Wouter Hindriks

@Sikorsky78@infosec.exchange
121 Followers
99 Following
724 Posts
Please report any account that tells you that you need to verify your #Mastodon account to continue using it through a private message. It is a scam. We do not require identity verification. Real staff accounts either have a special role badge on their profile or are verified through the joinmastodon.org domain and will typically never reach out through private messages.
@GossiTheDog How are you monitoring this traffic? I remember you making a similar statement on the Ingram Micro case.
It’s my birthday give me boosts 💅

CVE-2025-5777 aka CitrixBleed 2 has been added to CISA KEV now over evidence of active exploitation.

Citrix are still declining to comment about evidence of exploitation as of writing.

https://www.cisa.gov/news-events/alerts/2025/07/10/cisa-adds-one-known-exploited-vulnerability-catalog

@GossiTheDog
*Surprised Pikachu*
If you’re in #ISC2 and in EMEA and/or awake at this hour, you can join my webinar, which starts at 13.00 London time

I'd like to thank the UK Supreme Court for refusing my appeal. They claim I haven't raised an arguable point of law, despite the text of the law already recognizing me as nonbinary. 🤷

This means I can now appeal to the European Court of Human Rights, which my lawyers are already working on.

Repost if you can hear this image blaring
×
The EU Product Liability Directive will take effect Dec 2026. Software, firmware, applications, AI systems, and will now be subject to the same strict liability regime as traditional physical goods. Cybersecurity vulnerabilities will be considered product defects. Analysis by Reed Smith LLP: https://www.lexology.com/library/detail.aspx?g=bbef1939-2af0-465a-8b8f-c1ff3ebe9118
@Weld Development of commercial software and sales thereof falling like a rock in the EU in 3...2...1...
@bontchev @Weld companies who were already doing a good job making more money because quality and security are meaningful differentiation now in 3… 2…
@Weld So if the EU compromises end-to-end encryption, that’s a defect?

@Weld I'm curious how "Companies cannot contractually exclude or limit their liability under the PLD, and disclaimers for software defects or security vulnerabilities are not valid." works with FOSS. Am I now exposed even if I leave a copy of my software in a repo somewhere; or is it only if I actually sell it to you?

If the former that seems apocalyptic; if the latter it seems like all software will either be free or eleventy-billion euros.

@Weld maybe a hot take— these requirements will improve personal privacy and security more than GDPR.