22 Followers
205 Following
53 Posts
Hey, I'm Tom, based in the UK. Security analyst and car enthusiast.
Twitterhttps://twitter.com/Tom_From_The_UK
Should add, source of activity is all VPN/anonymising services

Anyone else seeing Defender flagging the attempted usage of AADInternals against Microsoft services where authentication is failing (incorrect username/password)?

Just trying to understand why they are reporting this, can appreciate why you might if the password was correct but they are failing at the first hurdle. @GossiTheDog any ideas?

Microsoft are rolling out Gaming Copilot to all Windows 11 PCs (excluding in China).

Enabled by default, silent install, takes screenshots and trains MS AI by default.

It installed on my Windows 11 Professional PC 🫡 it’s also not dependent on an NPU or Copilot+

https://doublepulsar.com/microsoft-builds-on-recall-with-gaming-copilot-fails-basic-privacy-tests-52988576bcc8

Microsoft builds on Recall with Gaming Copilot — fails basic privacy tests

Gaming Copilot, rolling out now to Windows 11, adds a new attack surface to Windows.

Medium

I think the NCSC should probably release some details about what happened at JLR as I think it would help orgs defend, and help focus the minds of boards.

There’s 100% orgs out there thinking they were dealing with Russia’s elite intelligence unit, who they’d just pay off. Imagine, in fact, you’re in a fight with Mr. Bean.

@GossiTheDog same here, well, I was meant to be getting something sorted on the car. That was cancelled so was hoping to spend it playing BF6. Then realised the release time 😭

My Cisco ASA firmware versions scan is now public: https://github.com/GossiTheDog/scanning/blob/main/Cisco-ASA-firmware-updates-CVE-2025-20333-CVE-2025-20363-CVE-2025-20362.csv

Fields:
IP,hostnames,FirmwareVersionKnown,FirmwareModifiedDate,Errors

Dates are UK date format - DD/MM/YY

If FirmwareModifiedDate is below */08/25 or */09/25, the device is vulnerable to #CyberWillyWave as the firmware was complied August 2025 or later.

New scan running now, results at weekend.

It gives you a very good indication as to how regularly orgs patch, e.g.

@GossiTheDog thank you, can you share what date you started your scan on for that data?
@GossiTheDog hey Kevin, are there any plans to drop the output of your scan onto your GitHub repo?
@GossiTheDog keep up with the naming conventions, it makes the communication at work much more fun 😆

I've identified a way to establish if a box is vulnerable to #CyberWillyWave and started internet scanning, 90k boxes in progress.

Results probably at weekend if I'm bored or early next week.

Spoiler: a lot of orgs don't patch their Cisco edge devices. To be vuln to the full chain you have to be over a year behind with updates... and most orgs are over a year behind.