Blog

Vulnerabilities

WP2SHELL Update

This morning I’ve started to see exploitation attempts on pwndefend.com (they all failed because like about 80% of sites (based on sampling) this site automatically patched, but also, this site has word fence, is fronted by Cloudflare.

Global Exposure

On the 18th (AM) I did sampling of about 3.5K hosts and found ~20% were not patched. The cyber apocalypse is not seemingly here today! (let alone the fact that if every WordPress site was popped, the world would probably not end)

Read more “WP2SHELL Update” →
Threat Intel

WP2SHELL

Yesterday afternoon/early evening a patch for WordPress was released (7.0.2) which address two vulnerabilities which are named: WP2SHELL. This is a fast post (largely generated by Claude Opus) to provide some detail. For reference in our research we have found ~20% of WordPress sites still vulnerable as of a few hours ago (based on a sample), so this is a live scenario and it would be strongly advisable for organisations to take appropriate steps. This morning I’ve built a docker lab of a vulnerable WordPress site and demonstrated hash theft and web shell deployment to a vulnerable lab instance.

I’ve put some resources for people (use at own risk) into a repo: https://github.com/mr-r3b00t/wp2shell/

that includes a scanner, some info on the vulns and a PoC tool!

Read more “WP2SHELL” →
Leadership

You Cannot Block Infinity

We should block the RMM! We should block that IP! We should block that port! The trouble is; there’s 65535 ports per protocol (TCP/UDP), there’s billions of IPs (dynamic and rotating infra are a thing), and well that’s a lot of work, neve ending, in fact!!

This topic has come up a number of times recently so I thought I’d put it into a blog, so I had Claude generate this based on my quick fire views:

Read more “You Cannot Block Infinity” →
Cybercrime

When the negotiators go bad!

Every ransomware incident runs on one uncomfortable assumption: that the people you bring in to help are actually on your side. A case that concluded in a Florida federal court this month blew a hole straight through that assumption. Three cyber professionals — two of them ransomware negotiators whose day job was to defend victims — have been sentenced for working as an affiliate crew of the ALPHV/BlackCat operation. One of them didn’t just moonlight as an attacker; he sold out the very clients who were paying him to protect them.

This is not another “big scary ransomware gang” story. It’s an insider-threat story, and it lands right in the middle of the incident-response industry itself. If you run an IR practice, negotiate on behalf of victims, broker cyber insurance, or you’re a CISO who will one day have to trust one of these firms on the worst day of your career — this one is worth your time.

Read more “When the negotiators go bad!” →
AI

AI: Fear it, so I can sell you the…

We are already watching the fear, uncertainty and doubt industry spin up around AI. It follows a pattern anyone who has sat through a vendor pitch will recognise: take a real, narrow signal, strip out the caveats, and inflate it until it fills a keynote slide or a board paper. The problem is not that AI carries no risk. It carries plenty. The problem is that the loudest claims are almost always the least accurate, and the people making them usually have something to sell — a model, a defence against one, or a regulatory moat.

So let’s take the three narratives I keep hearing, put them next to the evidence, and separate the kernel of truth from the theatre.

Read more “AI: Fear it, so I can sell you the cure!” →
AI

How do LLMs work?

Ok full disclosure, because you know I like to say when I’m using ‘AI’, this post is specifically mostly created by an LLM. Because it’s an interesting experiment and I don’t claim to be an ‘AI’ model creation and platform expert, so let’s see if using an LLM can help me! I was in a meeting along time ago at MS Victoria with some people (can’t imagine what types of people that would be) and we were talking about this tech, it was so long ago I can’t remember the details or anyones faces (useful that)… but the convo was really good, anyway, so what is an LLM and how does it work?

Read more “How do LLMs work?” →
AI

Mythos, isn’t magic!

I’m in a bit of a rush with this one but the TLDR; the USA senate was told:

“On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”

This isn’t really great… and you will hopefully see why!

Read more “Mythos, isn’t magic!” →
Leadership

You Can’t Defend Everything: Threat Modelling as an Economics…

In a world now seemingly filled with mad probability robots you might think this makes the world simpler, I’m not so sure…. More code, faster, more tools, faster, more technical debt, faster… and then what of the erosion of the human importance? Well human 2.0 is probably augmented not redundant… and who doesn’t love a bit of Deus Ex! Now full disclosure this blog is guided by me but written by Claude (mostly), why? Why not? I’m still here, guiding things, writing this intro by hand, but the concepts of cyber security, the foundations and underpinning logic, well they are probably older than me! I’m not talking about castles and moats, but even they play a part in our understanding of attack and defence. There’s even a bit of a public wifi link here if you read between the lines. Not every threat actors is all knowing and all powerful (in fact no one is!). So let’s see what Claude Opus 4.8 has to say about the topic:

Read more “You Can’t Defend Everything: Threat Modelling as an Economics Problem” →