Kevin Beaumont's Avatar

Kevin Beaumont

@doublepulsar.com.bsky.social

cybersecurity weather man. scanning the horizons for cloudy cyber. Expert at nothing except computer rubbish. Anti-ransomware since 2015.

13,372 Followers  |  148 Following  |  392 Posts  |  Joined: 23.04.2023  |  1.8385

Latest posts by doublepulsar.com on Bluesky

Post image

Payton lives on in the Lake District πŸ•

02.08.2025 05:57 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

God damn it

31.07.2025 10:05 β€” πŸ‘ 15    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Strange reply - just pointing out it’s for a different vuln, it’s mentioned in the link.

It does include threat intel btw - namely, that vuln is being used to drop webshells (including .xhtml ones, which is also new info).

27.07.2025 18:00 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

β€˜tis a different vuln - CVE-2025-6543

27.07.2025 16:21 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Tomorrow you will have no legs

26.07.2025 16:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It’s not weird to me, since it’s just something you’ve made up in your head 🀣

26.07.2025 16:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

My take is MAPP should be protected btw, it’s a net win regardless.

26.07.2025 06:31 β€” πŸ‘ 10    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

MSTIC had a running joke that MAPP’s acronym stood for Microsoft Arming People’s rePublic of china. 🀣

26.07.2025 06:08 β€” πŸ‘ 50    πŸ” 10    πŸ’¬ 2    πŸ“Œ 0
Preview
citrix-2025/TLPCLEAR_check_script_cve-2025-6543-v1.6.sh at main Β· NCSC-NL/citrix-2025 Contribute to NCSC-NL/citrix-2025 development by creating an account on GitHub.

Emerging situation to be aware of - some of the #CitrixBleed2 session hijacking victims are also victims of webshell implants via a different vuln, CVE-2025-6543.

Script to check for Netscaler implants: https://github.com/NCSC-NL/citrix-2025/blob/main/TLPCLEAR_check_script_cve-2025-6543-v1.6.sh

25.07.2025 11:34 β€” πŸ‘ 19    πŸ” 12    πŸ’¬ 1    πŸ“Œ 0
Post image

dear satya,

i have a new product idea

mustafa suleyman xoxo

25.07.2025 16:02 β€” πŸ‘ 10    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Microsoft Bob - Wikipedia

Shush you, he's inventing Microsoft Bob en.wikipedia.org/wiki/Microso...

25.07.2025 16:00 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Clean on OPSEC

24.07.2025 15:04 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Nobody tell the US Government representatives about Jen Easterly existing.

24.07.2025 13:59 β€” πŸ‘ 17    πŸ” 3    πŸ’¬ 3    πŸ“Œ 0

yeah it's nonsense.

24.07.2025 13:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

this is bollocks, FYI. It's a minor outage, stop using Downdetector graphs as the primary source.

24.07.2025 13:21 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I am debating about updating my CitrixBleed2 vulnerability tracking on Github to include which boxes were exploited, and by which IPs and when.

It's a real mess.

24.07.2025 12:27 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

I think CISA, UK NCSC and authorities in Germany likely need to get more proactive on #CitrixBleed2. Left is unpatched CitrixBleed 2, right is that SharePoint vuln.

One is a much, much bigger problem leading to nation state actors sat in inside remote access to networks - and it's the Citrix one.

24.07.2025 12:11 β€” πŸ‘ 14    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1
Preview
At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds Of those, more than 200 appear to have had outages of services related to patient care following CrowdStrike’s disastrous crash, researchers have revealed.

When, one year ago, a buggy update to software sold by the cybersecurity firm CrowdStrike took down millions of computers around the world and sent them into a death spiral of repeated reboots, the global cost of all those crashed machines was equivalent to one of the worst cyberattacks in history.

21.07.2025 14:23 β€” πŸ‘ 158    πŸ” 41    πŸ’¬ 8    πŸ“Œ 7
Preview
At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds Of those, more than 200 appear to have had outages of services related to patient care following CrowdStrike’s disastrous crash, researchers have revealed.

At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage

Wired piece: www.wired.com/story/at-lea...

Study: jamanetwork.com/journals/jam...

20.07.2025 16:55 β€” πŸ‘ 14    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

vim how do I quit vim

VIM: hello dave

18.07.2025 17:07 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image Post image Post image Post image

the enron book 'the smartest guys in the room' is good btw, it's about people who invented things and then booked profits on those things without checking if anybody actually wanted them

18.07.2025 16:59 β€” πŸ‘ 26    πŸ” 0    πŸ’¬ 3    πŸ“Œ 0
Preview
a cat sitting on a counter next to a roll of green tape ALT: a cat sitting on a counter next to a roll of green tape

As a companion to this skeet please know I've had a Microsoft exec tell me that with generative AI, they've invented electricity, and it was quite possibly the best moment of my life.

18.07.2025 16:47 β€” πŸ‘ 28    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Post image Post image Post image

The Hague’s Public Prosecution Service has a cybersecurity incident running and have shut down services, the NCSC are directing people to my blog with headers such as β€œChina goes brrr” and β€œRussia goes bleep boop”

18.07.2025 14:30 β€” πŸ‘ 28    πŸ” 5    πŸ’¬ 2    πŸ“Œ 0

I have this image saved on my phone camera reel as I get so much use out of it

18.07.2025 07:27 β€” πŸ‘ 448    πŸ” 187    πŸ’¬ 7    πŸ“Œ 1

🀣 last time I checked The UN still hadn’t patched.

17.07.2025 20:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A photo of a TV where a woman dressed as a ghost for the Eras Tour is interviewed by local news. The caption reads β€œWoman hides identity because she called in sick to work.”

A photo of a TV where a woman dressed as a ghost for the Eras Tour is interviewed by local news. The caption reads β€œWoman hides identity because she called in sick to work.”

Unlike CEOs and other executives, individual contributors understand concert OPSEC

17.07.2025 17:29 β€” πŸ‘ 15314    πŸ” 2657    πŸ’¬ 104    πŸ“Œ 130
Post image

They essentially didn't investigate it properly, their statement: www.linkedin.com/posts/inform...

and my view:

17.07.2025 15:37 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I'm not a fan of how the ICO investigated this, for the record.

17.07.2025 15:36 β€” πŸ‘ 8    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

lol at the image they use

17.07.2025 12:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 β€” nearly two weeks before a public proof-of-concept was released on July 4.

GreyNoise observed exploitation of CitrixBleed 2 (CVE-2025-5777) nearly two weeks before a public PoC was released. Full breakdown ⬇️
#GreyNoise #ThreatIntel #CitrixBleed #Citrix #NetScaler

16.07.2025 20:45 β€” πŸ‘ 7    πŸ” 8    πŸ’¬ 0    πŸ“Œ 0

@doublepulsar.com is following 19 prominent accounts