<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-02-06T09:58:53Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Kevin Beaumont</title>
  <author>
    <name>Kevin Beaumont</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1lcc6wn885u6k395x5j5tmdm94r6dh9zajxm8gyk82pv2s2j3el7sc6lcye.rss" />
  <link href="https://yabu.me/npub1lcc6wn885u6k395x5j5tmdm94r6dh9zajxm8gyk82pv2s2j3el7sc6lcye" />
  <id>https://yabu.me/npub1lcc6wn885u6k395x5j5tmdm94r6dh9zajxm8gyk82pv2s2j3el7sc6lcye</id>
  <icon>https://cyberplace.social/system/accounts/avatars/109/387/499/752/708/037/original/a4c1cd571bcb7c2f.jpeg</icon>
  <logo>https://cyberplace.social/system/accounts/avatars/109/387/499/752/708/037/original/a4c1cd571bcb7c2f.jpeg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsq74lfz4s0m3kkxxqeytspysrcyn797qqsx42c3ftdgk9z0dz0utgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gadm7l</id>
    
      <title type="html">Anthropic: we can&amp;#39;t release our vuln research as it will end ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsq74lfz4s0m3kkxxqeytspysrcyn797qqsx42c3ftdgk9z0dz0utgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gadm7l" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg8lwwkfnf4z54v54leg0dklu9r4653lrnmffud7fzgvn5d3eue5cx2ntw4&#39;&gt;nevent1q…ntw4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Anthropic: we can&amp;#39;t release our vuln research as it will end the internet as we know it!!1!&lt;br/&gt;&lt;br/&gt;Me: if I release Teams Roulette I&amp;#39;ll probably cause global chaos with people getting their knobs out in board meetings&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://cyberplace.social/system/media_attachments/files/116/408/555/607/595/490/original/bb5138a4efe55296.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2026-04-15T11:46:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw3uxc7zc7f7pv2r5k0f6k0ahh3carkwcsm9vk46t54a3jh8tx5cszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gtz272</id>
    
      <title type="html">the word create isn&amp;#39;t in the thread anywhere</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw3uxc7zc7f7pv2r5k0f6k0ahh3carkwcsm9vk46t54a3jh8tx5cszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gtz272" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2xnnkd4g28vkjm4tm3ezj4vdkvd43df7syxac4asvk6kdppkhqes43qcwc&#39;&gt;nevent1q…qcwc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;the word create isn&amp;#39;t in the thread anywhere
    </content>
    <updated>2026-03-18T19:08:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0nqwx2a5d046m7yxpfu2zutjp0ddh6xujjrg4rkmw8njeja2cgpqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gfqrf9</id>
    
      <title type="html">Free copy of Battlefield 6 (PC I&amp;#39;m presuming) for anybody ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0nqwx2a5d046m7yxpfu2zutjp0ddh6xujjrg4rkmw8njeja2cgpqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gfqrf9" />
    <content type="html">
      Free copy of Battlefield 6 (PC I&amp;#39;m presuming) for anybody with an EA account -- 3F5T-NDK4-WN93-VEBH &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.ea.com/redeem&#34;&gt;https://www.ea.com/redeem&lt;/a&gt;
    </content>
    <updated>2026-03-18T18:40:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqada5qqlzxzv5vcx8yrf3esg6xt30mzw58ds7l02ez990khgksrczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l658yhhf</id>
    
      <title type="html">don&amp;#39;t worry, all these orgs are also hyping GenAI as the next ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqada5qqlzxzv5vcx8yrf3esg6xt30mzw58ds7l02ez990khgksrczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l658yhhf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv06jg6qr0g7gtpa4yq20zrncw2xkexfslme9asuu9fyeqnck8ksg2cfnqh&#39;&gt;nevent1q…fnqh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;don&amp;#39;t worry, all these orgs are also hyping GenAI as the next big thing.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/116/251/510/836/803/012/original/fdc1725cd4cbb52c.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/116/251/514/609/970/328/original/2eac8fb36b2b3bbc.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/116/251/519/073/424/378/original/386f8f5b11ae2a58.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/116/251/523/822/865/124/original/b47c42a7d5a6320f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-18T18:11:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv06jg6qr0g7gtpa4yq20zrncw2xkexfslme9asuu9fyeqnck8ksgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l67tnhm6</id>
    
      <title type="html">Meta, having renamed itself Meta and spending billions on it, is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv06jg6qr0g7gtpa4yq20zrncw2xkexfslme9asuu9fyeqnck8ksgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l67tnhm6" />
    <content type="html">
      Meta, having renamed itself Meta and spending billions on it, is shutting down it&amp;#39;s metaverse VR platform. &lt;a href=&#34;https://www.theshortcut.com/p/meta-is-shutting-down-horizon-worlds-vr-despite-investing-billions-into-the-metaverse&#34;&gt;https://www.theshortcut.com/p/meta-is-shutting-down-horizon-worlds-vr-despite-investing-billions-into-the-metaverse&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/116/251/502/489/240/665/original/d1f9af6fb14e849b.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-18T18:06:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrvfrt6zyfpqktu5rua25kn7x2572l7lh20uhmjvagvdh2klsv9kczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l63w7nej</id>
    
      <title type="html">We winning. https://www.bbc.co.uk/news/articles/cvg1gr5v333o</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrvfrt6zyfpqktu5rua25kn7x2572l7lh20uhmjvagvdh2klsv9kczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l63w7nej" />
    <content type="html">
      We winning. &lt;a href=&#34;https://www.bbc.co.uk/news/articles/cvg1gr5v333o&#34;&gt;https://www.bbc.co.uk/news/articles/cvg1gr5v333o&lt;/a&gt;
    </content>
    <updated>2026-03-18T15:15:24Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgud6hpdlwvp8f8dx39qzhat0cm8lmrz9dmq32eg28s7z3pmustuszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6fdtg8p</id>
    
      <title type="html">RE: https://mastodon.social/@404mediaco/116241338503387167 Add ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgud6hpdlwvp8f8dx39qzhat0cm8lmrz9dmq32eg28s7z3pmustuszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6fdtg8p" />
    <content type="html">
      RE: &lt;a href=&#34;https://mastodon.social/@404mediaco/116241338503387167&#34;&gt;https://mastodon.social/@404mediaco/116241338503387167&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Add this to the long list of execs fucking up their entire company using GenAI - CEO decides he doesn’t want to pay $250m bonus to staff, asks ChatGPT how to avoid it, his legal team tell him ‘are u fuckin dumb’, he does it anyway, gets sued, and loses in court.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1c24a8nv3xfuj3m4gxvthm566llxe82x4tt5f0kq990xlarsms8lqjkx5y2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1c24…x5y2&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; The CEO of Krafton used ChatGPT to push out the head of the studio developing Subnautica 2 against the advice of his own legal team and failed miserably.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.404media.co/ceo-ignores-lawyers-asks-chatgpt-how-to-void-250-million-contract-loses-terribly-in-court/&#34;&gt;https://www.404media.co/ceo-ignores-lawyers-asks-chatgpt-how-to-void-250-million-contract-loses-terribly-in-court/&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-03-16T23:35:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvndzd6v5k7wev2lclm03sd7j9ef7pf832adv6w4d37eyxl3cu9cszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6w82n37</id>
    
      <title type="html">Stryker have a liveblog of their security incident, linked from ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvndzd6v5k7wev2lclm03sd7j9ef7pf832adv6w4d37eyxl3cu9cszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6w82n37" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszehxpq3a6f8yrcyzdmzcl6hptxwxes9l6hhvjrz3fkz42ljjjdls99ffur&#39;&gt;nevent1q…ffur&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Stryker have a liveblog of their security incident, linked from the front page of their website:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.stryker.com/gb/en/about/news/a-message-to-our-customers-03-2026.html&#34;&gt;https://www.stryker.com/gb/en/about/news/a-message-to-our-customers-03-2026.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;tl;dr is most customer systems aren&amp;#39;t impacted as they run on Linux, but their corporate Windows systems are toast so please hold the line.
    </content>
    <updated>2026-03-16T17:13:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs049j8rsyfphw0a0twe8ct53tt5pv8x2w002ntp7rj70k53f36eugzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f263uu</id>
    
      <title type="html">I still don&amp;#39;t understand the US war on Iran. They declared ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs049j8rsyfphw0a0twe8ct53tt5pv8x2w002ntp7rj70k53f36eugzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f263uu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfrecq8w48ny9uzpkf7wrgc2dq9eknmuhdvzdvu3ychqjzkf740vsptgxkz&#39;&gt;nevent1q…gxkz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I still don&amp;#39;t understand the US war on Iran.  They declared war, then said it wasn&amp;#39;t a war, then it was, then it wasn&amp;#39;t, then it was, then declared victory, said Iran&amp;#39;s military was totally disabled.. and now they&amp;#39;re begging for help from the rest of the world as things keep getting blown up?&lt;br/&gt;&lt;br/&gt;Like - what is the plan here?&lt;br/&gt;&lt;br/&gt;There&amp;#39;s not point asking the UK for help, we probably sold all our boats to Lidl.
    </content>
    <updated>2026-03-16T13:33:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspp9mp799v4yxkw4xxp9taxknwk55aynnxjew5qgdv9jk5a02rvuszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6esg3k6</id>
    
      <title type="html">In other news, Hulu passed on the Buffy reboot, they didn&amp;#39;t ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspp9mp799v4yxkw4xxp9taxknwk55aynnxjew5qgdv9jk5a02rvuszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6esg3k6" />
    <content type="html">
      In other news, Hulu passed on the Buffy reboot, they didn&amp;#39;t like the pilot.  It&amp;#39;s easy to be cynical about that one but from what I&amp;#39;d heard it was actually good, and weird, and got death&amp;#39;d by a thousand exec cuts of clueless people going &amp;#34;we made Buffy The Vampire What?!&amp;#34;
    </content>
    <updated>2026-03-15T19:46:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9duur40nk4tn9kvp4mhnw79fhzjlzppjr6ef55qjxpd92ng2twxqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6up5aee</id>
    
      <title type="html">The Firefly cast have secured the rights to Firefly, and plan to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9duur40nk4tn9kvp4mhnw79fhzjlzppjr6ef55qjxpd92ng2twxqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6up5aee" />
    <content type="html">
      The Firefly cast have secured the rights to Firefly, and plan to turn it into an animated series with the original cast voicing. &lt;a href=&#34;https://deadline.com/2026/03/nathan-fillion-firefly-animated-series-development-1236754122/&#34;&gt;https://deadline.com/2026/03/nathan-fillion-firefly-animated-series-development-1236754122/&lt;/a&gt;
    </content>
    <updated>2026-03-15T19:38:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy8z9305htk92xnlm02xdch8t3d3yc8pe869mh4sgxaqeyq8sf8qszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6cnq7sk</id>
    
      <title type="html">Buzzfeed journey: - Successful - Pivoted to GenAI for content - ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy8z9305htk92xnlm02xdch8t3d3yc8pe869mh4sgxaqeyq8sf8qszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6cnq7sk" />
    <content type="html">
      Buzzfeed journey:&lt;br/&gt;&lt;br/&gt;- Successful&lt;br/&gt;- Pivoted to GenAI for content&lt;br/&gt;- Laid everybody off&lt;br/&gt;- Now admits it probably can&amp;#39;t stay in business&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://futurism.com/artificial-intelligence/buzzfeed-disastrous-earnings-ai&#34;&gt;https://futurism.com/artificial-intelligence/buzzfeed-disastrous-earnings-ai&lt;/a&gt;
    </content>
    <updated>2026-03-14T17:23:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsywev3qcuppvak7wm7ztkf7u2hdm3ykx78yrtf7p9h45fggf5cfvgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6uefjjt</id>
    
      <title type="html">If you use Sourcescrub by Datasite, they&amp;#39;re dumping all the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsywev3qcuppvak7wm7ztkf7u2hdm3ykx78yrtf7p9h45fggf5cfvgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6uefjjt" />
    <content type="html">
      If you use Sourcescrub by Datasite, they&amp;#39;re dumping all the things people export into a public Azure Storage Blob - prodscrubstorage.blob.core.windows.net&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;http://prodscrubstorage.blob.core.windows.net/export?restype=container&#34;&gt;http://prodscrubstorage.blob.core.windows.net/export?restype=container&lt;/a&gt;
    </content>
    <updated>2025-11-20T18:39:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf87sj0l3l0f5zljnehdws77w8uhe6carnhd9ktw9366wmjryca8gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6lzn2j6</id>
    
      <title type="html">I believe this is the fourth time Thalha Jubair has been arrested ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf87sj0l3l0f5zljnehdws77w8uhe6carnhd9ktw9366wmjryca8gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6lzn2j6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr4h0n7khyvn4y722vsqvlu4aey4h2rejjsq0v4hutgr9dt033x2qj6jeu0&#39;&gt;nevent1q…jeu0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I believe this is the fourth time Thalha Jubair has been arrested btw.&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://cyberplace.social/system/media_attachments/files/115/225/515/685/588/640/original/bfa1ae038d897ece.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2025-09-18T13:24:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr4h0n7khyvn4y722vsqvlu4aey4h2rejjsq0v4hutgr9dt033x2qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6usuzul</id>
    
      <title type="html">Suspect arrested for M&amp;amp;S hack have been rearrested (again), ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr4h0n7khyvn4y722vsqvlu4aey4h2rejjsq0v4hutgr9dt033x2qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6usuzul" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqhkzuq3u0kmjlgw2d4g7m6ngth7l6q58qrvk8sryvgkn2dvlhrnqcs060k&#39;&gt;nevent1q…060k&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Suspect arrested for M&amp;amp;S hack have been rearrested (again), this time for Transport for London hack last year: &lt;a href=&#34;https://therecord.media/scattered-spider-teenage-suspects-arrested-britain-nca&#34;&gt;https://therecord.media/scattered-spider-teenage-suspects-arrested-britain-nca&lt;/a&gt;
    </content>
    <updated>2025-09-18T13:22:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqhkzuq3u0kmjlgw2d4g7m6ngth7l6q58qrvk8sryvgkn2dvlhrnqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69faswr</id>
    
      <title type="html">Marks and Spencer CTO leaves, CISO still in role. It’s ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqhkzuq3u0kmjlgw2d4g7m6ngth7l6q58qrvk8sryvgkn2dvlhrnqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69faswr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg203jsfz9gvgqyem7mxn6gfrhkcfcjjpnwamy3vqqv39tap58ursp57ptr&#39;&gt;nevent1q…7ptr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Marks and Spencer CTO leaves, CISO still in role. &lt;br/&gt;&lt;br/&gt;It’s difficult to see what happened as her fault - eg the decision to outsource the frontline IT helpdesk that did the password resets dates 5 years before she joined. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.computerweekly.com/news/366630565/MS-parts-ways-with-CTO-after-cyber-attack&#34;&gt;https://www.computerweekly.com/news/366630565/MS-parts-ways-with-CTO-after-cyber-attack&lt;/a&gt;
    </content>
    <updated>2025-09-15T17:30:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszfy5dhcxgqwfvg23klxsuu7q49djzcppcrrmvpvpg2qt3wnkdd9gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6wpk778</id>
    
      <title type="html">This isn&amp;#39;t a dig at MS btw, as they&amp;#39;re actually really ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszfy5dhcxgqwfvg23klxsuu7q49djzcppcrrmvpvpg2qt3wnkdd9gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6wpk778" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqgkee43pf2d4qkjatg5msr59hwhj25hwhvguyt6w94uahl0g2knc9rz3vf&#39;&gt;nevent1q…z3vf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This isn&amp;#39;t a dig at MS btw, as they&amp;#39;re actually really good with high profile vulns in their own on prem products nowadays overall - they&amp;#39;ll frequently give extensive details to hunt on.&lt;br/&gt;&lt;br/&gt;Other vendors should learn from that.
    </content>
    <updated>2025-09-02T11:16:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd9m8zmg5efnr3j8gpudwyvkz5qy6n85rtnzn0m8x967hp09t8sxgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6838akx</id>
    
      <title type="html">The status updates on Colt&amp;#39;s website describing a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd9m8zmg5efnr3j8gpudwyvkz5qy6n85rtnzn0m8x967hp09t8sxgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6838akx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszzcvxpeuapqt9ug0nlzdatj6na62sngd2qza3l9j6u62t6w7y39g80053c&#39;&gt;nevent1q…053c&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The status updates on Colt&amp;#39;s website describing a &amp;#34;technical issue&amp;#34; have been removed, replacing it with always being a cyber incident.&lt;br/&gt;&lt;br/&gt;Left - internet archive - &lt;a href=&#34;https://web.archive.org/web/20250814102113/https://www.colt.net/status/&#34;&gt;https://web.archive.org/web/20250814102113/https://www.colt.net/status/&lt;/a&gt;&lt;br/&gt;Right - now &lt;a href=&#34;https://www.colt.net/status/#updates&#34;&gt;https://www.colt.net/status/#updates&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/115/066/657/646/160/919/original/8e15ee68209339f2.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/115/066/661/955/280/114/original/8320bddd46e86316.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-21T12:06:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg203jsfz9gvgqyem7mxn6gfrhkcfcjjpnwamy3vqqv39tap58urszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6tnjhcn</id>
    
      <title type="html">M&amp;amp;S still working on system recovery. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg203jsfz9gvgqyem7mxn6gfrhkcfcjjpnwamy3vqqv39tap58urszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6tnjhcn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxyy53khw36yz5saksx27d3tlheht5xyfwc5wa4j8pped3hfvnpws2qrdas&#39;&gt;nevent1q…rdas&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;M&amp;amp;S still working on system recovery.    &lt;a href=&#34;https://www.bbc.com/news/articles/cewyyjdzql4o&#34;&gt;https://www.bbc.com/news/articles/cewyyjdzql4o&lt;/a&gt;
    </content>
    <updated>2025-08-11T09:03:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxyy53khw36yz5saksx27d3tlheht5xyfwc5wa4j8pped3hfvnpwszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l605kqff</id>
    
      <title type="html">I understand the people released have not been charged.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxyy53khw36yz5saksx27d3tlheht5xyfwc5wa4j8pped3hfvnpwszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l605kqff" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg7njgs8709369rzycy7q90l6zxpflhjkf5zpsf7mxdepj94ltwtctwwf36&#39;&gt;nevent1q…wf36&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I understand the people released have not been charged.
    </content>
    <updated>2025-08-11T09:03:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg7njgs8709369rzycy7q90l6zxpflhjkf5zpsf7mxdepj94ltwtczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6e8egxe</id>
    
      <title type="html">The people arrested as part of the Co-op and M&amp;amp;S hack ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg7njgs8709369rzycy7q90l6zxpflhjkf5zpsf7mxdepj94ltwtczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6e8egxe" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8dwn75vk2jpv2ydr9atke7h7ysq9eeeu4w9uq6k2c0mpwnkw96ys7wa790&#39;&gt;nevent1q…a790&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The people arrested as part of the Co-op and M&amp;amp;S hack investigation have been released on bail.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://nation.cymru/news/four-people-bailed-after-arrests-over-cyber-attacks-on-ms-co-op-and-harrods/&#34;&gt;https://nation.cymru/news/four-people-bailed-after-arrests-over-cyber-attacks-on-ms-co-op-and-harrods/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Previously when this happened with LAPSUS$, they just continued hacking stuff.
    </content>
    <updated>2025-07-17T13:07:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8dwn75vk2jpv2ydr9atke7h7ysq9eeeu4w9uq6k2c0mpwnkw96yszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6haq0ts</id>
    
      <title type="html">Personally I think Co-op did a really good job getting out of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8dwn75vk2jpv2ydr9atke7h7ysq9eeeu4w9uq6k2c0mpwnkw96yszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6haq0ts" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs258854mkjjeu3grvel08d5rwgfel00ruqthuea3lzcusfakadn7smvqy2j&#39;&gt;nevent1q…qy2j&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Personally I think Co-op did a really good job getting out of that situation and minimising impact. &lt;br/&gt;&lt;br/&gt;I definitely think if you have a LAPSUS$ style advanced persistent teenagers situation, tilt towards open and honest comms as those kids will use secrecy against ya. It’s 2025, it’s okay to say you got hacked, people largely understand. Also, in IR, lawyers are usually stuck in 1980 advice - it’s just advice, they ain’t yo boss.
    </content>
    <updated>2025-07-16T08:58:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs258854mkjjeu3grvel08d5rwgfel00ruqthuea3lzcusfakadn7szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6mf6glz</id>
    
      <title type="html">Co-op finally admitted the entire membership database was stolen ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs258854mkjjeu3grvel08d5rwgfel00ruqthuea3lzcusfakadn7szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6mf6glz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvvp3d8tkdxrplywx4k6ax8el8fusyh920vznjfvhvg7yqcmtpltq7s04d9&#39;&gt;nevent1q…04d9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Co-op finally admitted the entire membership database was stolen  &lt;br/&gt;&lt;br/&gt;I had this in the thread months ago, they originally tried to deny it entirely then tried to say ‘some’ data was accessed when they knew it was the whole thing. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bbc.co.uk/news/articles/cql0ple066po&#34;&gt;https://www.bbc.co.uk/news/articles/cql0ple066po&lt;/a&gt;
    </content>
    <updated>2025-07-16T08:47:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvvp3d8tkdxrplywx4k6ax8el8fusyh920vznjfvhvg7yqcmtpltqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gl2alr</id>
    
      <title type="html">. @npub1vc3…axsh has broken the story that the key member (and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvvp3d8tkdxrplywx4k6ax8el8fusyh920vznjfvhvg7yqcmtpltqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gl2alr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdp773759nvz9efgyz62qm86s9h7lchsgglrzpzu6nalkm3egq9dc789g7f&#39;&gt;nevent1q…9g7f&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;. &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vc39pnjdqd77zzdxff4qyv8h3x0ey2mkx33c3vl8egr0a9ysxkxsk0axsh&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;BrianKrebs&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vc3…axsh&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; has broken the story that the key member (and teenager) of LAPSUS$ runs Scattered Spider &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://krebsonsecurity.com/2025/07/uk-charges-four-in-scattered-spider-ransom-group/&#34;&gt;https://krebsonsecurity.com/2025/07/uk-charges-four-in-scattered-spider-ransom-group/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/830/978/034/667/877/original/b5253b031d93741e.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-10T21:07:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdp773759nvz9efgyz62qm86s9h7lchsgglrzpzu6nalkm3egq9dczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6x7wdwg</id>
    
      <title type="html">After almost 3 months, Marks and Spencer recruitment system came ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdp773759nvz9efgyz62qm86s9h7lchsgglrzpzu6nalkm3egq9dczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6x7wdwg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxdadycc5wvh3lj0sg3zd0tgj5yfw5y86fznv07wn72m7c5z82w9gfyntvz&#39;&gt;nevent1q…ntvz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;After almost 3 months, Marks and Spencer recruitment system came back online just now.  First 4 jobs posted.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/830/043/138/465/663/original/0999651b7bfea908.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-10T17:10:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxdadycc5wvh3lj0sg3zd0tgj5yfw5y86fznv07wn72m7c5z82w9gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l627faeg</id>
    
      <title type="html">If you ever doubted the link between Scattered Spider(tm) and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxdadycc5wvh3lj0sg3zd0tgj5yfw5y86fznv07wn72m7c5z82w9gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l627faeg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp6nt4c0qkescfnewu5ty6sk20a90y2073e29pg00e5q82neyslmc4ey79u&#39;&gt;nevent1q…y79u&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If you ever doubted the link between Scattered Spider(tm) and LAPSUS$ - one of the people arrested today was a key part of the LAPSUS$ attacks a few years ago.
    </content>
    <updated>2025-07-10T16:58:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsp6nt4c0qkescfnewu5ty6sk20a90y2073e29pg00e5q82neyslmczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l63huusz</id>
    
      <title type="html">17 and two 19 year old teens picked up over Co-op and M&amp;amp;S ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsp6nt4c0qkescfnewu5ty6sk20a90y2073e29pg00e5q82neyslmczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l63huusz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyrx2tmv3x9jv9k2jnrd09jucr37spyflfttwy66gaywjm5qelpvstxf5m5&#39;&gt;nevent1q…f5m5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;17 and two 19 year old teens picked up over Co-op and M&amp;amp;S hacks, and a 20 year old woman. &lt;br/&gt;&lt;br/&gt;Pretend to be surprised. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bbc.com/news/articles/cwykgrv374eo&#34;&gt;https://www.bbc.com/news/articles/cwykgrv374eo&lt;/a&gt;
    </content>
    <updated>2025-07-10T11:17:17Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyrx2tmv3x9jv9k2jnrd09jucr37spyflfttwy66gaywjm5qelpvszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69adael</id>
    
      <title type="html">Marks and Spencer’s CEO says half of their online ordering is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyrx2tmv3x9jv9k2jnrd09jucr37spyflfttwy66gaywjm5qelpvszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69adael" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr2f4vlz7580dydettj9lypj8xafaqj0f8gzua6247tc8wylh47lc2gea5u&#39;&gt;nevent1q…ea5u&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Marks and Spencer’s CEO says half of their online ordering is still offline after their ransomware incident, they hope to get open in next 4 weeks. &lt;br/&gt;&lt;br/&gt;They are also rebuilding internal systems and hope a majority of that will be done by August. &lt;br/&gt;&lt;br/&gt;Lesson: mass contain early. M&amp;amp;S didn’t. Co-op did. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.reuters.com/business/retail-consumer/ms-ceo-most-cyberattack-impact-will-be-behind-us-by-august-2025-07-01/&#34;&gt;https://www.reuters.com/business/retail-consumer/ms-ceo-most-cyberattack-impact-will-be-behind-us-by-august-2025-07-01/&lt;/a&gt;
    </content>
    <updated>2025-07-01T12:56:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspcsygt0lrspw2dajvy2chj8j9m5d3cqhvxadgfv3cxjn4tmsr3cqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f4vss9</id>
    
      <title type="html">One thing for media covering the Co-op thing - attackers are not ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspcsygt0lrspw2dajvy2chj8j9m5d3cqhvxadgfv3cxjn4tmsr3cqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f4vss9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyc45nx4fuxnz49zzgzlj2kvys5fxkr03n6wzpdx4vj4f4am0nevq2mf3lq&#39;&gt;nevent1q…f3lq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One thing for media covering the Co-op thing - attackers are not impersonating IT help desks to gain access. They’re impersonating *staff* calling in to the IT help desks - they’re different things.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/466/416/024/433/698/original/f030bca626f42b41.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-07T11:55:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyc45nx4fuxnz49zzgzlj2kvys5fxkr03n6wzpdx4vj4f4am0nevqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f37c99</id>
    
      <title type="html">Contactless payment has been fixed at all Co-op Group stores.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyc45nx4fuxnz49zzgzlj2kvys5fxkr03n6wzpdx4vj4f4am0nevqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f37c99" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0fhtu8gvchdlkemmg5wmv8d302x439s2tq5u682dd3y092l2q9pg8ualpn&#39;&gt;nevent1q…alpn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Contactless payment has been fixed at all Co-op Group stores.
    </content>
    <updated>2025-05-06T14:52:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv6lyuvuq0hcq5vtr4fjvtv676arqxd9u2z7488xf59avnyt36k2szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6lym0qt</id>
    
      <title type="html">It sounds like the situation at Co-op has got worse. They’ve ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv6lyuvuq0hcq5vtr4fjvtv676arqxd9u2z7488xf59avnyt36k2szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6lym0qt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswl2x94qdd6lx94kx6yu9ng4aq5zy4ylug208h3tacf3ja6j3ff6s2hu36j&#39;&gt;nevent1q…u36j&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;It sounds like the situation at Co-op has got worse. They’ve stopped taking card payments, it’s cash only.  &lt;a href=&#34;https://www.telegraph.co.uk/business/2025/05/06/co-op-shops-stop-taking-card-payments-amid-cyber-attack/&#34;&gt;https://www.telegraph.co.uk/business/2025/05/06/co-op-shops-stop-taking-card-payments-amid-cyber-attack/&lt;/a&gt;
    </content>
    <updated>2025-05-06T10:21:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswl2x94qdd6lx94kx6yu9ng4aq5zy4ylug208h3tacf3ja6j3ff6szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6r7kv5p</id>
    
      <title type="html">Co-op Group appear to be trying to course correct with their ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswl2x94qdd6lx94kx6yu9ng4aq5zy4ylug208h3tacf3ja6j3ff6szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6r7kv5p" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszslwu6ntw0e8xz5h3ghapy9ssm6hg7ea7jkjwkgpsdp0ctf6dywgcc04k7&#39;&gt;nevent1q…04k7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Co-op Group appear to be trying to course correct with their cyber incident comms. &lt;br/&gt;&lt;br/&gt;They’re calling it a cyber incident now, and have put a statement on the front page of their website, along with an FAQ.  They haven’t yet emailed members (they should). &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.coop.co.uk/cyber-incident&#34;&gt;https://www.coop.co.uk/cyber-incident&lt;/a&gt;
    </content>
    <updated>2025-05-05T16:21:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszslwu6ntw0e8xz5h3ghapy9ssm6hg7ea7jkjwkgpsdp0ctf6dywgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6j2gj0p</id>
    
      <title type="html">One of the points of exploitation of large orgs is they usually ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszslwu6ntw0e8xz5h3ghapy9ssm6hg7ea7jkjwkgpsdp0ctf6dywgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6j2gj0p" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs05f8cdr96et0s2m3tw65s9c3273cnxjwswg6nmadfnqwts6cdwysvej0y6&#39;&gt;nevent1q…j0y6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One of the points of exploitation of large orgs is they usually outsource their Service Desk to somewhere cheap offshore who don’t know the org staff, and when you call and say your name, they normally put big all caps bold red warning if the person is a VIP, eg C suite, so they get VIP service - ie anything goes.
    </content>
    <updated>2025-05-05T14:32:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs05f8cdr96et0s2m3tw65s9c3273cnxjwswg6nmadfnqwts6cdwyszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6dy5ymv</id>
    
      <title type="html">BBC News has a look at teenagers phoning helpdesks and pretending ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs05f8cdr96et0s2m3tw65s9c3273cnxjwswg6nmadfnqwts6cdwyszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6dy5ymv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszgt4ndjev4l6nqf6j7k4wcsk75hly4s2ecl9sgzl54t0xz2whxjsx8qkf3&#39;&gt;nevent1q…qkf3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;BBC News has a look at teenagers phoning helpdesks and pretending to be the CISO. &lt;a href=&#34;https://www.bbc.com/news/articles/c4grn878712o&#34;&gt;https://www.bbc.com/news/articles/c4grn878712o&lt;/a&gt;
    </content>
    <updated>2025-05-05T14:18:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstgsrkch0ex048eck9wkezzwlhe0467kd0vt90upz3vmxfwzdf03szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6v2sa2j</id>
    
      <title type="html">The SignalNotSignal hack of US government is really big. Some ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstgsrkch0ex048eck9wkezzwlhe0467kd0vt90upz3vmxfwzdf03szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6v2sa2j" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswra5vt7c5w4cx26mr7jwln069rehgwu2mqzwdw8vfnt6yr7ntw6c0upx9h&#39;&gt;nevent1q…px9h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The SignalNotSignal hack of US government is really big. Some examples for those who haven’t seen it. The USG managed to take an encrypted platform, backdoor it, and got owned.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/455/202/237/947/143/original/52ac669d4ca17b82.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/455/202/488/201/917/original/5f18f46f66b82595.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-05T12:23:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvp4lftnxkwlc6x8ptj8sh0246xffs9mpld028eq535jvadtp3h6czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ehkyv6</id>
    
      <title type="html">I’ve been using Recall for a few weeks now on my daily driver. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvp4lftnxkwlc6x8ptj8sh0246xffs9mpld028eq535jvadtp3h6czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ehkyv6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgg2hrvsaadakhlqh4ulnknduttsvpnpgafhqjrjv33n42h65pvvsc0rqu8&#39;&gt;nevent1q…rqu8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I’ve been using Recall for a few weeks now on my daily driver. &lt;br/&gt;&lt;br/&gt;It scooped up my credit card statements after I logged into online banking - both screenshots (text indexed) of the PDFs, transaction history from the website, and my name, date of birth and security question reminders. &lt;br/&gt;&lt;br/&gt;Sensitive filtering mode only kicked in when I viewed my cards CVV number. &lt;br/&gt;&lt;br/&gt;Worth excluding bank websites from Recall’s options, if you see it enabled.
    </content>
    <updated>2025-05-05T10:42:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsp4slphrw82a035990484v905azhk3mvc3a5raw7seazfn4agwvkszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sz75st</id>
    
      <title type="html">#NoName are back targeting UK councils. Same config as prior UK ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsp4slphrw82a035990484v905azhk3mvc3a5raw7seazfn4agwvkszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sz75st" />
    <content type="html">
      #NoName are back targeting UK councils. Same config as prior UK runs. #threatintel&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/453/797/399/811/939/original/a2ea6e643c9913e9.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-05T06:25:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszgt4ndjev4l6nqf6j7k4wcsk75hly4s2ecl9sgzl54t0xz2whxjszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6e0kd00</id>
    
      <title type="html">Sky News quote a source in M&amp;amp;S head office saying Marks and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszgt4ndjev4l6nqf6j7k4wcsk75hly4s2ecl9sgzl54t0xz2whxjszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6e0kd00" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsglvvk4gvvugpp69yeaqw4sgfg9lupjy7qf0mtnq3ppugekayv7vg0tktpq&#39;&gt;nevent1q…ktpq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Sky News quote a source in M&amp;amp;S head office saying Marks and Spencer have no ransomware incident plan so they are making it up as they go along apparently, with staff sleeping in the office and communicating via WhatsApp. &lt;br/&gt;&lt;br/&gt;M&amp;amp;S dispute this, saying they have robust business continuity plans. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://news.sky.com/story/amp/mands-had-no-plan-for-cyber-attacks-insider-reveals-with-staff-left-sleeping-in-the-office-amid-paranoia-and-chaos-13361359&#34;&gt;https://news.sky.com/story/amp/mands-had-no-plan-for-cyber-attacks-insider-reveals-with-staff-left-sleeping-in-the-office-amid-paranoia-and-chaos-13361359&lt;/a&gt;
    </content>
    <updated>2025-05-05T05:33:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswra5vt7c5w4cx26mr7jwln069rehgwu2mqzwdw8vfnt6yr7ntw6czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6h0r3lq</id>
    
      <title type="html">The third party version of Signal the White House has been using ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswra5vt7c5w4cx26mr7jwln069rehgwu2mqzwdw8vfnt6yr7ntw6czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6h0r3lq" />
    <content type="html">
      The third party version of Signal the White House has been using has been hacked, and Signal messages from devices stolen (as they were being sent to the supplier) &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/&#34;&gt;https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/&lt;/a&gt;
    </content>
    <updated>2025-05-04T23:33:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsglvvk4gvvugpp69yeaqw4sgfg9lupjy7qf0mtnq3ppugekayv7vgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sa9c8t</id>
    
      <title type="html">Great NCSC piece by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsglvvk4gvvugpp69yeaqw4sgfg9lupjy7qf0mtnq3ppugekayv7vgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sa9c8t" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9xpls048dt56qq9e6x2dghscqeqzxd7encl7u956f36vt0c2u4xchjsl34&#39;&gt;nevent1q…sl34&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Great NCSC piece by [@ollie_whitehouse](&lt;a href=&#34;https://infosec.exchange/@ollie_whitehouse&#34;&gt;https://infosec.exchange/@ollie_whitehouse&lt;/a&gt; ) &lt;br/&gt;&lt;br/&gt;I’d add - block by Entra policy specifically High risk logins (below is too FP prone), and SOC monitor them. SOC playbook = account probably compromised. How? &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.ncsc.gov.uk/blog-post/incidents-impacting-retailers&#34;&gt;https://www.ncsc.gov.uk/blog-post/incidents-impacting-retailers&lt;/a&gt;
    </content>
    <updated>2025-05-04T18:40:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9xpls048dt56qq9e6x2dghscqeqzxd7encl7u956f36vt0c2u4xczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sv9kqx</id>
    
      <title type="html">A wrote a piece about paying ransoms does not equal quick ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9xpls048dt56qq9e6x2dghscqeqzxd7encl7u956f36vt0c2u4xczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sv9kqx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8r9prjtlunfz6qm9q7ekvm00d3mkykqn60k27ndxzzt7fzgferrs9fp72e&#39;&gt;nevent1q…p72e&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A wrote a piece about paying ransoms does not equal quick restoration - in fact, quite often it makes things worse. &lt;a href=&#34;https://doublepulsar.com/big-game-ransomware-the-myths-experts-tell-board-members-03d5e1d1c4b7&#34;&gt;https://doublepulsar.com/big-game-ransomware-the-myths-experts-tell-board-members-03d5e1d1c4b7&lt;/a&gt;
    </content>
    <updated>2025-05-04T11:16:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8r9prjtlunfz6qm9q7ekvm00d3mkykqn60k27ndxzzt7fzgferrszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6qxmwuf</id>
    
      <title type="html">Sunday Times has a piece looking into ransomware incident at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8r9prjtlunfz6qm9q7ekvm00d3mkykqn60k27ndxzzt7fzgferrszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6qxmwuf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv02e7tnpheqcjzj0jk885h4c8d066k0wg5r08jws8kh4daetn6asus4du9&#39;&gt;nevent1q…4du9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Sunday Times has a piece looking into ransomware incident at Marks and Spencer.  It&amp;#39;s pretty good, goes into their contain and eradicate focus.&lt;br/&gt;&lt;br/&gt;&amp;#34;By shutting down parts of the IT estate, Higham’s team had worked to prevent the attack from spreading, but had also stopped parts of its digital operations from functioning. This was considered a worthy trade-off.&amp;#34;&lt;br/&gt;&lt;br/&gt;One error in the article - lack of recovery doesn&amp;#39;t mean no ransomware paid.  Paying is not quick restoration.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.thetimes.com/business-money/companies/article/m-and-s-cyber-attack-ms-klrnxvwq6&#34;&gt;https://www.thetimes.com/business-money/companies/article/m-and-s-cyber-attack-ms-klrnxvwq6&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/445/873/790/799/993/original/366d4e68b247f7c3.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-03T20:56:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv02e7tnpheqcjzj0jk885h4c8d066k0wg5r08jws8kh4daetn6aszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l606ka05</id>
    
      <title type="html">Here&amp;#39;s the ITV News report anyhoo, logline: &amp;#34;ITV News ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv02e7tnpheqcjzj0jk885h4c8d066k0wg5r08jws8kh4daetn6aszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l606ka05" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsptj45sxrrxe92ywqd89q4uuv8m65zgl7vmg74h8fv3cjrptv2uzg38lgg6&#39;&gt;nevent1q…lgg6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Here&amp;#39;s the ITV News report anyhoo, logline: &amp;#34;ITV News understands the the ongoing cyberattack faced by the supermarket has worsened since Friday, impacting the ordering system, drivers and warehouse staff.&amp;#34;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.itv.com/news/2025-05-03/worsening-cyberattack-shuts-down-co-op-orders-itv-news-understands&#34;&gt;https://www.itv.com/news/2025-05-03/worsening-cyberattack-shuts-down-co-op-orders-itv-news-understands&lt;/a&gt;
    </content>
    <updated>2025-05-03T16:52:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsptj45sxrrxe92ywqd89q4uuv8m65zgl7vmg74h8fv3cjrptv2uzgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6j5uagr</id>
    
      <title type="html">There&amp;#39;s a report on ITV News that Co-op member data is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsptj45sxrrxe92ywqd89q4uuv8m65zgl7vmg74h8fv3cjrptv2uzgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6j5uagr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2yk880xrwlyhcum6dq8ngascmx27fhq3xal7a7kmx56jzddtxjeg7fua97&#39;&gt;nevent1q…ua97&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;There&amp;#39;s a report on ITV News that Co-op member data is available on the Dark Web(tm), but as far as I know this isn&amp;#39;t accurate.  DragonForce&amp;#39;s portal hasn&amp;#39;t been available for over a week.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/444/827/549/010/837/original/40d434fbac7c69bf.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-03T16:27:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2yk880xrwlyhcum6dq8ngascmx27fhq3xal7a7kmx56jzddtxjegzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sfac7s</id>
    
      <title type="html">By the way, this is absolutely terrible advice for dealing with a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2yk880xrwlyhcum6dq8ngascmx27fhq3xal7a7kmx56jzddtxjegzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sfac7s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs80ylmg8rt7clwrkc9ap78tksz0r3tr5qac2eay2v56qk4yav92vg973qcx&#39;&gt;nevent1q…3qcx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;By the way, this is absolutely terrible advice for dealing with a major and high visibility ransomware incident.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/440/825/134/064/907/original/a4b8dbace31247be.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-02T23:26:54Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs80ylmg8rt7clwrkc9ap78tksz0r3tr5qac2eay2v56qk4yav92vgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68vdj8q</id>
    
      <title type="html">One of M&amp;amp;S’ biggest suppliers have said they have reverted ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs80ylmg8rt7clwrkc9ap78tksz0r3tr5qac2eay2v56qk4yav92vgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68vdj8q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfvemyd8ppxawulypflu93gs8kxady8cm9hxal4vfgynprjdk4udqazxaax&#39;&gt;nevent1q…xaax&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One of M&amp;amp;S’ biggest suppliers have said they have reverted to pen and paper for orders due to M&amp;amp;S lacking IT. &lt;br/&gt;&lt;br/&gt;Additionally, M&amp;amp;S staff are raising concern about how they will be paid due to lack of IT systems. &lt;br/&gt;&lt;br/&gt;M&amp;amp;S are over a week into a ransomware incident and still don’t have their online store working. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bbc.com/news/articles/cvgnyplvdv8o&#34;&gt;https://www.bbc.com/news/articles/cvgnyplvdv8o&lt;/a&gt;&lt;br/&gt;&lt;br/&gt; #threatintel #ransomware
    </content>
    <updated>2025-05-02T23:24:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfvemyd8ppxawulypflu93gs8kxady8cm9hxal4vfgynprjdk4udqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6xn4fdd</id>
    
      <title type="html">Bleeping Computer have more on the Co-op breach ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfvemyd8ppxawulypflu93gs8kxady8cm9hxal4vfgynprjdk4udqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6xn4fdd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0wny6v4465yf75th7qdhfgn93f2fh5rel72nhgffyd9hwahee0xsw48yjs&#39;&gt;nevent1q…8yjs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Bleeping Computer have more on the Co-op breach &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/&#34;&gt;https://www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel #ransomware&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/440/005/208/877/125/original/0c84e4558d7e9dc4.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-02T19:58:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0wny6v4465yf75th7qdhfgn93f2fh5rel72nhgffyd9hwahee0xszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6zaj4q7</id>
    
      <title type="html">Pass the bong ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0wny6v4465yf75th7qdhfgn93f2fh5rel72nhgffyd9hwahee0xszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6zaj4q7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9qls7p74da7frmd2lzff0vdhkvraje4cq96usvtughz0pnsktdgqjn79g5&#39;&gt;nevent1q…79g5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Pass the bong&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/439/985/794/564/818/original/f7ebe7e360547636.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-02T19:53:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9qls7p74da7frmd2lzff0vdhkvraje4cq96usvtughz0pnsktdgqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ysz0r4</id>
    
      <title type="html">Regarding IOCs around the UK retailer activity - there’s loads ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9qls7p74da7frmd2lzff0vdhkvraje4cq96usvtughz0pnsktdgqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ysz0r4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd9mt9d39amqru8tve2fl9yplscrh3ueaxz9u2q6hnregevkwwmpcyeyyk2&#39;&gt;nevent1q…yyk2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Regarding IOCs around the UK retailer activity - there’s loads doing the rounds, and they’re almost all not useful. &lt;br/&gt;&lt;br/&gt;Eg hundreds of dynamic VPN IPs from 2022. If you google them you’ll find them on vendor blogs from years ago for Scattered Spider - people are recycling in panic and passing around in panic. &lt;br/&gt;&lt;br/&gt;Don’t hunt on random IOCs. IP addresses change. Strengthen foundational controls. Review sign in logs for abnormal activity etc.
    </content>
    <updated>2025-05-02T19:49:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd9mt9d39amqru8tve2fl9yplscrh3ueaxz9u2q6hnregevkwwmpczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f6v6fd</id>
    
      <title type="html">New by me - breaking down the attacks on UK highstreet retailers ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd9mt9d39amqru8tve2fl9yplscrh3ueaxz9u2q6hnregevkwwmpczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6f6v6fd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9vk3t4xhec9fnw2ucraysgnjkc60wnyvyt28w5nhhuwx27ndec7qza4056&#39;&gt;nevent1q…4056&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;New by me - breaking down the attacks on UK highstreet retailers&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://doublepulsar.com/dragonforce-ransomware-cartel-attacks-on-uk-high-street-retailers-walking-in-the-front-door-52ed8ba68534&#34;&gt;https://doublepulsar.com/dragonforce-ransomware-cartel-attacks-on-uk-high-street-retailers-walking-in-the-front-door-52ed8ba68534&lt;/a&gt;
    </content>
    <updated>2025-05-02T18:33:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9vk3t4xhec9fnw2ucraysgnjkc60wnyvyt28w5nhhuwx27ndec7qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6de52m8</id>
    
      <title type="html">Co-op Group have now admitted a significant amount of member ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9vk3t4xhec9fnw2ucraysgnjkc60wnyvyt28w5nhhuwx27ndec7qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6de52m8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyyvm5pcv7k780zcll3lmxn2aeugrrxs7u0k28v9jsv7ypgzaas4gthm202&#39;&gt;nevent1q…m202&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Co-op Group have now admitted a significant amount of member (customer) information has been stolen by DragonForce Ransomware Cartel, saying they &amp;#34;accessed data relating to a significant number of our current and past members&amp;#34; - around 20 million people.  The Member database, basically.&lt;br/&gt;&lt;br/&gt;Up until now Co-op hadn&amp;#39;t even used the words cyber or threat actor, referring to an &amp;#34;IT issue&amp;#34; and &amp;#34;third party&amp;#34; in comms.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bbc.co.uk/news/articles/crkx3vy54nzo&#34;&gt;https://www.bbc.co.uk/news/articles/crkx3vy54nzo&lt;/a&gt;
    </content>
    <updated>2025-05-02T17:51:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyyvm5pcv7k780zcll3lmxn2aeugrrxs7u0k28v9jsv7ypgzaas4gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6wvw0sq</id>
    
      <title type="html">The individuals operating under the DragonForce banner are using ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyyvm5pcv7k780zcll3lmxn2aeugrrxs7u0k28v9jsv7ypgzaas4gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6wvw0sq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs94zy0d78uzw7x40lx0reyjhe8w0uace0cvhta9dnmshzrrxpxxqcads6f3&#39;&gt;nevent1q…s6f3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The individuals operating under the  DragonForce banner are using social engineering for entry.  &lt;br/&gt;&lt;br/&gt;Defenders should urgently make sure they have read the CISA briefs on Scattered Spider and LAPSUS$ as it&amp;#39;s a repeat of the 2022-2023 activity. &lt;br/&gt;&lt;br/&gt;Links: &lt;a href=&#34;https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf&#34;&gt;https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.cisa.gov/sites/default/files/2023-11/aa23-320a_scattered_spider_0.pdf&#34;&gt;https://www.cisa.gov/sites/default/files/2023-11/aa23-320a_scattered_spider_0.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I would also suggest these NCSC guides on incident management: &lt;a href=&#34;https://www.ncsc.gov.uk/collection/incident-management&#34;&gt;https://www.ncsc.gov.uk/collection/incident-management&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;and effective cyber crisis comms: &lt;a href=&#34;https://www.ncsc.gov.uk/guidance/effective-communications-in-a-cyber-incident&#34;&gt;https://www.ncsc.gov.uk/guidance/effective-communications-in-a-cyber-incident&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/439/364/451/611/425/original/88443a28e91c4812.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-02T17:17:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs94zy0d78uzw7x40lx0reyjhe8w0uace0cvhta9dnmshzrrxpxxqczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6zqvqse</id>
    
      <title type="html">I&amp;#39;m going to make this the new ongoing megathread for ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs94zy0d78uzw7x40lx0reyjhe8w0uace0cvhta9dnmshzrrxpxxqczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6zqvqse" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgeym4e0fl90sqnqxul390rsc8z9zyzv7t5zz9rrqcpk7nx0n0zsq2u472t&#39;&gt;nevent1q…472t&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;m going to make this the new ongoing megathread for DragonForce Ransomware Cartel&amp;#39;s attack on UK retailers as they&amp;#39;re all connected.&lt;br/&gt;&lt;br/&gt;Why it matters: these are some of the UK&amp;#39;s largest retailers, think Target or some such in a US sense.&lt;br/&gt;&lt;br/&gt;Prior threads&lt;br/&gt;&lt;br/&gt;M&amp;amp;S: &lt;a href=&#34;https://cyberplace.social/@GossiTheDog/114381946765071799&#34;&gt;https://cyberplace.social/@GossiTheDog/114381946765071799&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Co-op: &lt;a href=&#34;https://cyberplace.social/@GossiTheDog/114426688834113446&#34;&gt;https://cyberplace.social/@GossiTheDog/114426688834113446&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Harrods:&lt;br/&gt;&lt;a href=&#34;https://cyberplace.social/@GossiTheDog/114433519351165250&#34;&gt;https://cyberplace.social/@GossiTheDog/114433519351165250&lt;/a&gt;
    </content>
    <updated>2025-05-02T17:13:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgeym4e0fl90sqnqxul390rsc8z9zyzv7t5zz9rrqcpk7nx0n0zsqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68l0pkp</id>
    
      <title type="html">DragonForce Ransomware Cartel are claiming credit for attacks on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgeym4e0fl90sqnqxul390rsc8z9zyzv7t5zz9rrqcpk7nx0n0zsqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68l0pkp" />
    <content type="html">
      DragonForce Ransomware Cartel are claiming credit for attacks on Marks and Spencer, Co-op and Harrods and say more are coming &lt;a href=&#34;https://www.bloomberg.com/news/articles/2025-05-02/-dragonforce-hacking-gang-takes-credit-for-uk-retail-attacks&#34;&gt;https://www.bloomberg.com/news/articles/2025-05-02/-dragonforce-hacking-gang-takes-credit-for-uk-retail-attacks&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/439/291/680/282/586/original/e2f2cb46a87536b1.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-02T16:56:56Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszj4ntfqayg0r3sk7k3efueh3a89dqv0w45ajctp287srushg90kgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6dusulf</id>
    
      <title type="html">in account.microsoft.com you can turn on passwordless, so your ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszj4ntfqayg0r3sk7k3efueh3a89dqv0w45ajctp287srushg90kgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6dusulf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd9xnxn7xwc35x78w4umrtm048537klwx0xv7qfq3g9a9lf7klpeqwrzmc9&#39;&gt;nevent1q…zmc9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;in account.microsoft.com you can turn on passwordless, so your hotmail account has no password at all, MFA is used for access.&lt;br/&gt;&lt;br/&gt;But if you enable it, can you still RDP with the old password?
    </content>
    <updated>2025-05-01T14:36:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8hlnq6zsex2uf7eyfcy3706qjkl9ps07wj49p08dgqzmwfg4t5gszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l668phca</id>
    
      <title type="html">what happens if you turn passwordless on with the account, does ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8hlnq6zsex2uf7eyfcy3706qjkl9ps07wj49p08dgqzmwfg4t5gszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l668phca" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvkjrezz6e0mv3knsz5qh424nx7tey0g6ms2n7xf9ml2lnuedaxqqgnehgw&#39;&gt;nevent1q…ehgw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;what happens if you turn passwordless on with the account, does it still accept the old password?
    </content>
    <updated>2025-05-01T12:31:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxpj7h2a5rfml7t98t4h40sltpscq96gjp0luz7svsv9qtvj6k8kszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gzkc7z</id>
    
      <title type="html">Lord, feel sorry for the M&amp;amp;S CISO. He only arrived just over ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxpj7h2a5rfml7t98t4h40sltpscq96gjp0luz7svsv9qtvj6k8kszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6gzkc7z" />
    <content type="html">
      Lord, feel sorry for the M&amp;amp;S CISO.  He only arrived just over a year ago.  &lt;br/&gt;&lt;br/&gt;It looks like they outsourced lots of their IT systems to TCS many years ago.  He&amp;#39;s spend years warning about ransomware and now he&amp;#39;s on the hook for a barn fire likely caused by years of prior decisions.
    </content>
    <updated>2025-04-29T21:38:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgchvsk4790n9lgzfgxzmj6n5ape73th7pdsyv47gj8hsd5jm0pcgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6zfp2q7</id>
    
      <title type="html">I’m very tempted to take next week off work 😅 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgchvsk4790n9lgzfgxzmj6n5ape73th7pdsyv47gj8hsd5jm0pcgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6zfp2q7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8fa4cjerkwfzdtp2njwp3nc434p9z2y47l027mj3xv8vrw284qhgcpc2gq&#39;&gt;nevent1q…c2gq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I’m very tempted to take next week off work 😅&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/349/473/220/930/641/original/f79c99058d414276.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T20:14:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8fa4cjerkwfzdtp2njwp3nc434p9z2y47l027mj3xv8vrw284qhgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ek92hx</id>
    
      <title type="html">Oblivion Remastered vs vanilla comparison ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8fa4cjerkwfzdtp2njwp3nc434p9z2y47l027mj3xv8vrw284qhgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ek92hx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs83dnd7ur4w6svf76lcc3sllqfvx0ahmamqv045pap4rm9uz470vcrsm5mg&#39;&gt;nevent1q…m5mg&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oblivion Remastered vs vanilla comparison &lt;a href=&#34;https://youtu.be/BppeLAz37rc&#34;&gt;https://youtu.be/BppeLAz37rc&lt;/a&gt;
    </content>
    <updated>2025-04-16T20:08:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf9w2sfcfrwsw3ejcdqhalev3f69ezl5t0telgym03wl43t9j4z3gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6l9nzrv</id>
    
      <title type="html">CVE extension to March 16th 2026 See y’all March 15th 2026 for ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf9w2sfcfrwsw3ejcdqhalev3f69ezl5t0telgym03wl43t9j4z3gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6l9nzrv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxxw4ttjfjehdmelgk84jwq6nh5v05wy2tj6wc5j72pcd8fsnwgaq78j2yh&#39;&gt;nevent1q…j2yh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;CVE extension to March 16th 2026&lt;br/&gt;&lt;br/&gt;See y’all March 15th 2026 for the last minute renewal 🫡😅&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.usaspending.gov/award/CONT_AWD_70RCSJ24FR0000018_7001_70RSAT20D00000001_7001&#34;&gt;https://www.usaspending.gov/award/CONT_AWD_70RCSJ24FR0000018_7001_70RSAT20D00000001_7001&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/348/122/205/370/434/original/574ab8fc6e0c1081.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T14:31:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxxw4ttjfjehdmelgk84jwq6nh5v05wy2tj6wc5j72pcd8fsnwgaqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6yc77xe</id>
    
      <title type="html">CVE extension by CISA = 11 months. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxxw4ttjfjehdmelgk84jwq6nh5v05wy2tj6wc5j72pcd8fsnwgaqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6yc77xe" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0tq3ymgztj9yv365gr9relv0qrgzmqayqu2x7a8fcmz0gzrhfktcy2ucax&#39;&gt;nevent1q…ucax&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;CVE extension by CISA = 11 months.  &lt;a href=&#34;https://infosec.exchange/@metacurity/114348047105534455&#34;&gt;https://infosec.exchange/@metacurity/114348047105534455&lt;/a&gt;
    </content>
    <updated>2025-04-16T14:14:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0tq3ymgztj9yv365gr9relv0qrgzmqayqu2x7a8fcmz0gzrhfktczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6pwrduw</id>
    
      <title type="html">Now all we need is for Breachforums to get back online and the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0tq3ymgztj9yv365gr9relv0qrgzmqayqu2x7a8fcmz0gzrhfktczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6pwrduw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgc09mztrrl437gz0url7wu7a0twcqszjvv2h7xzsruq6ax8udp2qkzdvj9&#39;&gt;nevent1q…dvj9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Now all we need is for Breachforums to get back online and the threat intelligence industry is alive again!&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/347/700/587/719/753/original/2ff378f6a90ded78.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T12:44:06Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgc09mztrrl437gz0url7wu7a0twcqszjvv2h7xzsruq6ax8udp2qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69xlp57</id>
    
      <title type="html">CISA have, at the last minute, extended the MITRE CVE contract. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgc09mztrrl437gz0url7wu7a0twcqszjvv2h7xzsruq6ax8udp2qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69xlp57" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf4agzu9q3aqd89py5ewql3xtsp4caap3klq0ughf5rwmdn5h38kgzdxy3h&#39;&gt;nevent1q…xy3h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;CISA have, at the last minute, extended the MITRE CVE contract. “The CVE Program is invaluable to cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.” HT &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub102xc6m40gwx94dhvcfk353alkvfsmk28rlnu508mtfjldnxj7k4qp6wzj6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Metacurity&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub102x…wzj6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-04-16T12:14:24Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf4agzu9q3aqd89py5ewql3xtsp4caap3klq0ughf5rwmdn5h38kgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6swdqqg</id>
    
      <title type="html">Another effort - https://gcve.eu/ Global CVE Allocation System</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf4agzu9q3aqd89py5ewql3xtsp4caap3klq0ughf5rwmdn5h38kgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6swdqqg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqykwdl406aqjqjn0rfv79c2ttupeptc7hkwsaa5cs3nujy84wrgsc4xwxx&#39;&gt;nevent1q…xwxx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Another effort -  &lt;a href=&#34;https://gcve.eu/&#34;&gt;https://gcve.eu/&lt;/a&gt; Global CVE Allocation System
    </content>
    <updated>2025-04-16T09:14:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqykwdl406aqjqjn0rfv79c2ttupeptc7hkwsaa5cs3nujy84wrgszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6len9rw</id>
    
      <title type="html">Looks like the US Government are going to lose control of CVE. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqykwdl406aqjqjn0rfv79c2ttupeptc7hkwsaa5cs3nujy84wrgszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6len9rw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs02ezsleuhyllj5xl9lg5hkuxe3facyye2exuk0x0u4l8j7fzcl0qt5edwe&#39;&gt;nevent1q…edwe&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Looks like the US Government are going to lose control of CVE. &lt;a href=&#34;https://www.thecvefoundation.org/&#34;&gt;https://www.thecvefoundation.org/&lt;/a&gt;
    </content>
    <updated>2025-04-16T08:22:44Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs02ezsleuhyllj5xl9lg5hkuxe3facyye2exuk0x0u4l8j7fzcl0qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68vs2yl</id>
    
      <title type="html">If you want to know how stupid the CVE situation is - CISA are ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs02ezsleuhyllj5xl9lg5hkuxe3facyye2exuk0x0u4l8j7fzcl0qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68vs2yl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2gkv3daqvv0jv3kswmaunvaqelxnj50ms40z0swc8cxypl0nnfhc5w4h67&#39;&gt;nevent1q…4h67&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If you want to know how stupid the CVE situation is - CISA are trying to source last minute funding or look at taking CVE management in house, but they themselves have had a massive budget cut where the staff trying to fix it are also at risk of being cut.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/346/615/524/679/501/original/421385df81c38d4e.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T08:08:09Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2gkv3daqvv0jv3kswmaunvaqelxnj50ms40z0swc8cxypl0nnfhczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6hqffjv</id>
    
      <title type="html">DOGE have terminated MITREs contracts, they say they will be ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2gkv3daqvv0jv3kswmaunvaqelxnj50ms40z0swc8cxypl0nnfhczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6hqffjv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq0cj47wruusxl6cxcj9tcd8e8g39lpfdhgukjrahk9w9frrgv04sy8pt2n&#39;&gt;nevent1q…pt2n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;DOGE have terminated MITREs contracts, they say they will be laying off nearly 500 people. This will have impacts beyond CVE - think MITRE ATT&amp;amp;CK etc.  &lt;a href=&#34;https://virginiabusiness.com/nova-govcon-firm-mitre-to-lay-off-442-employees-after-doge-cuts-contracts/&#34;&gt;https://virginiabusiness.com/nova-govcon-firm-mitre-to-lay-off-442-employees-after-doge-cuts-contracts/&lt;/a&gt;
    </content>
    <updated>2025-04-16T07:54:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdptz7shvp6hkmgqfd74vzylx4hpmxydts2vc6u45tfkztwfs6l3gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sjwq7h</id>
    
      <title type="html">Just as an update to this - @npub1vc3…axsh has confirmed with ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdptz7shvp6hkmgqfd74vzylx4hpmxydts2vc6u45tfkztwfs6l3gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sjwq7h" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvex4860lwzmtlrtaeazwu3u7pnydnjvvrjw25t4easprxuyarrsgv0u0ag&#39;&gt;nevent1q…u0ag&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Just as an update to this - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vc39pnjdqd77zzdxff4qyv8h3x0ey2mkx33c3vl8egr0a9ysxkxsk0axsh&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;BrianKrebs&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vc3…axsh&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; has confirmed with MITRE the letter is real, and as it stands the CVE database is likely to offline tomorrow.
    </content>
    <updated>2025-04-15T21:38:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvex4860lwzmtlrtaeazwu3u7pnydnjvvrjw25t4easprxuyarrsgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l66qxsnd</id>
    
      <title type="html">My take on the CVE contract issue for businesses: don’t ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvex4860lwzmtlrtaeazwu3u7pnydnjvvrjw25t4easprxuyarrsgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l66qxsnd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswzsw8x6pyyajdhq7drmqykxwnkktywlkqf8mdekpf7zja6y5u43cxt695g&#39;&gt;nevent1q…695g&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;My take on the CVE contract issue for businesses: don’t overreact, wait and see what impacts are. &lt;br/&gt;&lt;br/&gt;The NVD backlog was already pretty crazy.. the US gov has gotta put real funding into this area if it wants to retain control of cyber standards.
    </content>
    <updated>2025-04-15T18:58:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs80lj8r5gfrpvzrzewjjm0268vd8eh3uvxxfpur9asc6xjf75hn4qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6p05f4l</id>
    
      <title type="html">Also in both cases Oracle hasn’t filed an 8-K or told ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs80lj8r5gfrpvzrzewjjm0268vd8eh3uvxxfpur9asc6xjf75hn4qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6p05f4l" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyf9jt2gte5jxsezzd4r5fd3lq94kjnvweav3jrujnth2h67ntchcjd67ur&#39;&gt;nevent1q…67ur&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also in both cases Oracle hasn’t filed an 8-K or told regulators or provided an IR report to customers or a written technical statement of what happened or put anything on their website or commented to press.
    </content>
    <updated>2025-04-03T13:05:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyf9jt2gte5jxsezzd4r5fd3lq94kjnvweav3jrujnth2h67ntchczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l60jzymd</id>
    
      <title type="html">To answer my own question up thread - from talking to people, the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyf9jt2gte5jxsezzd4r5fd3lq94kjnvweav3jrujnth2h67ntchczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l60jzymd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvsmq7wxrfcs0qts5em27kks6xdt9uss4qy0r278c4hnrkc9etv6gndj9hk&#39;&gt;nevent1q…j9hk&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;To answer my own question up thread - from talking to people, the Oracle Health breach appears to be unrelated to the Oracle SaaS incident this thread describes. &lt;br/&gt;&lt;br/&gt;In both cases they’re being extorted, and in both cases they’re working with the FBI and external incident response.
    </content>
    <updated>2025-04-03T12:55:16Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvsmq7wxrfcs0qts5em27kks6xdt9uss4qy0r278c4hnrkc9etv6gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6vfcu6g</id>
    
      <title type="html">Oracle were still trying to get SaaS solutions *they* manage off ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvsmq7wxrfcs0qts5em27kks6xdt9uss4qy0r278c4hnrkc9etv6gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6vfcu6g" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswhphxgqthuf29xkkr253ru9d66cxs8fgtgw2myadyxzfscyemfkgecjf42&#39;&gt;nevent1q…jf42&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oracle were still trying to get SaaS solutions *they* manage off Oracle Classic aka Gen1 as of 2023. They made a mess of it.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/273/954/152/805/333/original/9462e09daeffbb8b.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-03T12:09:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswhphxgqthuf29xkkr253ru9d66cxs8fgtgw2myadyxzfscyemfkgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6m024pm</id>
    
      <title type="html">Yeah, by legacy system Oracle mean ‘a system we manage housing ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswhphxgqthuf29xkkr253ru9d66cxs8fgtgw2myadyxzfscyemfkgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6m024pm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx0wg5ef8hxutv344q5dz3e4u2genk25cw9ajhcm7vqk3pgsu0y9gqncazv&#39;&gt;nevent1q…cazv&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah, by legacy system Oracle mean ‘a system we manage housing active customer data’. They’ve also been telling people it isn’t Oracle Cloud.. but it is, and they know it is, they’re just doing customer talking points to wordsmith around it. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@Fringedcrow/114273919390396133&#34;&gt;https://infosec.exchange/@Fringedcrow/114273919390396133&lt;/a&gt;
    </content>
    <updated>2025-04-03T12:05:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx0wg5ef8hxutv344q5dz3e4u2genk25cw9ajhcm7vqk3pgsu0y9gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ujlvmu</id>
    
      <title type="html">The Bloomberg article is paywall so here’s screenshots. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx0wg5ef8hxutv344q5dz3e4u2genk25cw9ajhcm7vqk3pgsu0y9gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ujlvmu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszdvf5tv8da0c3nq44rhfgy4dqkl8na0uggmc76zrtusrpxq72knsuadkk0&#39;&gt;nevent1q…dkk0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The Bloomberg article is paywall so here’s screenshots.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/273/186/220/506/506/original/f8f2490848206049.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/273/186/529/949/197/original/42a2ca8df53b03fb.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-03T08:54:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszdvf5tv8da0c3nq44rhfgy4dqkl8na0uggmc76zrtusrpxq72knszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6epwjq4</id>
    
      <title type="html">“The company informed customers that the system has not been in ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszdvf5tv8da0c3nq44rhfgy4dqkl8na0uggmc76zrtusrpxq72knszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6epwjq4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspw5qha6z3dfu228afmjhmhgtwrlhdsl7m4cwszjrgny93f5le0cs9g2w9f&#39;&gt;nevent1q…2w9f&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;“The company informed customers that the system has not been in use for eight years and that the stolen client credentials therefore pose little risk, the report added. The stolen data included Oracle customer log-in credentials from as recently as 2024, the report said.”&lt;br/&gt;&lt;br/&gt;This would be Oracle Classic, aka Gen1. I’ve been told the systems were left online after migration.. unpatched. &lt;br/&gt;&lt;br/&gt;Oracle are trying to play legacy angle - but what else was stolen? What else did the attacker do? Why cover up?
    </content>
    <updated>2025-04-03T08:25:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspw5qha6z3dfu228afmjhmhgtwrlhdsl7m4cwszjrgny93f5le0cszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6qzz33e</id>
    
      <title type="html">We have an update. Reuters and Bloomberg confirm my blog, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspw5qha6z3dfu228afmjhmhgtwrlhdsl7m4cwszjrgny93f5le0cszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6qzz33e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswt8t9h004n039ddazjjyqmg7u5xgds6raqpqxf89h77dg96r9tjgyzvx4n&#39;&gt;nevent1q…vx4n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;We have an update. Reuters and Bloomberg confirm my blog, that’s there’s a security incident going on at Oracle cloud. Oracle declined to comment, after lying to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1pkrnqz97z2wckgmwglckccgg65eanvw3wpvuses7npqlvv6st06svz6763&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;BleepingComputer&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1pkr…6763&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; and other outlets on the record. &lt;br/&gt;&lt;br/&gt;CrowdStrike is the IR company. &lt;br/&gt;&lt;br/&gt;“Oracle staff acknowledged to some clients this week that an attacker had gotten into a legacy environment, Bloomberg News report said.”&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.reuters.com/technology/cybersecurity/oracle-tells-clients-second-recent-hack-log-in-data-stolen-bloomberg-news-2025-04-02/&#34;&gt;https://www.reuters.com/technology/cybersecurity/oracle-tells-clients-second-recent-hack-log-in-data-stolen-bloomberg-news-2025-04-02/&lt;/a&gt;
    </content>
    <updated>2025-04-03T08:22:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsz6nfuj4cmq0ax8xh0l40qya6n79mxuuhdlgm2ecltkmjwzy5r08czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69mfqz9</id>
    
      <title type="html">100% on this one, seen all the time on real world incidents. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsz6nfuj4cmq0ax8xh0l40qya6n79mxuuhdlgm2ecltkmjwzy5r08czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69mfqz9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfkx7fx3yw9jdr42tm0fnfngxe265e9qg0yrwsq43nm6jx0k0sxdcm66epr&#39;&gt;nevent1q…6epr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;100% on this one, seen all the time on real world incidents. &lt;br/&gt;&lt;br/&gt;Problem: somebody got a password for an account and nobody knows how. &lt;br/&gt;&lt;br/&gt;How: the business user signed into their personal Google account in Chrome at work, which synced all their bookmarks and saved passwords to Google. Then they switched on their home PC, Chrime synced, and infostealer took all the details&lt;br/&gt;&lt;br/&gt;Solution: Google Chrome ADMX, and set Group Policy to turn off personal account sign in with Chrome. &lt;br/&gt;&lt;br/&gt; &lt;a href=&#34;https://infosec.exchange/@Walker/114268652560517693&#34;&gt;https://infosec.exchange/@Walker/114268652560517693&lt;/a&gt;
    </content>
    <updated>2025-04-02T17:21:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfkx7fx3yw9jdr42tm0fnfngxe265e9qg0yrwsq43nm6jx0k0sxdczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6jhg068</id>
    
      <title type="html">I should also point out there&amp;#39;s a lot of infosec people at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfkx7fx3yw9jdr42tm0fnfngxe265e9qg0yrwsq43nm6jx0k0sxdczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6jhg068" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9guufgpcx20k2p309ln876j6e9qlmvpnad0rpja9s5k29u9t2d7qmduvk8&#39;&gt;nevent1q…uvk8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I should also point out there&amp;#39;s a lot of infosec people at trillion dollar tech companies sat thinking quantum and AI is going to be the next big problem...&lt;br/&gt;&lt;br/&gt;...when in reality SMBs make up a vast majority of the global economy - and are getting owned by people running this as they can&amp;#39;t work out nmap parameters, while playing Call of Duty on their second monitor (this isn&amp;#39;t even a joke, this was a ransomware deployment):&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/269/268/098/136/656/original/1f351dc552d9a58a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T16:20:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9guufgpcx20k2p309ln876j6e9qlmvpnad0rpja9s5k29u9t2d7qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l695pg5h</id>
    
      <title type="html">Finally, if you want the raw incident data to analyse, Sophos has ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9guufgpcx20k2p309ln876j6e9qlmvpnad0rpja9s5k29u9t2d7qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l695pg5h" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfsftvk20gfmf0t2m4ec6dm43sk03d0evg629dxane9e79cz7x89s50h22d&#39;&gt;nevent1q…h22d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Finally, if you want the raw incident data to analyse, Sophos has it, anonymized: &lt;a href=&#34;https://github.com/sophoslabs/Active_Adversary_Report/blob/main/sophos-aar2501-github-share.csv&#34;&gt;https://github.com/sophoslabs/Active_Adversary_Report/blob/main/sophos-aar2501-github-share.csv&lt;/a&gt;
    </content>
    <updated>2025-04-02T15:16:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfsftvk20gfmf0t2m4ec6dm43sk03d0evg629dxane9e79cz7x89szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6v2yak2</id>
    
      <title type="html">Notably, for the second year running (and same with all prior ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfsftvk20gfmf0t2m4ec6dm43sk03d0evg629dxane9e79cz7x89szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6v2yak2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2tpj6rnh5tr3vzqz3js2jt4jw0zn5amvksn9avmzzhnq5c5jrrks4hylal&#39;&gt;nevent1q…ylal&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Notably, for the second year running (and same with all prior reports) (and the same across other IR and MDR providers), the report doesn&amp;#39;t mention AI or Generative AI once.&lt;br/&gt;&lt;br/&gt;Absolutely not popular to say that and always get next to zero engagement on LinkedIn, but let me be super clear on this one:&lt;br/&gt;&lt;br/&gt;The threat to your business is foundational IT and security.  The big incident that screws you over will be somebody pointing and clicking.  Focus on what actually matters, not AI.
    </content>
    <updated>2025-04-02T15:15:06Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2tpj6rnh5tr3vzqz3js2jt4jw0zn5amvksn9avmzzhnq5c5jrrkszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6e20dyt</id>
    
      <title type="html">In 84% of cases - you know, almost all - attackers use RDP, aka ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2tpj6rnh5tr3vzqz3js2jt4jw0zn5amvksn9avmzzhnq5c5jrrkszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6e20dyt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx63rsk8e82f7du727rjgfg76cm2agd4zktuzhyesgvdw6v70wtwqcuapaq&#39;&gt;nevent1q…apaq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;In 84% of cases - you know, almost all - attackers use RDP, aka Remote Desktop.  &lt;br/&gt;&lt;br/&gt;Yes, you think attackers are hacking the matrix and using Generative AI to generate 31337 code... but in fact, almost all of them are using Remote Desktop to *point and click* hack you.&lt;br/&gt;&lt;br/&gt;There&amp;#39;s some really good recommendations in that for monitoring internal RDP usage.  It&amp;#39;s by far one of the biggest ways to catch people internally being naughty.  Why is somebody RDPing to a domain controller at 3am?&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/269/004/298/623/743/original/261720b193529c4f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T15:12:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx63rsk8e82f7du727rjgfg76cm2agd4zktuzhyesgvdw6v70wtwqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6senm3m</id>
    
      <title type="html">If you have a way of being able to block or at least alert on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx63rsk8e82f7du727rjgfg76cm2agd4zktuzhyesgvdw6v70wtwqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6senm3m" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs85sd793zzgqc9atvtc7vfzxgpcrl6e08uqp7z7nzx43pp9tjdyxq94zy45&#39;&gt;nevent1q…zy45&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If you have a way of being able to block or at least alert on software, yeet these:&lt;br/&gt;&lt;br/&gt;- SoftPerfect Network Scanner&lt;br/&gt;- AnyDesk&lt;br/&gt;- mimikatz (lol 2025)&lt;br/&gt;- Rclone&lt;br/&gt;- WinRAR&lt;br/&gt;- Advanced IP Scanner&lt;br/&gt;- Advanced Port Scanner&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/995/801/228/130/original/3e670dbc98e71494.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T15:09:31Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs85sd793zzgqc9atvtc7vfzxgpcrl6e08uqp7z7nzx43pp9tjdyxqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l64fk9m6</id>
    
      <title type="html">Bruteforce and external remote access drives a significant ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs85sd793zzgqc9atvtc7vfzxgpcrl6e08uqp7z7nzx43pp9tjdyxqzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l64fk9m6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfll89w0l346sx7scy2wkvelu8vnm426z2wqs2mr5cmt5tur5zv6gv4k7q2&#39;&gt;nevent1q…k7q2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Bruteforce and external remote access drives a significant portion of incidents, which also ties to compromised credentials (78% of cases is remote access with valid creds, infostealers go brrrr).  &lt;br/&gt;&lt;br/&gt;CitrixBleed was 5% of all security incidents - may explain why I made an MSPaint.exe logo for it&lt;br/&gt;&lt;br/&gt;The long story short is you need really robust authentication - if you get it wrong, you are toast in 2025 - and really, really robust external services patching. Don&amp;#39;t ever present RDP to the internet.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/985/251/405/106/original/b56a028a2912c150.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T15:07:31Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfll89w0l346sx7scy2wkvelu8vnm426z2wqs2mr5cmt5tur5zv6gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6mdn8xy</id>
    
      <title type="html">Compromised credentials continue to drive a majority of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfll89w0l346sx7scy2wkvelu8vnm426z2wqs2mr5cmt5tur5zv6gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6mdn8xy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqtsmp440270hg64vkzmklnayepjh3ace5hfrln84x92y5craftegtxsvjx&#39;&gt;nevent1q…svjx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Compromised credentials continue to drive a majority of incidents.  Why? home PCs and infostealers.  &lt;br/&gt;&lt;br/&gt;MS Recall got the shite kicked out of it because it would have been a disaster for exactly this reason, we don&amp;#39;t need to pour petrol on that already raging and unsolved fire.&lt;br/&gt;&lt;br/&gt;Bruteforcing of VPNs and exploitation of network border vulnerabilities continues to be a major (and growing) problem.&lt;br/&gt;&lt;br/&gt;Bang for buck: Concentrate on MFA everything, patch everything internet facing, monitor bruteforce.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/477/001/972/365/original/4f9e7c5d782aeef0.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T13:00:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqtsmp440270hg64vkzmklnayepjh3ace5hfrln84x92y5craftegzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sep5jt</id>
    
      <title type="html">The 2025 Sophos Active Adversary Report is out. I thread these ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqtsmp440270hg64vkzmklnayepjh3ace5hfrln84x92y5craftegzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6sep5jt" />
    <content type="html">
      The 2025 Sophos Active Adversary Report is out.&lt;br/&gt;&lt;br/&gt;I thread these every year as, personally, I think yearly IR and MDR reports are the best source of data for defenders on _real world_ threats.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://news.sophos.com/en-us/2025/04/02/2025-sophos-active-adversary-report/&#34;&gt;https://news.sophos.com/en-us/2025/04/02/2025-sophos-active-adversary-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Key take aways for me:&lt;br/&gt;&lt;br/&gt;- Despite what you read from scare vendors, ransomware dwell time (initial access to deployment) is still measured days.  &lt;br/&gt;&lt;br/&gt;It is not hopeless and by active monitoring you *can* stop attackers.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/471/173/532/870/original/2e2261a255c41905.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T12:55:31Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswt8t9h004n039ddazjjyqmg7u5xgds6raqpqxf89h77dg96r9tjgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6mx284x</id>
    
      <title type="html">Meanwhile, on the Oracle cloud front, Oracle’s silence is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswt8t9h004n039ddazjjyqmg7u5xgds6raqpqxf89h77dg96r9tjgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6mx284x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspr2tyjymaql5r560fg4tv467ylt4r49g9l0egvrudx9hrmcj7w3qphmscw&#39;&gt;nevent1q…mscw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Meanwhile, on the Oracle cloud front, Oracle’s silence is deafening.&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/255/102/142/354/original/21819ef23b2b1800.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/255/364/172/111/original/966f7d243c226f18.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/268/255/650/012/976/original/a109334601c72870.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T12:00:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspr2tyjymaql5r560fg4tv467ylt4r49g9l0egvrudx9hrmcj7w3qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6tumsp2</id>
    
      <title type="html">A class action lawsuit has been filed in the US around Oracle ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspr2tyjymaql5r560fg4tv467ylt4r49g9l0egvrudx9hrmcj7w3qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6tumsp2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstyup0evsheejfwqc2fsajgwayk2sszkx7s54q003wwau9r6h0x4skwltf2&#39;&gt;nevent1q…ltf2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A class action lawsuit has been filed in the US around Oracle failing to publicly disclose a breach of Oracle Health.  &lt;a href=&#34;https://storage.courtlistener.com/recap/gov.uscourts.txwd.1172831612/gov.uscourts.txwd.1172831612.1.0.pdf&#34;&gt;https://storage.courtlistener.com/recap/gov.uscourts.txwd.1172831612/gov.uscourts.txwd.1172831612.1.0.pdf&lt;/a&gt;
    </content>
    <updated>2025-04-02T11:54:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstyup0evsheejfwqc2fsajgwayk2sszkx7s54q003wwau9r6h0x4szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68myzd5</id>
    
      <title type="html">Heise has a look at the Oracle security incident. Oracle didn’t ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstyup0evsheejfwqc2fsajgwayk2sszkx7s54q003wwau9r6h0x4szyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l68myzd5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstxgesh3murymnw4adeu3m98mlu6hxx5ud662exp2zdwdcs86402chu7ku9&#39;&gt;nevent1q…7ku9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Heise has a look at the Oracle security incident.  Oracle didn’t return request for comment when asked about Oracle Classic - I understand from multiple large outlets they’ve also declined to comment. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.heise.de/en/news/Data-leak-at-Oracle-Up-to-2000-German-victims-What-is-known-and-what-is-not-10336366.html&#34;&gt;https://www.heise.de/en/news/Data-leak-at-Oracle-Up-to-2000-German-victims-What-is-known-and-what-is-not-10336366.html&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/267/165/009/827/296/original/58a6ec2b3a93f12c.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/267/165/328/659/618/original/a2a2a8e48860fc2b.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/267/165/585/108/447/original/ada78dbdffcb3ee2.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T07:23:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstxgesh3murymnw4adeu3m98mlu6hxx5ud662exp2zdwdcs86402czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6depanh</id>
    
      <title type="html">Oracle Health customers dealing with the breach there of patient ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstxgesh3murymnw4adeu3m98mlu6hxx5ud662exp2zdwdcs86402czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6depanh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8mx4z2fn6a07jpgqrt5sw3nlhpu7ds3tgda72tn8xr8fppr5s6fg7vwa3k&#39;&gt;nevent1q…wa3k&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oracle Health customers dealing with the breach there of patient PII, if you’ve had a verbal briefing could you please Signal me? GossiTheDog.1337&lt;br/&gt;&lt;br/&gt;I’m interested to see if they’ve told you it was in legacy Oracle Classic aka OCI Gen1 environments, like they have with Oracle Cloud customers - I’m trying to line up if the breaches are actually related. &lt;br/&gt;&lt;br/&gt;It appears Oracle migrated people off OCI G1 a few years ago, but left the systems on and unpatched with customer data.
    </content>
    <updated>2025-04-01T10:26:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswzyljfu94g0au99w36jj9pxcs40sgpks4yuz633xy4dr3lpyhafczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l66refxp</id>
    
      <title type="html">I can confirm there has definitely been a serious security ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswzyljfu94g0au99w36jj9pxcs40sgpks4yuz633xy4dr3lpyhafczyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l66refxp" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9d27n3hnvspm9l8g2uzjcjfzr5vyuazy8txt0ldwpr72z02ddtxgamkqqa&#39;&gt;nevent1q…kqqa&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I can confirm there has definitely been a serious security incident at Oracle&amp;#39;s managed cloud service, and they&amp;#39;re attempting to wordsmith their way out of it. &lt;a href=&#34;https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a&#34;&gt;https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a&lt;/a&gt;
    </content>
    <updated>2025-03-31T11:53:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9d27n3hnvspm9l8g2uzjcjfzr5vyuazy8txt0ldwpr72z02ddtxgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6m0feug</id>
    
      <title type="html">Going back to the Oracle Cloud security incident, the 2019 video ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9d27n3hnvspm9l8g2uzjcjfzr5vyuazy8txt0ldwpr72z02ddtxgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6m0feug" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg92aqpmc70yuf6w4c9nf7nqae6s608mrvpqnvhaegwyz9m5d4yzg2vhnyn&#39;&gt;nevent1q…hnyn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Going back to the Oracle Cloud security incident,  the 2019 video posted by the threat actor: &lt;a href=&#34;https://youtu.be/375_G9wAffo&#34;&gt;https://youtu.be/375_G9wAffo&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;Now has an audio transcription &lt;a href=&#34;https://github.com/j-klawson/oracle_breach_2025/blob/main/youtube_video_transcript.txt&#34;&gt;https://github.com/j-klawson/oracle_breach_2025/blob/main/youtube_video_transcript.txt&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/240/775/632/585/626/original/608845a01b8aee49.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-28T15:31:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg92aqpmc70yuf6w4c9nf7nqae6s608mrvpqnvhaegwyz9m5d4yzgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6rpht2y</id>
    
      <title type="html">There’s now been a data breach at Oracle Health, which is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg92aqpmc70yuf6w4c9nf7nqae6s608mrvpqnvhaegwyz9m5d4yzgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6rpht2y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg3k9076mkm93pddanrxc8yvm0af3egtjy22hnu8qpppcr8t8ft6q2729f0&#39;&gt;nevent1q…29f0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;There’s now been a data breach at Oracle Health, which is separate to the ongoing security issue at Oracle Cloud. &lt;br/&gt;&lt;br/&gt;Oracle have not commented publicly on the breach, instead telling people to only talk to their CISO by phone, not in writing. They’ve sent out letters without Oracle letterheads, using external lawyers instead. &lt;br/&gt;&lt;br/&gt;The behaviour going on at Oracle with cybersecurity is extremely alarming. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/oracle-health-breach-compromises-patient-data-at-us-hospitals/&#34;&gt;https://www.bleepingcomputer.com/news/security/oracle-health-breach-compromises-patient-data-at-us-hospitals/&lt;/a&gt;
    </content>
    <updated>2025-03-28T15:27:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg3k9076mkm93pddanrxc8yvm0af3egtjy22hnu8qpppcr8t8ft6qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6w8k4ph</id>
    
      <title type="html">Also, that YouTube video I linked above has two hours of audio of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg3k9076mkm93pddanrxc8yvm0af3egtjy22hnu8qpppcr8t8ft6qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6w8k4ph" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw4ke62cl3zcdcwqfwqe20qnekd0cxu6jqm9rrjq0t67g7s735wfs4cmer6&#39;&gt;nevent1q…mer6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also, that YouTube video I linked above has two hours of audio of Oracle employees talking.  I haven’t transcribed it yet. &lt;br/&gt;&lt;br/&gt;Separately, the threat actor has shared what they claim to be current config files from Oracle Cloud servers with a different reporter. &lt;br/&gt;&lt;br/&gt;I’m deliberately staying out of this one for now as I’m trying to finish Assassin’s Creed Shadows first.. but I think Oracle may have a pending PR disaster when the TikTok deal is due to complete.
    </content>
    <updated>2025-03-26T21:42:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw4ke62cl3zcdcwqfwqe20qnekd0cxu6jqm9rrjq0t67g7s735wfszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l63ajfzr</id>
    
      <title type="html">Bleeping Computer say multiple Oracle customers confirm their ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw4ke62cl3zcdcwqfwqe20qnekd0cxu6jqm9rrjq0t67g7s735wfszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l63ajfzr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8qcw6p2mcdkjam8r0wjr8eha9ktffs0tduv53y9pekfpf9055j5gla8kkz&#39;&gt;nevent1q…8kkz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Bleeping Computer say multiple Oracle customers confirm their customer data has been stolen from Oracle Cloud. Oracle continue to deny there is a problem. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/oracle-customers-confirm-data-stolen-in-alleged-cloud-breach-is-valid/&#34;&gt;https://www.bleepingcomputer.com/news/security/oracle-customers-confirm-data-stolen-in-alleged-cloud-breach-is-valid/&lt;/a&gt;
    </content>
    <updated>2025-03-26T21:26:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs22a6uru50l2x82hx5qn2tehwp75sk8gxvn2xqpp7fgz87jpnxd6czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l67amfn8</id>
    
      <title type="html">I think it’s entirely possible the US gov will try arresting ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs22a6uru50l2x82hx5qn2tehwp75sk8gxvn2xqpp7fgz87jpnxd6czyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l67amfn8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg2rmrgv5q5shyq6jd6vuh8rt0zvsnxj2zylp5tkumm3847l2l0lgv4u0h8&#39;&gt;nevent1q…u0h8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I think it’s entirely possible the US gov will try arresting the reporters and staff at that outlet to try to shut the story down, we’ll see.
    </content>
    <updated>2025-03-26T12:40:31Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg2rmrgv5q5shyq6jd6vuh8rt0zvsnxj2zylp5tkumm3847l2l0lgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ga3qlk</id>
    
      <title type="html">More Signal messages have been posted online, sent to a reporter, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg2rmrgv5q5shyq6jd6vuh8rt0zvsnxj2zylp5tkumm3847l2l0lgzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6ga3qlk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs84w5762v52dle6cv7ynk6fwwdv64gjm44ftk75rh8pff57uugvng4y22f6&#39;&gt;nevent1q…22f6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;More Signal messages have been posted online, sent to a reporter, which clearly show a breach in US national security.  &lt;a href=&#34;https://www.theatlantic.com/politics/archive/2025/03/signal-group-chat-attack-plans-hegseth-goldberg/682176/?utm_source=bluesky&amp;amp;utm_medium=social&amp;amp;utm_campaign=the-atlantic&amp;amp;utm_content=edit-promo&#34;&gt;https://www.theatlantic.com/politics/archive/2025/03/signal-group-chat-attack-plans-hegseth-goldberg/682176/?utm_source=bluesky&amp;amp;utm_medium=social&amp;amp;utm_campaign=the-atlantic&amp;amp;utm_content=edit-promo&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/228/767/200/484/510/original/0d6c1cc2b1ea9f7f.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-26T12:37:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs84w5762v52dle6cv7ynk6fwwdv64gjm44ftk75rh8pff57uugvngzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6czavc3</id>
    
      <title>Nostr event nevent1qqs84w5762v52dle6cv7ynk6fwwdv64gjm44ftk75rh8pff57uugvngzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6czavc3</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs84w5762v52dle6cv7ynk6fwwdv64gjm44ftk75rh8pff57uugvngzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6czavc3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqyn5cn3zev9z7x3fhccztvrj50zfmdu8k76mtwms7uneep2few7qffhf9f&#39;&gt;nevent1q…hf9f&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;lol&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/225/000/521/387/503/original/682dc6a53cb32460.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-25T20:39:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqyn5cn3zev9z7x3fhccztvrj50zfmdu8k76mtwms7uneep2few7qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69j5xcs</id>
    
      <title type="html">The Trump administration claims the Signal chats don’t contain ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqyn5cn3zev9z7x3fhccztvrj50zfmdu8k76mtwms7uneep2few7qzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l69j5xcs" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq0dux687wev86y6pway5cckjqcx326wpwy0mw4chazvlgzvhpktssxdeqw&#39;&gt;nevent1q…deqw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The Trump administration claims the Signal chats don’t contain classified material, but they refused to release them publicly. &lt;br/&gt;&lt;br/&gt;The journalist in the conversations is saying he won’t release them, as they do contain classified information.  &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bbc.co.uk/news/live/cg70xgxl3vmt?post=asset%3Ac0c0c6ea-9066-4cd0-88d9-f5b1e59cb801#post&#34;&gt;https://www.bbc.co.uk/news/live/cg70xgxl3vmt?post=asset%3Ac0c0c6ea-9066-4cd0-88d9-f5b1e59cb801#post&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/224/276/946/081/264/original/e3716b7c70329e34.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-25T17:35:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsq0dux687wev86y6pway5cckjqcx326wpwy0mw4chazvlgzvhpktszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6wexqqv</id>
    
      <title type="html">Well done to Trump administration officials for starting a major ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsq0dux687wev86y6pway5cckjqcx326wpwy0mw4chazvlgzvhpktszyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6wexqqv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstte8lcls6n2kgz949dt8tvny3a0p6580emeapzlt7vhmc25trv5s5874zz&#39;&gt;nevent1q…74zz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Well done to Trump administration officials for starting a major diplomatic crisis via a secure messaging platform that children should be able to operate.  &lt;a href=&#34;https://www.bbc.co.uk/news/live/cg70xgxl3vmt&#34;&gt;https://www.bbc.co.uk/news/live/cg70xgxl3vmt&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cyberplace.social/system/media_attachments/files/114/223/236/084/839/803/original/9afb858ca922e523.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-25T13:11:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8qcw6p2mcdkjam8r0wjr8eha9ktffs0tduv53y9pekfpf9055j5gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6qknqda</id>
    
      <title type="html">CloudSEK are doubling down on their Oracle Cloud breach ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8qcw6p2mcdkjam8r0wjr8eha9ktffs0tduv53y9pekfpf9055j5gzyrlrrf6vu7nn26yks6j230dhvk50fku5tkgmvaqjcag932p2288l6qknqda" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxqs597tz32kl53jufncnlfg0y2mwmdwxj0m0c9s2kky762577veq6km6yj&#39;&gt;nevent1q…m6yj&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;CloudSEK are doubling down on their Oracle Cloud breach reporting, despite a denial from Oracle:  &lt;a href=&#34;https://cloudsek.com/blog/part-2-validating-the-breach-oracle-cloud-denied-cloudseks-follow-up-analysis&#34;&gt;https://cloudsek.com/blog/part-2-validating-the-breach-oracle-cloud-denied-cloudseks-follow-up-analysis&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I am still looking into this and will probably do a blog post this week. The threat actor is still dropping files everywhere and they do tend to point to a security incident at Oracle Cloud.
    </content>
    <updated>2025-03-25T11:01:32Z</updated>
  </entry>

</feed>