Jennifer Wood
@notnextjen.bsky.social
290 followers 210 following 13 posts
Space geek, roaming gnome, comms at Luta Security. Ex-USG: OMB, NASA, EPA, U.S. Senate. Formerly Kaspersky, Avast, BlackBerry, Microsoft/WE Comms. https://www.linkedin.com/in/jenniferjwood/
Posts Media Videos Starter Packs
notnextjen.bsky.social
Today is the day…#LABScon2025 is live from Phoenix, AZ. Get ready for two days of unique research and excellent speakers.
Reposted by Jennifer Wood
zackwhittaker.com
New: French phone giant Bouygues confirmed a data breach affects the personal information of 6.4 million customers.

Bouygues disclosed the breach on a dedicated web page; however, the page is currently deliberately excluded from search engines using "noindex" code, making it more difficult to find.
Data breach at French telecom giant Bouygues affects millions of customers | TechCrunch
This is the latest cyberattack to hit a French cellular carrier in recent weeks, following an attack on Orange Telecom in July.
techcrunch.com
notnextjen.bsky.social
Enjoying the #threebuddyproblem podcast live from BH /Vegas!
notnextjen.bsky.social
If all goes to plan, I’ll be in Vegas for #BlackHat this week. DM me if you would like to meet. See y’all soon and safe travels to all!
Reposted by Jennifer Wood
threatintel.microsoft.com
Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately.

Full guidance and detection details: msft.it/6010sDzSE.
Reposted by Jennifer Wood
josephcox.bsky.social
New from 404 Media: a startup is selling data hacked from peoples' computers to debt collectors, divorce lawyers, more. People already hacked, now being re-vicitmized by startup. I used the tool, found peoples' personal addresses.

“This is so gross and predatory.”

www.404media.co/a-startup-is...
A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors
Infostealer data can include passwords, email and billing addresses, and the embarrassing websites you use. Farnsworth Intelligence is selling to to divorce lawyers and other industries.
www.404media.co
notnextjen.bsky.social
No patch but here’s the suggested mitigations from MSFT:
Configure Antimalware Scan Interface integration in SharePoint and deploy Defender AV on all SharePoint servers, and/or consider disconnecting your server from the internet until a security update is available.

www.forbes.com/sites/daveyw...
Microsoft Confirms Ongoing Mass SharePoint Attack — No Patch Available
Microsoft has confirmed that SharePoint Server is under mass attack and no patch is yet available — here’s what you need to know and how to mitigate the threat.
www.forbes.com
Reposted by Jennifer Wood
metacurity.com
A website developed for the UK Home Office's 2022 "flop" anti-encryption campaign has seemingly been hijacked to push a payday loan scheme.
www.theregister.com/2025/06/25/h...
Home Office anti-encryption site pushes payday loan scheme
: Company at center of findings blamed SEO on outsourcer
www.theregister.com
Reposted by Jennifer Wood
ericjgeller.com
Iran's APT42 (Charming Kitten) hacker team is now conducting targeted spearphishing attacks on high-profile Israeli national security journalists and cybersecurity researchers, according to Check Point. blog.checkpoint.com/security/edu...
Reposted by Jennifer Wood
lutasecurity.bsky.social
#Cryptocurrency Exchanges—Do you need a security assessment? Do you need an audit for your #bugbounty program? Hire LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure & handling processes. @lutasecurity.bsky.social www.lutasecurity.com/bug-bounty-s...
Bug Bounty Solutions | Luta Security
Luta Security provides bug bounty program audits, offers end-to-end vulnerability case resolution management, creates new VDP and bug bounty programs, and performs security maturity assessments.
www.lutasecurity.com
Reposted by Jennifer Wood
lorenzofb.bsky.social
NEW: The Trump admin has fired members of the Cyber Safety Review Board, a committee that was lauded for its investigation into Microsoft hacks of 2023, and was working on the recent Salt Typhoon telco hacks.

One source called it a “horribly shortsighted” decision.

techcrunch.com/2025/01/22/t...
Trump administration fires members of cybersecurity review board in “horribly shortsighted” decision | TechCrunch
The Department of Homeland security told members of the Cyber Safety Review Board that their membership was terminated.
techcrunch.com
notnextjen.bsky.social
Back in DC. Not for political reasons. Still feels like home.