228 Followers
237 Following
626 Posts

I liked ranting so much, I made it my job.
Pentester. I mostly break Web stuff but sometimes hardware too. OSINT from time to time.

Terrible music connoisseur.

@faker_ on Twitter.
#infosec #pentester #OSINT

Bloghttps://infosec.rm-it.de/
LocationMunich, Germany

RE: https://social.heise.de/@heisec/116278847114165195

German police was physically sent out to warn businesses about a vulnerability in Windchill and ZeroPLM in the middle of the night.
Apparently they just showed up and wanted to warn them, and if nobody was there they tried calling.
Imagine being an admin and getting a call by the BKA at 4am just to tell you some internal system needs patching.
wtf indeed

Inbox zero is overrated
speak next week friends

Phenomenal reporting from ProPublica. Big takeaways:

  • FedRAMP is too understaffed to be effective.
  • Microsoft never answered serious questions about its cloud security architecture.
  • Despite a damning report, Microsoft's government cloud product was approved anyway.

https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government

Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.

A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.

ProPublica
First time seeing this, promoted crypto scams on LinkedIn probably using stolen accounts.
@weddige over a year ago for sure. But don't worry! They have a Discord server now 🙄

From the company that sells you DDoS protection but also is somehow the preferred hoster of DDoS crews: They now sell you bot / AI crawling protection, and have released a feature to quickly crawl an entire website!

Great stuff, Cloudflare.

https://developers.cloudflare.com/changelog/post/2026-03-10-br-crawl-endpoint/

Crawl entire websites with a single API call using Browser Rendering

Browser Rendering's new /crawl endpoint lets you submit a starting URL and automatically discover, render, and return content from an entire website as HTML, Markdown, or structured JSON.

Cloudflare Docs

A sales person contacted me and asked if I'd be interested in their AI pentests with super low daily rates.
Should I reply and ask if he is interested in replacing Sales in their company with AI?

How tone deaf can you be to approach a pentester and ask "can I replace you with our AI?"

Crazy that Apple RAM prices now seem almost normal. In a new MacBook Pro the 24 to 64 GB upgrade is "only" 750 EUR

🤦Oh, it’s the Snowden revelations all over again.

They are claiming that AI-powered mass surveillance is a good thing but mass **domestic** surveillance isn’t

https://www.anthropic.com/news/statement-department-of-war