25 Followers
9 Following
476 Posts
"You learn something new every day, if you're not careful." — Wilf Lunn
LocationDuluth, MN
@briankrebs Sign-in required.
@munin Still a better CEO than Elon.

Exciting news for open source + vuln nerds alike: runZero now speaks Nuclei!

We 🩵 open source and are beyond excited to announce that we have added initial support for ProjectDiscovery’s open source Nuclei scanner — kicking off with safe, targeted checks for default and weak web credentials across IT, OT, IoT, and cloud environments.

Check out today's post from @todb to see how we:

✅ Curated ~180 safe, non-disruptive templates
✅ Only run checks when services are positively fingerprinted
✅ Keep scans fast, polite, and precise — even in fragile ICS environments

This is just the beginning. More protocols, smarter checks, and community collaboration ahead!

👉 Check it out: https://www.runzero.com/blog/integrating-nuclei/

Remarkable investigation into Telegram by IStories (in Russian):
https://www.istories.media/stories/2025/06/10/kak-telegram-svyazan-s-fsb/

English version by OCCRP:
http://www.occrp.org/en/investigation/telegram-the-fsb-and-the-man-in-the-middle

tl;dr:

👉 Telegram uses a single company with ties to the Russian FSB as their sole infrastructure provider, globally.

👉 Combined with a cleartext device identifier Telegram's protocol requires to be prepended to all encrypted messages, this allows for global surveillance of Telegram users.

I am quoted in this story.

#Telegram #InfoSec #Privacy

Как «Телеграм» связан с ФСБ

За инфраструктуру мессенджера отвечают те, кто обслуживает секретные комплексы российских спецслужб, используемые для слежки за гражданами

@briankrebs I have very flat ridges on my fingertips, plus sometimes eczema. Fingerprint scanners basically don't work for me.

It was a big problem when I was getting citizenship and they wanted to take my fingerprints.

Shortly after waking up I got a possible fraud attempt notification from AmEx. 15 minutes later, I'd canceled the card. Sorry not sorry, thief.
10 MB hard disk from the 1960's

For TechCrunch, I wrote about Thinkst Canary, a bootstrapped maker of honeypots (for catching hackers), which this month marks its 10th anniversary. The company now brings in $20 million in ARR without VC funding or an outbound sales team.

Refreshing at a time when cyber is dominated by VC dollars.

https://techcrunch.com/2025/05/29/a-decade-in-bootstrapped-thinkst-canary-reaches-20m-in-arr-without-vc-funding/

A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding | TechCrunch

Reflecting on 10 years since its launch, the honeypot maker explains why the company did not take on any VC funding.

TechCrunch

@briankrebs There are also the VPNs with ties to ex-spies from the Israeli IDF, that advertise themselves on web sites they own that pretend to be independent reviews of VPNs.

https://www.mintpressnews.com/exposed-how-israeli-spies-control-your-vpn/288259/

Exposed: How Israeli Spies Control Your VPN

A new report uncovers the troubling ties between top VPN services like ExpressVPN and the Israeli security state, raising alarms about how much control Israel’s Unit 8200 has over your online privacy.

MintPress News

@rhialto I think passkeys are for people who won't use long passwords in a password manager. Like my mother, for example.

Passkeys can be stored in a password manager and synced between devices just like passwords. The main thing missing so far is a standard import/export format, but apparently that's being worked on.