Scott Wilson

@scottwilson@infosec.exchange
370 Followers
363 Following
99 Posts

27+ year information security “professional”.

I like non-alcoholic #beer, #gardening and yardwork, playing guitar, and reading #books (mystery, thriller, suspense, #scifi, fantasy, astrophysics, and cosmology).

Stage IIIB #ColorectalCancer survivor.

I'm a middle-aged, middle class, Christian, husband, dad, doggy-daddy, and friend. I’m supporter of #LGBTQIA rights, a #BlackLivesMatter advocate, a believer in #TransRights and proponent of equality. I support #Ukraine.

Only hand-crafted, artisanal memes.

Posts are on auto-delete (1 week).

Home Pagehttps://bscottwilson.com
Codehttps://codeberg.org/bswilson

Servo Report Week 25 2025

Recent project highlights:
- Encoding improvements making Servo pass over 1.7M WPT subtests now
- More progress on WebDriver support
- Start using fontations to read font tables
- Initial IndexDB support
- Continue work on ImageBitmap implementation

You can help support Servo, an independent web browser engine, and the health of the web ecosystem by donating:

https://github.com/sponsors/servo
https://opencollective.com/servo

@Vivaldi, keep this up. This is what people want. They don't want AI integration in everything.

Next, Open Source the browser. Opening up the source will gain a lot of new users. I can almost guarantee this. Each time I post something about Vivaldi here on Mastodon, the main comment I get is, "I won't use Vivaldi because it's not Open Source."

https://mastodon.world/@Captain_Jack_Sparrow/114755366285625623

#vivaldi #opensource #ai

Captain Jack Sparrow (@Captain_Jack_Sparrow@mastodon.world)

I just switched by browser to #Vivaldi because they refuse to include AI

Mastodon
I just switched by browser to #Vivaldi because they refuse to include AI
🙈 Cute & Funny Animals 🙉 (@CuteFunnyAnimals@mastodonapp.uk)

Attached: 1 image #Cat #Cats #CatClothing #CatClothes. #Animal #Animals #CuteAnimal #CuteAnimals #FunnyAnimal #FunnyAnimals #Meme #Memes

Mastodon App UK
I got a text from a "lawyer" saying they had trademarked my business name and I had to either pay them or "cease using the name immediately." I googled the phone number and it came up associated with a group of scammers so I screen shot that with a "This you?" message. He responded, "Have a blessed day." 🤣
I'm excited to announce our "Out-of-Band" series; these articles focus on the security risks of management devices like BMCs, serial servers, and IP-enabled KVMs. "Out-of-Band, Part 1: The new generation of IP KVMs and how to find them" is now live at:
https://www.runzero.com/blog/oob-p1-ip-kvm/
Such amazing news to share soon on @pancakescon - call for volunteers is open, and this year is definitely going to be the most ambitious and exciting yet.

Our Call for Volunteers is now open! Please lend a hand if you can at: https://forms.gle/VF5vzEkq8DomRuZv5

A lot of you asked about hours! This year we will run from 21 September 6AM-3PM US Central Time (Chicago). This is because of a Very Secret Surprise for our Australia friends, to be announced soon...(!)

Call for Sponsors is also open. Swag, badge, and training raffles help our junior attendees and give great name recognition. Contact us at hacks4pancakes at gmail.

PancakesCon 6: Call for Volunteers

This form is to volunteer for virtual shifts on 9/21/2025 between 6:00 AM and 3:00 PM Central US Time, as well as preparatory and post-process work outside those hours. Our con takes a lots of hands to keep running! Please do join our Slack, and read up on the con at pancakescon.com if you are unfamiliar. Slack is linked in the top banner.

Google Docs

The open source Zapier alternative. Build workflow automation without spending time and money.

https://github.com/automatisch/automatisch

GitHub - automatisch/automatisch: The open source Zapier alternative. Build workflow automation without spending time and money.

The open source Zapier alternative. Build workflow automation without spending time and money. - automatisch/automatisch

GitHub
×
-Saudi Games leak
-Another leak on WarThunder forums
-Windows 11 restore points last 60 days now
-Iran strikes had US cyber component
-Telegram dark markets rise to fill void after Huione takedown
-Scammer who stole $4mil from Coinbase customers identified
-Fake SonicWall app steals VPN credentials
-ConnectWise abused to sign malware
-Malware reports on SparkKitty, PulsarRAT, LapDogs botnet
-APT reports on TAG-140, APT36, APT-Q-14, APT-C-06
-Libxml2 makes security reports public by default
-New WinRAR RCE
-New Echo Chamber LLM Attack
-New SSRF technique
-New FileFix technique
-New Phantom Persistence technique
-CIDP shuts down
-Akamai finds method to shut down crypto-mining botnets
-CODE BLUE 2024 videos
-SANS CTI Summit 2025 videos

@campuscodi The "#FileFix" technique has an nonsensical name, but the design decision by #Microsoft which makes it possible is absolutely ridiculous. It at least makes sense to let the user run an executable from in the "Run" dialog; letting the user run an executable from the Location bar makes no sense. What conceivable use case did some engineer have in mind? Or did they just re-use an API without thinking?

They implemented a security defect by design, by violating the Principle of Least Astonishment. Microsoft never ceases to amaze.

https://en.wikipedia.org/wiki/Principle_of_least_astonishment

#humanFactor #POLA

Principle of least astonishment - Wikipedia