Sign in

Fran Donoso

@francisck.com
498 followers 180 following 158 posts

I'm an infosec person who currently works as the CTO of a security services firm. Have done DevSecOps, Red Teaming, and reverse engineering. I reversed some of the tooling leaked by the Shadow Brokers and spoke about it publicly

PostsRepliesMedia
Reposted by Fran Donoso
Socket @socket.dev · 08/07/2026
🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow them, and 2FA-bypass tokens are starting to be phased out. Details → socket.dev/blog/npm-12 #nodejs
socket.dev
npm v12 Ships With Install Scripts Off by Default, Begins De...
npm v12 is generally available, turning install scripts off by default and beginning the deprecation of 2FA-bypass publishing tokens.
03913
Reposted by Fran Donoso
evacide @evacide.bsky.social · 04/03/2026
I'm reading a bunch of Coruna reports after dinner because I am a cool person who knows how to party. Of particular interest: not only does Coruna not work against iOS in lockdown mode, but if it even detects lockdown mode running, it bails. This is why I talk about lockdown mode so damn much.
213927
Reposted by Fran Donoso
Joseph Menn @joemenn.bsky.social · 24/02/2026
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
washingtonpost.com
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
616066
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 25/02/2026
OpenAI disrupted new malicious use of ChatGPT... mostly for romance scams and info-ops openai.com/index/disrup...
openai.com
Disrupting malicious uses of AI
Our latest threat report examines how malicious actors combine AI models with websites and social platforms—and what it means for detection and defense.
194
Reposted by Fran Donoso
Cynthia Brumfield @metacurity.com · 25/02/2026
Cisco said there are no workarounds for the vulnerability and urged customers to apply available patches immediately. The company also recommended reviewing system logs, validating controller integrity, and implementing additional hardening measures where possible. www.csoonline.com/article/4137...
csoonline.com
Five Eyes issue emergency directive on exploited Cisco SD-WAN zero-day
The Five Eyes cybersecurity agencies warn that a critical Cisco SD-WAN vulnerability is under active exploitation and should be patched immediately.
23532
Reposted by Fran Donoso
Kevin Beaumont @doublepulsar.com · 26/12/2025
patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds. Somebody posted an exploit on Christmas Day, Merry Christmas! doublepulsar.com/merry-christ...
doublepulsar.com
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
310245
Reposted by Fran Donoso
cje @cje.io · 20/12/2025
HARDEN YO' N8N - [CVSS 10.0 RCE] Remote Code Execution via Expression Injection m.cje.io/4qhl2JX cc: @networkchuck @danielmiessler @jhaddix
m.cje.io
Remote Code Execution via Expression Injection
### Impact n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users dur...
074
Fran Donoso @francisck.com · 01/11/2025
I may have gone overboard on the Halloween goodies this year #halloween
6 boxes of full sized candy bars, tiny stuffed Halloween themed toys, and hot wheels.
020
Fran Donoso @francisck.com · 14/09/2025
This report from @interseclab.bsky.social on how a Chinese company is exporting some of the capabilities of "The Great Wall of China" to other autocratic countries is INSANELY INTERESTING: interseclab.org/wp-content/u... *EVERY Page is worth reading* Some interesting tidbits in the thread
interseclab.org
131
Fran Donoso @francisck.com · 08/09/2025
Plex was hacked. It included usernames, emails, and hashed passwords. Change your passwords when you can,
010
Reposted by Fran Donoso
ESET Research @esetresearch.bsky.social · 26/08/2025
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/7
26543
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 05/08/2025
SentinelOne and Beazley Security have discovered a new Windows infostealer used in the wild named PXA Stealer, most likely the work of a Vietnamese-speaking cybercrime group. www.sentinelone.com/labs/ghost-i... labs.beazley.security/articles/gho...
0123
Fran Donoso @francisck.com · 04/08/2025
I mean I’ve been urging people to toss their sonicwall devices into a shredder for years now 🤷🏻‍♂️
051
Fran Donoso @francisck.com · 04/08/2025
Our team collaborated with our friends at @sentinellabs.bsky.social to identify and disrupt a PXA infostealer campaign that has an intricate and complex delivery chain: labs.beazley.security/articles/gho... Thanks for the fantastic collab SentinelLabs team!
labs.beazley.security
BSL - Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
032
Reposted by Fran Donoso
andy jabbour @andyjabbour.bsky.social · 24/07/2025
👀 Update from @threatintel.microsoft.com: 'our continued monitoring of exploitation activity by Storm-2603 leading to the deployment of Warlock ransomware' www.microsoft.com/en-us/securi... #Microsoft #SharePoint #cybersecurity #ransomware @gate15.bsky.social @ransomwaresommelier.com @ecrime.ch
microsoft.com
Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog
Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting vulnerabilities targeting internet-facing SharePoint servers. In addition, we have observed a...
043
Fran Donoso @francisck.com · 21/07/2025
We’re actively seeing this exploitation as well. Here is my team’s advisory on this vulnerability: labs.beazley.security/advisories/B... Is your have a publicly exposed SharePoint server, its probably already compromised so get ready to do some IR.
labs.beazley.security
SharePoint 0Day Vulnerability Under Active Exploitation (CVE-2025-53770)
000
Reposted by Fran Donoso
Glenn @ntkramer.bsky.social · 16/07/2025
🩸& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2 1/2
greynoise.io
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
1129
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 13/07/2025
Two high-severity patches are coming to Node.js on Tuesday nodejs.org/en/blog/vuln...
0134
Reposted by Fran Donoso
Joe Slowik @pylos.co · 11/07/2025
Context: labs.watchtowr.com/pre-auth-sql...
labs.watchtowr.com
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
Welcome back to yet another day in this parallel universe of security. This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no o...
172
Fran Donoso @francisck.com · 02/07/2025
Worth turning on if you have AT&T. Other carriers (like T-mobile) have similar programs.
000
Reposted by Fran Donoso
Whitney Merrill @wbm312.bsky.social · 26/06/2025
Need something positive to do in your life this week? If you don’t have a library card, go get one. Then learn about all the awesome things your local public library has to offer.
1215
Fran Donoso @francisck.com · 06/06/2025
This is related to ROP code exec on switch 2
000
Reposted by Fran Donoso
Zack Whittaker @zackwhittaker.com · 28/05/2025
New, by me: Data broker giant LexisNexis has revealed that its risk solutions unit (think "know your customer," risk assessing, due diligence, and law enforcement assistance) was breached, affecting the personal data and Social Security numbers of at least 364,000 people.
techcrunch.com
Data broker giant LexisNexis says breach exposed personal information of over 364,000 people | TechCrunch
The data collector said the stolen data includes Social Security numbers.
610758
Reposted by Fran Donoso
Kenn White @kennwhite.bsky.social · 27/05/2025
Just the tip of the iceberg from this roll-your-own security protocol. We're about to usher in a golden age of Valhalla-level AI pwnage, and it'll be riding on the coattails of badly designed agents. invariantlabs.ai/blog/mcp-git...
invariantlabs.ai
GitHub MCP Exploited: Accessing private repositories via MCP
We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariant's security ...
14120
Reposted by Fran Donoso
Wietze @wietzebeukema.nl · 24/03/2025
By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections. My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees. Here’s what I found and why it matters 👉 wietze.github.io/blog/bypassi...
13619
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 08/05/2025
Ubiquiti has released a security update for UniFi Protect Cameras to fix an RCE vulnerability with a severity score of 10/10 Oh boy... community.ui.com/releases/Sec...
13319
Reposted by Fran Donoso
Joseph Cox @josephcox.bsky.social · 04/05/2025
New from 404 Media: the Signal clone the Trump administration uses was just hacked. TeleMessage makes a modified version of Signal that archives messages for government agencies, Waltz used it. A hacker got some users' messages, group chats. Hugely significant breach www.404media.co/the-signal-c...
404media.co
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
15459942731
Reposted by Fran Donoso
The DFIR Report @thedfirreport.bsky.social · 23/03/2025
🧙 Want to join the team? 🧙 We’re on the hunt for volunteer DFIR analysts—with potential for paid opportunities! You’ll get a set of artifacts and a limited time to show us what you’ve got. 🔎 Follow us on socials—details drop soon!
0126
Fran Donoso @francisck.com · 15/03/2025
This is interesting. Good write up here: www.stepsecurity.io/blog/harden-... The commit that backdoors this is bash that executes something that is base64 encoded which is something that attempts to run a python script to scrape memory on the runner for secrets (see attached image) 🧵 1/2
stepsecurity.io
Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity
tj-actions/changed-files
144
Reposted by Fran Donoso
Mike Masnick @masnick.com · 04/03/2025
Wrote up something about Techdirt's recent coverage, and why (whether we like it or not) we need to be a "democracy blog" now, rather than just a "tech" blog (not that we've ever been just a tech blog). This story is *the* story and it impacts everything else. www.techdirt.com/2025/03/04/w...
techdirt.com
Why Techdirt Is Now A Democracy Blog (Whether We Like It Or Not)
While political reporters are still doing their view-from-nowhere “Democrats say this, Republicans say that” dance, tech and legal journalists have been watching an unfortunately recogn…
11040091275
Reposted by Fran Donoso
Andy Greenberg @agreenberg.bsky.social · 13/02/2025
China's Salt Typhoon hackers are still breaching telecom networks worldwide, including two in the US in Dec-Jan, says Recorded Future. Lately they're exploiting Cisco devices with unpatched 2023 bugs and seem undeterred by high profile exposure and sanctions. www.wired.com/story/chinas...
wired.com
China’s Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers
Despite high-profile attention and even US sanctions, the group hasn’t stopped or even slowed its operation, including the breach of two more US telecoms.
11256120
Reposted by Fran Donoso
Chad Loder @chadloder.dev · 11/02/2025
NEW: Security patch for Apple iPhones and iPads fixes an "actively exploited" flaw that allows law enforcement to unlock your device. Install it right now.
thehackernews.com
Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update
Apple released an emergency iOS update to fix CVE-2025-24200, a zero-day flaw exploited to bypass USB Restricted Mode on locked devices in sophisticat
5288187
Reposted by Fran Donoso
Joseph Menn @joemenn.bsky.social · 10/02/2025
The new book Chasing Shadows by Ron Deibert, founder and leader of Citizen Lab, reads like an adventure in telling how he wove security expertise, human rights activism and political savvy together to expose government malfeasance and save a generation of heroes from arrest and murder. Five stars.
3167
Fran Donoso @francisck.com · 06/02/2025
The last few weeks have made me proud to be a subscribed of @wired.com and have solidified by desire to remain subscribed for the foreseeable future. Great work keeping us informed about the craziness that is happening.
010
Fran Donoso @francisck.com · 28/01/2025
I’ve updated the cybersec feed to temporarily remove “social engineering” due to that language showing up in a recent Executive Order and causing the feed to fill up with non infosec stuff.
030
Fran Donoso @francisck.com · 20/12/2024
This was a great talk! Worth a watch for sure
020
Reposted by Fran Donoso
Hacking News @handle.invalid · 17/12/2024
QiAnXin's XLab found "Glutton," a new PHP backdoor likely from Winnti (APT41). Active since 2023, it targets multiple countries (China, US, etc.), using a modular design for stealth and potentially exploiting the cybercrime market.#GluttonBackdoor
131
Reposted by Fran Donoso
Nicolas Krassas @dinosn.bsky.social · 11/12/2024
Cleo Harmony, VLTrader, and LexiCom - RCE via Arbitrary File Write (CVE-2024-50623) labs.watchtowr.com/cleo-cve-202...
labs.watchtowr.com
Cleo Harmony, VLTrader, and LexiCom - RCE via Arbitrary File Write (CVE-2024-50623)
Note: this is a rapidly-drafted post on an evolving topic - we'll update the post with more details as we discover more about the situation. Hit that F5 key regularly for updates! We were having a ...
021
Reposted by Fran Donoso
Kathryn Tewson @kathryntewson.bsky.social · 29/11/2024
Pro tip for bad guys: do not, in your efforts to evade detection, give @nixonnixoff.bsky.social an extra strong motivation to hunt you down and peel the layers of your opsec back like an onion, because she will fucking do it www.therecord.com/news/waterlo...
therecord.com
Accused Kitchener hacker unmasked after threatening woman online
Kitchener-based hacker Alexander “Connor” Moucka was unmasked after making threats against a woman on the messaging app Telegram. Moucka threatened Allison Nixon, the chief research officer at Unit221...
502006406
Reposted by Fran Donoso
Matthew Kennedy @matthewkennedy.bsky.social · 05/12/2024
MSTIC is hiring! Current roles in US and AU. The Microsoft Threat Intelligence Center (MSTIC) is recruiting experienced nation-state threat hunters with highly honed threat intel analysis skills. MSTIC is responsible for delivering timely threat intelligence across our product & services teams.
411535
Reposted by Fran Donoso
TechCrunch @techcrunch.com · 02/12/2024
AWS launches an incident response service to combat cybersecurity threats
tcrn.ch
AWS launches an incident response service to combat cybersecurity threats
Companies often struggle with how to respond to cybersecurity incidents. According to one recent poll, only three out of five organizations have an incident response plan in place, and only around a third do regular drills to ensure that their plans…
6967
Fran Donoso @francisck.com · 26/11/2024
Interesting discussion in this thread.
000
Reposted by Fran Donoso
Michael Lynch @mtlynch.io · 26/11/2024
Time to update your 7-zip install to avoid this remote code execution vulnerability in ZSTD decompression www.zerodayinitiative.com/advisories/Z...
zerodayinitiative.com
ZDI-24-1532
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability
022
Reposted by Fran Donoso
CNN @cnn.com · 26/11/2024
A ransomware attack has disrupted a third-party software system that Starbucks uses to track and manage its baristas’ schedules, forcing the coffee chain to shift to manual mode to ensure its employees get paid properly, a Starbucks spokesperson said.
cnn.com
Starbucks forced to pay its baristas manually because of a ransomware attack on third-party software | CNN Business
A ransomware attack has disrupted a third-party software system that Starbucks uses to track and manage its baristas’ schedules, forcing the coffee chain to shift to manual mode to ensure its employee...
1729869
Fran Donoso @francisck.com · 22/11/2024
Great research from the Volexity team into how a Russian APT weaponized some WIFI access points close to their target to ultimately pivot into target networks. www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
030
Reposted by Fran Donoso
jinx69.bsky.social @jinx69.bsky.social · 22/11/2024
Get started with malware reverse engineering's Part 2 Series by @IntezerLabs #malware #infosec
intezer.com
Malware Reverse Engineering for Beginners - Part 2
As a reverse engineer, you need to understand how malware is packed, obfuscated, delivered, and executed on the endpoint.
051