Alexandre Dufresne

21 Followers
119 Following
335 Posts
Security Analyst by day. Awesome all the time.

I’m doing another live book stream 😊

June 3, 8:00 am PST, I’ll be diving into Chapter 3 of Alice and Bob Learn Secure Coding with Scott Helme.

This chapter, “Improving”, is one of my favourites because it’s all the “okay but how do I actually do that?” stuff.

https://twp.ai/Ilr9pT
1/3

@jerry it would definitely be too much of a drain on resources...
I'm quoted in the following article with best practices for developers to lock down their build systems: Anthropic employee error exposes Claude Code source
https://twp.ai/E6HJiG
Anthropic employee error exposes Claude Code source

A version of the AI coding tool in Anthropic's npm registry included a source map file, which leads to the full proprietary source code.

CSO Online

New: Anime streaming service Crunchyroll has confirmed a data breach involving customer service ticket information following an incident with a third-party vendor.

https://techcrunch.com/2026/03/24/crunchyroll-confirms-data-breach-after-hacker-claims-unauthorized-access/

Crunchyroll confirms data breach after hacker claims unauthorized access | TechCrunch

Crunchyroll said it continues to investigate the data breach involving its users' personal information.

TechCrunch
⚠️ Confirmed: Metrics indicate a collapse in connectivity on AS12880, a key #Iran telecoms network that had so far remained partly online as part of the ~1% reserved state infrastructure. The incident corroborates reports of instability on the NIN domestic intranet.

@Natasha_Jay just last week I plugged in my old backup solution, a singular external hard drive, and found out that it died overnight.

It's like your mechanic that drives a beater car. IT pros do not always follow their own advice 😅

February was anything but quiet at GreyNoise, from our 2026 State of the Edge Report to new edge attack research, Ivanti + BeyondTrust deep dives, and a packed March of events, check it all out in this month's Noiseletter! 🚀

https://www.greynoise.io/resources/noiseletter-february-2026

NoiseLetter February 2026

Get GreyNoise updates! Read the February 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.

@sans_isc The insistence on "secure" while you were bringing up the FMC vulnerabilities got a couple of chuckles out of me. Well done 🤭

Whoops. The data broker giant LexisNexis has suffered another data breach. LN says the data taken was no big deal. The group claiming credit for the breach claims otherwise, of course.

https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/

This brings back memories of previous breach stories. One of my first big scoops that made the WaPo dead tree edition's front page involved a breach at LexisNexis in 2005 that exposed >300k consumer records. That breach was from a group of 15-18y/os in the US who also social engineered T-Mobile into giving them access to Paris Hilton's cell phone and the nudes w/in.

https://web.archive.org/web/20160513195758/http://www.washingtonpost.com/wp-dyn/content/article/2005/05/19/AR2005051901854_pf.html

In 2013, I published a scoop about a LexisNexis breach that came from group of criminal hackers who had seized control over ssndob[.]ru, then the largest ID theft service in the underground. In that months-long investigation, we found the hackers had installed backdoors on servers at LexisNexis, Dun & Bradstreet, and Kroll and were using them as part of a small and custom data broker botnet.

https://krebsonsecurity.com/2013/09/data-broker-giants-hacked-by-id-theft-service/

LexisNexis confirms data breach as hackers leak stolen files

American data analytics company LexisNexis Legal & Professional has confirmed to BleepingComputer that hackers breached its servers and accessed some customer and business information.

BleepingComputer
@sans_isc That Airsnitch webcast was super interesting. Definitely got me down a rabbit hole into wireless security.