Jeff McJunkin

1.4K Followers
999 Following
21 Posts
Started in ops and blue team, now I hack for a living. SANS author/instructor in Oregon. Founder of http://roguevalleyinfosec.com. GSE #128. He/him.
A new paper shows that less than 2 months of exposure to Twitter’s algorithmic feed significantly shifts people’s political views to the right. Moving from chronological feed to the algorithmic feed also increases engagement. This is one of the most concerning papers I’ve read in awhile.
@wdormann may be interested to hear -- I got the Python 2.7 CERT Basic Fuzzing Framework ported to Python 3 and Windows 11, along with getting MSEC (!exploitable) compiled using VS 2022, working well enough to find exploitable flaws that Claude Code could then build an exploit for:
@egypt, you are loved and missed at Wild West Hackin' Fest. The chess tournament is still going strong, thanks to you starting it.

If you read between the lines on the JetBrains and Rapid7 story, you'll see that JetBrains decided to cut Rapid7 out of the loop on Feb 23, but told Rapid7 that they're "still investigating" on Mar 1.

However you feel about PoCs, technical details, disclosure, etc., it's super inappropriate to lie to researchers who disclosed this to you responsibly about what your plans are.

Refs:

JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities | Rapid7 Blog

In February 2024, Rapid7's vulnerability research team identified two new vulnerabilities affecting JetBrains TeamCity CI/CD server. Learn more!

Rapid7
@shortstack @chrissanders88 @recon_infosec Thank you, Chris! Always a pleasure.
@iagox86 @skullsecurity Great work! Less work *and* less attack surface all at once!

@hacks4pancakes Lesley, you are constantly, delightfully, wonderfully a force for good.

Thank you ❤️