597 Followers
2.4K Following
578 Posts

Doing DFIR, in love with the thrill of the thrunt <3

"Chaotisch neutral" (@HonkHase)
"Bester Faden-Jäger EU West" (@jrt)
"So ein Troll, ey" (@brahms)
"lol. lmao." (@gayint)

#DontEatMyHomies
#LowkeyLoki
#SparklyOpossum
#ThruntersAnonymous

Disclaimer:
Personal account. Opinions expressed are my own and not related in any way with my employer.

Wanted Hasheshttps://pastebin.com/Fn79UvzC
Ego-Tootinghttps://justmytoots.com/@g0rb@infosec.exchange
VThttps://www.virustotal.com/gui/user/nhs28

I just gave an interview with a journalist raising concerns about Kessler Syndrom and complaining about megaconstellations in general. And less than 5 minutes later, I see a post about a starlink satellite being involved in a "fragment creation event".

@sundogplanets

I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:

🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻‍♂️

The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy

If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.

https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec

Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

One Microsoft product was approved despite years of concerns about its security.

Ars Technica

A person who was made to undergo Chinese political re-education as part of China’s ongoing, undeniable genocide

Built a propaganda tracker tracking Chinese state media and terms. They noticed how, during the re-education program, language was shifting: he was no longer Chinese Mongolian, he was from the ‘northern frontier’.

This work documents and tracks how quickly terms shift through Chinese state media

https://propagandascope.org/

#China #Uighur #Uyghur #Mongolian #Chinese #Languages #CCP

PropagandaScope

What number CitrixBleed are we on?

Join us, yet again, for part 2 of our analysis of Citrix NetScaler CVE-2026-3055 - which now appears to be multiple vulnerabilities bundled into one.

Sigh.

https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2

Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)

Today, we woke up with a nagging feeling: what if Citrix had, in fact, patched multiple Memory Overread vulnerabilities as part of CVE-2026-3055? While we've been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately identify exploitable Citrix NetScaler appliances across

watchTowr Labs

Our new release 0.89.0 is published! 🎉

This round we bring not one but two big new features: sync with Health Connect and internet access. 💪
Do these features sound a bit strange, coming from us? 🤔 Then make sure to read the blog post for details and rationale!

And of course this release also contains the usual list of newly supported devices, smaller features, improvements and bug fixes.

Read more in our blog post: https://gadgetbridge.org/blog/release-0_89_00/

Gadgetbridge 0.89.0: Two big new features - Gadgetbridge

A free and open source Android application for bluetooth devices.

This is the prediction market I'm here for: you can now bet on German train delays. Glorious stuff. Peak trolling.
https://bahn.bet/
Bahn.Bet — Bet on German Train Delays

Prediction markets on Deutsche Bahn departure delays

Bahn.Bet

NINETY DAYS

NINETY INCIDENTS

NINETY PERCENT

YOU PAID FOR ALL FIVE NINES BUT YOU’LL ONLY NEED THE EDGE

#github