Aprovecho la ocasión para presentar la alternativa a YouTube que lanzamos hoy, una plataforma propia para nuestro contenido de hacking y ciberseguridad.
Nos meten un strike, una semana silenciados, publicamos el vídeo y hoy YouTube se cae.
Casualidades.
https://t.co/pNtrnt6SsC
🇲🇽
Dentro de los preparativos que 🇲🇽 está implementando para el mundial, dicen que utilizarán herramientas de inteligencia artificial para identificar personas con mandamientos judiciales
- Reconocimiento facial
- Lectores de placas
- Atención del 911 con IA
- Uso de una aplicación llamada Nexus
- De 20k a 30k cámaras
Pero...
Editor para crear diagramas isométricos 3D de tu arquitectura de software e infraestructura.
Funciona desde el navegador, sin registros y es open source: https://t.co/d7r3jUcUlD
Alguien ha recopilado TODAS las canciones de Spotify y las ha subido como un torrent de 300 TB.
Una copia de seguridad de Spotify (metadatos y archivos de música)
Se distribuye en torrents masivos (~300 TB), agrupados por popularidad
https://t.co/3xTk2L2X2I
🚨 110+ Splunk Queries for SOC Analysts ⚡🔍
Just found a huge collection of real-world detection queries a goldmine for SOC analysts, threat hunters, and blue teamers.
Comment PDF for the full guide with ready to use queries
Tor ha anunciado una mejora en el cifrado y la seguridad del tráfico del circuito mediante la sustitución del antiguo algoritmo de cifrado de retransmisión tor1 por un nuevo diseño denominado Counter Galois Onion (CGO)
https://t.co/JJ1MMhI45D
𝗪𝗵𝗮𝘁 𝗵𝗮𝗽𝗽𝗲𝗻𝘀 𝘄𝗵𝗲𝗻 𝗖𝗹𝗼𝘂𝗱𝗳𝗹𝗮𝗿𝗲 𝘁𝗮𝗸𝗲𝘀 𝗱𝗼𝘄𝗻 𝗵𝗮𝗹𝗳 𝘁𝗵𝗲 𝗜𝗻𝘁𝗲𝗿𝗻𝗲𝘁
Last week, Cloudflare took down ChatGPT, Claude, X, Reddit, Spotify, Uber, and thousands of other sites on November 18. The root cause? A ClickHouse permissions change made a query return duplicate rows.
𝗛𝗲𝗿𝗲'𝘀 𝘄𝗵𝗮𝘁 𝗯𝗿𝗼𝗸𝗲
Bot Management uses a machine learning model to score every request. The model needs a feature file listing the traits it uses to detect bots. This file is refreshed every 5 minutes and deployed across Cloudflare's entire network.
The engineering team was improving security by moving from shared system accounts to individual user accounts. They updated database permissions to make access explicit instead of implicit.
This changed the behavior of one query. Instead of returning ~60 features from the "default" database, it now pulls from both "default" and "r0", returning over 200 features. The Bot Management module had a hard limit of 200. It panicked. The proxy crashed.
The file is deployed every 5 minutes. Good and bad versions rolled out randomly depending on which ClickHouse nodes generated them. Systems would recover, then fail again. This pattern appeared to be a DDoS attack.
Then Cloudflare's status page went down, completely unrelated, but it reinforced the attack theory. The team spent 2.5 hours investigating the wrong problem.
By 14:30, they identified the bad configuration file, stopped propagation, and deployed a known-good version. Full recovery took until 17:06 (2.5 hours).
𝗪𝗵𝗮𝘁 𝗲𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝘀 𝗰𝗮𝗻 𝗹𝗲𝗮𝗿𝗻 𝗳𝗿𝗼𝗺 𝘁𝗵𝗶𝘀 𝗲𝘃𝗲𝗻𝘁
• 𝗨𝗻𝘄𝗿𝗮𝗽() 𝗸𝗶𝗹𝗹𝘀 𝘀𝘆𝘀𝘁𝗲𝗺𝘀. The Rust code used `.unwrap()` on a function that could fail. No error logging. No graceful degradation. When the limit was reached, the system panicked rather than logging what went wrong. If the error had been logged, they'd have found the root cause in minutes, not hours.
• 𝗚𝗹𝗼𝗯𝗮𝗹 𝗱𝗮𝘁𝗮𝗯𝗮𝘀𝗲 𝗰𝗵𝗮𝗻𝗴𝗲𝘀 𝗮𝗿𝗲 𝗶𝗻𝘃𝗶𝘀𝗶𝗯𝗹𝗲 𝗴𝗿𝗲𝗻𝗮𝗱𝗲𝘀. The permissions change seemed safe. No one predicted it would double query results. There's no good way to test this. Staging environments won't catch it. The lesson: assume any global change can trigger unexpected behavior in parts of the system you don't control.
• 𝗖𝗼𝗶𝗻𝗰𝗶𝗱𝗲𝗻𝗰𝗲𝘀 𝗺𝗶𝘀𝗹𝗲𝗮𝗱 𝗳𝗮𝘀𝘁𝗲𝗿 𝘁𝗵𝗮𝗻 𝗹𝗶𝗲𝘀. Two unrelated failures at the same time sent the team down the wrong path. The status page failure made the DDoS theory credible. You can't blame them. Cloudflare is under constant attack. But it cost them 2.5 hours. The fix: trust the data over the narrative.
• 𝗖𝗗𝗡𝘀 𝗮𝗿𝗲 𝘀𝗶𝗻𝗴𝗹𝗲 𝗽𝗼𝗶𝗻𝘁𝘀 𝗼𝗳 𝗳𝗮𝗶𝗹𝘂𝗿𝗲. Most companies can't afford a backup CDN or the infrastructure to absorb traffic spikes if their CDN fails. Cloudflare's outage proves how much of the internet depends on a handful of providers. There's no easy answer here. The dependency is real, and the alternatives are expensive.
• 𝗣𝗼𝘀𝘁𝗺𝗼𝗿𝘁𝗲𝗺𝘀 𝘀𝗵𝗼𝘂𝗹𝗱 𝘀𝗵𝗶𝗽 𝗳𝗮𝘀𝘁. Cloudflare published theirs in 24 hours. CEO Matthew Prince wrote the first draft during the incident; the team filled in the gaps overnight and shipped it the next day. Most companies take weeks. The value of a postmortem drops every day you wait.
‼️CrowdStrike confirmed they were hit by an insider threat, someone took screenshots on internal systems and shared them with scattered LAPSUS$ hunters.
scattered LAPSUS$ hunters confirmed to us they paid $30K in total to the insider and gained direct access after receiving SSO authentication cookies.
CrowdStrike identified the insider threat quickly and revoked access.