James Atack

Cyber defender with an offensive name.
Managing your attack surface

Opinions : all mine
Special skill : machine empathy

2025-04-23

@adulau the cynic in me assumes it means "fixed without anyone noticing"

2025-04-23

Great talk from @adulau on pivots at #FIRSTCTI25

Pointing out that many TOR services have google analytics or GTM trackers

category:onionscan -exists:app.http.tracker -since:3M

đŸ€Šâ€â™‚ïž

James Atack boosted:
ValĂ©ry Rieß-Marchive :verified:ValeryMarchive@infosec.exchange
2024-12-17

đŸ‡«đŸ‡· Ecritel (ecritel.fr) a Ă©tĂ© victime d'une cyberattaque autour du 08 dĂ©cembre 2024.

L'entreprise de services numĂ©riques française Ecritel a Ă©tĂ© victime d'une cyberattaque par le groupe de ransomware Hunters International, qui revendique le vol de 270 Go de donnĂ©es. Selon Ecritel, l'attaque a Ă©tĂ© dĂ©tectĂ©e et arrĂȘtĂ©e rapidement, sans impact sur la continuitĂ© de l'activitĂ©, et seul un serveur interne de documents de travail a Ă©tĂ© compromis. Hunters International est une franchise de ransomware liĂ©e Ă  Hive, qui a Ă©tĂ© surprise en train de recycler des donnĂ©es issues de cyberattaques prĂ©cĂ©demment conduites sous banniĂšre Hive.

👉 lemagit.fr/actualites/36661733

James Atack boosted:
2024-12-17

@GossiTheDog Have you heard about a new Forti Manager vulnerability ? There's no Fortiguard assigned , but like always, they're deploying update with short deadline.

James Atack boosted:
2024-12-17

Today, we have opened formal proceedings against TikTok for a suspected breach of the Digital Services Act.

Following serious indications that foreign actors interfered by using TikTok in the Romanian presidential elections, we are now thoroughly investigating whether TikTok has violated the DSA by failing to tackle such risks.

We must protect our democracies from any foreign interference.

More: europa.eu/!w7DbvY

#EU #DSA

A purple graphic with the European Commissionlogo and the text "DIGITAL SERVICES ACT" in large white letters. Below that, it reads "Formal proceedings opened against TikTok on election risks." There are seven yellow stars arranged in a circle around the text. Each star has a symbol inside it: a bell, a padlock, a document with a magnifying glass, a checkmark, a crossed-out face, a no symbol, and an ad symbol.
2024-10-28

@nixCraft or if everyone dies

James Atack boosted:
Claus Cramon Houmannclaushoumann
2024-10-28

Hi everyone at @hack_lu -> I picked up at the conference. I hope you didn’t, but please test.

James Atack boosted:
Eugen RochkoGargron
2024-10-25

Mastodon is financed by crowdfunding instead of venture capital not because we don't know that venture capital exists, not because we don't have bills to pay, and not because venture capital isn't willing to give money to new social media platforms. VCs don't want a sustainable business, they want a big exit. Every VC-backed business is on a timer to deliver or die.

2024-10-25

So I got to do a talk at #hacklu2024 youtu.be/wv0syhH2e1k
Thanks @hack_lu for the opportunity and your trust 🙏

James Atack boosted:
2024-10-25

Very interesting talk by @jamesatack from #onyphe at #hacklu2024 on the october 2023 compromise of cisco XE routers. This campaign did not receive enough attention...

There is some good quality content over there ! (Both Onyphe and hack.lu).

James Atack boosted:
Claus Cramon Houmannclaushoumann
2024-10-25

At @hack_lu @jamesatack is profiling the threat actor behind the IOS XE compromise campaign that’s been going on the last year or so

James Atack boosted:
RNLI: Out On A ShoutOutOnAShout@botsin.space
2024-10-24

Hello! This is an automatic account, which checks every 10 minutes or so to see if there has been a lifeboat launch by the RNLI, and if there has, posts the location and time of the launch.

rnli.org/what-we-do/lifeboats-

I know a lot of people were very fond of the equivalent bot on twitter/X, so I made this one for you to follow and not miss out.

Please boost to spread the word!

Always consider making a donation to the RNLI if you can -
rnli.org/support-us/give-money

James Atack boosted:
Claus Cramon Houmannclaushoumann
2024-10-24

Btw do I know anyone who’d be interested to help organizing a for 2025? LF volunteers and co-organizers.

Please boost for reach

James Atack boosted:
ValĂ©ry Rieß-Marchive :verified:ValeryMarchive@infosec.exchange
2024-10-24

đŸ’„ Vous aimez la CVE-2024-47575 qui affecte FortiManager de #Fortinet ? Vous n'ĂȘtes pas seul ! Selon les donnĂ©es de ONYPHE, vous pouvez ouvrir un club et commander polos et casquettes : vous ĂȘtes prĂšs de 495 000 dans le 🌍 lemagit.fr/actualites/36661395

James Atack boosted:
2024-10-23

FortiNet have now gone public about FortiJump, aka CVE-2024-47575 fortiguard.fortinet.com/psirt/

Not in the advisory but exploitation stems to at least September, and it's being used to enter downstream networks.

#FortiJump

2024-10-23

@claushoumann @hack_lu bitwarden obvs

2024-10-22

@adel great talk, thanks 🙏

James Atack boosted:
2024-10-22

@claushoumann All video (when the speaker allows the video to be public) is available at the following location: administraitor.video/edition/H all videos are recorded by the Master Cooper (who will be soon in the fediverse ;-).

@resingm

#video #hacklu2024 #hacklu

2024-10-21

@GossiTheDog while seeming to spend not insignificant engineering resources on obfuscating firmware with no meaningful security benefit for customers

2024-10-14

@SwiftOnSecurity was it PAC behaviour?

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst