1.4K Followers
473 Following
17.4K Posts
I break software.
Bloghttps://sempf.net
OWASPhttps://owasp.org/www-chapter-columbus/
Githubhttps://github.com/sempf
Amateur RadioKE8PCT
POINThttps://pointweb.net
HeaderMedeco Biaxial
Latin Easter mass with a Chicago accent is one of my new favourite things.

Aww dood crunchyroll was breached. Now everyone will know I ... uuuuh so they were breached!

https://haveibeenpwned.com/Breach/Crunchyroll

#breach #anime

Have I Been Pwned: Crunchyroll Data Breach

In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users. The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the contents of the support tickets" were exposed. A subset of 1.2M email addresses from an alleged 2M record dataset being sold was later provided to HIBP.

Have I Been Pwned
Dammit. I already marinated the lamb!
Hey, you! Yeah you, all hunched over like a croissant in your screen-lit windowless room. Go the fuck outside.

Over the past year, I've been quietly building something...and it's ready enough to share. 🧵

It's called https://ThisWas.News — every day, it shows you the lead headlines from one week, two weeks, one month, three months, six months, and one year ago today — with a short summary of what was actually happening.

Remember what the headlines used to be

This Was News is a daily time capsule of top news stories. Pick any date to see the lead headline and other major stories from that day, curated from major fact-focused news outlets so you can remember what the world thought was important.

This Was News
ATTACK OF THE KILLER WASP BUTTS!!!
@Gabrielle just made a remote control lava lamp!
v.1.8.0 of my .NET Bluesky library has dropped. Highlights include Bot property on profile views Protections against malicious handles and did docs introducing SSRF vulnerabilities Protections against a malicious sending messages about a max size Metrics Support

Release v.1.8.0 · blowdart/idu...
Release v.1.8.0 · blowdart/idunno.Bluesky

Added idunno.AtProto Added metrics in AtProtoHttpClientMetrics including request duration, request count and failure count. Added metrics in DidPlcDirectory including request duration, request cou...

GitHub
Weather forecasting in the 614 has just sucked this week. Every day this week, Wednesday, Thursday, Friday, Saturday, they said thunderstorms, rain all day. It's going to be sloppy and warm and humid and gross, and it was absolutely beautiful every single day. #ohwx

Talos found this ginormous automated React2Shell exploitation scheme for credential harvesting at scale. I'll bed the SOB was vibe coded, too.

https://www.securityweek.com/react2shell-exploited-in-large-scale-credential-harvesting-campaign/

#react2shell #breach

React2Shell Exploited in Large-Scale Credential Harvesting Campaign

The UAT-10608 hacking group is using automated scanning and scripts to exploit React2Shell in a large-scale credential harvesting campaign.

SecurityWeek