Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Caint logo. It's just text.
Kevin BeaumontG

gossithedog@cyberplace.social

@gossithedog@cyberplace.social
Welcome to Caint!

Issues? Post in Comments & Feedback
You can now view, reply, and favourite posts from the Fediverse. You can click here or click on the on the navigation bar on the left.
About
Posts
55
Topics
10
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • I’ll say the elephant in the room - due to the sheer amount of Salesforce customers who have been hit, and that Salesforce is a fully SaaS service - Salesforce should have detected and been more proactive about all of their customer’s data being stolen.
    Kevin BeaumontG Kevin Beaumont

    I’ll say the elephant in the room - due to the sheer amount of Salesforce customers who have been hit, and that Salesforce is a fully SaaS service - Salesforce should have detected and been more proactive about all of their customer’s data being stolen. https://databreaches.net/2025/09/11/exclusive-high-end-fashion-retailers-gucci-balenciaga-brion-and-alexander-mcqueen-hit-by-salesforce-attacks/

    Uncategorized

  • pretty good example of why I think cybersecurity is getting worse, not better, in the trenches
    Kevin BeaumontG Kevin Beaumont

    pretty good example of why I think cybersecurity is getting worse, not better, in the trenches

    Uncategorized

  • Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.
    Kevin BeaumontG Kevin Beaumont

    JLR have started switching border routers back on (don't ask me why SNMP, NTP and SSH are internet facing).

    Uncategorized

  • Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.
    Kevin BeaumontG Kevin Beaumont

    JLR are keeping car production closed until least Monday. They also say “some data was impacted”, whatever that means.

    https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-issues-crisis-32447659

    Uncategorized

  • Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡
    Kevin BeaumontG Kevin Beaumont

    I didn’t know about @microsoft before and now I’m enjoying reading their prior toots and trying to decide which one pissed off an MS exec and caused the brand protection squad to arrive.

    Uncategorized

  • As a follow up thread to this - if you use SAP Netweaver and present it directly to the internet, either patch CVE-2025-31324 or put a very robust mitigation in place in front of the SAP webapp.
    Kevin BeaumontG Kevin Beaumont

    As a follow up thread to this - if you use SAP Netweaver and present it directly to the internet, either patch CVE-2025-31324 or put a very robust mitigation in place in front of the SAP webapp.

    Patching rate is still absolutely abysmal, vast majority of orgs years behind any patching.
    https://cyberplace.social/@GossiTheDog/115142288361584633

    Uncategorized

  • Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.
    Kevin BeaumontG Kevin Beaumont

    Jaguar Land Rover car production is still shut down tomorrow, day 8. I’ve checked the network border, everything except one system in UK is also still offline.

    Uncategorized

  • Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡
    Kevin BeaumontG Kevin Beaumont

    If anybody else thinks it's a phishing email btw.. it isn't.

    They also don't appear to know I'm not CEO of the fediverse and can't just delete an account on another server.

    Also, obviously, a parody account is fair use in the US and protected speech so they shouldn't be trying to take them offline, too. It's basically a brand reputation service for Microsoft that damages brand reputation by not understanding brand reputation.

    Uncategorized

  • Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡
    Kevin BeaumontG Kevin Beaumont

    If anybody is wondering, Tracer.ai is legit and operating at the instruction of Microsoft.

    They’re an AI brand protection service which has been systematically harming Microsoft’s brand for a while. An example - getting YouTube videos about Minecraft removed, which has hindered Minecraft’s visibility online (which is a huge part of Xbox revenue). https://www.reddit.com/r/PhoenixSC/comments/1fk28zm/microsoft_has_started_using_some_kind_of_ai_that/

    Uncategorized

  • Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡
    Kevin BeaumontG Kevin Beaumont

    AI causes another embarrassing social media cycle at Microsoft in 3..2..

    Uncategorized

  • Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡
    Kevin BeaumontG Kevin Beaumont

    Oh no 🤣

    Uncategorized

  • Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡
    Kevin BeaumontG Kevin Beaumont

    Apparently Microsoft don’t understand how the Fediverse works, and want me to delete the parody account @microsoft 🤣🫡

    Uncategorized

  • That NodeJS supply chain hack incident is amazing because the threat actor(tm) got RCE access to like a billion devices and ran the world’s shittest Etherum dumper.
    Kevin BeaumontG Kevin Beaumont

    That NodeJS supply chain hack incident is amazing because the threat actor(tm) got RCE access to like a billion devices and ran the world’s shittest Etherum dumper.

    Imagine if they had done reverse shells instead, or automated lateral movement to ransomware deployment NotPetya style.

    The thing that saved companies here was the threat actor was incompetent crypto boy, nothing more.

    Uncategorized

  • Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.
    Kevin BeaumontG Kevin Beaumont

    Just checked in on JLR - factory production won't be resuming tomorrow (day 7).

    Uncategorized

  • Malicious javascript compromise on npmjs
    Kevin BeaumontG Kevin Beaumont

    For anybody confused about how this happens, basically:

    - For about the past 15 years every business has been developing apps by pulling in 178 interconnected libraries written by 24 people in a shed in Skegness

    - For about the past 2 years orgs have been buying AI vibe coding tools, where some exec screams "make online shop" into a computer and 389 libraries are added and an app is farted out

    The output = if you want to own the world's companies, just phish one guy in Skegness

    Uncategorized

  • Malicious javascript compromise on npmjs
    Kevin BeaumontG Kevin Beaumont

    Developer confirms they fell for phishing email

    It looks like others have too, found one other compromised repo from a different user, will have a dig tomorrow as bored of cyber tonight.

    https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y

    Uncategorized

  • Malicious javascript compromise on npmjs
    Kevin BeaumontG Kevin Beaumont

    Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.

    Uncategorized

  • Malicious javascript compromise on npmjs
    Kevin BeaumontG Kevin Beaumont

    Weekly download stats for impacted packages prior to incident

    ansi-styles (371.41m)
    debug (357.6m)
    backslash (0.26m)
    chalk-template (3.9m)
    supports-hyperlinks (19.2m)
    has-ansi (12.1m)
    simple-swizzle (26.26m)
    color-string (27.48m)
    error-ex (47.17m)
    color-name (191.71m)
    is-arrayish (73.8m)
    slice-ansi (59.8m)
    color-convert (193.5m)
    wrap-ansi (197.99m)
    ansi-regex (243.64m)
    supports-color (287.1m)
    strip-ansi (261.17m)
    chalk (299.99m)

    Total 2674m

    Uncategorized

  • Malicious javascript compromise on npmjs
    Kevin BeaumontG Kevin Beaumont

    additional backdoored packages

    ansi-styles
    debug
    chalk
    supports-color
    strip-ansi
    ansi-regex
    has-ansi

    Uncategorized

  • Malicious javascript compromise on npmjs
    Kevin BeaumontG Kevin Beaumont

    If you want an idea of scale of trojan attempt - 'color' alone had 32m downloads in a week, the combined attempt was pushing a billion due to upstream dependencies.

    Hunt tip: look for registry.npmjs.org in proxy logs, package names are in the URLs.

    Uncategorized
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups