@mjidhage.bsky.social
Security Janitor
📣 Säkerhetspodcasten #294 - Ostrukturerat V.50 📣 Sha-Hulud 2.0 NPM/Github/PostHog hack, Glassworm gömmer sitt malware med Unicode Variation Selectors, ShadyPanda Browser Malware, CloudFlare/Rust krash, Ryska hackers trashar OT/ICS honypot, React2Shell, Pixelnapping spionerar på din OTP, Flock...
08.12.2025 13:46 — 👍 3 🔁 2 💬 0 📌 0Last week @theverge.com published my essay exploring the limitations of large-language models. This week, that same essay is cited by a federal judge in Michigan to distinguish the process of human reasoning from what these models do. Very, very gratifying.
03.12.2025 21:04 — 👍 1562 🔁 365 💬 24 📌 13React Developers: I need you to upgrade right now. I don't ring the alarm bell often, but this time I am. It's similar to Log4j, but not yet exploited in the wild. This is quite serious, please upgrade now.
03.12.2025 20:04 — 👍 14 🔁 12 💬 1 📌 2📣 Säkerhetspodcasten #293 - Molnet Har Fallit 📣 Molnet har fallit. Två stora hyperscalers har gått ner. AWS står och brinner. Zombies vandrar runt i Azure’s datahallar. Säkerhetspodcasten försöker leda dig genom den post-apokalyps vi nu lever i, tiden efter att molnet gick ner.
Körde du EKG över...
The first thread is good. It makes sense and is accurate. 9/10 times (and maybe even 10/10) you are not targeted. You are simply an opportunistic victim who was the easiest out of a dozen to run copy/paste commands against. Do the basics of cybersecurity and save yourself a crisis. As for the second thread, you hit it perfectly for me. I am a firm believer of "the person behind the keyboard" a computer is just a tool, a means, an endpoint... what you actually have to realize is the human factor of it all.
A Counter-Threat Intelligence lead for a major firm, who runs a team penetrating hacker networks to uncover new threats and comments about their company, and this is their reply to this thread. (posted with permission)
The mythology around hackers is wildly oversold. But defense requires doing it.
Vilken överraskning!
www.dn.se/direkt/2025-...
📣 Säkerhetspodcasten #292 - Ostrukturerat V.46 📣 Mössen lyssnar, Secret Service hittar SIM-kort, TPM-diskussion, Unity sårbarhet, Oracle SSRF RCE, Osignerade tokens till Azure Graph API, Signal PQC Ratchet, OSINT mot FSB, Malware i din jobbintervju.
01:13:21 Försnack Rickard pratar om varför han...
Look at this ridiculous primitive country, casting out its sex pests rather than making them Presidents or Mayors or Supreme Court justices
30.10.2025 20:25 — 👍 4224 🔁 782 💬 123 📌 21Goda nyheter! Danmark ger upp sitt försök att få igenom kravet på massövervakning och bakdörrar i totalsträckskrypterade meddelandeappar! politiken.dk/viden/art106...
#ChatControl
We trusted images because they were hard to fake. That assumption is dead. Authentication must shift to cryptographic signatures from photographers and publishers. Trust becomes transitive: you trust the image only to the extent you trust its signer.
29.10.2025 01:33 — 👍 3 🔁 2 💬 1 📌 0📣 Säkerhetspodcasten #291 - Kubernetes Drivers 📣 Kubernetes och CSI/CNI/… driver-infrastrukturen, Priviligerade tjänster (DaemonSet) - vilka hål kan det finns det där? Hur illa kan det gå om det är dåligt konf’at eller om ondingar kan pilla på konfigurationen?
Varför kräver vissa typer av...
Oh! And if you're a $3 and up subscriber, it's free to download: www.patreon.com/posts/131427...
15.10.2025 01:52 — 👍 16 🔁 12 💬 1 📌 0"Child protection" is one of the two main means by which states attempt to manufacture a convincing enough "compelling state interest" for a law to survive strict scrutiny (the other is "preventing terrorism".)
15.10.2025 01:58 — 👍 131 🔁 15 💬 2 📌 0Thus we score with the worst possible case in mind, a security feature bypass which changes scope.
Is that likely? No, probably not unless your application code is doing something odd and skips a bunch of checks that it ought to be making on every request.
But please go update.
(4/7)
📣 Säkerhetspodcasten #290 - Ostrukturerat V.42 📣 VPN med e-identitet/BankID. RedHat, Discord läckor. DrayTek och CISCO hål. Audacity, Qualcomm, Arduino - off-topic!
52:28 Plugs Vi promotar random kul vagt relaterat till säkerhet:
Security Fest: WWWInterpub Friday, November 7, 2025 Lyssnarfråga...
Är det inte sent att göra en sådan översyn efter att lagarna är på plats?
Borde inte det arbetet vara del i det underlag som tas fram innan man tar beslut?
Har för mig att visst förberedande arbete gjordes inför första vändan? Med resultat att flera remissinstanser var negativa?
This is an EU proposed policy with the benign-sounding name "Child Sexual Abuse Regulation" which proposes to screen private online communications using sketchy image-scanning algorithms. It is technically unworkable, and would be a privacy catastrophe, especially for those in authoritarian states
06.10.2025 08:42 — 👍 155 🔁 67 💬 4 📌 1📣 Germany's close to reversing its opposition to mass surveillance & private message scanning, & backing the Chat Control bill. This could end private comms-& Signal-in the EU.
Time's short and they're counting on obscurity: please let German politicians know how horrifying their reversal would be.
📣 Säkerhetspodcasten #289 - Ostrukturerat V.41 📣 SEC-T. Självrefererande Git. NPM: S1ngularity, och Shai-Hulud. Massa randomware och läckor: Miljödata, Jaguar LandRover (JLR), Collins, Kinesiska Muren (GFwC). Minnesskydd. Kassa kassaskåp! WhatsApp/iOS/DNG attack. Hotaktör säkrar dina server....
06.10.2025 08:01 — 👍 6 🔁 2 💬 0 📌 0Vårt motto: ”Hellre bra än dåligt”
01.10.2025 17:24 — 👍 7 🔁 1 💬 0 📌 0Tung och grafiskt imponerande granskning. Kudos @lisarostlund.bsky.social special.aftonbladet.se/story/3MvXrL
17.09.2025 12:07 — 👍 9 🔁 1 💬 1 📌 0We are all made of stars, but your RBAC shouldn’t be
21.07.2025 13:28 — 👍 305 🔁 39 💬 10 📌 4Grillöl
Tack för anekdoterna, det fick bli (impromptu) grillad lövbiff.
03.09.2025 18:37 — 👍 1 🔁 1 💬 0 📌 0📣 Säkerhetspodcasten #288 - Era Anekdoter 📣 Lyssnarna hör av sig om befängda API-servers, och skolan som ger elever för mycket rättigeter.
35:32 Plugs Building Secure AI, Stockholm, 23-24 September 2025 Lyssnarbrev om galen JSON (Google transkribering av ljudfil, samt mindre manuella...
We must seize the means of computation
20.08.2025 03:19 — 👍 25 🔁 1 💬 2 📌 0Phrack 40th Anniversary ansi art by Harvest
Phrack turns 40.
The digital drop is live.
Download it. Archive it. Pass it on.
💾 www.phrack.org
#phrackat40 #phrack72
Great resource from @eff.org as always
17.08.2025 21:14 — 👍 4 🔁 6 💬 0 📌 0Desinformationskampanj som ligger väl i tid med lansering av nytt chatcontrol-förslag?
15.08.2025 06:54 — 👍 2 🔁 1 💬 0 📌 0Polisens smutskastning av Signal fortsätter. Rikspolischef Petra Lundh sade precis i SVT Morgonstudion att Signal inte har något normalt användningsområde (i en kommentar om barns användande av Signal). www.svt.se/nyheter/inri... 52:45
(Via Jonas Säkerhetsbubblan.)