hoodie🐴's Avatar

hoodie🐴

@hoodiepony.com

I'm a pony. Sometimes a cyber sherpa, and helping keep myself safe by helping other be cyber safe. Also sometimes breaks stuff and void warranties. πŸ³οΈβ€πŸŒˆ (they/them/it) Also, infosec.exchange/@hoodiepony Other Endpoints @ hello.unicorncyber.space

415
Followers
1,021
Following
210
Posts
07.07.2023
Joined
Posts Following

Latest posts by hoodie🐴 @hoodiepony.com

Preview
Microsoft Authenticator to nuke Entra creds on rooted and jailbroken phones Warning, lockout, then wipe if your device trips detection Microsoft is removing Entra credentials for school and work from jailbroken and rooted devices running iOS and Android.…

ICYMI: Microsoft Authenticator to nuke Entra creds on rooted and jailbroken phones

11.03.2026 13:32 πŸ‘ 2 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
Preview
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack Could steal sensitive personal and financial data After a whopper of a Patch Tuesday last month, with six Microsoft flaws exploited as zero-days, March didn't exactly roar in like a lion. Just two of the 83 Microsoft CVEs released on Tuesday are listed as publicly known, and none is under active exploitation, which we're sure is a welcome change to sysadmins.…

Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack

10.03.2026 20:38 πŸ‘ 17 πŸ” 13 πŸ’¬ 1 πŸ“Œ 2
CVE-2026-3315 - ASSA ABLOY Visionline Windows Unprivileged Execution Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.

CVE-2026-3315 - ASSA ABLOY Visionline Windows Unprivileged Execution
CVE ID : CVE-2026-3315

Published : March 10, 2026, 10:20 a.m. | 2Β hours, 55Β minutes ago

Description : Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assig...

10.03.2026 13:22 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Age verification for R-rated games and websites raises privacy concerns New online safety codes requiring R-rated games and websites to verify their users' ages come into effect, prompting concerns about online privacy.

"Because when we go into a bottle store or buy cigarettes, we flash our ID. The store doesn't photocopy it and keep it forever."

Can the gov guarantee that there is adequate protection from misuse of the IDs collected? Is selling access to it okay? πŸ€”πŸ€”πŸ€”
www.abc.net.au/news/2026-03...

10.03.2026 13:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...

A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password.

Why?
Longer SHA-256 nonce + bcrypt truncation at 72 bytes.

A nice example of why secure systems are about composition, not just stronger primitives.

pentesterlab.com/blog/freshrs...

10.03.2026 08:54 πŸ‘ 10 πŸ” 5 πŸ’¬ 0 πŸ“Œ 1
Preview
Outsourced call centre sweeps Centrelink customer privacy breaches β€˜under the rug’, staff allege Workers accuse government-contracted Telco Services Australia of fabricating performance statistics, denying adequate breaks and penalising staff for taking leave

Outsourced call centre sweeps Centrelink customer privacy breaches β€˜under the rug’, staff allege www.theguardian.com/australia-ne...

10.03.2026 08:56 πŸ‘ 14 πŸ” 7 πŸ’¬ 1 πŸ“Œ 0

Mmm... interesting...
I wonder how that cleared IRAP Protected and above. πŸ€”

10.03.2026 12:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Brit competition cops warn AI agents may not be 'faithful servants' to consumers Autonomous assistants could manipulate choices, push pricier deals, and prioritize their creators Britain's competition watchdog says the next wave of agentic AI assistants could end up nudging people toward worse deals, manipulating choices, or quietly prioritizing the interests of the companies behind them.…

Brit competition cops warn AI agents may not be 'faithful servants' to consumers

10.03.2026 09:32 πŸ‘ 10 πŸ” 7 πŸ’¬ 1 πŸ“Œ 1

Now who's age to enter for the kettle/telco tower/light switch/door bell/etc running Linux? How?

How will anyone be able to comply? So, everyone that creates any software product is now by default a criminal? πŸ€”

Keep this in mind as you write policies, when you're filtering for criminal history. 🫣

08.03.2026 23:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

This is very clearly written. Kudos to Proton.

Pay extra attention to the not subtle reminder you that if you pay anonymously they won’t have any data about your identity!

This is how you walk the line to keep your customers safe while also keeping your employees out of jail.

08.03.2026 19:10 πŸ‘ 18 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0

I'm losing the ability to contrive law school exam hypotheticals that are more absurd than the actual news

07.03.2026 02:09 πŸ‘ 80 πŸ” 16 πŸ’¬ 4 πŸ“Œ 0
Petition e-7195 - Petitions

To my Canadian friends, an acquaintance started a petition to allow US transgender citizens to claim refugee status here.

www.ourcommons.ca/petitions/en...

If you’re Canadian please sign it.
If you’re not, please share ❀️

06.03.2026 17:49 πŸ‘ 895 πŸ” 878 πŸ’¬ 12 πŸ“Œ 26

This feels like impersonation.
Big yikes.

If you still use Grammarly, you might want to check your legal liability for continuing using it for work.

Supply chain risks are really going to get spicy.

06.03.2026 23:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
People Are Calling Meta Ray-Bans "Pervert Glasses" On Bluesky, users quickly embraced the term "pervert glasses" to refer to Meta's Ray Ban smart glasses, following a shocking investigation.

Make it stick.

06.03.2026 18:25 πŸ‘ 10199 πŸ” 2911 πŸ’¬ 176 πŸ“Œ 353
Preview
Declarative configuration is stable! What happened? Key portions of the declarative configuration specification have been marked stable, including The JSON schema for the data model, as defined in opentelemetry-configuration which…

⏳️ Years in the making...

The #OpenTelemetry project is delighted to announce that declarative configuration is stable!

Congratulations to everyone who contributed to this momentous accomplishment!

buff.ly/HhL8swj

05.03.2026 21:16 πŸ‘ 9 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

this is how multiplayer games treat your data while demanding you install kernel level secureboot rootkits to β€˜prevent cheating’ lol

05.03.2026 18:30 πŸ‘ 1519 πŸ” 637 πŸ’¬ 10 πŸ“Œ 3

It's interesting takes in the comments 🫣.

Remember that any company that wants to keep existing, or person that works there not be penalised, will need to comply with their local laws. And all their suppliers will need to comply with their respective local laws too.
Diversify & localise ur supply.

05.03.2026 23:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

New version of OpenRelik (the #DFIR workflow engine) is out. New workflow UI, support for chords (task groups with callback), MCP server and much much more. Give it a try!

Take a look at the new page for workers showcase, both official and community contributed: openrelik.org/workers/

03.03.2026 15:51 πŸ‘ 4 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0
Post image

-Dutch parties want a digital security package for citizens (ad-blocker, VPN, password manager, antivirus)
-France wants 8y in prison for IMSI catcher gang
-Sextortionist pleads guilty
-India arrests 27 fraudsters
-New OAuth redirection abuse
-ClickFix campaign targets crypto investors

04.03.2026 09:53 πŸ‘ 8 πŸ” 4 πŸ’¬ 2 πŸ“Œ 1

How you can tell a rare lunar event is happening in Melbourne...

The cloud coverage is 100%

#LunarEclipse

03.03.2026 09:44 πŸ‘ 43 πŸ” 6 πŸ’¬ 4 πŸ“Œ 0

Melbourne was sadly not much better too for me :(

03.03.2026 13:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
curl security moves again tldr: curl goes back to Hackerone. When we announced the end of the curl bug-bounty at the end of January 2026, we simultaneously moved over and started accepting curl security reports on GitHub inste...

curl left HackerOne after being flooded with AI slop reports

They left for GitHub, but are now returning to HackerOne because it's a better platform to handle reports

daniel.haxx.se/blog/2026/02...

03.03.2026 12:53 πŸ‘ 10 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0

We quietly launched this last week. It's early days and we only have a dozen or so vendors there so far, but the plan is to have pretty decent coverage of the industry after a while

02.03.2026 21:35 πŸ‘ 21 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Preview
Last total lunar eclipse until 2029 is coming tomorrow – don’t miss it

Australia and Aotearoa New Zealand are in a prime position to catch this total eclipse of the Moon; find the timing in our interactive map.

02.03.2026 09:07 πŸ‘ 15 πŸ” 10 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

There’s a total #LunarEclipse coming tomorrow evening and the east coast of Australia, NZ and the Pacific Islands are in a grand position for it!

Looks like we have a bit of cloud in Sydney but it may be patchy.

Best part of the show is between 10-11pm. Max eclipse at 10:33pm.

πŸ“Έ timeanddate

πŸ”­

01.03.2026 20:46 πŸ‘ 47 πŸ” 17 πŸ’¬ 3 πŸ“Œ 0
Preview
Got a Public Amazon Wishlist? Upcoming Change Could Reveal Your Address Effective March 25, you can no longer block third-party sellers from your Amazon Wishlists, which could allow buyers to see your address via delivery updates and tracking information.

Starting March 25, your Amazon wishlist could possibly expose your address due to new Amazon changes

www.pcmag.com/news/got-a-p...

01.03.2026 19:09 πŸ‘ 12 πŸ” 9 πŸ’¬ 0 πŸ“Œ 3
The Internet Was Weeks Away From Disaster and No One Knew
The Internet Was Weeks Away From Disaster and No One Knew YouTube video by Veritasium

Excellent video.
Lots of very critical lessons here.

01.03.2026 07:14 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
New York sues Valve for promoting illegal gambling via game loot boxes New York Attorney General Letitia James sued video game developer and publisher Valve Corporation for using game loot boxes to facilitate illegal gambling activities among children and teenagers.

New York Attorney General Letitia James sued video game developer and publisher Valve Corporation for using game loot boxes to facilitate illegal gambling activities among children and teenagers.

26.02.2026 06:45 πŸ‘ 10 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover A rare joint alert from all five spy agencies means serious business The Five Eyes intelligence alliance is urgently warning defenders to patch two Cisco Catalyst SD-WAN vulnerabilities used in attacks.…

Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover

26.02.2026 11:46 πŸ‘ 3 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0