Bill
@sempf.infosec.exchange.ap.brid.gy
📤 95
📥 7
📝 3357
I break software. 🌉 bridged from ⁂
https://infosec.exchange/@Sempf
, follow
@ap.brid.gy
to interact
I carefully curate my feeds here and on Reddit, probably the only two real social networks that I hang out on. LinkedIn is so much harder to fine-tune your feed. There are just so many options that it's impossible to pick some. You know what I mean? It's out of this world how they manage to […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@Sempf/116404997406926646
about 11 hours ago
0
0
0
I am grilling chicken thighs on the gas grill. I have an aluminium foil tray under them, and I have indirect heat to the left and right. Everybody, think non-firy thoughts for the next forty-five minutes or so, please. 🐔 🔥
about 11 hours ago
0
0
0
Glasswing may be the most sophisticated undercover marketing campaign in the history of mankind.
about 13 hours ago
0
0
0
This is a picture of a stalk of asparagus growing in the middle of a lemon balm patch. Now, that would seem to be odd, and I agree, but I have grown asparagus before. However, where I had it is fully 30 ft from where that stalk is growing. This isn't the […]
[Original post on infosec.exchange]
about 18 hours ago
1
0
0
"Anthropic is supporting Project Glasswing with $100 million in Mythos Preview usage credits..." Mmm hmm. https://www.darkreading.com/cloud-security/csa-cisos-prepare-post-mythos-exploit-storm
#mythos
#marketing
1 day ago
1
0
0
TIL Slack has "huddles."
1 day ago
3
0
0
These awesome apple blossoms brought to you by an actual Johnny Appleseed apple tree grown from seeds harvested from his grove in Medina, Ohio.
1 day ago
0
0
0
When Mistral Vibe is thinking, it puts up random "statements of work" like "Contemplating the universe" or "Buttering my toast" The last one to go by was "counting the Rs in Strawberry" which tends to make me think that vibe coding will have lore and canon all its own.
1 day ago
0
0
0
Bloomberg is covering Mythos. The journalists are VERY skeptical, and the AIBros are all like "THIS SHOULD BE A GLOBAL LAW EVERYONE SHOULD TEST WITH THIS AAAH WE ARE ALL GONNA DIE." OH man they have Kara Sprague on and she is speaking truth. THANK goodness. And now it's kreiger "OH NOT THIS IS […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@Sempf/116398049505236874
1 day ago
0
2
12
2 days ago
0
0
1
#silentsunday
loading . . .
3 days ago
0
1
0
Could prospects for breakfast look any better? I think not.
3 days ago
0
1
0
I just discovered Warhammer 40k Terminus and WHY DIDN'T YOU ALL TELL ME ABOUT THIS GAME?!??!
3 days ago
1
0
0
At the Columbus Museum of Art and somehow I think everything is gonna be ok.
3 days ago
0
0
0
In a few months my Reddit account will be legal to drink.
4 days ago
0
0
0
Oooh boy, Microsoft has some thoughts about AI in the SOC. https://www.microsoft.com/en-us/security/blog/2026/04/09/the-agentic-soc-rethinking-secops-for-the-next-decade/
#microsoft
#agenticai
loading . . .
https://www.microsoft.com/en-us/security/blog/2026/04/09/the-agentic-soc-rethinking-secops-for-the-next-decade/
4 days ago
0
0
1
I don't remember who mentioned Littlesnitch for Linux, but HOLY CRAP is it neat. Mighta been @viss? I don't know but damn, thannks.
5 days ago
0
0
1
For those getting questions about Glasswing from their executives, give them this article.
https://tryaether.ai/blog/anthropic-glasswing-frontier-attack
loading . . .
While Everyone Watches Glasswing, Attackers Are Walking Through Your Front Door. - Aether AI
Aether AI's agents pressure test your attack surface continuously, across every attack vector, internally and externally. The same agents then dynamically generate the unique defensive signals required to protect your organisation at machine speed.
https://tryaether.ai/blog/anthropic-glasswing-frontier-attack
6 days ago
0
0
0
Fuck. "The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database [...]" h/t
@404mediaco
6 days ago
1
0
0
The Ohio Renaissance Festival utterly shut down Bigtickets.com.
6 days ago
0
0
0
"Conviction is sufficient." That is a powerful, terrifying statement.
6 days ago
0
0
0
The
@eff
has an epic writeup about how the Arab spring was a catalyst for authoritarian information gathering and then there changes to digital life. Three part series. https://www.eff.org/deeplinks/2026/04/digital-hopes-real-power-how-arab-spring-fueled-global-surveillance-boom
#arabspring
[…]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@Sempf/116372681782111378
6 days ago
0
0
0
Oh look. I need to not be on social media today.
7 days ago
2
0
0
Good writeup on
@wdormann
's recent efforts. https://securityaffairs.com/190400/breaking-news/experts-published-unpatched-windows-zero-day-bluehammer.html
#0day
#microsoft
loading . . .
Experts published unpatched Windows zero-day BlueHammer - Security Affairs
A researcher leaked the unpatched Windows zero-day “BlueHammer,” letting attackers gain SYSTEM rights; no patch exists yet. A disgruntled researcher released the BlueHammer Windows zero-day, a privilege escalation flaw that allows attackers to gain SYSTEM or admin rights, Bleeping Computer reports. The researcher privately reported the vulnerability to Microsoft but criticized the way the Microsoft’s Security […]
https://securityaffairs.com/190400/breaking-news/experts-published-unpatched-windows-zero-day-bluehammer.html
7 days ago
0
0
1
We have the NEST cyber security in 200 years!!! When will you all get tired if WINNING!?!?! https://www.securityweek.com/white-house-seeks-to-slash-cisa-funding-by-707-million/
#usgov
#cisa
7 days ago
0
0
0
Putting hidden text in web pages just to pwn AI agents for fun and profit sounds like a good time. https://www.securityweek.com/google-deepmind-researchers-map-web-attacks-against-ai-agents/
#agenticai
#posioning
8 days ago
1
0
3
Aww food crunchyroll was breached. Now everyone will know I ... uuuuh so they were breached! https://haveibeenpwned.com/Breach/Crunchyroll
#breach
#anime
loading . . .
Crunchyroll - 1,195,684 breached accounts
In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users. The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the contents of the support tickets" were exposed. A subset of 1.2M email addresses from an alleged 2M record dataset being sold was later provided to HIBP.
https://haveibeenpwned.com/Breach/Crunchyroll
10 days ago
1
0
0
Dammit. I already marinated the lamb!
10 days ago
0
0
0
Hey, you! Yeah you, all hunched over like a croissant in your screen-lit windowless room. Go the fuck outside.
11 days ago
0
0
0
ATTACK OF THE KILLER WASP BUTTS!!!
11 days ago
0
0
0
@Gabrielle
just made a remote control lava lamp!
11 days ago
0
0
0
reposted by
Bill
Barry Dorrans
11 days ago
v.1.8.0 of my .NET Bluesky library has dropped. Highlights include Bot property on profile views Protections against malicious handles and did docs introducing SSRF vulnerabilities Protections against a malicious sending messages about a max size Metrics Support
loading . . .
Release v.1.8.0 · blowdart/idunno.Bluesky
Added idunno.AtProto Added metrics in AtProtoHttpClientMetrics including request duration, request count and failure count. Added metrics in DidPlcDirectory including request duration, request cou...
https://github.com/blowdart/idunno.Bluesky/releases/tag/v1.8.0
4
18
5
Weather forecasting in the 614 has just sucked this week. Every day this week, Wednesday, Thursday, Friday, Saturday, they said thunderstorms, rain all day. It's going to be sloppy and warm and humid and gross, and it was absolutely beautiful every single day.
#ohwx
11 days ago
0
0
0
Talos found this ginormous automated React2Shell exploitation scheme for credential harvesting at scale. I'll bed the SOB was vibe coded, too. https://www.securityweek.com/react2shell-exploited-in-large-scale-credential-harvesting-campaign/
#react2shell
#breach
11 days ago
0
0
0
Nopesauce on a fresh fried tilapia sandwich. 🧑🏻🍳💋
11 days ago
0
0
0
We need a new XKCD with the swordfighting that says "Waiting for the AI"
11 days ago
0
0
0
OK, Trends in Appsec talk given twice in one week. That HAS to be a record.
12 days ago
0
0
0
"I checked DownDetector to see if there was an Outlook outage, but I could not find a version of DownDetector that covers space." […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@Sempf/116338848038646822
12 days ago
0
0
0
Kine of a neat vulnerability discovered in the OWASP Common Rule Set. Test your stuff on Windows folks! https://seclists.org/fulldisclosure/2026/Apr/0
#owasp
#cve
loading . . .
Full Disclosure: [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability
https://seclists.org/fulldisclosure/2026/Apr/0
12 days ago
0
1
0
This came out and I thought "Anyone actually using this with so many inexpensive commercial options right meow? Just future proofing?" Well, guess so https://www.securityweek.com/mercor-hit-by-litellm-supply-chain-attack/
#llm
#malware
12 days ago
1
1
1
OK, added AI to my Making and Baking an Application Security Department talk. See ya at
#stirtrek
!
12 days ago
0
0
0
Oh now I know it is spring. 🦨
12 days ago
0
0
0
I love the fact that pro football in Columbus has to play in a repainted soccer stadium. Heh heh heh.
12 days ago
0
0
0
Anyone feel the under boomer in the bay area?
12 days ago
1
0
1
RE: https://c.im/@columbusnewsbot/116335927266389479 Now we are crashing into banks.
#ohio
loading . . .
https://c.im/users/columbusnewsbot/statuses/116335927266389479
13 days ago
1
0
0
So how is the Fediverse doing today? POINT has been busier than hell, so I haven't been around reading stuff.
13 days ago
0
0
0
What the fuck does "detailed summary" even mean.
13 days ago
0
1
0
You know, when you have to go to the con web site to remember what talk you told them you were gonna give? Yeah, onea those days.
14 days ago
0
1
0
reposted by
Bill
Bruce Lawson ✅ ♫ ♿ ✌️♂️✊
15 days ago
I Decompiled the White House's New App
https://blog.thereallo.dev/blog/decompiling-the-white-house-app
The official White House Android app has a cookie/paywall bypass injector, tracks your GPS every 4.5 minutes, and loads JavaScript from some guy's GitHub Pages.
loading . . .
I Decompiled the White House's New App
The official White House Android app has a cookie/paywall bypass injector, tracks your GPS every 4.5 minutes, and loads JavaScript from some guy's GitHub Pages.
https://blog.thereallo.dev/blog/decompiling-the-white-house-app
1
0
9
Load more
feeds!
log in