Sign in

Layer Old½

@layer8-half.eurosky.social
35 followers 90 following 78 posts

I'm a Security Awareness & Culture Specialist. This account will soon be deactivated and my publishing will continue on mbrookspetersen.eurosky.social.

PostsRepliesMedia
Layer Old½ @layer8-half.eurosky.social · 24/07/2026
Last notice: This account will be deleted soon. Find me @mbrookspetersen.eurosky.social
010
Layer Old½ @layer8-half.eurosky.social · 04/07/2026
👀
011
Reposted by Layer Old½
Layer Old½ @layer8-half.eurosky.social · 03/07/2026
I deleted my leaflet publication. I will be up and running again soon. @leaflet.pub : any idea, when the subdomain will be available again after deleting the publication?
221
Reposted by Layer Old½
Layer Old½ @layer8-half.eurosky.social · 03/07/2026
Since it is not possible to change the DID (expeted) or to migrate account data this account will be deleted shortly and I will continue all this on a new account. I'll keep you few posted.
211
Reposted by Layer Old½
InfoSec @infosec.skyfleet.blue · 03/07/2026
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
theregister.com
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
032
Reposted by Layer Old½
Leaflet @leaflet.pub · 02/07/2026
New: image galleries, lightboxing, and more — great for photos, illustrations, comics & other visual publishing! 🌅🌆🌉🏞️🎆🏙️ 🔸 image gallery block with three modes: grid, carousel, strip 🔺 lightboxing for both galleries & single images 🔹 *also* improved alt text & made it easier to add cover images
17017
Reposted by Layer Old½
Catalin Cimpanu @campuscodi.risky.biz · 02/07/2026
A threat actor has deployed an AI agent to hack Langflow servers, steal credentials, expand access, and then deploy ransomware on production databases The attacks are the first known cybercriminal campaign to be fully automated using an AI agent from start to finish www.sysdig.com/blog/jadepuf...
sysdig.com
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig
The Sysdig TRT documents JADEPUFFER: the first known agentic ransomware operation, where an LLM autonomously exploited Langflow, harvested credentials, and executed full database extortion.
1105
Reposted by Layer Old½
Bundesamt für Sicherheit in der Informationstechnik (BSI) @bsi.bund.de · 02/07/2026
🎵 Ihr seid gut genuuuuuuug. Ihr seid gut genuuuuuug. 🎶 Fehler gehören zum Alltag, auch im digitalen Raum. Wir vom BSI sind für euch da & helfen euch mit unseren Tipps & Tricks durch die kleinen & großen Cyber-Pannen. Gemeinsam im #TeamBSI, für mehr #Cybersicherheit & die #CybernationDeutschland. 🫶
Gemälde einer erschöpften Person, die mit dem Kopf auf einem Holztisch liegt. Darüber steht der Text: „Reminder des Tages: Ihr seid gut genuguuuug! Auch wenn ihr manchmal … “.Grafik mit violettem Textfeld auf hellviolettem Hintergrund mit dezenten Binärzahlen. In weißer Schrift steht: „…Passwörter sichtbar am Arbeitsplatz liegen lasst.“Lila Hintergrund mit einem dunkleren Rechteck in der Mitte. Darauf steht in weißer Schrift: „… die Aktivierung der Zwei-Faktor-Authentisierung vergesst.“Lila Hintergrund mit einem dunkleren Rechteck in der Mitte. Darauf steht in weißer Schrift: „… Spam-Inhalte nicht sofort erkennt.“
172
Reposted by Layer Old½
Catalin Cimpanu @campuscodi.risky.biz · 02/07/2026
AirDrop and Quick Share have some common bugs Attackers need to be within 10 to 30 meters of a target to exploit the bugs No pairing, authentication, or user interaction is needed www.helpnetsecurity.com/2026/06/30/a... arxiv.org/abs/2606.26967
helpnetsecurity.com
AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin - Help Net Security
Six AirDrop Quick Share vulnerabilities span iOS, macOS, Android, and Windows, affecting protocols on over five billion devices.
053
Reposted by Layer Old½
Kevin Beaumont @doublepulsar.com · 02/07/2026
Microsoft's played a blinder with this one btw. Copilot is in almost everywhere now. Microsoft are throwing billions at it each month subsidising it to hook orgs. I'll give you a spoiler: orgs are going to get a bill they can't afford in the future.
1225
Reposted by Layer Old½
Kevin Beaumont @doublepulsar.com · 02/07/2026
If major US banks can't afford staff GenAI usage already - these organisations have deep deep deep pockets - good luck to organisations that haven't upgraded from Windows 7 yet. Which is a lot of organisations.
14311
Reposted by Layer Old½
Catalin Cimpanu @campuscodi.risky.biz · 02/07/2026
Threat actors are mass-scanning the internet for misconfigured LLM backend servers. Mass-reconnaissance campaigns have been spotted targeting Ollama, LiteLLM, Langserv, and OpenClaw infrastructure labs.zenity.io/p/scanning-f...
labs.zenity.io
Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild
056
Reposted by Layer Old½
Schneier on Security @schneier.com · 02/07/2026
Cybersecurity Mission Creep in the US Interesting paper: "Cybersecurity Mission Creep." Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of… www.schneier.com/blog/archives/2026…
schneier.com
Cybersecurity Mission Creep in the US
Interesting paper: "Cybersecurity Mission Creep." Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls "cybersecuritized." Before this reframing, these issues present as important but not existential.
094
Reposted by Layer Old½
Catalin Cimpanu @campuscodi.risky.biz · 02/07/2026
The Gentlemen ransomware group has been spotted abusing a zero-day in the Kontron API driver (ktapi.sys) to disable EDR products on the networks they're attacking expel.com/blog/not-ver...
expel.com
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs
How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.
1105
Reposted by Layer Old½
Matthew Gracie @infosecgoon.bsky.social · 01/07/2026
043
Reposted by Layer Old½
Microsoft Threat Intelligence @threatintel.microsoft.com · 01/07/2026
AI is accelerating vulnerability research, enabling defenders to find and prioritize issues faster while also lowering barriers for threat actors. As these capabilities become more accessible, cybersecurity experts expect vulnerability volume to continue growing. msft.it/63325vtZAT
121
Reposted by Layer Old½
ThreatInsight @threatinsight.proofpoint.com · 01/07/2026
Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.
111
Reposted by Layer Old½
AlexSa @netalexx.bsky.social · 01/07/2026
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website Run Code on Your PC
amibeingpwned.com
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website Run Code on Your PC
Signer.Digital's browser extension and its native helper turned a path-traversal bug into drive-by remote code execution on Windows. Any web page you visited could load an attacker DLL into a process ...
011
Reposted by Layer Old½
Rowenna. 2 ‘n’s. Ro-WEN-na. @missiggeek.bsky.social · 01/07/2026
I’ve created a toolkit for tackling the missing piece of (most) DPIAs - impact assessment itself! If you’re interested in spotting hazards and preventing harm, please sign up to this free, open-access webinar where I’ll be showcasing and explaining what I’ve put together theodi.org/news-and-eve...
theodi.org
Data Ethics Professional #14: A smarter way to spot data & AI harms
The ODI was founded in 2012 by Sir Tim Berners-Lee and Sir Nigel Shadbolt, placing us at the heart of the data economy. Our primary mission is to foster transparency, accountability, and innovation th...
042
Reposted by Layer Old½
marktsec @marktsec.bsky.social · 01/07/2026
🧵 1/ A newly advertised ransomware operation, SevyWare RaaS, is promoting an unusual addition to its affiliate offering: "Violence as a Service." #ThreatIntel #Ransomware
111
Reposted by Layer Old½
InfoSec @infosec.skyfleet.blue · 01/07/2026
This phishing kit looks more like BEC-as-a-service
cyberscoop.com
This phishing kit looks more like BEC-as-a-service
Cisco Talos has uncovered ARToken, a full-fledged "BEC-as-a-service" platform linked to EvilTokens that uses sophisticated AI lures to hijack corporate accounts.
011
Reposted by Layer Old½
Florentine Dömges @fdoemges.bsky.social · 29/06/2026
Das KI-Strategiepapier das gerade alle Eliten lesen verschweigt die einzige KI-Architektur die der Bevölkerung nützt. Nicht aus Versehen. Die Autoren verdienen an der Alternative nichts. 🧵
23617
Reposted by Layer Old½
𝖈0𝖗𝖊𝖉𝖚𝖒𝖕𝖊𝖉 @c0redumped.bsky.social · 01/07/2026
Good morning dear amazing Blueskyroonies of this n that☕🌞 Odinsday, cloudy morning but r clearing up, just a few days til weekend now😉 I wisv yous a superb day full of happiness, kindness, optimism, love, camaradery, insight, magic, funs, joys, smiles, giggles n laughter😊🤙 #MorningGreetings
Comics like drawed Cat in an armchair n the incoming sunlight from a window, a steamy much of hot beverage on table infront.
Text;
Be enough for yourself first,
the rest of the world can wait
191
Reposted by Layer Old½
James Wilson @jameswilson.io · 30/06/2026
Mythos on your desk. Source-local code reviews with frontier-like capabilities. Karsten Nohl and I talked for an hour about this in the latest Risky Business Features episode available now on YouTube and your favourite Podcast app. 🎧 risky.biz/RBFEATURES30/ 📺 www.youtube.com/watch?v=nhS5...
risky.biz
Mythos on your desk? Using local LLMs for code reviews - Risky Business Media
In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code [Read More]
041
Reposted by Layer Old½
Ben Collins @bencollins.bsky.social · 01/07/2026
Not a great economy alert! Wall Street Bets users think Palantir spiked today because The Onion story titled “Palantir Acquires Pentagon for $800 Billion” hit their front page. They’re guessing trading bots indexed the top post on the subreddit reddit not understanding source.
A chart showing an immediate spike after the headline hit the front page of Wall Street Bets.
480150713213
Reposted by Layer Old½
Graham Cluley @grahamcluley.com · 30/06/2026
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered emergency relief-themed domains in just five days. Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Scammers race to cash in on Venezuelan earthquake disaster
When a devastating earthquake struck north central Venezuela last week, rescue teams were not the only ones who mobilised fast.
176
Reposted by Layer Old½
Bundesamt für Sicherheit in der Informationstechnik (BSI) @bsi.bund.de · 30/06/2026
Wir haben die Technische Richtlinie TR-03188 „Passkey Server“ veröffentlicht. 🤓 Sie richtet sich an alle, die eine Website betreiben. Ziel ist es, Passkeys als Stand der Technik zu definieren. Mehr dazu findet ihr hier: 👉 www.bsi.bund.de/dok/1199376
Zu sehen ist ein Schlüssel auf dunklen Hintergrund der abstrakt dargestellt wurde. Der Schlüssel hat die Anmutung einer Plantine. Auf blauem Hintergrund steht in weisser Schrift: BSI veröffentlicht TR-03188 "Passkey Server"
0162
Reposted by Layer Old½
marktsec @marktsec.bsky.social · 30/06/2026
🧵1/ Since its public debut in early June, the emerging VOLTA MaaS stealer has maintained a rapid development cadence, with 6 public updates released in less than a month. Below is a timeline of its development 👇 #ThreatIntel #infosec
121
Reposted by Layer Old½
CCC @ccc.de · 30/06/2026
EU-US Framework: The US is not an “adequate” country when it comes to the protection of personal data, the US Supreme Court just blew it up. EU Commission must repeal the EU-US deal! noyb.eu/en/us-suprem...
noyb.eu
US Supreme Court just blew up EU-US Data Transfers
The US Supreme Court decided that the US Federal Trade Commission (“FTC”) may not be independent anymore - with major implications for EU-US Data Transfers.
06136
Reposted by Layer Old½
Dr. Christopher Kunz @christopherkunz.bsky.social · 30/06/2026
So this kind of flew under my radar during the hot weekend. It seems that one of the two owners of Mullvad made a € 450K donation to the Örebro party, a populist party with a strong "Sweden for the Swedes" & "we support remigration" sentiment. [1/2]
154
Reposted by Layer Old½
Jens Lange @kommunaler-notbetrieb.de · 30/06/2026
In Schriesheim führte die Überhitzung zentraler Server dazu, dass zeitweise keine IT-gestützten Dienstleistungen und keine telefonische Erreichbarkeit mehr möglich waren. Betroffen waren neben der Verwaltung auch Schulen, Bibliothek, Feuerwehr und Kindergärten. #ITSicherheit #Kommunen
kommunaler-notbetrieb.de
Stadtverwaltung Schriesheim – Kommunaler Notbetrieb
142
Layer Old½ @layer8-half.eurosky.social · 30/06/2026
People who liked this claim where also intersted in • masculinity is in danger • people don't want to work anymore
000
Reposted by Layer Old½
InfoSec @infosec.skyfleet.blue · 29/06/2026
Anonymous researcher drops 0-day 'exploitarium' repo
theregister.com
Anonymous researcher drops 0-day 'exploitarium' repo
011
Reposted by Layer Old½
Silas Cutler @silascutler.bsky.social · 29/06/2026
The past few months have been incredible in the malware analysis space. AI has enabled a lot of folks to rapidly catch up in this space to where top researchers were about 5 years ago. The pace has wildly increased, but what I'm seeing set the leaders in this space is depth.
1166
Reposted by Layer Old½
Lukas Pitschl @lukele.gpgtools.com · 29/06/2026
Who could have possibly seen it coming that the problem will not be AI taking over the world but instead assholes ruining everything themselves again, without any AGI necessary.
0277
Reposted by Layer Old½
Jennifer (JJ) Minella @jjx.therealjj.com · 29/06/2026
🚨 FortiGate admins: Stop and check 2 things TODAY: 1️⃣ Unexpected admin logins, config exports & config changes 2️⃣ Are ALL admin accounts using PBKDF2—not legacy SHA-256 hashes? That second one is a much bigger deal than most #FortiBleed coverage suggests. Details 👇 www.linkedin.com/feed/update/...
linkedin.com
#fortigate #fortibleed #firewalls #cybersecurity #sha256 #pbkdf2 #cryptography #securityuncorked | Jennifer Jabbusch
FORTIGAGTE ADMINS, PLEASE CHECK THESE 2 THINGS If you're responsible for FortiGate firewalls, I'd recommend taking 10 minutes today to check these two things. After digging through the FortiBleed r...
132
Reposted by Layer Old½
Joe Uchill @joeuchill.bsky.social · 29/06/2026
"Could" lead to arson? People set their own stuff on fire for insurance money all the time.
131
Reposted by Layer Old½
marktsec @marktsec.bsky.social · 29/06/2026
🧵1/ The developers behind the Stealc malware have announced the sale of the complete Stealc v2 source code ahead of the planned v3 release. According to the advertisement, only two copies of the source code will be sold for $60,000 each. #ThreatIntel #Malware #secops
145
Layer Old½ @layer8-half.eurosky.social · 28/06/2026
👀👀👀
000
Reposted by Layer Old½
AlexSa @netalexx.bsky.social · 28/06/2026
OMG it's true #Mullvad is far-right. Free speech my ass
flamman.se
Techprofil ger miljoner till Örebropartiet
It-bolaget Mullvads grundare donerade fem miljoner – till parti som vill se ”storskalig återvandring”
011
Reposted by Layer Old½
Jens Lange @kommunaler-notbetrieb.de · 28/06/2026
Kurzer Reminder, warum „wir nutzen das Produkt nicht" nicht dasselbe ist wie „uns betrifft das nicht": SpyCloud Labs hat bei FortiBleed nicht nur den Leak angesehen (gültige VPN-Zugänge für 74.000 FortiGate-Firewalls), sondern die Server der Täter selbst. 🧵
spycloud.com
More Than a Leak: What SpyCloud Found Inside the FortiBleed Threat Actor Infrastructure
Cybercrime research on the FortiBleed campaign reveals 73,932 compromised Fortinet firewalls – plus Synology devices, Sophos firewalls & MSSQL servers. Get the full picture.
122
Layer Old½ @layer8-half.eurosky.social · 28/06/2026
Reading about Cybetcrime-as-a-Service like this one now always reminds me of @jameswilson.io s remarks on TeamPCP: These are people who enjoy building big reliable systems. As defenders, we not only face AI augmentation and commmoditization of cybercrime tools but also a kind of passion 🧵1/2
110
Reposted by Layer Old½
marktsec @marktsec.bsky.social · 28/06/2026
🧵1/ A new update to the ErrTraffic ClickFix framework was recently advertised on a Russian-language cybercrime forum. The release focuses less on new delivery techniques and more on scaling affiliate operations. #ThreatIntel #ClickFix #infosec
154
Reposted by Layer Old½
Maia George @maiageorge.bsky.social · 28/06/2026
Ich habe mal viele Jahre in einem Land gelebt, wo 35°-40° Alltag waren. Und ich merke hier in Deutschland, was für eine große Rolle eine an Hitze angepasste Kultur spielt. Diese Kultur ist für mich selbstverständlich. Aber hier nicht. Ich möchte ein paar Beobachtungen mit euch teilen. 🧵
702047814
Reposted by Layer Old½
rekdt @rekdt.com · 30/04/2026
Mad at your favorite software for requiring you to upload a photo of your ID?? Get revenge by uploading a photo of your credit card instead Welcome to PCI DSS, bitch
143
Reposted by Layer Old½
Secure ICS OT @secure-ics-ot.bsky.social · 27/06/2026
When IT manages all the layers of security.
051
Reposted by Layer Old½
Rosamunde Van Brakel @rosamundevb.bsky.social · 27/06/2026
‘Our new paper offers a rare look inside the “black box” of algorithmic hiring, showing that these tools increase racial bias and shut the same people out of jobs everywhere they apply’ hai.stanford.edu/news/ai-hiri...
hai.stanford.edu
AI Hiring Tools Can Yield Racial Bias and Systemic Rejection | Stanford HAI
The first large-scale study of hiring algorithms in the wild finds concerning patterns to how systems reject candidates.
0115