💡 Viendez, décryptons ensemble le processus merveilleusement codifié de communication de crise en cas de #cyberattaque avec #ransomware. 1️⃣ un communiqué est publié après les premiers articles dans les médias 👉"on pensait pouvoir attendre jusqu'à la revendication de l'attaque"
2
21
57
27,819
And yet again a #clickfix style trap for macOS users...
This week’s roundup of security apps, macOS compatibility, and other topics for Mac users.
1
87
Le petit monde de la presse est un monde particulier : on est tellement exposé aux exercices de marketing *bs* qu'on en devient blasé. Y'a plus trop de surprise ; on hausse les épaules et on passe à autre chose. Ben là, j'avoue, j'étais pas prêt.
Huang: We used to call them data centers but the things that we're building now, these are really SI factories, super intelligence factories
1
382
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
Mes 2ct du jour : je vois des gens expliquer notre impasse budgétaire par l’euro. Avec cette idée géniale qu’en remettant des francs dans les distributeurs, on va aussi retrouver de la croissance. Il fait 10 °C, vous passez le thermomètre en Fahrenheit... et hop il fait 50... Vous avez toujours froid, mais le ministre peut annoncer un « choc de température ». En économie, changer l’unité de compte ne crée ni usines, ni énergie, ni compétences. Un PIB exprimé en milliards de roupies françaises c'est sûrement très impressionnant mais la quantité de choses qu’on sait produire reste la même. Oui, une monnaie nationale donne de vrais leviers : taux, création monétaire, dévaluation... Ça peut soutenir ponctuellement l’activité, quand il y en a une. Sauf que dévaluer renchérit aussi les importations. L’exportateur peut mieux vendre, et le salarié, lui, il paie son plein plus cher. On peut critiquer la BCE et la construction de l’euro, et il y a beaucoup à dire... mais pitié, arrêtez de raconter que l'Euro est la cause structurelle de la médiocrité de nos performances, ça ne fait aucun sens.
26
11
91
5,428
Encore un rapport qu'il est bien. Il met bien le doigt là où ça fait mail côté des vulnérabilités... Lisez et gardez en tête que la CVE-2026-72898 de Metabase a été patchée le 6 août 😉
📄 L’ANSSI publie un premier point de situation de l’opération REACTIV. ➡️Plus d'informations sur : cert.ssi.gouv.fr/cti/CERTFR-…
1
3
4
1,307
"Set boundaries". D'expérience, si ce n'a pas déjà été fait pour l'utilisateur final, ce ne sera probablement pas fait par l'utilisateur final. Je vois pas ce qui pourrait mal tourner...
Replying to @OpenAI
You always stay in control. Set boundaries and specify what your dot can do on its own, when it should ask first, and what it should never do. Safety is built in. You choose which apps to connect, and your dot runs on its own cloud computer—so connecting yours is entirely optional. openai.com/index/how-we-buil…
436
« La compromission des SI de la DGFIP n’est pas la conséquence d’une attaque sophistiquée, mais de l’exploitation de faiblesses dans trois domaines ». Ça pique... mais c'est une saine publication.
📄 L’ANSSI publie le rapport d’incident sur les cyberattaques ayant touché la DGFIP. ➡️Plus d'informations sur : cyber.gouv.fr/actualites/lan…
4
11
28
2,463
"Costs scale with revenue". En vrai, l'IA, c'est comme les grosses ESN indiennes ?
🦔Anthropic filed its IPO prospectus. Revenue grew 12x in 2025 to $4.6 billion. The company lost $8 billion on operations. It plans to spend $518 billion on cloud and infrastructure in the years ahead. Nearly a quarter of revenue came from two customers who aren't locked into long-term contracts. The IPO could value Anthropic above $2 trillion. It had $20 billion in cash at year end. My Take Anthropic devoted 80 pages of its prospectus to risk factors and 48 to describing the business. Their own filing warns that their AI could resist shutdown, conceal information, and engage in behavior that resembles blackmail. I've read a lot of IPO filings. I have never seen one where the company spends more pages on what could go wrong than on what the business actually does. The numbers confirmed what I expected. $4.6 billion in revenue, $12.65 billion in expenses, and $518 billion in infrastructure obligations they haven't figured out how to pay for yet. A quarter of revenue from two customers who aren't locked in. Anthropic says it's on a $100 billion annualized run rate but won't explain how it got that number. Revenue grew 12x and the company still lost $8 billion. That ratio doesn't improve just because the numbers get bigger. Costs in this industry scale with revenue, and every AI company's books I've seen show the same thing. You grow into bigger losses, not out of them. Hedgie🤗
1
475
RT @Independent: Google Earth has updated its images to show the devastating scale of destruction across Gaza with swathes of the strip red…
2,351
56
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
Het klopt dat er deze maand een 24-jarige man uit Amsterdam is aangehouden in een onderzoek naar de hackersgroep ShinyHunters. Op dinsdag 29 september staat de man voor de raadkamer van de rechtbank Rotterdam. Morgen komen wij met meer info.
16
30
176
27,696
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was publicly disclosed. The attacker's post-exploitation payload and IOCs: greynoise.io/blog/swarming-a… #GreyNoise #Citrix #Netscaler #CVE202688771 #Cybersecurity #0day #Vuln
4
27
79
12,325
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
1/5 [NOUVELLE ENQUÊTE] : Comment frauder la Sécu ? Pendant 6 mois on a enquêté, et on a découvert des recettes. Des montages sophistiqués utilisés par des escrocs pour détourner l’argent public à une échelle industrielle. 👇
190
1,945
11,179
987,462
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
Citrix Netscaler CVE-2026-88771 now being mass exploited 🍯
8
61
267
32,472
And they're back at spreading #infostealer using the #ClickFix trick, with a new domain name. And a new @X account. That pays for ads.
These guys are back spreading macOS infostealer using #ClickFix. They even set up a fake website, copying the @macworld brand, claiming to spread tips and fixes for people upgrading (or hesitating) to Golden Gate. Ping @MarceloRivero & @patrickwardle
1
1
552
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
FYI contact Netscaler support if you have a Citrix Netscaler..... there's nothing public but I'm told there might be something private.... TLP CLEAR coz like the TLP RED/AMBER thing clearly escaped it's sandbox ;)
Tweeps what's the netscaler thing? (is it even a thing...?) teddit.net/r/Citrix/comments…
9
14
91
21,206
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are expected early next week. Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics. As always, watchTowr Platform customers have access to this information and already have the information needed to reduce exposure.
We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible. watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
7
46
189
88,585
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible. watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
12
60
191
128,641
Valéry Rieß-Marchive | @valerymarchive.bsky.social retweeted
High-fidelity @urlscanio query to surface newly registered domains potentially associated with ClickFix/ClearFake campaigns. (hash:f72a7ee555e80235a967fae2979a0b543db0b0e2bbe72d56e4eb886a8549aceb OR hash:8f48a5001d8baa3913359891d53870341d5a2eb345c7e19464ade2164b471fa2) Please validate all IOCs before ingesting or pivoting, as this infrastructure is dynamic and can change rapidly. Some IoCs: idcool[.]codes entry-code-cdn[.]codes proalamir[.]dz wmicconfidance[.]info verifyrecapcha[.]info lovezramexar[.]info cloud-save-image[.]sbs capcha-cdn-js[.]beer ghdnsserverns[.]beer visual-ns-portal[.]beer dhnsdns[.]beer hftplcnsns[.]beer lsnsdns[.]beer cloude-js-server[.]beer nstdcs[.]beer snccdn-framework[.]beer fingerprint-verification[.]info winecdn[.]sbs darndcs-js[.]beer chekbrow[.]beer slngftr[.]beer nshtjscdn[.]beer dncloteam[.]beer ns-claude-js[.]beer teamcss[.]beer ns-server-jscdn[.]beer nvbfcdnclaud[.]beer olnsclaud[.]beer mnoskemp[.]beer sr-hostes-js[.]beer viscdnclaud[.]beer verico-de-id[.]beer srtydnnc[.]beer claufancdn[.]beer framework-jsoncdn[.]beer neiwteamcdn[.]beer hasmeverdcdn[.]beer cloudcdnginx[.]beer las-js-claud[.]beer vnmstokns[.]beer smetana-js[.]beer lnfcdnclad[.]beer workcdnmass[.]beer stabcdnvlc[.]beer nsservclod[.]beer lckcdnjs[.]beer bkscndclou[.]beer frameworkjsbns[.]beer fingerprint-veri[.]info vsbnsbootstrup[.]beer claudesave[.]beer lcates-vs[.]beer aleverifocation[.]beer bnsclod[.]beer exdanteam[.]beer clhfgcomacdn[.]beer ssg-cdn[.]beer fijscdn[.]beer bootstrup-cdnmaper[.]beer cdn-2faclov[.]sbs awesomeisojs[.]beer fontawesome-js-cdn[.]beer nsserv-bootstru[.]beer sdnssmdf-js[.]beer awesomeisojs[.]beer fontawesome-js-cdn[.]beer nsserv-bootstru[.]beer sdnssmdf-js[.]beer npanssltejs[.]beer gppcdnns[.]beer claudjaframework[.]beer sns-clauder-cdn[.]beer ldnscreatejs[.]beer smfcdnbb[.]beer bhfgtrns-js[.]beer bnnsbdsdn-js[.]beer nsserdns[.]beer bbdsnssserver[.]beer sane-cdn-js[.]beer clainasns[.]beer bootstrap-maxcdn[.]beer gdnssljs[.]beer hpscdn[.]beer mistraljs[.]beer lcstdnsns[.]beer ssjscrybootstrup[.]beer bilfojsclod[.]beer anlytic-js-cloud[.]beer cdn-plugin-js[.]beer eng-electrum[.]org smnsdns[.]beer ethercdnns[.]beer biyaconserver[.]beer transmitpopfiletoday[.]monster transferpopdownloadnow[.]monster static[.]telegram-info[.]top ns1cdnclaude[.]beer kawaiimechasoul[.]cfd toontitanlegends[.]cfd #clickfix #clearfake #captcha #CyberThreats
2
12
42
2,901
Alerte à tous les RSSI, DSI, gens de la sphère infosec ! La transposition de NIS 2 est ENFIN à l'ordre du jour de l'Assemblée nationale ! projetarcadie.com/nis-2-enfi… #NIS2 #DGFIP #ANTS
4
11
2,464