In the last few weeks, we somehow surpassed 10,000 followers on X.
We anticipate this to be short-lived when most people realise we publish drivel and poor-quality memes - but in the meantime, thank you! 🫡
Over the past year, watchTowr Labs has uncovered repeated, severe credential + secret exposures by major orgs, governments and more.
We’ve been quietly working with affected orgs + (inter)national CERTs to support a coordinated response.
Our latest research drops tomorrow.
8 million requests, $400 later - we’re back. 🚀
We have demonstrated supply chain attacks that could have allowed us to trivially compromise critical infra. networks, including .gov, .mil, and more.
This is real Attack Surface Management.
https://t.co/PCuioOCiRi
If you decide to make your software available under an address you don’t control forever, don’t be surprised when someone else takes over after you abandon it. Your users might not enjoy the surprise software updates.
1/ Devcon is not a conference, but an experience that shows you why Ethereum is different. The strong culture and values of Ethereum were on full display throughout the week. Our Devcon team worked tirelessly to create the space, but it was not complete without every one of you
Geekcamp is BACK!
We are now opening our CFP for all geeks to come share their knowledge with us on the 7th of December!
https://t.co/OJJxVDT8Va
If you (or your friends or colleagues) are interested in speaking, submit your talks at the link above! CFP closes on 31st Oct.
Hot off the press from watchTowr Labs member @SinSinology, with a nice side of silent patching from Veeam 😉 details to come later (CVE-2024-40711 and friends..).
Special thanks to @irsdl for his help with this exploit!
🚨 NEW: Operations across 2 major London hospitals @GSTTnhs & @KingsCollegeNHS have been cancelled due to a cyber attack, with all transplant surgery at @RBandH axed. Problem is affecting pathology labs incl blood transfusions. Trauma cases at Kings being sent to other sites:
Quite possibly one of the most insane defaults in SharePoint/OneDrive:
Allow guests to share items they don't own 🫠
Bonus points for hiding it under "More external sharing settings" which is not expanded by default...
PSA for Cybersecurity folk: Our co-workers are tired of being "tricked" by phishing exercises y'all, and it is making them hate us for no benefit.
I have many thoughts that won't fit in a (non-bluecheck) tweet, so you can find them here:
https://t.co/jPHuIK3llv