Rob Pomeroy

820 Followers
902 Following
1,065 Posts

TLDR: #infosec #cloud #devops #OpenSource #a11y #JC #MostlyHarmless

๐Ÿ‘‹๐Ÿป๐Ÿ”’ Friendly British Security/Technology wonk.

๐Ÿ˜‡๐Ÿ™ Good guy wannabe.
โœ๐Ÿป๐Ÿ‘ฝ Sci-fi author.
๐Ÿ‘ฆ๐Ÿป๐Ÿ‘ฆ๐Ÿป Father to twins (one passed away 24 Feb 2024) with severe learning difficulties and other disabilities.
๐Ÿฆธ๐Ÿปโ€โ™€๏ธ Husband to superhero wife.
โš–๏ธ Solicitor (no longer practising law though).
โœ๏ธ To everything there is a season.

๐Ÿ”๐Ÿ‘๐Ÿป Visit my website for secure/private methods of contacting me

Website ๐ŸŒhttps://pomeroy.me/about/
GitHub ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ปhttps://robpomeroy.github.io/mastodon.html
Keybase ๐Ÿ”‘https://robpomeroy.keybase.pub/mastodon.html
BrightOS ๐Ÿ’กhttps://github.com/robpomeroy/BrightOS

Extremely cool breakdown of some self-replicating malware that probably (?) predates Stuxnet by 5 years:

https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/

#stuxnet #malware

fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet

A previously unknown 2005 cyber sabotage framework patches high-precision calculation software in memory to silently corrupt results.

SentinelOne

Given the offensive capabilities of Mythos, what will the US government do (once the petty squabbles have subsided)?

A) Classify Mythos and similar models as a weapon, restricting their use and export.
B) Ban the use of such models except by US military and defence agencies.
C) Find some financial pretext for burying American AI companies with red tape, penalties and lawsuits.
D) All of the above.

#ai #ml #mythos

That's a bit embarrassing!

Iran-Linked Hackers Breach FBI Directorโ€™s Personal Email, Hit Stryker With Wiper Attack
https://thehackernews.com/2026/03/iran-linked-hackers-breach-fbi.html

#FBI #hackers #Iran #breach

Iran-Linked Hackers Breach FBI Directorโ€™s Personal Email, Hit Stryker With Wiper Attack

Iran-linked Handala Hack breached FBI Directorโ€™s email amid MOIS domain seizures, escalating destructive cyber ops.

The Hacker News

This is a decent read - one way of avoiding US cloud infrastructure providers.

"Made in EU" - it was harder than I thought.
https://www.coinerella.com/made-in-eu-it-was-harder-than-i-thought/

#cloud #trade #us #eu #sovereignty

"Made in EU" - it was harder than I thought.

I tried building my startup entirely on European infrastructure. Here's the stack I landed on, what was harder than expected, and what you still can't avoid.

Coinerella

This is a great paper on the risks of malicious servers when using password managers: https://zkae.io/. I understood about 2% of it.

You have to dig down in the paper to see that there was pretty good engagement from the password manager developers, once contact was established. That's encouraging, particularly in the light of recent reputational damage suffered by LastPass, and doubts about its future under private equity ownership.

#crypto #passwordmanager #lastpass #dashlane #bitwarden #1password

Great teardown of the Notepad++ breach by Rapid7: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/

Definitely worth checking your logs for these IoCs. Stealth level is high. Standard AV is unlikely to detect.

#malware #stateactor #lotusblossom #notepadplusplus

The Chrysalis Backdoor: A Deep Dive into Lotus Blossomโ€™s toolkit

Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.

Rapid7

Oof. With my legal background, this one hits close to home! ๐Ÿ˜ฌ

The ICO fined a law firm after data breach and subsequent leak to dark web. Identities of protected victims and witnesses were exposed. All attackers gained access to an old, supposedly archived case management system. (Why was this online?)

https://www.lawsociety.org.uk/topics/ethics/dark-web-data-leak

Given the size of the fine (ยฃ60k), I would guess this was not a large law firm. Some of the affected individuals may sue, so that's probably not the end of the matter.

#databreach #law #lawfirm #ico #darkweb #exfiltration

Dark web data leak: firm fined following breach

Jonathan Friend considers a genuine case where a data breach led to client details being leaked on the dark web.

Boo. ๐Ÿ™๐Ÿ‘Ž

"an autistic man ... was told he had to stop stacking shelves at a Waitrose store where he had worked as a volunteer for years"

"his placement was stopped when the firm's head office was asked about the possibility of paid work"

https://www.bbc.co.uk/news/articles/c205le1e27zo

Hooray! ๐Ÿ™‚๐Ÿ‘

"Asda have offered him two five-hour paid shifts a week"

https://www.bbc.co.uk/news/articles/c98n53dpzx6o

Asda wins this particular PR skirmish. ๐Ÿค”

#autism #diversity #inclusion #PR #Waitrose #Asda

Some pretty sane recommendations about password requirements from NIST. Don't make it hard for your users!

NIST Special Publication 800-63B
https://pages.nist.gov/800-63-4/sp800-63b.html

NIST Special Publication 800-63B

NIST Special Publication 800-63B