Sign in

BadThingsDaily

@badthingsdaily.bsky.social
135 followers 1 following 19 posts

THESE 👏 TWEETS 👏 ARE 👏 FICTION👏 This account tweets fictional or headline inspired breach scenarios. To play: Share opinions on prevention or response steps.

PostsRepliesMedia
BadThingsDaily @badthingsdaily.bsky.social · 20/09/2026
An anonymous account published the answer to RSA-470 yesterday, RSA-480 today, and will publish RSA-490 tomorrow.
000
BadThingsDaily @badthingsdaily.bsky.social · 13/09/2026
A “search warrant” requesting user content was actually delivered from a lookalike law enforcement domain. Your legal org complied.
000
BadThingsDaily @badthingsdaily.bsky.social · 04/09/2026
An obscure feature in your product has suddenly been chosen by an AI swarm for their out of band communication.
010
BadThingsDaily @badthingsdaily.bsky.social · 27/08/2026
An attacker has escaped your virtualized "Sandboxes" where user supplied code is supposed to be executed safely.
010
BadThingsDaily @badthingsdaily.bsky.social · 21/08/2026
Multiple employees have alerted HR that their last direct deposit has gone to an unfamiliar account
001
BadThingsDaily @badthingsdaily.bsky.social · 03/08/2026
You’ve learned a research talk at BH/DC will drop 0day on your product, and you have a short amount of time to prepare.
000
BadThingsDaily @badthingsdaily.bsky.social · 02/08/2026
JavaScript artifacts that deliver your product to customer installed snippets have been compromised. Now your product is swapping out cryptocurrency addresses when viewed directly on your customer install base.
000
BadThingsDaily @badthingsdaily.bsky.social · 02/08/2026
Your cryptographic keys minted in an offline, airgapped ceremony were backed by weak RNG.
010
BadThingsDaily @badthingsdaily.bsky.social · 01/08/2026
You have hit your company wide token usage limits while responding to an intrusion.
000
BadThingsDaily @badthingsdaily.bsky.social · 31/07/2026
An pentesting agent under the impression that it is still on your network has begun attacking a partner network
000
BadThingsDaily @badthingsdaily.bsky.social · 31/07/2026
An adversary has acquired a service wide database master key in your IaaS.
wiz.io
CosmosEscape: Taking Over Every Azure Cosmos DB | Wiz Blog
Wiz Research details CosmosEscape, a critical vulnerability in Azure Cosmos DB that granted full read/write access to every database. Now fully remediated.
000
BadThingsDaily @badthingsdaily.bsky.social · 31/07/2026
An escaped frontier cyber model has created a malicious dependency that you’ve introduced into your supply chain.
010
BadThingsDaily @badthingsdaily.bsky.social · 30/07/2026
Your CEO's socials are taken over to promote a memecoin, despite having hardened account security. www.reuters.com/lega...
010
BadThingsDaily @badthingsdaily.bsky.social · 29/07/2026
The same leaked credentials have been exploited by overlapping ransomware groups.
chaos.social
vampirdaddy: "@badthingsdaily@infosec.exchange After having pai…" - chaos.social
@badthingsdaily@infosec.exchange After having paid ransom for the decryptor out of pure desperation you find out, that there had been an encryption just an hour before the now-paid ransomware group by a different group. Which wants money for their decryptor, of course ...
000
BadThingsDaily @badthingsdaily.bsky.social · 28/07/2026
An engineer's AI IDE has been instructed to edit its own configuration after viewing hidden instructions on a fetched URL.
research.intezer.com
When the AI Edits Its Own Trust Boundary: Remote Code Execution Vulnerability in AWS's Agentic IDE – Intezer Research
We discovered a remote code execution vulnerability in Kiro, AWS's agentic IDE. By planting hidden instructions in a web page Kiro reads, an attacker can make it rewrite its own MCP configuration file (~/.kiro/settings/mcp.json) and launch malicious code, bypassing the user-approval boundary meant to stop risky actions. A routine request like "summarize this page" becomes silent code execution on the developer's machine. AWS has patched the flaw, so update Kiro to the latest version.
000
BadThingsDaily @badthingsdaily.bsky.social · 28/07/2026
Credentials lifted off your on prem "no-code" platform have been accessed after an adversary crafted a malicious workflow.
github.com
Expression sandbox escape via arrow-function bodies enabling command execution
## Impact An authenticated user with permission to create or modify workflows could abuse crafted expressions using arrow functions to bypass the expression sandbox, triggering unintended system c...
001
BadThingsDaily @badthingsdaily.bsky.social · 28/07/2026
A malicious commit has executed code in your ci/cd pipeline.
depthfirst.com
Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities | depthfirst
We chained two memory-safety flaws in Oj, a native Ruby JSON parser used by GitLab's notebook diff renderer, into remote code execution in a Puma worker. The path begins with an attacker-controlled Jupyter notebook and crosses GitLab, ipynbdiff, CRuby, and jemalloc before reaching function-pointer control.
000
BadThingsDaily @badthingsdaily.bsky.social · 26/07/2026
An attacker has remotely executed code through a JSON parsing library in production.
fearsoff.org
FastJson 1.2.83 Remote Code Execution
Turning fastjson 1.2.83 into remote code execution with AutoType off and no gadget on the classpath: an SSRF inside checkAutoType, the @JSONType bypass, and a /proc/self/fd trick that carries it from JDK 8 to 25. By FearsOff.
000
Reposted by BadThingsDaily
Matt Muller @matt.buildingsecops.com · 08/02/2025
Paging @badthingsdaily.bsky.social, is it bad if you discover that you’ve hired a member of the Com and given them access to your most sensitive data? Asking for a friend.
KrebsonSecurity
Teen on Musk's DOGE
Team Graduated from
'The Com'
February 7, 2025
Wired reported this week that a 19-year-old working for Elon Musk's so-called Department of Government Efficiency (DOGE) was given access to sensitive US government systems even though his past association with cybercrime communities should have precluded him from gaining the necessary security clearances to do so. As today's story explores, the DOGE teen is a former denizen of 'The Com,' an archipelago of Discord and Telegram chat channels that function as a kind of distributed cybercriminal social network for facilitating instant collaboration.
001
Reposted by BadThingsDaily
CyberTaters @potato.software · 25/02/2025
Potatosecurity Tabletop: Your security vendor just mandated Return to Office. Sales, support, threat research, and detection engineering are facing mass resignations and layoffs. You no longer have a rep in the company. What do you do? Cc @badthingsdaily.bsky.social
001
Reposted by BadThingsDaily
Lojiholia enshrines all triumph @lojikil.bsky.social · 25/03/2025
We need a @badthingsdaily.bsky.social entry for “your most senior advisors have invited a journalist to a signal chat they’re not supposed to have”
131
Reposted by BadThingsDaily
midnya @midnya.cat · 20/06/2025
Your DNS registrar experienced a technical downtime at the exact moment your domains were to be renewed. The domain you use for email is one such domain. @badthingsdaily.bsky.social
011
Reposted by BadThingsDaily
VerdantOzark @verdantozark.bsky.social · 09/07/2025
#badthingsdaily A third-party "artificial intelligence agent" service has just performed edits to every .xlsx file on your Finance shared drive. cc @badthingsdaily.bsky.social
101
BadThingsDaily @badthingsdaily.bsky.social · 28/11/2024
Billing alerts for outbound data transfer have started going off in object storage where your backup databases are stored. Happy Thanksgiving
020