Xavier «X» Santolaria  

@0x58@infosec.exchange
1.8K Followers
638 Following
637 Posts

👨‍👩‍👧‍👦 Husband. Proud Father. He/Him.


👁️ 🐝 Ⓜ️ IBM Inventor and Cloud Security Solution Architect at @IBM. Member of the IBM Academy of Technology (AoT).

 ex-#OpenBSD (xsa@). Hacker. Open Source Advocate.

#ibm #infosec #cloudsecurity #fedi22 #fedi23 #wehackhealth #crossfit #emtb #fieldhockey #porsche #nobot


💬 My Own Views. Always.

My #cybersecurity and #infosec Weekly Newsletter:

📨 https://infosec-mashup.santolaria.net


Maintaining a list of {Cyber,Info}Security Events:

📆 https://github.com/xsa/infosec-events

📍 Location🇧🇪🇪🇸 @ 🇨🇭
🌍 Websitehttps://0x58.santolaria.net
:github: GitHubhttps://github.com/xsa
🔑 Keybasehttps://xsa.keybase.pub/mastodon.html
📨 Newsletterhttps://infosec-mashup.santolaria.net
:youtube: Channelhttps://www.youtube.com/@0x58_

🔥 Latest issue of my curated #cybersecurity and #infosec list of resources for week #26/2025 is out!

It includes the following and much more:

🇺🇸 🇮🇷 The U.S. Department of Homeland Security has warned about increased #cyberattack risks from Iranian hacking groups;
🇨🇳 🇨🇦 Hackers linked to the Chinese government exploited a serious #vulnerability in a Canadian telecom provider;

🇷🇺 ⚖️ A Russian court released four members of the #REvil #ransomware gang after they served their time;

🇺🇸 💬 The U.S. House of Representatives has banned #WhatsApp on staff devices;

✨ 🐱 New #malware called #SparkKitty was discovered in apps on Google Play and the Apple App Store;

📨 Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-26-2025

🕵🏻‍♂️ [InfoSec MASHUP] 26/2025

The U.S. Department of Homeland Security has warned about increased cyberattack risks from Iranian hacking groups; Hackers linked to the Chinese government exploited a serious vulnerability in a Canadian telecom provider; A Russian court released four members of the REvil ransomware gang after they served their time; The U.S. House of Representatives has banned WhatsApp on staff devices; New malware called SparkKitty was discovered in apps on Google Play and the Apple App Store;

X’s InfoSec Newsletter
You know back in my day, we had static analysis tooling that would give you exactly this kind of feedback, except it was correct. Now we have shit which only looks at the vibes of the source text and does no semantic analysis whatsoever, so of course it's just fucking wrong

Sent a pull request to Audacity fixing a crash bug I'd been running into frequently. The cause was an out-of-bounds memmove. Classic C++ areas.

Anyway I got a fucking copilot review on my PR which left two comments, both completely wrong, one of which suggesting I reintroduce the out of bounds memory access. I'm furious!

🐝 The dating platform #Bumble sends user data to #OpenAI without their consent. We have therefore filed a GDPR complaint against the company.

📰 Read more on our website: https://noyb.eu/en/bumbles-ai-icebreakers-are-mainly-breaking-eu-law

#AI #law #MakePrivacyReality

🔥 Latest issue of my curated #cybersecurity and #infosec list of resources for week #25/2025 is out!

It includes the following and much more:

🇺🇸 📰 The Washington Post experienced a #cyberattack that compromised the email accounts of several journalists;

🇬🇧 The U.K. watchdog fined #23andMe £2.31 million;

🇨🇭 🏦 #UBS Confirms Data Stolen After Hack at External Supplier;

👾 Over 1,500 #Minecraft players have been infected by a new Java #malware;

🤖 🛠️ Researchers say #AI hacking tools sold online were powered by #Grok, #Mixtral;

📨 Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-25-2025

🕵🏻‍♂️ [InfoSec MASHUP] 25/2025

The Washington Post experienced a cyberattack that compromised the email accounts of several journalists; The U.K. watchdog fined 23andMe £2.31 million; UBS Confirms Data Stolen After Hack at External Supplier; Over 1,500 Minecraft players have been infected by a new Java malware; Researchers say AI hacking tools sold online were powered by Grok, Mixtral;

X’s InfoSec Newsletter
Some lockpicking spy action 🤫👀
One of the coolest Spawn-Camp and Girls Who Hack classes 😉

Today we'll go behind the scenes of one of the most beloved and successful #hacker cons, with the husband and wife team who ran it for 20 years, from the Snowpocalypse to Shmoo balls and the chandelier shard miracle.

@ShmooCon

https://podcast.firewallsdontstopdragons.com/2025/06/23/shmoocon-moose-you-already/

ShmooCon: Moose You Already - Firewalls Don't Stop Dragons Podcast

On January 12th, 2025, the ShmooCon hacker conference held it’s 20th and final gathering. I was lucky enough to be able to not only...

Firewalls Don't Stop Dragons Podcast
La ville de #Lyon annonce le déploiement progressif de logiciels bureautiques libres, en remplacement de la suite Microsoft Office, dans les services municipaux afin de renforcer la souveraineté technologique. https://www.lyon.fr/actualite/action-municipale/la-ville-de-lyon-renforce-sa-souverainete-numerique
La Ville de Lyon renforce sa souveraineté numérique

Yo, fellow Linuxers, #CVE20256019 has been published and updates are available. The TL;DR. A Local Privilege Escalation to root via libblockdev. Notice the local. So you need to be able to be on the machine. Still, update now.

https://nvd.nist.gov/vuln/detail/CVE-2025-6019

NVD - CVE-2025-6019

The United Nations hosted its first-ever InnerSource panel, marking a significant acknowledgment of this methodology as a cornerstone of organizational transformation and the adoption of open source principles.

#innersource #opensource #oss #tech

https://apnews.com/press-release/pr-newswire/united-nations-forum-elevates-innersource-as-essential-tool-for-open-source-scaling-dcc14cdf0c5862ff02f726c23fe797aa

United Nations Forum Elevates InnerSource as Essential Tool for Open Source Scaling

Mercedes-Benz Tech Innovation, Bosch Digital, CURIOSS, BBC, and Dutch Tax Administration Join Forces to Discuss InnerSource as Key Driver for Open Collaboration

AP News