Tod Beardsley's Avatar

Tod Beardsley

@todb2.hugesuccess.org

Shmethical #Hacker. #Research mucky-muck at @runzero. #Election worker. #CVE bagman. #Metasploit collaborator. Briefly a fed. Anti-Fascist. #FriendofDeSoto. #Podcaster […] πŸŒ‰ bridged from ⁂ https://infosec.exchange/@todb, follow @ap.brid.gy to interact

58
Followers
3
Following
111
Posts
21.01.2025
Joined
Posts Following

Latest posts by Tod Beardsley @todb2.hugesuccess.org

[TXPol]

Update: They both won.

\o/

#Texas #Congress #Democrats

04.03.2026 15:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

[TXPol]

You in #Texas? North Austin out to Odessa and Temple?

Then you can help put Texas and the US back on track by voting for Claire Reynolds or Justin Early for #Congress. They’re both #Democrats and both ready to take back Congress’s Constitutional […]

[Original post on infosec.exchange]

03.03.2026 12:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

And there was no widespread fraud in the 2020 election. For the love of god. He is a liar and a fraud.

28.02.2026 12:02 πŸ‘ 108 πŸ” 13 πŸ’¬ 4 πŸ“Œ 1
Post image

The decor at the hotel I’m staying at is reminding me strongly of #OxygenNotIncluded. Am I in danger?

27.02.2026 13:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

@hdm ay caramba.

26.02.2026 18:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises: https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/

AirSnitch resets WiFi security back to the bad-old-days of ARP spoofing and trivial MITM.

26.02.2026 17:27 πŸ‘ 0 πŸ” 12 πŸ’¬ 1 πŸ“Œ 0

@missingthept.bsky.social @da_667 goddammit i am a sucker for almost any It’s A Wonderful Life joke

21.02.2026 16:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
It’s a Wonderful Life bank run scene.

It’s a Wonderful Life bank run scene.

β€œYou're thinking of the $175 billion in tariff money all wrong. As if I had the money back in a safe. The money's not here. Your money's in the White House ballroom, the renaming of the Department of Defense, the $10 billion transfer to the Board of Peace, and a hundred other unauthorized actions.”

20.02.2026 22:20 πŸ‘ 4984 πŸ” 1582 πŸ’¬ 96 πŸ“Œ 56

Breaking news: Max Headroom, one of the greatest TV shows ever made, is free on Tubi.

I find the terrible Tubi ads really enhance the dystopia.

21.02.2026 02:41 πŸ‘ 1 πŸ” 13 πŸ’¬ 3 πŸ“Œ 0

@whitequark IΓ€! IΓ€! IRC fhtagn!

18.02.2026 04:23 πŸ‘ 0 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

@mauvehed @zate @zate75 Yep. Everything your team fails at is your fault, everything your team succeeds at is their win.

19.02.2026 17:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Original post on defcon.social

I'll never forget the first time I threw a direct report under the bus. I was in a sort of "manager-limbo" where I was leading a team but wasn't fully an administrative manager in the HR system. It was all very awkward.

Very shortly into this time period, my boss asked me a direct question […]

19.02.2026 16:11 πŸ‘ 2 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Original post on infosec.exchange

[Suicide, USPOL]

Today is my oldest kid's, Molly's, birthday, and she would have been 30 today if she wasn't dead from a gunshot, bringing to a close a rocky few years dealing with opioid addiction.

Miss you, kiddo.

Anyway, just typing it out loud. And also, let me share a link to one of the […]

18.02.2026 22:24 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Original post on infosec.exchange

RE: https://mstdn.social/@locuta/116069618872093099

SUPER

Just so you (and my employer and family) know, I have written down "Cancelling free and fair elections" as my Rubicon, which means I'll be rioting in the streets until elections are restored.

https://www.youtube.com/watch?v=0YFdwfNh5vs […]

18.02.2026 17:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
John Henry (folklore) - Wikipedia

Seriously, why aren't there way more John Henry allegories involving LLMs?

https://en.wikipedia.org/wiki/John_Henry_(folklore)

18.02.2026 14:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
runZero Hour – Subscribe to the series Deep dive web series into all things exposure, from new threats and risky devices to vulnerabilities hiding in IT, OT, IoT, remote, cloud, and mobile…

There’s still plenty of time to get in on the chat action for today’s runZero Hour, wherein we talk all about the KEV.

Sign up below.

https://www.runzero.com/research/runzero-hour/

18.02.2026 14:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

On behalf of witch-haunted #Arkham, @hotdogitsclaire gets the @podsothoth #vote in the #Congress race in #Texas’ 11th district.

https://claire11.org

17.02.2026 23:47 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Oh, joke's on me.

This training is, indeed, chronical.

17.02.2026 17:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Chronicals WHAT of Narnia

Chronicals WHAT of Narnia

Strapping in for this security training that doesn't know how to spell "chronicles"

Good job ESET

17.02.2026 17:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

Hello Austin Go hackers! Tonight (2026-02-11) is our next ATX Golang meetup, located in Station Austin (aka Capital Factory ). We will have pizza, drinks, and various short talks and discussions related to the Go ecosystem. If you're looking for a Go job […]

[Original post on infosec.exchange]

11.02.2026 18:37 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

@hrbrmstr @vulncheck this effect is especially apparent in CVEs published in January, btw.

10.02.2026 16:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

@hrbrmstr @vulncheck This is a great object lesson in "don't date your CVEs based on the label." Go with the publish date, instead. The label year is more loosey-goosey than many expect.

10.02.2026 16:36 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Original post on infosec.exchange

@hrbrmstr Ah ha. It's a @vulncheck bug. They do have a tendency to do some bug archeology. Looks like the original report is from 2015.

From the CVE Rules:

4.2.21 CNAs SHOULD assign the year part of a CVE ID based on the calendar year in which the vulnerability was first Publicly Disclosed […]

10.02.2026 16:33 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

@hrbrmstr well that's weird. Not every day you get a 2015-labelled CVE minted in 2026.

This kind of behavior is discouraged, but legal, in CVE-land. Let's see what's up here. Give me two shakes!

10.02.2026 16:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Unforgivable vulnerabilities

A vulnerability that should not exist in software as the difficulty of implementing mitigations is deemed negligible. This could be because:

the mitigation is fully documented
it is cheap to implement
the technical implementation of the mitigation does not rely on too many (or too complex) prerequisites 
Note: There may be multiple causes of a single vulnerability, with each cause having a different mitigation.

Unforgivable vulnerabilities A vulnerability that should not exist in software as the difficulty of implementing mitigations is deemed negligible. This could be because: the mitigation is fully documented it is cheap to implement the technical implementation of the mitigation does not rely on too many (or too complex) prerequisites Note: There may be multiple causes of a single vulnerability, with each cause having a different mitigation.

NCSC published a method for classifying vulnerabilities as "forgivable" or "unforgivable" based on how easy the mitigations are to implement.

The main gist is that if the fix is cheap, well-documented, and has no complex prerequisites, there's no excuse for […]

[Original post on mastodon.social]

09.02.2026 11:43 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Original post on fediscience.org

"Federal Data Is Disappearing."
https://www.notus.org/trump-white-house/federal-data-is-disappearing

"Since retaking office, the Trump administration has transformed how the government collects data, cut access to previously-public data and stopped collecting some data altogether. This overhaul […]

06.02.2026 14:25 πŸ‘ 0 πŸ” 11 πŸ’¬ 1 πŸ“Œ 1

Got some Dark Reading coverage on my #CISA kEV musings. Check it.

https://www.darkreading.com/threat-intelligence/data-tool-triage-exploited-vulnerabilities-make-kev-catalog-more-useful

06.02.2026 15:00 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

RE: https://infosec.exchange/@runZeroInc/116018384585774852

dang i like working at @runZeroInc

like, like-like like it.

05.02.2026 14:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

@hrbrmstr bookmarking. you're saying i can be a font snob in a consistent way across my apple-flavored things? Neat. @MonaApp

05.02.2026 13:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
The apparent window size for my browser, at full screen, on my little MacBook Air. I tile my tabs on the left size which takes a little bit extra horizontal space away from the viewable browser screen. Just so happens to be 1337px across.

This is a funny number.

Screenshot from https://howbigismybrowser.com

The apparent window size for my browser, at full screen, on my little MacBook Air. I tile my tabs on the left size which takes a little bit extra horizontal space away from the viewable browser screen. Just so happens to be 1337px across. This is a funny number. Screenshot from https://howbigismybrowser.com

well of course it is

05.02.2026 13:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0