/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Dave Kennedy

@hackingdave
40 posts
2025-01-13
I completely ditched Sonos in my house and moved to Bluesound. Aside from the app being horrendous in Sonos.. SonosNet is devastating to any smart network creating network loops and broadcast storms. Fought it with STP for 8 years and decided move on.
2025-01-13 View on X
Bloomberg

Sonos CEO Patrick Spence is leaving following a botched app revamp that upset customers and stymied growth; Sonos names board member Tom Conrad as interim CEO

- 'We've let far too many‬‭ people down,' company tells staffers  — Former Snap and Pandora executive Tom Conrad named interim CEO

2024-08-31
I hope this decision gets reversed and soon. For @MayorGinther - the targeting of @cgoodwolf is not a good look. The data was/is already public and accessible to anyone that has a TOR browser. The data is already exposed and gone. Targeting security researchers for
2024-08-31 View on X
BleepingComputer

The City of Columbus, OH, sues security researcher David Leroy Ross, aka Connor Goodwolf, accusing him of sharing data stolen by a ransomware gang with media

The City of Columbus, Ohio, has filed a lawsuit against security researcher David Leroy Ross, aka Connor Goodwolf …

2024-04-12
Massive data breach at SiSense - a business intelligence platform. Actors allegedly compromised network, exfiltrated data and could potentially contain customer data. Highly recommend if using SiSense, to look at the following: * Change passwords of any SiSense accounts...
2024-04-12 View on X
Krebs on Security

CISA is investigating a breach at business intelligence company Sisense; sources: the attackers copied several terabytes of customer data, including credentials

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said today it is investigating a breach at business intelligence …

2024-02-23
👀👀👀👀 This could be pretty big if true - looks to be.
2024-02-23 View on X
TechCrunch

Researchers warn that hackers are exploiting ConnectWise's remote access tool via a flaw “embarrassingly easy” to exploit; ConnectWise has confirmed the attacks

2024-02-22
👀👀👀👀 This could be pretty big if true - looks to be.
2024-02-22 View on X
TechCrunch

Researchers warn that hackers are exploiting ConnectWise's remote access tool via a flaw “embarrassingly easy” to exploit; ConnectWise has confirmed the attacks

“I can't sugarcoat it — this shit is bad," said Huntress' CEO  —  Security experts are warning that a high-risk vulnerability …

2024-02-04
The AnyDesk situation is something to pay close attention to.
2024-02-04 View on X
BleepingComputer

Remote desktop software maker AnyDesk says it has suffered a cyberattack recently; source: hackers stole source code and private code signing keys

AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems.

2023-12-20
Big one, and many more coming that are discovering the Citrix bleed vuln used in their environment
2023-12-20 View on X
BleepingComputer

Comcast's Xfinity says hackers breached one of its Citrix servers in October 2023, two weeks after Citrix issued a patch, and stole data on 35,879,455 people

what we know Laura French / SC Media : 35 million Xfinity customers have data leaked in breach tied to Citrix Bleed bug Helga Labus / Help Net Security : Citrix Bleed leveraged to ...

2023-09-22
Not surprised on this one - curious to see if Cisco will take take more aggressive pricing model for all especially on storage. It's a great product and super powerful - but most can't afford it. If they make it more affordable - could put them ahead. https://www.splunk.com/...
2023-09-22 View on X
Bloomberg

Cisco plans to acquire cybersecurity company Splunk in cash for $157 per share, a 31% premium on Splunk's September 20 closing price, in a deal valued at ~$28B

https://www.reuters.com/... Chris Merkel / @chrismerkel@infosec.exchange : Scoop: Anonymous has hacked the neuralinks of the leadership teams at Splunk and Cisco.  While I can't id...

2022-12-01
Data breach in third party cloud storage service used by LastPass. Passwords not impacted however customer information obtained. https://blog.lastpass.com/...
2022-12-01 View on X
BleepingComputer

LastPass says customer data was accessed after hackers breached its third-party cloud storage, shared with parent GoTo, using info stolen in an August 2022 hack

LastPass says unknown attackers breached its cloud storage using information stolen during a previous security incident from August 2022.

2022-10-13
Really bad call here imo. Making it your normal text solution was the main thing keeping Signal alive with most folks. I have to imagine signal adoption drops significantly with this stance. https://twitter.com/...
2022-10-13 View on X
BleepingComputer

Signal plans to phase out SMS and MMS support from its Android app; users have “several months to transition away from SMS” and export messages to another app

Signal says it will start to phase out SMS and MMS message support from its Android app to streamline the user experience and prioritize security and privacy.

2022-08-24
I've followed @dotMudge and have known him for years. He's in my top 5 people that I look up to in this industry and one of the folks who energized me to be where I am today in my career. His credentials/career are second to none. This is concerning if he is raising this.
2022-08-24 View on X
Washington Post

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

“Mr. Zatko was fired from his senior executive role at Twitter for poor performance and ineffective leadership over six months ago,” the Twitter spokesperson said. ^ total bullshit
2022-08-24 View on X
Washington Post

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

I've followed @dotMudge and have known him for years. He's in my top 5 people that I look up to in this industry and one of the folks who energized me to be where I am today in my career. His credentials/career are second to none. This is concerning if he is raising this.
2022-08-24 View on X
Washington Post

A profile of Peiter Zatko, aka Mudge, who worked at DARPA, Google, and Stripe before Twitter, and was a member of hacker groups L0pht and Cult of the Dead Cow

From the L0pht and Cult of the Dead Cow to DARPA and Google, Peiter ‘Mudge’ Zatko took unorthodox approaches to ‘make a dent in the universe’

“Mr. Zatko was fired from his senior executive role at Twitter for poor performance and ineffective leadership over six months ago,” the Twitter spokesperson said. ^ total bullshit
2022-08-24 View on X
Washington Post

A profile of Peiter Zatko, aka Mudge, who worked at DARPA, Google, and Stripe before Twitter, and was a member of hacker groups L0pht and Cult of the Dead Cow

From the L0pht and Cult of the Dead Cow to DARPA and Google, Peiter ‘Mudge’ Zatko took unorthodox approaches to ‘make a dent in the universe’

2022-08-23
I've followed @dotMudge and have known him for years. He's in my top 5 people that I look up to in this industry and one of the folks who energized me to be where I am today in my career. His credentials/career are second to none. This is concerning if he is raising this.
2022-08-23 View on X
Washington Post

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

In an explosive whistleblower complaint obtained by The Washington Post, former Twitter security chief Peiter ‘Mudge’ Zatko alleges …

“Mr. Zatko was fired from his senior executive role at Twitter for poor performance and ineffective leadership over six months ago,” the Twitter spokesperson said. ^ total bullshit
2022-08-23 View on X
Washington Post

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

In an explosive whistleblower complaint obtained by The Washington Post, former Twitter security chief Peiter ‘Mudge’ Zatko alleges …

2022-08-09
Twilio data breach has a good amount of detail on how the phishing campaign was successful. Tactics are consistent with what we are seeing with adversaries using SMS/texts in pretexts more and more. Phish domains were specific to Twilio and Okta. https://www.twilio.com/...
2022-08-09 View on X
TechCrunch

Twilio discloses “unauthorized access” on August 4 by a “sophisticated” unknown actor using an SMS-based phishing attack on staff to gain info on some accounts

Leaks Private Data via Phishing Jose Montes de Oca / Newslit Daily : 🗞 Axios to Sell to Cox Enterprises for $525MM Pierluigi Paganini / Security Affairs : Twilio discloses data bre...

2022-05-20
This is pretty huge. The CFAA still needs a complete overhaul / rewrite / tear down but recognizing good faith as an exception for criminal charges in cyber is a big step. https://twitter.com/...
2022-05-20 View on X
VICE

In a policy shift, the US Department of Justice plans to stop prosecuting good-faith security research that would have violated the Computer Fraud and Abuse Act

to choose not to prosecute security research as a violation of the Computer Fraud and Abuse Act. “The policy for the first time directs that good-faith security research should not...

2022-02-26
Looks like major attack underway at NVIDIA with “multiple compromised business units” and “email systems offline”. https://twitter.com/...
2022-02-26 View on X
Bloomberg

Nvidia confirms an “incident” caused internal outages; source: the event appears to be a minor ransomware attack unrelated to Russia's invasion of Ukraine

A cyber breach suffered by Nvidia Corp. in recent days appears to have been a ransomware attack that's not connected …

2021-06-28
Yikes. Fascinating read with hopefully more details coming out soon: “Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.” https://twitter.com/...
2021-06-28 View on X
Reuters

Microsoft, following a probe of SolarWinds hack, says an attacker compromised one of the company's support agents to launch attacks against customers