Sign in

Brendan

@tychosmoose.bsky.social
132 followers 283 following 26 posts

Hackaveloper, trophy husband, fur-baby daddy, hobby ranch-hand, hiker, and Researcher for Metasploit. My opinions are my own unless I stole them. He/Him

PostsRepliesMedia
Brendan @tychosmoose.bsky.social · 03/07/2026
Caught him briefly looking majestic...
Great Pyrenees in a field with yellow wildflowers.
000
Brendan @tychosmoose.bsky.social · 16/06/2026
It is amazing how much this dog loves for me to sit out in a field so he can protect me like some sort of sheep who has learned how to make coffee and answer emails.
Great Pyrennes dog lying in the grass smiling
000
Brendan @tychosmoose.bsky.social · 27/04/2026
As a Southeast Dallas resident, I'm absolutely fine with North of Dallas being the gathering place for anyone who thinks Chick-Fil-a, Chipotle, and HOAs are the best. I'll be down here on an affordable acreage doing whatever I like and eating amazing food from taco trucks and falling-down sheds.
110
Brendan @tychosmoose.bsky.social · 15/04/2026
No; it would be nice to get a bill and pay it. IRS has all the documents I do and knows how much I owe, so they can darn well tell me, and I can "file" taxes if I disagree. This yearly "guess how much you owe" crap is stupid.
040
Reposted by Brendan
Stephen Fewer @stephenfewer.bsky.social · 18/02/2026
We have disclosed CVE-2026-2329, a critical unauth stack-based buffer overflow vuln affecting the Grandstream GXP1600 series of VoIP phones. Read our disclosure on the @rapid7.com blog, including technical details for unauth RCE, and accompanying @metasploit-r7.bsky.social modules: r-7.co/4tIzope
035
Reposted by Brendan
Rapid7 @rapid7.com · 08/01/2026
🚨 In November 2025, a critical vuln. was patched in #n8n, a popular piece of automation software. The advisory for (what the finders have dubbed) #Ni8mare was published on January 7, 2026 – now tracked as CVE-2026-21858 with a CVSS score of 10.0. More: r-7.co/3Z3aGBP
r-7.co
Ni8mare and N8scape flaws among multiple critical vulnerabilities affecting n8n
On November 18, 2025, a patched release was published for a critical unauthenticated file read vulnerability in n8n, a popular piece of automation software. Read more in the Rapid7 blog.
001
Brendan @tychosmoose.bsky.social · 05/01/2026
Looked over this morning and saw this dufus was in full blanket-snorkel mode. Pure jealousy.
Large dog in a bed hidden under a blanket with only his snoot sticking out.A close up of a dog's snoot sticking out from under covers.
020
Reposted by Brendan
Stephen Fewer @stephenfewer.bsky.social · 21/11/2025
We now have a (draft) @metasploit-r7.bsky.social exploit module for the recent Fortinet FortiWeb vulns, chaining CVE-2025-64446 (auth bypass) + CVE-2025-58034 (command injection) to achieve unauthenticated RCE with root privileges: github.com/rapid7/metas...
12110
Reposted by Brendan
Catalin Cimpanu @campuscodi.risky.biz · 20/11/2025
There's an unpatched admin auth bypass in the Twonky Server www.rapid7.com/blog/post/cv...
rapid7.com
CVE-2025-13315, CVE-2025-13316: Critical Twonky Server Authentication Bypass (NOT FIXED)
Rapid7 has identified two vulnerabilities that facilitate administrator authentication bypass in Twonky Server, a media solution.
111
Brendan @tychosmoose.bsky.social · 20/10/2025
Please forgive me if I'm saying something you already know, but as a former Jacksonville resident if you have some time, Chamblin Bookmine is a lovely way to spend it.
110
Brendan @tychosmoose.bsky.social · 20/10/2025
I would have thought so too. Saying "cloud native solution" would be a bit confusing alone, as it is a string of three nouns (or a verb and two nouns), but "cloud-native solution" clearly identifies the nouns/verb acting as a single adjective, leaving the subject clear?
010
Reposted by Brendan
Caitlin Condon @catc0n.bsky.social · 19/09/2025
Last night, Fortra disclosed a critical vulnerability in their GoAnywhere MFT file transfer product. CVE-2025-10035 has a virtually identical description to CVE-2023-0669, which was exploited by ransomware crews. Unclear if this one has been exploited. Patch now. www.vulncheck.com/blog/cve-202...
vulncheck.com
CVE-2025-10035: Critical Vulnerability in Fortra GoAnywhere MFT | Blog | VulnCheck
A new critical vulnerability was disclosed in Fortra's GoAnywhere managed file transfer product, which has been targeted in the past by ransomware and extortion groups
054
Brendan @tychosmoose.bsky.social · 02/09/2025
Is it wrong I pictured a half-drunk dude waiving a stump saying "I thought this was AMERICA!" Also, as a recreational diver: Please do not train sharks to think my hand is holding something tasty.
060
Brendan @tychosmoose.bsky.social · 02/09/2025
Can confirm- in 2019 no stomach shots. Got 4 IG injections at the bite site, 1 in the butt cheek, and then 4 vaccinations in the arm over the next month or two. The IG was the worst, as it made me feel like I had the flu the next day, but better than death. Also make sure you are current on TDAP.
091
Brendan @tychosmoose.bsky.social · 26/06/2025
Just finished reading @carlhiaasen.com's Double Whammy and immediately thought about Jim Tile's assertion that while Clinton Tyree's environmental and anti-corruption platforms are great, it will be his teeth that get him elected.
020
Brendan @tychosmoose.bsky.social · 06/06/2025
This is awkward....
000
Brendan @tychosmoose.bsky.social · 03/03/2025
In happy news, our most recent foster found his forever home this weekend. He showed up on the ranch when the weather was in the 20's, and stayed for a warm bed, lots of kibble, surgery to remove a benign tumor, a couple baths, rest, and lots of treats and pets. Day 1 vs day 40(?).
Very dirty dog in a crateModerately clean dog lying in the grass
010
Brendan @tychosmoose.bsky.social · 26/02/2025
Having been a civilian at the DoD, there cannot be anything more explicit in that chat than what I heard daily from some servicemembers and old straight white dudes. The culture change going from DoD civilian/contractor to tech space was so dramatic, I had not realized how "used" to it I had become.
030
Brendan @tychosmoose.bsky.social · 07/02/2025
I'm all for burning down stupid bureaucratic nonsense, but maybe ask why it is done that way and what happened that caused those rules to be created before striking the match?
000
Brendan @tychosmoose.bsky.social · 07/02/2025
A great way to do this for non-compliant managers is to type up your notes from face-to-face encounters and email them to the person to ask if you missed anything in the discussion. I once made a senior DoD manager go apoplectic using this tactic.
514934
Brendan @tychosmoose.bsky.social · 19/09/2024
www.today.com/news/man-liv...
Pepperidge Farm remembers blank meme
010
Reposted by Brendan
Eden @edenbrandy.bsky.social · 17/07/2024
He probably started the form, but didn’t finish it.
722811
Brendan @tychosmoose.bsky.social · 09/07/2024
Super excited that Microsoft has enabled "quick create" on Hyper-V to let you automagically create popular VMs. Less excited that it appears to create the same x64 VM, even if your host OS is ARM-based. 😅 Maybe at least put the arch in the vhdx filename?
VM Failing to startImage of automatically created VM Hard drive on ARM PC with MD5 hashSame MD5 Hash showing on VM Hard drive created on an x64 Host OS
010
Reposted by Brendan
Ron Bowes @iagox86.bsky.social · 16/05/2024
I'm on at 15:15 ET tomorrow!
012
Brendan @tychosmoose.bsky.social · 30/04/2024
Truly uncanny how he can find waterfowl hidden in the grass.
Pointer dog pointing at a large goose two feet away
010
Reposted by Brendan
opfuchs.gay @opfuchs.gay · 26/04/2024
CVE-2023-20198 (critical RCE in Cisco IOS XE) PoC and associated Fofa query: github.com/W01fh4cker/C...
github.com
GitHub - W01fh4cker/CVE-2023-20198-RCE: CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands. - W01fh4cker/CVE-2023-20198-RCE
023
Brendan @tychosmoose.bsky.social · 19/04/2024
I don't know why I keep being surprised that Enterprise software is as utterly cobbled together as the code I wrote to control the temperature of my kegerator 20 years ago.
000
Brendan @tychosmoose.bsky.social · 11/04/2024
Yeah; some of the $500+ rescue fees are..... suspicious. Our local shelters are so dang happy to get dogs into homes we often don't even pay adoption fees, though we usually drop off a couple hundred pounds of kibble throughout the year as a "thank you."
010
Brendan @tychosmoose.bsky.social · 04/04/2024
I know those feels......
Great Pyr with muddy paws
150
Brendan @tychosmoose.bsky.social · 28/03/2024
I don't think our GP digs delicately enough for archeology work. It is more civil engineering focused.
150
Brendan @tychosmoose.bsky.social · 27/03/2024
That time we found our Great Pyr had taken out a K-BAR, managed to get it unsheathed, and got real serious about livestock guarding.....
Great Pyrenees Dog lying on a carpet with a K-BAR knife unsheathed with the scabbard next to it.
000
Reposted by Brendan
mankrik's wife guy @byelacey.bsky.social · 15/03/2024
do u enjoy silly little guys??? i got u. get yourself some silly little guys, today 🦴✨ fangcrush.storenvy.com
536186
Brendan @tychosmoose.bsky.social · 13/02/2024
I am often jealous of our dogs....
Two dogs on beds covered in blankets by a fireplace
0130
Brendan @tychosmoose.bsky.social · 26/09/2023
I'm in a meeting and someone said "all the way back in Python 2.7" like it was code carved in stone and now my back hurts.
010
Brendan @tychosmoose.bsky.social · 22/09/2023
Can we please put one introvert in every HR department and give them veto power?
030