Rob Pomeroy

@robpomeroy@infosec.exchange
801 Followers
904 Following
1,056 Posts

TLDR: #infosec #cloud #devops #OpenSource #a11y #JC #MostlyHarmless

πŸ‘‹πŸ»πŸ”’ Friendly British Security/Technology wonk.

πŸ˜‡πŸ™ Good guy wannabe.
βœπŸ»πŸ‘½ Sci-fi author.
πŸ‘¦πŸ»πŸ‘¦πŸ» Father to twins (one passed away 24 Feb 2024) with severe learning difficulties and other disabilities.
πŸ¦ΈπŸ»β€β™€οΈ Husband to superhero wife.
βš–οΈ Solicitor (no longer practising law though).
✝️ To everything there is a season.

πŸ”πŸ‘πŸ» Visit my website for secure/private methods of contacting me

Website 🌍https://pomeroy.me/about/
GitHub πŸ‘¨πŸ»β€πŸ’»https://robpomeroy.github.io/mastodon.html
Keybase πŸ”‘https://robpomeroy.keybase.pub/mastodon.html
BrightOS πŸ’‘https://github.com/robpomeroy/BrightOS

This is super-super niche, but I just made a little launcher for Visual Studio Code workspaces. Very helpful for quickly opening workspaces based on Windows and/or WSL.

Free & open source: https://github.com/robpomeroy/vscode-launcher

#VSCode #WSL #Windows #Development

#EU_OS looks out for potential early adopters in the public sector to inform the design of the proof of concept.

Many current Linux on the Desktop deployments are in the education sector: schools and universities.

Dear @primtux or any other education Linux project, would you be interested to join the first developer sprint in person in Paris or online?

Event: https://hackdays.numerique.gouv.fr/

Planning: https://gitlab.com/eu-os/eu-os.gitlab.io/-/issues/31

@bluehats @codegouvfr @blagarrigue
@ThierryM
#plasma #gcompris #endof10

HackDays - Hackathon Digital Workspace

Les 2, 3 et 4 Juin 2025 - Travaillons ensemble Γ  dΓ©velopper des outils souverains & open source

Marks and Spencer cyber incident = ransomware.

It's DragonForce ransomware cartel, they have encrypted their VMware ESXi clusters. Lines up with network traffic I saw.

https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/

Marks & Spencer breach linked to Scattered Spider ransomware attack

Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as "Scattered Spider" BleepingComputer has learned from multiple sources.

BleepingComputer

Dear America,

WHAT?!

"Individuals associated with DOGE have attempted to exfiltrate and alter data while also using high-level systems access to remove sensitive information..."

Whistleblower describes how DOGE tore through NLRB IT system β€’ The Register
https://www.theregister.com/2025/04/17/whistleblower_nlrb_doge/

#1984 #dictatorship #exfiltration #DataBreach

Whistleblower describes DOGE IT dept rampage at America's labor watchdog

: Ignored infosec rules, exfiltrated data … then the mysterious login attempts from a Russian IP address began – claim

The Register

"Credential stuffing as a service".

https://www.bleepingcomputer.com/news/security/new-atlantis-aio-automates-credential-stuffing-on-140-services/

Imagine if these people used their powers for good? 😏

#Cybercrime #Innovation

New Atlantis AIO platform automates credential stuffing on 140 services

A new cybercrime platform named 'Atlantis AIO' provides an automated credential stuffing service against 140 online platforms, including email services, e-commerce sites, banks, and VPNs.

BleepingComputer
This one hits too close tbh

DrayTek routers in the UK (and to a lesser extent elsewhere) are having A Bad Weekend. Lots of "spontaneous" reboots.

Also, DrayTek's UK website is unreachable. So this looks like a concerted attack.

Details are patchy, but ISP Review is tracking the problem: https://www.ispreview.co.uk/index.php/2025/03/broadband-isps-report-uk-connectivity-problems-with-vulnerable-draytek-routers.html

Applying firmware upgrades and disabling VPN services will help. Search your networks for indicators of compromise.

#DrayTek #Outage #DDoS #CVE

Broadband ISPs Report UK Connectivity Problems with Vulnerable DrayTek Routers

A number of broadband ISPs from across the United Kingdom (and possibly other countries too), such as ICUK and Andrews & Arnold (AAISP), have this weekend n

ISPreview UK

LastPass* in the Krebs spotlight again for all the wrong reasons...

Feds Link $150M Cyberheist to 2022 LastPass Hacks – Krebs on Security
https://krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/

*I remain a LastPass user. Come at me bro.

#LastPass #Crypto

Feds Link $150M Cyberheist to 2022 LastPass Hacks – Krebs on Security

Trump 2.0 Brings Cuts to Cyber, Consumer Protections – Krebs on Security