Xavier «X» Santolaria  

1.8K Followers
659 Following
264 Posts

👨‍👩‍👧‍👦 Husband. Proud Father. He/Him.


👁️ 🐝 Ⓜ️ IBM Inventor and Cloud Security Solution Architect | Open Innovation Community.

Member of the IBM Academy of Technology (AoT).

 ex-#OpenBSD (xsa@). Hacker. Open Source Advocate.


💬 My Own Views. Always.

#ibm #infosec #cloudsecurity #fedi22 #wehackhealth #crossfit #emtb #fieldhockey #porsche #nobot

📍 Location🇧🇪🇪🇸 @ 🇨🇭
🌍 Websitehttps://0x58.santolaria.net
:github: GitHubhttps://github.com/xsa
🔑 Keybasehttps://xsa.keybase.pub/mastodon.html
📨 Newsletterhttps://infosec-mashup.santolaria.net/?utm_source=mastodon&utm_medium=social
🗓️ {Cyber,Info}Sec Eventshttps://xsa.github.io/infosec-events/

🕵🏻‍♂️ [InfoSec MASHUP] 23/2026 - Built Broken, Patched by Others.

Another week, another set of trojaned packages, hijacked registries, and one-click credential theft. The operational response is by now well-rehearsed: patch, rotate secrets, enable 2FA, audit your dependencies, check your CI/CD workflows. The patching teams are doing their jobs. The question this week's malware section keeps nudging at is a different one: why is so much of what they're patching broken at the point of creation?

The supply chain attack surface exists because the software ecosystem normalized shipping fast over shipping secure, because package registries scaled adoption without scaling trust infrastructure, and because the developer who published a package with a hardcoded credential and the organization running it in production are rarely the same person bearing the consequences. #IBM and #RedHat just committed $5 billion to fix this upstream. #CISA launched CI Fortify to help #OT operators survive worst-case scenarios downstream. Both efforts are necessary. Both are also symptoms of an industry that has spent decades externalizing the cost of insecure software onto the people least positioned to refuse it.

→ Week #23/2026 also covers: Palo Alto Networks Alto GlobalProtect auth bypass is actively exploited, Weil, Gotshal & Manges LLP reportedly paid $20M to keep client files quiet, and the #EU is moving to limit U.S. cloud in sensitive infrastructure

Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-23-2026-built-broken-patched-by-others

If you find it useful, subscribe to get it in your inbox every weekend 📨

#infosecMASHUP #cybersecurity #infosec #threatintel #AI

🕵🏻‍♂️ [InfoSec MASHUP] 23/2026 - Built Broken, Patched by Others

Plus: Palo Alto GlobalProtect auth bypass is actively exploited, Weil Gotshal reportedly paid $20M to keep client files quiet, and the EU is moving to limit U.S. cloud in sensitive infrastructure

X’s InfoSec Newsletter
‘Bots have now passed human traffic online,’ Cloudflare boss laments — says agentic traffic wasn’t expected to eclipse real people until next year
https://www.tomshardware.com/tech-industry/artificial-intelligence/bots-have-now-passed-human-traffic-online-cloudflare-boss-laments-says-agentic-traffic-wasnt-expected-to-eclipse-real-people-until-next-year
‘Bots have now passed human traffic online,’ Cloudflare boss laments — says agentic traffic wasn’t expected to eclipse real people until next year

Bot (automated) vs. human HTTP requests are split 57.5 vs. 42.5 percent, according to the firm’s latest data.

Tom's Hardware
We're hiring again!
Fancy helping people debug their email or website issues?
https://www.irishjobs.ie/job/Technical-Support-Executive/a-job107477627
#hosting #domains #buyIrish

I was reading @dangoodin's interesting post on whatever is going on at Dashlane and had to laugh at this:

"As a paying customer I think I should have known about this from Dashlane and not Mastodon infosec folks."

https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/

While it is cats and dogs and gardens that anchor a lot of what I view, it's incredible all the OTHER stuff that one can pick up here.

#Mastodon #InfoSec

Dashlane issues opaque advisory warning 20 encrypted vaults were stolen

Security advisory leaves out key details. Dashlane maintains complete silence.

Ars Technica

As Mastodon adoption grows, attackers are also looking at leveraging it for hostile activities.

Sekoia explains how Russian malware used Mastodon encrypted post updates as a dead drop resolver to tell the malware where to exfiltrate data:

"[Mastodon] posts were consistently updated four times per day at uniform intervals with a variance of only a few minutes”

https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/

FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel

Discover part 3 of our FSB Matryoshka investigation. We deep dive into Gamaredon's Gammasteel info-stealer, its data exfiltration TTPs, and indicators.

Sekoia.io Blog

🚨 One more week to submit your workshop ideas!

📝✨ Still have an innovative idea or an exciting topic to share? You’re in luck!

We’re extending the deadline to give everyone a chance to contribute. Don’t miss this opportunity to make your voice heard and shape our program.

👉 Submit your proposals by the end of the week: https://cfp.insomnihack.ch/workshhops-2027/cfp

#CyberSecurity #CFP #InfoSec

I was laid off last month due to cost reduction so I used this unexpected « opportunity » to give a boost on the renovation of my house. Doing everything by myself allows me to keep it on a decent budget but I will need to go back to work in a few months 👀

I’m a software engineer with 17 years of experience on distributed systems. I’ve been writing Rust for 6 years (prior to that PHP/NodeJs/Go). I have a good experience with CI/CD, DevOps, Databases & IaaS. Very much opened to learning embedded systems.
Open to remote part-time contract or employee status (max 4 days/week) with occasional travel.

My recent projects : https://otso.fr/cv.html

Hopefully the Fediverse will work its magic ✨

#rust #rustLang #FediHire #getFediHired #toulouse #paris

My past projects - Otso

A list of my freelance projects over the years as a remote product egineer

It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to ‘give back’? Use this thread and hashtag to connect

🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

#Megalodon backdoored 5,500 #GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, #IBM and #RedHat announced a $5 billion commitment, called Project Lightwell, to securing the open source supply chain, #Anthropic's #Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry's response to supply chain risk is finally arriving at a scale that looks serious.

The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon's six-hour window isn't an anomaly — it's a benchmark. Last week it was TeamPCP and the GitHub cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it's being deployed against a threat that doesn't need a budget cycle to iterate. Project Lightwell will fund important work. Megalodon already shipped.

→ Week #22/2026 also covers: #ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance.

Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack

If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

Plus: ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance

X’s InfoSec Newsletter
Don’t ever connect your soap to the internet, no matter how much it asks.