Goupil
furaxfox.bsky.social
Goupil
@furaxfox.bsky.social
Parceque !
(mes opinions n'engagent que moi)
Ailleurs en ligne:
http://goupilland.net
http://github.com/FuraxFox/
http://mastodon.acm.org/@FuraxFox
Max is not your friend: a deep look at Russian state approved chat app
arxiv.org/html/2609.11...
Don’t Trust the Super-App: A Case Study of Russia’s Max
arxiv.org
September 18, 2026 at 3:02 PM
Reposted by Goupil
Tankers can get hacked (they're floating cities with complex systems). But I haven't heard of this happening before:

> One of the tankers was *boarded* by a "highly specialized team" of U.S. Coast Guard law enforcement officers, cyber protection members and an FBI cyber team in the Gulf of Mexico.
September 16, 2026 at 11:21 AM
Reposted by Goupil
I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇
www.team-cymru.com/post/ransomw...
Ransomware Incident Response: Infrastructure Analysis
A year of incident response data reveals how Akira, DragonForce & Clop build ransomware infrastructure — and how defenders can hunt it.
www.team-cymru.com
September 15, 2026 at 9:30 PM
Reposted by Goupil
You haven’t seen a ship like this before(!): China’s New Giant Submarine Drone Mothership

www.navalnews.com/naval-news/2...
China's New Giant Submarine Drone Mothership - Naval News
A new vessel spotted at a Chinese shipyard is likely the world’s first mothership designed to deploy submarine drones. It represents the latest piece in the puzzle of China’s undeclared effort to deve...
www.navalnews.com
September 15, 2026 at 8:34 AM
Reposted by Goupil
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate.

ifin-intel.org/blog/...

#ThreatIntel #ThreatIntelligence #TIIMA
Announcing IFIN Lists | IFIN
IFIN Lists is a project to build a well curated, community driven set of permanent block lists for all to use.
ifin-intel.org
September 14, 2026 at 3:23 PM
Reposted by Goupil
Nouvelle vidéo : « NeXT, le système qui a donné macOS (et sauvé Apple) »

Dans cette vidéo, je vous propose de revenir sur l'histoire de NeXT, qui donnera naissance à Rhapsody, Mac OS X puis macOS

🔗 youtu.be/Qo5fQHur8q0
NeXT, le système qui a donné macOS (et sauvé Apple)
YouTube video by Olivier Poncet
youtu.be
September 14, 2026 at 11:27 AM
Reposted by Goupil
⚠️Alerte CERT-FR⚠️

Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898.

www.cert.ssi.gouv.fr/alerte/CERTF...
September 10, 2026 at 4:04 PM
Reposted by Goupil
#CyberResilienceAct | 💻 Fabricants, déclarez les vulnérabilités activement exploitées et les incidents graves de sécurité ayant un impact sur les produits comportant des éléments numériques.

RDV sur la Single Reporting Platform de l'ENISA :
🔗 portal.cra-srp.enisa.europa.eu
September 14, 2026 at 8:41 AM
Reposted by Goupil
I did a somewhat deep dive into the recent OpenAI and Anthropic "hacks" for an upcoming interview.

IMO, the AI companies are better off running with the "rogue AI" story because the real story is actually pretty embarrassing.

Like making your Wi-Fi password "wifi" embarrassing. 🧵
September 13, 2026 at 1:12 PM
Imaginons que vous développiez un code malveillant, et que par négligence il se propage sur Internet et compromette plusieurs systèmes. Votre responsabilité serai sans doute engagée, même si vous plaidez l'incident.
September 13, 2026 at 5:28 PM
Reposted by Goupil
*Those tokens that come free with the Chinese dumplings, are those fungible or non-fungible
September 12, 2026 at 6:11 PM
Reposted by Goupil
AI Doomers, Death Cults, WeChat Worm Exploit
YouTube video by Three Buddy Problem
youtu.be
September 12, 2026 at 6:50 PM
Reposted by Goupil
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
www.bleepingcomputer.com
September 12, 2026 at 2:15 PM
Reposted by Goupil
My essay on rogue AI has been republished by the Bulletin of the Atomic Scientists — “Rogue AI didn’t breach Hugging Face, human decisions did.” Grateful to @thebulletin.org for the invitation!
Rogue AI didn’t breach Hugging Face, human decisions did
At the core of the Hugging Face hacking incident were a series of human choices that traded security for speed.
thebulletin.org
September 11, 2026 at 10:19 AM
eddie.codes/posts/pandas...
Your big data problem might be a medium data problem
Pandas Should Go Extinct
Pandas has taken us a long way, but it's time for a new bear
eddie.codes
September 12, 2026 at 9:41 AM
Reposted by Goupil
Kudelski and Sekoia researchers look at how the Lazarus Group is now operating from six distinct sub-clusters after a major reorganization of the North Korean intel service two years ago

www.sekoia.com/blog/beyond-...

kudelskisecurity.com/research/bey...
September 8, 2026 at 7:30 PM
Reposted by Goupil
After the DOJ and State Department, Congress now wants CyberCommand to use cyber contractors too

A new provision authorizing the DOD to use cyber contractors was included in the National Defense Authorization Act for Fiscal Year 2027

www.bloomberg.com/news/article...
Senate Considers Allowing Contractors to Conduct Military Hacks
Contractors would be allowed to conduct military hacking operations with US government approval under a Senate defense bill that would mark the first time Congress has explicitly authorized the privat...
www.bloomberg.com
September 6, 2026 at 7:44 PM
Reposted by Goupil
Dans son dernier bulletin d'actualité, le CERT-FR revient sur certaines vulnérabilités significatives de la semaine dernière.
https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-037/
August 31, 2026 at 12:55 PM
Reposted by Goupil
CERTFR-2026-AVI-1111: Multiples vulnérabilités dans les produits F5
https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1111/
September 3, 2026 at 2:48 PM
Reposted by Goupil
Also, ICYMI: Last week I published a 3,200-word deep-dive explainer on a major threat to your home and office: Residential proxy networks allow hackers to use your internet connection for crime and cyberattacks. Find out why resproxies are a threat, how they work, and what *you* can do about them. 🤖
How residential proxy networks are hiding hackers in your home
Security researchers say residential proxy networks present a major threat by allowing hackers to commandeer home and office networks for cybercrime.
this.weekinsecurity.com
August 31, 2026 at 12:26 PM
matduggan.com/you-know-gdp...
(and the funniest part: the banners that everybody associate with GDPR actually do not come from GDPR but ePrivacy a different regulation)
You Know GDPR Is Good Based on Who Hates It
FDR has always been one of my favorite presidents, second maybe to Lincoln. Both were men the establishment assumed were one of them until, to their horror, they governed like they weren't. Both could...
matduggan.com
August 29, 2026 at 10:35 AM