Rob Pomeroy

@robpomeroy@infosec.exchange
815 Followers
902 Following
1,061 Posts

TLDR: #infosec #cloud #devops #OpenSource #a11y #JC #MostlyHarmless

πŸ‘‹πŸ»πŸ”’ Friendly British Security/Technology wonk.

πŸ˜‡πŸ™ Good guy wannabe.
βœπŸ»πŸ‘½ Sci-fi author.
πŸ‘¦πŸ»πŸ‘¦πŸ» Father to twins (one passed away 24 Feb 2024) with severe learning difficulties and other disabilities.
πŸ¦ΈπŸ»β€β™€οΈ Husband to superhero wife.
βš–οΈ Solicitor (no longer practising law though).
✝️ To everything there is a season.

πŸ”πŸ‘πŸ» Visit my website for secure/private methods of contacting me

Website 🌍https://pomeroy.me/about/
GitHub πŸ‘¨πŸ»β€πŸ’»https://robpomeroy.github.io/mastodon.html
Keybase πŸ”‘https://robpomeroy.keybase.pub/mastodon.html
BrightOS πŸ’‘https://github.com/robpomeroy/BrightOS

This is a great paper on the risks of malicious servers when using password managers: https://zkae.io/. I understood about 2% of it.

You have to dig down in the paper to see that there was pretty good engagement from the password manager developers, once contact was established. That's encouraging, particularly in the light of recent reputational damage suffered by LastPass, and doubts about its future under private equity ownership.

#crypto #passwordmanager #lastpass #dashlane #bitwarden #1password

Great teardown of the Notepad++ breach by Rapid7: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/

Definitely worth checking your logs for these IoCs. Stealth level is high. Standard AV is unlikely to detect.

#malware #stateactor #lotusblossom #notepadplusplus

The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit

Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.

Rapid7

Oof. With my legal background, this one hits close to home! 😬

The ICO fined a law firm after data breach and subsequent leak to dark web. Identities of protected victims and witnesses were exposed. All attackers gained access to an old, supposedly archived case management system. (Why was this online?)

https://www.lawsociety.org.uk/topics/ethics/dark-web-data-leak

Given the size of the fine (Β£60k), I would guess this was not a large law firm. Some of the affected individuals may sue, so that's probably not the end of the matter.

#databreach #law #lawfirm #ico #darkweb #exfiltration

Dark web data leak: firm fined following breach

Jonathan Friend considers a genuine case where a data breach led to client details being leaked on the dark web.

Boo. πŸ™πŸ‘Ž

"an autistic man ... was told he had to stop stacking shelves at a Waitrose store where he had worked as a volunteer for years"

"his placement was stopped when the firm's head office was asked about the possibility of paid work"

https://www.bbc.co.uk/news/articles/c205le1e27zo

Hooray! πŸ™‚πŸ‘

"Asda have offered him two five-hour paid shifts a week"

https://www.bbc.co.uk/news/articles/c98n53dpzx6o

Asda wins this particular PR skirmish. πŸ€”

#autism #diversity #inclusion #PR #Waitrose #Asda

Some pretty sane recommendations about password requirements from NIST. Don't make it hard for your users!

NIST Special Publication 800-63B
https://pages.nist.gov/800-63-4/sp800-63b.html

NIST Special Publication 800-63B

NIST Special Publication 800-63B

It's always sad to see a well-functioning venture killed by friendly fire. I joined the UK's CISP (Cybersecurity Information Sharing Partnership) circa 2017. At that time, CISP had been running for four years.

At its heart, it was an active forum, peopled by information security professionals from diverse public and private sectors in the UK. Was it perfect? No. But professionally, it was an invaluable resource. I found it particularly helpful when investigating issues specific to the legal and maritime sectors, while I managed cybersecurity at international law firm Hill Dickinson. Importantly, much of the information I received and shared on CISP was not available anywhere else, not least information covered by amber/red TLP ratings.

In late 2023, NCSC replaced the forum software with an all-new site based on Microsoft SharePoint. Like many CISP members I was more than willing to attempt to use the new platform. But it quickly became apparent that it was impossible to communicate with the ease we'd previously enjoyed. SharePoint is not forum software.

Active use of CISP evaporated. And today, NCSC has given notice that CISP will be mothballed.

Sad as I am to have lost such a valuable resource (in 2023), I would like to thank all the wonderful people at NCSC that made it happen, and who successfully evangelised its merits. I know your resources are stretched thinly and there's no blame here. If you are ever tasked with recreating the original CISP magic though, count me in.

#CISP #NCSC #eulogy

♻️ Reboost please! Some people say #EU_OS should try to reach out to politicians who use BlueSky instead of Mastodon. EU OS has there so far about 130 follows and on Mastodon 1600. If you use both, please reach out to your BlueSky network: follow and share EU OS on BlueSky!

https://bsky.app/profile/eu-os.eu

#Microsoft #Windows #endof10 #Linux #Trump #tariffs #DigitalSovereignty #Khan

EU OS (@eu-os.eu)

Community-led Proof-of-Concept for a free Operating System for the EU public sector. EU OS is not a project of the European Union, but it should be! πŸ‡ͺπŸ‡Ί https://eu-os.eu. Account operated by https://riemann.cc/about

Bluesky Social

This is super-super niche, but I just made a little launcher for Visual Studio Code workspaces. Very helpful for quickly opening workspaces based on Windows and/or WSL.

Free & open source: https://github.com/robpomeroy/vscode-launcher

#VSCode #WSL #Windows #Development

#EU_OS looks out for potential early adopters in the public sector to inform the design of the proof of concept.

Many current Linux on the Desktop deployments are in the education sector: schools and universities.

Dear @primtux or any other education Linux project, would you be interested to join the first developer sprint in person in Paris or online?

Event: https://hackdays.numerique.gouv.fr/

Planning: https://gitlab.com/eu-os/eu-os.gitlab.io/-/issues/31

@bluehats @codegouvfr @blagarrigue
@ThierryM
#plasma #gcompris #endof10

HackDays - Hackathon Digital Workspace

Les 2, 3 et 4 Juin 2025 - Travaillons ensemble Γ  dΓ©velopper des outils souverains & open source

Marks and Spencer cyber incident = ransomware.

It's DragonForce ransomware cartel, they have encrypted their VMware ESXi clusters. Lines up with network traffic I saw.

https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/

Marks & Spencer breach linked to Scattered Spider ransomware attack

Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as "Scattered Spider" BleepingComputer has learned from multiple sources.

BleepingComputer