RSSAmplifier

Blog

DoublePulsar - Medium

Cybersecurity from the trenches, written by Kevin Beaumont. Opinions are of the author alone, not their employer. - Medium

doublepulsar.comRSS feed ↗10 posts

Latest posts

Adform compromised to serve crypto stealer via supply chain attack

Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category. They operate by offering a Javascript embed for websites, via this URL: hxxps://s2.adform.net/banners/scripts/st/trackpoint-async.js This script was compromised to serve a crypto stealer. Adform have been hacked. As far as I can tell Adform haven’t told people. This allows end…

An update on FortiBleed — what’s happening with victim orgs

An update on FortiBleed — what’s happening with victim orgs Two days ago I wrote something about FortiBleed: FortiBleed — 75k Fortinet firewalls have admin passwords cracked Fortinet told media orgs the data was from prior breaches and bruteforcing. That isn’t true — or at least, not the full story. We’ll get into that in this blog. I’ve been working with impacted organisations to help them…

FortiBleed — 75k Fortinet firewalls have admin passwords cracked

FortiBleed — 75k Fortinet firewalls have admin passwords cracked An interesting post popped up on LinkedIn at the weekend from Voldymyr Diachenko saying plain text passwords were found in the wild by Hunt Intelligence Inc for Fortinet firewalls: This is similar to the Belsen Group incident, which I revealed last year: 2022 zero day was used to raid Fortigate firewall configs. Somebody just…

Microsoft’s stance on zero day exploits is a dumpster fire of their own making

Recently, somebody going by the name of Nightmare Eclipse has been having an online beef with Microsoft around security vulnerabilities they claim they had been trying to report. Their posts read like those of a former Microsoft employee. They’ve been dumping proof of concept exploits for said vulnerabilities publicly. As a defender myself, it’s not great — but it is what it is; Microsoft should…

Microsoft Vibing — capturing screenshots and voice samples without governance

Microsoft Vibing — capturing screenshots and voice samples without governance An interesting executable caught my eye on endpoints recently — Vibing.exe It was delivered by Microsoft Store , and claims to be “your interface to the AI-native world”: Published by “Vibing-Team”, the executable flags behaviour for capturing the user’s screen and contents, the clipboard, the user’s microphone, and…

Merry Christmas Day! Have a MongoDB security incident.

Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day. Here’s said exploit: GitHub - joe-desimone/mongobleed The vuln, which dropped just before Christmas, in theory allowed memory read without authentication. Patches are available. It impacts every version of MongoDB going back about a decade. Another vendor decided it would be a great idea to post…

Cybersecurity industry overreacts to React vulnerability, starts panic, burns own house down again

A few days ago, CVE-2025–55182 was revealed alongside an excellent write up: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components The disclosure write up is great — it’s full of facts, and explains when you are and aren’t vulnerable. I don’t think anybody knows how to parse it and people have started taking actions before even knowing what they’re doing. To…

Small numbers of Notepad++ users reporting security woes

Interesting one, has been rumbling for about a week in my circles. I’ve heard from 3 orgs now who’ve had security incidents on boxes with Notepad++ installed, where it appears Notepad++ processes have spawned the initial access. These have resulted in hands on keyboard threat actors. It is unclear exactly what is happening, and this blog is not to blame the (very good) developer of Notepad++. It’s…

What organisations can learn from the record breaking fine over Capita’s ransomware incident

Recently, the ICO fined Capita £14m for their Black Basta ransomware incident — the largest amount ever fined by the Information Commissioners Office. It ruled Capita were “negligent” when it comes to cybersecurity. They also noted that Capita bill themselves as a primary supplier to the UK government, and sell a Managed SOC (Security Operations Center) service — when the SOC was the primary…

CyberSlop — meet the new threat actor, MIT and Safe Security

CyberSlop — meet the new threat actor, MIT and Safe Security Cybersecurity vendors peddling nonsense isn’t new, but lately we have a new dimension — Generative AI. This has allowed vendors — and educators — to peddle cyberslop for profit. coining a new phrase — cyberslop — where trusted institutions use baseless claims about cyber threats from generative AI to profit, abusing their perceived…