My latest mix from August 3rd is out now:
www.youtube.com/watch?v=D9w-...
soundcloud.com/djscottv/bas...
www.mixcloud.com/djscottv/bas...
@flakshack.bsky.social
Your friendly neighborhood Cybersecurity DJ. #netsec #sysadmin #cybersecurity #python #powershell #legal #it #technology #house #dj #f1 Latest DJ Mix (8/3): https://youtu.be/D9w-XWHB2QE
My latest mix from August 3rd is out now:
www.youtube.com/watch?v=D9w-...
soundcloud.com/djscottv/bas...
www.mixcloud.com/djscottv/bas...
Pacer court system that handles filings for federal district courts has been hacked. Their systems have long been underfunded. Hopefully this will encourage some change.
07.08.2025 16:35 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0why is no one capable of basic appsec these days?
25.07.2025 17:10 โ ๐ 0 ๐ 1 ๐ฌ 0 ๐ 0Clorox is claiming in a lawsuit that a Cognizant help desk worker reset Okta and Microsoft passwords three different times for a cybercriminal without verifying who was asking
Clorox says it lost $380 million from the August 2023 hack
therecord.media/clorox-cyber...
If you run VMware vSphere/vCenter/ESXi at your company, take some time to read this breakdown of an attack.
Attackers showing a very high level of sophistication and persistence even after discovery. This is the stuff of nightmares.
Wow. Spain is putting salt typhoon out of business. They are just going to hand it all to them: Huawei contracted to manage their wiretapsโฆ.
therecord.media/spain-awards...
After their first year, law students generally work summers at various law firms. It's a cross between an internship and job interview. "Above the Law" reports here on one of these summer associates that was let go because she was biting her coworkers.
14.07.2025 14:25 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0New Google Chrome zero-day. Update your browser now.
thehackernews.com/2025/07/goog...
Screenshot of malware page where attacker asks victim to press CTRL-S to save the page and rename with .HTA extension.
New variation of the "FileFix" attack works by convincing end users to save a malware web page to disk and rename the extension.
www.bleepingcomputer.com/news/securit...
This is hilarious. Senators under cyberattack by nation states and the FBI's advice is to avoid clicking on untrusted links.
01.07.2025 15:31 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 1Two good security discussions on Reddit:
www.reddit.com/r/cybersecur...
www.reddit.com/r/cybersecur...
Remove Default Microsoft Store packages from the system
If you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.
Windows 11 25H2 build 26200.5670
Increase in recon scanning for MOVEit (file transfer) systems implies new attack forthcoming.
These systems are highly desirable because rather than just being a beachhead to launch other attacks, attackers get instant access to the confidential data.
People in the southeast US reporting seeing fireballs in the sky during the day today. This is the Bootid Meteor Shower that is expected to peak tomorrow.
www.space.com/stargazing/t...
New Cisco ISE 10.0 vulnerability. ISE is a high value target for attackers, equal or close to a Domain Controller compromise.
It is unfortunate that Cisco ISE patches and upgrades have such a high risk and failure rate (in our experience).
Any IT person that has had to deal with court IT services knows that they are often woefully underfunded and terribly outdated. We often had to implement special controls because their sites required risky Java or ActiveX years after browsers had dropped support.
26.06.2025 17:01 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0A quick search shows that this isn't even the first time this has happened. Estimates of 50-100 people have died as a direct result of ransomware.
26.06.2025 16:53 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0New WinRAR vulnerability allows an attacker to trigger an execution when extracting an archive. Patch released yesterday.
www.bleepingcomputer.com/news/securit...
nobody reverse this patch ๐คช
doublepulsar.com/citrixbleed-...
Attackers uploaded malware apps to the Google and Apple app stores that try to steal photos and screenshots of crypto wallet recovery keys.
24.06.2025 15:53 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0New variation on the ClickFix attacks tries to convince the victim to paste a malicious command into a Windows File Explorer window (launched by the browser).
24.06.2025 15:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Latest DJ mix of chill downtempo electronica and progressive house for your 6 AM ride home after the club.
๐ง๐ถ๐ง๐ถ
Tenable announces multiple privilege escalation vulnerabilities in their Tenable Agent software.
Note that while most agents should be self-updating, they had issues in recent months that broke the self-update for some agents. If your systems are properly updating, they should be on 10.9.0 now.
Microsoft's failure to provide an API for light and fan controls continues to lead to problems as vendors must write kernel mode drivers to be able to do this themselves... As a result, otherwise minor security failures become complete system compromises.
17.06.2025 17:20 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Article discusses recent attack on Freedman Healthcare. Worth noting is how the attackers have moved from ransomware to straight data theft and extortion.
www.theregister.com/2025/06/16/e...
Congress actually trying to do something useful for once.
17.06.2025 17:08 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0One more time, here is EFF/Freedom of the Press' guide for journalists securing their devices to cross the US border.
Stories like Alistair's help us understand the real threats on the ground and allow us to threat model more accurately.
freedom.press/digisec/blog...
-suspected APT
-targeted MSFT accounts
-targeted natsec and economic policy reporters
-breach discovered Thursday
-staff notified today
NEW: Palantir threatened to call police on @wired.com reporter @carolinehaskins.bsky.social and kicked out other journalists from a recent conference following reports of the data analytics firm's work with the Trump administration. @carolinehaskins.bsky.social reports www.wired.com/story/palant...
05.06.2025 19:23 โ ๐ 914 ๐ 446 ๐ฌ 20 ๐ 23