Ah niche apps, you've got to love them. My latest open source app is FrameFit, fixing my own problem: optimising photos for a digital photo frame, for maximum performance.
It's not ground breaking, but it's free!
TLDR: #infosec #cloud #devops #OpenSource #a11y #JC #MostlyHarmless
๐๐ป๐ Friendly British Security/Technology wonk.
๐๐ Good guy wannabe.
โ๐ป๐ฝ Sci-fi author.
๐ฆ๐ป๐ฆ๐ป Father to twins (one passed away 24 Feb 2024) with severe learning difficulties and other disabilities.
๐ฆธ๐ปโโ๏ธ Husband to superhero wife.
โ๏ธ Solicitor (no longer practising law though).
โ๏ธ To everything there is a season.
๐๐๐ป Visit my website for secure/private methods of contacting me
| Website ๐ | https://pomeroy.me/about/ |
| GitHub ๐จ๐ปโ๐ป | https://robpomeroy.github.io/mastodon.html |
| Keybase ๐ | https://robpomeroy.keybase.pub/mastodon.html |
| BrightOS ๐ก | https://github.com/robpomeroy/BrightOS |
Ah niche apps, you've got to love them. My latest open source app is FrameFit, fixing my own problem: optimising photos for a digital photo frame, for maximum performance.
It's not ground breaking, but it's free!
Extremely cool breakdown of some self-replicating malware that probably (?) predates Stuxnet by 5 years:
Given the offensive capabilities of Mythos, what will the US government do (once the petty squabbles have subsided)?
A) Classify Mythos and similar models as a weapon, restricting their use and export.
B) Ban the use of such models except by US military and defence agencies.
C) Find some financial pretext for burying American AI companies with red tape, penalties and lawsuits.
D) All of the above.
That's a bit embarrassing!
Iran-Linked Hackers Breach FBI Directorโs Personal Email, Hit Stryker With Wiper Attack
https://thehackernews.com/2026/03/iran-linked-hackers-breach-fbi.html
This is a decent read - one way of avoiding US cloud infrastructure providers.
"Made in EU" - it was harder than I thought.
https://www.coinerella.com/made-in-eu-it-was-harder-than-i-thought/
This is a great paper on the risks of malicious servers when using password managers: https://zkae.io/. I understood about 2% of it.
You have to dig down in the paper to see that there was pretty good engagement from the password manager developers, once contact was established. That's encouraging, particularly in the light of recent reputational damage suffered by LastPass, and doubts about its future under private equity ownership.
#crypto #passwordmanager #lastpass #dashlane #bitwarden #1password
Great teardown of the Notepad++ breach by Rapid7: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
Definitely worth checking your logs for these IoCs. Stealth level is high. Standard AV is unlikely to detect.
Oof. With my legal background, this one hits close to home! ๐ฌ
The ICO fined a law firm after data breach and subsequent leak to dark web. Identities of protected victims and witnesses were exposed. All attackers gained access to an old, supposedly archived case management system. (Why was this online?)
https://www.lawsociety.org.uk/topics/ethics/dark-web-data-leak
Given the size of the fine (ยฃ60k), I would guess this was not a large law firm. Some of the affected individuals may sue, so that's probably not the end of the matter.
Boo. ๐๐
"an autistic man ... was told he had to stop stacking shelves at a Waitrose store where he had worked as a volunteer for years"
"his placement was stopped when the firm's head office was asked about the possibility of paid work"
https://www.bbc.co.uk/news/articles/c205le1e27zo
Hooray! ๐๐
"Asda have offered him two five-hour paid shifts a week"
https://www.bbc.co.uk/news/articles/c98n53dpzx6o
Asda wins this particular PR skirmish. ๐ค