Zak's Avatar

Zak

@zakthoreson

SecOps | Cloud | OT Interested in F1 🏎️ and Cycling 🚴 πŸ“ https://medium.com/@zakthoreson πŸ‘Ύ https://github.com/ZakThoreson

44
Followers
117
Following
68
Posts
19.10.2023
Joined
Posts Following

Latest posts by Zak @zakthoreson

Post image

My top #GitHub list for cybersecurity projects is updated for this month. Explore top FOSS projects spanning both the defensive and offensive sides πŸ˜ŽπŸ‘‡

Find a high-res pdf book with all my #cybersecurity related infographics from study-notes.org

#infosec #pentesting #informationsecurity

27.01.2026 13:10 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Great read! Very interesting use of stenography to obfuscate payloads.

25.11.2025 13:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CISA, eyeing China, plans hiring spree to rebuild its depleted ranks The agency will also change some of its workforce policies to avoid driving away talented staff.

Scoop: CISA plans to embark on a hiring spree and change some workforce policies in an effort to rebuild its depleted ranks ahead of a possible conflict with China, according to a memo from its acting director that I obtained.

www.cybersecuritydive.com/news/cisa-hi...

17.11.2025 21:30 πŸ‘ 44 πŸ” 35 πŸ’¬ 8 πŸ“Œ 11
Post image

We identified a malvertising campaign targeting users searching for legitimate software, leading to the download of a trojanized WinSCP installer that deployed Broomstick/OysterLoader.

All files involved in the initial access phase were signed with valid certificates.

16.10.2025 13:29 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Salesforce refuses to pay ransom over widespread data theft attacks Salesforce has confirmed that it will not negotiate with or pay a ransom to the threat actors behind a massive wave of data theft attacks that impacted the company's customers this year.

Seems the 1 billion records is a collection of all the organizations breached. Salesforce will not be paying the ransom. Also, an interesting note at the end about the leak site potentially being seized
www.bleepingcomputer.com/news/securit...

08.10.2025 13:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Super helpful thread - thanks for the intel

06.10.2025 16:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Kevin Beaumont (@GossiTheDog@cyberplace.social) Attached: 1 image LAPSUS$ have now listed the breach at Red Hat on their portal. They have posted CER - Consulting Engagement Requests. Sensitive info, for AMEX, Atos, HSBC, Walmart, NHS Scotland am...

LAPSUS have the Red Hat gitlab breach up on their portal

They’ve posted Consulting Engagement Requests for AIR, AMEX_GBT, Atos_Group (NHS Scotland), BOC, HSBC and Walmart. Also a file tree, 370,852 directories, 3,438,976 files.

cyberplace.social/@GossiTheDog...

05.10.2025 23:44 πŸ‘ 20 πŸ” 7 πŸ’¬ 2 πŸ“Œ 0
Preview
Shutdown guts U.S. cybersecurity agency at perilous time The lead U.S. agency for protecting the electric grid, water supply and other critical services from hacking has furloughed most of its staff.

The lead U.S. cyber defense agency has furloughed 65% of its staff. The 20-year-old law that encourages organizations to share information on attacks just expired. Happy Cybersecurity Awareness Month! wapo.st/46Nk53R

02.10.2025 14:51 πŸ‘ 175 πŸ” 88 πŸ’¬ 13 πŸ“Œ 14
Post image

New: The Multi-State Information Sharing and Analysis Center lost its federal funding at midnight. Here's my story about what happened, why it matters, and how the group β€” a critical resource for state and local governments β€” is trying to move forward: www.cybersecuritydive.com/news/ms-isac...

01.10.2025 14:04 πŸ‘ 55 πŸ” 35 πŸ’¬ 2 πŸ“Œ 6
Preview
You name it, VMware elevates it (CVE-2025-41244) NVISO has identified zero-day exploitation of CVE-2025-41244, a local privilege escalation vulnerability impacting VMware's guest service discovery features.

Great write-up from NVISO Labs on #CVE-2025-41244
blog.nviso.eu/2025/09/29/y...

Privilege escalation zero-day in VMWare Tools & Aria Operations actively exploited

30.09.2025 18:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

When sharing articles or open-source intel, be sure to read and digest the entire article. Be an expert on the data or information you're communicating, or things may slip through the cracks.

Don't just be a reposter; communicate *how* or *why* the information being shared is important.

29.09.2025 13:39 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Interview with Cloud Architect in 2025
Interview with Cloud Architect in 2025 YouTube video by Kai Lentit

Public S3 Bucket is not a mistake, it's a 'Growth Hacking Funnel'
www.youtube.com/watch?v=xIk0...

25.09.2025 17:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Anatomy of a Billion-Download NPM Supply-Chain Attack A massive NPM supply chain attack has compromised foundational packages like Chalk, affecting over 1 billion weekly downloads. We dissect the crypto-stealing malware and show you how to protect your p...

Supply chains are so much fun! jdstaerk.substack.com/p/we-just-fo...

09.09.2025 14:53 πŸ‘ 75 πŸ” 14 πŸ’¬ 4 πŸ“Œ 1
Post image

Reading material:

www.nsa.gov/Press-Room/P...

27.08.2025 15:01 πŸ‘ 13 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

FBI has issued an alert about Russian hackers exploiting a vulnerability in Cisco networking devices to target critical infrastructure orgs & do recon on industrial control systems: www.ic3.gov/PSA/2025/PSA...

Cisco also published research on the group: blog.talosintelligence.com/static-tundra/

20.08.2025 17:00 πŸ‘ 8 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - edoardottt/cariddi: Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more - edoardottt/cariddi

Cariddi is a CLI tool for IT pros, developers & infosec pros that scans websites to find hidden endpoints, exposed secrets like API keys and credentials, and sensitive files. It's an ideal tool for bug pentester, providing customizable scans with options for custom endpoint lists, regex patterns etc

19.08.2025 19:03 πŸ‘ 33 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0

It’s wild that the same day the president did a weird roof dance for no apparent reason, the state dept implements huge visa fees and the head of the HHS cancels vaccine research. This is just one day! And not even all the terrible things that happened! I feel insane!

06.08.2025 03:02 πŸ‘ 56 πŸ” 7 πŸ’¬ 3 πŸ“Œ 1
Post image

Scoop: CISA's contract with ICF has expired, reducing the JCDC's contractor workforce from 100+ to just 10. CISA can use emergency money & 2-week extensions to keep those 10 around, but only through Sept. Other contracts also caught up in huge backlog. www.cybersecuritydive.com/news/cisa-jo...

30.07.2025 14:53 πŸ‘ 19 πŸ” 13 πŸ’¬ 2 πŸ“Œ 1
How to disable handsfree mode for bluetooth headphones on windows 11

Bose + Windows 11 + Updates rechecking 'handsfree telophony' has one of the deepest rabbit holes through the Windows 11 settings menu. If your audio sucks, check this out.
www.reddit.com/r/Windows11/...

25.07.2025 15:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
YouTube’s July 15th Update: Is Your AI Channel About to Get Demonetized? For the past few weeks, there’s been a lot of nervous chatter in the YouTube community, especially among creators who use Artificial…

YouTube's changes for payout of AI generated content is promising. There's so much AI garage that pushes genuine and creative content down.

www.merca20.com/goodbye-yout...

09.07.2025 13:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image
20.06.2025 10:47 πŸ‘ 105 πŸ” 33 πŸ’¬ 3 πŸ“Œ 2
Preview
I Tried Pre-Ordering the Trump Phone. The Page Failed and It Charged My Credit Card the Wrong Amount I got a confirmation email saying I'll get another confirmation when it's shipped. But I haven't provided a shipping address.

I Tried Pre-Ordering the Trump Phone. The Page Failed and It Charged My Credit Card the Wrong Amount

πŸ”—

17.06.2025 16:00 πŸ‘ 142 πŸ” 26 πŸ’¬ 14 πŸ“Œ 13
Post image Post image

This is a big deal. Predatory Sparrow’s past cyber attacks on Iranian steel plants and gas stations have demonstrated tangible effects in Iran. Disrupting the availability of this bank’s funds, or triggering a broader collapse of trust in Iranian banks, could have major impacts there.

17.06.2025 12:07 πŸ‘ 6 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

CVE-2025-33053 is really interesting. Setting a working directory to a remote WebDAV location and it works. Even worse than hash coercion since you can run something.

12.06.2025 13:29 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Abuse will continue until we fix the legal system to the point they are afraid to do this on camera.

That's the bare minimum. They must be afraid to be recorded in their misdeeds. If we can't hit that VERY LOW bar, abuse will continue unchecked. That was so obviously assault.

10.06.2025 10:30 πŸ‘ 26 πŸ” 6 πŸ’¬ 2 πŸ“Œ 0
Video thumbnail

πŸŽ™οΈ New Podcast Episode Dropping Soon!

We dive into our latest public report with Randy Pargman, Jake Ouellette, Kostas T., and Mangatas Tondang.

Stay tuned for deep insights, behind-the-scenes analysis, and expert commentary from the front lines of DFIR. πŸ”

10.06.2025 12:06 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
New Windows Server 2025 Attack Compromises Any Active Directory User Windows Server 2025 is vulnerable to a newly discovered, and trivial to implement, attack that enables a hacker to compromise any user in Active Directory.

By me @forbes.com: Ooh, this one could be nasty. #kudos Akamai for the exquisite research.

#infosec

www.forbes.com/sites/daveyw...

21.05.2025 14:03 πŸ‘ 5 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
From the ExperiencedDevs community on Reddit: My new hobby: watching AI slowly drive Microsoft employees insane Explore this post and more from the ExperiencedDevs community

Humorous thread on watching Microsoft employees wrangle AI to fix bugs in code.

I don't think developers are going anywhere soon
www.reddit.com/r/Experience...

21.05.2025 14:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duping Cloud Functions: An emerging serverless attack vector Cisco Talos built on Tenable’s discovery of a Google Cloud Platform vulnerability to uncover how attackers could exploit similar techniques across AWS and Azure.

Another prime example of 'it's in the cloud, its secure'. It's super important to understand attack vectors in the cloud. Serverless is extremely powerful and popular solution, but not immune to attack or misconfigurations.

blog.talosintelligence.com/duping-cloud...

20.05.2025 13:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0