André 3001
andrevdw.bsky.social
André 3001
@andrevdw.bsky.social
Cyber Janitor. Mangler of machines.
Defender of the realm.
Reposted by André 3001
Glad to see the Ombudsman for Children leaving X. The office is on Bluesky - @ocoireland.bsky.social
January 13, 2026 at 10:16 AM
Reposted by André 3001
If you're in the UK and have Facebook, a woman is giving away her late father's PDP-8/L based in Bristol. Schematics included.

www.facebook.com/share/p/1A95...
January 8, 2026 at 10:53 AM
Reposted by André 3001
🥴
January 8, 2026 at 9:02 AM
Reposted by André 3001
Mac users found their Logitech mice stopped working because someone at Logitech forgot to renew an expired app certificate.

*pinches bridge of nose and sighs loudly for the rest of time*
Logitech caused its mice to freak out by not renewing a certificate
That’s one heck of an oversight.
www.theverge.com
January 7, 2026 at 1:44 PM
Reposted by André 3001
Not the "pulling a Rabbit out of a hat" magic trick that most want. This Firefox extension completely changes from a "Simple Label Editor" to a Rabby wallet stealer overnight.
January 5, 2026 at 7:35 PM
Reposted by André 3001
Look at this collapse in StackOverflow post creation! Over 186,000 in April 2022 to just 3800 in December 2025.

data.stackexchange.c...
January 5, 2026 at 4:23 PM
Reposted by André 3001
Emails waiting and ready to circle back now that it's the new year
January 1, 2026 at 2:21 PM
Reposted by André 3001
For social media companies, the fight against tech regulation has nothing to do with free speech but everything to do with continuing to generate profit from the scam industry, which is stealing money from their users, without oversight or accountability.
www.reuters.com/investigatio...
Meta created ‘playbook’ to fend off pressure to crack down on scammers, documents show
As regulators pressure Meta to verify the identity of advertisers on Facebook and Instagram, the social media giant has drafted a “playbook” to stall them. A Reuters investigation examines its tactics...
www.reuters.com
December 31, 2025 at 5:09 PM
Reposted by André 3001
pound for pound this might be the funniest thing ever written
December 31, 2025 at 6:15 PM
Reposted by André 3001
My teammate Asger Deleuran Strunk worked on a case where the TA tried to dump LSASS with procdump on a server, resulting in Defender blocking the attempt:
December 31, 2025 at 8:14 AM
Reposted by André 3001
Sorry my computer’s late. It woke up and the NIST atomic clock was blinking 12:00.
December 21, 2025 at 3:38 AM
Reposted by André 3001
Stealing Microsoft Teams access tokens in 2025 - Randorisec - blog.randorisec.fr/ms-teams-acc...
Stealing Microsoft Teams access tokens in 2025
RandoriSec Offensive Security
blog.randorisec.fr
December 15, 2025 at 4:31 PM
Reposted by André 3001
G DATA's Karsten Hahn documents a few browser hijacking techniques and also suggests a new malware type: unlike a RAT, this malware doesn't control the whole computer, and Karsten coins the term BRAT—a browser remote access tool. www.gdatasoftware.com/blog/2025/11...
December 15, 2025 at 11:20 AM
Reposted by André 3001
We are familiar with eMClient and axios, so let me introduce Trufflehog, the new kid on the block.

Trufflehog made headlines during the recent "Shai-Hulud" campaign, in which threat actors used it to search for passwords and sensitive information. [1] According to the Trufflehog GitHub page:
December 11, 2025 at 6:08 AM
Reposted by André 3001
EMAIL WRAPPED 2025

This year, you received too fucking much email!

Number of emails that found you well: zero

Number of emails that you printed, even though you didn't consider the environment: zero

Number of times an "out of office" autoresponder was immediately followed by the person […]
Original post on discuss.systems
discuss.systems
December 9, 2025 at 2:04 AM
Reposted by André 3001
Whoever designed the FIFA trophy seems to be unclear on the single most basic rule in soccer
in the movies this is the screensaver on the computers at the world’s most evil company
December 5, 2025 at 9:29 PM
Reposted by André 3001
I don't know who needs to hear this, but if you press and hold the space bar on your phone keyboard, sliding your finger will control the position of the cursor when you're editing text
December 4, 2025 at 12:45 PM
Reposted by André 3001
Learned today that around 1990, Mercedes-Benz briefly offered a "mobile office" package for the W126 S-Class that included a fully functioning printer, scanner, and fax machine built into an armrest.
December 3, 2025 at 2:56 AM
Reposted by André 3001
The EU single market’s elephant in the room on.ft.com/4izH73J
The EU single market’s elephant in the room
Small, often invisible barriers to trade affect products from businesses across Europe, including a fluffy Ikea pachyderm
on.ft.com
December 3, 2025 at 5:04 AM
Reposted by André 3001
We’ve published new research from the EU co-funded project NGSOTI: “Learning from large-scale IPv4 blackhole: Behavioral analysis of SNMP traffic”.

Over a 12-month period (Nov 2024–Oct 2025), our network telescope captured ~634 million unsolicited SNMP queries from more than 153,000 unique IPv4 […]
Original post on infosec.exchange
infosec.exchange
November 27, 2025 at 3:10 PM
Reposted by André 3001
There's a prevailing idea in the UK that a customs union with the EU would be a compromise solution if single market membership is not possible, e.g @eddavey.libdems.org.uk and @jonathanfreedland.bsky.social recently. But a customs union is, from a trade policy, a more radical step. (1/N)
November 23, 2025 at 1:25 PM
Reposted by André 3001
The government could, of course, just fix the bizarre (and bad) flaw in the tax system that makes people pay a marginal rate of 62% (or 71% with student loans) at £100k, vs 42% at £99k or £126k – which is why people use salary sacrifice.

They could do this in ways that *raise more revenue*.
FT WEEKEND: Ukraine deal risks loss of dignity or US support, Zelenskyy warns #TomorrowsPapersToday
November 21, 2025 at 10:02 PM
Reposted by André 3001
“Silently patching vulnerabilities is an established bad practice that enables attackers and harms defenders." @catc0n.bsky.social

decipher.sc/2025/11/17/f...
Fortinet CVE-2025-64446 Under Active Attack - Decipher
That vulnerability (CVE-2025-64446) affects several versions of FortiWeb and CISA  has added it to its Known Exploited Vulnerabilities catalog.
decipher.sc
November 17, 2025 at 3:28 PM
Reposted by André 3001
Researchers tried plugging every possible phone number into WhatsApp's web app. They found they could collect 3.5 billion users' phone numbers, plus photos for half and profile text for more than a third, the biggest personal data exposure ever by some measures. www.wired.com/story/a-simp...
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.
www.wired.com
November 18, 2025 at 2:04 PM