Advertisement · 728 × 90

Posts by InfoSanity Research Group

Wasn't sure on the plan when originally signing up for BlueSky (other than fleeing the $OtherPlace)

Needing to re-organise. So, splitting personas....

Stay here for professional(ish) InfoSec releases. For personal stuff and uneducated hot-takes, come find me @andrew.waitesworld.co.uk

11 months ago 0 0 0 0
Holy Smoke (2015 Remaster)
Holy Smoke (2015 Remaster) YouTube video by Iron Maiden - Topic

It’s an Iron Maiden sort of day, not sure why….

youtu.be/9a7xa6W39o4

11 months ago 0 0 0 0
Preview
Politics latest: Should 'headphone dodgers' be fined? The Liberal Democrats have put forward a policy idea to fine people £1,000 for playing music out loud on public transport. The government suggests it's open to the idea - and we asked for your thought...

Yes, yes, a 1000-times yes - one of my major per-peeves

news.sky.com/story/politi...

11 months ago 1 1 0 0

Fills me with the same question I always have with stats like that:

20% increase in breaches?
20% increase in breaches *reported*?
20% increase in breaches *detected*?

From the data I’m never 100% confident of the correct narrative, and always spun all ways depending on vendors’ goal.

1 year ago 1 0 0 0

“I never heard of when a kid…”

When I was a kid, I knew nothing about nothing. When I grew up I (tried) to learn and fill in the blanks. I did not just assume that I’m anything I didn’t personally know about was wrong/fiction/conspiracy.

How big an ego do you need to make that leap?

1 year ago 1 0 0 0

This is cool af y’all

1 year ago 13 3 2 0

Started my career running a colo-DataCentre.

The look of bewilderment when explaining “we run part of the Internet” or better, showing them the racks, cables and blinky lights is something I’ll never forget.

One Old Chap discussing WiFi, staring at ceiling like he could see packets in the air…

1 year ago 0 0 0 0
Preview
It's 2025... so why are obviously malicious advertising URLs still going strong? - SANS Internet Storm Center It's 2025... so why are obviously malicious advertising URLs still going strong?, Author: Jan Kopriva

Simple, because they still work

If they weren’t successfully achieving the goals of Threat Actors, TAs would move on. whilst they achieve the aim, why reinvent the wheel?

isc.sans.edu/diary/31880

1 year ago 0 0 0 0

Woohoo!

Tickets acquired - see you there

1 year ago 1 0 0 0

If it wasn’t a real data breach, and no tangible impact, orgs would have no issue being open and transparent. The fact that guidelines like these provide wiggle room for silence, is deafening

1 year ago 2 0 0 0
Advertisement
Preview
KeyPlug Server Exposes Fortinet Exploits & Webshell Activity Targeting a Major Japanese Company Briefly exposed KeyPlug infrastructure revealed Fortinet exploits, encrypted webshells, and recon scripts targeting Shiseido, a major Japanese enterprise. Learn more..

A Chinese APT left a server exposed and leaked its exploits

-Fortinet firewall and VPN exploit scripts
-A PHP-based webshell
-Network reconnaissance scripts

hunt.io/blog/keyplug...

1 year ago 40 12 2 0

It’s strange (and terrifying), I’m currently in US on vacation (booked *long* before $currentTimes), and I’ve been discussing current events and issues with some locals, who were previously completely unaware of goings on (and not just recent, “happened yesterday” events either….)

1 year ago 3 0 0 0

I’ve watched the WayBack machine grow from interesting curiosity to cultural necessity.

In the darkness of misinformation, silent edits and rewriting of history, WayBack machine offers a light in the dark.

It needs protecting at all costs.

1 year ago 1 0 0 0

I’ve been meaning to pickup new egg cups after smashing one of the set.

Not seen these yet (on vacation and away from hobby news). On the scale of “paint pot to Titan”, how scared should my wallet be?

1 year ago 1 0 1 0

Can confirm that my NSF grant "How False Beliefs Form & How to Correct Them" was cancelled today because it is "not in alignment with current NSF priorities" Shocking that understanding how people are misled by false information is now a forbidden topic. Our work will continue but at a smaller scale

1 year ago 3079 1370 142 64
Ticket purchase page for BSides Cheltenham. All currently available tickets sold out.

Ticket purchase page for BSides Cheltenham. All currently available tickets sold out.

Downside of vacation: timezones, missed ticket release for @bsideschelt.bsky.social

Just keep my eyes open for the next release

1 year ago 0 0 0 0
Get Carter (Michael Caine version) cinema poster: Caine, holding shotgun

Get Carter (Michael Caine version) cinema poster: Caine, holding shotgun

1 year ago 1 0 0 0

Oh wow. This just in from a CISA spokesperson:

“The CVE Program is invaluable to cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.”

1 year ago 375 114 8 16

I doubt anyone would….*intentionally*.

I also highly doubt the current administration is competent enough to be trusted the the centralised functions we’ve all accepted that US Institutions run for the global collective up until this point. And not sure we can pivot fast enough to avoid pain now

1 year ago 1 0 0 0
Advertisement
Preview
A whistleblower's disclosure details how DOGE may have taken sensitive labor data A whistleblower tells Congress and NPR that DOGE may have taken sensitive labor data and hid its tracks. "None of that ... information should ever leave the agency," said a former NLRB official.

Oh dear you’re going to want to read this. Looks like DOGErs were caught exfiltrating NLRB data, likely on unions, for private (seemingly Elony) use. This is must read. What we’ve all suspected. But now details. www.npr.org/2025/04/15/n...

1 year ago 11226 5424 356 582

Seen too many junior (and senior, tbf) devs blindly run what the LLM BS-Machine spits out, then troubleshoot from there.

Probably should have already been a control, but time to allowlist packages (or at least monitor) in the same vein as we (should) limit DNS, web and other external content?

1 year ago 1 0 0 0

I want to make jokes in reply, but they all make me sad and (more) depressed….

1 year ago 1 0 0 0
Preview
In Support of Chris Krebs and SentinelOne Chris Krebs and his current employer are under investigation. If the infosec community unites to speak up for our friends and colleagues and leaves politics out of it, we can help strengthen our share...

I’m speaking up in support of @thekrebscycle.bsky.social & @sentinelone.com
Cybersecurity should be a non-partisan issue that unites us in our shared mission to defend our country.
National security can’t afford the chilling effect on both public & private sector
www.lutasecurity.com/post/in-supp...

1 year ago 307 99 5 4

DShield one might do what you need, couple of their recent articles covered findings from similar deployments.

They freely share data via API feeds if you want to poke around some datasets whilst you get a feel for what you’re looking to look for.

1 year ago 1 0 1 0

Depends what protocols you’re looking for? Dshields honeypot isn’t a bad starting point. With HTTP*/SSH/telnet.

For “multi” I typically run different protocol pots via K8s/similar, and aggregate to a central log/analysis platform depending on needs/wants.

1 year ago 1 0 1 0

Expressing public support for Chris Krebs, Alex Stamos, and Renee DiResta.

They were doing their jobs.

And they should be celebrated, not vilified.

1 year ago 12 2 0 0
Advertisement

The former was trying to protect themselves, so is the latter.

1 year ago 68 11 1 0

The InfoSec industry needs to step up and push back against the USG’s moves here, which read like Soviet Russia.

Targeting Chris Krebs and his employer (and CISA) like this is appalling. Chris, a Republican if memory serves, was a great leader for CISA.

1 year ago 41 18 4 0
Post image
1 year ago 35 7 3 0