Mike Sheward

4.9K Followers
342 Following
12.3K Posts
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Infosec Diarieshttps://infosecdiaries.com
Business Inquirieshttps://www.securebeing.com
Mediumhttps://mike-sheward.medium.com/
Goodreadshttps://www.goodreads.com/author/list/8153753.Mike_Sheward
Author Pagehttps://www.amazon.com/Mike-Sheward/e/B00JKND75S
Linktreehttps://linktr.ee/secureowl

Air to Ground Message:

HI GUYS. PLS CAN YOU ADVISE PAX IN REUS TO BUY FOOD IN TERMINAL. 7 BACON BUTTIES ONBOARD AINT GONNA COVER IT

Area: UK
Type: Airbus A320
A: #aa329a1f8ae
F: #f2be305be45

#acars #vdlm2

all you need for a good time is at baggage claim 14

Air to Ground Message:

OS KLAX WE HAVE A PAX WHO SPILT HOT LIQUID ON HIS GROIN AREA AND BURNED HIMSELF WE HAVE A MED PROFSNL ON BOARD ASSISTING REQUEST MEDICAL AT THE GATE PLEASE PASSENGER IS IN 30F XXXXX XXX MIDDLE AGED MALE THANKS

Area: Los Angeles, CA, USA
Type: Airbus A321
A: #a04c6ffe0ce
F: #f9681d76eac

#acars #vdlm2

Air to Ground Message:

FAILURE TO DISINFECT SOILED SEATS

Area: Portland, OR, USA
Type: Embraer 175 (Enhanced Wing)
A: #a4a011c1a6c
F: #f4f6829bfef

#acars #vdlm2

Air to Ground Message:

ATC IS SAYING THERES AN EMERGENCY SITCH AT THE AIRPORT...THX

Area: Raleigh, NC, USA
Type: Boeing 737-800
A: #ae71973d7dd
F: #fd11d203e29

#acars #vdlm2

RE: https://live.acarsdrama.com/@acarsdrama/116460768612916004

have made similar reports after chipotle

Disclosure: This was Rippling (rippling.com)

Essentially, the flaw I discovered was that if you use their platform to send someone a job offer via email, shortly after sending said offer (no interaction required on the part of the recipient, such as, say, actually looking at or accepting the offer), if that person already had a Rippling account, such as from a prior employer, a Rippling process would run that would populate their information from what was already in the Rippling backend from another tenant.

This info includes all the PII, including SSN, banking, address etc.

That info would automatically become visible to the Rippling user who had sent the job offer email.

So, all you needed was a rippling tenant, and if your target had previously used Rippling ever - you could exchange their email address for all the info.

Timeline: reported in July 2025 to the Rippling Bugcrowd bug bounty program, accepted as a critical issue within 48 hours, only fixed last week (9 months).

No bounty was offered.

Just a data point for anyone else who considers submitting to this program. Probably the least impressive bug bounty experience I’ve had in the last 15+ years.

#infosec #bugbounty

RE: https://live.acarsdrama.com/@acarsdrama/116460178970112357

kash patel’s tequila co-ordinator on the morning taxi ride to the office

america 250

Reactions to this headline:

The security team: oh noe, sounds bad

The business: how do we get in on this?