Reposted by metlstormKawaiicon @kawaiicon.bsky.social · 04/05/2026Kawaiicon is back for 2026 and while we get a lot done with volunteer help, Wellington City Council don't accept venue payment in high fives 🙏. The 2026 Kawaiicon Call for Sponsors is open! If you want a copy of our sponsor pack, throw us an email at kiwicon@kiwicon.org. 01618
Reposted by metlstormJoe Tidy BBC News @joetidy.bsky.social · 22/01/2026With my book launching in the US + Canada I joined @patrick.risky.biz & @metlstorm.risky.biz on the RiskyBiz pod. I've listened to these guys for 8yrs so it was an honour to chat through cyber news and explain why I decided to write a book about teenage hackers and the Vastaamo case. risky.biz 1112
metlstorm @metlstorm.risky.biz · 03/11/2025I am mad about @jags.bsky.social 's cat on the pod. Why does't Riskybiz have a pod-kitty?! 😾 381
metlstorm @metlstorm.risky.biz · 12/09/2025Lol its been a whlie since I last hit the "please write your card name, number, expiry and cvv in this pdf and email it back" ecommerce checkout flow. Such PCI! Very DSS. 🤦 Paging a QSA and an acquiring bank, cleanup aisle my card data 0110
Reposted by metlstormPatrick Gray @patrick.risky.biz · 04/07/2025Well, yeah. We're going to let our "kernel bug" description of Crowdstrike's mass murder of Windows systems stand 0151
Reposted by metlstormPatrick Gray @patrick.risky.biz · 04/07/2025Maybe we should stagger newsletter releases in ringed deployments so we can catch these egregious errors... you know, like they should have done with their shitty content update that wiped out 8.5m boxes! 3491
Reposted by metlstormPatrick Gray @patrick.risky.biz · 04/07/2025A Crowdstrike PR exec has written to us (twice) to demand we change some phrasing in one of our newsletters. We said a bug in their kernel driver caused their meltdown when it was actually a bad update file that caused a kernel panic. Huge mistake! 5251
Reposted by metlstormKawaiicon @kawaiicon.bsky.social · 19/06/2025It is that time! Call for Participation (CFP) time! Got a talk in mind? Done some cool research? Want to do something for hallway con? Want to be able to summon sparkle pots on cue? Submit to our CFP! Closes eventually, so just get your submission in now! kawaiicon.org/cfp/media.tenor.coma cartoon panda bear is holding a notebook and a pencil .Alt: a cartoon panda bear is holding a notebook and a pencil . 0138
metlstorm @metlstorm.risky.biz · 12/06/2025Omg, how is the webdav CVE-2025-33053 so dumb?! You make a .url shortcut file to run a local binary, with working-dir set to a webdav path, and if the binary happens to fork out to another bin without an absolute path, cwd is first in the search path... oh no? Is it.. is the bug really that stupid?! 2210
Reposted by metlstormPatrick Gray @patrick.risky.biz · 22/04/2025The most recent episode of Wide World of Cyber w @thekrebscycle.bsky.social and @stamos.org is back in our podcast feed... it was offline for a week(ish) due to the recent unpleasantness So yeah, it's back. If you missed it, here it is VIDEO: www.youtube.com/watch?v=JPYt... AUDIO: risky.biz/WWC8/youtube.comWide World of Cyber: How the Trump admin is changing the cybersecurity landscapeYouTube video by Risky Business Media 1284
Reposted by metlstormPatrick Gray @patrick.risky.biz · 11/04/2025I have cancelled our planned trip to the RSA Conference in San Francisco later this month. @metlstorm.risky.biz and I were headed over to record some live shows and see everyone. Unfortunately I have received advice that crossing the border into the United States right now would be a bad idea. 1615329
Reposted by metlstormPatrick Gray @patrick.risky.biz · 11/04/2025I've pulled down the most recent episode of Wide World of Cyber with Chris Krebs and Alex Stamos at the request of their employer SentinelOne, the sponsor of the series. I will say more about this in next week's Risky Business, but I want to make one thing clear: SentinelOne is not the bad guy here 7716
Reposted by metlstormbrsn @br-sn.bsky.social · 10/04/2025@metlstorm.risky.biz @patrick.risky.biz looks like rapid7 found a nice exploit strategy for that Ivanti BOF you discussed in the recent ep: attackerkb.com/topics/0ybGQ...attackerkb.comCVE-2025-22457 | AttackerKBOn April 3, 2025, Ivanti published an advisory for CVE-2025-22457, an unauthenticated remote code execution vulnerability due to a stack based buffer overflow.… 041
metlstorm @metlstorm.risky.biz · 26/03/2025If you've ever run into your ios exploit dev mate at the pub after work and they seem a lil crazy-eyed, you can kinda see why: googleprojectzero.blogspot.com/2025/03/blas...googleprojectzero.blogspot.comBlasting Past WebpAn analysis of the NSO BLASTPASS iMessage exploit Posted by Ian Beer, Google Project Zero On September 7, 2023 Apple issued an out-... 191
metlstorm @metlstorm.risky.biz · 26/03/2025This is real handy to have in the pocket when some family/acquaintance asks about a service or platform you yourself don't use. "Just click about and see if anyone has logged in as you" makes sense to us nerds, but for normies, this is helpful as! Thanks Lorenzo! 0163
Reposted by metlstormPatrick Gray @patrick.risky.biz · 21/03/2025We’re stoked to say Amberleigh Jack has joined Risky Biz full time as a producer and editor. Amberleigh has mountains of experience as a journalist and editor and she’s already such an important part of the team. She also has a deep connection to security via her (sadly departed) brother Barnaby 3533
metlstorm @metlstorm.risky.biz · 28/02/2025Jesus, I think rather than being booted outta FVEY, Canada’s spooks are gonna be more likemedia.tenor.comtwo men standing next to each other with the words lea may i be excused on the bottomALT: two men standing next to each other with the words lea may i be excused on the bottom 080
metlstorm @metlstorm.risky.biz · 19/02/2025Why you gotta be like this Cisco? Quote the url to get your "entitlement to a free upgrade" for a CVSS 10/10 bug in your product? Really? Thats where we're at with product security in 2025AD? SMDH. 🖕🌉🖕 3325