Josh Lemon

@joshlemon.bsky.social

Chief of DIFR at SoteriaSec | SANS Institute Principal Instructor | Digital Forensics & Incident Response geek.

How would your organisation fare in detecting IP theft via a hard drive connected to a sensitive system? "Williams used a portable external hard drive to transfer the exploits out of secure networks at Trenchant's offices in Sydney and Washington, D.C." www.bleepingcomputer.com/news/securit...

Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker

The former head of Trenchant, a specialized U.S. defense contractor unit, was sentenced Tuesday to more than seven years in federal prison for stealing and selling zero-day exploits to a Russian broke...

bleepingcomputer.com

Here's an update on the data breach of court documents from the NSW JusticeLink website. tl;dr - it was an individual that was able to download +9k documents over two months, it doesn't appear they were leaked anywhere publicly. www.theguardian.com/australia-ne...

NSW man charged over ‘serious data breach’ that exposed thousands of sensitive court documents

More than 9,000 files downloaded from NSW JusticeLink system but authorities say no personal data compromised

theguardian.com

🚨 New Critical RCE in Erlang/0TP SSH (CVSS 10) - CVE-2025-32433 - Exploitable without authentication needed - Exists in Erlang's built-in SSH server - Commonly found in loT and Teleco gear - Exploit model now in Metasploit and on GitHub