Mastodon Digest
for the past
scorer
threshold
Posts

I’ve said this many times - have a playbook for Advanced Persistent Teenagers, ransomware and extortion groups. Practice it.

It’s far more likely to need to be used than nation-state espionage playbooks - and these incidents are far more damaging if not well handled.

You need to flood the zone with messaging, put it on the front page of your website, be calm and upfront with customers. If you have 15 lawyers on a call debating legal risks, you’ll lose customer trust. Get the CEO on BBC News.

Very fun lessons for cyber incident response over the ASOS thing - the extortion groups push message has caused BBC News to clear the air waves for it, set up a dedicated YouTube stream for it, and the company has no media statement.

RE: cyberplace.social/@GossiTheDog

Fun one - over half of the CVEs added to CISA KEV are over a year old, ie issued a year or more ago.

There’s this whole narrative around how GenAI will find zero day vulns and the apocalypse is coming. Slight issue - almost all incidents are caused by orgs not patching. Basically at all.

The cybersecurity industry never solved that.. and doesn’t even understand it is the case.

🚨 Windows 11 Zero-Day LPE and Pre-Auth RCE Exploits Offered for Sale

A forum actor is advertising an alleged Windows 11 zero-day local privilege escalation exploit claimed to work across all versions.

The seller also claims to have pre-auth RCE exploits for Ivanti Connect Secure SSLVPN and Zimbra, along with an RCE exploit targeting Switchvox SMB.

Pricing is negotiable, with transactions offered through escrow.

Claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Someone appears to have hacked the British retailer ASOS and is sending push notifications to customers stating that their data was hacked via a compromised instance at the cloud data storage provider Snowflake. Interesting direct approach, trying to get customers flooding the company with angry emails and pressure the company to pay a ransom.

sg.finance.yahoo.com/news/asos

A

I’ve had a couple of people asking how I’m fingerprinting Netscaler versions remotely still, and the truth is I don’t wanna say as every time I do, Citrix patch out the methods. 🤣

Patch rates still well below 50% on latest vulns, and that’s removing honeypots and the like.

Boosts

new SonicWall SMA1000 advisory. Check out CVE-2026-102255 (10.0 critical) Pre-authentication SSRF via unintended forward-proxy. No mention of exploitation, but it's not a good look that your Secure Mobile Access is not secure (including four known exploited vulnerabilities in the past 90 days)

psirt.global.sonicwall.com/vul