<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-06-06T17:27:03Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Glenn 📎</title>
  <author>
    <name>Glenn 📎</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1p03fezkj06uy70fp8d4vvmlcgl47grjl8rxk4hs5vkn2l0zuu3jsczq09v.rss" />
  <link href="https://yabu.me/npub1p03fezkj06uy70fp8d4vvmlcgl47grjl8rxk4hs5vkn2l0zuu3jsczq09v" />
  <id>https://yabu.me/npub1p03fezkj06uy70fp8d4vvmlcgl47grjl8rxk4hs5vkn2l0zuu3jsczq09v</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/320/853/553/361/576/original/039cf3e58191829a.jpeg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/320/853/553/361/576/original/039cf3e58191829a.jpeg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqs0lj3d2hcqusuu34460kyzema0eq3sm8uvl8x807cuz6nyvqxhxmgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx258t0ur</id>
    
      <title>Nostr event nevent1qqs0lj3d2hcqusuu34460kyzema0eq3sm8uvl8x807cuz6nyvqxhxmgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx258t0ur</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0lj3d2hcqusuu34460kyzema0eq3sm8uvl8x807cuz6nyvqxhxmgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx258t0ur" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy5dnxaewwcvpxs6l2rry40a9epuj96lhw95pj4f78ur05hhf8x9gen3fn9&#39;&gt;nevent1q…3fn9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/516/434/862/139/408/original/1ab6fb4de2aefb9f.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2026-05-04T13:01:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsp9fkndmc2xe3zd8kxvhaj3fcadqmxs3567zd72k3d884a430dedszyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2njgc8v</id>
    
      <title type="html">Bittersweet yet exciting transition ahead. This week marks my ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsp9fkndmc2xe3zd8kxvhaj3fcadqmxs3567zd72k3d884a430dedszyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2njgc8v" />
    <content type="html">
      Bittersweet yet exciting transition ahead. This week marks my last at GreyNoise.&lt;br/&gt;&lt;br/&gt;Lately I&amp;#39;ve spent a lot of time thinking about what I value most in this field: research and findings grounded in clarity, integrity, actionability, and truth that drives outcomes.&lt;br/&gt;&lt;br/&gt;#TheSignalShift
    </content>
    <updated>2026-04-27T16:27:09Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy9k0kntxstlw9yynxzva2xnfdvwxgkd4t2cgugeu8svsu7ud56lgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2rqclce</id>
    
      <title type="html">RE: https://infosec.exchange/@kev_Stalker/116020576227249969 So, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy9k0kntxstlw9yynxzva2xnfdvwxgkd4t2cgugeu8svsu7ud56lgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2rqclce" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@kev_Stalker/116020576227249969&#34;&gt;https://infosec.exchange/@kev_Stalker/116020576227249969&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;So, based on my work of digging into the KEV Ransomware flips, the RSS feed will now auto-toot here, if interested. There was a flip Tuesday (before the bot) and another just now.&lt;br/&gt;&lt;br/&gt;#threatintel&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1gla06g93cv06xudmxzsyydyqtg5rt3nktnc8q299d8np2v3zp0psyswvqr&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1gla…wvqr&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; CVE-2026-24423 - Changed to Known Ransomware Status&lt;br/&gt;&lt;br/&gt;SmarterTools SmarterMail Missing Authentication for Critical Function VulnerabilityVendor: SmarterToolsProduct: SmarterMailSmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead &lt;a href=&#34;https://nvd.nist.gov/vuln/detail/CVE-2026-24423&#34;&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-24423&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-02-05T23:33:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxw322xfjzysgkaqhy4fy4svan3t0jkun9y3q7k6w7hr3h3p98srgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2vvddta</id>
    
      <title type="html">☕ &amp;amp; #threatintel: CISA has moved the due date for ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxw322xfjzysgkaqhy4fy4svan3t0jkun9y3q7k6w7hr3h3p98srgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2vvddta" />
    <content type="html">
      ☕ &amp;amp; #threatintel: CISA has moved the due date for mitigating CVE-2025-55182 (Meta React Server Components Remote Code Execution Vulnerability) up two weeks. It was initially set for December 26, but it is now due on December 12. IIRC, this is the first time the due date has been modified. &lt;br/&gt;&lt;br/&gt;In all honesty, if you haven&amp;#39;t already patched this vulnerability, it&amp;#39;s likely too late. As a reminder, patching does not boot attackers, so you should check for indicators of compromise.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/695/646/728/738/384/original/751749d4c9f0a9ac.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-12-10T14:04:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdss3n8wmlekt734dwcsqzrfy6uny07gvpyyn60w0lm06m6mptzdszyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2pece7k</id>
    
      <title type="html">soon :tm:</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdss3n8wmlekt734dwcsqzrfy6uny07gvpyyn60w0lm06m6mptzdszyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2pece7k" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst57gekudylp6r67emqaze76dewc90zkfpy6w72qjpeddryd8fhzgj2rpe0&#39;&gt;nevent1q…rpe0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;soon :tm:
    </content>
    <updated>2025-07-16T20:17:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqpslveh7tudjnak4d69hp68ecggl30ecs78yhkw3jeztlc8hvvuczyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx28gjyft</id>
    
      <title type="html">🧐 are you referring to CVE-2025-5777 or did I miss yet ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqpslveh7tudjnak4d69hp68ecggl30ecs78yhkw3jeztlc8hvvuczyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx28gjyft" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd3wmtmkrqk0xyxwguvdj9ddgmwm8m9hhxqt3qy3t900tq6723skqn0thpn&#39;&gt;nevent1q…thpn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;🧐 are you referring to CVE-2025-5777 or did I miss yet another? We hadn’t planned on it but what are you thinking?
    </content>
    <updated>2025-07-16T01:34:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsp70yf78u757mdzrqk8a64c7k2zapgy0ce88fraqm08vx06cn5jqgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx20v64uq</id>
    
      <title type="html">🥜 &amp;amp; #threatintel - Thanks to Horizon3, we pushed a tag out ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsp70yf78u757mdzrqk8a64c7k2zapgy0ce88fraqm08vx06cn5jqgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx20v64uq" />
    <content type="html">
      🥜 &amp;amp; #threatintel - Thanks to Horizon3, we pushed a tag out today for CitrixBleed 2 CVE-2025-5777 and are backfilling. Currently, we see 233 hits starting on July 1 from:&lt;br/&gt;64.176.50[.]109&lt;br/&gt;38.154.237[.]100&lt;br/&gt;102.129.235[.]108&lt;br/&gt;121.237.80[.]241&lt;br/&gt;45.135.232[.]2&lt;br/&gt;&lt;br/&gt;Follow along here: &lt;a href=&#34;https://viz.greynoise.io/tags/citrixbleed-2-cve-2025-5777-attempt?days=10&#34;&gt;https://viz.greynoise.io/tags/citrixbleed-2-cve-2025-5777-attempt?days=10&lt;/a&gt;
    </content>
    <updated>2025-07-07T21:56:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv4q95xmlgsmwn6qze0hq642qqyflqnfx5w7h5qmqnsalyk6tdvvqzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2yzzxg8</id>
    
      <title type="html">If you attend this at RSA (by choice; excluding journalists) -- ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv4q95xmlgsmwn6qze0hq642qqyflqnfx5w7h5qmqnsalyk6tdvvqzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2yzzxg8" />
    <content type="html">
      If you attend this at RSA (by choice; excluding journalists) -- don&amp;#39;t ever talk to me again.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/417/840/628/115/785/original/79ff5ff2302c4a50.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-28T22:01:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrl893xxaph2mjhwv3fmx5em86r4l3rqruwltg035u3dnll2hq84qzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2y9q2mw</id>
    
      <title type="html">Hi yes. Help your local cybersecurity researchers. If you blog a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrl893xxaph2mjhwv3fmx5em86r4l3rqruwltg035u3dnll2hq84qzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2y9q2mw" />
    <content type="html">
      Hi yes. Help your local cybersecurity researchers. If you blog a thing, please date the blog.  kthx.
    </content>
    <updated>2025-04-07T15:26:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy0rhx3lz3cuvw0wr3xxmc74j82sxefs7fwwlx5yhfwxdqp4vh2rszyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx25x42rs</id>
    
      <title type="html">Words have meanings. Words have consequences. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy0rhx3lz3cuvw0wr3xxmc74j82sxefs7fwwlx5yhfwxdqp4vh2rszyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx25x42rs" />
    <content type="html">
      Words have meanings. Words have consequences.  &lt;br/&gt;&lt;a href=&#34;https://apple.news/AcP5I9x7QQ1iUHU_1zTJzOw&#34;&gt;https://apple.news/AcP5I9x7QQ1iUHU_1zTJzOw&lt;/a&gt;
    </content>
    <updated>2025-02-22T15:59:50Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxvn6f9v54px0mgdy9utxxcpswxq4pws68dfayz7ratdspwz2s0dgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2aghhtn</id>
    
      <title type="html">We, @npub1lmd…m9t8, are seeing a massive uptick in IPs ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxvn6f9v54px0mgdy9utxxcpswxq4pws68dfayz7ratdspwz2s0dgzyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx2aghhtn" />
    <content type="html">
      We, &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;GreyNoise&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lmd…m9t8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, are seeing a massive uptick in IPs attempting to authenticate via telnet using one of several known backdoor accounts in FiberHome routers.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://viz.greynoise.io/tags/fiberhome-telnet-backdoor-attempt?days=30&#34;&gt;https://viz.greynoise.io/tags/fiberhome-telnet-backdoor-attempt?days=30&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;1/2&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/398/027/632/927/559/original/8b99f6d9cd0e7869.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-10-30T19:29:44Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrly7hpgkc254wykmlfkh74z5tqeapfdjqmy2urw80ugxqfsw4ykczyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx235mhl9</id>
    
      <title type="html">🎃 &amp;amp; #threatintel: We/GreyNoise have observed a significant ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrly7hpgkc254wykmlfkh74z5tqeapfdjqmy2urw80ugxqfsw4ykczyq9798y26fltsneayyak43n0lpr7heqwtuuv66k7z3j6dtautnjx235mhl9" />
    <content type="html">
      🎃 &amp;amp; #threatintel: We/GreyNoise have observed a significant increase in Fortinet SSL brute force attempts recently. This is the highest level in the past two months and the third highest of 2024.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://viz.greynoise.io/tags/fortinet-ssl-vpn-bruteforcer?days=10&#34;&gt;https://viz.greynoise.io/tags/fortinet-ssl-vpn-bruteforcer?days=10&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/330/483/046/725/506/original/809a4977dafe180a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-10-18T21:12:16Z</updated>
  </entry>

</feed>