VessOnSecurity

Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance.

PGP keyID: 0x365697c632dd98d9

2026-02-13

Picking a dog's name.

2026-02-13

CSS Developer award:

2026-02-13

"UK High Court rules Palestine Action terror ban is unlawful, marking blow to government":

lite.cnn.com/2026/02/13/uk/uk-

2026-02-12

Health (or lack thereof) update:

bontchev.nlcv.bas.bg/bye.html#

(BTW, I've tried to make the page a bit more mobile-friendly. I don't know for sure if I've succeeded; I don't use smartphones.)

VessOnSecurity boosted:
Catalin Cimpanucampuscodi
2026-02-12

Security researcher Eugene Lim has released Vulnerability Spoiler Alert, a service that monitors open-source repositories and uses Claude AI to detect when commits are patching security vulnerabilities before a CVE is even assigned or an update is released

vulnerabilityspoileralert.com/

2026-02-12

@campuscodi Seems like simple corruption case. He didn't leak classified info; he used insider (classified) knowledge to make money privately.

VessOnSecurity boosted:
2026-02-12

RE: swecyb.com/@anderseknert/11605

lol.. why are people arguing with an AI bot in the PR? What a world.

2026-02-12

"Steep drop in violent crime in major US cities, data analysis shows":

lite.cnn.com/2026/02/11/us/vio

See? This is what happens when you recruit criminals in law enforcement - they no longer have time to do crimes that aren't sanctioned by the government.

VessOnSecurity boosted:
Waldo Jaquithwaldoj
2026-02-12

Don't miss this explanation of how backbone providers coordinated on this telnetd exploit in advance of the CVE release, and simply blocked port 23 traffic. labs.greynoise.io/grimoire/202

VessOnSecurity boosted:
Catalin Cimpanucampuscodi
2026-02-12

Don't show this to kids in Australia or the UK: age-verifier.kibty.town/

VessOnSecurity boosted:
Graham Sutherland / Polynomialgsuberland@chaos.social
2026-02-12

security advice, 1996: writing your passwords down in a notebook is a very bad idea and nobody should do it

security advice, 2026: writing your passwords down in a notebook is one of the most secure storage methods for most users

(fun how threat models change over time, eh?)

VessOnSecurity boosted:
Catalin Cimpanucampuscodi
2026-02-12

CloudSEK says it intercepted the leaked credentials of a tech support and maintenance company that had access to the IT networks of more than 200 airports. The account also didn't have MFA enabled

cloudsek.com/blog/the-hidden-b

VessOnSecurity boosted:
๐Ÿ’™๐Ÿฉท๐Ÿ’œโ’ทโ“กโ“”โ“ฃโ“ฃ๐Ÿก๐Ÿ‰๐Ÿงbrettm@swarm.coiloptic.org
2026-02-11
psa if you have to use notepad (new version) the disable ai button is hidden in the fonts section.
2026-02-11

@campuscodi Didn't the EU recently vote the 20th package of sanctions against Russia? What else can they do - write a strongly-worded letter to Putin?

2026-02-10

From the WTF department, sorry, I mean from Microsoft: an RCE in Notepad of all things. (Well, the new app with AI and stuff; not the old one.)

msrc.microsoft.com/update-guid

2026-02-10

@BleepingComputer I'd make the joke that Microsoft 365 should be renamed to Microsoft 364 but there have been so many outages that it ought to be named Microsoft 265 by now...

VessOnSecurity boosted:
2026-02-10

Looks like the dev told an LLM to generate test files for a Shai Hulud detection app.

The LLM complied and generated malicious test files...

github.com/Cobenian/shai-hulud

VessOnSecurity boosted:
2026-02-10

Let's remind everyone what a safe internet actually means. ๐ŸŒ๐ŸŒ

Share this & Spread the word!

A safer internet IS MADE BY:
Encryption
Privacy
Open source

A safer internet is not made by:
Age verification
Scanning communication
Tracking & data collection

#Saferinternetday
2026-02-10

@erratarob Gringo, obviously.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst