Sign in

Farhan Nearhan ❼

@farhanible.bsky.social
243 followers 230 following 54 posts

Former CISO | Now Advisory/Fractional CISO | NYC | Founder ovrsr.com | A very personal account | Been to @arbys once

PostsRepliesMedia
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 06/09/2026
Last week, MikroTik users were complaining about new "ops" admin accounts on their routers: www.reddit.com/r/mikrotik/c... CERT-LV warned of attacks: cert.gov.lv/lv/2026/09/u... And CERT-PL later confirmed two zero-days: cert.pl/en/posts/202... Patches are out now: mikrotik.com/supportsec/s...
1135
Reposted by Farhan Nearhan ❼
Bluesky @bsky.app · 17/08/2026
We apologize for yesterday’s service problems. Bluesky experienced a DDoS attack—a flood of junk traffic meant to knock servers offline—over a period of 24 hours. We have upgraded our defenses in response, and we continue to monitor the situation. Follow @status.bsky.app for any updates.
689190882740
Reposted by Farhan Nearhan ❼
404 Media @404media.co · 14/08/2026
A person representing themselves in a Connecticut court hid a series of instructions designed to manipulate artificial intelligence in an official court filing. As the judge pointed out, court docs do not get processed through AI. @jasonkoebler.bsky.social reports: www.404media.co/person-hides...
616639
Reposted by Farhan Nearhan ❼
404 Media @404media.co · 26/07/2026
“Print books from the pre-LLM era are structurally guaranteed to be free of this contamination." www.404media.co/ai-companies...
404media.co
AI Companies Are Buying Tons of Old Books Because They're Free of AI Slop
ISBNdb, a company that sources printed books for AI companies to turn into training data, tells clients “the optics problem is real.”
819494
Reposted by Farhan Nearhan ❼
The Citizen Lab @citizenlab.ca · 03/07/2026
1/ NEW REPORT: Former Member of the European Parliament Stelios Kouloglou was repeatedly hacked with NSO Group’s Pegasus spyware while serving on the EU committee investigating Pegasus and other spyware abuses in Europe. Full report: citizenlab.ca/research/mem...
citizenlab.ca
Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Eur...
13121
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 02/07/2026
Threat actors are mass-scanning the internet for misconfigured LLM backend servers. Mass-reconnaissance campaigns have been spotted targeting Ollama, LiteLLM, Langserv, and OpenClaw infrastructure labs.zenity.io/p/scanning-f...
labs.zenity.io
Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild
056
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 02/07/2026
Vint Cerf, the co-developer of the TCP/IP standard, is stepping down from his role of chief internet evangelist at Google and retiring at the age of 83 techcrunch.com/2026/06/30/t...
techcrunch.com
The 'Father of the Internet' is finally retiring | TechCrunch
Vinton Cerf, one of the creators of the protocols underlying the internet, will step down as Google's chief internet evangelist next week.
0218
Reposted by Farhan Nearhan ❼
Lukasz Olejnik @lukaszolejnik.bsky.social · 15/06/2026
Anthropic reportedly got 90 minutes to cut access to one of the strongest AI systems on the market. OpenAI models can perform similar tasks, but OpenAI did not get the shutdown order. The European Commission is monitoring the situation and its impact on Europe.
2106
Reposted by Farhan Nearhan ❼
Lukasz Olejnik @lukaszolejnik.bsky.social · 15/06/2026
Public CVEs are becoming raw material for reproducible vulnerability infrastructure / factories. Agentic systems can now produce proof of concepts and exploits from security advisories, diffs, reports. arxiv.org/pdf/2602.07287 arxiv.org/pdf/2602.14345 arxiv.org/pdf/2602.03012
072
Reposted by Farhan Nearhan ❼
John Scott-Railton @jsrailton.bsky.social · 08/06/2026
BREAKING: NSO Group caught trying to hack across #WhatsApp. Again! Defying 🇺🇸US Courts. WhatsApp disrupted the Pegasus campaign & says it violates US Federal injunction they won against NSO. Asks Federal judge to hold NSO Group in contempt. Many implications... 1/ about.fb.com/news/2026/06...
7279130
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 07/06/2026
Microsoft has taken down 73 of its own GitHub source code repositories after they were infected with a worm. The repos appear to have been infected with Miasma, a variant of the Shai-Hulud worm. opensourcemalware.com/blog/miasma-...
opensourcemalware.com
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
GitHub disabled 73 Microsoft repositories across four of its GitHub organizations — the entire Azure Functions org, the whole Durable Task family, and a row of AI sample apps — in a 105-second sweep o...
15120
Reposted by Farhan Nearhan ❼
404 Media @404media.co · 06/06/2026
The news shows the extreme risk associated with offloading support or critical functions to an AI chatbot. www.404media.co/hackers-simp...
404media.co
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
The exploit shows the extreme risk of offloading technical support to AI.
519068
Reposted by Farhan Nearhan ❼
Zack Whittaker @zackwhittaker.com · 30/05/2026
It's rare to see near-universal condemnation from the infosec community, but Microsoft threatening a security researcher has done it. Notable exceptions: When Keeper Security sued Ars Technica over a story (2017); NSA's mass surveillance uncovered (2013); and FBI demanding an Apple backdoor (2016).
techcrunch.com
Microsoft under fire for threatening security researcher with criminal investigation | TechCrunch
A public spat between Microsoft and an independent security researcher reopens a long-running debate over who is responsible for securing software.
37331
Reposted by Farhan Nearhan ❼
Dare Obasanjo @carnage4life.bsky.social · 24/05/2026
I think this is a key insight about the AI psychosis we are seeing exhibited by big tech CEOs. The further you are away from the work, the more you assume it’s trivial for Claude or ChatGPT to replace the worker.
23555118
Reposted by Farhan Nearhan ❼
Zack Whittaker @zackwhittaker.com · 23/05/2026
New, by me at this.weekinsecurity.com: Health wearable giant Oura says it has received government demands for users' information (because Oura does not use end-to-end encryption). Will Oura say how often it gets demands for user data, and how often Oura hands over users' data to authorities?
this.weekinsecurity.com
Oura says it gets government demands for user data. Will it share how many?
Oura users' data is not end-to-end encrypted and can be handed to the government. Will the wearable tech maker say how often it turns over data?
20287154
Reposted by Farhan Nearhan ❼
emptywheel @emptywheel.bsky.social · 23/05/2026
For the second time we know of, Kash Patel's FBI got a warning about a dangerous Nazi sympathizer (the other is the Evergreen shooter) but did not prevent an attack. This time 3 people were murdered. www.nytimes.com/2026/05/21/u...
The F.B.I. also was alerted to concerns about one of the teens before the shooting and had an open inquiry within its threat monitoring system, according to internal agency communications seen by The New York Times.

Local law enforcement agencies regularly flag possible domestic terrorist activity to the F.B.I. by submitting reports to the bureau’s Guardian system, where agents assess whether the federal government needs to open its own investigation.

Editors’ Picks

Luminous New Historical Fiction

Can I Ask My Parents to Put Away Their Phones When They Watch My Children?

Everything We Know About ‘The White Lotus’ Season 4
When the F.B.I. does investigate a report, it has 30 days to determine whether the incident could be considered terrorist activity and then update local law enforcement partners about its decision.

It is not clear what local law enforcement shared with the F.B.I. or whether it prompted the bureau to investigate. The F.B.I. did not respond to a request for comment.
571943904
Reposted by Farhan Nearhan ❼
404 Media @404media.co · 21/05/2026
After teen girls were targeted by AI-generated CSAM, Radnor Township High School in Pennsylvania has become a case study in how schools and police around the country grapple with how to response to deepfake crimes involving children. @samleecole.bsky.social reports. www.404media.co/radnor-high-...
12497177
Reposted by Farhan Nearhan ❼
Keith @mosheroperandi.bsky.social · 22/05/2026
We need more walkable, mixed-use datacenters. Like community gardens, people should be able to experience the joy and satisfaction of cultivating their own hardware. Big Cloud has alienated the connection people felt with their computers. Kids should know what it's like to swear at rack mount rails.
27830136
Reposted by Farhan Nearhan ❼
Proton @proton.me · 21/05/2026
Google I/O for those that didn't watch.
A meme from the movie "They Live" where the main character, John Nada, finds glasses that allow him to see the true nature of the world. In the first scene the glasses are off, and he looks at a Google exec by a board which says "Google Search is AI Search". He then puts the glasses on and the board changes to "We will enshittify everything you love, then we'll do it to all the things you hate, too"
9471114
Reposted by Farhan Nearhan ❼
Gillian Branstetter @gbbranstetter.bsky.social · 20/05/2026
Lmao
Chart showing share of federal filings by pro se litigants spiking from 10-12% to 17% upon the release of ChatGPT
703965660
Reposted by Farhan Nearhan ❼
Bees 🎃🍄🍂 @voiceofkosh.bsky.social · 19/05/2026
So, the cyber security arm of the Department of Homeland Security left passwords in plain text, in a csv file, out in the open, on a public repository called "Private-CISA". 😂 And somehow this article gets funnier the further you read. gizmodo.com/the-worst-le...
gizmodo.com
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
Passwords were stored as plain text in a public GitHub repository.
3349
Reposted by Farhan Nearhan ❼
Joseph Menn @joemenn.bsky.social · 18/05/2026
A giant of cyber security has passed. www.nytimes.com/2026/05/17/o...
nytimes.com
Peter G. Neumann, Who Warned of Computer Security Risks, Dies at 93
44021
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 19/05/2026
Microsoft takes down Signing Cloud, a service that sold digital signing certificates obtained through fake accounts on Microsoft's Artifact Signing service This was broadly used by Rhysida and other ransomware groups blogs.microsoft.com/on-the-issue...
073
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 14/05/2026
More of those AI-found vulnerabilities: -Tomcat unauth RCE: www.striga.ai/research/tom... -18yo RCE in NGINX: depthfirst.com/research/ngi... They're everywhere now.
striga.ai
Fail Open, Game Over: Turning a One-Line Tomcat Fix into Unauthenticated RCE
Striga uncovered a fail-open regression in Apache Tomcat's cluster encryption that turns a one-line code change into unauthenticated Remote Code Execution.
097
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 10/05/2026
The FreeBSD team has patched a remote code execution in its operating system that impacts all versions released since 2005 Tracked as CVE-2026-42511, the vulnerability resides in the FreeBSD DHCP client and is extremely easy to exploit aisle.com/blog/aisle-d...
03919
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 09/05/2026
This push for age-verification and VPN bans is driven by social media company lobby groups. The goal is to prevent people from hiding their online activity and then selling that behavioral data. Buying something online without being algorithmically overpriced is the end goal, not tracking your pr0n
47535
Reposted by Farhan Nearhan ❼
Marcus Hutchins @malwaretech.com · 30/04/2026
Listening to infosec people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.
28756180
Reposted by Farhan Nearhan ❼
Eliot Higgins @eliothiggins.bsky.social · 25/04/2026
Who could have imagined blowing up their leadership would have resulted in this?
911359185
Reposted by Farhan Nearhan ❼
Luca @lucagalletti.bsky.social · 20/04/2026
机器人马拉松高燃补给 "Robot Marathon High-Fuel Supply" The ice is to cool the batteries. Excessive crotch spray though. IG: Shanghai Daily
13419
Reposted by Farhan Nearhan ❼
Dare Obasanjo @carnage4life.bsky.social · 21/04/2026
The biggest tell that you’re reading AI-generated writing these days isn’t em dashes but instead the “it’s not X, it’s Y” sentence structure. Whenever I spot it, my first instinct is to wonder if the author even read the document or if I’m the first human to read their ChatGPT-authored masterpiece?
techcrunch.com
It's not just one thing — it's another thing | TechCrunch
This sentence construction ("It's not just this — it's that") has become so common in AI-generated writing that it's no longer just a clue that a piece of writing may be synthetic — it's almost a guar...
138910
Reposted by Farhan Nearhan ❼
derek guy @dieworkwear.bsky.social · 17/04/2026
this morning, mamdani’s team got in touch with me to float a new tax proposal: if your net worth exceeds $5 million and you dress badly, you’ll be hit with a 10% annual levy for “visual pollution.” i would be in charge of deciding if the outfits are bad.
453176801349
Reposted by Farhan Nearhan ❼
404 Media @404media.co · 13/04/2026
WebinarTV scraped and shared 12 steps-based anonymous meetings for people recovering from addiction and other private support groups.
404media.co
WebinarTV Secretly Scraped Zoom Meetings of Anonymous Recovery Programs
WebinarTV scraped and shared 12 steps-based anonymous meetings for people recovering from addiction and other private support groups.
16217
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 09/04/2026
Chrome 147 is rolling out with: -Vertical tabs -Device Bound Session Credentials (cookie protections) turned on -A way to report scam sites to Safe Browsing -56 security fixes
1113
Reposted by Farhan Nearhan ❼
Catalin Cimpanu @campuscodi.risky.biz · 09/04/2026
Socket Security has tracked North Korean-linked malware and malicious packages on five distinct package portals, on npm, PyPI, Rust Crates, Go Packages, and PHP's Packagist socket.dev/blog/contagi...
193
Reposted by Farhan Nearhan ❼
Lina Mounzer @warghetti.bsky.social · 08/04/2026
Massacre upon massacre in Beirut in the last hour. AUBMC announced a “code disaster.” Over 100 airstrikes in 10 minutes across the country. One hit right behind my house. Sirens ambulances & the smell of sulphur. The city is in total chaos the people in complete panic
3935281800
Reposted by Farhan Nearhan ❼
The Citizen Lab @citizenlab.ca · 08/04/2026
Our submission to the UN Working Group regarding the use of tech in the operations and activities of mercenaries, mercenary-related actors and private military and security companies, warns that states should stop relying on the private sector for digital operations. citizenlab.ca/wp-content/u...
citizenlab.ca
0155
Reposted by Farhan Nearhan ❼
Elizabeth N. Saunders @profsaunders.bsky.social · 06/04/2026
Don't think I've ever been as terrified in all the Trump security crises. As @pkrugman.bsky.social said, "It’s the most astonishing, awful thing that I’ve ever seen, and we’ve all seen a lot of awful things." Mainly as cope, and to teach it, I keep asking why. 1/ open.substack.com/pub/paulkrug...
open.substack.com
Living in Hell
War crimes coming: A horrifying update
271096402
Reposted by Farhan Nearhan ❼
Katrina Miller @katrinamillerphd.bsky.social · 07/04/2026
"It’s a bright spot on the moon,” CSA astronaut Jeremy Hansen said, his voice breaking up, “and we would like to call it Carroll.” The crew all shared a hug after. www.nytimes.com/2026/04/06/s...
nytimes.com
Astronauts Dedicate Moon Crater to Carroll Wiseman, Wife of NASA Commander
283263509
Reposted by Farhan Nearhan ❼
Dan "Mr. Bones and Me" Greene @dmgreene.bsky.social · 06/04/2026
You can safely ignore anyone using the word "tankie" to describe anything besides support for Stalin
2101
Reposted by Farhan Nearhan ❼
🐔 Brian Bucklew 🐔 ₑͤ>∿<ₑͤ ∞🌮 @unormal.bsky.social · 05/04/2026
every day of the war costs us a dozen rural hospitals
4589
Reposted by Farhan Nearhan ❼
The Times Of America @timesofamerica.bsky.social · 05/04/2026
The American bombing of Iranian girls’ middle schools has been messy. But it‘s also created an opportunity for genuine educational reform. —Today in @washingtonpost.com
238742
Reposted by Farhan Nearhan ❼
The Times Of America @timesofamerica.bsky.social · 05/04/2026
Live children grow up to be soldiers, and provide aid and comfort to parents who are soldiers. That’s why elementary schools are legitimate military targets. Today by Pete Hegseth in the @nytimes.com
1542949
Reposted by Farhan Nearhan ❼
Andrew Lawrence @ndrew.bsky.social · 02/04/2026
unlike education, health care, child care or parental leave which is woke bull shit
353368576
Reposted by Farhan Nearhan ❼
Jordan @cocktailchem.bsky.social · 02/04/2026
A tweet:

[inside washing machine]

duvet cover: climb in my brothers

every single piece of clothing: we shall build a new life in the big sock
17510
Reposted by Farhan Nearhan ❼
Iron Spike @ironspike.bsky.social · 01/04/2026
Shout-out to every other Gen Xer that was holding their breath the entire time for the first five mintues of the launch For r e a s o n s
16119291087
Reposted by Farhan Nearhan ❼
Press Gazette @pressgazette.co.uk · 30/03/2026
A Press Gazette investigation into parasite SEO firm Clickout Media has been removed from Google’s search index after a bogus legal complaint under the US Digital Millennium Copyright Act. A Search Engine Land follow-up report has also been removed from Google pressgazette.co.uk/news/parasit...
pressgazette.co.uk
Press Gazette exposé of parasite SEO firm removed from Google results
Press Gazette reporting on parasite SEO company Clickout Media removed from Google search results after anonymous complaint.
02116
Reposted by Farhan Nearhan ❼
mayor of clown town 🤠✨ @linguangst.bsky.social · 29/03/2026
trust & safety status quo, per @julietshen.bsky.social and @cassidyjames.com at #ATmosphereConf: kinda broken! (to say the least)
two presenters in front of a slide, titled "Status quo: T&S is kind of broken"

reasons include unaffordable vendor tools; platforms reinventing basic functionality; generative AI accelerating harms; openness being taboo
1113