Sign in

Ravenholm Tech

@ravenholmtech.bsky.social
31 followers 37 following 56 posts

Real life cybersecurity engineer and consultant. Even got the CISSP cert to prove it.

PostsRepliesMedia
Reposted by Ravenholm Tech
cj @cjcoffey.com · 20/02/2026
It's been weighing on me for a bit, so I wrote some thoughts on the whole AI thing. cjcoffey.com/posts/though...
cjcoffey.com
A few thoughts on AI
Pardon me for a moment while I dump the contents of my brain onto this piece of digital paper. I...
021
Reposted by Ravenholm Tech
TrustedSec @trustedsec.com · 17/02/2026
If you were expecting a CMMC-style rollout, GSA has other plans. In our latest blog, Director of Advisory Solutions Chris Camejo explains how new CUI requirements can be inserted into GSA contracts immediately and what that means for compliance readiness. Check it out! trustedsec.com/blog/updated...
trustedsec.com
Updated GSA Contractor CUI Protection Requirements
012
Reposted by Ravenholm Tech
TrustedSec @trustedsec.com · 03/02/2026
Model Context Protocol servers often rely on SSE and WebSockets, which makes manual testing tricky. @hoodoer.bsky.social introduces MCP-ASD, a new Burp Suite extension designed to help testers identify, enumerate, and interact with MCP servers more effectively. trustedsec.com/blog/mcp-in-...
trustedsec.com
MCP in Burp Suite: From Enumeration to Targeted Exploitation
022
Ravenholm Tech @ravenholmtech.bsky.social · 23/01/2026
Pay up Benny
000
Reposted by Ravenholm Tech
MinnMax @minnmax.com · 23/01/2026
In solidarity with today's ICE OUT OF MINNESOTA blackout, MinnMax is donating $1 to the Immigrant Law Center of Minnesota for every share of this Bluesky post for the next hour.
2151648920292
Ravenholm Tech @ravenholmtech.bsky.social · 16/01/2026
Saw this on reddit. Very relatable.
000
Ravenholm Tech @ravenholmtech.bsky.social · 06/12/2025
I just said this in a meeting a few days ago.
010
Reposted by Ravenholm Tech
TrustedSec @trustedsec.com · 02/10/2025
A key cybersecurity information-sharing law has temporarily expired amid broader government funding delays. David Kennedy told The Hill that the lapse eliminates key protections that the exchange of information, which is encouraged by CISA, provides. Read now! thehill.com/homenews/552...
thehill.com
Cyberthreat sharing law expires as government shuts down
A law allowing private companies to share information about cybersecurity threats with the government expired Wednesday after Congress failed to reauthorize the legislation amid a wider shutdown fi…
011
Ravenholm Tech @ravenholmtech.bsky.social · 20/08/2025
Gottem #HackTheBox
010
Ravenholm Tech @ravenholmtech.bsky.social · 30/07/2025
Thanks for hosting the ISC2 meeting @trustedsec.com. Pretty cool to see the Back to the Future collection.
120
Ravenholm Tech @ravenholmtech.bsky.social · 28/07/2025
Been working helping people resolve this "little" issue. nvd.nist.gov/vuln/detail/... If you're running on-prem Sharepoint 2016 or 2019 you might want to take care of this quickly.
nvd.nist.gov
NVD - CVE-2025-53770
100
Ravenholm Tech @ravenholmtech.bsky.social · 02/07/2025
Built a cool little volume mixer for a family member's PC. It was built using Deej. It was a fun little project. I picked the colors to match their PC case, it was pretty straight forward and easy to produce. github.com/omriharel/deej
000
Ravenholm Tech @ravenholmtech.bsky.social · 27/06/2025
Oh man. I've been seeing sooooo many bad takes about plain text credentials in code. Certainly, every software developer/engineer knows that plain text creds in code is bad. I'm sure they all know how to use a secrets vault. Who cares if it's only accessible internally? Just fix it.
000
Ravenholm Tech @ravenholmtech.bsky.social · 17/01/2025
I really like strange hardware designs. This looks really fun.
000
Reposted by Ravenholm Tech
Dr Ravi Nayyar @ravirockks.bsky.social · 02/01/2025
1 malicious version each of 2 npm packages for a popular JavaScript bundler were released by an attacker 'who gained unauthorized npm publishing access'. One of the legit npm packages has around 370k downloads/week, the other, 135k/week. socket.dev/blog/rspack-...
socket.dev
Supply Chain Attack on Rspack npm Packages Injects Cryptojac...
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
073
Ravenholm Tech @ravenholmtech.bsky.social · 24/12/2024
Hello fellow humans. I have a neighbor that informed me about a "thing" on his Amazon Fire Stick. Apparently, it's a service they pay for. ViewTV. Pretty interesting. It's clearly a side loaded app from a third-party source. I can't find any information about how the back end of this works.
100
Reposted by Ravenholm Tech
David Buchanan @retr0.id · 19/12/2024
probably don't get your cybersecurity advice from youtube sponsor segments
1347159
Ravenholm Tech @ravenholmtech.bsky.social · 17/12/2024
Look, seriously. I don't care if it's "internal only" patch it anyway. Also, why is there a script to disable EDR when you use a certain piece of software?
000
Ravenholm Tech @ravenholmtech.bsky.social · 12/12/2024
Can you even imagine months of negotiation to harden a VPN configuration? I can.
000
Reposted by Ravenholm Tech
TrustedSec @trustedsec.com · 03/12/2024
In our new #blog, Senior Security Consultant @two06.bsky.social goes over methodology that led him to discovering a deserialization vulnerability in #LINQPad, a .NET scratchpad application commonly used by developers. Read it now! trustedsec.com/blog/discove...
trustedsec.com
Discovering a Deserialization Vulnerability in LINQPad
094
Reposted by Ravenholm Tech
Black Hills Information Security @bhinfosecurity.bsky.social · 04/12/2024
Open-Source Tools Forensic Kit - exterro.com/forensic-toolkit Autopsy - autopsy.com Volatility - volatilityfoundation.org Zimmerman - ericzimmerman.github.io/#lindex.md Wireshark - wireshark.org iLEAPP/aLEAPP - github.com/abrignoni/iLEAPP github.com/abrignoni/aLEAPP Klogg - klogg.filimonov.dev
exterro.com
Data Risk Management - Data Discovery & Privacy Platform | Exterro
Exterro's powerful data risk management platform unifies e-discovery, privacy, data governance, digital forensics, and cybersecurity compliance to…
191
Ravenholm Tech @ravenholmtech.bsky.social · 28/11/2024
Finally got my CISSP certification today. The wait is over!!!
100
Ravenholm Tech @ravenholmtech.bsky.social · 25/11/2024
Ugh... Week 5 of waiting for ISC2 to click the checkbox on my CISSP cert.
010
Ravenholm Tech @ravenholmtech.bsky.social · 25/11/2024
I still see those log4j vulnerabilities out there..... #CyberSecurity
010
Ravenholm Tech @ravenholmtech.bsky.social · 22/11/2024
I really gotta get back to work on this. Took a little break. Time to go for pro hacker.
010
Ravenholm Tech @ravenholmtech.bsky.social · 22/11/2024
security.paloaltonetworks.com/CVE-2024-0012 Authentication Bypass security.paloaltonetworks.com/CVE-2024-9474 Privilege Escalation Finding these two together isn't good news. If you're running palo alto firewalls update them... yes... even if they are "internal only"
security.paloaltonetworks.com
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perfor...
010
Ravenholm Tech @ravenholmtech.bsky.social · 22/11/2024
So... where are all of the other #CyberSecurity people? I remember a few from the .... other place. Either way, keep an eye here for complaints about vulnerabilities that terrorize me throughout the day or the evils of cloud storage and using email for critical business processes (don't).
000