Sign in

Jim Mahony

@jpmahony.bsky.social
359 followers 670 following 186 posts

CISO, Cybersecurity Researcher, PhD, OSINT, SecOps, IoT/OT Sec, Yinzer, Coffee, Music, Guitars, Fly Fishing, Lock Picking Carpenter. Good Trouble. Peace.

PostsRepliesMedia
Reposted by Jim Mahony
Jake Williams @malwarejake.bsky.social · 27/09/2026
We need this on a campaign ad.
1275
Reposted by Jim Mahony
Sami Laiho @samilaiho.com · 06/09/2026
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities thehackernews.com/2026/09/atta...
thehackernews.com
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Attackers exploit two PaperCut flaws to steal credentials from U.S. and European education organizations.
123
Reposted by Jim Mahony
Library of Congress @librarycongress.bsky.social · 25/08/2026
The Library is devastated to learn of the passing of Dolly Parton, a music legend and titan of children's literacy. Her Imagination Library program has earned multiple Library Literacy Awards and, in 2018, she visited us to donate its 100 millionth book to our collection and host a story time. 🦋❤️
Dolly Parton reads to children in the Library’s Great Hall in 2018. Photo by Shawn Miller.
194335147163
Reposted by Jim Mahony
The Phantom Judge You Harshly 🎃💀🦇🧛‍♂️ @judgeyouharshly.bsky.social · 26/08/2026
A selection of Dolly murals 🥹
735611939
Reposted by Jim Mahony
Ninja Owl @ninjaowl.ai · 26/08/2026
Popular school apps may be sharing student data with advertisers #cybersecurity #hacking #news #infosec #security #technology #privacy
malwarebytes.com
Popular school apps may be sharing student data with advertisers
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
011
Reposted by Jim Mahony
Cynthia Brumfield @metacurity.com · 12/08/2026
7.3M chess dot com records leaked, and the data is real ransomnews.com/chess-com-le...
ransomnews.com
7.3M chess.com records leaked, and the data is real
A 15.5 GB file of 7.3 million chess.com user records is circulating free on two leak forums. We verified it: the data is genuine and days old, but the shape points to scraping, not a breach.
023
Reposted by Jim Mahony
Jon of The North @krauza.bsky.social · 29/07/2026
I don't want a "Smart Fridge" that orders milk for me. I want a fridge that lasts 25 years and doesn't have a privacy policy that allows it to share my late-night snacking habits with my health insurance provider.
42130182199
Reposted by Jim Mahony
Danny Palmer @dannypalmer.bsky.social · 24/07/2026
A side note to this, especially as I went to uni 20 years ago, but it's still weird to remember how internet was so locked down in student halls, I, to that point a competitive CS/TFC player* couldn't play online games. At all. *No money in it then www.infosecurity-magazine.com/news/univers...
infosecurity-magazine.com
Ransomware Attacks Targeting Universities on the Rise
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
141
Reposted by Jim Mahony
BleepingComputer @bleepingcomputer.com · 13/06/2026
Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity.
bleepingcomputer.com
Chinese hackers hijack auth flow, spy on isolated network for a decade
Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity.
0103
Reposted by Jim Mahony
The Register @theregister.com · 29/05/2026
ChatGPT blindly trusts browser content, turning the page into a payload
theregister.com
ChatGPT blindly trusts browser content, turning the page into a payload
You and me go ChatGPhish-ing in the dark
1145
Reposted by Jim Mahony
Angeliki T. 💎 in NYC @ellinidata.bsky.social · 16/05/2026
Chinese newspaper cartoon (Today... 😂 )
736232207616
Reposted by Jim Mahony
Whitney Merrill @wbm312.bsky.social · 09/05/2026
Them: why is AI so unpopular with people? Also them:
25413
Reposted by Jim Mahony
Robert Reich @rbreich.bsky.social · 09/05/2026
The NRA buys off Congress. No action on guns. The oil industry buys off Congress. No action on climate. Insurance companies buy off Congress. No action on health care. The list goes on and on. Money in politics is the root of our dysfunction.
776224277185
Reposted by Jim Mahony
InfoSec @infosec.skyfleet.blue · 05/05/2026
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
darkreading.com
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
A proof-of-concept exploit (PoC) shows how someone with admin privileges can exploit the issue to steal passwords, and thus use them to engage in further malicious activity.
073
Reposted by Jim Mahony
sam³⁰⁰⁰ @samgavin.com · 29/03/2026
A remarkable photo from #NoKings in DTLA from Connor Sheets of @latimes.com www.latimes.com/california/l...
LAPD officers arrest a protester dressed as the Statue of Liberty outside a federal building during a ‘Kings Day’ protest. (Connor Sheets/Los Angeles Times)
163135325008
Jim Mahony @jpmahony.bsky.social · 27/03/2026
another from gregorysmith-art.com #pittsburgh #art Pittsburgh Evening Storm, 1993, oil on canvas, 28" x 46"
Pittsburgh Evening Storm, 1993, oil on canvas, 28" x 46"
060
Jim Mahony @jpmahony.bsky.social · 27/03/2026
I discovered that a neighborhood friend is a retired artist, and that his house is full of magnificent works of art that he created. He is Gregory Smith, 85 and very talented. This piece is: Courthouse Towers, Arches National Park, 2025, oil on canvas, 48 x 80 gregorysmith-art.com #art
Courthouse Towers, Arches National Park, 2025, oil on canvas, 48 x 80

gregorysmith-art.com
2130
Reposted by Jim Mahony
Deth Veggie @dethveggie.bsky.social · 24/03/2026
My money's on it being a really big wooden horse.
1233
Jim Mahony @jpmahony.bsky.social · 02/02/2026
Hackers attempt to extort parents after school refuses to pay ransom fee That's a new twist to the attack parents were told they could either pressure the school to pay or pay 50 euros per child themselves therecord.media/hackers-atte...
therecord.media
Hackers attempt to extort parents after school refuses to pay ransom fee
The attackers are believed to have gained access to the internal networks of OLV Pulhof, a secondary school in the Berchem district of Antwerp, shortly after the Christmas break.
000
Jim Mahony @jpmahony.bsky.social · 02/02/2026
Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks When exploited it can enable an attacker to bypass object linking and embedding (OLE) CVE-2026-21509, a high-severity vulnerability (with a CVSS 3.1 score of 7.8) #cybersecurity www.infosecurity-magazine.com/news/fancy-b...
infosecurity-magazine.com
Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks
Russia-linked hacking group Fancy Bear is exploiting a brand-new vulnerability in Microsoft Office, CERT-UA says
030
Reposted by Jim Mahony
Mr. Spock 🖖 @spockresists.bsky.social · 07/12/2025
Whoever put this sign on London tabloid rag sheets gets a 🖖 from me. F**k the billionaires.
391948494
Reposted by Jim Mahony
NPR @npr.org · 01/12/2025
In matching, brilliant blue suits, David Byrne and his band squeeze behind the Desk to perform four songs, including Talking Heads' "Life During Wartime." n.pr/4pFYoun
n.pr
David Byrne: Tiny Desk Concert
In matching, brilliant blue suits, David Byrne and his band squeeze behind the Desk to perform four songs, including Talking Heads' "Life During Wartime."
19901198
Reposted by Jim Mahony
Hackmanac @hackmanac.com · 21/11/2025
🚨Cyber Alert‼️ 🇺🇸USA - Crowdstrike CrowdStrike has identified and terminated a malicious insider who leaked internal screenshots to hackers. Status: Confirmed Source: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
CrowdStrike catches insider feeding information to hackers
American cybersecurity firm CrowdStrike has confirmed that an insider shared screenshots taken on internal systems with hackers after they were leaked on Telegram by the Scattered Lapsus$ Hunters thre...
033
Reposted by Jim Mahony
Patrick C Miller @patrickcmiller.bsky.social · 04/10/2025
www.technologyreview.com/2025/10/02/1...
technologyreview.com
Microsoft says AI can create “zero day” threats in biology
Artificial intelligence can design toxins that evade security controls.
133
Reposted by Jim Mahony
Robert Reich @rbreich.bsky.social · 02/09/2025
Never forget this: Working people outnumber the billionaires and CEOs by a huge margin. If workers stand together, they will win. Solidarity.
15468381688
Reposted by Jim Mahony
Cynthia Brumfield @metacurity.com · 27/08/2025
The DOGE team at SSA might have violated FISMA and other laws by not following security protocols as spelled out in NIST's SP 800-53, which are mandatory for all government agencies. 1/2 www.csoonline.com/article/4046...
csoonline.com
Whistleblower: DOGE put Social Security database covering 300 million Americans on insecure cloud
The complaint accuses DOGE of bypassing security protocols to move Americans’ sensitive personal data outside federal oversight and onto an insecure AWS cloud instance, potentially violating establish...
35023
Reposted by Jim Mahony
Lesley Carhart @hacks4pancakes.com · 16/08/2025
You really should read this article on how criminal groups routinely bypass EDR. This isn’t state stuff. I see it all the time, and have for a while. The sad truth is EDR is one rung in defense in depth and it surviving tampering is a perpetual cat mouse game. www.theregister.com/2025/08/14/e...
theregister.com
Ransomware crews don't care about your EDR
: Some custom malware, some legit software tools
512434
Jim Mahony @jpmahony.bsky.social · 18/08/2025
This mess needs to be taken care of. Roblox Corp responds to Louisiana lawsuit that claims it built 'the perfect place for pedophiles' #cybersecurity #infosec www.gamedeveloper.com/business/rob...
gamedeveloper.com
Roblox Corp responds to Louisiana lawsuit that claims it built 'the perfect place for pedophiles'
A new lawsuit has accused Roblox of knowingly enabling the 'systemic sexual exploitation and abuse of children across the United States.'
010
Jim Mahony @jpmahony.bsky.social · 28/07/2025
Oh WordPress, what are we going to do with you! #cybersecurity #vulnerability #infosec
020
Jim Mahony @jpmahony.bsky.social · 21/07/2025
350M Cars, 1B Devices Exposed to 1-Click Bluetooth RCE Four vulnerabilities in a popular Bluetooth implementation can be chained together to enable remote code execution (RCE) in untold millions of vehicles and miscellaneous devices. #cybersecurity #infosec www.darkreading.com/vulnerabilit...
darkreading.com
350M Cars, 1B Devices Exposed to 1-Click Bluetooth RCE
Mercedes, Skoda, and Volkswagen vehicles, as well as untold industrial, medical, mobile, and consumer devices, may be vulnerable to an attack chain called "PerfektBlue."
010
Jim Mahony @jpmahony.bsky.social · 10/07/2025
This is awesome #Lego
010
Jim Mahony @jpmahony.bsky.social · 10/07/2025
yup, this is what happens, and this is why we can't have nice things ...
010
Reposted by Jim Mahony
Phil Hagen @philhagen.com · 01/07/2025
This is utterly unethical. If you let the make-shit-up-machine be your lawyer, you deserve the pain brought on by your stupidity.
4184
Reposted by Jim Mahony
Bryce Kunz @tweekfawkes.bsky.social · 23/06/2025
Think your Smart TV is just showing you movies? It's also a data goldmine for advertisers, learning your habits. A good reminder that *you* often have some control in the settings! 🕵️‍♂️📺 #Cybersecurity #AI archive.is/FIJx0
011
Reposted by Jim Mahony
InfoSec @infosec.skyfleet.blue · 22/06/2025
WordPress Motors theme flaw mass-exploited to hijack admin accounts
bleepingcomputer.com
WordPress Motors theme flaw mass-exploited to hijack admin accounts
Hackers are exploiting a critical privilege escalation vulnerability in the WordPress theme "Motors" to hijack administrator accounts and gain complete control of a targeted site.
011
Reposted by Jim Mahony
Allison Gill @muellershewrote.com · 30/05/2025
Holy shit. www.wired.com/story/cbp-dn...
wired.com
The US Is Storing Migrant Children’s DNA in a Criminal Database
Customs and Border Protection has swabbed the DNA of migrant children as young as 4, whose genetic data is uploaded to an FBI-run database that can track them if they commit crimes in the future.
51660073129
Reposted by Jim Mahony
Dane Pavitt 🦕🌍 @danepavitt.bsky.social · 22/05/2025
*pretends to be surprised*
newscientist.com
Colossal scientist now admits they haven’t really made dire wolves
Despite a huge media fanfare in which Colossal Biosciences claimed to have resurrected the extinct dire wolf, the company's chief scientist now concedes that the animals are merely modified grey wolve...
0347
Reposted by Jim Mahony
BleepingComputer @bleepingcomputer.com · 20/05/2025
A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete control of websites.
bleepingcomputer.com
Premium WordPress 'Motors' theme vulnerable to admin takeover attacks
A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete control of websites.
033
Reposted by Jim Mahony
Mark Johnson @markjohnsonit.bsky.social · 19/05/2025
Just read this very real supply chain risk story: rogue comms devices found inside Chinese solar inverters. If hardware can be compromised at this level, what are we missing in software? Especially in open source and gov procurement. The implications are bigger than solar. #SupplyChain #ZeroTrust
reuters.com
www.reuters.com
U.S. energy officials are reassessing the risk posed by Chinese-made devices that play a critical role in renewable energy infrastructure after unexplained communication equipment was found inside some of them, two people familiar with the matter said.
2176
Reposted by Jim Mahony
InfoSec @infosec.skyfleet.blue · 14/05/2025
Windows Remote Desktop Gateway Vulnerability Let Attackers Trigger Dos Condition
cybersecuritynews.com
Windows Remote Desktop Gateway Vulnerability Let Attackers Trigger Dos Condition
031
Reposted by Jim Mahony
Charlie Angus @charlieangus104.bsky.social · 09/05/2025
Song of the day: Life During War Time "This ain't no party, this ain't no disco, this ain't no fooling around." My nomination for the soundtrack song of 2025. www.youtube.com/watch?v=8al5...
youtube.com
Talking Heads - Life During Wartime (live)
YouTube video by forcedcoitus
33164161081
Reposted by Jim Mahony
Saganism @sagan.bsky.social · 08/05/2025
Another day of reminding everyone of Carl Sagan’s eerily accurate warning about the dangers of not being able to ask skeptical scientific questions to those in power or authority.
214146694257
Jim Mahony @jpmahony.bsky.social · 05/05/2025
At least 500 e-commerce sites hacked in Supply-Chain Attack Supply-chain security is important, very important Companies need to hold themselves accountable, too Monitoring of sites and due diligence pre-contract is super important #cybersecurity #vulnerability arstechnica.com/security/202...
arstechnica.com
Hundreds of e-commerce sites hacked in supply-chain attack
Attack that started in April and remains ongoing runs malicious code on visitors’ devices.
010
Jim Mahony @jpmahony.bsky.social · 05/05/2025
what a total mess. amazing #cybersecurity #hack
000
Reposted by Jim Mahony
Mark Hamill @markhamillofficial.bsky.social · 04/05/2025
Proof this guy is full of SITH.
2735451758178
Reposted by Jim Mahony
Royans Tharakan @royans.bsky.social · 01/05/2025
FBI releases list of 42,000 phishing domains linked to dismantled LabHost platform. #Cybersecurity #Phishing #FBI
bleepingcomputer.com
FBI Shares List of 42,000 LabHost Phishing Domains
FBI releases list of 42,000 phishing domains linked to dismantled LabHost platform. #Cybersecurity #Phishing #FBI
001
Reposted by Jim Mahony
Zoey Selman (V3rbaal) @v3rbaal.bsky.social · 28/04/2025
I've finally made my way over here! 👋
6214
Reposted by Jim Mahony
Saganism @sagan.bsky.social · 28/04/2025
Neil degrees Tyson Explaining the "God of the Gaps".
30971301592
Reposted by Jim Mahony
The Tennessee Holler @thetnholler.bsky.social · 27/04/2025
WATCH: “You’re saying you revere a time when their ancestors were in bondage.” In NC, @davidjoy.bsky.social powerfully explains why it’s wrong to remove a “compromise plaque” without public input, and why revering the confederacy is offensive. Full: www.instagram.com/reel/DI9vdzA...
429109533810