Last notice: This account will be deleted soon. Find me @mbrookspetersen.eurosky.social
Layer Old½
@layer8-half.eurosky.social
I'm a Security Awareness & Culture Specialist. This account will soon be deactivated and my publishing will continue on mbrookspetersen.eurosky.social.
I deleted my leaflet publication. I will be up and running again soon. @leaflet.pub : any idea, when the subdomain will be available again after deleting the publication?
Since it is not possible to change the DID (expeted) or to migrate account data this account will be deleted shortly and I will continue all this on a new account. I'll keep you few posted.
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
theregister.com
New: image galleries, lightboxing, and more — great for photos, illustrations, comics & other visual publishing! 🌅🌆🌉🏞️🎆🏙️ 🔸 image gallery block with three modes: grid, carousel, strip 🔺 lightboxing for both galleries & single images 🔹 *also* improved alt text & made it easier to add cover images
A threat actor has deployed an AI agent to hack Langflow servers, steal credentials, expand access, and then deploy ransomware on production databases The attacks are the first known cybercriminal campaign to be fully automated using an AI agent from start to finish www.sysdig.com/blog/jadepuf...
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig
The Sysdig TRT documents JADEPUFFER: the first known agentic ransomware operation, where an LLM autonomously exploited Langflow, harvested credentials, and executed full database extortion.
sysdig.com
🎵 Ihr seid gut genuuuuuuug. Ihr seid gut genuuuuuug. 🎶 Fehler gehören zum Alltag, auch im digitalen Raum. Wir vom BSI sind für euch da & helfen euch mit unseren Tipps & Tricks durch die kleinen & großen Cyber-Pannen. Gemeinsam im #TeamBSI, für mehr #Cybersicherheit & die #CybernationDeutschland. 🫶
AirDrop and Quick Share have some common bugs Attackers need to be within 10 to 30 meters of a target to exploit the bugs No pairing, authentication, or user interaction is needed www.helpnetsecurity.com/2026/06/30/a... arxiv.org/abs/2606.26967
AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin - Help Net Security
Six AirDrop Quick Share vulnerabilities span iOS, macOS, Android, and Windows, affecting protocols on over five billion devices.
helpnetsecurity.com
Microsoft's played a blinder with this one btw. Copilot is in almost everywhere now. Microsoft are throwing billions at it each month subsidising it to hook orgs. I'll give you a spoiler: orgs are going to get a bill they can't afford in the future.
If major US banks can't afford staff GenAI usage already - these organisations have deep deep deep pockets - good luck to organisations that haven't upgraded from Windows 7 yet. Which is a lot of organisations.
“Companies across tech, entertainment, banking, and many other industries are throttling their employees’ use of AI and pleading with workers to use less powerful models to stop AI costs from spiraling out of control…”
Threat actors are mass-scanning the internet for misconfigured LLM backend servers. Mass-reconnaissance campaigns have been spotted targeting Ollama, LiteLLM, Langserv, and OpenClaw infrastructure labs.zenity.io/p/scanning-f...
Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild
labs.zenity.io
Cybersecurity Mission Creep in the US Interesting paper: "Cybersecurity Mission Creep." Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of… https://www.schneier.com/blog/archives/2026/07/cybersecurity-mission-creep-in-the-us.html
Cybersecurity Mission Creep in the US
Interesting paper: "Cybersecurity Mission Creep." Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls "cybersecuritized." Before this reframing, these issues present as important but not existential.
schneier.com
The Gentlemen ransomware group has been spotted abusing a zero-day in the Kontron API driver (ktapi.sys) to disable EDR products on the networks they're attacking expel.com/blog/not-ver...
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs
How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.
expel.com
AI is accelerating vulnerability research, enabling defenders to find and prioritize issues faster while also lowering barriers for threat actors. As these capabilities become more accessible, cybersecurity experts expect vulnerability volume to continue growing. msft.it/63325vtZAT
Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website Run Code on Your PC
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website Run Code on Your PC
Signer.Digital's browser extension and its native helper turned a path-traversal bug into drive-by remote code execution on Windows. Any web page you visited could load an attacker DLL into a process ...
amibeingpwned.com
I’ve created a toolkit for tackling the missing piece of (most) DPIAs - impact assessment itself! If you’re interested in spotting hazards and preventing harm, please sign up to this free, open-access webinar where I’ll be showcasing and explaining what I’ve put together theodi.org/news-and-eve...
Data Ethics Professional #14: A smarter way to spot data & AI harms
The ODI was founded in 2012 by Sir Tim Berners-Lee and Sir Nigel Shadbolt, placing us at the heart of the data economy. Our primary mission is to foster transparency, accountability, and innovation th...
theodi.org
🧵 1/ A newly advertised ransomware operation, SevyWare RaaS, is promoting an unusual addition to its affiliate offering: "Violence as a Service." #ThreatIntel #Ransomware
Das KI-Strategiepapier das gerade alle Eliten lesen verschweigt die einzige KI-Architektur die der Bevölkerung nützt. Nicht aus Versehen. Die Autoren verdienen an der Alternative nichts. 🧵
Good morning dear amazing Blueskyroonies of this n that☕🌞 Odinsday, cloudy morning but r clearing up, just a few days til weekend now😉 I wisv yous a superb day full of happiness, kindness, optimism, love, camaradery, insight, magic, funs, joys, smiles, giggles n laughter😊🤙 #MorningGreetings
Mythos on your desk. Source-local code reviews with frontier-like capabilities. Karsten Nohl and I talked for an hour about this in the latest Risky Business Features episode available now on YouTube and your favourite Podcast app. 🎧 risky.biz/RBFEATURES30/ 📺 www.youtube.com/watch?v=nhS5...
Mythos on your desk? Using local LLMs for code reviews - Risky Business Media
In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code [Read More]
risky.biz
Not a great economy alert! Wall Street Bets users think Palantir spiked today because The Onion story titled “Palantir Acquires Pentagon for $800 Billion” hit their front page. They’re guessing trading bots indexed the top post on the subreddit reddit not understanding source.
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered emergency relief-themed domains in just five days. Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
Scammers race to cash in on Venezuelan earthquake disaster
When a devastating earthquake struck north central Venezuela last week, rescue teams were not the only ones who mobilised fast.
bitdefender.com
Wir haben die Technische Richtlinie TR-03188 „Passkey Server“ veröffentlicht. 🤓 Sie richtet sich an alle, die eine Website betreiben. Ziel ist es, Passkeys als Stand der Technik zu definieren. Mehr dazu findet ihr hier: 👉 https://www.bsi.bund.de/dok/1199376
🧵1/ Since its public debut in early June, the emerging VOLTA MaaS stealer has maintained a rapid development cadence, with 6 public updates released in less than a month. Below is a timeline of its development 👇 #ThreatIntel #infosec