Scott Vintinner
@flakshack.bsky.social
83 followers 180 following 220 posts
Your friendly neighborhood Cybersecurity DJ. #netsec #sysadmin #cybersecurity #python #powershell #legal #it #technology #house #dj #f1 Latest DJ Mix (10/12): https://www.youtube.com/watch?v=4xidQ_SLUuQ
Posts Media Videos Starter Packs
Increased scanning of Palo Alto Networks login portals.

GreyNoise noted...that surges in malicious scanning, brute-forcing, or exploit attempts are often followed by the disclosure of a new CVE affecting the same technology within six weeks.
Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day
GreyNoise detects 500% spike in Palo Alto login scans, linking it to recent Cisco ASA exploit trends.
thehackernews.com
Fortra GoAnywhere (secure file transfer system) vulnerability being exploited by Storm-1175.

"While Fortra patched the vulnerability on September 18 without mentioning active exploitation, security researchers at WatchTowr Labs tagged it as exploited... as a zero-day since September 10."
Microsoft: Critical GoAnywhere bug exploited in ransomware attacks
A cybercrime group, tracked as Storm-1175, has been actively exploiting a maximum severity GoAnywhere MFT vulnerability in Medusa ransomware attacks for nearly a month.
www.bleepingcomputer.com
More details emerge about Red Hat data breach from last week.

Attackers compromised a Red Hat Gitlab instance used for consulting engagements (possible customer data) and have set a ransom deadline for 10/10.
Red Hat data breach escalates as ShinyHunters joins extortion
Enterprise software giant Red Hat is now being extorted by the ShinyHunters gang, with samples of stolen customer engagement reports (CERs) leaked on their data leak site.
www.bleepingcomputer.com
Crazy that this shows up on my cybersecurity feed.
Reposted by Scott Vintinner
Store passwords in a password manager that is refrigerated and airtight to keep them fresh until their expiration date.

Follow me for more infosec tips!
Reposted by Scott Vintinner
So this happened:

The ENTIRE Los Angeles Superior Court system - the largest state court system in the nation - is down today due to a ransomware attack, forcing the closure of all 36 courthouses.
If you are in the job market for a cybersecurity or even regular IT job, there's a great post over on /r/cybersecurity to help you tune your resume:
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
www.reddit.com
Pacer court system that handles filings for federal district courts has been hacked. Their systems have long been underfunded. Hopefully this will encourage some change.
Federal court filing system hit in sweeping hack
The identities of confidential court informants are feared compromised in a series of breaches across multiple U.S. states.
www.politico.com
Reposted by Scott Vintinner
Reposted by Scott Vintinner
If you run VMware vSphere/vCenter/ESXi at your company, take some time to read this breakdown of an attack.

Attackers showing a very high level of sophistication and persistence even after discovery. This is the stuff of nightmares.
Fire Ant: Hypervisor-Level Espionage Targeting VMware ESXi & vCenter | Sygnia
Discover Sygnia’s investigation into Fire Ant, an advanced cyber-espionage campaign breaching VMware ESXi, vCenter, and network appliances. Learn how the attackers bypassed traditional defenses with h...
www.sygnia.co