hexamander

@hexamander@infosec.exchange
120 Followers
156 Following
1.7K Posts
Who would win? East coast aviation or one(1) toasty boi?

how many companies are you aware of that had "oh fuck someone actually blew up the datacenter" in their threat model or DR recovery efforts?

how many are like "whatevs, our shit is in the cloud and all the contract language has us well protected against lawsuits if shit goes down"?

how many do you think realize that attitude towards technology solves for "the lawsuits after the fact" but does absolutely zero for business continuity?

NHS England has announced that it is pausing new prescriptions of gender-affirming hormones for those aged under 18 years old.

Read the full explainer here: https://tinyurl.com/under18sGAHpause

We will continue to campaign against this attempt to strip people of their human right to bodily autonomy – please look out for further statements and information in the coming weeks.

Please also help us to continue this work by donating: https://tinyurl.com/DonateTransActual

#TransYouth #NHS #GAHT #TransHealthcare

AI Used to Promote Non-Existent Evacuation Flights From the Middle East - bellingcat

A Dutch newspaper published a story about private evacuation flights from Dubai, but the photo shows signs of AI generation and the flights appear never to have existed.

bellingcat

You owe your soul to the company store. Company scrip is back, but not in the coal mines ...in the AI software mines.

#ML #AI #MLsec

https://www.businessinsider.com/ai-compute-compensation-software-engineers-greg-brockman-2026-3

Silicon Valley is buzzing about this new idea: AI compute as compensation

AI inference emerges as a critical factor in tech compensation, impacting engineer productivity and Silicon Valley hiring dynamics.

Business Insider

Forgot your password? No worries, we attackers can reset even the admin's. 🔑

PTT-2025-030: Matei "Mal" Bădănoiu and Raul Bledea from our team found SQL injection hiding inside the password reset flow of FuelCMS v1.5.2.

The parameters meant to verify your reset token and email? Both injectable.

So a valid reset token becomes a master key to:
🗄️ Dump the entire database
🔑 Reset any account's password, not just yours
✍️ Modify or delete content across the site as the admin

CVSS: 7.7 High. No fix is coming, the FuelCMS master branch hasn't seen a commit in ~4 years. We emailed the vendor. They're as quiet as an unmonitored server at 3am.

See the full technical breakdown in the comments. 👇

#offensivesecurity #vulnerabilityresearch #infosec

OMG I LOVE IT... an AI incident database...YES
https://incidentdatabase.ai/apps/incidents/
Incidents

AIID incidents list

Seeing the reactions to the privacy nightmare of the Meta Ray Ban glasses has inspired me to go poke around what people in the anti-surveillance fashion world have been up to recently and it's kinda fun!

(ICYMI: https://futurism.com/future-society/meta-ray-ban-smart-pervert-glasses)

🧵

People Are Calling Meta Ray-Bans “Pervert Glasses”

On Bluesky, users quickly embraced the term "pervert glasses" to refer to Meta's Ray Ban smart glasses, following a shocking investigation.

Futurism
🚨🚨 URGENT: Multiple political groups are meeting NOW to discuss their voting on the Chat Control amendments TOMORROW. They are being lobbied massively by industry and NGOs. Chat Control hurts everyone. The template has been updated, take contact now: https://fightchatcontrol.eu/ !
Fight Chat Control - Protect Digital Privacy in the EU

Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.