Portions of the U.S. government are very concerned about updating web sites to erase DEI.
But the DEA still forces you to use Internet Explorer.
Portions of the U.S. government are very concerned about updating web sites to erase DEI.
But the DEA still forces you to use Internet Explorer.
@GossiTheDog They are traded OTC as RVRF. Only 365 employees. Up over 50% in the past 1y.
Seems like there should have been money for endpoint protection against malware and lateral movement.
Is this another 3rd-party admin'd environment where dropping $1K can get you inside with good creds?
TL;DR - LastPass was not breached.
If you're worried that because of this, now your work email, office phone, and preference of cigars or whiskey was compromised, you're living in a wonderful world. Enjoy it.
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl

How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.