Sign in

Cheryl Babcock

@blackasphodel.bsky.social
78 followers 120 following 102 posts

Cybersecurity ninja, too many food allergies, nerd of many flavors

PostsRepliesMedia
Cheryl Babcock @blackasphodel.bsky.social · 08/09/2025
I was diagnosed with alpha-gal about 3 month ago, and my allergist tested a bunch of my existing allergies to see how it affected me. Apparently this has reversed my dairy allergy I have had since BIRTH. Bodies are weird, but I guess thank you Random Tick for giving me cheese back?!
100
Cheryl Babcock @blackasphodel.bsky.social · 08/09/2025
www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Max severity Argo CD API flaw leaks repository credentials
An Argo CD vulnerability allows API tokens with even low project-level get permissions to access API endpoints and retrieve all repository credentials associated with the project.
010
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 06/09/2025
Zuckerberg Caught in Revealing Hot Mic Moment During White House Dinner | Discussion
pcmag.com
022
Cheryl Babcock @blackasphodel.bsky.social · 14/08/2025
The Meta chatbot *invited him to a real location to meet*. What the ever living dystopian fuck. www.reuters.com/investigates...
reuters.com
A flirty Meta AI bot invited a retiree to meet. He never made it home.
Impaired by a stroke, a man fell for a Meta chatbot originally created with Kendall Jenner. His death spotlights Meta’s AI rules, which let bots tell falsehoods.
220
Cheryl Babcock @blackasphodel.bsky.social · 17/07/2025
Just found out I have Alpha-gal now. @foodallergyscience.org do you have any research going on into that?
100
Cheryl Babcock @blackasphodel.bsky.social · 27/06/2025
Because most of us have used Notepad++ at one time or another. Note while the article calls out updating to 8.8.2 its still a release candidate so it's a manual update. socprime.com/blog/cve-202...
socprime.com
CVE-2025-49144 Vulnerability: Critical Privilege Escalation Flaw in Notepad++ Leads to Full System Takeover | SOC Prime
Explore details for CVE-2025-49144, a privilege escalation vulnerability affecting Notepad++, with in-depth analysis in the SOC Prime blog.
020
Reposted by Cheryl Babcock
Johnny Xmas @j0hnnyxm4s.johnnyxmas.net · 23/06/2025
CVEs and ATT&CK TTPs currently being seen in use in the wild by known Iranian threat groups:
033
Cheryl Babcock @blackasphodel.bsky.social · 10/06/2025
Lots of stuff down today...
000
Cheryl Babcock @blackasphodel.bsky.social · 10/06/2025
apnews.com/article/ai-s...
apnews.com
Scammers are using AI to enroll fake students in online classes, then steal college financial aid
Financial aid fraud is exploding, thanks to the rise of artificial intelligence. Crime rings are deploying “ghost students” — chatbots who enroll in online college classes and stay just long enough to...
000
Cheryl Babcock @blackasphodel.bsky.social · 04/06/2025
localmess.github.io
localmess.github.io
Covert Web-to-App Tracking via Localhost on Android
000
Reposted by Cheryl Babcock
Gwen Snyder is uncivil @gwensnyder.bsky.social · 31/05/2025
Someone else said something very similar to this the other day, but. It really burns me that our (millennials') generation was legally terrorized for like, downloading Radiohead discographies But we're supposed to be ok with billionaires stealing human intellectual output in its entirety bc AI
111132114386
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 29/05/2025
Google Is Using AI to Censor Independent Websites Like Mine | Discussion
travellemming.com
Google is Using AI to Censor Independent Websites
My letter to the FTC explaining how Google is using AI to censor thousands of independent websites - and to control the flow of information online.
001
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 28/05/2025
The Chinese APT41 hacking group uses a new malware named 'ToughProgress' that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service.
bleepingcomputer.com
APT41 malware abuses Google Calendar for stealthy C2 communication
The Chinese APT41 hacking group uses a new malware named 'ToughProgress' that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service.
037
Reposted by Cheryl Babcock
nixCraft @cyberciti.biz · 28/05/2025
Pro tip: Are you using Ublock Origin? Add "google.com##.hdzaWe" without quotes to your Ublock Origin My Filters to block the google AI overview and apply changes.
Pro tip: Are you using Ublock Origin? Add "google.com##.hdzaWe" without quotes to your Ublock Origin My Filters to block the google AI overview and apply changes.
1021691
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 19/05/2025
The Windows Subsystem for Linux is now open source | Discussion
blogs.windows.com
The Windows Subsystem for Linux is now open source
Today we’re very excited to announce the open-source release of the Windows Subsystem for Linux. This is the result of a multiyear effort to prepare for this, and a great closure to the first ever issue raised on the Microsoft/WSL repo:
041
Cheryl Babcock @blackasphodel.bsky.social · 17/05/2025
Saw this on @cyberciti.biz 's FB page...life of a web app tester lol
000
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 15/05/2025
Tor has announced Oniux, a new command-line tool for routing any Linux application securely through the Tor network for anonymized network connections.
bleepingcomputer.com
New Tor Oniux tool anonymizes any Linux app's network traffic
Tor has announced Oniux, a new command-line tool for routing any Linux application securely through the Tor network for anonymized network connections.
064
Cheryl Babcock @blackasphodel.bsky.social · 08/05/2025
Supply. Chain. Security. Can’t. Be. An. Afterthought
000
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 06/05/2025
Curl: We still have not seen a single valid security report done with AI help | Discussion
linkedin.com
#hackerone #curl | Daniel Stenberg | 184 comments
That's it. I've had it. I'm putting my foot down on this craziness. 1. Every reporter submitting security reports on #Hackerone for #curl now needs to answer this question: "Did you use an AI to find the problem or generate this submission?" (and if they do select it, they can expect a stream of proof of actual intelligence follow-up questions) 2. We now ban every reporter INSTANTLY who submits reports we deem AI slop. A threshold has been reached. We are effectively being DDoSed. If we could, we would charge them for this waste of our time. We still have not seen a single valid security report done with AI help. | 184 comments on LinkedIn
011
Cheryl Babcock @blackasphodel.bsky.social · 05/05/2025
Yeah let’s cut things when cyber attacks are becoming more sophisticated 😑
020
Cheryl Babcock @blackasphodel.bsky.social · 02/05/2025
That feeling when you go and look up the URL for documentation for YARA-L and the Google AI helpfully(?) gives you an example rule for detecting ‘minicats’
010
Reposted by Cheryl Babcock
Lesley Carhart @hacks4pancakes.com · 29/04/2025
Sign your names or you're a toaster, American cyber pros. www.eff.org/press/releases/eff-lead…
169141
Cheryl Babcock @blackasphodel.bsky.social · 27/04/2025
One of my SOC team sent me this: cybersecuritynews.com/microsoft-de... TLDR: the false positive means tons of private Adobe documents were sent to Any.Runs public sandbox for analysis. They are marking all those docs private to reduce spillage but people keep uploading....
cybersecuritynews.com
Microsoft Defender XDR False Positive Leads to Massive Data Leak of 1,700+ Sensitive Documents
ANY.RUN research identified a large-scale data leak event triggered by a false positive in Microsoft Defender XDR. The security platform incorrectly flagged benign files as malicious, leading to their...
011
Cheryl Babcock @blackasphodel.bsky.social · 22/04/2025
SANS has put out a checklist for developers to write more secure web apps. The biggest strength is a link to CWEs for each item to provide more detail. www.sans.org/cloud-securi...
sans.org
Security Checklist for Web Application | SANS Institute
SWAT Checklist from SANS Securing the App. The first step toward building a base of secure knowledge around web application security.
010
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 18/04/2025
Cisco has released security updates for a high-severity Webex vulnerability that allows unauthenticated attackers to gain client-side remote code execution using malicious meeting invite links.
bleepingcomputer.com
Cisco Webex bug lets hackers gain code execution via meeting links
Cisco has released security updates for a high-severity Webex vulnerability that allows unauthenticated attackers to gain client-side remote code execution using malicious meeting invite links.
056
Cheryl Babcock @blackasphodel.bsky.social · 16/04/2025
The CVE database is being shutdown tomorrow per Brian Krebs. This is asinine. Cybersecurity depends on it. The OSV (osv.dev/list) is an alternative but it's sponsored by Google so who knows when they will shut it down. www.linkedin.com/feed/update/...
linkedin.com
MITRE has announced that its funding for the Common Vulnerabilities and… | Brian Krebs | 332 comments
MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The ...
111
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 15/04/2025
Car rental giant Hertz Corporation warns it suffered a data breach after customer data for its Hertz, Thrifty, and Dollar brands was stolen in the Cleo zero-day data theft attacks.
bleepingcomputer.com
Hertz confirms customer info and drivers' licenses stolen in data breach
Car rental giant Hertz Corporation warns it suffered a data breach after customer data for its Hertz, Thrifty, and Dollar brands was stolen in the Cleo zero-day data theft attacks.
086
Cheryl Babcock @blackasphodel.bsky.social · 14/04/2025
This is one reason why poor developer supply chain security is one of my biggest pet peeves. TLDR: AI makes up package names, hackers take advantage of that and create malicious packages with those hallucinated names. You download, get pwned. www.theregister.com/AMP/2025/04/...
theregister.com
LLMs can't stop making up software dependencies and sabotaging everything
: Hallucinated package names fuel 'slopsquatting'
000
Cheryl Babcock @blackasphodel.bsky.social · 07/04/2025
000
Cheryl Babcock @blackasphodel.bsky.social · 02/04/2025
cyberinsider.com/security-fir...
cyberinsider.com
Security Firm APIsec Exposed 3TB of Sensitive Customer Data
A misconfigured Elasticsearch database belonging to APIsec.ai was discovered leaking over three terabytes of highly sensitive customer data.
000
Reposted by Cheryl Babcock
rstevens 👻💨 @rstevens.bsky.social · 31/03/2025
remember this well, inter-net users: tomorrow is april fool’s day and that shit wasn’t funny twenty-five years BEFORE stupid AI image generators existed
121027360
Cheryl Babcock @blackasphodel.bsky.social · 31/03/2025
Wordpress. Again. This is getting as bad as Adobe products back in the day :P
100
Cheryl Babcock @blackasphodel.bsky.social · 31/03/2025
Here's an amicus brief being filed to ensure Seniors get celiac-safe food in care homes. This is hugely important to anyone who has the disease, but also should be expanded to hospitals for ANY celiac. nationalceliac.org/wp-content/u...
nationalceliac.org
121
Cheryl Babcock @blackasphodel.bsky.social · 30/03/2025
Fighting back against AI crawlers: techcrunch.com/2025/03/27/o...
000
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 30/03/2025
GitHub CodeQL Actions Critical Supply Chain Vulnerability (CodeQLEAKED) Discussion
praetorian.com
CodeQLEAKED - Public Secrets Exposure Leads toSupply Chain Attack on GitHub CodeQL
An exposed GitHub token could have been used to launch a supply chain attack on GitHub CodeQL, resulting in source code exposure and repository tampering of CodeQL users.
011
Cheryl Babcock @blackasphodel.bsky.social · 30/03/2025
Nothing says happy Sunday morning like reporting a security bug to the software company that runs your doctor's patient portal system 😑 This one is so dumb too.
010
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 30/03/2025
Everyone knows all the apps on your phone Discussion
peabee.substack.com
Everyone knows all the apps on your phone
Until a few years ago, any app you installed on an Android device could see all other apps on your phone without your permission.
031
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 29/03/2025
OSS-SEC: Three bypasses of Ubuntu's unprivileged user namespace restrictions Discussion
seclists.org
oss-sec: Three bypasses of Ubuntu's unprivileged user namespace restrictions
021
Cheryl Babcock @blackasphodel.bsky.social · 29/03/2025
Assuming this is what @rachelonthebay was referring to the other day
000
Cheryl Babcock @blackasphodel.bsky.social · 29/03/2025
Me, playing Xenoblade Chronicles X for the first time: “Wow, that looks like the spaceship wreckage I’m supposed to find.” Me, moments after being stomped by a level 60 robot: “That was definitely NOT spaceship wreckage.”
120
Cheryl Babcock @blackasphodel.bsky.social · 29/03/2025
Who’s got a Chromebook? cloudisland.nz/@rmi/1142198...
cloudisland.nz
Rob Isaac (@rmi@cloudisland.nz)
Today Google bricked my Chromebook by force-installing a hidden extension that trains a machine vision model on the contents of my screen without my consent, making the whole machine too hot to touch,...
000
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 28/03/2025
A breach at Oracle Health impacts multiple US healthcare organizations and hospitals after a threat actor stole patient data from legacy servers. This is not related to the alleged Oracle Cloud breach. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Oracle Health breach compromises patient data at US hospitals
A breach at Oracle Health impacts multiple US healthcare organizations and hospitals after a threat actor stole patient data from legacy servers.
023
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 27/03/2025
Vivaldi has announced the integration of Proton VPN directly into its browser without requiring add-on downloads or plugin activations, allowing users to protect their data against 'Big Tech' surveillance for free.
bleepingcomputer.com
Vivaldi integrates Proton VPN into the browser to fight web tracking
Vivaldi has announced the integration of Proton VPN directly into its browser without requiring add-on downloads or plugin activations, allowing users to protect their data against 'Big Tech' surveillance for free.
274
Cheryl Babcock @blackasphodel.bsky.social · 23/03/2025
Oops
000
Cheryl Babcock @blackasphodel.bsky.social · 23/03/2025
The concern is what happens to your data if 23+Me goes under or sells out...Even if you aren't in CA worth checking out if you did the tests. oag.ca.gov/news/press-r...
oag.ca.gov
Attorney General Bonta Urgently Issues Consumer Alert for 23andMe Customers
Californians have the right to direct the company to delete their genetic data OAKLAND — California Attorney General Rob Bonta today issued a consumer alert to customers of 23andMe, a genetic testing ...
100
Reposted by Cheryl Babcock
Best of r/cybersecurity @cybersecurity.page · 20/03/2025
Decrypting Encrypted files from Akira Ransomware (Linux/ESXI variant 2024) using a bunch of GPUs -- "I recently helped a company recover their data from the Akira ransomware without paying the ransom. I’m sharing how I did it, along with the full source code."
reddit.com
Decrypting Encrypted files from Akira Ransomware (Linux/ESXI variant 2024) using a bunch of GPUs -- "I recently helped a company recover their data from the Akira ransomware without paying the ransom. I’m sharing how I did it, along with the full source code."
View post on Reddit.
082
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 17/03/2025
A critical remote code execution (RCE) vulnerability in Apache Tomcat tracked as CVE-2025-24813 is actively exploited in the wild, enabling attackers to take over servers with a simple PUT request.
bleepingcomputer.com
Critical RCE flaw in Apache Tomcat actively exploited in attacks
A critical remote code execution (RCE) vulnerability in Apache Tomcat tracked as CVE-2025-24813 is actively exploited in the wild, enabling attackers to take over servers with a simple PUT request.
044
Reposted by Cheryl Babcock
BleepingComputer @bleepingcomputer.com · 17/03/2025
A supply chain attack on the widely used 'tj-actions/changed-files' GitHub Action, used by 23,000 repositories, potentially allowed threat actors to steal CI/CD secrets from GitHub Actions build logs.
bleepingcomputer.com
Supply chain attack on popular GitHub Action exposes CI/CD secrets
A supply chain attack on the widely used 'tj-actions/changed-files' GitHub Action, used by 23,000 repositories, potentially allowed threat actors to steal CI/CD secrets from GitHub Actions build logs.
011
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 15/03/2025
Popular GitHub Action tj-actions/changed-files is compromised Discussion
semgrep.dev
Semgrep | 🚨 Popular GitHub Action tj-actions/changed-files is compromised
Popular GitHub Action tj-actions/changed-files has been compromised with a payload that appears to attempt to dump secrets, impacting thousands of CI pipelines.
001
Reposted by Cheryl Babcock
Hacker News Top Stories @hackernewsbot.bsky.social · 14/03/2025
Everything you say to your Echo will be sent to Amazon starting on March 28 Discussion
arstechnica.com
Everything you say to your Echo will be sent to Amazon starting on March 28
Amazon is killing a privacy feature to bolster Alexa+, the new subscription assistant.
022