Sign in

Nicolas Krassas

@dinosn.bsky.social
737 followers 1 following 2.9K posts

Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA t.co/NC1orlKrW3 Also at : @dinosn

PostsRepliesMedia
Nicolas Krassas @dinosn.bsky.social · 28/07/2025
28th July – Threat Intelligence Report research.checkpoint.com/2025/28th-ju...
research.checkpoint.com
28th July – Threat Intelligence Report - Check Point Research
For the latest discoveries in cyber research for the week of 28th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The US Energy Department, including its National Nucl...
010
Nicolas Krassas @dinosn.bsky.social · 27/06/2025
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted thehackernews.com/2025/06/move...
thehackernews.com
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted
Surge in scanning activity targets MOVEit Transfer systems, raising concerns over possible exploitation.
010
Nicolas Krassas @dinosn.bsky.social · 18/06/2025
BeyondTrust warns of pre-auth RCE in Remote Support software www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
BeyondTrust warns of pre-auth RCE in Remote Support software
BeyondTrust has released security updates to fix a high-severity flaw in its Remote Support (RS) and Privileged Remote Access (PRA) solutions that can let unauthenticated attackers gain remote code ex...
001
Nicolas Krassas @dinosn.bsky.social · 18/06/2025
Asana warns MCP AI feature exposed customer data to other orgs www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Asana warns MCP AI feature exposed customer data to other orgs
Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users a...
000
Nicolas Krassas @dinosn.bsky.social · 17/06/2025
Is b For Backdoor? Pre-Auth RCE Chain In Sitecore Experience Platform labs.watchtowr.com/is-b-for-bac...
labs.watchtowr.com
Is b For Backdoor? Pre-Auth RCE Chain In Sitecore Experience Platform
Welcome to June! We’re back—this time, we're exploring Sitecore’s Experience Platform (XP), demonstrating a pre-auth RCE chain that we reported to Sitecore in February 2025. We’ve spent a bit of time...
010
Nicolas Krassas @dinosn.bsky.social · 16/06/2025
Google’s $32 Billion Wiz Deal Draws DOJ Antitrust Scrutiny: Report www.securityweek.com/googles-32-b...
securityweek.com
Google’s $32 Billion Wiz Deal Draws DOJ Antitrust Scrutiny: Report
According to reports, the US Department of Justice will assess whether the deal would harm competition in the cybersecurity market.
101
Nicolas Krassas @dinosn.bsky.social · 16/06/2025
Washington Post's email system hacked, journalists' accounts compromised www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Washington Post's email system hacked, journalists' accounts compromised
Email accounts of several Washington Post journalists were compromised in a cyberattack believed to have been carried out by a foreign government.
001
Nicolas Krassas @dinosn.bsky.social · 16/06/2025
High-Severity Vulnerabilities Patched in Tenable Nessus Agent www.securityweek.com/high-severit...
securityweek.com
High-Severity Vulnerabilities Patched in Tenable Nessus Agent
Three high-severity Tenable Agent vulnerabilities could allow users to overwrite and delete files, or execute arbitrary code.
010
Nicolas Krassas @dinosn.bsky.social · 12/06/2025
CISA Releases Ten Industrial Control Systems Advisories www.cisa.gov/news-events/...
cisa.gov
CISA Releases Ten Industrial Control Systems Advisories | CISA
010
Nicolas Krassas @dinosn.bsky.social · 12/06/2025
GitLab patches high severity account takeover, missing auth issues www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
GitLab patches high severity account takeover, missing auth issues
GitLab has released security updates to address multiple vulnerabilities in the company's DevSecOps platform, including ones enabling attackers to take over accounts and inject malicious jobs in futur...
010
Nicolas Krassas @dinosn.bsky.social · 12/06/2025
'Major compromise' at NHS temping arm exposed gaping security holes go.theregister.com/feed/www.the...
go.theregister.com
'Major compromise' at NHS temping arm never disclosed
Exclusive: Incident responders suggested sweeping improvements following Active Directory database heist
010
Nicolas Krassas @dinosn.bsky.social · 10/06/2025
Ivanti Workspace Control hardcoded key flaws expose SQL credentials www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Ivanti Workspace Control hardcoded key flaws expose SQL credentials
Ivanti has released security updates to fix three high-severity hardcoded key vulnerabilities in the company's Workspace Control (IWC) solution.
000
Nicolas Krassas @dinosn.bsky.social · 10/06/2025
OpenAI working to fix ChatGPT outage affecting users worldwide www.bleepingcomputer.com/news/technol...
bleepingcomputer.com
OpenAI working to fix ChatGPT outage affecting users worldwide
OpenAI is working to fix an ongoing outage impacting ChatGPT users worldwide and preventing them from accessing the chatbot on the web or via mobile and desktop apps.
010
Nicolas Krassas @dinosn.bsky.social · 09/06/2025
Update: Dumping Entra Connect Sync Credentials posts.specterops.io/update-dumpi...
posts.specterops.io
Update: Dumping Entra Connect Sync Credentials
Recently, Microsoft changed the way the Entra Connect Connect Sync agent authenticates to Entra ID. These changes affect attacker tradecraft, as we can no longer export the sync account credentials…
010
Nicolas Krassas @dinosn.bsky.social · 08/06/2025
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads
A significant supply chain attack hit NPM after 15 popular Gluestack packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT).
000
Nicolas Krassas @dinosn.bsky.social · 05/06/2025
HMRC: Crooks broke into 100k accounts, stole £43M from British taxpayer in late 2024 go.theregister.com/feed/www.the...
go.theregister.com
Crims breached 100k UK tax accounts to steal £43M from HMRC
: It’s definitely not a cyberattack though! Really!
010
Nicolas Krassas @dinosn.bsky.social · 05/06/2025
US offers $10M for tips on state hackers tied to RedLine malware www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
US offers $10M for tips on state hackers tied to RedLine malware
The U.S. Department of State has announced a reward of up to $10 million for any information on government-sponsored hackers with ties to the RedLine infostealer malware operation and its suspected cr...
000
Nicolas Krassas @dinosn.bsky.social · 05/06/2025
Vodafone Germany Fined $51 Million Over Privacy, Security Failures www.securityweek.com/vodafone-ger...
securityweek.com
Vodafone Germany Fined $51 Million Over Privacy, Security Failures
Germany fined Vodafone $51 million for failing to protect user data from partners and unauthorized third-parties.
000
Nicolas Krassas @dinosn.bsky.social · 04/06/2025
Exclusive: Hackers Leak 86 Million AT&T Records with Decrypted SSNs hackread.com/hackers-leak...
hackread.com
Exclusive: Hackers Leak 86 Million AT&T Records with Decrypted SSNs
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
000
Nicolas Krassas @dinosn.bsky.social · 04/06/2025
Sleeper Sound: LayerX Uncovers Malicious “Sleeper” Sound Management Extensions with Nearly 1.5 Million Users Worldwide layerxsecurity.com/blog/sleeper...
layerxsecurity.com
Sleeper Sound: LayerX Uncovers Malicious “Sleeper” Sound Management Extensions with Nearly 1.5 Million Users Worldwide - LayerX
LayerX has unearthed network of malicious “sleeper agent” extensions that appear to serve as infrastructure for future malicious activity, currently installed on nearly 1.5 million users worldwide.   ...
000
Nicolas Krassas @dinosn.bsky.social · 03/06/2025
Vulnerability leaks Vanta customer info www.scworld.com/brief/vulner...
scworld.com
Vulnerability leaks Vanta customer info
TechCrunch reports that leading trust management platform Vanta had private information from less than 4% of its over 10,000 clients inadvertently exposed to other customers due to a product code chan...
000
Nicolas Krassas @dinosn.bsky.social · 30/05/2025
Police takes down AVCheck site used by cybercriminals to scan malware www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Police takes down AVCheck site used by cybercriminals to scan malware
An international law enforcement operation has taken down AVCheck, a service used by cybercriminals to test whether their malware is detected by commercial antivirus software before deploying it in th...
001
Nicolas Krassas @dinosn.bsky.social · 30/05/2025
Threat Actor Claims TikTok Breach, Puts 428 Million Records Up for Sale hackread.com/threat-actor...
hackread.com
Threat Actor Claims TikTok Breach, Puts 428 Million Records Up for Sale
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
000
Nicolas Krassas @dinosn.bsky.social · 27/05/2025
Adidas confirms criminals stole data from customer service provider go.theregister.com/feed/www.the...
go.theregister.com
Adidas confirms data swiped from customer service provider
: Hackers take personal data bytes from the brand with three stripes
001
Nicolas Krassas @dinosn.bsky.social · 27/05/2025
Alleged AT&T breach compromises 31M records www.scworld.com/brief/allege...
scworld.com
Alleged AT&T breach compromises 31M records
AT&T had a database purportedly including 31 million sensitive user records exposed on a popular hacking forum, reports Cybernews.
000
Nicolas Krassas @dinosn.bsky.social · 21/05/2025
M&S warns of £300M dent in profits from cyberattack go.theregister.com/feed/www.the...
go.theregister.com
M&S warns of £300M dent in profits from cyberattack
: Downtime stings retailer, with technical recovery costs coming at a later date
000
Nicolas Krassas @dinosn.bsky.social · 21/05/2025
SK Telecom says malware breach lasted 3 years, impacted 27 million numbers www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
SK Telecom says malware breach lasted 3 years, impacted 27 million numbers
SK Telecom says that a recently disclosed cybersecurity incident in April, first occurred all the way back in 2022, ultimately exposing the USIM data of 27 million subscribers.
000
Nicolas Krassas @dinosn.bsky.social · 17/05/2025
Coinbase Extorted, Offers $20M for Info on Its Hackers www.darkreading.com/cyberattacks...
darkreading.com
Coinbase Extorted, Offers $20M for Info on Its Hackers
Coinbase is going Liam Neeson on its attackers, potentially setting a new precedent for incident response in the wake of crypto- and blockchain-targeting cyberattacks.
000
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
The Epoch Times purportedly hacked, 32M records exposed www.scworld.com/brief/the-ep...
scworld.com
The Epoch Times purportedly hacked, 32M records exposed
International far-right media outlet The Epoch Times was reported by SafetyDetectives cybersecurity experts to have a database of 32 million records allegedly stolen from its systems leaked online, ac...
010
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
Broadcom employee data stolen by ransomware crooks following hit on payroll provider go.theregister.com/feed/www.the...
go.theregister.com
Broadcom data stolen in payroll provider ransomware raid
EXCLUSIVE: The tech biz was in the process of dropping the payroll company as it learned of the breach
021
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
Data broker protection rule quietly withdrawn by CFPB www.malwarebytes.com/blog/news/20...
malwarebytes.com
Data broker protection rule quietly withdrawn by CFPB
The CFPB has decided to withdraw a 2024 rule that was aimed at limiting the sale of Americans’ personal information by data brokers.
000
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
The Good, the Bad and the Ugly in Cybersecurity – Week 20 www.sentinelone.com/blog/the-goo...
sentinelone.com
The Good, the Bad and the Ugly in Cybersecurity – Week 20
Police disrupt cybercrime ops, malicious NPM package hides malware via Unicode, and spies leverage zero-day in enterprise messaging app.
000
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
CISA tags recently patched Chrome bug as actively exploited www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
CISA tags recently patched Chrome bug as actively exploited
On Thursday, CISA warned U.S. federal agencies to secure their systems against ongoing attacks exploiting a high-severity vulnerability in the Chrome web browser.
000
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
Scammers are deepfaking voices of senior US government officials, warns FBI go.theregister.com/feed/www.the...
go.theregister.com
Deepfake voices of senior US officials used in scams: FBI
: They're smishing, they're vishing
000
Nicolas Krassas @dinosn.bsky.social · 16/05/2025
Commit Stomping blog.zsec.uk/commit-stomp...
blog.zsec.uk
Commit Stomping
Manipulating Git Histories to Obscure the Truth
000
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428) labs.watchtowr.com/expression-p...
labs.watchtowr.com
Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
Keeping your ears to the ground and eyes wide open for the latest vulnerability news at watchTowr is a given. Despite rummaging through enterprise code looking for 0days on a daily basis, our interest...
000
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
Coinbase extorted for $20M. Support staff bribed. Customers scammed. One hell of a breach disclosure… go.theregister.com/feed/www.the...
go.theregister.com
Hackers scam Coinbase users and ransom data for $20M
: One expert tells us: 'It is the most unique breach disclosure I've ever seen'
062
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
CISA Releases Twenty-Two Industrial Control Systems Advisories www.cisa.gov/news-events/...
cisa.gov
CISA Releases Twenty-Two Industrial Control Systems Advisories | CISA
000
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails thehackernews.com/2025/05/coin...
thehackernews.com
Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
Insiders bribed at Coinbase leaked customer data (<1% of users), triggering $20M extortion; funds safe.
000
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers thehackernews.com/2025/05/russ...
thehackernews.com
Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers
APT28 exploited MDaemon zero-day CVE-2024-11182 in targeted webmail hacks across 10+ nations.
000
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
Kosovo authorities extradited admin of the cybercrime marketplace BlackDB.cc securityaffairs.com/177870/cyber...
blackdb.cc
000
Nicolas Krassas @dinosn.bsky.social · 15/05/2025
New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy thehackernews.com/2025/05/new-...
thehackernews.com
New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy
Chrome flaw CVE-2025-4664 enables cross-origin data leaks; active exploit confirmed; update to 136.0.7103.113.
002
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
Microsoft Restructures: 6,000 Jobs Cut Amid AI Focus securityonline.info/microsoft-re...
securityonline.info
Microsoft Restructures: 6,000 Jobs Cut Amid AI Focus
Microsoft announces a 3% workforce reduction (around 6,000 jobs) as part of a strategic restructuring to align with its AI-driven market strategy.
001
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
The cryptography behind passkeys blog.trailofbits.com/2025/05/14/t...
blog.trailofbits.com
The cryptography behind passkeys
This post will examine the cryptography behind passkeys, the guarantees they do or do not give, and interesting cryptographic things you can do with them, such as generating cryptographic keys and sto...
000
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
Steel giant Nucor Corporation facing disruptions after cyberattack www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Steel giant Nucor Corporation facing disruptions after cyberattack
A cybersecurity incident on Nucor Corporation's systems forced the company to take offline parts of its networks and implement containment measures.
010
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
North Korean Hackers Stole $88M by Posing as US Tech Workers hackread.com/north-korean...
hackread.com
North Korean Hackers Stole $88M by Posing as US Tech Workers
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
000
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
Analyzing the Attack Surface of Ivanti's DSM code-white.com/blog/ivanti-...
code-white.com
CODE WHITE | Analyzing the Attack Surface of Ivanti's DSM
Ivanti's Desktop & Server Management (DSM) product is an old acquaintance that we have encountered in numerous red team and internal assessments. The main purpose of the product is the centralized dis...
000
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
Microsoft to Lay Off About 3% of Its Workforce www.securityweek.com/microsoft-to...
securityweek.com
Microsoft to Lay Off About 3% of Its Workforce
Microsoft began laying off nearly 3% of its entire workforce Tuesday, its largest mass layoff in more than two years.
000
Nicolas Krassas @dinosn.bsky.social · 14/05/2025
Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks securityonline.info/siemens-rugg...
securityonline.info
Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
Siemens RUGGEDCOM devices face CVSS 9.9 command injection flaws. Authenticated users can execute root-level code via web tools. Patch to V2.16.5 now.
010
Nicolas Krassas @dinosn.bsky.social · 13/05/2025
Ivanti warns of critical Neurons for ITSM auth bypass flaw www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Ivanti warns of critical Neurons for ITSM auth bypass flaw
​Ivanti has released security updates for its Neurons for ITSM IT service management solution that mitigate a critical authentication bypass vulnerability.
000