Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Joshua Small

@jsmall@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
191 Followers
98 Following
23 Posts
Joined November 06, 2022
Website:
https://lolware.net/
Github:
https://github.com/technion/
Age Key:
https://lolware.net/age.txt
Open post
Joshua Small @jsmall@infosec.exchange
· 1w ago
Replying to
@alda@topspicy.social The user management was always interesting to me. That woocommerce users who made an account to buy something get "a wordpress account" on the same table with the same apparent config as a Wordpress Admin with just an ACL preventing them editing the site always rubbed me the wrong way. (information is old and I'm open to be updated)
1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 1w ago
I've published some tools relevant to the recent Netscaler vulnerability. https://github.com/technion/netscaler_scanner/
GitHub

GitHub - technion/netscaler_scanner: Tooling related to CVE-2026-88771 and CVE-2026-88772

Tooling related to CVE-2026-88771 and CVE-2026-88772 - technion/netscaler_scanner

1
0
1
0
Open post
Joshua Small @jsmall@infosec.exchange
· 1w ago
Replying to
@wdormann@infosec.exchange I'm staring at a Citrix console after patching and that entire IOC Scanner section doesn't exist on my install.
1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 1mo ago
Replying to
Like seriously I will connect to any public network you want and open Outlook right now and challenge you to start reading my passwords the way you pretend is easy.
3
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 3mo ago
The update to Microsoft's certification credentials is basically just a big removal of everything not AI related. For example, they've replaced "Microsoft Certified: Azure Security Engineer Associate" with "Microsoft Certified: Cloud and AI Security Engineer Associate (Exam SC-500)" and "Microsoft 365 Certified: Administrator Expert" with "Microsoft 365 Certified: AI Services Administrator Associate (Exam AB-650)". There's a whole bunch of stuff they couldn't yet shoehorn AI into, so they just EOL'd the certification branch wholesale. I'm not anti AI, in fact I'm using it extensively, but declaring Microsoft certs have to be about AI surely makes them less valuable and I'd urge people putting these down as job requirements consider this. https://techcommunity.microsoft.com/blog/skills-hub-blog/microsoft-credentials-roundup-june-2026/4528350
techcommunity.microsoft.com
7
3
9
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange Yeah I've responded to three Clickfix incidents from hacked Wordpress sites just yesterday (for scale, my usual number is one a month) and somehow people are convinced this is a non event. I don't even know what's going on any more when the major intelligence agencies put out major alerts about "router hygiene" a few days ago are completely silent on this.
2
1
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Synergy Wholesale's SSL purchase form sure is something else.
1
1
1
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
One of the ways the security landscape has changed - which I haven't seen discussed - is that URL blocklists seem a lot easier for attackers to evade. I had a Clickfix incident three days ago. I used a https://app.any.run/ sandbox to replicate that loading the site, which was full of hidden online casino SEO spam, delivered a password stealer. Reported to Google Safebrowse, Fortigate, Palo Alto, Microsoft. Today the URL has absolutely 0 flags on Virustotal.
Interactive Online Malware Analysis Sandbox - ANY.RUN
app.any.run

Interactive Online Malware Analysis Sandbox - ANY.RUN

Cloud-based malware analysis service. Take your information security to the next level. Analyze suspicious and malicious activities using our innovative tools.

1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
What in hell is this Microsoft will the pilot group be included or exlcuded?
1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 11mo ago
Replying to
@Tarah@infosec.exchange somewhere, I have a security advisor not getting the joke, prepared to come in Monday and tell me thats an example of a good move.
1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 11mo ago
Replying to
@mubix@infosec.exchange had to double take after reading that as "900 lb hackers"
1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 14mo ago
Replying to on abyssdomain.expert
@filippo@abyssdomain.expert We've seen this for a while with Powershell scripts but I'm amazed someone wrote a bash version.
1
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Telstra Custdata logon (business DNS management) calling themselves "Multifactor" on an email magic link logon.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Are there any Ruby people with views on [CVE-2026-66066] ? The official release uses wording like "In a default configuration" but as far as I can see the exploit is down to using a specific method storing and user uploaded images and then doing something specific with them? Image manipulation has always been a huge attack surface, it's the sort of thing I always would have put in its own backend or container.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Microsoft's latest advisory has a bunch of slop related typos. Really the part that worries me is the take away from these sort of write ups is "Buy Nord VPN" or some stupid shit when Device Code phishing and Clickfix 100% do not care.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 1w ago
Time for a hill to die on: it makes no logical sense to say "two unknown cves in citrix". The whole definition of a cve is as a constant public identifier of a specific vulnerability. If you cannot give me a cve number there is no new cve - just an exploit with no published information. Its like saying there are two new words in the official English dictionary, but no dictionary is allowed to document them.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social All I see is an very typical phishing email and someone will say "good English, so must have had AI assistance writing" and suddenly it's an AI attack.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 5mo ago
Replying to
@rmondello@hachyderm.io while I agree, in the microsoft world entra wont let you setup a passkey unless you have either Ms authenticator push or totp setup first. I have no idea why.
0
1
1
0
Open post
Joshua Small @jsmall@infosec.exchange
· 10mo ago
Replying to
@briankrebs@infosec.exchange Huge round of applause for this response.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Replying to
@merill@infosec.exchange The custom CSS was valuable for logon canaries, and I've seen them detect phishing pages in the wild before. It's a loss to see them go.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Replying to
@offseq@infosec.exchange How broken are these AI summaries that people are getting these "CRITICAL" alerts to "Patch ASAP" for Exchange Online, a SaaS you cannot patch yourself.
0
0
0
0
Open post
Joshua Small @jsmall@infosec.exchange
· 2mo ago
Replying to
@alda@topspicy.social To an Australian the silent t in Costco is new to me and totally weird.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:02:04 UTC