Sign in

PCI Guru

@jbhall56.bsky.social
1.2K followers 57 following 15K posts

Information Security professional. At least that is what people claim. More of an information security curmudgeon.

PostsRepliesMedia
PCI Guru @jbhall56.bsky.social · 30/09/2026
Guesstimates are that 7% of the workforce faces replacement by AI. www.semafor.com/article/09/2...
semafor.com
Around 11 million US workers may face AI displacement
Voters globally have soured on AI because of existential risks the technology poses as well as concerns such as job losses and energy use.
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
010
PCI Guru @jbhall56.bsky.social · 30/09/2026
How many of you have this on your Incident Response Plan BINGO card? www.infoworld.com/article/4227...
infoworld.com
What happens when the cloud blows up?
When we plan for cloud failures, we need to consider more than power failures or network outages. Recent damage from the Iran war has impacted multiple availability zones.
110
PCI Guru @jbhall56.bsky.social · 30/09/2026
The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.
001
PCI Guru @jbhall56.bsky.social · 30/09/2026
Some thoughts on Claude Code plugins. medium.com/@hii_mohit/9...
medium.com
9 Claude Code Plugins Every Developer Should Install in 2026
Claude Code Plugins
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). thehackernews.com/2026/09/new-...
thehackernews.com
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
Spectre BTR reuses stale JIT branch targets; Linux PoCs recover the root password hash within minutes on a fully patched Intel system.
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
The feature, introduced on Android nearly a year ago, lets users create end-to-end encrypted backups of their chats and restore them on other devices if they lose their phone. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows).
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
You can get the feature by running wsl --update, and once installed, there's a new wslc.exe command-line tool. www.bleepingcomputer.com/news/microso...
bleepingcomputer.com
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available.
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
The OpenClaw project has started work on an enterprise edition in the hope that businesses lose their fear of the agentic AI project. www.theregister.com/ai-and-ml/20...
theregister.com
OpenClaw slips on a suit to evade widespread business bans
Red Hat, Nvidia, OpenAI and friends are working on an enterprise edition they say is ‘Kubernetes for agents’
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. www.securityweek.com/high-severit...
securityweek.com
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
OpenSSL and WolfSSL developers have released updates that patch a dozen vulnerabilities in each, including high-severity flaws.
000
PCI Guru @jbhall56.bsky.social · 30/09/2026
Great read on the latest AI “hacks” that show they might not be as renegade as you think. www.schneier.com/blog/archive...
schneier.com
I Want Better Reporting on AI Genie Behavior - Schneier on Security
AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie beh...
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Most business and IT leaders have added a day’s worth of work to their weeks managing AI risk, thanks to exploding use and a focus on governance that hasn’t resulted in AI readiness. www.cio.com/article/4225...
cio.com
AI governance is fast becoming an unmanageable chore
Most business and IT leaders have added a day’s worth of work to their weeks managing AI risk, thanks to exploding use and a focus on governance that hasn’t resulted in AI readiness.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
The former special counsel intends to stand by his investigations into Donald Trump, which led to criminal charges. www.politico.com/live-updates...
politico.com
What Jack Smith plans to tell the Senate Judiciary Committee
The former special counsel intends to stand by his investigations into Donald Trump, which led to criminal charges.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Tech companies are ramping up outreach to the administration as they lose ground in Congress, where concern over AI's risks is rapidly growing. www.politico.com/news/2026/09...
politico.com
Nvidia, AMD want Trump to keep their chips flowing to China
Tech companies are ramping up outreach to the administration as they lose ground in Congress, where concern over AI's risks is rapidly growing.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Its GPT-6.1 Astra system, which performs tasks like browsing the web and using apps by itself, "didn't quite meet the bar" of the company's standards, according to Saachi Jain, head of safety systems at OpenAI. www.bbc.com/news/article...
bbc.com
OpenAI scraps rollout of new AI model over safety concerns
The firm also issued an update on incidents in which its models accessed Australian government systems.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
The country is struggling to reconcile alarming AI disclosures from the same industry players eager to show off their latest, most advanced tech. www.axios.com/2026/09/29/w...
axios.com
The AI industry's contradictions take center stage in Washington, Silicon Valley
All eyes are on Washington AI meeting as OpenAI prepares to release new products.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
The revelation in Axios that researchers are investigating tens of thousands of problematic AI security incidents — rather than the dozens that had been publicly revealed — raised questions about whether AI leaders have control over their technology. www.axios.com/2026/09/29/t...
axios.com
The solution to the AI safety crisis is more AI
The solution to the AI safety crisis is more AI
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Tracked as CVE-2026-20700, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Hackers are exploiting two critical flaws in Citrix NetScaler, a widely used gateway that organizations rely on to let employees connect to internal systems from anywhere. www.govinfosecurity.com/hackers-hit-...
govinfosecurity.com
Hackers Hit NetScaler Zero-Days Before Citrix Patched
Attackers exploited two critical Citrix NetScaler flaws before fixes were available, including a bug that lets hackers with no credentials run commands on
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
100
PCI Guru @jbhall56.bsky.social · 29/09/2026
Rise of the Googlebook means ChromeOS users get eight years' support, not a decade. www.theregister.com/os-platforms...
theregister.com
Google ending ChromeOS support two years early
Rise of the Googlebook means ChromeOS users get eight years' support, not a decade
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. thehackernews.com/2026/09/rath...
thehackernews.com
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Cleafy traced nearly 100 RatHat console deployments since April 2026, with the platform building malware and using Gemini to rank victims.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Copland was intended to replace Apple's System 7 with a PowerPC-native operating system built around a microkernel, protected memory, and preemptive multitasking for system services. www.theregister.com/os-platforms...
theregister.com
Apple buried Copland 30 years ago. Now the failed OS boots in a browser
The final developer build offers a glimpse of the future Cupertino abandoned for NeXT
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
“Our models accessed Australian government websites in ways they were not authorised to,” the post opens. “We also should have handled our response better. We are sorry and working to do better in the future.” www.theregister.com/ai-and-ml/20...
theregister.com
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
Admits its agents side-swiped four Australian government sites
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Historically, building an application on top of AWS felt less like buying well-thought-out products, and more like a trip to Home Depot. www.theregister.com/paas-and-iaa...
theregister.com
AWS needs to embrace its place as the Home Depot of AI infrastructure
What's wrong with being a great wholesaler?
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
The Register asked Amazon to comment on the ad, and which other Asian countries it plans to enter. The company had not responded at the time of writing. www.theregister.com/personal-tec...
theregister.com
Amazon evaluating drone deliveries in Australia, Asia
PLUS: Singapore helps Meta find new form of scam; Nothing bets it can create Indian consumer tech giant; Bangkok floods, tech holds on
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication. www.securityweek.com/google-warns...
securityweek.com
Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign
Google warns of a new ShinyHunters campaign mass targeting Oracle PeopleSoft with a modified CVE-2026-35273 exploit.
000
PCI Guru @jbhall56.bsky.social · 29/09/2026
Blind-signature systems like Privacy Pass, used by Apple and Cloudflare, could be exposed. www.techspot.com/news/114006-...
techspot.com
Researchers forged RSA signatures without ever cracking the key
The technique is practical against 1,024-bit RSA keys, which are already deprecated. It also lowers the estimated security of 2,048-bit and 4,096-bit keys when they are used...
000
PCI Guru @jbhall56.bsky.social · 25/09/2026
Interesting read on why another person is bailing out of an AI project. robert.ocallahan.org/2026/09/good...
robert.ocallahan.org
Goodbye Google
000
PCI Guru @jbhall56.bsky.social · 25/09/2026
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. thehackernews.com/2026/09/clou...
thehackernews.com
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Cloudflare fixed a Containers flaw that let customers read leftover disk data from other accounts' deleted containers on shared servers.
000
PCI Guru @jbhall56.bsky.social · 24/09/2026
The incident is an example of how shipping vessels, oil tankers, and the broader global logistics network can be targeted by hackers. techcrunch.com/2026/09/18/f...
techcrunch.com
FBI, Coast Guard boarded hacked oil tankers heading toward US coast | TechCrunch
The feds are said to be investigating the compromise of the tankers' networks, which in one case interfered with one of the tanker's navigation and propulsion systems.
000
PCI Guru @jbhall56.bsky.social · 24/09/2026
Beyond 250 kW a server rack can no longer be cooled by a hybrid approach of liquid and air. At this density a 70/30 liquid-air split leaves 75 kW of air load. spectrum.ieee.org/fanless-liqu...
spectrum.ieee.org
Why Near Total Liquid Cooling Is the New Standard for AI Racks
The next generation of computing presents mounting heat challenges with every new launch
020
PCI Guru @jbhall56.bsky.social · 24/09/2026
China and the U.S. agree on three AI certainties: The country with the most powerful AI holds power, sets global standards, and wins the coming decades economically and militarily. www.axios.com/2026/09/24/c...
axios.com
Inside China's mind on AI
It's waging a much different war for AI supremacy than the U.S.
000
PCI Guru @jbhall56.bsky.social · 23/09/2026
Here is a real life risk. www.linkedin.com/feed/update/...
linkedin.com
Four Corners asked a Canberra cybersecurity expert to hack a BYD Shark 6. The entry point he found didn't even have a password. From a laptop by the road, Daniel Hreszczuk of Fortify Labs locked ...
Four Corners asked a Canberra cybersecurity expert to hack a BYD Shark 6. The entry point he found didn't even have a password. From a laptop by the road, Daniel Hreszczuk of Fortify Labs locked the ...
000
PCI Guru @jbhall56.bsky.social · 23/09/2026
Another read on RSA cracking. medium.com/asecuritysit...
medium.com
Traditional Maths and AI in Harmony Breaking Crypto
RSA Cracking is still a long way off
000
PCI Guru @jbhall56.bsky.social · 23/09/2026
Was RSA 896 broken? It could be. saweis.net/posts/rsa-89...
saweis.net
RSA-896
A post about RSA-896.
000
PCI Guru @jbhall56.bsky.social · 23/09/2026
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. www.securityweek.com/ai-powered-p...
securityweek.com
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Microsoft and its partners have disrupted EvilTokens, a phishing platform that uses AI throughout the attack chain.
010
PCI Guru @jbhall56.bsky.social · 23/09/2026
The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and jo...
010
PCI Guru @jbhall56.bsky.social · 23/09/2026
Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it. www.theregister.com/networks/202...
theregister.com
In the age of AI, teaching networking principles remains more important than learning protocols
Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it
000
PCI Guru @jbhall56.bsky.social · 23/09/2026
The adversary targeted multiple technologies, including PAN-OS Global Protect, FlowiseAI, Nuclio, Proxmox, Ubiquity, with exploits for known security issues. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in...
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
Palo Alto Networks is rolling out a new subscription service today that allows customers to use a mix of gated frontier models and open-weight models to find security flaws on their systems and recommend fixes. www.axios.com/2026/09/22/p...
axios.com
Exclusive: A major cyber vendor's new service to fight AI cyberattacks
Cyber pros are using AI to fight AI.
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
While the AI industry panics about extinction risks that are years away, financially motivated hackers are already using existing AI tools to turn stolen corporate network access into opportunities for fraud. www.axios.com/2026/09/22/m...
axios.com
A major AI-powered phishing service has lost access to its key infrastructure
Microsoft, other tech partners disrupted domains linked to EvilTokens.
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
The Metropolitan Water Reclamation District would like to sell recycled sewer water to big data centers that support artificial intelligence. Revenue could be millions of dollars a year. chicago.suntimes.com/environment/...
chicago.suntimes.com
Hatred for data centers is sky high, but this local government agency sees dollar signs
The Metropolitan Water Reclamation District would like to sell recycled sewer water to big data centers that support artificial intelligence. Revenue could be millions of dollars a year.
000
Reposted by PCI Guru
Darth Putin @darthputinkgb.bsky.social · 22/09/2026
"We'd love Russia to stop attacking and equally we'd love Ukraine to stop defending itself"
31480103
PCI Guru @jbhall56.bsky.social · 22/09/2026
OpenAI has thousands and thousands of contractors helping improve the company's AI models. Multiple contractors have been fired for using AI to train the AI. www.404media.co/people-train...
404media.co
People Training OpenAI’s AI Fired for Using AI to Train the AI
OpenAI has thousands and thousands of contractors helping improve the company's AI models. Multiple contractors have been fired for using AI to train the AI.
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
If you’re wondering how the hackers got by disk encryption, one of the unencrypted partitions contained the key for an encrypted partition. That’s pretty bad security engineering. www.schneier.com/blog/archive...
schneier.com
Reverse-Engineering Flock Cameras - Schneier on Security
Hackers captured a Flock camera and got a look (alternate link) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, t...
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
Your conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself. www.wired.com/story/how-to...
wired.com
How to Use AI With Your Privacy Intact
Your conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself.
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
Researchers from Cisco Talos shared an open-source framework on Monday that they hope will be used widely to classify and analyze AI-integrated malware. They also have proof that it's already working. www.wired.com/story/a-tool...
wired.com
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.
000
PCI Guru @jbhall56.bsky.social · 22/09/2026
UK cloud provider Civo plans to build 40 edge datacenters to bring sovereign AI services closer to customers, with the first due to open in Hertfordshire by March 2027. www.theregister.com/off-prem/202...
theregister.com
Are we human?
010