Sign in

Fran Donoso

@francisck.com
500 followers 180 following 158 posts

I'm an infosec person who currently works as the CTO of a security services firm. Have done DevSecOps, Red Teaming, and reverse engineering. I reversed some of the tooling leaked by the Shadow Brokers and spoke about it publicly

PostsRepliesMedia
Reposted by Fran Donoso
Socket @socket.dev · 08/07/2026
🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow them, and 2FA-bypass tokens are starting to be phased out. Details → socket.dev/blog/npm-12 #nodejs
socket.dev
npm v12 Ships With Install Scripts Off by Default, Begins De...
npm v12 is generally available, turning install scripts off by default and beginning the deprecation of 2FA-bypass publishing tokens.
03913
Fran Donoso @francisck.com · 01/04/2026
I’m so sorry to hear that, Yael. Your work was outstanding and some of my favorite content. Consumer Reports is worse off without you on the team 😢
011
Reposted by Fran Donoso
evacide @evacide.bsky.social · 04/03/2026
I'm reading a bunch of Coruna reports after dinner because I am a cool person who knows how to party. Of particular interest: not only does Coruna not work against iOS in lockdown mode, but if it even detects lockdown mode running, it bails. This is why I talk about lockdown mode so damn much.
213927
Reposted by Fran Donoso
Joseph Menn @joemenn.bsky.social · 24/02/2026
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
washingtonpost.com
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
616066
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 25/02/2026
OpenAI disrupted new malicious use of ChatGPT... mostly for romance scams and info-ops openai.com/index/disrup...
openai.com
Disrupting malicious uses of AI
Our latest threat report examines how malicious actors combine AI models with websites and social platforms—and what it means for detection and defense.
194
Reposted by Fran Donoso
Cynthia Brumfield @metacurity.com · 25/02/2026
Cisco said there are no workarounds for the vulnerability and urged customers to apply available patches immediately. The company also recommended reviewing system logs, validating controller integrity, and implementing additional hardening measures where possible. www.csoonline.com/article/4137...
csoonline.com
Five Eyes issue emergency directive on exploited Cisco SD-WAN zero-day
The Five Eyes cybersecurity agencies warn that a critical Cisco SD-WAN vulnerability is under active exploitation and should be patched immediately.
23532
Fran Donoso @francisck.com · 04/02/2026
I’m so sorry to hear that, Joe. You’re one of the greats and it breaks my heart to see that you were laid off. Looking forward to seeing where you end up and where I need to subscribe next.
000
Reposted by Fran Donoso
Kevin Beaumont @doublepulsar.com · 26/12/2025
patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds. Somebody posted an exploit on Christmas Day, Merry Christmas! doublepulsar.com/merry-christ...
doublepulsar.com
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
310245
Fran Donoso @francisck.com · 26/12/2025
This channel started to get recommended to me recently. I watched a bit of one video, realized it’s AI generated, and then just removed the channel from my recommendations. Pretty crummy quality, and whoever is making this is just pumping a ton of content out.
000
Reposted by Fran Donoso
cje @cje.io · 20/12/2025
HARDEN YO' N8N - [CVSS 10.0 RCE] Remote Code Execution via Expression Injection m.cje.io/4qhl2JX cc: @networkchuck @danielmiessler @jhaddix
m.cje.io
Remote Code Execution via Expression Injection
### Impact n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users dur...
074
Fran Donoso @francisck.com · 14/11/2025
Yep, that also tracks with the data we have (owned by a large cyber insurer). Akira is by far the most active and impactful for our clients. Responsible for most incidents in Q3 for sure.
031
Fran Donoso @francisck.com · 01/11/2025
I may have gone overboard on the Halloween goodies this year #halloween
6 boxes of full sized candy bars, tiny stuffed Halloween themed toys, and hot wheels.
020
Fran Donoso @francisck.com · 15/10/2025
This is one of my favorite sci-fi books and my fav Andy Weir book! I was cautiously excited when I saw they were making a movie
010
Fran Donoso @francisck.com · 05/10/2025
Yooooo idk what you’re talking about. That stuffed animal looks awesome!
010
Fran Donoso @francisck.com · 04/10/2025
I’ve been reading further and it seems like it was a third party provider who was like a business process outsourcer. This is similar to the recent Air France and stellantis breaches but no idea if they’re related.
000
Fran Donoso @francisck.com · 04/10/2025
I think this is probably Salesforce compromised via Salesloft drift? It aligns with the salesloft drift stuff we’ve seen. Most of the other parties were also using SalesForce for support ticketing and had salesforce auth tokens stolen from drift.
120
Fran Donoso @francisck.com · 14/09/2025
I encourage cybersecurity professionals to read this report to understand the type of capabilities that can be deployed against citizens at scale by autocratic regimes. Organizations designing products that support privacy should understand these capabilities and design to protect users from them.
010
Fran Donoso @francisck.com · 14/09/2025
"The requirements for future development also mention adding the ability to check which users are connected to specific mobile base stations in order to support location triangulation through these stations and detect when a large number of people congregate in a particular area"
100
Fran Donoso @francisck.com · 14/09/2025
" It uses the in-path injection capability in TSG to effectively recruit unsuspecting users' computers to participate in the attack, thereby creating a botnet"
100
Fran Donoso @francisck.com · 14/09/2025
"however, a closer examination reveals that it is actually a platform for launching DDoS attacks against websites and other internet services deemed politically undesirable. This would appear to be Geedge's own implementation of China's Great Cannon, as described in a 2015 Citizen Lab report"
100
Fran Donoso @francisck.com · 14/09/2025
"TSG's in-path injection capability system allows for sophisticated targeting of this malicious code for the specific user, facilitating on-the-fly modifications across a variety of file formats [...] complemented by Cyber Narrator [...] hijack in order to infect specific individuals."
100
Fran Donoso @francisck.com · 14/09/2025
"TSG is also capable of modifying HTTP sessions in realtime through techniques such as spoofing redirect responses, altering headers, injecting scripts, replacing text, and overriding response bodies."
100
Fran Donoso @francisck.com · 14/09/2025
From the report: "Cyber Narrator is a powerful tool capable of tracking network traffic at the individual customer level and can identify the geographic location of mobile subscribers in real time [..]. The system also allows the government client to see aggregated network traffic."
100
Fran Donoso @francisck.com · 14/09/2025
This report from @interseclab.bsky.social on how a Chinese company is exporting some of the capabilities of "The Great Wall of China" to other autocratic countries is INSANELY INTERESTING: interseclab.org/wp-content/u... *EVERY Page is worth reading* Some interesting tidbits in the thread
interseclab.org
131
Fran Donoso @francisck.com · 10/09/2025
Incredible work, Yael!
000
Fran Donoso @francisck.com · 08/09/2025
Plex was hacked. It included usernames, emails, and hashed passwords. Change your passwords when you can,
010
Reposted by Fran Donoso
ESET Research @esetresearch.bsky.social · 26/08/2025
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/7
26543
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 05/08/2025
SentinelOne and Beazley Security have discovered a new Windows infostealer used in the wild named PXA Stealer, most likely the work of a Vietnamese-speaking cybercrime group. www.sentinelone.com/labs/ghost-i... labs.beazley.security/articles/gho...
0123
Fran Donoso @francisck.com · 04/08/2025
I mean I’ve been urging people to toss their sonicwall devices into a shredder for years now 🤷🏻‍♂️
051
Fran Donoso @francisck.com · 04/08/2025
Our team collaborated with our friends at @sentinellabs.bsky.social to identify and disrupt a PXA infostealer campaign that has an intricate and complex delivery chain: labs.beazley.security/articles/gho... Thanks for the fantastic collab SentinelLabs team!
labs.beazley.security
BSL - Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
032
Fran Donoso @francisck.com · 30/07/2025
Look forward to seeing you!!!
110
Reposted by Fran Donoso
andy jabbour @andyjabbour.bsky.social · 24/07/2025
👀 Update from @threatintel.microsoft.com: 'our continued monitoring of exploitation activity by Storm-2603 leading to the deployment of Warlock ransomware' www.microsoft.com/en-us/securi... #Microsoft #SharePoint #cybersecurity #ransomware @gate15.bsky.social @ransomwaresommelier.com @ecrime.ch
microsoft.com
Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog
Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting vulnerabilities targeting internet-facing SharePoint servers. In addition, we have observed a...
043
Fran Donoso @francisck.com · 21/07/2025
We’re actively seeing this exploitation as well. Here is my team’s advisory on this vulnerability: labs.beazley.security/advisories/B... Is your have a publicly exposed SharePoint server, its probably already compromised so get ready to do some IR.
labs.beazley.security
SharePoint 0Day Vulnerability Under Active Exploitation (CVE-2025-53770)
000
Reposted by Fran Donoso
Glenn @ntkramer.bsky.social · 16/07/2025
🩸& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2 1/2
greynoise.io
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
1129
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 13/07/2025
Two high-severity patches are coming to Node.js on Tuesday nodejs.org/en/blog/vuln...
0134
Reposted by Fran Donoso
Joe Slowik @pylos.co · 11/07/2025
Context: labs.watchtowr.com/pre-auth-sql...
labs.watchtowr.com
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
Welcome back to yet another day in this parallel universe of security. This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no o...
172
Fran Donoso @francisck.com · 03/07/2025
Congrats!!!!
100
Fran Donoso @francisck.com · 02/07/2025
Worth turning on if you have AT&T. Other carriers (like T-mobile) have similar programs.
000
Reposted by Fran Donoso
Whitney Merrill @wbm312.bsky.social · 26/06/2025
Need something positive to do in your life this week? If you don’t have a library card, go get one. Then learn about all the awesome things your local public library has to offer.
1215
Fran Donoso @francisck.com · 06/06/2025
This is related to ROP code exec on switch 2
000
Reposted by Fran Donoso
Zack Whittaker @zackwhittaker.com · 28/05/2025
New, by me: Data broker giant LexisNexis has revealed that its risk solutions unit (think "know your customer," risk assessing, due diligence, and law enforcement assistance) was breached, affecting the personal data and Social Security numbers of at least 364,000 people.
techcrunch.com
Data broker giant LexisNexis says breach exposed personal information of over 364,000 people | TechCrunch
The data collector said the stolen data includes Social Security numbers.
610758
Reposted by Fran Donoso
Kenn White @kennwhite.bsky.social · 27/05/2025
Just the tip of the iceberg from this roll-your-own security protocol. We're about to usher in a golden age of Valhalla-level AI pwnage, and it'll be riding on the coattails of badly designed agents. invariantlabs.ai/blog/mcp-git...
invariantlabs.ai
GitHub MCP Exploited: Accessing private repositories via MCP
We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariant's security ...
14120
Reposted by Fran Donoso
Wietze @wietzebeukema.nl · 24/03/2025
By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections. My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees. Here’s what I found and why it matters 👉 wietze.github.io/blog/bypassi...
13619
Reposted by Fran Donoso
Catalin Cimpanu @campuscodi.risky.biz · 08/05/2025
Ubiquiti has released a security update for UniFi Protect Cameras to fix an RCE vulnerability with a severity score of 10/10 Oh boy... community.ui.com/releases/Sec...
13319
Reposted by Fran Donoso
Joseph Cox @josephcox.bsky.social · 04/05/2025
New from 404 Media: the Signal clone the Trump administration uses was just hacked. TeleMessage makes a modified version of Signal that archives messages for government agencies, Waltz used it. A hacker got some users' messages, group chats. Hugely significant breach www.404media.co/the-signal-c...
404media.co
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
15459922731
Fran Donoso @francisck.com · 12/04/2025
I’m sorry to hear that and I hope things improve for you. I know we haven’t really connected, but feel free to reach out if you need to talk.
010
Fran Donoso @francisck.com · 04/04/2025
A lot of the time IR firms aren’t even allowed to write IR reports for the companies themselves because breach counsel is worried about discovery during litigation. Have literally been in situations where clients are begging for a report so they can justify investment, but the lawyers say no
020