Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions. I have Direct Messages disabled - you can send them, but I will never receive them.
Public Key
npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Profile Code
nprofile1qqs0dpc2ln0yfq8vs5y02qcysk0pffgnp8ljf2elp7rzc54acjhcw3cpz4mhxue69uhhyetvv9ujumt0wd68ytnsw43q408pgy
Show more details
Published at
2026-08-17T14:36:30Z Event JSON
{
"id": "fe9e964cf3819d83c43ea4e16f7a7a2caf73d18fdbc4d5d06f8dd17f99d040cc" ,
"pubkey": "f6870afcde4480ec8508f50304859e14a51309ff24ab3f0f862c52bdc4af8747" ,
"created_at": 1786977390 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://cyberplace.social/users/GossiTheDog",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"Kevin Beaumont\",\"about\":\"Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.\\n\\nI have Direct Messages disabled - you can send them, but I will never receive them.\",\"picture\":\"https://cyberplace.social/system/accounts/avatars/109/387/499/752/708/037/original/a4c1cd571bcb7c2f.jpeg\",\"banner\":\"https://cyberplace.social/system/accounts/headers/109/387/499/752/708/037/original/7acb89f4ac3231c3.jpg\",\"nip05\":\"[email protected] \",\"fields\":[[\"My website\",\"https://doublepulsar.com\"],[\"Github\",\"https://github.com/GossiTheDog\"],[\"Signal\",\"GossiTheDog.1337\"]]}" ,
"sig": "a7aee7be7bf39d1e0d7f115b64a8538c704db43150714484247741baec84d7c4c823d7778564e85f3e6ea02451831062b3f7a5b52d0871007305cf07a37ee721"
}
Last Notes npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont The one and only time somebody asked me for a selfie, which is good since I wouldn’t know how to fame poses 🤣 https://cyberplace.social/system/media_attachments/files/117/105/187/499/948/351/original/e798c964a1b2c684.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Massive leak of credentials and secrets at thousands of orgs where developers executed LiveLLM, terabytes of creds are circulating online now. Root cause = orgs adopting GenAI solutions without proper security. Threat actor = the kids at TeamPCP. Screenshot = Microsoft https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure https://cyberplace.social/system/media_attachments/files/117/082/928/963/499/766/original/5e322606cd9c1c72.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Somebody made a movie about how it’s only legal to have sex one a year - the Purge for sex basically - and then the director cut out the sex and the nudity from the movie over concerns about the audience being too prude, then the press are too worried to write about sex and nudity when quoting him. 2030 The Purge reboot will end out the murder at this rate 🤣 https://cyberplace.social/system/media_attachments/files/117/066/769/693/814/148/original/592debb83a156894.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Microsoft have introduced limits for its engineers AI tools usage https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/ https://cyberplace.social/system/media_attachments/files/117/038/255/227/980/499/original/50163086d592d8f2.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Well done to the US government for running an AIDS conference, AI generating the slides, and presenting the slides with every country in Africa mislabelled by said AI https://www.theguardian.com/us-news/2026/jul/30/government-map-mislabels-african-countries npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Adform, a web advertising firm, have been hacked and have been serving a supply chain attack to steal crypto https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Elon Musk, an immigrant, was interviewed recently by the editor of the Economist. He said a bunch of dumb shit - for example that money wouldn’t exist in 2036, and that everybody wouldn’t have to work any more as AI would do their job for them. Anyway, he’s now essentially calling for the assassination of the journalist over her questions about immigration. https://cyberplace.social/system/media_attachments/files/116/986/523/670/932/738/original/834d0c9cab83b8fe.jpeg https://cyberplace.social/system/media_attachments/files/116/986/523/725/376/414/original/518c795273ca41ab.jpeg https://cyberplace.social/system/media_attachments/files/116/986/523/837/211/418/original/a6b85d485904d624.jpeg https://cyberplace.social/system/media_attachments/files/116/986/523/977/604/522/original/7e34c8188f3d6797.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont if you want to read a reddit post that causes your brain to fall out https://cyberplace.social/system/media_attachments/files/116/976/556/778/379/242/original/b5346359b02db7af.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont America has fallen https://cyberplace.social/system/media_attachments/files/116/971/683/561/199/250/original/e0288e889db3153a.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Microsoft are telling customers there is no ETA to resolution and they may want to review their DR plans for their SaaS services. "Customers may wish to review their business continuity and disaster recovery plans and take actions appropriate for their environment." npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont It's taken several hours but Microsoft finally put impacted services on the Azure status page, prior it was showing no impacted services. https://cyberplace.social/system/media_attachments/files/116/970/432/289/311/563/original/940dfcca3e04c95a.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont For anybody tracking the Microsoft outages... Azure West US is the cause: Starting at 14:44 UTC on 23 July, 2026, we began investigating a networking issue affecting connectivity to Azure services in the West US region. Impacted customers may be experiencing intermittent connectivity failures, increased latency, or difficulty accessing Azure services. Customers with traffic traversing the West US region may also experience downstream impact. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Microsoft 365 aka Microsoft Copilot aka Office 365 has jumped off a cliff. https://cyberplace.social/system/media_attachments/files/116/970/067/142/940/405/original/a06fc044349b8a4f.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont OpenAI are criminally negligent when it comes to cybersecurity, and are very good at viral marketing to executives via poor and uncritical media coverage. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont In an era where companies need to become more efficient and diverse they’ve basically picked the least efficient way to do it, with the biggest risks and highest costs - because everybody else is doing it. I know somebody at one of the big 4 who has written something in Claude that prompts Claude each twenty minutes for a question, then feeds Claude’s question back into Claude to use their tokens - because token usage is factored into employee evaluations. What are we even doing. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont This isn’t, btw, a Kevin Doesn’t Use AI rant. I use GenAI extensively for various testing things. I had access to Mythos before almost everybody. I pay for Copilot Pro+. I pay for Gemini. I AI generate terrible songs. I vibecode security scanners. My personal spend exceeds £500 this month to date. Do I think you should make every employee depend on these third party GenAI tools for their job? No. Its ridiculous. You’re also *locked in* to costs you can’t afford which *will rise*. It’s a cliff. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I’m really serious about this one btw. Companies have no measurable way of knowing what employees are doing with GenAI. They’re giving Claude Code out like it’s candy and just presuming everybody is an IT power user. They aren’t. They’re converting PDFs and vibe coding garden planning tools. Copilot M365 has a fake dashboard showing how productive people are.. it has no actual data. It just shows people use it. It’s CIO porn for the CEO. Orgs are pissing money up a wall worldwide. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Anybody who has worked in IT support in the trenches in enterprise IT will tell you there are some Excel power users who basically run the company, are macros wizards and actual ninjas.. about 0.1% of the workforce. About 99% of people can’t align a table in Word. Giving the 99% of people tools which cost $$$ per user a month and letting them do anything is like giving a child a car, and being surprised when they ram the car into a wall three days later and cost $10k after achieving nothing. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont LinkedIn is about to cum as an AI security vendor has documented what it believes is an AI ransomware incident they've called JADEPUFFER. A few things to note: - They say "Ransomware is no longer a craft for the highly skilled". Ransomware has never been a highly skilled craft. Every single incident I've dealt with has been dumb as bricks. - It exploited a vulnerability from 2021 with default creds, internet facing. - The incident had no impact to a company, and had an invalid Bitcoin key. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont https://www.google.com/maps/place/55%C2%B055'18.5%22N+3%C2%B009'02.9%22W/@55.9217082,-3.1507973,18z/ https://cyberplace.social/system/media_attachments/files/116/851/383/910/795/952/original/3b8a3a10dea66e86.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Update https://checkfirst.network/roska-bridge-how-a-pro-russian-ims-exploits-vulnerabilities-of-decentralised-platforms-to-spread-propaganda/ npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Mastodon has automatic age verification built it, no scanning your face ✅ if you join here you're old ✅ you've seen too much shit ✅ you're tired of said shit npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont sassed by mastodon https://cyberplace.social/system/media_attachments/files/116/834/324/928/073/537/original/7b6ae842a6666a15.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont “Mistakenly, we thought that by just introducing artificial intelligence and ingesting the design requirements that we had, that that would produce a high-quality product.” It’s had to rehire what they call “greybeards” 🤣 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Gizmodo's serving ClickFix malware to Mac users @nprofile…w6mj https://bsky.app/profile/juliametraux.bsky.social/post/3moomipmam22i https://cyberplace.social/system/media_attachments/files/116/782/119/723/315/733/original/716d3845d898b134.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont So there are definitely devices which weren't in the Belsen Group post back last year, in fact almost all of them weren't. On how they got the passwords - until about a year ago, FortiOS (Fortinet firewall OS) stored admin passwords SHA-256 salted, which can be bruteforced. In an update about a year ago, if installed and admins log in, passwords are stored much more securely - but most orgs won't be that condition yet. https://cyberplace.social/system/media_attachments/files/116/765/736/421/232/371/original/99378007b9a008a1.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont It’s similar to the Belsen Group thing, although that was a smaller collection of devices - prior thread https://cyberplace.social/@GossiTheDog/113834848200229959 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Data looks like this, appears they validated creds too. https://cyberplace.social/system/media_attachments/files/116/765/184/936/319/367/original/309beb6a558e64d0.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont An ecrime group has somehow gained access to 75k Fortinet firewall devices - dubbed Fortibleed Blog https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/ Check if your domain is impacted: https://www.hudsonrock.com/fortinet I’ve verified the data is real. They’ve been dumping the Fortinet config - not sure how yet - and then cracking the passwords it appears. Data is being resold online. #fortibleed npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont The US government has intervened in a lawsuit on the side of X, saying Grok is "critical for national security" https://www.wired.com/story/doj-lawyers-argue-xai-vital-national-security-naacp-lawsuit/ npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Was just talking to a friend at a US technology company, they’ve had their budget reduced by 50% as the company says it wants to announce “the largest layoffs in US corporate history” to prove GenAI can replace jobs. There’s no plan to actually replace the jobs with GenAI.. they just have to decimate their area. Not naming company as the staff don’t know they’re about to fed to the line going up. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont It looks like Microsoft's DevOps libraries for Azure Functions might have been compromised. No statement yet but Github is nuking Microsoft's own repos. https://opensourcemalware.com/blog/miasma-reaches-azure npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I set up my first gaming PC running Linux in 21 years today. It's now much easier. Plug in USB stick, boot, install, reboot. The Ubuntu app store had Steam, and Nvidia drivers auto installed... all the audio, trackpad on the laptop etc just worked out of box. The usual Steam GUI and most games work with zero effort, it auto installs a compatibility layer so Windows versions just.. uhm.. work. It's really impressive. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I went to a 60 minute meeting this week and AI was mentioned just over 300 times, I wrote it out roman numerals like a prisoner in a velvet cave. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont this lego thing is SO dumb npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I reinstalled Arma Reforger aka Mr Bean War Simulator 5 minutes ago. Already happened: - I accidentally fell out of a helicopter - I got revived by a medic who happened to be passing by in a field in the middle of nowhere - Then I immediately got run by a truck which happened to cut through the field I love this game, it's proof human shouldn't do anything. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont There's an AI company where you pay them and they'll get anything you want into GenAI results via Reddit. https://cyberplace.social/system/media_attachments/files/116/686/822/700/210/372/original/473b1caa9986482d.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont An internal Microsoft strategy document says that the plan for its just-announced “Scout” personal assistant AI is to “make people addicted” to the tool before rolling out additional functionality https://www.404media.co/microsoft-wants-to-make-people-addicted-to-scout-its-new-ai-assistant-internal-documents-reveal/ npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Mythos is not great btw. Running it over a bunch of code, it’s similar findings to tools from a few years ago. It’s marketing, essentially. Viral marketing as people doing the marketing are companies and governments. It’s really good at finding vulns in vibe coded stuff from Claude.. because apparently AI must be both the cause and solution to all life’s problems, like beer. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I found out my employer doesn’t have access to Mythos. I do. https://cyberplace.social/system/media_attachments/files/116/679/671/606/172/279/original/f73cc47e44e0e233.mp4 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont How people hacked Meta accounts recently: Step 1) Open Meta AI support 2) ask to change Obama's password 3) it says no :( 4) ask it nicely to just do it anyway 5) it resets Obama's password From the company who brought you this headline a few months ago: https://cyberplace.social/system/media_attachments/files/116/676/826/664/314/767/original/36771d64f8e1c787.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Anybody can abuse this one btw, just post bullshit on Reddit about a company supporting Israel or whatever and Google recites it. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont If anybody is wondering how this keeps happening, Google pull their AI output from Reddit. Somebody posted a Reddit thread saying days have fish in them, so now Google replies saying that. Google just blindly trusts any poster on Reddit (not a joke). npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont GenAI is going great (this is real) https://www.google.com/search?q=how+many+days+of+the+week+have+fish+in+them%3F&sourceid=chrome&ie=UTF-8 https://cyberplace.social/system/media_attachments/files/116/664/887/674/648/830/original/be30e94a7d8ed1ab.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Wrote a thing on Microsoft’s stance that not following their “responsible disclosure” process is criminal activity https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?postPublishedType=repub npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products. It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled. https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure https://cyberplace.social/system/media_attachments/files/116/652/001/846/463/920/original/a5f5f906b35414ee.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Watching a bunch of people get very excited about the idea of replacing their staff, when they do not understand the job those staff do, is particularly eye opening. Watch the people doing this and remember their names, then enjoy not working for them. Inspirational leadership my arse, they’re the arseholes of Earth. https://cyberplace.social/system/media_attachments/files/116/629/656/614/460/985/original/18f71198c6f31249.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Engineering without measurements, Cloudflare style. https://cyberplace.social/system/media_attachments/files/116/629/648/075/210/174/original/bac6f279971c4dd3.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont A reminder that Cloudflare’s CEO is a world class clown. https://cyberplace.social/system/media_attachments/files/116/629/630/590/559/627/original/9db4c67dac47bd8d.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…p9u9 that looks like you're at a press conference after breaking the world record for eating bees or something npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…kgg0 separation agreement? Are you married to work? 😅 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont OpenAI has a negative 122% operating margin and growth of usage has stopped. https://www.theinformation.com/articles/openai-held-1-billion-revenue-lead-anthropic-first-quarter https://cyberplace.social/system/media_attachments/files/116/615/020/890/212/086/original/c667880e6d4bbc91.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Also - if you think 'none of our users run VSCode', check your telemetry. They do. It doesn't even need local admin rights to install. I've tooted about this one for about two years now, Microsoft have created their own security bonfire and it's going off in their own backyard, they just haven't realised yet. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont If you want on to Microsoft's internal network, CORPNET, publish or own an existing a VSCode extension. The Visual Studio Code Marketplace, which Microsoft own, is completely uncontrolled. Anybody can publish an extension, it provides code execution on endpoints, extensions auto update by default, "verified" blue tick extensions just need any domain registration, and there's no endpoint security controls at all around what users can install. VSCode is an absolute security shittip as a result. #nevent1q…r5ul npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont The great thing about BlueSky is because it’s decentralised, it never goes offline. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont This is the dumbest fucking thing I’ve read since the last AI thing. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont A reminder that one of the reasons people love AI as you can ask it to justify any dipshit idea and it'll just write whole documents about it being a great idea, write the PowerPoint decks, the Capex requests etc. https://cyberplace.social/system/media_attachments/files/116/595/779/051/170/254/original/62679bdd0bae072e.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…dzml you can't on personal accounts - it's an enterprise Entra ID feature. Also, not everybody is you - the MS personal account signup directs you to install the app. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…dzml it does in MS world :D as it sends a push prompt to the authenticator app regardless npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…xvaj most companies do npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont The Metaverse stuff in Teams was such a waste of time. Trend chasing a trend which never existed in the first place. With my AI avatar I used to robot dance in meetings to piss people off. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont The consequence of going passswordless: https://www.reddit.com/r/cybersecurity/s/7KIJL7R0Zz npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Regarding CVE-2026-42945 in nginx - no modern (or even old) Linux distribution runs nginx without ASLR. The way the PoC exploit works is they spawn nginx like this: > exec setarch x86_64 -R /nginx-src/build/nginx -p /app -c /app/nginx.conf Setarch -R disables ASLR. I've had a look through Github and I can't find any other software which actually does this for nginx either. So, cool, sweet technical vuln - it's valid - but the RCE apocalypse ain't coming. https://cyberplace.social/system/media_attachments/files/116/578/013/298/718/371/original/1e57e928d3bae1b0.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I will likely be one of the first people banging the drum to patch and mitigate if any of the recent AI vulns results in serious harm. Otherwise, keep calm and carry on patching as usual. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont CVE-2026-42945 - Nginx (otherwise branded Nginx Rift) It relies on a specific Nginx config to be vulnerable, and for attacker to know or discover the config to exploit it. To reach RCE, also ASLR needs to have been disabled on the box. The PoC they've built specifically disabled ASLR, deploys a specifically vulnerable config and the exploit knows about the vulnerable config endpoint. https://cyberplace.social/system/media_attachments/files/116/572/637/830/948/345/original/684bf86549dc61a8.png https://cyberplace.social/system/media_attachments/files/116/572/643/615/861/086/original/b9a7396629fec05f.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont CVE-2026-34486 - Tomcat - Only exploitable if a certain feature is used, if it's endpoint is reachable and if port 4000. It's pretty niche. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont There's serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. Automated vulnerability hype train again, basically. A thread on a few of them. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont So I’ve just had a quick play with this and yes, it works. Essentially BitLocker has a backdoor. https://github.com/Nightmare-Eclipse/YellowKey Mitigation = BitLocker PIN and BIOS password lock. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…mej2 @nprofile…c808 @nprofile…m4cn do you have cloud protection turned on? npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont i don't even know what a kumquat is, it sounds like a transformer npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont fuck i'm gonna have to buy a kumquat https://cyberplace.social/system/media_attachments/files/116/557/115/083/535/562/original/de0238eb1f72f792.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont If you enjoy watching old people fail to read the room, watch somebody try to tell students that Generative AI is the next industrial revolution: https://cyberplace.social/system/media_attachments/files/116/556/671/917/990/617/original/15b55a600aecf77c.mp4 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Vodafone were being held to ransom by some organised crime clowns. Vodafone refused to pay, good on 'em, break the cycle of crime clowns. It's not "full infrastructure" as claimed (it's only a 5gb file), nor is it VMware ESXi as originally claimed. https://cyberplace.social/system/media_attachments/files/116/552/573/055/550/983/original/d8e81e45d09a348d.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I have a spare room or two in my house so I’m thinking of setting up a Which Will Last Longer, Keir Stamer Or This Kumquat twitch stream. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I’m half an hour into this game and I’ve laughed out loud 5 times and had actual tingles from memories of being a kid. I’m currently frenching a boy. https://cyberplace.social/system/media_attachments/files/116/541/133/128/072/453/original/84b713978056cef5.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Fuck it, I’m in. https://cyberplace.social/system/media_attachments/files/116/541/123/628/058/336/original/344eee50e6076a0e.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Mixtape is out now. It's the highest rated game by critics of the year so far. It's basically a John Hughes movie as a game. I'm diving in tomorrow. https://www.youtube.com/watch?v=aQoEd5rnxiQ npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Always good when your EDR provider gets hit by a ransomware group. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont If you want a fun threat hunt, look at what Claude et all are doing in your company. Spoiler: dumb shit. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont me tweet from last week about the world going to shit around the time Gamestop realised it could just pretend to be a functioning mega company, so have this video with the CEO trying to explain how they'll buy eBay instead. https://cyberplace.social/system/media_attachments/files/116/517/133/324/614/553/original/480e6ab42b1b3e47.mp4 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…44dh they're being DDoS'ed npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Meta send smart glass recordings for manual human review. When workers at a company disclosed they were viewing people having sex and such, Meta terminated the contractor's contract, with just over 1k job losses. The devices still operate the same, they just swapped the contractor after receiving regulatory questions. https://www.bbc.co.uk/news/articles/c5y7yvgy0w6o npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Here's a question - re the Microsoft Vibing thing. Microsoft didn't disclose they were behind Vibing, multiple staff pretended on Github it was an open source community project (it wasn't), one specifically said they weren't involved (they were), they collected screenshots and mic recordings, and it had no security, compliance or AI review by Microsoft. Is that okay? npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I’ve updated my write up. https://doublepulsar.com/microsoft-vibing-capturing-screenshots-and-voice-samples-without-governance-6973c48f03a7 https://cyberplace.social/system/media_attachments/files/116/489/005/430/159/646/original/dd403a260d759189.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont So @nprofile…ss8w asked Microsoft about Vibing - they’ve confirmed it is a Microsoft research project. They say “We have removed the application as we review its functionality and adherence to our policies. We remain committed to responsible AI and are taking appropriate steps as part of this review.” npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont @nprofile…qznj ? npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont An attempt to hide the MS link with Microsoft Vibing on GitHub - “This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.” - the commit hiding the compliance review has been redone today without Yaoyao’s name on it.# New commit: https://github.com/VibingJustSpeakIt/Vibing/commit/84c82ccad2092b4bc2dffe5c96ef8c8d4466cc6e Hidden commit: https://github.com/VibingJustSpeakIt/Vibing/commit/ab8e6302543754685f85cf02e02d1d0287d2f4f0 https://cyberplace.social/system/media_attachments/files/116/476/693/517/803/832/original/477749f2f4d1d073.jpeg https://cyberplace.social/system/media_attachments/files/116/476/693/561/811/463/original/de7cd021e269cd9c.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Did anybody happen to the screenshot or archive the Microsoft Vibing website ( https://vibingjustspeakit.github.io/Vibing/ ) and Github ( https://github.com/VibingJustSpeakIt/Vibing/ ) showing the compliance suspension messages before they were deleted? The changes are archived on GitHub, but I'd like to document what they looked like prior to removal. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont For those who can’t read between the lines, it appears the US wiped an oil company and disguised it as a ransomware attack. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Microsoft are now trying to hide the compliance review message, by removing the download links and removing the compliance review messages on Github. https://github.com/VibingJustSpeakIt/Vibing/commit/ab8e6302543754685f85cf02e02d1d0287d2f4f0 https://cyberplace.social/system/media_attachments/files/116/464/760/595/137/195/original/f967106e3c365289.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Vibing has removed from Microsoft Store: https://cyberplace.social/system/media_attachments/files/116/464/749/958/170/727/original/5c8b5cfb1b9bc245.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Tokenmaxxing. Tokenmaxxing 🤣 amazing stuff. https://cyberplace.social/system/media_attachments/files/116/462/120/240/737/863/original/f9f6c75bb74caf1d.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Also worth noting - Yaoyao Chang made the changes to the Vibing-Team repo, which is the first time Microsoft has officially been linked to Vibing. It’s a very strange situation where MS were covertly operating an AI service, while pretending it was an open source project. npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Vibing has been suspended and downloads removed pending a compliance review by Microsoft. https://github.com/VibingJustSpeakIt/Vibing https://cyberplace.social/system/media_attachments/files/116/459/655/209/562/837/original/92bb389d34026f10.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I have a theory about when the business world went to shit. At the beginning of 2021. Reddit bros realised they could inflate the value of GameStop - a business selling physical video games which is as doomed as Blockbuster - by just... vibing and pretending. And now everybody just vibes and pretends across business. Everybody knows everything is bullshit, e.g. GenAI's largely bullshit... but as long as we vibe along, who cares! https://cyberplace.social/system/media_attachments/files/116/459/151/702/475/621/original/2bb52f99069f26cf.png npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I withheld a load of details from the blog on this so far btw, if you're a researcher and want a laugh pull the binaries and have a look at what the MS Research team were doing and poke the backend. Something tells me Microsoft are going to end up freezing the Azure backend for Vibing and having a security incident. https://cyberplace.social/system/media_attachments/files/116/458/790/281/790/444/original/793d02f38e5a64fb.mp4 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont Since publishing my blog, Yaoyao Chang, who authored Vibing, has removed references to it from Microsoft’s VibeVoice repo - marking the change as “removing outdated links”. https://cyberplace.social/system/media_attachments/files/116/456/572/411/789/865/original/e475c4ec2d046316.jpeg npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont This Vibing one is a fun blog btw as every page it gets to be a bigger version of this https://cyberplace.social/system/media_attachments/files/116/454/877/590/781/137/original/6967f4101ba8c984.mp4 npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw Kevin Beaumont I just want to give the analysts at Dragos credit here for how they framed this - it's really responsible.