Sign in

Layer 8½

@mbrookspetersen.eurosky.social
68 followers 130 following 388 posts

Cybersecurity Awareness & Culture Specialist. Posting about #infosec and related people stuff. Opinions are my own.

PostsRepliesMedia
Layer 8½ @mbrookspetersen.eurosky.social · 2h
#CybersecurityAwarenessMonth This is Jeff. This is how he'll look for the next 31 days. Jeff will not blink. Jeff will be cyber aware. Will you? Because Jeff will know.
Jeff from the old DoD cyber training videos sitting at a computer in his white shirt and his blue sweater staring at you. His gaze is mostly dead with a judgemental remainder of devastating dissappointment.
Caption: Stares in Cyber Awareness
000
Reposted by Layer 8½
celine @cozylittle.house · 3h
We've improved our Leaflet onboarding!!! Now when you log in for the first time, you'll be greeted by this lil guy and find more guidance overall on how to start a publication and write your first post!!
a lil guy pops out of a bend in a hilly path. There is a speech bubble above him that says "Welcome to Leaflet!"
45012
Reposted by Layer 8½
Microsoft Threat Intelligence @threatintel.microsoft.com · 7h
Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed legitimate RMM software through meeting invitations, PDF-themed lures, software update prompts, and other social engineering content. msft.it/63326acCeC
msft.it
Phishing Abuses RMM Tools for Persistent Access | Microsoft Security Blog
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
121
Layer 8½ @mbrookspetersen.eurosky.social · 2h
You can switch to @eurosky.social #AppView in @skywalkerapp.bsky.social by entering that service string to keep on reading and skeeting when bluesky appview is down due to DDoS or other shenanigans. Mind: Bookmarks for example are kept on the appview and will not migrate.
000
Reposted by Layer 8½
B. Prendergast @renderg.host · 8h
@bsky.app is down? Didn't notice because I'm using the @eurosky.social appview in @mu.social ( enable it here → mu.social/settings/net... )
Choose the content service that supplies profiles, posts, and most feeds. This kind of service is sometimes called an AppView. This setting applies to every account on this device. Only use a content service you trust. Different services may return different content and apply different moderation policies.
311
Reposted by Layer 8½
Hannah Vardit @hannahvardit.bsky.social · 23h
i worry that men think being A Good Guy is dramatically and heroically intervening on behalf of an endangered woman and then being publicly rewarded on a grand scale when actually being A Good Guy is just usually saying, “hey man that’s not funny” or “wow that’s fucked up” and there is no reward
10114673172
Layer 8½ @mbrookspetersen.eurosky.social · 9h
Since writing this blog, I even more find myself tripping over saying security awareness. Because that's just not it. And in lack of a really better tem I then default to Human Factors (in Security) which is a mouthful and produces side-eyes and I'm also not convinced.
layer8-half.leaflet.pub
Security Awareness Shmawareness
Taking a look at the SANS Security Awareness & Culture Report 2026
011
Reposted by Layer 8½
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 15h
Lol, nice. Debian linux security update DSA 6528-1: "Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks." "Several", as in... 1,313 CVEs. Enjoy! ✌️ […]
mstdn.social
Original post on mstdn.social
275
Reposted by Layer 8½
Kenn White @kennwhite.bsky.social · 10h
So proud of this: real-time highly scalable distributed generalized database search on fully encrypted data, what we call Queryable Encryption is now out of beta. Culmination of 25+ years of academic work and 7 years of R&D engineering leadership under @senykamara.com and Tarik Moataz... (1/2)
1107
Layer 8½ @mbrookspetersen.eurosky.social · 11h
When you're doing crisis communication in your org because of a cybersecurity incident (or any other tbh), don't only address those you deem affected. People should know when they're not affected as well in order to minimize FUD-by-omission. "You're not affected. We'll update infos here" suffices.
000
Reposted by Layer 8½
Active Measures, LLC @activemeasures.bsky.social · 13h
before hype another programmer with psychosis from not touching grass comes forward consider
1227
Reposted by Layer 8½
GreyNoise @greynoise.io · 13h
A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24. 🔗 Full analysis: www.greynoise.io/blog/swarmin...
093
Reposted by Layer 8½
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 15h
Huh, who knew the jackasses behind Shiny Hunters ransomware group were not good people. “The 24-year-old Pepijn van der S., who was arrested on suspicion of involvement in the hacker group ShinyHunters on 15 September, is also suspected of an attempted provocation of two murders.”
rtl.nl
ShinyHunters-verdachte Pepijn van der S. ook verdacht van opdracht geven tot moorden
De 24-jarige Pepijn van der S. die 15 september was aangehouden op verdenking van betrokkenheid bij hackersgroep ShinyHunters, wordt ook verdacht van een poging van uitlokking van twee moorden.
21610
Reposted by Layer 8½
Schneier on Security @schneier.com · 17h
Using Device Linking to Eavesdrop on WhatsApp and Signal Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are…... www.schneier.com/blog/archives/2026…
schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany's Customs Office has been using these features to connect a police-controlled computer to a suspect's account.
163
Reposted by Layer 8½
Catalin Cimpanu @campuscodi.risky.biz · 18h
Meta pulled down Brazilian President Lula's Facebook page and blocked his campaign from running political ads but allows paid ads calling for a military coup It also didn't take down any of the right-wing disinformation campaigns reported in August novaramedia.com/2026/09/28/f...
novaramedia.com
Facebook Blocks Lula’s Campaign Ads Just Days Before Brazil Election
Meta briefly disabled ads on the Facebook page of Brazil’s leftwing president on Friday – just days before he faces a far-right challenger in national elections.
19955
Reposted by Layer 8½
Jens Lange @kommunaler-notbetrieb.de · 19h
Cyberangriff Berlin: Die Aufzeichnung der gestrigen Sitzung des Berliner Ausschusses für Digitalisierung und Datenschutz wurde heute veröffentlicht. Seit Mitte August hat der Senat keine weiteren Aktivitäten der Angreifer festgestellt. #ITSicherheit #Kommunen #Berlin
youtu.be
78. Sitzung des Ausschusses für Digitalisierung und Datenschutz am 28.09.2026
YouTube video by Abgeordnetenhaus von Berlin
132
Reposted by Layer 8½
Joe Tidy BBC News @joetidy.bsky.social · 20h
Bizarre update/ twist in the FBI hack case. The hackers - Shiny Hunters - are now saying that they won't publish the stolen data on their darknet site and actually 'never intended to'. They sent me and other reporters this ridiculous statement saying the media 'took the story out of context'.
2167
Reposted by Layer 8½
InfoSec @infosec.skyfleet.blue · 21h
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
thehackernews.com
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
011
Reposted by Layer 8½
Jessica Ellis @baddestmamajama.bsky.social · 29/09/2026
I have separated the art from the artist and am now whipping the art to stiff peaks, after which I will gently fold it into the artist before baking at 350 til golden and puffed
3243761035
Reposted by Layer 8½
InfoSec @infosec.skyfleet.blue · 28/09/2026
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
therecord.media
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
064
Layer 8½ @mbrookspetersen.eurosky.social · 28/09/2026
Thanks, I hate it.
121
Reposted by Layer 8½
Skywalker @skywalker.thereforeiam.eu · 28/09/2026
I see that the Bluesky app now automatically numbers posts in a thread in the view. I will implement that too in the next release. There would be no need for putting numbers in the posts themselves anymore when you write the thread.
1132
Reposted by Layer 8½
Raphael Satter @raphae.li · 28/09/2026
From @reuters.com: DUTCH POLICE: 24-YEAR-OLD MAN FROM AMSTERDAM WAS ARRESTED IN AN INVESTIGATION INTO THE HACKER GROUP SHINYHUNTERS
1117
Layer 8½ @mbrookspetersen.eurosky.social · 28/09/2026
Interesting.
inoti.fyi
File Notification Attacks
File notification attacks is a class of system-level side-channel attacks on filesystem notification APIs like Linux's inotify, Window's ReadDirectoryChangesW, and macOS' FSEvents API.
000
Reposted by Layer 8½
EULE (EU Linux Evolution) @eulinuxevolutionde.eurosky.social · 28/09/2026
Dateibenachrichtigungen: Forschende der TU Graz finden Schwachstellen in Windows, Linux, Android und macOS www.all-about-security.de/dateibenachr... #Linux #LinuxNews #LinuxDE #LinuxNewsDE #EULE #EULEde #Android #Windows #macOS
all-about-security.de
Sicherheitslücke in Dateibenachrichtigungen von Windows & Co.: Ein Überblick
Ein Team der TU Graz hat Sicherheitslücken in Dateibenachrichtigungen von Windows & Co. aufgedeckt. Erfahren Sie mehr darüber.
097
Reposted by Layer 8½
Joe Slowik @pylos.co · 28/09/2026
Threat intel acted on or disclosed is often threat intel lost - so how to balance long term collection with immediate needs? I tried exploring this a bit a few years ago… a discussion that I should do a deeper dive into. youtu.be/Cuhs4EJqxMw?...
youtu.be
The Disclosure Dilemma and Ensuring Defense
YouTube video by FIRST
093
Layer 8½ @mbrookspetersen.eurosky.social · 28/09/2026
Three weeks of heavy nightly cough for my child. Three weeks of bad and not enough sleep for us both. We're exhausted.
000
Reposted by Layer 8½
Taggart @taggart-tech.com · 27/09/2026
Today is very effectively making the argument for us at IFIN that TLP:CLEAR should be the *default*, and only extremely sensitive intelligence should be withheld. Active exploitation is not a reason to withhold, given the fact that more information always advantages defenders.
0114
Reposted by Layer 8½
Anuj Ahooja @quillmatiq.com · 27/09/2026
This is wild in many ways but... "DHH is known for controversial discussions, but this topped them all" I dunno, I'd argue the "murder the immigrants" rhetoric was a bit more controversial than what programming language this very rich lonely loser is using?
67212
Reposted by Layer 8½
Zack Whittaker @zackwhittaker.com · 27/09/2026
Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️
community.citrix.com
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, ...
0113
Reposted by Layer 8½
Zack Whittaker @zackwhittaker.com · 27/09/2026
Shoutout to the folks on that Citrix subreddit thread, the security researchers validating the bugs, and the random IT teams who proactively reached out to affected NetScaler customers over the weekend, all of whom did a far better job at mitigating the damage before Citrix joined the party.
2182
Reposted by Layer 8½
Catalin Cimpanu @campuscodi.risky.biz · 27/09/2026
Journalists have tracked down two employees of Kremlin disinformation group Rybar to villas near Berlin, Germany, with the two living comfortably and safe in the decadent EU they villainize each day correctiv.org/aktuelles/ru... istories.media/news/2026/09...
correctiv.org
Russischer Kriegskanal Rybar operiert von Berlin aus
Der russische Propaganda-Kanal „Rybar“ erreicht 1,5 Millionen Nutzer und ist in der EU sanktioniert. Zwei Mitarbeiter des Kanals wohnen trotzdem in Berlin.
076
Reposted by Layer 8½
KeePassXC @keepassxc.org · 23/09/2026
🎉 We're happy to announce #KeePassXC version 2.8.0-beta1! This is the first test release of our next major update, which brings you an upgrade to Qt6, Auto-Type on Wayland, remote sync, ARM64 builds for Windows, and much more. More info and download links on our blog: keepassxc.org/blog/2026-09...
keepassxc.org
KeePassXC 2.8.0 (Beta 1) released – KeePassXC
KeePassXC Password Manager
14213
Reposted by Layer 8½
Ron Deibert @rondeibert.bsky.social · 27/09/2026
At @citizenlab.ca we spend enormous time labouring over the ethical and legal limits to our investigative methods (for good reason!) If we didn't, we'd surely be shut down. Meanwhile AI platforms routinely unleash their systems to hack left, right and centre *without consequence* 🤷‍♂️
12410
Reposted by Layer 8½
Zack Whittaker @zackwhittaker.com · 27/09/2026
Solid reporting here on the ongoing Citrix shituation.
1204
Reposted by Layer 8½
Zack Whittaker @zackwhittaker.com · 27/09/2026
I'm fine with Shitrix, for what it's worth. Also, Citrix (Shitrix) is still run by CEO Tom Krause, a former DOGE staffer who worked for Elon Musk to lead the clusterfuck of destruction at the Treasury. If anyone's to blame for Citrix's shitty technology and years of layoffs, it's Tom Krause.
2234
Reposted by Layer 8½
Catalin Cimpanu @campuscodi.risky.biz · 27/09/2026
A Dutch security non-profit involved in responsible vulnerability disclosure says it was hacked by an AI agent www.linkedin.com/posts/securi...
linkedin.com
Security people always say it's not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we're the hackers that got hacked. We noticed suspicious ac...
Security people always say it's not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we're the hackers that got hacked. We noticed suspicious activity, ...
1155
Reposted by Layer 8½
Jens Lange @kommunaler-notbetrieb.de · 27/09/2026
(Vor-)Warnung zu Citrix NetScaler: Die Hinweise auf eine bislang ungepatchte Zero-Day-Schwachstelle verdichten sich. Sicherheitsforscher Kevin Beaumont schreibt, die Lücke sei real und werde bereits aktiv ausgenutzt. Einen Patch gibt es derzeit noch nicht. #ITSicherheit #NetScaler
cyberplace.social
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 1 image There are rumours swirling for the past week behind the scenes that there are two actively exploited zero days in Citrix Netscaler. The rumours have now broken containment to Reddit...
121
Reposted by Layer 8½
Catalin Cimpanu @campuscodi.risky.biz · 27/09/2026
JADEPUFFEr, the AI-powered ransomware group, is destroying Azure environments as part of its extortion campaigns, most likely to put pressure on victims www.microsoft.com/en-us/securi...
microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and prov...
1108
Reposted by Layer 8½
Lisa Forte @lisaforte.bsky.social · 26/09/2026
Found in a lead mine. It’s not a lack of security it’s just misalignment 😂😂😂 that’s how it works now right!?!
371
Reposted by Layer 8½
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Layer 8½ @mbrookspetersen.eurosky.social · 26/09/2026
Not great that Germany is reliably making headlines like these now on a regular basis. No, it's not just AfD.
000
Reposted by Layer 8½
Joe Tidy BBC News @joetidy.bsky.social · 26/09/2026
Inside the FBI hack: Agents fearful and angry after 'dangerous' data breach. I've spoken to current/ former FBI agents who have expressed shock, fear and anger following a hack that appears to have exposed the private and personal information of the agency's entire workforce. "This is really bad..
1137
Reposted by Layer 8½
Brian Honan @brianhonan.bsky.social · 26/09/2026
Stop saying the agents are “acting improperly” or that the agents “went rogue”. AI agents are software. The agents just follow the instructions given to them. It was OpenAI who failed in ensuring their agents were controlled properly
42418
Reposted by Layer 8½
Dr. Christopher Kunz @christopherkunz.bsky.social · 26/09/2026
RE: infosec.exchange/@watchTowr/1173383… And the next "turn off your appliances NAU" type of advisory, if one can believe the rumors.
infosec.exchange
watchTowr (@watchTowr@infosec.exchange)
Angehängt: 1 Bild We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the limited information available is credible, and we are thus imploring organizations to take it seriously. Active watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
021
Reposted by Layer 8½
❌👑 Bernadette🫘🟧💙🐈‍⬛ @vintageknits.bsky.social · 26/09/2026
359392
Layer 8½ @mbrookspetersen.eurosky.social · 26/09/2026
OpenAI b̶o̶t̶s̶ meddled with multiple US government agency sites
010
Reposted by Layer 8½
EuroAlternative @euroalternative.eu · 26/09/2026
Project management tools usually stop at tickets and boards. YouTrack goes further, folding in a knowledge base and customer support alongside the tracker itself. Free for teams of up to 10. euroalternative.eu/youtrack
euroalternative.eu
YouTrack: European Alternative to ClickUp, Jira and Trello
Comprehensive project management platform combining task tracking, knowledge base, customer support, and team collaboration. Free for up to 10 users.
0102
Reposted by Layer 8½
IntelFusions @intelfusions.com · 26/09/2026
A Firefox add-on posing as a PDF identity checker shipped with no malicious code at all, then downloaded instructions after install to hijack victims' Google accounts. Few people installed it, but the design is built to slip past store review. #databreach #infosec
intelfusions.com
Firefox add-on hid its malware until after you installed it
Cyber Incidents · IntelFusions threat intelligence
012