Jeremy Kirk
@jkirk.bsky.social
4K followers 1.1K following 600 posts
Threat intel @ Intel 471 (@intel471.bsky.social). Personal account. Interests: Cybercrime, cyber threat intelligence, OSINT, data breaches, photography. Also produce Intel 471's "Cybercrime Exposed" podcast. #Australia
Posts Media Videos Starter Packs
Pinned
jkirk.bsky.social
A new episode of @intel471.bsky.social's Cybercrime Exposed podcast is out! DukeEugene is a Russian Android malware dev who has a big problem, and he puts everything on the line to solve it. Link to pod here: www.intel471.com/resources/po...
jkirk.bsky.social
The Register reports Microsoft has cut off Chinese vendors from its MAPP program, which gives advanced warning of pending patches so vendors can prepare. #infosec www.theregister.com/2025/08/21/m...
www.theregister.com
jkirk.bsky.social
A new episode of @intel471.bsky.social's Cybercrime Exposed podcast is out! DukeEugene is a Russian Android malware dev who has a big problem, and he puts everything on the line to solve it. Link to pod here: www.intel471.com/resources/po...
jkirk.bsky.social
Trail of Bits has open-sourced its Buttercup Cyber Reasoning System, an AI tool that can find vulnerabilities in open source repositories and then patch them using a multi-agent AI patcher. #infosec Project here: github.com/trailofbits/...
GitHub - trailofbits/buttercup
Contribute to trailofbits/buttercup development by creating an account on GitHub.
github.com
Reposted by Jeremy Kirk
phrack.org
Phrack turns 40.
The digital drop is live.
Download it. Archive it. Pass it on.
💾 www.phrack.org
#phrackat40 #phrack72
Phrack 40th Anniversary ansi art by Harvest
jkirk.bsky.social
Onery Apple decided to comply with right-to-repair laws by making spare parts available but for massively, makes-no-sense prices. A $20 charge port is being sold for $250. Outrageous. By @404media.co. www.404media.co/apple-is-sel...
Apple Is Selling iPad Repair Parts for Astronomical Prices
“I believe Apple is charging this because they know if the price is high enough no one will buy it."
www.404media.co
jkirk.bsky.social
Well, if this is accurate so be it - fair, scoped play. At least US spies didn't try to exploit every vulnerable one it found on the internet, like (ahem). #infosec www.theregister.com/2025/08/01/c...
China: US spies used Microsoft Exchange 0-day to steal info
: Spy vs. spy
www.theregister.com
jkirk.bsky.social
Some 110,000 ChatGPT conversations that were (inadvertently?) allowed by users to become discoverable via search engines were picked up in the Wayback Machine. www.digitaldigging.org/p/chatgpt-co... #infosec
ChatGPT Confessions gone? They are not !
OpenAI closes gap, but another opens of 110.000 chats
www.digitaldigging.org
Reposted by Jeremy Kirk
bencollins.bsky.social
Holy shit, they did it. They wrote the headline.
NYC Mass Shooting Was Nearly Impossible to Prevent, Experts Say
jkirk.bsky.social
@campuscodi.risky.biz Coming off the SharePoint flaw mess, I found this line in the Risky Bulletin hilarious 🤣.
jkirk.bsky.social
Jacob Larsen is an #infosec pro who was involuntarily pulled into the dark world of doxing. I spoke with him about doxing's effects, how sites like Doxbin use legal loopholes and how to defend against being doxed. Latest Studio 471 podcast from @intel471.bsky.social
www.youtube.com/watch?v=y5AO...
Defending against doxing ft. Jacob Larsen, Threat Researcher, Offensive Security Lead, CyberCX
YouTube video by Intel 471
www.youtube.com
jkirk.bsky.social
The infamous XSS cybercrime forum appears to have been seized. #infosec
Reposted by Jeremy Kirk
threatintel.microsoft.com
Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately.

Full guidance and detection details: msft.it/6010sDzSE.
Reposted by Jeremy Kirk
propublica.org
Our investigation revealed how a little-known Microsoft program could leave some of the U.S. government’s most sensitive data vulnerable to hacking from its leading cyber adversary.

TL;DR, these are the 9 biggest takeaways ⤵️
jkirk.bsky.social
Seems to come in waves for me. There will be months where I get 2-3 a day and the last several months nothing at all.
jkirk.bsky.social
Aldi is selling 50-gram packets of "hand picked" dried mixed forest mushrooms this week if anyone is interested, mmmmm? #Australia
jkirk.bsky.social
Low-quality bug reports generated by AI are overwhelming open-source projects such as curl and Python. This might necessitate projects moving to bug reporting platforms where security researchers are vetted rather than leaving an open inbox. #infosec www.theregister.com/2025/07/15/c...
Curl creator mulls nixing bug bounty awards to stop AI slop
: Maintainers struggle to handle growing flow of low-quality bug reports written by bots
www.theregister.com