Sean Gallagher  🐀 

4.3K Followers
926 Following
1.1K Posts
Principal Threat Poker @ Sophos X-Ops. Natsec/Infosec Editor Emeritus and now infrequent contributor @ Ars Technica. Ex Navy officer and actual battleship sailor. Verified cat furniture. Bird paparazzo. Still mostly s***posting as @[email protected]. Also federating @thepacketrat and @thepacketrat
Works atSophos
Works asPrincipal Threat Researcher
Non-Infosec thingsbirds, pottery, shoulder cats, media criticism, natsec
Twitterhttps://twitter.com/thepacketrat
bloghttps://fancybearfriends.org
Work bloghttps://news.sophos.com/en-us/author/sean-gallagher/
Synapse, you're killing me.
(Reuters) — US Navy has refused near-daily requests from the shipping industry for military escorts through the Strait of Hormuz, saying the risk of attacks is too high for now. https://www.reuters.com/world/middle-east/us-navy-tells-shipping-industry-hormuz-escorts-not-possible-now-2026-03-10/
US Navy tells shipping industry Hormuz escorts not possible for now

The U.S. Navy has refused near-daily requests from the shipping industry for military escorts through the Strait of Hormuz since ​the start of the war on Iran, saying the risk of attacks is too high for now, according to sources familiar with the matter.

Reuters
After an easy breach, hackers leave “TIPS WHEN RUNNING A SECURITY COMPANY”

DDoS protection firm Staminus apparently stored customers' credit card data in the clear.

Ars Technica

Also, 10 years ago, one of my many conversations with John McAfee. Love him, loathe him, whatever, nobody deserves the ending John got. #mentalhealthawareness

https://arstechnica.com/information-technology/2016/03/john-mcafee-tells-ars-hes-fighting-a-lonely-battle-but-hes-not-lying/

John McAfee tells Ars he’s fighting a lonely battle, but that he’s not lying

The dangers of government overreach are real—and he just wants you to see them.

Ars Technica
Dam you! Justice Dept. to indict Iranians for probing flood control network

2013 breach of Rye, NY dam facility part of wider Iranian probing of US networks.

Ars Technica

Welp.

As of this morning, I am no longer employed, and am looking for a new role.

If you happen to know anyone hiring remote positions in the US, and looking for:

- Lead/Senior/Principal level software engineers (Ruby/Rails, React, NodeJS, etc.)
- Business Analysts
- Engineering Managers

please let me know.

#FediHire #getfedihired #job #jobsearch

This weekend, I demonstrated to my dad that passwords on MacOS are no barrier to someone with physical access (he forgot his password he set the last time he opened his computer to do his taxes).

On a related note, I am hoping he doesn't connect that to my statement that I could not get into my brother's MacBook after he died. I didn't want him going through his search history.

Proof AI is not ready for CTI #36,453,325:

Prompt: Here is some base64-encoded text. Can you extract the URL for me?

AI: (gives an actual URL to an example from an unrelated source)

Me: You hallucinated that didn't you?

AI: Please do your own Cyberchef-ing, I don't deobfuscate malware asshole

It’s been a long winter.
Brace yourselves for critical birb updates.