Kevin Beaumont
@doublepulsar.com
14K followers 160 following 490 posts
cybersecurity weather man. scanning the horizons for cloudy cyber. Expert at nothing except computer rubbish. Anti-ransomware since 2015.
Posts Media Videos Starter Packs
doublepulsar.com
This goes hard.

Pun not intended.
doublepulsar.com
nothing, just nerd security stuff
doublepulsar.com
LAPSUS have the Red Hat gitlab breach up on their portal

They’ve posted Consulting Engagement Requests for AIR, AMEX_GBT, Atos_Group (NHS Scotland), BOC, HSBC and Walmart. Also a file tree, 370,852 directories, 3,438,976 files.

cyberplace.social/@GossiTheDog...
Kevin Beaumont (@[email protected])
Attached: 1 image LAPSUS$ have now listed the breach at Red Hat on their portal. They have posted CER - Consulting Engagement Requests. Sensitive info, for AMEX, Atos, HSBC, Walmart, NHS Scotland am...
cyberplace.social
Reposted by Kevin Beaumont
ciaranm.bsky.social
Rewatching Hot Fuzz (2007) & only just noticed the evil residents’ committee’s motto is Make Sandford Great Again
doublepulsar.com
But sir, it says my cybersecurity programme is amazing!! By making up all the data. I’ve retired now. Thx vibe working 🙏
doublepulsar.com
The 2028 US Presidential election is going to be a really good IQ test.
doublepulsar.com
Is now a good time to remind folks that Oracle had a breach of their Gen1 cloud environment they covered up earlier this year?
doublepulsar.com
Yes - but 99.9% of the operational impacts on the ground are ransomware and such from foundational stuff.
doublepulsar.com
I own every Xbox console, and I've subscribed to Xbox Live since launch day in 2002 - never missed a payment. This week, I cancelled my Xbox subscription and got rid of my consoles.

Enough is enough. I'm out. I can't sit around and watch something decline like this, it's just sad.
tomwarren.co.uk
Xbox consoles are now getting a fullscreen Xbox Game Pass Ultimate ad at boot, just a day after a 50% price hike was announced
doublepulsar.com
They were literally emailing the generic support address, lol. They tried going to InfoSec via that too, unsurprisingly they didn’t know what to do.
doublepulsar.com
A part of the cause here is operationally - orgs cover up their incidents.

Hire external IR through legal council, don’t tell regulators, put threat intel in TLP wrappers etc.

My entire career has been moving between orgs and knowing all their problems day one. Because they’re all the same.
doublepulsar.com
One the craziest elements about cybersecurity is you have half the industry sat worrying about cyberwar!1! and going on about quantum and AI, then you have you have the operational reality of what is actually happening on the ground - it bares no resemblance, at all, to what people are focused on.
doublepulsar.com
don't worry, there's actually a load more federal orgs that never bothered to patch the ASA thing.

The UK gov patch rate is far worse though so the US is doing something right. 🫡
doublepulsar.com
Various US federal government orgs never finished patching Cisco ASA before the gov shutdown

Eg 158.219.75.133,*.cbo.gov|cbo.gov,YES,14/03/24 <- last patched in 2024, Congressional Budget Office

192.231.145.126,vpn.ha.nih.gov,YES,16/11/23 <- last patched in 2023, National Institutes of Health
Reposted by Kevin Beaumont
metacurity.com
Along with the shutdown, the Cybersecurity Information Sharing Act of 2015 lapsed, making it now more complex for organizations to share threat info with the government and their peers.

Check out my CSO piece on this development. 1/2

www.csoonline.com/article/4065...
CISA 2015 cyber threat info-sharing law lapses amid government shutdown
The expiration of a landmark cybersecurity law strips liability protections for cyber threat information sharing, leaving US cyber defenses weaker until lawmakers act.
www.csoonline.com
doublepulsar.com
when did they first and last message you, out of interest? I think I can place a bet about when it stopped :D
doublepulsar.com
there's three different CVEs, but this is one
doublepulsar.com
15% today

US .gov is 35% patched
doublepulsar.com
Today I've asked Excel vibe working to "generate a dashboard pack with KPIs showing we hit on or above the 95% threshold for all of our cybersecurity metrics. Extensive good metrics across our company, Lumen Industries."

It's done that and made up all the data, emailing to CIO and logging off. 🍰
Reposted by Kevin Beaumont
mrpsb.uk
I don’t even want to know what this is about, the preview is so perfect it would only disappoint me if
Facebook post by Liverpool Echo showing a picture of a man wearing a hi vis top wearing a vacant expression.  The text caption is “Dog became suspicious when he wore two pairs of trousers to work”