Sign in

Goupil

@furaxfox.bsky.social
292 followers 448 following 175 posts

Parceque ! (mes opinions n'engagent que moi) Ailleurs en ligne: goupilland.net github.com/FuraxFox mastodon.acm.org/@FuraxFox

PostsRepliesMedia
Reposted by Goupil
ANSSI @anssi-fr.bsky.social · 02/10/2026
🏥 82% des établissements de #santé ont eu connaissance de vulnérabilités sur leur système lors des douze derniers mois.* 📕 Découvrez le RETEX du CERT Santé et de l'ANSSI relatif aux vulnérabilités de produits du secteur santé : cert.ssi.gouv.fr/cti/CERTFR-2...
Vulnérabilités de produits du secteur santé RETEX du CERT Santé et du CERT-FR
252
Reposted by Goupil
The Verge @theverge.com · 29/09/2026
Every single one of 21 tested vehicles sent data to a third-party domain over Wi-Fi. Over half contacted domains specializing in advertising, tracking, or analytics. These companies gather details about your vehicle or driving behavior to sell to insurance companies or target you with ads.
theverge.com
Your car’s data privacy problems are worse than you think
“There’s a lot to be worried about,” the project lead said.
721291712
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 28/09/2026
⚠️ Alerte CERT-FR ⚠️ Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway. www.cert.ssi.gouv.fr/alerte/CERTF...
032
Reposted by Goupil
ANSSI @anssi-fr.bsky.social · 28/09/2026
⚠️ Vulnérabilités Citrix NetScaler ADC et Gateway. 📢 Le @cert-fr.bsky.social publie un bulletin d'alerte concernant plusieurs vulnérabilités affectant NetScaler ADC et Gateway. ➡️ Plus d'informations sur : www.cert.ssi.gouv.fr/alerte/CERTF...
Alerte de sécurité
036
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 21/09/2026
Dans son dernier bulletin d'actualité, le CERT-FR revient sur certaines vulnérabilités significatives de la semaine dernière. www.cert.ssi.gouv.fr/actualite/CERT…
011
Reposted by Goupil
Ailo @airavn.eurosky.social · 21/09/2026
It’s been 8 years since we published our report on how Google tricks people into extensive location tracking, and simultaneously filed complaints against Google. Today the decision from the Irish Data Protection Commission arrived: a €400 million euros fine. www.forbrukerradet.no/siste-nytt/d...
forbrukerradet.no
Google Fined €403 Million Following Consumer Council Report
Google has been fined €403 million by the Irish Data Protection Commission after the Norwegian Consumer Council exposed how the company manipulated users into accepting extensive tracking.
45937
Reposted by Goupil
BleepingComputer @bleepingcomputer.com · 21/09/2026
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
bleepingcomputer.com
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
031
Reposted by Goupil
halvarflake.bsky.social @halvarflake.bsky.social · 20/09/2026
A great read on EA and rationalism: contraptions.venkateshrao.com/p/ea-safety
contraptions.venkateshrao.com
EA Safety
EA promises to solve AI Safety. Now we have two problems.
235
Goupil @furaxfox.bsky.social · 18/09/2026
Max is not your friend: a deep look at Russian state approved chat app arxiv.org/html/2609.11...
arxiv.org
Don’t Trust the Super-App: A Case Study of Russia’s Max
100
Goupil @furaxfox.bsky.social · 18/09/2026
www.arretsurimages.net/chroniques/c... IA et panique, un échec des médias ?
arretsurimages.net
"L'IA va tous nous tuer" : anatomie d'une faillite journalistique - Par Thibault Prévost | Arrêt sur images
Piratage informatique par une "civilisation" de machines, prophétie apocalyptique d'un "lanceur d'alerte" d'OpenAI et Anthropic, probabilités d'extinction... la semaine dernière a encore été un grand ...
012
Reposted by Goupil
Zack Whittaker @zackwhittaker.com · 16/09/2026
Tankers can get hacked (they're floating cities with complex systems). But I haven't heard of this happening before: > One of the tankers was *boarded* by a "highly specialized team" of U.S. Coast Guard law enforcement officers, cyber protection members and an FBI cyber team in the Gulf of Mexico.
4265
Goupil @furaxfox.bsky.social · 15/09/2026
www.electrospaces.net/2026/09/trum...
electrospaces.net
Trump's new gold-trimmed phones in historical perspective
A weblog about Signals Intelligence, Communications Security and top level telecommunications equipment
000
Reposted by Goupil
Will T @bushidotoken.net · 15/09/2026
I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇 www.team-cymru.com/post/ransomw...
team-cymru.com
Ransomware Incident Response: Infrastructure Analysis
A year of incident response data reveals how Akira, DragonForce & Clop build ransomware infrastructure — and how defenders can hunt it.
065
Reposted by Goupil
H I Sutton @covertshores.bsky.social · 15/09/2026
You haven’t seen a ship like this before(!): China’s New Giant Submarine Drone Mothership www.navalnews.com/naval-news/2...
navalnews.com
China's New Giant Submarine Drone Mothership - Naval News
A new vessel spotted at a Chinese shipyard is likely the world’s first mothership designed to deploy submarine drones. It represents the latest piece in the puzzle of China’s undeclared effort to deve...
2531263
Reposted by Goupil
IFIN @ifin-intel.org · 14/09/2026
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. ifin-intel.org/blog/... #ThreatIntel #ThreatIntelligence #TIIMA
ifin-intel.org
Announcing IFIN Lists | IFIN
IFIN Lists is a project to build a well curated, community driven set of permanent block lists for all to use.
175
Reposted by Goupil
Olivier Poncet 🦝 @ponceto91.bsky.social · 14/09/2026
Nouvelle vidéo : « NeXT, le système qui a donné macOS (et sauvé Apple) » Dans cette vidéo, je vous propose de revenir sur l'histoire de NeXT, qui donnera naissance à Rhapsody, Mac OS X puis macOS 🔗 youtu.be/Qo5fQHur8q0
youtu.be
NeXT, le système qui a donné macOS (et sauvé Apple)
YouTube video by Olivier Poncet
7191
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 10/09/2026
⚠️Alerte CERT-FR⚠️ Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898. www.cert.ssi.gouv.fr/alerte/CERTF...
011
Reposted by Goupil
ANSSI @anssi-fr.bsky.social · 14/09/2026
#CyberResilienceAct | 💻 Fabricants, déclarez les vulnérabilités activement exploitées et les incidents graves de sécurité ayant un impact sur les produits comportant des éléments numériques. RDV sur la Single Reporting Platform de l'ENISA : 🔗 portal.cra-srp.enisa.europa.eu
11/09/2026
Déclaration obligatoire pour les fabricants
Cyber Resilience Act
082
Reposted by Goupil
Jess Miers 🦝 @jmiers230.bsky.social · 13/09/2026
I did a somewhat deep dive into the recent OpenAI and Anthropic "hacks" for an upcoming interview. IMO, the AI companies are better off running with the "rogue AI" story because the real story is actually pretty embarrassing. Like making your Wi-Fi password "wifi" embarrassing. 🧵
341835795
Goupil @furaxfox.bsky.social · 13/09/2026
Imaginons que vous développiez un code malveillant, et que par négligence il se propage sur Internet et compromette plusieurs systèmes. Votre responsabilité serai sans doute engagée, même si vous plaidez l'incident.
11415
Reposted by Goupil
#BruceSterling @bruces.bsky.social · 12/09/2026
*Those tokens that come free with the Chinese dumplings, are those fungible or non-fungible
0171
Reposted by Goupil
Ryan Naraine @ryanaraine.bsky.social · 12/09/2026
FULL SHOW youtu.be/dhRnaXXSSIs?...
youtu.be
AI Doomers, Death Cults, WeChat Worm Exploit
YouTube video by Three Buddy Problem
043
Reposted by Goupil
BleepingComputer @bleepingcomputer.com · 12/09/2026
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
bleepingcomputer.com
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
084
Reposted by Goupil
Eryk Salvaggio @eryk.bsky.social · 11/09/2026
My essay on rogue AI has been republished by the Bulletin of the Atomic Scientists — “Rogue AI didn’t breach Hugging Face, human decisions did.” Grateful to @thebulletin.org for the invitation!
thebulletin.org
Rogue AI didn’t breach Hugging Face, human decisions did
At the core of the Hugging Face hacking incident were a series of human choices that traded security for speed.
314964
Goupil @furaxfox.bsky.social · 12/09/2026
eddie.codes/posts/pandas... Your big data problem might be a medium data problem
eddie.codes
Pandas Should Go Extinct
Pandas has taken us a long way, but it's time for a new bear
000
Goupil @furaxfox.bsky.social · 10/09/2026
brucesterling.tumblr.com/post/8272715... Now and then ...
brucesterling.tumblr.com
BruceS
SCIENCE FICTION FILMS + SET IN THE FUTURE Escape from New York (1981) dir. John Carpenter 2001: A Space Odyssey (1968) dir. Stanley Kubrick Back to the Future Part II (1989) dir. Robert Zemeckis The...
000
Reposted by Goupil
Catalin Cimpanu @campuscodi.risky.biz · 08/09/2026
Kudelski and Sekoia researchers look at how the Lazarus Group is now operating from six distinct sub-clusters after a major reorganization of the North Korean intel service two years ago www.sekoia.com/blog/beyond-... kudelskisecurity.com/research/bey...
2156
Reposted by Goupil
Catalin Cimpanu @campuscodi.risky.biz · 06/09/2026
After the DOJ and State Department, Congress now wants CyberCommand to use cyber contractors too A new provision authorizing the DOD to use cyber contractors was included in the National Defense Authorization Act for Fiscal Year 2027 www.bloomberg.com/news/article...
bloomberg.com
Senate Considers Allowing Contractors to Conduct Military Hacks
Contractors would be allowed to conduct military hacking operations with US government approval under a Senate defense bill that would mark the first time Congress has explicitly authorized the privat...
093
Goupil @furaxfox.bsky.social · 06/09/2026
Trusted third parties are not always very trustable www.techdirt.com/2026/09/03/h...
techdirt.com
Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.
From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it "age" verification, but it always ends up as identity verification), we've been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn't waiting. Maybe it was already happening. This week a...
010
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 31/08/2026
Dans son dernier bulletin d'actualité, le CERT-FR revient sur certaines vulnérabilités significatives de la semaine dernière. www.cert.ssi.gouv.fr/actualite/CERT…
011
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 03/09/2026
CERTFR-2026-AVI-1111: Multiples vulnérabilités dans les produits F5 www.cert.ssi.gouv.fr/avis/CERTFR-20…
012
Reposted by Goupil
Zack Whittaker @zackwhittaker.com · 31/08/2026
Also, ICYMI: Last week I published a 3,200-word deep-dive explainer on a major threat to your home and office: Residential proxy networks allow hackers to use your internet connection for crime and cyberattacks. Find out why resproxies are a threat, how they work, and what *you* can do about them. 🤖
this.weekinsecurity.com
How residential proxy networks are hiding hackers in your home
Security researchers say residential proxy networks present a major threat by allowing hackers to commandeer home and office networks for cybercrime.
13310
Goupil @furaxfox.bsky.social · 29/08/2026
matduggan.com/you-know-gdp... (and the funniest part: the banners that everybody associate with GDPR actually do not come from GDPR but ePrivacy a different regulation)
matduggan.com
You Know GDPR Is Good Based on Who Hates It
FDR has always been one of my favorite presidents, second maybe to Lincoln. Both were men the establishment assumed were one of them until, to their horror, they governed like they weren't. Both could...
112
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 24/08/2026
Dans son dernier bulletin d'actualité, le CERT-FR revient sur certaines vulnérabilités significatives de la semaine dernière. www.cert.ssi.gouv.fr/actualite/CERT…
011
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 24/08/2026
⚠️ Ciblage de téléphones Apple 📱 ⚠️ Le CERT-FR a connaissance de notifications envoyées par Apple le 13 août 2026 à des utilisateurs ciblés par des logiciels espions. Si vous en avez été destinataire, contactez le CERT-FR au plus vite ⤵️ cert.ssi.gouv.fr/cti/CERTFR-2...
039
Goupil @furaxfox.bsky.social · 23/08/2026
The colors of industrial safety bethmathews.substack.com/p/why-so-man...
bethmathews.substack.com
Why So Many Control Rooms Were Seafoam Green
The Color Theory Behind Industrial Seafoam Green
000
Reposted by Goupil
Denis Bodor @lefinnois.bsky.social · 22/08/2026
Je trouve ça complètement dingue... En 2026, pouvoir mettre à jour un iMac G4 de presque 25 ans avec la dernière version d'OpenBSD. sysupgrade, sysmerge, pkg_add -Uu et l'affaire est dans le sac. C'est juste beau 🥰
612723
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 17/08/2026
Dans son dernier bulletin d'actualité, le CERT-FR revient sur certaines vulnérabilités significatives de la semaine dernière. www.cert.ssi.gouv.fr/actualite/CERT…
022
Goupil @furaxfox.bsky.social · 14/08/2026
How good are AI generated patches ? 1Password checked. 1password.com/blog/why-ai-...
1password.com
Off-by-1 Labs Research: AI-generated vulnerability patches require human review | 1Password
Defenders are increasingly turning to LLMs to to generate vulnerability patches. But our research showed that LLMs only successfully generate patches (without materially changing application behavior)...
010
Reposted by Goupil
Dark Reading @darkreading.bsky.social · 10/08/2026
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius by #darkreading Rob Wright www.darkreading.com/vulnerabilities… #cybersecurity #zeroday
darkreading.com
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The max-severity vuln, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
011
Reposted by Goupil
CERT-FR @cert-fr.bsky.social · 10/08/2026
Dans son dernier bulletin d'actualité, le CERT-FR revient sur certaines vulnérabilités significatives de la semaine dernière. www.cert.ssi.gouv.fr/actualite/CERT…
043
Reposted by Goupil
Python Coding (CLCODING) @clcoding.bsky.social · 10/08/2026
📘 Deep Learning with Python, Second Edition — Free PDF Deep Learning with Python, Second Edition by François Chollet — 504 pages. 📚 Topics include: Deep Learning fundamentals Neural networks Keras & TensorFlow Computer vision 🔗 Free PDF post: www.clcoding.com/2025/05/deep...
071
Reposted by Goupil
gloriouscow.bsky.social @gloriouscow.bsky.social · 08/08/2026
The following Egyptian hieroglyphics are also a valid MS-DOS COM file. I don't know, what's left? Wingdings? 𓐁𓀸𓐁𓈁𓐕𓐁𓀿𓐐𓍽𓐘𓍽𓐙𓍽𓐞𓍽𓐟𓁃𓀀𓁃𓈀𓁃𓐀𓁃𓐑𓁃𓐮𓁃𓐮𓁃𓐮𓁃𓐮𓁃𓐮𓐧𓁃𓀿𓐧𓁃𓅀𓁃𓐀𓁃𓐀𓁃𓐜𓁃𓐮𓁃𓐮𓁃𓐮𓁃𓐮𓐧𓁃𓌀𓁃𓐀𓁃𓐀𓁃𓐀𓁃𓐏𓁃𓐮𓁃𓐮𓐧𓁃𓀷𓁃𓐮𓁃𓐮𓁃𓐮𓐧𓁃𓏀𓁃𓐀𓁃𓐀𓁃𓐀𓁃𓐒𓁃𓐮𓁃𓐮𓐧𓁃𓌀𓁃𓐀𓁃𓐀𓁃𓐔𓁃𓐮𓁃𓐮𓁃𓐮𓁃𓐮𓐧𓁃𓁀𓁃𓐀𓁃𓐋𓐧𓁃𓀀𓁃𓀐𓁃𓋿𓁃𓏿𓐧𓁃𓐀𓁃𓐧𓁃𓐮𓁃𓐮𓁃𓐮𓐧𓁃𓉊𓁃𓐮𓐧𓁃𓃿𓁃𓏿𓁃𓏿𓐧𓁃𓀀𓁃𓐎𓁃𓐮𓁃𓐮𓐐𓐑𓐒𓐕𓐖𓐗𓀈𓀀𓀀𓀀𓊀𓀎𓀀 #x86 #asm
2338550
Reposted by Goupil
Andy Greenberg @agreenberg.bsky.social · 06/08/2026
At Black Hat, security researcher Vangelis Stykas reveals what he found by lurking inside North Korean hackers’ infrastructure for nearly two years: They got footholds inside 1,640 networks, by his count. About half of those intrusions were serious breaches. www.wired.com/story/a-secu...
wired.com
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
14726
Reposted by Goupil
Eric Geller @ericjgeller.com · 05/08/2026
Senior US, UK, and Canadian cyber officials today urged critical infrastructure providers and other businesses to stop obsessing over AI nightmare hacks and prioritize resilience to prepare for basic and inevitable incidents. My story from Black Hat: www.cybersecuritydive.com/news/ai-cybe...
cybersecuritydive.com
Western government leaders call for a focus on infrastructure resilience, not AI hype
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.
0115
Reposted by Goupil
The Register @theregister.com · 05/08/2026
Time Magazine has a separate version of its website with ads only AI can see
theregister.com
Time Magazine has a separate version of its website with ads only AI can see
Brands are already paying to influence what chatbots say about them
0143
Reposted by Goupil
evacide @evacide.bsky.social · 04/08/2026
You would think that all of these people pushing for social media bans for kids would be interested in whether or not these bans actually work...but no, I guarantee we will keep on seeing age-gating bills. theconversation.com/more-than-80...
theconversation.com
More than 80% of kids still using social media despite ban, new eSafety report finds
The report provides more evidence Australia’s world-leading social media ban isn’t going to plan.
1216346
Reposted by Goupil
"Online Rent-a-Sage" Bret Devereaux @bretdevereaux.bsky.social · 04/08/2026
Ok, I haven't been remotely keeping up with House of the Dragon, but I just saw a scene clip that not only includes a spiked-ball-and-chain flail (not a completely fake weapon, but a very rare one), but also a company-sized unit successfully 'playing dead' while being walked over for an ambush.
1735611
Goupil @furaxfox.bsky.social · 04/08/2026
No surprise: of AI by attackers as a substitute to skill results in very noisy attacks
001
Reposted by Goupil
Eric Geller @ericjgeller.com · 03/08/2026
A small army of volunteer security experts has spent the past few years helping rural water utilities with cybersecurity. How has it gone? What have they learned? And what's next? Read my (timely!) new story about DEF CON Franklin: www.cybersecuritydive.com/news/water-c...
cybersecuritydive.com
How volunteer cyber experts are helping protect rural water systems
A first-in-the-nation program is seeing promising results as it charts a path for supporting the U.S.’s most vulnerable infrastructure.
47425