Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

alesandroortiz@infosec.exchangeA

alesandroortiz@infosec.exchange

@alesandroortiz@infosec.exchange
About
Posts
25
Topics
1
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @zkat Apparently. I didn't even know the slang meaning until people started pointing it out to me recently. πŸ˜… I have yet to find a good explanation for the name.

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    Still waiting on promised postmortem. Latest update from Saturday:
    "A security researcher privately disclosed a vulnerability that allowed access to production credentials. We've fixed the underlying issue and are actively working on additional hardening.

    As a precaution, we immediately rotated our most sensitive production credentials."

    Link Preview Image
    PostHog Status

    Current status of PostHog services

    favicon

    (www.posthogstatus.com)

    Uncategorized

  • oh god I just accidentally copied a python virtualenv onto a MS-DOS 6.22 machine
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @foone Expect a vortex shortly due to the rip in the space-time continuum you've created.

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @olearysec Yeah, I posted about it here: https://infosec.exchange/@AlesandroOrtiz/116661218239511606

    Was still really hoping you were right.

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    Kudos to PostHog for the real-time disclosure at least. They could have disclosed this in a quiet blog post a week from now. Only customers subscribed to app status page incidents would be notified via email, so also need to see how they notify customers directly who aren't subscribed to status page.

    Also #hugops since security incidents are never fun.

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @olearysec Update: It's a security incident of sorts.

    Link Preview Image
    Alesandro Ortiz πŸ‡΅πŸ‡·πŸ³οΈβ€πŸŒˆ (@AlesandroOrtiz@infosec.exchange)

    Attached: 1 image Sounds like an external security researcher was able to access one of PostHog's AWS environments. Also note the quiet update of the existing status (same timestamp as earlier update; no email sent out to incident subscribers). "We are rotating keys after a security research team was able to confirm an exploit in one of our AWS environments. We're working with the security research team on the issue. No keys were publicly available, and no data has been compromised. You may see impacts on exports, reverse proxies, and other services. We'll have more updates as we continue to work on this incident." https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1

    favicon

    Infosec Exchange (infosec.exchange)

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    Sounds like an external security researcher was able to access one of PostHog's AWS environments.

    Also note the quiet update of the existing status (same timestamp as earlier update; no email sent out to incident subscribers).

    "We are rotating keys after a security research team was able to confirm an exploit in one of our AWS environments. We're working with the security research team on the issue. No keys were publicly available, and no data has been compromised. You may see impacts on exports, reverse proxies, and other services. We'll have more updates as we continue to work on this incident."

    Link Preview Image
    PostHog Status

    Current status of PostHog services

    favicon

    (www.posthogstatus.com)

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @olearysec AFAIK this is the first time they've done any planned maintenance that impacted web app availability, going back several years.

    There's been many unplanned issues that impacted web app availability, but none cited anything similar to this (like key rotation or security exercise).

    I hope you're right and they forgot to announce it, but also seems unusual given they haven't done this before in a way that impacted web app availability, either as planned maintenance or unplanned maintenance. All the unplanned maintenance affecting web app uptime I've seen has never cited security exercise or key rotation.

    Uncategorized

  • I have a few questions...
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    I have a few questions... "Security exercise" sounds planned but this is "Unplanned maintenance" on a Friday night.

    Is PostHog rotating keys due to a security incident?

    Link Preview Image
    PostHog Status

    Current status of PostHog services

    favicon

    (www.posthogstatus.com)

    Uncategorized

  • Holy crap he got it
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @SwiftOnSecurity πŸŽ‰ I was just telling my Dad over the phone to install Paint.net but NOT to go to Paint.net, and to not Google "paint.net" because they might click on a malicious ads.

    Uncategorized

  • reluctant to say a single good thing about Twitter for every obvious reason.
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @retrohistories I agree. Honestly surprised it has remained untouched through the current era. I thought it would be one of the first things to go given the blatant disregard of facts by top accounts and the audience they want to keep.

    Uncategorized

  • Discovering that Formula Two teams move their stuff from the pitlane back to the support paddock with these ludicrous golf cart trains has been a highlight
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @mjg59 Took me a minute to figure out what was hooked up to the front. Thought it was for golf cart aerodynamics for a moment. πŸ˜‚

    Those back carts can carry a lot too, especially with the people.

    Uncategorized

  • pronouncing TOCTOU like "hawk tuah" to drive people insane
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @gsuberland Can't unhear.

    Uncategorized

  • I have procrastinated on an important thing for multiple days.
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @freddy Obligatory ADHDinos comic: https://www.reddit.com/r/ADHDinos/comments/1shui3s/self_improvement/

    Link Preview Image
    Uncategorized

  • back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @rebane2001 Nice find! I should have woken up earlier to see the details. πŸ˜…

    Uncategorized

  • New: NYC Health and Hospitals says a data breach earlier this year affects 1.8 million people.
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @zackwhittaker Is your article about the March 24 notification on their website?

    https://www.nychealthandhospitals.org/pressrelease/notice-of-data-breach/

    No one in my family has received paper or email notices about this. I learned about it now through your article.

    I've been personally affected by lots of data breaches but this one is particularly bad. πŸ˜•

    Uncategorized

  • This post did not contain any content.
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @SwiftOnSecurity Thought this was one of @gsuberland's Unsafe Warnings stickers. πŸ˜„

    Uncategorized

  • There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter?
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @SecureOwl Followed by:
    - Malicious ad fingerprints your browser and runs a zero day exploit.
    - Your AWS, GitHub, and npm credentials are exfiltrated within seconds.
    - Within 5 hours you are triaging a widespread supply chain attack that started with you typing in a domain name and pressing enter.

    Uncategorized

  • So I’ve just had a quick play with this and yes, it works.
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @GossiTheDog Do you think U.S. authorities could be investigating NightmareEclipse due to their disclosures?

    I imagine Microsoft is investigating internally to determine if it's someone with previous/current access to internal info that is still legally protected (by contract or law).

    Based on their posts, MS might already know their identity if they have interacted with this person via MSRC and have their payment info for the bug bounty programs.

    Uncategorized

  • Cracking open a new tube of toothpaste and uh, they shurnkflated the toothpaste 😒
    alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

    @benjojo Unrelated: TIL about eu.com, a US company pitching itself as a workaround to .eu TLD restrictions.

    It's hilarious it's found a market despite easy alternatives like "companyname-eu[.]com".

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups