Sign in

Patrice <GomoR> Auffret

@patriceauffret.bsky.social
161 followers 131 following 18 posts

ONYPHE founder, CEO and CTO - FreeBSD & Perl sculptor rather than GNU/Linux & Python - My views are those of my employer

PostsRepliesMedia
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 29/12/2025
📣 ANNOUNCEMENT: we have reached the 2,100+ scanned ports milestone, at Internet scale with a weekly refresh rate. Next step: 5,000+ ports, weekly refresh. Then 10,000 by end of next year. We will be the competitor number 1 to @censys.bsky.social in 2026. #ASM #CTI #ASD
022
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 28/12/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #MongoDB product: CVE-2025-14847: remote unauthenticated memory reading #MongoBleed search.onyphe.io/search?q=cat...
031
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 11/11/2025
Perl
000
Reposted by Patrice <GomoR> Auffret
Olivier Poncet 🦝 @ponceto91.bsky.social · 09/11/2025
RustScan est un outil de scan de ports écrit en Rust. Il mise tout sur la rapidité et se veut scanner l'ensemble des ports d'une machine en quelques secondes ⬇️ github.com/bee-san/Rust...
github.com
GitHub - bee-san/RustScan: 🤖 The Modern Port Scanner 🤖
🤖 The Modern Port Scanner 🤖. Contribute to bee-san/RustScan development by creating an account on GitHub.
0144
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 03/06/2025
Cc @onyphe.io
000
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 28/04/2025
The electrical power outage in Spain and Portugal as seen from the Internet (France included for reference)
A chart showing Internet scan data plots for three countries; Spain, Portugal and France. The three lines are stable, with minor variations from 09:00 to 12:30. At 12:30 the lines for  Spain and Portugal drop almost vertically to roughly 50% of their original levels. The line for France continues as for the start of the day.
The lines for Spain and Portugal have not returned to their original levels.
022
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 10/04/2025
Patch management is a multi-decade failure.
000
Reposted by Patrice <GomoR> Auffret
Pierre Arlais @pierrearlais.bsky.social · 23/03/2025
0269
Reposted by Patrice <GomoR> Auffret
InfoSec @infosec.skyfleet.blue · 19/03/2025
VPN Vulnerabilities Emerges As The Key Tool for Threat Actors to Attack Organizations
cybersecuritynews.com
VPN Vulnerabilities Emerges As The Key Tool for Threat Actors to Attack Organizations
064
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 18/03/2025
The latest version of our cli tool has been released. Get v4.19.0 and find wrappers with sweet new APIs inside. Available here ➡️ search.onyphe.io/docs/onyphe-... or here 🐳 hub.docker.com/r/onyphe/ony... or even here 🥷 metacpan.org/dist/Onyphe
search.onyphe.io
Installation | ONYPHE
Installation
032
Reposted by Patrice <GomoR> Auffret
Regis Le Guennec @regisleguennec.bsky.social · 04/03/2025
🧙‍♀️Cc @fs0c131y.com @gazlacrymo.fr @hacker0x01.bsky.social @gandalfistari.bsky.social @jnocetti.bsky.social @korben.info @tariqkrim.bsky.social @reesmarc.bsky.social @jeromenotin.bsky.social @oliviertesquet.bsky.social @patriceauffret.bsky.social @untersin.gr ça devrait t’intéresser 🪄
021
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 03/03/2025
Mais il a bien dormi.
000
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 14/02/2025
Oui enfin, c'est comme un moustique qui s'écrase contre le pare-brise d'une voiture.
000
Reposted by Patrice <GomoR> Auffret
InfoSec @infosec.skyfleet.blue · 14/02/2025
RedMike Hackers Exploited 1000+ Cisco Devices to Gain Admin Access
cybersecuritynews.com
RedMike Hackers Exploited 1000+ Cisco Devices to Gain Admin Access 
043
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 14/02/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #PaloAltoNetworks PA product: CVE-2025-0108: authentication bypass on management interface search.onyphe.io/search?q=cat... Thanks to @assetnote.io for having shared the detection method.
063
Reposted by Patrice <GomoR> Auffret
James Atack @jamesatack.com · 12/02/2025
Yet by performing an awkward legal waltz around the subject, Talos have helpfully supported my hypothesis that compromised IOS XE devices are part of an ORB network serving multiple APTs. archive.hack.lu/hack-lu-2024...
archive.hack.lu
The XE Files - Trust No Router hack.lu 2024
On the 16th October 2023 Cisco Talos shared intelligence about a handful of compromised routers discovered while resolving customer support requests. As the full story unfolded, a handful of backdoore...
122
Reposted by Patrice <GomoR> Auffret
Léαlinux 🐧 @lea-linux.org · 26/01/2025
"Command & Conquer : Red Alert" en version Open source : www.openra.net
openra.net
OpenRA
Classic strategy games rebuilt for the modern era
12610
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 20/01/2025
Roughly same numbers as @onyphe.bsky.social
010
Reposted by Patrice <GomoR> Auffret
@G4l4drim @g4l4drim.bsky.social · 20/01/2025
Back in the dayz the fake exploit did "rm -rf /" www.trendmicro.com/en_us/resear... #CTI
trendmicro.com
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
Our blog entry discusses a fake PoC exploit for LDAPNightmare (CVE-2024-49113) that is being used to distribute information-stealing malware.
021
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 17/01/2025
More than 50k *vulnerable* devices. This one is pretty bad.
010
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 02/01/2025
Don't expose DCERPC protocol on the Internet.
010
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 12/12/2024
Je plussoie.
000
Reposted by Patrice <GomoR> Auffret
Laurent Cheylus @lcheylus.bsky.social · 09/12/2024
FreeBSD 14.2-RELEASE now includes OCI-compatible images, and the Podman toolkit is ready to use them, on both amd64 and arm64 systems - A brief Introduction by Dave Cottlehuber #FreeBSD #BSD
people.freebsd.org
A Brief Introduction to OCI Containers on FreeBSD - Random Musings
O for a muse of fire, that would ascend the brightest heaven of invention!
053
Reposted by Patrice <GomoR> Auffret
Legrugru @legrugru.fr · 09/12/2024
répondez à vos emails putain dire que j'ai connu un temps où les gens répondaient à un FAX
12603
Reposted by Patrice <GomoR> Auffret
stacksmashing @stacksmashing.bsky.social · 08/12/2024
Stop. Truncating. Hashes. www.phoronix.com/news/OpenWrt...
2. **Truncated SHA-256 Hash Collisions**: The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache and deliver compromised images to unsuspecting users.
3236
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 06/12/2024
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Mitel MiCollab product: CVE-2024-35286: unauthenticated SQL injection on login page CVE-2024-41713: unauthenticated arbitrary file read www.onyphe.io/search?q=cat...
052
Reposted by Patrice <GomoR> Auffret
Renaud Lifchitz ⠵ @nono2357.bsky.social · 28/11/2024
#Cyberattaques : une étude dévoile la porte d'#entrée préférée des #ransomwares www.01net.com/actualites/cyberattaq…
001
Reposted by Patrice <GomoR> Auffret
GZY ⍼ גז"י @gamzehyaavor.bsky.social · 29/08/2024
Optimist: the cup is 1/2 full Pessimist: the cup is 1/2 empty Excel: the cup is January 2nd
6863351464
Reposted by Patrice <GomoR> Auffret
Cedric Pernet @cedricpernet.bsky.social · 21/11/2024
I just reached 1k followers on #Bluesky - It has been growing pretty fast. Starting to believe the place will be as cool as the old #Twitter ! Thx everyone ! <3
171
Reposted by Patrice <GomoR> Auffret
Murielle S @frenchieinlimbo.bsky.social · 20/11/2024
I'm so ever tactful 😆
1249
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 19/11/2024
"Additionally, the vulnerability is not remotely exploitable over the open internet. This means the actor would already need to have access to the internal network" Are you serious?!?
000
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 19/11/2024
Users urges D-Link to provide patches for their unfixed routers.
000
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 19/11/2024
Ça commence à ressembler a quelque chose ici. Masse critique atteinte ?
040
Reposted by Patrice <GomoR> Auffret
ONYPHE @onyphe.io · 19/11/2024
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #PaloAltoNetworks PA product: CVE-2024-0012: authentication bypass on mgmt interface CVE-2024-9474: authenticated (bypassed) RCE on mgmt interface www.onyphe.io/search?q=cat...
063
Reposted by Patrice <GomoR> Auffret
James Atack @jamesatack.com · 19/01/2024
Using @onyphe.bsky.social I count 4758 unique vCenter Servers on the Internet. onyphe -export 'category:datascan device.product:"vcenter server" | uniq ip,port,forward | addcount | output' You could also search by cpe, or by vendor, or use a full-text search dork if you really wanted to 😉
022
Reposted by Patrice <GomoR> Auffret
M82 @m82.eurosky.social · 07/11/2023
📢 notez la date ! 22 Novembre, notre célèbre rendez-vous des rencontres de la grenouille @m82.bsky.social sera une rainette (à Rennes donc...) Avec @g0ul4g.bsky.social et @patriceauffret.bsky.social ! Inscription ici ⬇️ www.helloasso.com/associations...
helloasso.com
La reinette du 22 novembre
Conférence organisé·e par M82 project à Rennes - Les rencontres cyber du M82 project proposent des échanges conviviaux autours des questions de cybersécurité, cyberdéfense et lutte contre la ...
054
Reposted by Patrice <GomoR> Auffret
cybart.eurosky.social @cybart.eurosky.social · 07/11/2023
Un belle soirée en perspective à Rennes avec @g0ul4g.bsky.social et @patriceauffret.bsky.social www.helloasso.com/associations...
helloasso.com
La reinette du 22 novembre
Conférence organisé·e par M82 project à Rennes - Les rencontres cyber du M82 project proposent des échanges conviviaux autours des questions de cybersécurité, cyberdéfense et lutte contre la ...
274
Reposted by Patrice <GomoR> Auffret
James Atack @jamesatack.com · 17/10/2023
This afternoon #ONYPHE identified 71K unique IPs exposing a webui vulnerable to #CVE-2023-20198 in 201 different countries That's the Cisco ios XE vuln, CVSS 10, actively exploited with no patch. What can you say? sec.cloudapps.cisco.com/security/cen... www.onyphe.io @patriceauffret.bsky.social
141
Reposted by Patrice <GomoR> Auffret
Bruno Tréguier @bruno.treguier.org · 27/09/2023
Coucou les gens du ciel bleu ! Pour info, Unlock Your Brain 2023, c'est parti ! Les early birds sont en vente ! Saisissez votre ticket... 😉 pretix.eu/cantine/UYBH...
pretix.eu
Unlock Your Brain, Harden Your System #UYBHYS !
3 novembre 2023 – 4 novembre 2023
2810
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 05/10/2023
@jamesatack.bsky.social welcome James :)
110
Reposted by Patrice <GomoR> Auffret
Baptiste Robert @fs0c131y.com · 28/09/2023
Les jours passent et ne se ressemblent pas ! Merci à éric bothorel pour l’organisation de la conférence “Tech Against Terrorism” à l’Assemblée nationale Merci à RISKINTEL MEDIA et aux copains de Sesame it pour les échanges et le bon moment !
021
Reposted by Patrice <GomoR> Auffret
The Washington Post @washingtonpost.com · 26/09/2023
These companies are using techniques developed by NASA to capture the naturally produced CO2 and dissolve the molecules into their products.
washingtonpost.com
Breweries are starting to capture carbon — from beer
These companies are using techniques developed by NASA to capture the naturally produced CO2 and dissolve the molecules into their ales and beers.
06422
Reposted by Patrice <GomoR> Auffret
The Washington Post @washingtonpost.com · 25/09/2023
In March 2022, temperatures near the eastern coast of Antarctica spiked at least 70 degrees Fahrenheit (39 degrees Celsius) above normal — making it the most intense recorded heat wave to occur anywhere on Earth, according to a recent study.
washingtonpost.com
Scientists found the most intense heat wave ever recorded — in Antarctica
On March 18, 2022, temperatures peaked to minus-10 degrees Celsius. That’s warmer than even the hottest temperature recorded during the summer months.
312875
Reposted by Patrice <GomoR> Auffret
M82 @m82.eurosky.social · 24/09/2023
Et voilà, tout juste sortie de presse, la version augmentée de la bibliographie #cyber du M82 project ! C'est ici: www.m82-project.com
m82-project.com
Bibliographie | M82 Project
M82 Project est une bibliographie partagée sur la cybersécurité, la cyberdéfense et les enjeux du numérique.
043
Reposted by Patrice <GomoR> Auffret
The Washington Post @washingtonpost.com · 25/09/2023
The rules for phone calls have changed. When is it okay to leave voice mails, call multiple times in a row or take a call in public? We spoke to an etiquette expert and people of all ages to help everyone navigate phone calls in 2023.
washingtonpost.com
The new phone call etiquette: Text first and never leave a voice mail
The rules for phone calls have changed. Here are the basics on when and how to make a phone call, and why you should think twice before leaving that voice mail.
149426
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 24/09/2023
Hello world!
040