbone of agentic AI โ€” is optional, and nobody's implementing it. Instead, they're allowing any passing attackers full control of their servers.

End of Line: AI customers seem without a CLU as nearly all MCP servers are exposed with no authentication checks of any kind www.darkreading.com/vulnerabilit...

21.07.2025 11:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
750,000 Impacted by Data Breach at The Alcohol & Drug Testing Service The Alcohol & Drug Testing Service (TADTS) says personal information was stolen in a July 2024 ransomware attack.

High and Dry: Alcohol and Drug Testing Service gets smoked by ransomware gang, losing PII on more than 750K individuals. www.securityweek.com/750000-impac...

21.07.2025 10:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
McDonaldโ€™s AI Hiring Bot Exposed Millions of Applicantsโ€™ Data to Hackers Who Tried the Password โ€˜123456โ€™ Basic security flaws left the personal info of tens of millions of McDonaldโ€™s job-seekers vulnerable on the โ€œMcHireโ€ site built by AI software firm Paradox.ai.

Not lovin it...: Researchers find an unhappy meal of 64 million records containing candidate chats with McDonald's AI hiring chatbot, driving thru the data with a kids meal password of 123456. www.wired.com/story/mcdona...

10.07.2025 10:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0