Kevin Poireault's Avatar

Kevin Poireault

@leekthehack.bsky.social

Tech reporter https://linksta.cc/@kevinpoireault

140 Followers  |  825 Following  |  195 Posts  |  Joined: 20.09.2023  |  2.1695

Latest posts by leekthehack.bsky.social on Bluesky

Post image

๐—ก๐—˜๐—ช - ๐—จ๐—ž'๐˜€ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ง๐—ฒ๐—น๐—ฐ๐—ผ๐˜€ ๐—•๐—น๐—ผ๐—ฐ๐—ธ๐˜€ ๐Ÿญ ๐—•๐—ถ๐—น๐—น๐—ถ๐—ผ๐—ป ๐— ๐—ฎ๐—น๐—ถ๐—ฐ๐—ถ๐—ผ๐˜‚๐˜€ ๐—ฆ๐—ถ๐˜๐—ฒ ๐—”๐˜๐˜๐—ฒ๐—บ๐—ฝ๐˜๐˜€

Almost one billion early-stage cyber-attacks have been prevented in the past year in the UK thanks to Share and Defend, a service run by @ncsc.gov.uk.

www.infosecurity-magazine.com/news/uk-cybe...

03.12.2025 16:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐—ก๐—˜๐—ช - ๐—จ๐—ž ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ฃ๐—ฎ๐˜†๐—บ๐—ฒ๐—ป๐˜ ๐—•๐—ฎ๐—ป ๐˜๐—ผ ๐—–๐—ผ๐—บ๐—ฒ ๐˜„๐—ถ๐˜๐—ต ๐—˜๐˜…๐—ฒ๐—บ๐—ฝ๐˜๐—ถ๐—ผ๐—ป๐˜€

Speaking at the @financialtimes.com's Cyber Resilience Summit: Europe today, British Security Minister Dan Jarvis said the ban on ransomware payments will include "national security exemptions."

www.infosecurity-magazine.com/news/uk-rans...

03.12.2025 16:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ‘€ VulnWatch Monday: CVE-2025-35028 ๐Ÿ”“

A critical vulnerability was found by the Austin Hackers Association in HexStrike AI MCP server.

takeonme.org/cves/cve-202...

01.12.2025 15:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ”Ž VulnWatch Friday: CVE-2025-66022 ๐Ÿ”“

A critical vulnerability was discovered in Faction, a pentesting report generation framework developed by Faction Security.

๐Ÿ”ง This issue has been patched in version 1.7.1.
๐Ÿ”Ž nvd.nist.gov/vuln/detail/...

28.11.2025 15:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐—ก๐—˜๐—ช - ๐—™๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ต ๐—™๐—ผ๐—ผ๐˜๐—ฏ๐—ฎ๐—น๐—น ๐—™๐—ฒ๐—ฑ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฆ๐˜‚๐—ณ๐—ณ๐—ฒ๐—ฟ๐˜€ ๐——๐—ฎ๐˜๐—ฎ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต

๐Ÿ‡ซ๐Ÿ‡ท The FFF detected unauthorized access to the software platform used by all licensed football clubs in France to manage administrative tasks, incl. registering their players with the federation.

๐Ÿ“ฐ www.infosecurity-magazine.com/news/french-...

28.11.2025 11:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ‡ฌ๐Ÿ‡ง Cyber Security & Resilience Bill: Key Changes Revealed

Shona Lester, Head of CSR Bill Team, just shared the bill's key provisions.

Hereโ€™s whatโ€™s coming:
โ˜‘๏ธ Expanded Regulatory Scope
โ˜‘๏ธ Enhanced Incident Reporting
โ˜‘๏ธ Strengthened Regulatory Powers

๐Ÿ“ฐ www.infosecurity-magazine.com/news/key-pro...

27.11.2025 10:47 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Pour les plus friands de dรฉtails techniques mais pas forcรฉment anglophones, jโ€™ai aussi concoctรฉ un tableau rรฉsumant les rรฉsultats de lโ€™analyse des chercheurs, ร  dรฉcouvrir ici : datawrapper.dwcdn.net/Ea0qo/13/

25.11.2025 13:40 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Votre VPN est-il vulnรฉrable ร  la censure numรฉrique ?

Des chercheurs de lโ€™IIIT Delhi, en Inde, se sont demandรฉ dans quelle mesure un gouvernement pourrait dรฉtecter du trafic VPN et ainsi (potentiellement) le bloquer.

On vous explique ce qu'ils ont trouvรฉ โฌ‡๏ธ

coupecircuit.substack.com/p/vpn-voici-...

25.11.2025 13:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿšจ ๐Ž๐ฉ. ๐„๐ง๐๐ ๐š๐ฆ๐ž 3.0 ๐ƒ๐ข๐ฌ๐ฆ๐š๐ง๐ญ๐ฅ๐ž๐ฌ ๐‘๐ก๐š๐๐š๐ฆ๐š๐ง๐ญ๐ก๐ฒ๐ฌ, ๐•๐ž๐ง๐จ๐ฆ๐‘๐€๐“ ๐š๐ง๐ ๐„๐ฅ๐ฒ๐ฌ๐ข๐ฎ๐ฆ

The third "season" of Operation Endgame resulted in:
๐Ÿ—„๏ธ Over 1025 servers taken down or disrupted
๐ŸŒ 20 domains seized
๐Ÿšช 11 locations searched
๐Ÿ‘ฎ One arrest

๐Ÿ“ฐ www.infosecurity-magazine.com/news/operati...

13.11.2025 13:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐๐Ž๐ƒ๐‚๐€๐’๐“ - ๐‡๐จ๐ฐ ๐๐ซ๐ข๐ฏ๐š๐ญ๐ž ๐‘๐ž๐ฌ๐ž๐š๐ซ๐œ๐ก๐ž๐ซ๐ฌ ๐€๐ซ๐ž ๐“๐š๐ค๐ข๐ง๐  ๐ƒ๐จ๐ฐ๐ง ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž ๐Ž๐ฉ๐ž๐ซ๐š๐ญ๐ข๐จ๐ง๐ฌ

I sat down with Matthew Maynard, a cybersecurity pro by day and a cyber ghost-buster by night, who doesnโ€™t just hunt vulnerabilities, but haunts the hackers themselves.

๐ŸŽง Listen here: feeds.soundcloud.com/users/soundc...

05.11.2025 11:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Russia may be behind European airport cyber attacks: 'Anything is possible'
YouTube video by Times Radio Russia may be behind European airport cyber attacks: 'Anything is possible'

My post is mainly about the thumbnails above and below. The videos from the Times Radio actually show good reporting. But I feel like many people seeing these thumbnails will immediately believe "The Times is claiming it comes from the Kremlin." (5/5)

www.youtube.com/watch?v=GPoe...

22.09.2025 19:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Journalists (and politicians) have a responsibility to avoid amplifying unproven claims, no matter how tempting the headline. Letโ€™s demand evidence-first reporting, even when the story is breaking. (4/5)

22.09.2025 19:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Airports latest: Government must say if Russia behind European airport cyber attack chaos, Lib Dems demand Multiple European airports have said they have been impacted by a suspected cyber attack, with Heathrow passengers stranded for hours and flights cancelled in Brussels.

I understand why this framing exists: The Lib Demsโ€™ statement is newsworthy, and Putinโ€™s image drives clicks. But at this stage, I believe there is no public evidence linking Russia (or any state actor) to this attack. (3/5)

news.sky.com/story/cyber-...

22.09.2025 19:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Heathrow cyber attack brings chaos and disruption: Is Putin responsible?
YouTube video by Times Radio Heathrow cyber attack brings chaos and disruption: Is Putin responsible?

But when a major outlet like The Times frames the story with Vladimir Putinโ€™s face, amplifying the Lib Demsโ€™ call for the government to disclose Kremlin involvement, it risks prioritizing engagement over evidence. (2/5)

www.youtube.com/watch?v=xZ_3...

22.09.2025 19:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Airport Chaos Enters Third Day After Supply Chain Attack Heathrow, Brussels, Dublin and Berlin airports are among those disrupted by a cyber-attack on Collins Aerospace

๐˜—๐˜ฆ๐˜ณ๐˜ด๐˜ฐ๐˜ฏ๐˜ข๐˜ญ ๐˜ฐ๐˜ฑ๐˜ช๐˜ฏ๐˜ช๐˜ฐ๐˜ฏ: ๐‚๐ฒ๐›๐ž๐ซ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐‘๐ž๐ฉ๐จ๐ซ๐ญ๐ข๐ง๐  ๐’๐ก๐จ๐ฎ๐ฅ๐๐งโ€™๐ญ ๐‰๐ฎ๐ฆ๐ฉ ๐ญ๐จ ๐†๐ž๐จ๐ฉ๐จ๐ฅ๐ข๐ญ๐ข๐œ๐š๐ฅ ๐‚๐จ๐ง๐œ๐ฅ๐ฎ๐ฌ๐ข๐จ๐ง๐ฌ (๐„๐ฌ๐ฉ๐ž๐œ๐ข๐š๐ฅ๐ฅ๐ฒ ๐–๐ข๐ญ๐ก๐จ๐ฎ๐ญ ๐„๐ฏ๐ข๐๐ž๐ง๐œ๐ž)

The latest cyberattack on airports is a serious incident that warrants thorough investigation. (1/5)

www.infosecurity-magazine.com/news/airport...

22.09.2025 19:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image

EXCLUSIVE - Why Three Vendors Pulled Out of โ€˜Cybersecurity Olympicsโ€™

Microsoft, SentinelOne and Palo Alto Networks have decided not to take part in the 2025 edition of MITREโ€™s EDR test.

I spoke with MITRE CTO to understand what motivated these moves.

www.infosecurity-magazine.com/news/cyber-v...

22.09.2025 13:03 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cyberattack on K Club before Irish Open The five-star resort was hit by a ransomware attack, with leaked data including financial records, IT documentation and administrative information

Hackers calling themselves SafePay. carried out a ransomware attack on the five-star K Club resort in Co Kildare as it prepared to host some of the worldโ€™s top golfers at the Irish Open this past weekend.
www.thetimes.com/world/irelan...

08.09.2025 12:29 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cybersecurity firm Netskope eyes up to $6.5 billion valuation in US IPO Netskope is seeking a valuation of up to $6.5 billion in its initial public offering in the United States, the cloud-based cybersecurity firm said on Monday, signaling investors' appetite for new listings.

Cybersecurity firm Netskope eyes up to $6.5 billion valuation in US IPO
www.reuters.com/business/cyb...

08.09.2025 12:22 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Do Security Blogs Enable Vibe-Coded Cybercrime? Security companies routinely publish detailed analyses of security incidents, making attacker tactics, techniques, and procedures (TTPs) widely known and visible. These reports often provide comprehen...

Hackers are using security reports to translate technical problems into โ€œpartial malicious codeโ€ as part of the โ€œvibe codingโ€ trend.
www.trendmicro.com/vinfo/us/sec...

04.09.2025 10:39 โ€” ๐Ÿ‘ 5    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
US: CISA 2015 Safe Harbor at Risk as September 2025 Deadline Nears The deadline for the reauthorization of the US Cybersecurity Information Sharing Act is September 30

๐Ÿ“ฐ Read the full article here: www.infosecurity-magazine.com/news-feature...

02.09.2025 11:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐‚๐ˆ๐’๐€ 2015 ๐’๐š๐Ÿ๐ž ๐‡๐š๐ซ๐›๐จ๐ซ ๐š๐ญ ๐‘๐ข๐ฌ๐ค ๐š๐ฌ ๐’๐ž๐ฉ๐ญ๐ž๐ฆ๐›๐ž๐ซ 30 ๐ƒ๐ž๐š๐๐ฅ๐ข๐ง๐ž ๐๐ž๐š๐ซ๐ฌ

โŒ›As the expiration date for the Cybersecurity Information Sharing Act of 2015 looms in the US, I spoke to experts about the provisions the Act offers and the debates surrounding the renewal and the consequences of non-renewal.

02.09.2025 11:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐•๐จ๐ญ๐ซ๐ž ๐•๐๐ ๐ž๐ฌ๐ญ-๐ข๐ฅ ๐ฎ๐ง ๐œ๐ก๐ž๐ฏ๐š๐ฅ ๐๐ž ๐“๐ซ๐จ๐ข๐ž ๐œ๐ก๐ข๐ง๐จ๐ข๐ฌ ? ๐Ÿ‡จ๐Ÿ‡ณ

Dโ€™aprรจs 3 รฉtudes, des dizaines dโ€™applis VPN (Google Play Store/Apple App Store) sont liรฉes entre ellesโ€ฆ et certaines appartiennent ร  Qihoo 360, proche de lโ€™armรฉe chinoise.

๐Ÿ”— Nouvelle รฉdition de Coupe-Circuit : open.substack.com/pub/coupecir...

31.08.2025 15:29 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Security Advisory: Please Lock Down Your Administrator Access The Sangoma FreePBX Security Team is aware of a potential exploit affecting some systems with the administrator control panel exposed to the public internet, and we are working on a fix, with expected...

๐Ÿ”Ž Security advisory: community.freepbx.org/t/security-a...
๐Ÿ’พ Download JSON: cveawg.mitre.org/api/cve/CVE-2

29.08.2025 14:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The critical flaw, tracked as CVE-2025-57819, affects FreePBX versions 15, 16 and 17. When exploited, it can allow unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.

๐Ÿ”ง Fix? FreePBX 15.0.66, 16.0.89 and 17.0.3.

29.08.2025 14:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿ”Ž VulnWatch Friday: CVE-2025-57819 ๐Ÿ”“

The Sangoma FreePBX Security Team has warned of a vulnerability being exploited in the wild.

FreePBX is an open-source graphical user interface (GUI) for managing Asterisk, the popular open-source Private Branch Exchange (PBX) and telephony platform.

29.08.2025 14:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Citrix Patches Three Zero Days as One Sees Active Exploitation Citrix customers are urged to patch their vulnerable NetScaler appliances, but โ€œpatching alone wonโ€™t cut it,โ€ experts said

๐Ÿ“ฐ My story on Infosecurity Magazine: www.infosecurity-magazine.com/news/citrix-...
๐Ÿ”Ž Citrix's security advisory: support.citrix.com/support-home...

27.08.2025 10:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿง VulnWatch Wednesday: CVE-2025-7775 ๐Ÿ”“

Citrix has released patches for three critical zero days in NetScaler ADC and Gateway, one of which was already being exploited by attackers.

According to Kevin Beaumont, exploit campaigns ๐ŸŽฏCVE-2025-7775 began before the patches were made available.

27.08.2025 10:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Public Exploit Released for Critical SAP NetWeaver Flaw A critical flaw in SAP NetWeaver AS Java is being widely exploited, allowing unauthenticated remote code execution

๐Ÿ“ฐ Read our latest story on Infosecurity Magazine: www.infosecurity-magazine.com/news/sap-net...
๐Ÿ’พ Download JSON: cveawg.mitre.org/api/cve/CVE-...

20.08.2025 16:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿง VulnWatch Wednesday: CVE-2025-31324 ๐Ÿ”“

A critical vulnerability in SAP NetWeaver is now being widely exploited following the release of public exploit tooling.

๐Ÿ†• The public availability of the full source code makes the exploit easy to use even for attackers with little technical expertise.

20.08.2025 16:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
SpyVPN: The Google-Featured VPN That Secretly Captures Yourย Screen | Koi Blog FreeVPN.One, a Chrome-verified extension with over 100K installs, claimed to offer privacy but instead captured usersโ€™ screens. Our research exposes how it operated.

๐Ÿ”Ž Read the full Koi Security report here: koi-security.webflow.io/blog/spyvpn-...

19.08.2025 13:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@leekthehack is following 19 prominent accounts