Sign in

Larry W. Cashdollar

@larry0.bsky.social
696 followers 594 following 32 posts

Principal Security researcher at Akamai. Exploit Coder. Research covered by Slashdot, ZDNet, arstechnica, MSN + more also a Mitre CVE CNA with 200+ CVEs

PostsRepliesMedia
Reposted by Larry W. Cashdollar
emptywheel @emptywheel.bsky.social · 27/04/2026
Also: Cole Allen: I was targeting the rapist, pedophile, and traitor. Donald Trump: Couldn't be me! I'm not a rapist or pedophile! bsky.app/profile/atru...
1132069
Larry W. Cashdollar @larry0.bsky.social · 12/02/2026
@adamshostack.bsky.social
141
Larry W. Cashdollar @larry0.bsky.social · 10/02/2026
Shipped a copy of this book that contains an entry from me to the library of congress. They accepted it as a donation for inclusion in their collection.
040
Reposted by Larry W. Cashdollar
Matthew Guariglia @mguariglia.bsky.social · 09/02/2026
Ok, you can stop texting me, I saw the Ring ad. Troubling things about it 🧵: -The long awaited (much warned about) intro of “AI” recognition. It starts w/ searching for a “brown dog” but means the tech is there for lisence plate reading, face recognition, searching for suspects by description, etc
251673610
Reposted by Larry W. Cashdollar
Catalin Cimpanu @campuscodi.risky.biz · 02/02/2026
-Chat & Ask AI leaks chatbot messages -Nobel Committee investigates hack -Data leak at the Ttareungyi bike-sharing service -Comcast agrees to $117.5m settlement over 2023 breach -Aperture Finance and SwapNet get hacked -NVIDIA RTX comes to Linux -Tor Browser gets vandalized -US investigates WhatsApp
164
Larry W. Cashdollar @larry0.bsky.social · 22/01/2026
www.akamai.com/blog/securit... command injection in vivotek camera firmware
akamai.com
021
Larry W. Cashdollar @larry0.bsky.social · 21/11/2025
I've been looking at legacy IOT camera firmware checking for command injection vulnerabilities -> www.akamai.com/blog/securit...
akamai.com
040
Larry W. Cashdollar @larry0.bsky.social · 22/10/2025
At 50 years old I put my foot on a skate board after not touching one for 20+ years and it felt like peering into death's face.
030
Reposted by Larry W. Cashdollar
Union of Concerned Scientists @ucs.org · 08/09/2025
Science is under attack! 🚨 Join Bill Nye and thousands of science supporters in fighting back against this anti-science administration. Your voice matters! ➡️ act.ucsusa.org/41Eqmxm
515161
Reposted by Larry W. Cashdollar
Chris Wysopal @weld.bsky.social · 11/08/2025
Honored to be named an Industry Visionary in the 2025 #CyberScoop50. Special respect to Amit Yoran, who was posthumously awarded Lifetime Achievement. Amit’s vision & integrity shaped our industry. Many of us followed his lead, myself included. His example endures. cyberscoop.com/cyberscoop-5...
cyberscoop.com
CyberScoop 50 reveals 2025 winners; honors Amit Yoran with lifetime award
The cybersecurity world stands immeasurably stronger because of the vision, expertise, and leadership of Amit Yoran. Throughout his distinguished career, Amit fundamentally shaped the field of cyberse...
045
Larry W. Cashdollar @larry0.bsky.social · 09/08/2025
TIL there is professional pillow fighting.
110
Larry W. Cashdollar @larry0.bsky.social · 08/08/2025
witnessed a new member joining the #cDc tonight! @biascilab.bsky.social youtube.com/shorts/kg7Qh... #defcon
youtube.com
I witnessed hacker history @biascilab #hackers #hackerhistory #infosec #cultofthedeadcow
YouTube video by Maxtheautowolf
0216
Larry W. Cashdollar @larry0.bsky.social · 28/07/2025
I’ll be at Defcon this year.
030
Larry W. Cashdollar @larry0.bsky.social · 23/06/2025
Neat phishing campaign sending out docusign requests redirecting to a fake apple icloud login page
010
Larry W. Cashdollar @larry0.bsky.social · 13/05/2025
Avocados are like schrödinger’s cat.
021
Reposted by Larry W. Cashdollar
BostonJoan 🏳️‍🌈 🦫 @bostonjoan.bsky.social · 08/05/2025
@micahflee.com gets the goods. If this doesn’t tell you how unserious the current administration is about Security then I don’t know what will. micahflee.com/doge-bro-kyl...
micahflee.com
DOGE bro Kyle Schutt's computer infected by malware, credentials found in stealer logs
Kyle Schutt is a 37 year old "DOGE software engineer," according to ProPublica. In February, Drop Site News reported that he gained access to FEMA's "core financial management system." His computer wa...
29738
Reposted by Larry W. Cashdollar
Randall Munroe @xkcd.com · 25/04/2025
PhD Timeline xkcd.com/3081
5865979420444
Larry W. Cashdollar @larry0.bsky.social · 20/04/2025
fawn in my yard
050
Larry W. Cashdollar @larry0.bsky.social · 18/03/2025
thehackernews.com/2025/03/unpa...
thehackernews.com
Unpatched Edimax Camera Flaw Exploited for Mirai Botnet Attacks Since Last Year
Unpatched Edimax IC-7100 flaw (CVE-2025-1316) exploited for Mirai botnet malware since May 2024, enabling DDoS attacks via default credentials.
020
Reposted by Larry W. Cashdollar
Phillip Wylie @phillipwylie.bsky.social · 21/02/2025
How I Rob Banks: A Journey into the World of Ethical Hacking with Freakyclown podcasters.spotify.c...
podcasters.spotify.com
How I Rob Banks: A Journey into the World of Ethical Hacking with Freakyclown by Phillip Wylie Show
About The Guest: FC Barker aka Freakyclown is an ethical hacker and professional cyber criminalist with over three decades of experience. He is the co-founder of Sygenta, a company that specializes in ethical hacking and penetration testing. Freakyclown has a background in offensive cyber research and has worked for major defense firms. Summary:Freakyclown shares his experience as an ethical hacker and professional cyber criminalist. He discusses the type of pen testing he does, which goes beyond the typical cookie-cutter approach. He emphasizes the importance of manual work and understanding the foundations of hacking. Freakyclown also talks about the evolution of hacking over the years and the changes he has witnessed. He provides advice for those interested in getting into offensive security, including participating in CTFs and bug bounty programs. Freakyclown also talks about his new book, "How I Rob Banks," which shares anecdotes and tips from his career in physical pen testing. Key Takeaways: Ethical hacking goes beyond automated tools and requires manual work and understanding of the foundations. The barrier to entry in offensive security has lowered, but the threat landscape has expanded. Participating in CTFs and bug bounty programs is a great way to gain skills and experience in offensive security. Freakyclown's book, "How I Rob Banks," provides entertaining anecdotes and tips from his career in physical pen testing. Freakyclown resources: https://twitter.com/_Freakyclown_ https://www.linkedin.com/in/freakyclown/ https://www.cygenta.co.uk/ How I Rob Banks book: https://www.wiley.com/en-us/How+I+Rob+Banks%3A+And+Other+Such+Places-p-9781119911517
083
Reposted by Larry W. Cashdollar
George Takei @georgetakei.bsky.social · 18/02/2025
I’m sorry. You can’t conduct “peace talks” with Russia over its invasion of Ukraine without Ukraine at the table.
4058192956
Reposted by Larry W. Cashdollar
Simeon Pundit @loudlong.bsky.social · 13/02/2025
Now that RFK Jr. is confirmed as HHS Secretary, and with the bird flu moving toward becoming a pandemic, we can all look forward to this:
media.tenor.com
a man in a helmet is saying `` bring out your dead '' while standing in the rain .
ALT: a man in a helmet is saying `` bring out your dead '' while standing in the rain .
42811
Reposted by Larry W. Cashdollar
John Scalzi @scalzi.com · 12/02/2025
I personally will continue to use "Gulf of Mexico" because our president is a wrathful felonious nincompoop with the intellect of paramecium and I do not consent to his cartographic buffoonery
940283693686
Reposted by Larry W. Cashdollar
Encyclopaedia Britannica @britannica.com · 12/02/2025
Encyclopædia Britannica will continue to use ‘Gulf of Mexico’ for a few reasons: -We serve an international audience, a majority of which is outside the U.S. -The Gulf of Mexico is an international body of water, and the U.S.’s authority to rename it is ambiguous. 🧵⬇️
563325766973
Reposted by Larry W. Cashdollar
cryptax.bsky.social @cryptax.bsky.social · 06/02/2025
Analyzing ELF/Sshdinjector (IoT bot) with r2ai. Really helpful and time save to use AI (with r2ai) for analysis *but* use it with a non-AI decompiler side by side: 1. To direct the AI 2. To spot more easily hallucinations or extrapolations. www.fortinet.com/blog/threat-... #r2ai #IoT #botnet #AI
fortinet.com
Analyzing ELF/Sshdinjector.A!tr with a Human and Artificial Analyst | FortiGuard Labs
FortiGuard Labs reverse engineers a malware’s binaries to look into what the malware is actually doing.…
011
Reposted by Larry W. Cashdollar
Joy-Ann Reid @joyannreid.bsky.social · 01/02/2025
Happy Black History Month, and yeah, we're still doing that.
media.tenor.com
a drawing of a fist with a purple bracelet around it
ALT: a drawing of a fist with a purple bracelet around it
10195815213206
Larry W. Cashdollar @larry0.bsky.social · 28/01/2025
My co-worker noticed this in our honeypot logs and tagged me into investigate it with him -> www.akamai.com/blog/securit...
akamai.com
142
Larry W. Cashdollar @larry0.bsky.social · 19/12/2024
Digiever devices are actively being expolited in the wild a blog post by the Akamai SIRT -> www.akamai.com/blog/securit...
akamai.com
010
Reposted by Larry W. Cashdollar
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 12/12/2024
A book that I wrote a chapter for, '97 Things Every Application Security Professional Should Know: Collective Wisdom from the Experts', is available on Kindle now! Woohoo! www.amazon.com/Thing...
262
Reposted by Larry W. Cashdollar
Deth Veggie @dethveggie.bsky.social · 23/11/2024
go.bsky.app/RQGGsfb Word to the Herd.
54512
Larry W. Cashdollar @larry0.bsky.social · 23/11/2024
Patton Delacroix
130
Reposted by Larry W. Cashdollar
Deth Veggie @dethveggie.bsky.social · 23/11/2024
Now we're talkin'! Make Ed's Redeeming Qualities popular again!
192
Larry W. Cashdollar @larry0.bsky.social · 11/10/2024
My discovery of the DDoS amplification vector in cups-browsed is in the news www.computerweekly.com/news/3666128... CVE-2024-47850
computerweekly.com
Cups Linux printing bugs open door to DDoS attacks, says Akamai | Computer Weekly
The Cups Linux printing vulnerabilities disclosed at the end of September would seem to have a nasty sting in their tail, according to researchers at Akamai
031
Larry W. Cashdollar @larry0.bsky.social · 06/12/2023
www.akamai.com/blog/securit... #0day #malware
022
Reposted by Larry W. Cashdollar
foxinSOCKS5 @foxinsocks5.bsky.social · 13/10/2023
Moving over to bsky, need to rebuild all connections lost in the other platform. Never been a #FF person but Fri the 13th is just as good as any to start. @larry0.bsky.social @amyengineer.bsky.social @remyhax.bsky.social @quine.bsky.social @piratemoo.bsky.social @steved3.io @nullcookies.bsky.social
1101
Larry W. Cashdollar @larry0.bsky.social · 18/08/2023
www.akamai.com/blog/security-resear…
020