Tanawts

Things are not always what they seem

Redfin | Rent Head of Information Security

Former Ubisoft Director of Security Operations
Microsoft Alumni | Former Director of MSRC's Cloud Incident Response | He/Him/Hrm | Philosopher & Ninja

SANS:
GCIH #16353 - Cerified Incident Handler
GWAPT #3274- Web Application Pen Tester
GXPN #164 - Exploit Researcher and Advanced Penetration Tester

2026-02-07

@Viss *lightsaber noises*

2025-12-28

@GossiTheDog ok. Officially notified.

You feel strongly on the signs of IOC for that particular mongodb though?

2025-12-28

@GossiTheDog is the system in question still online or did you get an ack / confirmation the thing got pulled

Tanawts boosted:
2025-12-10

If you reward technology teams to ignore cybersecurity, they will.

If you think security teams can magically stop criminals and spies while this is happening, you are fooling yourself.

Tanawts boosted:
Tanawts boosted:
2025-09-17

That one is straight outta the UK LAPSUS playbook btw, eg they frequently get access to Azure and start spinning up VMs and using them to host data from other victims, they daisy chain them together like The Data Centerpede so every victim hosts other stolen data.

ReliaQuest may have been detailing the Prosper incident there, we’ll see.

Tanawts boosted:
2025-09-17

Jimmy Kimmel show got cancelled by his network for saying:

“The MAGA Gang desperately trying to characterize this kid who murdered Charlie Kirk as anything other than one of them and doing everything they can to score political points from it.. In between the finger-pointing, there was grieving,”

Good thing everybody is so concerned about free speech.

cnbc.com/2025/09/17/charlie-ki

2025-09-17

@GossiTheDog sigh

Yup... if the cloud fixes it and the customer doesnt have to take action for a fix, then it's mostly silent.

Due diligence review of potential post-breach unauthorized access is completely excluded

CVE is obsolete in cloud service paradigm

:/

2025-09-16

@GossiTheDog internet time capsules

Tanawts boosted:
Davey :sugar_approved:sugar@goblin.camp
2025-09-10

i don't know who needs to hear this, but

the words "you look great, your teeth are sharp, your eyes are luminous, the townsfolk whisper your name in hushed tones"
2025-09-09

@zackwhittaker a reminder that plex has recent history with chaining attacks to valuable targets....

thehackernews.com/2023/03/last

2025-09-08

@GossiTheDog "The bar is low."

Tanawts boosted:
2025-09-08

That NodeJS supply chain hack incident is amazing because the threat actor(tm) got RCE access to like a billion devices and ran the world’s shittest Etherum dumper.

Imagine if they had done reverse shells instead, or automated lateral movement to ransomware deployment NotPetya style.

The thing that saved companies here was the threat actor was incompetent crypto boy, nothing more.

2025-09-08

@BleepingComputer

Ok, fixed, github updated their advisory to reflect the affected debug version: 4.4.2

2025-09-08

Ok, fixed, github updated their advisory to reflect the affected debug version: 4.4.2

Tanawts boosted:
2025-09-08

Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.

2025-09-08

@BleepingComputer
It would be nice if Github could be talked to about their preference for strong wording so as not to cause a panic...

Patched Versions: None
Affected versions: All?
Remediation steps, blanket rotate all creds in all things with dependencies on debug?

<sigh> come on folks...

github.com/advisories/GHSA-8mg

GitHub Advisory Database / Malware / GHSA-8mgj-vmr8-frr6é
Malware in debug
Malware ) Published 2 hours ago to the GitHub Advisory Database
Vulnerability details  Dependabot alerts 0
Package Affected versions Patched versions
Im debug (npm) >=0 None
Description
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that
computer should be rotated immediately from a different computer. The package should be removed, but as full control of the
computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious
software resulting from installing it.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst