Gallagher's Avatar

Gallagher

@dumpsterfire.life

Infosec: I like to build things and chase rabbits I am likely going to focus more on what I do outside of work on here rather than be Infosec focused... Outside of work: - astrophotography - hardware hacking - robotics - ham radio - cars - cats - potato

61
Followers
48
Following
8
Posts
10.05.2023
Joined
Posts Following

Latest posts by Gallagher @dumpsterfire.life

Preview
Self-replicating Shai-hulud worm spreads token stealing malware on npm | ReversingLabs | ReversingLabs RL researchers have detected the first self-replicating worm compromising popular npm packages with cloud token-stealing malware.

πŸ‘€
www.reversinglabs.com/blog/shai-hu...

16.09.2025 16:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Every Monday morning.

05.05.2025 12:46 πŸ‘ 8 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Turn on PSK Reporter spots and you can see in near real time how far your signal is being heard :) I use it to see how I need to adjust my power output up or down depending on band conditions.

21.04.2025 21:57 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Buying browser extensions for fun and profit An investigation into buying access to browsers through extensions

I acquired a Chrome extension for $5 and began redirecting the browsing traffic of existing users to whatever I wanted.

While doing so, I caught an ownership transfer of an extension with 400,000 installs that folks should be aware of.

www.secureannex.com/blog/buying-...

18.03.2025 13:58 πŸ‘ 23 πŸ” 11 πŸ’¬ 2 πŸ“Œ 1

β€œThe Enemy of Art is the Absence of Limitations” - Orson Welles

23.02.2025 19:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
How to detect malicious browser extensions using Elastic Learn how the Elastic Infosec team created a full inventory of all browser extensions using osquery and Elastic Security with examples on building detections to alert the security team when a known…

If you use Elastic, @acjewitt.bsky.social wrote up how you can use their osquery based agent to get an inventory of browser extensions in your environment allowing you to know what is installed by your users no matter what browser. More with Elastic to come πŸ‘¨β€πŸ³

06.02.2025 17:45 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

Has anyone found the new DOGE server they installed at the Treasury Department on Shodan yet? πŸ€”

06.02.2025 01:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Announcing the Elastic Bounty Program for Behavior Rule Protections β€” Elastic Security Labs Elastic is launching an expansion of its security bounty program, inviting researchers to test its SIEM and EDR rules for evasion and bypass techniques, starting with Windows endpoints. This initiativ...

www.elastic.co/security-lab...

28.01.2025 16:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Congrats my friend! πŸ™‚

17.01.2025 22:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image
06.01.2025 04:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ₯²

18.12.2024 04:45 πŸ‘ 20 πŸ” 2 πŸ’¬ 2 πŸ“Œ 0
Post image

nailedit

www.joanwestenberg.com/modern-work-...

11.12.2024 21:34 πŸ‘ 11 πŸ” 4 πŸ’¬ 1 πŸ“Œ 1

I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.

30.03.2024 17:13 πŸ‘ 687 πŸ” 275 πŸ’¬ 7 πŸ“Œ 13
A darker image of space that contains a number of stars and reddish clouds of gas. The clouds become pretty dense across the lower right corner. A cluster of bright stars at the top appear to be embedded in and very near  one of the gas clouds by the way their light reflects off of it.

A darker image of space that contains a number of stars and reddish clouds of gas. The clouds become pretty dense across the lower right corner. A cluster of bright stars at the top appear to be embedded in and very near one of the gas clouds by the way their light reflects off of it.

One of my hobbies outside of Infosec is astrophotography and this is one of the most recent images I have captured. I am still learning, but I am pretty happy with the way this turned out and wanted to share. This is the center of the Heart Nebula and was about 3.5 hours of exposure time (52 x 240s)

09.10.2023 12:28 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 1

On BlueSky we don't tweet, we post. Tweets go viral so what do posts on BlueSky do? Do my posts go "Stratocumulus" now vs "viral" ?

Will the cool kids be going around and saying, "My post went nimbus!"

24.07.2023 15:11 πŸ‘ 2 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0