Audra Streetman

@audrastreetman.bsky.social

Threat Intel @ Target

Censys identifies ~2.15M exposed web services running Next.js or other RSC-based frameworks, predominantly in the U.S. and China. Not all are vulnerable, but given the scale, “spray-and-prey” seems more accurate than "spray-and-pray." censys.com/advisory/cve...

December 5 Advisory: Unauthenticated RCE Flaw in React Server Components [CVE-2025-55182]

CVE-2025-55182 is a critical unauthenticated RCE flaw in React Server Components with a CVSS score of 10.

censys.com

Some of the LLM skepticism in security looks more like backlash to hype than analysis. AlphaFold showed how experts can underestimate capability jumps. Dismissing early signals from Anthropic/Google assumes the future stays static, but AI capability and adoption curves may not behave that way.

404 Media is suing ICE for documents relating to its $2 million contract with Paragon Solutions. These are the journalists you should be supporting with your subscription money because they are meeting the moment. www.404media.co/were-suing-i...

We’re Suing ICE for Its $2 Million Spyware Contract

404 Media has filed a lawsuit against ICE for access to its contract with Paragon, a company that sells powerful spyware for breaking into phones and accessing encrypted messaging apps.

404media.co

Supposed experts and mainstream media have spent the past few days hyperventilating over reports of a colossal data breach that exposed more than 16 billion credentials. There’s just one inconvenient detail: evidence to support its sensational claim is lacking. cyberscoop.com/colossal-dat...

The ‘16 billion password breach’ story is a farce

Experts told CyberScoop the research 'doesn’t pass a sniff test' and detracts from needed conversations around credential abuse and information stealers.

cyberscoop.com

Iran has demonstrated its capability/intent to keep up cyber operations amid Israeli strikes. On Friday, an IRGC-linked group targeted Albania's capital in retaliation for the country hosting ~3k Iranian dissidents. The intrusion could disrupt services/expose data: www.politico.eu/article/iran...

Iranian hackers target Albania in retaliation for hosting dissidents

A group tied to Iran’s Revolutionary Guard targeted the capital of Tirana in retaliation for Albania hosting around 3,000 Iranian dissidents.

politico.eu

News: The Washington Post has suffered a cyber intrusion that compromised the emails of at least several reporters at the paper, including those on the national security and economic policy teams, according to people familiar with the matter.

Google's @hultquist.bsky.social‬ says his threat intel team expects Iranian hackers to "rededicate themselves to attacks against Israeli targets" following Israel's bombing operation, though he says 🇮🇷-on🇮🇱 hacking "is already persistent and aggressive." US infrastructure could face more hacks too.

Bild

@npr.org EXCLUSIVE: The Department of Agriculture is demanding states hand over personal data of food assistance recipients — including Social Security numbers, addresses and, in at least one state, citizenship status, according to emails shared with NPR.

USDA, DOGE demand states hand over personal data about food stamp recipients

The Department of Agriculture is demanding sensitive data from states about more than 40 million food stamp recipients, as DOGE is amassing data for immigration enforcement.

npr.org

In December, leading EdTech company PowerSchool was hacked, exposing the private information of tens of millions of American kids. PowerSchool paid the ransom to keep the data private. That apparently didn't work: somebody started using that data today to extort public schools in North Carolina.

School districts hit with extortion attempts months after education tech data breach

The attempted extortion has so far targeted schools in Canada and North Carolina.

nbcnews.com

Hm! He argues the CSRB has to evolve + be fully separated from CISA (it was dismantled at start of Trump 2.0), noting that, during the board's Salt Typhoon probe, some telcos got nervous and said they will not share information with the agency b/c CSRB is tied to the DHS office.

Initial probe into cause of power outages in Spain & Portugal today suggests fault rather than cyberattack, according to the European Union Agency for Cybersecurity (ENISA). “For the moment the investigation seems to point out to a technical/cable issue,” a spokesperson for the agency tells me.

If this contract ends, the damage will be immense. To be clear, that's immense damage to the US' ability to protect its computer systems, both in the commercial and in the public sectors. And yes, this includes critical infrastructure such as power, water, and transportation.

Tib3rius@tib3rius.bsky.social · last yr.

BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.