Caitlin Condon's Avatar

Caitlin Condon

@catc0n.bsky.social

Adventurer. Takes a lot of photos, calls many places home. VP of research @VulnCheck. Previously vulnerability research director @Rapid7 / @metasploit.

757 Followers  |  498 Following  |  149 Posts  |  Joined: 30.05.2023  |  2.0734

Latest posts by catc0n.bsky.social on Bluesky

More governors need to stand up like this.

I'm no fan of Newsom generally, but he's at least not rolling over for the administration. California is better off for it.

02.10.2025 22:37 β€” πŸ‘ 25    πŸ” 1    πŸ’¬ 2    πŸ“Œ 0

I haven't found exploitation of Fortra's GoAnywhere MFT CVE-2025-10035 in EDR telemetry yet. Which means it is probably still rare and folks have some time to patch. Wonder how long it will stay that way. The previously exploited vulns appeared fairly quickly.

27.09.2025 18:26 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

It seems like there’s still a piece of the story missing re: the private key.

27.09.2025 18:32 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 We’re back, just over 24 hours later, to share our evolving understanding of CVE-2025-10035. Thanks to everyone who reached out after Part 1, and especially to the individual who shared credible inte...

Pretty unfortunate update on Fortra GoAnywhere MFT CVE-2025-10035 from the folks at watchTowr labs.watchtowr.com/it-is-bad-ex...

25.09.2025 20:08 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Federal agencies given one day to patch exploited Cisco firewall bugs Vulnerabilities in some models of Cisco's Adaptive Security Appliances (ASA) have been exploited by "an advanced threat actor," according to a warning from CISA.

Federal agencies have about 24 hours to patch two critical bugs in a line of Cisco firewalls

patch CVE-2025-30333 and CVE-2025-20362 asap

therecord.media/cisco-asa-fi...

25.09.2025 18:51 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

I don’t think I’ve ever loved anything as much as ICE loves violently attacking women.

25.09.2025 18:41 β€” πŸ‘ 15035    πŸ” 4208    πŸ’¬ 1265    πŸ“Œ 337

The Secret Service isn't claiming it foiled any plot targeting the UN General Assembly. Just that a big collection of SIMs (probably used for fraud) could have *potentially* disrupted NYC cell service. The SIMs were in a *35 MILE* radius of the UN.

These headlines are all pretty egregiously wrong:

23.09.2025 21:20 β€” πŸ‘ 359    πŸ” 100    πŸ’¬ 11    πŸ“Œ 8

This is incredible stuff

21.09.2025 11:57 β€” πŸ‘ 37    πŸ” 6    πŸ’¬ 1    πŸ“Œ 0
Preview
CVE-2025-10035: Critical Vulnerability in Fortra GoAnywhere MFT | Blog | VulnCheck A new critical vulnerability was disclosed in Fortra's GoAnywhere managed file transfer product, which has been targeted in the past by ransomware and extortion groups

Last night, Fortra disclosed a critical vulnerability in their GoAnywhere MFT file transfer product. CVE-2025-10035 has a virtually identical description to CVE-2023-0669, which was exploited by ransomware crews. Unclear if this one has been exploited. Patch now. www.vulncheck.com/blog/cve-202...

19.09.2025 16:36 β€” πŸ‘ 4    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Diagram titled 'Possible causes of your problems'. On the left hand side, subtitled 'Yes': Funding removed from local councils, growing gap between rich and poor, multinational companies not paying their taxes, lack of new affordable housing, government not investing sufficiently in schools and healthcare. On the right hand side, subtitled 'No': Picture of small boat, with arrow; 'People fleeing horrific situations that you and I can't imagine'.

Diagram titled 'Possible causes of your problems'. On the left hand side, subtitled 'Yes': Funding removed from local councils, growing gap between rich and poor, multinational companies not paying their taxes, lack of new affordable housing, government not investing sufficiently in schools and healthcare. On the right hand side, subtitled 'No': Picture of small boat, with arrow; 'People fleeing horrific situations that you and I can't imagine'.

Possible causes of your problems. It’s a diagram that (sadly) still seems relevant in 2025, so reposting a year and a bit on.

25.08.2025 17:18 β€” πŸ‘ 2630    πŸ” 1625    πŸ’¬ 14    πŸ“Œ 28
Preview
VulnCheck - Outpace Adversaries Vulnerability intelligence that predicts avenues of attack with speed and accuracy.

Hey, security research friends! You know how vulnerability disclosure coordination is the most painful part of vuln research? Good news: VulnCheck will do it for you! You get credit, we handle the CVEs + vendor discussions.

Report vulnerabilities for disclosure here: vulncheck.com/advisories/r...

17.09.2025 22:40 β€” πŸ‘ 7    πŸ” 0    πŸ’¬ 0    πŸ“Œ 1
Preview
When to call the witches 1-800 dark magic

A beautiful, tender piece about grief and aging and friendship and the sacred call to haunt: joysullivan.substack.com/p/when-to-ca...

13.09.2025 03:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

We need community notes here to clarify that in fact Michelle Wu ended his campaign

11.09.2025 23:18 β€” πŸ‘ 1542    πŸ” 189    πŸ’¬ 24    πŸ“Œ 4
A meme with the black spinning top from the movie "Inception". It's on a beige-ish background and the text of the meme says "It's like...a third-order command injection."

A meme with the black spinning top from the movie "Inception". It's on a beige-ish background and the text of the meme says "It's like...a third-order command injection."

Quote from the VulnCheck team exploit mines 2025-09-11T19:24:00Z

11.09.2025 23:45 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Overachievers

09.09.2025 14:19 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Gen Z in Nepal burned down the parliament, burned down the homes of government officials, forced the prime minister to resign, and paraded the finance minister through the streets nearly naked.

09.09.2025 14:14 β€” πŸ‘ 8046    πŸ” 2420    πŸ’¬ 231    πŸ“Œ 835
Preview
VulnCheck Insights: CVE Context at the Hover of Your Cursor | Blog | VulnCheck Instead of bouncing between tabs, you now get instant, current context the moment a CVE appears on your screen.

I know NPM and SAP and probably other acronyms are on fire today, but @vulncheck.bsky.social put out a Chrome extension for #CVE and #exploit intel and it's saving me kind of a lot of tab-switching effort, so you get πŸŽ‰ 🀠posts from me instead of πŸ—‘οΈπŸ”₯ posts www.vulncheck.com/blog/vuln-ch...

08.09.2025 21:13 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Friends, for your Friday, here's a new image of planets being born.

29.08.2025 17:43 β€” πŸ‘ 418    πŸ” 63    πŸ’¬ 3    πŸ“Œ 4

The inverse of this skeet is "Some enterprising young sys admins used example machine keys for production deployments, which is also significantly less surprising than anyone reading docs."

05.09.2025 21:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

There is something soothing about watching a baseball diamond get steamrolled.

04.09.2025 20:31 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690) | Google Cloud Blog An active ViewState deserialization attack affecting Sitecore products, where attackers achieved remote code execution.

Some enterprising young threat actor read the Sitecore docs, which is significantly less surprising than literally anyone else reading docs cloud.google.com/blog/topics/...

03.09.2025 22:34 β€” πŸ‘ 7    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1
Preview
THREATCON1 Agenda

Holy speaker agenda, Batman! This is a shameless plug that is also wholly sincere: @vulncheck.bsky.social is hosting our inaugural THREATCON1 in VA Sept. 21 and 22. The conference is free, Jen Easterly and Andrew Boyd are keynoting (!), and the talk tracks slap. COME!! www.threatcon1.org/agenda

29.08.2025 17:49 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

oh, brother

27.08.2025 19:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Great metaphor

27.08.2025 16:38 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"I hate this piece of crap."

Quote from the team #exploit mines 2025-08-26T21:48:00Z

(am I doing ISO 8601 right, since this is apparently what we are doing now?)

27.08.2025 02:36 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
New Citrix NetScaler Zero-Day Vulnerability Exploited in the Wild | Blog | VulnCheck Three new Citrix NetScaler vulnerabilities were disclosed on August 26, including CVE-2025-7775, a fresh zero-day flaw being used in the wild

New Citrix #NetScaler 0day (CVE-2025-7775), plus a bonus management interface improper access control vuln. The zero-day has been added to @vulncheck.bsky.social KEV βœ… www.vulncheck.com/blog/new-cit...

26.08.2025 17:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
New exploits and detections for FortiSIEM, SharePoint, SUSE Manager, Web-Check, and CHCNAV P5E GNSS. New support for legacy Censys queries. - Initial Access API Update, CVE-2025-25256: Fortinet FortiSIEM Command Injection, CVE-2022-30622: CHCNAV P5E GNSS, CVE-2020-1147: SharePoint .NET Core Deserialization RCE, CVE-2025-46811: SUSE Manager RemoteMinionCom...

New additions to @VulnCheckAI's initial access intelligence: Exploits, PCAPs, signatures, and queries for FortiSIEM CVE-2025-25256, SharePoint CVE-2020-1147, SUSE Manager CVE-2025-46811, an underappreciated GNSS reference station cred leak, and plenty more πŸ‘€ docs.vulncheck.com/initial-acce...

25.08.2025 12:48 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
VulnCheck | Webinar August 2025

Yo I don't always post @runZeroInc spam here.

Sometimes I post @vulncheck spam.

I'm super stoked for this:

https://wwv.vulncheck.com/1h-state-of-exploitation-webinar

22.08.2025 20:18 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
VulnCheck | Webinar August 2025

In 1H 2025 alone, 400+ CVEs were reported as exploited in the wild for the first time, and 180+ CVEs were freshly attributed to known threat actors.

Into #CVE and #exploit data? Join @vulncheck.bsky.social on Tuesday, August 26 for more 1H 2025 attack trends 🐚
wwv.vulncheck.com/1h-state-of-...

21.08.2025 22:22 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

holy crap.

"In Ireland, there are more than 80 data centres, gobbling up 50 per cent of the electricity in the Dublin region, and hoovering up more than 20 per cent nationally, as they work to process and distribute huge quantities of digital information."

10.08.2025 15:07 β€” πŸ‘ 1596    πŸ” 701    πŸ’¬ 36    πŸ“Œ 31

@catc0n is following 20 prominent accounts