Fran Donoso
@francisck.com
460 followers
180 following
150 posts
I'm an infosec person who currently works as the CTO of a security services firm. Have done DevSecOps, Red Teaming, and reverse engineering. I reversed some of the tooling leaked by the Shadow Brokers and spoke about it publicly
Posts
Media
Videos
Starter Packs
Pinned
Fran Donoso
@francisck.com
· Nov 14
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· 26d
Fran Donoso
@francisck.com
· Sep 10
Fran Donoso
@francisck.com
· Sep 8
Reposted by Fran Donoso
Reposted by Fran Donoso
Fran Donoso
@francisck.com
· Aug 4
jon greig
@jgreig.bsky.social
· Aug 4
SonicWall urges customers to take VPN devices offline after ransomware incidents
Multiple cybersecurity incident response firms are warning about the possibility that a zero-day vulnerability in some SonicWall devices is allowing ransomware attacks.
therecord.media
Fran Donoso
@francisck.com
· Jul 30
Reposted by Fran Donoso
andy jabbour
@andyjabbour.bsky.social
· Jul 24
Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog
Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting vulnerabilities targeting internet-facing SharePoint servers. In addition, we have observed a...
www.microsoft.com
Fran Donoso
@francisck.com
· Jul 20
Reposted by Fran Donoso
Glenn
@ntkramer.bsky.social
· Jul 16
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
www.greynoise.io
Reposted by Fran Donoso
Catalin Cimpanu
@campuscodi.risky.biz
· Jul 13
Reposted by Fran Donoso
Joe Slowik
@pylos.co
· Jul 11
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
Welcome back to yet another day in this parallel universe of security.
This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no o...
labs.watchtowr.com