Sign in

Ron Bowes

@iagox86.bsky.social
3.4K followers 786 following 1.6K posts

Staff Product Detection Engineer @ Censys. skullsecurity.org Mostly post about professional stuff, maybe some improv stuff and maybe even magic some day. Seattle-based (originally Canadian), queer, cybersecurity nerd. (He/him)

PostsRepliesMedia
Reposted by Ron Bowes
Ninja Owl @ninjaowl.ai · 16h
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
021
Reposted by Ron Bowes
Censys @censys.bsky.social · 30/09/2026
In the 2026 State of the Internet Report, we are looking beyond the weekly news cycle to benchmark security trends across more than 2 years of Internet data. Join Censys ARC Flash on Oct 14 at 11 AM ET to hear directly from the researchers behind the report & ask questions. bit.ly/3ToHoyz
021
Ron Bowes @iagox86.bsky.social · 30/09/2026
I recently visited IMDb and it automatically logged me in with the account I use on Amazon, then started sending me spam. The "unsubscribe" link in the spam was a 404 I deleted the account, blocked the email address, and banned IMDb results in Kagi. Wikipedia does it better anyways
010
Reposted by Ron Bowes
Catalin Cimpanu @campuscodi.risky.biz · 29/09/2026
Kiteworks patches the vulnerability law enforcement warned it about last week and revokes its "take server offline" recommendation www.kiteworks.com/company/pres...
kiteworks.com
Kiteworks' Difficult and Unique Decision to Ensure Customer Data Protection Through Customer-Wide Shutdown Successfully Navigates Credible Threat
Kiteworks restored all customer systems after a precautionary shutdown, confirming no evidence of compromise from the credible threat. Read the full update.
041
Reposted by Ron Bowes
Catalin Cimpanu @campuscodi.risky.biz · 29/09/2026
Two recently patched Citrix NetScaler zero-days are seeing widespread mass-exploitation after detailed write-ups and POCs were published on Monday www.greynoise.io/blog/swarmin... x.com/LupovisDefen... mastodon.social/@GossiTheDog...
greynoise.io
Swarming Against Citrix 0-Day Exploitation
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the ...
2104
Reposted by Ron Bowes
Censys @censys.bsky.social · 28/09/2026
🚨Two Citrix NetScaler RCE vulnerabilities are being actively exploited as zero-days. Censys sees 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC advisory:
011
Reposted by Ron Bowes
Ninja Owl @ninjaowl.ai · 27/09/2026
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
042
Ron Bowes @iagox86.bsky.social · 26/09/2026
The really smart people extracting money from gamblers feels so evil to me Also, governments profiting from gambling is just wrong - tax the rich, not the poor/addicts FFS I liked the part in the middle about how forcing companies to regulate themselves is both unfair and unproductive
020
Ron Bowes @iagox86.bsky.social · 26/09/2026
Today's debate is hilarious. I had no idea people cared about bringing drinks into interviews, I've interviewes a ton (both sides of the table) and it's never occurred to me to consider what they're drinking - I just want to know if they can do the job (Also I always have an iced latte)
140
Reposted by Ron Bowes
Catalin Cimpanu @campuscodi.risky.biz · 22/09/2026
Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN) blog.checkpoint.com/security/sec...
blog.checkpoint.com
Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 - Check Point Blog
As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our %
084
Reposted by Ron Bowes
Censys @censys.bsky.social · 18/09/2026
@feedly.com now links straight into Censys. When a threat report surfaces an IP, it rarely tells you what that host is doing right in real-time. Now analysts can click 'Open in Censys' from a Feedly IoC Insights Card and land on the live host record. Great threat intel integration! bit.ly/3V4kr42
021
Reposted by Ron Bowes
Ninja Owl @ninjaowl.ai · 18/09/2026
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
022
Reposted by Ron Bowes
Ninja Owl @ninjaowl.ai · 18/09/2026
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
022
Reposted by Ron Bowes
Ninja Owl @ninjaowl.ai · 17/09/2026
Critical ScreenConnect flaw now actively exploited in attacks #cybersecurity #hacking #news #infosec #security #technology #privacy
bleepingcomputer.com
Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
032
Reposted by Ron Bowes
Censys @censys.bsky.social · 16/09/2026
🚨CVE-2026-91843 is a critical (CVSS 9.8) pre-auth RCE affecting Check Point Quantum Security Management and Log Servers. Censys sees 3,836 hosts globally with the management/log server role. No public PoC or confirmed exploitation as of publication. Patches are available. bit.ly/4cRApEJ
033
Reposted by Ron Bowes
Censys @censys.bsky.social · 09/09/2026
A few hours to go. Join @silascutler.bsky.social and @martijngrooten.bsky.social at 11 AM ET for Censys ARC Flash to hear about their latest Internet research. Join live to participate in the Q&A. Register: bit.ly/4uEpjd2 #CensysARC
043
Reposted by Ron Bowes
Video Game History Foundation @gamehistoryorg.bsky.social · 08/09/2026
Since the Zelda 40th anniversary stream is happening... This is the first (and only?) American review of the original Legend of Zelda, from the August 1987 issue of Computer Entertainer. The reviewer praised its "mythic aura" and "fairy-tale quality." Read the full issue: ow.ly/tg3s50ZJMSY
"THE LEGEND OF ZELDA (***1/2/****) from Nintendo for the NES is THE most eagerly anticipated title yet released for the system. With all the hoopla, including golden package and matching golden cartridge, we just didn't feel right about playing the game with our usual review set-up: NES Control Deck hooked up to a modest, 12-inch composite monitor. So we dragged the deck into the living room, connected it to a 27-inch Sony monitor/receiver, and dared Nintendo to impress us. Not only did Nintendo impress us with the many wonders of ZELDA, but they also managed to get us totally hooked on this excellent game. Imagine a great adventure: the rescue of the princess Zelda, the recovery of the Triforce of Wisdom, the defeat of of an evil prince. Imagine yourself as Link, the young hero about to set out on this adventure, with all 97-plus screens of the Hyrulean Overworld to explore and nine levels of multi-screen labyrinths in the Underworld as well.""Alone in the Forest
The story begins with young Link alone and unarmed in a forest clearing. If he enters the cave at one edge of the clearng, he can find a sword and begin his adventure. As an inexperienced young hero, he will suffer many defeats in the early going. The forests are full of dangerous creatures. The lakes harbor nasty monsters that shoot balls at Link. But there are jewels and other goodies to be found by slaying the creatures, and jewels can buy useful items sold by merchants in some of the caves. After wandering for a while (or following the directions in the instruction book), Link can find the entrance to the first underground labyrinth. In the Underworld, the player has an overhead view into the chambers, which are full of many surprises and more nasty creatures of all kinds. The trip through a labyrinth is a treasure hunt, with a Triforce segment the ultimate treasure to be gained. Along the way, there are monsters to fight, secret doors to discover, and plenty of frustration. As Link gathers treasures, new weapons, and experience, he is able to venture into new places and make new discoveries. Thanks to the built-in battery in the cartridge, the objects that Link accumulates are saved from one playing session to the next. It's a good thing they are saved for Link, because it would be impossible to complete this game in one sitting. (The battery also allows you to save three "Link" characters.) Players are also aided by maps and hints included in the package.""Fairy-Tale Quality
THE LEGEND OF ZELDA has a beautiful, fairy-tale quality that we found very appealing. As an adventure, it has more to offer than the typical hack-and-slash epics because of its special mythic aura that carries you into the story. And ZELDA offers an incredibly rich, deep gaming experience that goes far beyond the typical cartridge game. The game is well supported by charming graphics, superb original music, excellent animation, and smooth transitions in scrolling between locations. We believe that THE LEGEND OF ZELDA will appeal to both male and female players of all ages. It has a very special kind of magic that makes it a "must-have" for every owner of the Nintendo Entertainment System. (Solo play; Pause.) Recommended. (MSR $44.95)"
535583
Reposted by Ron Bowes
Catalin Cimpanu @campuscodi.risky.biz · 07/09/2026
Hackers are using a new zero-day to take over Adobe Commerce and Magento online stores. A successful attack allows attackers to start a backdoored background process on hacked stores sansec.io/research/sty...
sansec.io
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current ver...
13313
Reposted by Ron Bowes
Censys @censys.bsky.social · 31/08/2026
🎥 Looks like an MP4. Carries an encrypted NetSupport client. Censys ARC researcher @exraritas.bsky.social uncovered an active malware payload hiding inside a fake video file. He tracked the NetSupport RAT delivery kit across 40 live endpoints and 18 builds. bit.ly/3Uuc15N #CensysARC
bit.ly
The Video That Plays You: Fake MP4 File Carries Malicious Payload - Censys
Censys ARC examines the kit that hides malicious payloads within a fake MP4 file that can pass file-type checks. Here's how it works.
031
Ron Bowes @iagox86.bsky.social · 28/08/2026
They're letting me write advisories now, so I had fun with this one :⁠-⁠)
081
Reposted by Ron Bowes
Censys @censys.bsky.social · 27/08/2026
Censys ARC researcher @silascutler.bsky.social examines an exposed server containing Moobot botnet source code, active attack records, additional DoS tooling, and a fraudulent identity verification service. Full analysis of what the exposed directory revealed: bit.ly/3SUCPvz
052
Ron Bowes @iagox86.bsky.social · 27/08/2026
It's remarkable how amateurish these backdoors are
100
Reposted by Ron Bowes
The Beaverton @thebeaverton.com · 26/08/2026
Report: Tim Curry's death to be investigated by suspicious group of eccentrics gathering at his house
thebeaverton.com
Report: Tim Curry's death to be investigated by suspicious group of eccentrics gathering at his house
LOS ANGELES - Following the death of beloved 80-year-old British actor Tim Curry, observers have noted a coterie of anonymous upper crust suspects arriving at his mansion in order to investigate the m...
10089281890
Reposted by Ron Bowes
Catalin Cimpanu @campuscodi.risky.biz · 26/08/2026
0184
Reposted by Ron Bowes
Joseph Cox @josephcox.bsky.social · 26/08/2026
New: in leaked audio, Flock's CEO Garrett Langley tells cops that a story we wrote about Flock being used to track a woman who self-administered an abortion is "entirely false." He's lying. The audio shows how Flock speaks when doesn't think comments will be public www.404media.co/flocks-ceo-i...
404media.co
Flock’s CEO Is Lying to Cops About 404 Media's Reporting on Abortion Case
Garrett Langley, Flock’s CEO, told cops that a 404 Media story about cops using Flock to track someone who self-administered an abortion was "entirely false." He's lying.
227995
Ron Bowes @iagox86.bsky.social · 25/08/2026
My first advisory!
071
Reposted by Ron Bowes
Catalin Cimpanu @campuscodi.risky.biz · 23/08/2026
Security researchers have identified the first malware strain that infected the Android-based head unit of a modern smart car. The malware was part of BADBOX and added the car to a botnet that engaged in ad fraud and proxy traffic. securelist.com/android-head...
securelist.com
First Android malware targeting automotive head units
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
22511
Reposted by Ron Bowes
Ninja Owl @ninjaowl.ai · 22/08/2026
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
011
Ron Bowes @iagox86.bsky.social · 20/08/2026
Every time I see engagement bait or rage bait, I mute the account and move on. Highly recommend.
030
Reposted by Ron Bowes
The Long Con Winnipeg @thelongcon.bsky.social · 20/08/2026
We've opened our Call for Presentations! We love talks on all infosec-related subjects, especially from new speakers! Submit your idea before August 30: forms.gle/dZCbB8UqwM8b...
forms.gle
The Long Con 2026 Call for Presentations / Villages (CFP)
The Long Con is Winnipeg's technical information security conference, back for its seventh year! This year’s event takes place on November 7th & 8th (2026) at the West End Cultural Center! As usual, w...
021
Ron Bowes @iagox86.bsky.social · 20/08/2026
Submit a talk, come to our awesome little prairie conference!!
031
Reposted by Ron Bowes
Rob DenBleyker @robdenbleyker.com · 18/08/2026
81275274
Reposted by Ron Bowes
Greg Otto @gregotto.bsky.social · 19/08/2026
The long tail of Clop’s PTC hack is just beginning to emerge cyberscoop.com/clop-zero-da...
cyberscoop.com
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.
154
Ron Bowes @iagox86.bsky.social · 19/08/2026
RIP to a legend in magic, Juan Tamariz www.elconstitucional.es/en/qtv/more-...
elconstitucional.es
The last "chan-tatachán" of Juan Tamariz: the magician who marked several generations dies at 83
His daughter Ana has confirmed the death of the Madrid artist, world champion in 1973, unforgettable television face and generous master of several generations of illusionists
012
Reposted by Ron Bowes
Rachel Coldicutt @rachelcoldicutt.bsky.social · 17/08/2026
No thanks Google
• No sooner than September 21, 2026: The new configuration goes into effect for all users.
• Auto-enablement rules:
When a user creates a meeting in Google Calendar with a Google Meet conference and adds the third participant (including the organizer), the "Take notes for me" feature and the transcription will be automatically pre-enabled.
The first time this occurs, Google Calendar displays an explanatory callout.
78906196
Reposted by Ron Bowes
GreyNoise @greynoise.io · 17/08/2026
The new GreyNoise Visualizer just dropped 💥 We redesigned the GreyNoise Visualizer to match how defenders actually work. Log in and hit "Try the New Visualizer" to explore it today. 🔗https://www.greynoise.io/blog/new-way-to-navigate-greynoise
151
Ron Bowes @iagox86.bsky.social · 12/08/2026
So the guy that stole my e-bike, threatened me with a weapon on video, essentially destroyed the bike, and got arrested with it? Seattle declined to prosecute. I have a mountain of notes and photos and everything. On the plus side, I guess I can write about this now!
250
Ron Bowes @iagox86.bsky.social · 12/08/2026
We've reached the "unsubscribe from vendor spam" part of the Defcon experience I swear I'm going to make a new email domain just to register for events...
020
Ron Bowes @iagox86.bsky.social · 11/08/2026
So I couldn't help but notice that the vegan options at @defcon.bsky.social were dire.. literally the only thing I found was a food truck that requested 30 minutes of standing in the Vegas sun. I ended up leaving for my remaining meals. Do we need to start a Vegan Village? I can't be the only one
140
Ron Bowes @iagox86.bsky.social · 09/08/2026
I really enjoyed the path of reading that this post sent me down today: soatok.blog/2024/11/15/w...
soatok.blog
What To Use Instead of PGP - Dhole Moments
It’s been more than five years since The PGP Problem was published, and I still hear from people who believe that using PGP (whether GnuPG or another OpenPGP implementation) is a thing they s…
160
Ron Bowes @iagox86.bsky.social · 08/08/2026
"Is everyone ready for a 0-day?" there we go!! (Darren MacDonald on hacking thin clients)
020
Ron Bowes @iagox86.bsky.social · 08/08/2026
"We did this through a big bounty so we can't give full details" I love this talk but having to hold back details due to a bounty is crap @defcon.bsky.social
181
Ron Bowes @iagox86.bsky.social · 08/08/2026
I can't reply to this post, but I need to say to all the curious out there: if you want to understand Canadian (prairie) culture, watch Corner Gas. It's such a good show, and it's aged pretty well!
041
Reposted by Ron Bowes
GrapheneOS @grapheneos.org · 08/08/2026
Google replaced pushing Git tags for certain source code with obtaining source code via Google Drive after making a request through Google Forms. It's completely ridiculous and they've gradually become very slow at handling requests. They're in clear violation of the GPLv2 now.
7545119
Ron Bowes @iagox86.bsky.social · 07/08/2026
Old man opinion: let me request a non-electronic badge at conferences so I don't have to wear something pointy that gets caught on everything (and that also feels wasteful because it's just going to waste) I'll still take the free batteries of course @defcon.bsky.social
230
Ron Bowes @iagox86.bsky.social · 06/08/2026
This was a thoroughly enjoyable read about a nuclear enrichment facility seemingly run by Mr Burns: magazine.atavist.com/2026/toxic-l...
magazine.atavist.com
The Whistleblowers Who Exposed Decades of Nuclear Lies
In Paducah, Kentucky, workers at a revered uranium-enrichment plant were exposed to dangerous levels of radiation. Management assured them nothing was wrong. Then four friends risked everything to rev...
000
Reposted by Ron Bowes
Jimmy Wylie @mayahustle.com · 05/08/2026
We have two malware analyst openings at Dragos! In many malware jobs, your work disappears into the void. But at Dragos, it's easy to see the impact of your work across the company and community. And you get to work on interesting cases across OT verticals. job-boards.greenhouse.io/dragos/jobs/...
job-boards.greenhouse.io
Associate Principal Malware Analyst
United States
035
Ron Bowes @iagox86.bsky.social · 05/08/2026
Just in time! With @rapid7.bsky.social killing the best information source they probably didn't know they had (AttackerKB), we instantly get a plausible replacement! It's funny that I was also just talking to somebody at BSidesLV about how I miss bugtraq lists.securityfocus.com/hyperkitty/l...
lists.securityfocus.com
Bugtraq is back - Bugtraq - SecurityFocus Mailing Lists
210
Ron Bowes @iagox86.bsky.social · 04/08/2026
I loved @eliselzer.bsky.social 's guest Rex Parker NYT crossword blog today. I doubt the right people will see it or care, but we need more of this rexwordpuzzle.blogspot.com/2026/08/litt...
"Unfortunately, today's puzzle continued the New York Times' continued love affair with transphonic hate-monger JK Rowling at 27D. They just will not stop with the Harry Potter references. This woman is a bigoted monster, and by continuing to promote her work, they are implicitly endorsing her disgusting views. It shouldn't be this hard for adults to give up a children's book when its creator is using every cent of the profit from it to attack an already marginalized community."
010
Ron Bowes @iagox86.bsky.social · 31/07/2026
I just noticed that my "2tb storage plan" at Google is now called "AI Plus", which I guess makes the metrics for their shitty AI look better? Bundling to scam investors
011