Somewhere in between foodie, wine lover and security geek Python đź’™| B4C2 - profiling web injects | cancer survivor

APD
Pinned Tweet
There is a difference between posting IOCs and TTPs for behaviors found and investigated. Not querying a hunting platform who collected data or from platforms indexing past occurrences. Go follow behaviors, discover GENUINELY NEW INTEL! That is the joy of the hunt!
2
5
490
Patched @NetScaler for CTX697096 and use SAML? Patch again. CVE-2026-88779 is a separate bulletin, CTX697174 (CVSS 8.7), not part of CTX697096. It's the SAML attack crashing patched NetScalers since 2 Oct. @citrix sees targeted attacks. Affected: "add authentication samlAction" or "samlIdPProfile" in ns.conf Fixed: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 Interim: Global Deny List (NetScaler Console) or Citrix Support's responder policy, -type AAA_REQUEST on every Gateway/AAA vserver Free checker v1.12 covers both bulletins: • CVE-2026-88779 on every run • SAML policy coverage per vserver • "may have run" window ends at the fix • 98 IPs, 16 domains, 34 hashes Thanks to @GothamTG , @BeazleySecurity , @Deyda84 , @citrixguyblog , @rjfaulknerjr @FerroqueSystems, @bishopfox , @watchtowrcyber and the community 🙏 #NetScaler #Citrix #CitrixNetScaler #NetScalerGateway #CVE202688779 #CVE202688771 #CTX697174 #CTX697096 #CyberSecurity #InfoSec #IncidentResponse #ThreatHunting
12
35
2,631
WASN'T US.
#BREAKING: Lab technician dies of suspected pneumonic plague in Russia after breaking test tube.
609
8,515
59,805
1,323,881
Varys retweeted
Do you write Cybersecurity incident reports and need to spice up the language so the report isn’t so boring?? Instead of saying we suffered a breach due to the compromise of a 3rd party partner, say instead: >we got fucked in the aaS Follow me for more pro writing tips
6
13
186
4,677
Varys retweeted
73
215
3,320
Varys retweeted
We are tracking rumors + honeypot activity relating to a new vulnerability affecting Citrix appliances, acknowledged just now in a Citrix blog. It is currently unclear whether this is “DoS via bad patch" or "another bad vuln in SAML config'd appliances" Our hearts 💔
9
47
190
33,580
Varys retweeted
1
4
28
969
Today Reuters reported that Spanish authorities arrested the leader of KillSec ransomware group. He is 16 years old. Who are these people bro? When I was 16 I was being a nerd and doing malware stuff, but I also was doing stuff like talking to girls, learning how to drive, going to school events, etc. How are you going to do international cybercrime at 16? You're only a kid once, enjoy being a kid and having some freedom. Go outside, touch some grass, hold a girls hand, throw a ball, look at silly pictures of cats. Pic unrelated
58
59
1,532
39,235
Found an open directory on #Microsoft #Azure: 160 files, 647 MB, with #AsyncRAT, #XWorm, and #PhantomStealer sitting in plain sight. Host: 51.144.45[.]141 ASN: Microsoft (AS8075) Location: Amsterdam, NL Explored with @Huntio
1
12
17
835
‼️ A WordPress backdoor can rebuild itself after cleanup. SC keeps redundant copies across files, the database, and, where supported, System V shared memory. Any surviving copy can restore the malware, while Ethereum is used for command-and-control. Inside the reinfection loop: thehackernews.com/2026/10/wo…
13
36
116
29,419
Varys retweeted
🚨 We are seeing in-the-wild exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-76504 / API auth bypass) in our honeypots since Sep 30 UTC, about seven hours after Cisco's advisory. Attackers are hex-encode the login path (/%6a_security_check) to slip past the auth rule and reach the admin API. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
11
31
3,713
⚡ Attackers are exploiting a Citrix NetScaler flaw to gain root access and hide PHP web shells behind .deb and .sig files. The attacks also deploy SLAPSHOT, a Python tunneler. In at least one case, attackers used it for internal reconnaissance and credential theft. Inside the attack chain: thehackernews.com/2026/09/at…
9
25
118
37,859
Security ran a phishing test offering employees a free catered lunch. 72% clicked. Leadership was furious. “People need better security instincts.” So we ran another test. Fake password expiration notice. 14% clicked. Fake payroll update. 9%. Fake message from the CEO. 6%. Then I sent: “Someone left a box of Krispy Kreme in the 4th floor kitchen.” 81%. No malicious link. No fake login page. Just a button labeled: VIEW DONUTS Security asked what we learned. I said our attack surface is glazed. HR has now banned food-based phishing simulations because they’re “unreasonably persuasive.” Apparently hackers are still allowed to use them.
17
96
1,819
57,326
Varys retweeted
6
23
468
Varys retweeted
Data from Censys shows about 36,000 NetScaler appliances exposed to the Internet. via @DecipherSec
Researchers Warn of Citrix NetScaler Exploitation decipher.sc/2026/09/27/resea… #decipher #deciphersec
2
7
13
2,056
🚨 CVE-2026-59310: VMware vCenter RCE A directory traversal flaw in the vCenter Syslog server can lead to arbitrary code execution. CVSS 9.8 | KEV | Public exploit Ransomware use: Known ExploitGrid: 95/100 Critical 🔎 exploitgrid.net/vulnerabilit…
1
18
96
7,426
Varys retweeted
Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. bit.ly/3T4RXGY
14
123
221
99,887
🚨 UPDATE: WORDPRESS CVE-2026-87902 HAS MOVED FROM PROBING TO ACTIVE RCE — ATTACKERS NOW WRITING PHP FILES TO SERVERS The WordPress core vulnerability we flagged earlier has materially escalated. Patchstack now reports active exploitation attempts reaching actual code execution, not just reconnaissance. • CVE-2026-87902 is an unauthenticated path traversal/LFI flaw with conditional RCE in WordPress Core • Patchstack observed the first malicious activity on September 22 at 11:49 UTC — the same day WordPress 7.1.2 and the advisory were released • By 15:34 UTC, attackers were already attempting to use pearcmd.php to write attacker-controlled PHP files to disk • Attack traffic has grown to more than 10× the volume seen on the first evening and is now coming from hundreds of addresses • The exploitation chain has progressed through three stages: vulnerability probing → checking whether pearcmd.php is reachable → arbitrary PHP file writes/code execution • Public scanning tooling is now circulating, including a named Nuclei template, materially lowering the barrier to mass exploitation • Observed files include wp-pear-rce-flag.php, poc87902.php, luci_<random>.php, and zeta_<random>.php in /tmp and /var/tmp • Patchstack says some payloads execute shell commands; this is no longer just researcher scanning • Affected versions are WordPress 4.7.0 through 7.1.1; fixes have been backported across supported security branches ⚠️ Analyst Note: This changes the risk assessment from our earlier post. At that point there was no confirmed in-the-wild exploitation; there now is direct telemetry showing attackers moving from patch-diff reconnaissance to code-execution attempts in hours. The speed is the key signal: the patch-to-exploitation window effectively collapsed to the same day. Any site that remained exposed during that window and meets the theme/PHP prerequisites should be reviewed for compromise rather than treated as a patch-only event. Original Patchstack threat telemetry: patchstack.com/articles/cve-… #WordPress #CVE202687902 #RCE #ActiveExploitation #WebSecurity #ThreatIntel #DDW
1
11
28
7,465
Keep your dreams bigger than your fears.
9
98
714
10,070