Sam Bowne 

@sambowne@infosec.exchange
1.3K Followers
731 Following
28.1K Posts
Instructor at CCSF, corporate trainer for Infosec Decoded.
websitehttps://samsclass.info
Mystery of Why Brown Shooter Murdered MIT Genius

Police have announced a shock link between the mass shooting at Brown University and the assassination of a nuclear professor.

The Daily Beast
Infosec Decoded Season 5 #100: Smart Devices Are Stupid
With sambowne@infosec.exchange and Doug Spindler
Recorded Fri, Dec 19, 2025
https://youtu.be/F13H_i-AfDI
Smart Devices Are Stupid

YouTube
Revealed: FBI opened domestic terrorism investigations into anti-ICE activity across US | FBI https://www.theguardian.com/us-news/2025/dec/19/fbi-terrorism-investigations-anti-ice-activity
Revealed: FBI opened domestic terrorism investigations into anti-ICE activity across US

Internal report shared with Guardian shows FBI has launched cases in 23 regions, some linked to Trump memo on thwarting ‘terroristic activities’

The Guardian
Noise machines installed by LA Home Depot ‘torture’ for day laborers, advocates say https://www.theguardian.com/us-news/2025/dec/18/home-depot-la-noise-machines-day-laborers
Noise machines installed by LA Home Depot ‘torture’ for day laborers, advocates say

Advocates call for removal of machines and demand that company speak out against ICE raids in parking lots

The Guardian
It’s time to accept that the US supreme court is illegitimate and must be replaced | Ryan Doerfler and Samuel Moyn https://www.theguardian.com/commentisfree/2025/dec/19/us-supreme-court-legitimacy
It’s time to accept that the US supreme court is illegitimate and must be replaced

We need to remake the US high court so Americans don’t suffer future decades of oligarchy-facilitating rule

The Guardian

HPE OneView CVE-2025-37164 worth paying attention to

- Widely used enterprise management software

- HPE added a REST command, executeCommand, which requires no authentication to execute commands. Obviously, this is dumb and now patched out

- Being on OneView allows attacker to access VMware, 3PAR storage etc by design

- Expect exploitation in the wild as it's so simple

- The vulnerability (executeCommand) was introduced around 2020, feels like a vulndoor

Shodan dork: product:"HPE OneView"

Danish intelligence officials blamed Russia for orchestrating cyberattacks against Denmark's critical infrastructure, as part of Moscow's hybrid attacks against Western nations.

https://www.bleepingcomputer.com/news/security/denmark-blames-russia-for-destructive-cyberattack-on-water-utility/

Denmark blames Russia for destructive cyberattack on water utility

Danish intelligence officials blamed Russia for orchestrating cyberattacks against Denmark's critical infrastructure, as part of Moscow's hybrid attacks against Western nations.

BleepingComputer

Suspicions in the crypto community point to AI-supported hackers carrying out a concentrated campaign to steal around $5 million in old and sometimes abandoned DeFi projects.

Is an AI hacker targeting old DeFi projects in $5M spree?

https://protos.com/is-an-ai-hacker-targeting-old-defi-projects-in-5m-spree/

Is an AI hacker targeting old DeFi projects in $5M spree?

Old Ribbon Finance, Yearn Finance and Rari Capital contracts were hacked. Are attackers using AI to scan for missed opportunities in DeFi?

Protos

Russia is responsible for destructive and disruptive cyberattacks against Denmark

PDF: https://www.fe-ddis.dk/globalassets/fe/dokumenter/2025/-russia-responsible-for-cyber-attacks-.pdf

Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability.

https://www.bleepingcomputer.com/news/security/over-25-000-forticloud-sso-devices-exposed-to-remote-attacks/

Over 25,000 FortiCloud SSO devices exposed to remote attacks

Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability.

BleepingComputer