Adrian Sanabria

🎙️ Enterprise Weekly Podcast
🤝 Founder @bsidesknoxville
🗣️ Faculty @IANS_Security
🕵️ Security Research
🍳 Cooking
⛰️ Hiking
🏎️ F1

"I rant with data!"

2025-05-24

And sadly, it looks like the replacement I got off Amazon has a manufacturing defect, boooo

Maybe I could swap the board from the new one to the old screen, which is fine?

Problem is, I have no idea how difficult that would be and don’t see anyone doing this repair online, which means it probably isn’t worth it.

We’ll see if the seller sends me a replacement.

2025-05-24

@xabean lololol, true

2025-05-24

Repair time!

Today, it is a Macbook Air that had some Arizona Mucho Mango spilled into the keyboard.

A thermal event burned out the display board, which can’t be replaced without replacing the entire screen (boooo)

2025-05-21

Long ago, in my practitioner career, I remember thinking

"wow, employees in 8 countries can access 1521 on the datawarehouse server, where we've got over 7 billion rows of credit card transaction data, flat networks are a really bad idea"

it still is

2025-05-21

@da_667 it is an extremely important skill

especially on LinkedIn

2025-05-21

I don't think I've even THOUGHT about TCP 1521 in at least 15 years. It has always been the #1 spot to create Oracle database mayhem and that doesn't change today.

It has a vulnerability, but that shouldn't even matter - access to 1521 on Oracle DB servers should be SERIOUSLY restricted these days. If you've got a flat/flat-ish network, you should jump on this soonish.

scworld.com/news/oracle-databa

2025-05-21

@wendynather ooooh, I've got my copy on my reMarkable, but haven't dug in yet

2025-05-20

@mattjay I cannot WAIT to get rid of mine. This is one of the worst-designed devices I've ever owned.

Eagerly waiting on my new Pebble to arrive. 30 days battery life is what they're saying.

2025-05-20

Let me set the scene: it has been a LONG week, 60 hours wrapping up an incident. You caught up on a little sleep last night, but still very fatigued when you get up on Saturday morning.

You decide to go to a friend's BBQ anyway. They're cooking up both hamburgers and hot dogs - yet another decision to make, UGH

But no! Some unnamed hero has saved you from having to make that decision!

A miscarriage of culinary creation: a modified hamburger bun perfectly shaped to fit a centered hotdog with a hamburger split in two, on either side of the hot dog. Imagine a hamburger bun with two handles on either side, to accommodate the extra length of the hot dog.
Adrian Sanabria boosted:
2025-05-20

Another classic from @Javvad — the Work Trip: youtu.be/pi93TSwqd4A

Adrian Sanabria boosted:
2025-05-20

So judging by the $256 million dollar sale of 23andMe, your genetic data is worth like $17

404media.co/23andme-sale-shows

Adrian Sanabria boosted:
2025-05-20

Organisations still don’t know what is at their network border, don’t have a CMDB, can’t patch, getting owned by children etc etc. Leaders:

Adrian Sanabria boosted:
Insecurity Princess 🌈💖🔥saraislet@infosec.exchange
2025-05-20

Framing is important

What's your preferred title for the introductions today?

"Princess Sarai, Engineering Manager for Cloud Security at Netflix, Mother of Kittens, Breaker of Attack Chains"

How shall it be abbreviated for a written list of panelists

Engineering Manager for Netflix Cloud Security

Asking the right question is important

I mean both were valuable information
2025-05-18

@Chip_Unicorn It is nuts. The idea was a full keyboard in an ergonomic handheld form factor. I ran the community for them and used to chat with the inventor regularly. We sadly never saw a wireless version released.

I still have three of them, part of my weird keyboard collection.

2025-05-18

@GossiTheDog I was doing product testing full time for a bit back during the pandemic. I haven’t tested the product they mention, but I tested some of their competitors who make similar claims (using self-learning ML tech), and… they didn’t work.

Like, straight up, didn’t detect the most basic, noisy, routine stuff we threw at them.

Adrian Sanabria boosted:
2025-05-18

Sigh. It's possible to remotely, physically locate any O2 mobile customer at any time over the internet with a trivial method using their mobile phone number, due to O2's poor implementation of 4G Calling which, by design, gives away the Cell ID.

mastdatabase.co.uk/blog/2025/0

2025-05-16

@GossiTheDog to be fair, IIRC, Coop Sweden went down because their payment provider used Kaseya.

So, it was ransomware on a fourth party, nothing Coop Sweden had any direct control over

2025-05-16

@hrbrmstr even Mike Judge wasn’t bold enough to suggest something like this in the script for Idiocracy

2025-05-16

@Chip_Unicorn I learned QWERTY and Alphagrip’s layout

Adrian Sanabria boosted:
2025-05-15

Coinbase filed an 8K with the SEC for a breach. They believe multiple insiders have sold customer information to a threat actor who is now extorting them.

It looks like a very significant breach as it includes customers passport scans.

sec.gov/ix?doc=/Archives/edgar

#threatintel

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst