Oneironaut

@Oneironaut@infosec.exchange
13 Followers
95 Following
1.4K Posts
GRC advocate. Cyber adjacent. Celine Dion fan
Ultra spicy post claiming to be from UK retailer employee (M&S or Co-op) about their experience with TCS on their security incident. https://www.reddit.com/r/cybersecurity/comments/1ll1l6c/scattered_spider_tcs_blame_avoidance/?utm_source=share&utm_medium=mweb3x&utm_name=mweb3xcss&utm_term=1&utm_content=share_button

Critical Citrix Netscaler "Citrix Bleed 2" flaw actively exploited

A critical vulnerability in Citrix NetScaler devices, dubbed "Citrix Bleed 2" (CVE-2025-5777), is now being actively exploited by threat actors according to ReliaQuest, raising concerns of a repeat of the devastating 2023 "Citrix Bleed" campaign that affected major companies like Boeing and Comcast's 36 million customers.

**This is now important and URGENT. Your Citrix NetScaler ADC or Gateway, exposed on the internet, they are actively attacked and exploited. After patching, you must terminate all active ICA and PCoIP sessions since they may already be compromised by attackers.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-citrix-netscaler-citrix-bleed-2-flaw-actively-exploited-4-y-j-i-q/gD2P6Ple2L

Critical Citrix Netscaler "Citrix Bleed 2" flaw actively exploited

A critical vulnerability in Citrix NetScaler devices, dubbed "Citrix Bleed 2" (CVE-2025-5777), is now being actively exploited by threat actors according to ReliaQuest, raising concerns of a repeat of the devastating 2023 "Citrix Bleed" campaign that affected major companies like Boeing and Comcast's 36 million customers.

BeyondMachines
Remote Code Execution on 40,000 WiFi alarm clocks

While looking for an API to use with Home Assistant, I found a remote code execution vulnerability in a popular WiFi-connected alarm clock.

On the CrowdStrike AI layoffs:

"These were not underperformers. Many of them were relatively new hires. [...] So, AI has literally killed many jobs at CrowdStrike this week. I'm fortunate to be among the survivors, but I don't know for how long."

https://www.bloodinthemachine.com/p/how-ai-is-killing-jobs-in-the-tech-f39

AI Killed My Job: Tech workers

Tech workers at TikTok, Google, and across the industry share stories about how AI is changing, ruining, or replacing their jobs.

Blood in the Machine

Ugh, here we go. People in the U.S. will get sicker more often, overall health and average life expectancy (US currently ranks 48th or so) will further decline. But because that impact will individually be subtle and compound only over years, the idiot population won’t make the connection.

Next on the chopping block: MMR vaccines. So yeah, young kids and infants are actually going to die. USA, USA.

https://www.nytimes.com/2025/06/26/health/rfk-jr-vaccines-acip-cdc.html

RFK Jr.’s New Advisers Rescind Recommendations for Some Flu Vaccines

Critics saw in the move the beginnings of a more restrictive approach to providing vaccines to Americans.

The New York Times
Microsoft is moving antivirus providers out of the Windows kernel https://www.theverge.com/news/692637/microsoft-windows-kernel-antivirus-changes
Microsoft is moving antivirus providers out of the Windows kernel

Microsoft is making changes to Windows to get antivirus apps out of the kernel. A private preview is being released to security vendors in July.

The Verge

Holy #surveillance hell, Batman.

Let me get this straight:

First, they feed your video, which is already stored in their cloud, into an #AI transformer to write descriptions.

Then they feed your descriptions into a pattern learning system (ML, maybe?) to figure out your patterns and habits.

All of this is stored in the cloud. So they not only have your video, but a narrative about your habits, ready to be exfiltrated, monetized, and shared with law enforcement.

#ai #enshittification #RingCamera

https://www.theregister.com/2025/06/25/amazons_ring_ai_video_description/

Amazon's Ring can now use AI to 'learn the routines of your residence'

: It's meant to cut down on false positives but could be a trove for mischief-makers

The Register
Hate to say it but running a live service game already requires putting on the big boy pants and if you're not ready for something as mild as "please have a sunsetting plan" then you're definitely not ready for the realities of running a live service game
@pluralistic In The USA they should make USPS an ISP, call all fibre "post roads" with all the protections and rights this gives them under the constitution (US Art 1 Sec 8), and start building… :D

So the UK Met Office is inviting people to suggest up to 5 names for storms. And apparently lots of people have been suggesting "Storm Bigoil", along with BP, Equinor, Exxon & Shell... This is obviously appalling & definitely not to be emulated via this link:

https://www.metoffice.gov.uk/forms/name-our-storms-call-for-names

×

So the UK Met Office is inviting people to suggest up to 5 names for storms. And apparently lots of people have been suggesting "Storm Bigoil", along with BP, Equinor, Exxon & Shell... This is obviously appalling & definitely not to be emulated via this link:

https://www.metoffice.gov.uk/forms/name-our-storms-call-for-names

@Natasha_Jay appalling. I just wanted to say that I definitely did not do that.
@crouton @Natasha_Jay me neither. That would draw attention to these companies' role in the climate crisis, and embarrass them, which we should certainly not do.
@Natasha_Jay Gosh darn that would be a darn shame were my fingers to accidentally click on that and fill in those boxes...
@Natasha_Jay I made some suggestions too!
I think Big Pete (BP) and Valero (well... Valero!), might be the least conspicious
@Natasha_Jay I followed your advice and didn't do that, but somehow a screenshot appeared on my laptop
@johnflomax @Natasha_Jay I would try to stick to the same names because they will probably only look at the most popular ones. 50 BeePee 50 BP and 90 Alice, Alice wins. It's not as good as 100 BP 90 Alice.
Agree, atleast for the first choice
@econads @johnflomax @Natasha_Jay it’s not like any of these names will ever actually be used. we should give them a large and creative list.
@maccruiskeen @johnflomax @Natasha_Jay no for sure, or Boaty McBoatface taught us nothing :D
But I assume the point is to make a news article about it. Top of the list being BP is more newsworthy (i.e. simpler to verify) than 1000 variations on BP. Anyway, I'm just some internet rando, do whatever you like :-)
@Natasha_Jay 👍 But at the same time, it would be advertising them as making a negative reference to them is better for them than not to mention them.
@Natasha_Jay
It would be a shame if the form allowed inputs outside the UK 
@Natasha_Jay boosting to make sure people are aware filling this form should be taken _seriously_
@Natasha_Jay I suggested Cassandra. The met office as been *modelling climate change for decades

@Natasha_Jay Hmm, think I will definitely not go over there and suggest Shelly McShellface...

Though Shelly is a perfectly legit name of course. No reason a storm can't be called that... 🤔

@Natasha_Jay humble contributions submitted

@Natasha_Jay
Worry that these will fall under "Any offensive names submitted will be deleted" but I filed with Saudi Aramco, Chevron, Gazprom, Putin, and ExxonMobil.

I wanted to include "Israel" but you know that's never getting through.

@xinit Yeah , Ok. Though not allowing blatant antisemitism seems to be a good thing. If you ask me. @Natasha_Jay
@DerGiga there's being against the Israel state's actions and there's anti-semitism. Maybe "Palestinian Genocide" then?
@xinit Ok. Clarification: Has Israel the right to exist?
@DerGiga
Ok. Clarification: Has Israel the right to do what it's doing?
@xinit To some degree it was defense and an expectable overreaction, that turned to a genocide at a point.
Though this was calculated in the terrorist attack.
I answered your question. Could you answer my simple question.
I may have confused you with someone you are not.
@DerGiga
I wish Israel hadn't been a place built on suffering for a whole class of people since the creation of the state. I've visited Jerusalem and the old city and enjoyed the cities and met some amazing people, but this really can't continue.
@xinit I answer later, since I have stuff to do.
But I do apologize, since I DID confuse you with someone you are not.
@xinit Thousands of years, have taught the jews, that they should never again be helpless. If there is a good reason for the existence of a state Israel would be a prime example. Though it would have been more fair if they were given the territory of Brandenburg.
It would be different if my neighbors would not have to wear basecaps on shabbat.
@xinit Also, I agree that there should be a Palestinian state, but that would need Israel to exist or it would become a vassal or territory of their neighbors.
Sadly, it has become the Palestinian fate to suffer, because their suffering is a weapon that can be weilded against Isreal . This suffering is also prolonged by the inheritable refugee status.
@xinit Also it would help, if the antisemitism everywhere would not pressure an exodus, that pushes people searching for affordable living space into the settlements and in extension taking land from the Palestinians.

@DerGiga It sure does. But it doesn't have the moral right to kill, torture, disable, starve and orphan thousands of Palestinians, to deprive them off their livelyhoods and turn their entire land into a rubble desert. Is it antisemitism to point that out, to find that inhumane?

But we were talking about storms, weren't we? So let's not derail this thread!

@xinit

@Natasha_Jay
Mine:

"Giant" is a film with James Dean and Elizabeth Taylor, and a good name for a big storm.

"Burgan" is an oil field in Kuwait. If it's worth going to war over, it's a pretty good name for a storm.

"Big Tex" is a symbol of all things Texas, a tall statue at the Texas State Fair, that burned up a few years ago, so it seems fitting.

"Ghawar" is an oil field in Saudi Arabia. Lest we forget.

"Ahvaz" is an oil field in Iran. Included to be fair and balanced in these nominations.

@Natasha_Jay The Met Office say that I'm inhuman!
@Natasha_Jay Presumably Stormy McStormface was already taken?
@Natasha_Jay I definitely didn't type this, the form came pre-filled.
@Natasha_Jay Storm Drax would be poignant.
@Natasha_Jay
Fossilfuelkills
And more
Largest oil and gas companies by market cap

List of the largest oil and gas companies by market capitalization, all rankings are updated daily.

@Natasha_Jay Despicable! People, where's the love for Saudi Aramco? They deserve credit too for all their hard work ❤️
@Natasha_Jay Oh no, I accidently did that! Shame on me. My reasoning: "We should honour the biggest polluters on the planet and the drivers of the climate catastrophe by naming storms after them. Their contribution should not go unnoticed."
@Natasha_Jay Michael Fish probably deserves one 😂

@Natasha_Jay It's fair that fossil fuel companies that contribute so much to these storms receive the recognition they deserve.

#Climate #ClimateChange #ClimateCrisis #GlobalWarming #BigOil #FossilFuel #Environment

@Natasha_Jay No Stormy McStormface? 😛
@Natasha_Jay Oops I accidentally filled this out. It would be a shame if it happened again....
@Natasha_Jay Oh, bugger! I slipped on my keyboard and accidentally suggested a bunch of planet destroyers
@Natasha_Jay
I don't know who did it, I think this malicious person used my phone. Oops, it happens. He posted this:
The names of the super-rich who are contributing to increasing climate instability and using the influence they have through their wealth to restrict civil liberties.
@floreana @Natasha_Jay for the longest time storms exclusively had female names. It is time indeed to address this!
@Natasha_Jay
I don't know who did this but someone else has suggested very suspicious names right now...
@Natasha_Jay as much as I want to suggest Stormy McStormface, these sound like far better options!
@Natasha_Jay the UK has learned nothing from Boaty McBoatface apparently