kurt baumgartner's Avatar

kurt baumgartner

@kurtisj

cybersecurity researcher. I have many leather-bound books and my apartment smells of rich mahogany. thanks for all the xor

104
Followers
109
Following
64
Posts
02.05.2025
Joined
Posts Following

Latest posts by kurt baumgartner @kurtisj

Preview
Is Now on VT! on X: "Although none of the Coruna hashes mentioned by Google and iVerify are on @virustotal just yet, we uploaded a number of samples from live exploit kit harvesting, using the URLs from the @ValidinLLC blog and also samples shared by @matteyeux on GitHub. Here's a list of" / X Although none of the Coruna hashes mentioned by Google and iVerify are on @virustotal just yet, we uploaded a number of samples from live exploit kit harvesting, using the URLs from the @ValidinLLC blog and also samples shared by @matteyeux on GitHub. Here's a list of

Although none of the Coruna hashes mentioned by Google and iVerify are on
@virustotal
just yet, we uploaded a number of samples from live exploit kit harvesting, using the URLs from the
@ValidinLLC
blog and also samples shared by
@matteyeux
on GitHu...

x.com/Now_on_VT/st...

07.03.2026 03:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

These ridiculous mega-projects like "datacenters in space" (doomed by thermodynamics) make a LOT more sense when you realize they're massive Ponzi schemes designed to transfer wealth from pension funds to VC's through "fee stacking."

It's the old Assets Under Management con. It should be illegal.

11.12.2025 09:29 πŸ‘ 3048 πŸ” 1062 πŸ’¬ 63 πŸ“Œ 49

If you are a resident of California, the state now has a portal where you can demand deletion of your personal data from 500+ registered data brokers with a single request form, for free.

consumer.drop.privacy.ca.gov

02.01.2026 02:26 πŸ‘ 11739 πŸ” 5191 πŸ’¬ 277 πŸ“Œ 362

MatrixLLC sanctioned "for their acquisition and distribution of cyber tools harmful to U.S. national security". it appears that they acquired eight stolen 0day and/or "tools" and sold to non-NATO

home.treasury.gov/news/press-r...

24.02.2026 21:38 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Russia charges Telegram founder Pavel Durov with facilitating terrorism as the Kremlin escalates its crackdown on the app β€” Meduza Russia has opened aΒ criminal investigation into Telegram founder Pavel Durov onΒ charges ofΒ facilitating terrorist activity, according toΒ articles published February 24Β in the nation’s newspaper…

Russia has reportedly launched a criminal investigation into Telegram founder Pavel Durov, accusing him of enabling "terrorist activity." This follows months of "traffic degradation" and attempts to move the public to Max, a state-sponsored alternative. meduza.io/en/feature/2...

24.02.2026 06:26 πŸ‘ 44 πŸ” 25 πŸ’¬ 3 πŸ“Œ 9

I don’t understand how people can say the billionaires are out of touch, this person has obviously studied humans.

21.02.2026 22:37 πŸ‘ 34 πŸ” 3 πŸ’¬ 6 πŸ“Œ 0

you brought his search history to bluesky? you are the pam bondi of playground romance committee

15.02.2026 09:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Epstein is mentioned very often in the Trump files.

08.02.2026 08:02 πŸ‘ 1423 πŸ” 260 πŸ’¬ 0 πŸ“Œ 0
Preview
AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty) β€” LessWrong This is a partial follow-up to AISLE discovered three new OpenSSL vulnerabilities from October 2025. …

Have we reached the stage of β€œmany AIs make all bugs shallow”?
Great writeup on AI, open source, & bug bounties by @stanislavfort.bsky.social cofounder of AISLE.

β€œMass adoption collapsed the median quality (β€œslop” killed bug bounty..) but.. raised the ceiling”

www.lesswrong.com/posts/7aJwgb...

30.01.2026 19:18 πŸ‘ 12 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0

ghidrav12 pyghidra problems?
pip/pip3, versioning, virtual environments?

unpopular opinion - python still sucks

30.01.2026 19:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

if only they collected a royalty every time that thing showed up. or they could have charged per pew...

29.01.2026 15:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

the related propublica link is here

www.propublica.org/article/the-...

26.01.2026 16:49 πŸ‘ 3 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
Predator iOS Spyware: Undocumented Anti-Analysis Techniques Jamf Threat Labs reveals Predator spyware's sophisticated anti-analysis capabilities including error code taxonomy, crash monitoring and detection evasion.

www.jamf.com/blog/predato...

26.01.2026 04:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Cyberattack Targeting Poland’s Energy Grid Used a Wiper A cyberattack that targeted power plants and other energy producers in Poland at the end of December used malware known as a β€œwiper” that was intended to erase computers and cause a power outage and o...

Exclusive: A cyberattack targeting Poland's energy infrastructure in December used wiper malware that would have erased grid computers and rendered them inoperable had it not been thwarted, a researcher at @ESET told me. The researcher calls the attack "unprecedented" for Poland and "substantial"

23.01.2026 16:33 πŸ‘ 62 πŸ” 59 πŸ’¬ 2 πŸ“Œ 7
Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cyb...
Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cyb... YouTube video by Three Buddy Problem

great start with opsec tips...
1. don't upset the tail.
2. if you end up face to face, just ask for the time and DO NOT take a selfie with them. :)
3. oh yeah, and use google docs, at the appropriate time. no surprises.

youtu.be/pooCY4ZOYSM?...

17.01.2026 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
DEF CON Radio from SomaFM Music for Hacking. The DEF CON Year-Round Channel.

Just a friendly reminder that the exemplary humans at @somafm keep #defconradio going all year long. Stream the vibe immaculate at somafm.com/defcon/.

#defcon #grooves

16.01.2026 23:54 πŸ‘ 15 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

kevin still maintains the title for the best business card i received

13.01.2026 21:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Confessions to a data lake I’ve been building Confer: end-to-end encryption for AI chats. With Confer, your conversations are encrypted so that nobody else can see them. Confer can’t read them, train on them, or hand them over ...

Advertising is coming (to AI)

confer.to/blog/2025/12...

23.12.2025 18:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

sorry, disagree. this person has certainly heard of the civil rights movement...

21.12.2025 16:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Looking Back at 2025's Cybersecurity Landscape: Key Trends to Watch in 2026 An intelligence analyst's perspective on the dominant cybersecurity trends of 2025, from AI-driven threats to supply chain vulnerabilities and the evolving APT landscape

Looking Back at 2025's Cybersecurity Landscape: Key Trends to Watch in 2026
tlpblack.net/blog/2025121...

18.12.2025 20:36 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Belarusian KGB put spyware on phones of detained journalist.

Growing list of cases where authoritarian regimes use detention to implant spyware on phones:

🦠Belarus
🦠Kenya
🦠Serbia

And likely plenty more.

Important investigation & reminder that dictators don't always need zero-days.

17.12.2025 15:45 πŸ‘ 55 πŸ” 36 πŸ’¬ 1 πŸ“Œ 0
The Anatomy of a React2Shell Compromise Analysis of React Server Components RCE vulnerability (CVE-2025-55182) exploitation leading to cryptojacking campaigns targeting Next.JS applications

React2Shell Exploitation in the Wild: CVE-2025-55182 Analysis

Full technical analysis on our blog:

tlpblack.net/blog/2025120...

09.12.2025 21:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

i was cranked up on a cranberry sauce rage yesterday. there were no posters to warn us

28.11.2025 16:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Someone on Twitter writes: "Why are we normalizing $85-90 hoodies?" The attached photo shows a woman who looks exasperated.

Someone on Twitter writes: "Why are we normalizing $85-90 hoodies?" The attached photo shows a woman who looks exasperated.

Let me show you the difference between a $40 hoodie and a ~$100 hoodie. 🧡

12.11.2025 22:53 πŸ‘ 2789 πŸ” 421 πŸ’¬ 65 πŸ“Œ 80
Preview
RE//verse 2026 Training - Advanced Linux Malware Reverse Engineering with Marion Marschalek This fast-paced 3-day training explores Linux internals and Linux binary analysis techniques, before jumping right in with common Linux malware. Work through advanced samples, Linux software protectio...

Squeeeee πŸ₯³ I'll be teaching my Advanced Linux Malware Reverse Engineering class at RE//verse conference in 2026!! MORE Linux APT insides and peculiarities😍πŸ₯°πŸ€©Pls share if you canπŸ™ƒ
shop.binary.ninja/products/re-...

12.11.2025 18:59 πŸ‘ 24 πŸ” 12 πŸ’¬ 0 πŸ“Œ 0

cool. aluminum can strip?

08.11.2025 00:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.

The spyware is delivered through malformed DNG image files exploiting CVE-2025-21042...

The exploit chain possibly involved zero-click delivery using maliciously crafted images, similar to recent exploit chains seen on iOS and Samsung Galaxy.

unit42.paloaltonetworks.com/landfall-is-...

07.11.2025 15:00 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.Β  Key findingsΒ  Between June and August 2025,

New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...

05.11.2025 13:37 πŸ‘ 18 πŸ” 12 πŸ’¬ 2 πŸ“Œ 0
according to the liberation newspaper, documents dating back to a 2014 inspection by the French National Agency for the Security of Computer Systems reported a staggering detail: "the password of the louvre's video surveillance server was simply " louvre. "

according to the liberation newspaper, documents dating back to a 2014 inspection by the French National Agency for the Security of Computer Systems reported a staggering detail: "the password of the louvre's video surveillance server was simply " louvre. "

the password to the louvre surveillance server was "louvre"

www.thesocialpost.it/2025/11/02/f...

03.11.2025 17:56 πŸ‘ 11108 πŸ” 3020 πŸ’¬ 314 πŸ“Œ 1784
Preview
Alleged Jabber Zeus Coder β€˜MrICQ’ in U.S. Custody A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of millions of dollars from U.S. businesses was arrested in Italy and is now in custody in the United States...

another jabberzeus roundup!
krebsonsecurity.com/2025/11/alle...

03.11.2025 18:34 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0