jstnkndy
@jstnkndy.bsky.social
2K followers 410 following 240 posts
Infosec professional, beverage snob, and fantasy book consumer. Vice President @ Atredis Partners. Forever terrified of Kithicor.
Posts Media Videos Starter Packs
Reposted by jstnkndy
dcuthbert.bsky.social
It has been about two decades since I last needed/used one, but is there any modern KVM switch that works with Mac’s properly? Lost faith in a wide screen Picture in Picture monitor so hope the KVM world is better
jstnkndy.bsky.social
You think someone would really do that? Use static keys in distributed products? ;)
Reposted by jstnkndy
rcesecurity.com
Another day, another Remote Code Execution (and its 3 friends).

Pre-auth path traversal, hard-coded crypto key allowing cookie forgery, arbitrary file write, and PII disclosure in TRUfusion Enterprise (CVE-2025-27222 to CVE-2025-27225) #security

www.rcesecurity.com/2025/09/when...
When Audits Fail: Four Critical Pre-Auth Vulnerabilities in TRUfusion Enterprise | RCE Security
www.rcesecurity.com
jstnkndy.bsky.social
Hah! Great findings :D
Reposted by jstnkndy
quinnypig.com
I'd have jumped on this before my Echo Show started showing ads I couldn't disable. Hope the revenue was worth the customer trust.
techmeme.com
Amazon unveils the $220 Echo Studio, its high-end speaker for audiophiles, 8" and 11" Echo Show for $180 and $220, and the $100 Echo Dot Max, all with Alexa+ (Mark Gurman/Bloomberg)

Main Link | Techmeme Permalink
jstnkndy.bsky.social
that's definitely a risk!
jstnkndy.bsky.social
There may be a better way, but I could see Integrity being affect in that people would expect real emails from the site, but the integrity of the sender has been compromised.
jstnkndy.bsky.social
I'm at the point where I've seen first hand production platforms running AI generated code and have found critical vulnerabilities in those platforms. We're getting to the point where the number of emojis in the code will be telling of the number of bugs.
jstnkndy.bsky.social
hoping you found one bug, then another, then another, then another.
Reposted by jstnkndy
eliomen.bsky.social
"we take your privacy. seriously."
Reposted by jstnkndy
samhouston.bsky.social
I need more friends in the Bay Area/ #Vallejo and I'm feeling so unsure about what to do about it

A lot of my friends and old colleagues left the Bay during the pandemic.

Making friends in your 30s/40s is so difficult, especially if you don't want to hangout at a bar all night
jstnkndy.bsky.social
Fuck Trump, fuck Kirk, and fuck this timeline.
Reposted by jstnkndy
codewhitesec.bsky.social
CODE WHITE proudly presents #ULMageddon which is our newest applicants challenge at apply-if-you-can.com packaged as a metal festival. Have fun 🤘 and #applyIfYouCan
ULMageddon Logo
jstnkndy.bsky.social
I appreciate the practical context in which this was presented, well done!
Reposted by jstnkndy
t0xodile.com
The recording for my latest research has been released! If you prefer to listen rather than read, now is your chance.

P.S. It may be worth listening to it at a slower speed due to my tendency to talk at the speed of light...
The Single-Packet Shovel: Digging For Desync-Powered Request Tunnelling - Thomas Stacey
YouTube video by Bsides Exeter
www.youtube.com
jstnkndy.bsky.social
"That’s why we built Chariot, to make continuous offensive security actionable."

And there it is. Awful.
jstnkndy.bsky.social
it's too bad that @portswigger.net broke their navigation so now older links are no longer useful.
jstnkndy.bsky.social
It's almost that time of year
jstnkndy.bsky.social
this is why you should make bsky your primary ;) and congrats on the Phrack article!