Mitja Kolsek's Avatar

Mitja Kolsek

@mkolsek.bsky.social

CEO of ACROS Security; Co-founder of 0patch (https://0patch.com) Wishing billionaires would stop buying social platforms and making us rebuild synapses elsewhere https://acrossecurity.com

218 Followers  |  99 Following  |  39 Posts  |  Joined: 30.08.2023  |  1.9228

Latest posts by mkolsek.bsky.social on Bluesky

Preview
Tap-and-Steal: The Rise of NFC Relay Malware on Mobile Devices NFC relay malware on Android devices is exploiting Tap-to-Pay systems, targeting financial institutions globally with sophisticated attacks and minimal user interaction.

Zimperium has discovered more than 760 Android apps that steal and relay NFC data to a remote attacker

zimperium.com/blog/tap-and...

30.10.2025 15:29 β€” πŸ‘ 9    πŸ” 5    πŸ’¬ 0    πŸ“Œ 1
Preview
Introducing Aardvark: OpenAI’s agentic security researcher Now in private beta: an AI agent that thinks like a security researcher and scales to meet the demands of modern software.

Aardvark is a labor of love and mission for the whole team. We are super excited to bring it to you. Sign up for the beta immediately!!! openai.com/index/introd...

30.10.2025 18:14 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1
Post image

The latest WindowsUpdate disables Windows Explorer previews for files that were downloaded from the Internet or are on Internet Zone network shares.

gist.github.com/ericlaw1979/...

17.10.2025 16:36 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
For our scientists
YouTube video by Elle Cordova For our scientists

Need a summary of all the ways the White House has gutted science?

πŸ§ͺOr are you scientist who needs to hear your work valorized in song?

From brilliant songwriter, Elle Cordova:

β€œIf they don’t like the data in your graphs/they’ll just turn the lights out in your lab”

youtube.com/shorts/AYm9w...

24.09.2025 16:09 β€” πŸ‘ 42    πŸ” 16    πŸ’¬ 1    πŸ“Œ 0
Search Jobs | Microsoft Careers

Come work with me on Microsoft Defender for Endpoint!
jobs.careers.microsoft.com/global/en/jo...

18.09.2025 18:23 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

17.09.2025 13:20 β€” πŸ‘ 87    πŸ” 38    πŸ’¬ 9    πŸ“Œ 5
Unicode 16.0.0

If you want to understand the struggle anyone doing input validation has, just look at ver 16.0 of the unicode standard: unicode.org/versions/Uni...

Unicode 16.0 adds 5185 characters, for a total of 154,998 characters

244 pages.

yeah, good luck with that.

<script>alert('𐒀𐒁𐒂')</script>

29.08.2025 11:08 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
The Alot is Better Than You at Everything As a grammatically conscientious person who frequents internet forums and YouTube, I have found it necessary to develop a few coping mechani...

The Alot is better than you...

hyperbole-andahalf.blogspot.com/2016/08/the-...

25.08.2025 10:42 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
So Long to Tech’s Dream Job

Five-ish years ago, @lizthegrey.com told me tech workers needed to organize because the tech giants would automate their jobs, the market would flood with talent and they would lose bargaining power. I thought it was unlikely. Here’s a story about me being wrong. www.nytimes.com/2025/08/04/t...

04.08.2025 15:04 β€” πŸ‘ 301    πŸ” 82    πŸ’¬ 5    πŸ“Œ 5

I'm exploring new engagements! If your team needs expertise in cybersecurity, risk assessment, tech policy, regulations (GDPR, etc.), tech standards, strategic insight, or Comms/PR, let's talk! Open to contract, or flexible roles. DM/email at me@lukaszolejnik.com.

09.04.2025 14:30 β€” πŸ‘ 20    πŸ” 8    πŸ’¬ 0    πŸ“Œ 1
Video thumbnail

Morning in Kyiv. No sleep. Air quality is extremely bad. City is covered in thick smoke.

This is Russian terror, aimed at people who chose to stay, resist and fight.

04.07.2025 06:31 β€” πŸ‘ 1820    πŸ” 832    πŸ’¬ 94    πŸ“Œ 59
Post image

Re-reading Stumbling on happiness by @danielgilbert.bsky.social and loving every page again. Relatable facts, interesting actual and thought experiments wrapped in just my type of humor.

03.07.2025 10:14 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

OAuth is hard and we often find security flaws, but this is next level. Kudos to Modzero.

29.06.2025 10:24 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

A friendly reminder from the Patron Saint of the Internet, Deth Veggie

26.06.2025 03:49 β€” πŸ‘ 14    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0

So sorry to hear this. Chipped in and sharing.

26.06.2025 20:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Hey, we can sell you a USB-HDMI adapter that works well in your office but flickers on stage.

16.06.2025 06:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Roundcube ≀ 1.6.10 Post-Auth RCE via PHP Object Deserialization [CVE-2025-49113] A deep technical breakdown of CVE-2025-49113, a critical Roundcube vulnerability involving PHP session serialization. Learn how the bug was discovered, exploited, and responsibly disclosed with full P...

Threat actors are exploiting a recently patched vulnerability in the Roundcube webmail server.

Attacks began two days after a patch was published on GitHub.

FearsOff believes attackers bin-diffed the code before a final patch was ready and started exploiting servers.

fearsoff.org/research/rou...

05.06.2025 11:27 β€” πŸ‘ 7    πŸ” 2    πŸ’¬ 1    πŸ“Œ 1
Preview
Hacking My Car, and probably yoursβ€” Security Flaws in Volkswagen’s App This flaw made me the owner of thousands of cars (sort of).

Volkswagen fixed vulnerabilities in its mobile app that could allow attackers to hijack user accounts and retrieve car/owner details.

The app lacked brute-force protection, stored internal credentials in plaintext, and exposed any car owner's details via a VIN.

loopsec.medium.com/hacking-my-c...

18.05.2025 14:16 β€” πŸ‘ 33    πŸ” 11    πŸ’¬ 1    πŸ“Œ 4

You receive a call on your phone.

The caller says they're from your bank and they're calling about a suspected fraudulent payment.

"Oh yeah," you think. Obvious scam, right?

The caller says "I'll send you an in-app notification to prove I'm calling from your bank."

🧡 1/4

03.05.2025 08:32 β€” πŸ‘ 1646    πŸ” 1015    πŸ’¬ 18    πŸ“Œ 269

Makes sense, thanks.

02.05.2025 20:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Perhaps to prevent someone from pasting your potentially sensitive clipboard content to the username field?

02.05.2025 16:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. Researchers say the behavior amounts to a persistent backdoor.
30.04.2025 18:37 β€” πŸ‘ 40    πŸ” 10    πŸ’¬ 5    πŸ“Œ 2
Preview
New Windows 7 And Windows Server 2008 Security Updates Confirmed Users of end-of-support Windows 7 and Windows Server 2008 platforms are advised of the availability of new security updates.

By me @forbes.com: Roll up, roll up, you legacy-loving loons, get your Windows 7 and Windows Server 2008 R2 security updates here. #kudos @0patch.bsky.social and @mkolsek.bsky.social

#infosec

www.forbes.com/sites/daveyw...

29.04.2025 13:32 β€” πŸ‘ 5    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Oh

15.04.2025 10:52 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
No Reboot Security Updates Come To Windows 11 β€” But There’s A Catch Imagine being able to update Windows 11 with security patches but without rebooting. Well, now you can. But there’s a catch.

By me @forbes.com: Maybe Microsoft just needs to buy @0patch and be done with it? The security hotpatching needs of the many outweigh the needs of the few, as Mr Spock so famously said.

#infosec

www.forbes.com/sites/daveyw...

14.04.2025 13:56 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Windows Passwords At Risk As New 0-Day Confirmedβ€”Act Now New Windows password hash-stealing threat has no official fix. Here's how to stay protected for now.

By me @forbes.com: Pass the hash, anyone? New NTLM zero-day with no Microsoft fix confirmed. #kudos @mkolsek.bsky.social for this one.

#infosec

www.forbes.com/sites/daveyw...

26.03.2025 11:13 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Anyone who says they never fell for a phish or other online scam is either lying or doesn't use the Internet. We have all been there.

Well done to @troyhunt.com for being so open about his experience so that we can all learn from it

25.03.2025 09:16 β€” πŸ‘ 27    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Preview
Bypassing Detections with Command-Line Obfuscation Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits exec...

Signature based security only stops script kiddies. Always has.

Signature based security (partial list):
- AV/EDR/IDS
- virtual patches

NOT signature-based security (partial list):
- actual security patches
- canaries
- firewalls
- application control
- MFA

www.wietzebeukema.nl/blog/bypassi...

24.03.2025 12:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
I’m the Canadian who was detained by Ice for two weeks. It felt like I had been kidnapped I was stuck in a freezing cell without explanation despite eventually having lawyers and media attention. Yet, compared with others, I was lucky

I’m the Canadian who was detained by Ice for two weeks. It felt like I had been kidnapped

19.03.2025 10:16 β€” πŸ‘ 9300    πŸ” 4365    πŸ’¬ 518    πŸ“Œ 772

@mkolsek is following 19 prominent accounts