Sign in

James Atack

@jamesatack.com
272 followers 539 following 118 posts

Cyber defender with an offensive name. CTO at @onyphe.io | onyphe.io Managing your attack surface... from Europe 👀 Opinions : all mine Special skill : machine empathy

PostsRepliesMedia
James Atack @jamesatack.com · 22/07/2026
Deliberate or not, we now have a collective noun for CVEs A dumb It's perfect. Thanks @campuscodi.risky.biz !
Link to Risky Biz newsletter.
The Linux Kernel project has disclosed 442 vulnerabilities over the past three days, in a massive dumb of CVEs on its security mailing list
020
James Atack @jamesatack.com · 20/10/2025
21409
James Atack @jamesatack.com · 02/09/2025
JLR been ransomwared. www.bbc.com/news/article... A propos de nothing, I'll just leave this here...
020
James Atack @jamesatack.com · 28/05/2025
Yeah gee Fortinet - wonder what that reality would look like? 🙄 <goes back to day job>
Fortinet LinkedIn post : What happens when the infrastructure designed to defend becomes a new attack surface?
010
James Atack @jamesatack.com · 18/05/2025
A well-used family charging shelf - get phones out of bedrooms - ensure teens go out with charged devices - never have to look for a charger
A small alcove with two shelves holding a variety of electronic devices and chargers. Bottom shelf has a large Pendix bike battery.
010
James Atack @jamesatack.com · 14/05/2025
Good luck with that Microsoft. Thanks iPhone for the ALT text
Microsoft Teams: Enhanced Meeting Protection - Prevent Screen Capture
Microsoft Teams
To address the issue of unauthorized screen captures during meetings, the Prevent Screen Capture feature ensures that if a user attempts to take a screen capture, the meeting window will turn black, thereby protecting sensitive information. This feature will be available on Teams desktop applications (both Windows and Mac) and Teams mobile applications (both iOS and Android. For users joining from unsupported platforms, they will be placed in audio-only mode to maintain the integrity of the meeting's content.
Roadmap ID
490561
Cloud instances(s)
Worldwide (Standard Multi-Tenant)
Platform (s)
Android, Desktop, iOS, Web
IN I
ROLLOUT S
July 2025
Release phases(s)
General Availability, Targeted Release
Added to roadmap: 05/05/2025
SHARE
Last modified: 05/06/2025
010
James Atack @jamesatack.com · 28/04/2025
This is what he means 👇 😨 that's a national telecom network dying of thirst for power
020
James Atack @jamesatack.com · 14/04/2025
Dear @microsoft.com, I just tried *new* Outlook on Windows. What have you done? +ve : multithreading -ve : significantly slower -ve : uses +5x the amount of RAM -ve : WebView2? seriously? I wanted a serious desktop app not a browser plugin for a website. nevermind ... I'll just use OWA on Linux
Screenshots of Windows TaskManager running old and new versions of Outlook. Classic Outlook uses 125MB of RAM. New Outlook while running multiple threads is using 649MB of RAM.
011
James Atack @jamesatack.com · 14/02/2025
Or your toilet. Definitely not your toilet. Should we also add Ivanti ConnectSecure to this list?
030
James Atack @jamesatack.com · 12/02/2025
A glimmer of honesty squeaks through with "Vendors are working to try and resolve some of these weaknesses, but it also is paramount for defenders to take note." We get it. You're trying. Yet the number of open IOS XE WebUI interfaces just keeps going up. The message isn't getting through.
Chart showing changes in compromised Cisco IOS XE devices over time. Latest number is 26368 compromised out of 55891 devices (unique IPs)
010
James Atack @jamesatack.com · 15/01/2025
$659m in 12 months prompts me to repost the visionary insights of the IMF on how cryptocurrency innovation is a public good www.imf.org/en/Blogs/Art...
000
James Atack @jamesatack.com · 06/01/2025
ii) Go Oracle This is unique IPs by hosting organization.
100
James Atack @jamesatack.com · 06/01/2025
i) nice that people are happy to share their interest in C2 panels github.com/orgs/trojanp... I especially like "open source enthusiast" with commit permissions on an apache project. Also a "dubious C2 enthusiast" on the side, yet doesn't mention cyber as an interest. Odd.
100
James Atack @jamesatack.com · 06/01/2025
Couple of additional datapoints about the "Trojan Panel" C2 that \@shanholo had already found in April i) the github followers list is an eye-opener ii) Oracle the leading public cloud for once details below 👇
Screenshot from Twitter / X of a post by @shanholo with screenshot of the Trojan Panel C2
121
James Atack @jamesatack.com · 03/01/2025
And the next ... IP 101[.]99.93.144 exposing DCE/RPC protocol on 8th Oct 2024 for the record it also exposed winrm and smb around and before that date
IP 101[.]99.93.144 exposing DCE/RPC protocol on 8 Oct 2024
100
James Atack @jamesatack.com · 03/01/2025
The incident dates back to October, so I'm using our historical data functionality (Cyber Time-Travel if you're a CISO reading this). I'll discard all results after October. first ip I'm looking at : 101[.]99.93.108 B-I-N-G-O +1000 points in my rigorous CTI methodology
IP 101[.]99.93.108 exposing dce/rpc protocol on 28 september 2024
100
James Atack @jamesatack.com · 03/01/2025
2nd IOC is 185[.]158.248.104 a Windows box with RPC exposed - well that and everything else. Behind a Mikrotik router by the looks of it RPC hypothesis rigorous CTI methodology analysis ^^ : -1 on first IP +1 on 2nd IP
a Windows box on IP 185[.]158.248.104 exposing protocols btest, dce/rpc, rdp, smb, ssh and winrm
100
James Atack @jamesatack.com · 03/01/2025
we tag it at a risky protocol there are 2.2M results for Windows RPC boxes
onyphe ctiscan result showing the number of rpc protocol exposed on Windows boxes, that is 2193060 found in 0.26 seconds
111
James Atack @jamesatack.com · 03/01/2025
so the other C2 65[.]21.245.7 is marginally more interesting it's another windows box with SMB 🤦‍♂️ exposed and based on the IIS version it's an out-of-support Windows Server 2012 R2. It's still up. The interesting data point is that it also has dcerpc exposed hmm.
onyphe screenshot showing ip 65[.]21.245.7 exposing port 445 with smb on the 28 dec 2024. also exposing ports 135 and 80 and showing IIS version 8.5
100
James Atack @jamesatack.com · 03/01/2025
Looking at the first C2 IP 111[.]90.140.76 with @onyphe.bsky.social (yeah well...) nothing currently up but looking back in historical data we've got an RDP box with dcerpc also exposed going back to Sep 24
onyphe screenshot showing result for IP 111[.]90.140.76 on port 3389 exposing RDP, dated to 3 nov 2024. Also exposing port 135 dcerpc
121
James Atack @jamesatack.com · 04/12/2024
Si vous cherchez une école du 21ème siècle à Paris 👇
021
James Atack @jamesatack.com · 21/03/2024
My monthly reminder that two thirds of Cisco IOS XE devices are compromised. The threat actor gets knocked down, but they get up again ... #ciscoiosxe
chart showing 31051 compromised devices out of total of 45981
000
James Atack @jamesatack.com · 25/01/2024
Cisco encouraging customers to explore IOS XE automation => blogs.cisco.com/developer/io... Meanwhile ... someone else has automated over half of them This chart is unique IPs.
number of compromised Cisco IOS XE devices over time by unique IP. Variation between 25000 and 30000, with a total number of 50000.
010
James Atack @jamesatack.com · 08/12/2023
More malspam making it into my mailbox than usual this week. Where's it coming from? • A MikroTik router in Venezuela • A hosted linux box in Canada with SSH exposed The usual suspects
cropped poster of The Usual Suspects movie
000
James Atack @jamesatack.com · 17/11/2023
- Over the past month we've seen 113,147 unique IPs (IPv4) exposing SSH versions described as having vulnerable implementations 🔥
113147 total
96020 Cisco 
12226 generic sshd 
3798 Zyxel
407 Mocana
50 Zyxel protocol version 1.99 ( all others 2.0)
000
James Atack @jamesatack.com · 18/10/2023
The number is going up. ONYPHE this morning identified 53K unique IPs based on the same check. This threat actor : - compromises router/gateway devices - not doing ransomware - doesn't run away quietly when discovered - doubles down and tries to leverage as much as possible sounds familiar
121
James Atack @jamesatack.com · 17/10/2023
This afternoon #ONYPHE identified 71K unique IPs exposing a webui vulnerable to #CVE-2023-20198 in 201 different countries That's the Cisco ios XE vuln, CVSS 10, actively exploited with no patch. What can you say? sec.cloudapps.cisco.com/security/cen... www.onyphe.io @patriceauffret.bsky.social
141