Fran Donoso
francisck.com
Fran Donoso
@francisck.com
I'm an infosec person who currently works as the CTO of a security services firm. Have done DevSecOps, Red Teaming, and reverse engineering. I reversed some of the tooling leaked by the Shadow Brokers and spoke about it publicly
Pinned
Hey new folks, welcome to BlueSky! My name is Fran and I run the following #cybersecurity feed:

bsky.app/profile/did:...

I'll be working keep it spam free & good.

If you're curious here are the keywords I'm looking for:

gist.github.com/francisck/d8...

Please provide feedback if you have any.
Reposted by Fran Donoso
🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow them, and 2FA-bypass tokens are starting to be phased out.

Details → socket.dev/blog/npm-12 #nodejs
npm v12 Ships With Install Scripts Off by Default, Begins De...
npm v12 is generally available, turning install scripts off by default and beginning the deprecation of 2FA-bypass publishing tokens.
socket.dev
July 8, 2026 at 9:51 PM
Reposted by Fran Donoso
I'm reading a bunch of Coruna reports after dinner because I am a cool person who knows how to party. Of particular interest: not only does Coruna not work against iOS in lockdown mode, but if it even detects lockdown mode running, it bails. This is why I talk about lockdown mode so damn much.
March 4, 2026 at 5:12 AM
Reposted by Fran Donoso
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
www.washingtonpost.com
February 24, 2026 at 10:23 PM
Reposted by Fran Donoso
OpenAI disrupted new malicious use of ChatGPT... mostly for romance scams and info-ops

openai.com/index/disrup...
Disrupting malicious uses of AI
Our latest threat report examines how malicious actors combine AI models with websites and social platforms—and what it means for detection and defense.
openai.com
February 25, 2026 at 11:07 PM
Reposted by Fran Donoso
Cisco said there are no workarounds for the vulnerability and urged customers to apply available patches immediately. The company also recommended reviewing system logs, validating controller integrity, and implementing additional hardening measures where possible.

www.csoonline.com/article/4137...
Five Eyes issue emergency directive on exploited Cisco SD-WAN zero-day
The Five Eyes cybersecurity agencies warn that a critical Cisco SD-WAN vulnerability is under active exploitation and should be patched immediately.
www.csoonline.com
February 25, 2026 at 11:12 PM
Reposted by Fran Donoso
patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds.

Somebody posted an exploit on Christmas Day, Merry Christmas!

doublepulsar.com/merry-christ...
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
doublepulsar.com
December 26, 2025 at 10:57 PM
Reposted by Fran Donoso
HARDEN YO' N8N - [CVSS 10.0 RCE] Remote Code Execution via Expression Injection m.cje.io/4qhl2JX

cc: @networkchuck @danielmiessler @jhaddix
Remote Code Execution via Expression Injection
### Impact n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users dur...
m.cje.io
December 20, 2025 at 12:36 AM
I may have gone overboard on the Halloween goodies this year

#halloween
November 1, 2025 at 2:34 AM
This report from @interseclab.bsky.social on how a Chinese company is exporting some of the capabilities of "The Great Wall of China" to other autocratic countries is INSANELY INTERESTING:

interseclab.org/wp-content/u...

*EVERY Page is worth reading*

Some interesting tidbits in the thread
interseclab.org
September 14, 2025 at 6:15 PM
Plex was hacked. It included usernames, emails, and hashed passwords.

Change your passwords when you can,
September 8, 2025 at 10:37 PM
Reposted by Fran Donoso
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/7
August 26, 2025 at 3:38 PM
Reposted by Fran Donoso
SentinelOne and Beazley Security have discovered a new Windows infostealer used in the wild named PXA Stealer, most likely the work of a Vietnamese-speaking cybercrime group.

www.sentinelone.com/labs/ghost-i...

labs.beazley.security/articles/gho...
August 5, 2025 at 11:47 AM
I mean I’ve been urging people to toss their sonicwall devices into a shredder for years now 🤷🏻‍♂️
SonicWall is urging customers to take some VPN devices offline after multiple security firms discovered a campaign of ransomware attacks over the last two weeks

SonicWall did not explain if the ransomware gangs are using a zero-day

therecord.media/sonicwall-po...
SonicWall urges customers to take VPN devices offline after ransomware incidents
Multiple cybersecurity incident response firms are warning about the possibility that a zero-day vulnerability in some SonicWall devices is allowing ransomware attacks.
therecord.media
August 4, 2025 at 8:39 PM
Our team collaborated with our friends at @sentinellabs.bsky.social to identify and disrupt a PXA infostealer campaign that has an intricate and complex delivery chain:

labs.beazley.security/articles/gho...

Thanks for the fantastic collab SentinelLabs team!
BSL - Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
labs.beazley.security
August 4, 2025 at 5:58 PM
We’re actively seeing this exploitation as well.

Here is my team’s advisory on this vulnerability:

labs.beazley.security/advisories/B...

Is your have a publicly exposed SharePoint server, its probably already compromised so get ready to do some IR.
July 20, 2025 at 11:38 PM
Reposted by Fran Donoso
🩸& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2
1/2
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
www.greynoise.io
July 16, 2025 at 9:05 PM
Reposted by Fran Donoso
Two high-severity patches are coming to Node.js on Tuesday

nodejs.org/en/blog/vuln...
July 13, 2025 at 7:10 PM
Worth turning on if you have AT&T.

Other carriers (like T-mobile) have similar programs.
July 2, 2025 at 2:24 AM
Reposted by Fran Donoso
Need something positive to do in your life this week?

If you don’t have a library card, go get one. Then learn about all the awesome things your local public library has to offer.
June 26, 2025 at 9:43 PM
This is related to ROP code exec on switch 2
userland ROP on day 1 💪
June 6, 2025 at 12:42 PM
Reposted by Fran Donoso
New, by me: Data broker giant LexisNexis has revealed that its risk solutions unit (think "know your customer," risk assessing, due diligence, and law enforcement assistance) was breached, affecting the personal data and Social Security numbers of at least 364,000 people.
Data broker giant LexisNexis says breach exposed personal information of over 364,000 people | TechCrunch
The data collector said the stolen data includes Social Security numbers.
techcrunch.com
May 28, 2025 at 2:07 PM