Brutkey

Kevin Beaumont
@GossiTheDog@cyberplace.social

Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.

I have Direct Messages disabled - you can send them, but I will never receive them.


Notes
4000
Following
0
Followers
0
My website
https://doublepulsar.com
Github
https://github.com/GossiTheDog
Signal
GossiTheDog.1337
Kevin Beaumont
@GossiTheDog@cyberplace.social

cybersecurity 2025

Kevin Beaumont
@GossiTheDog@cyberplace.social

Ethics statement:

- I do not work for a cybersecurity vendor (or an MSSP, MSP, etc)

- I do not own shares in any cybersecurity company, tech company etc

- I do not have any shorts in any company

- I’m busy in the trenches dealing with attackers typing β€œ../..” to get root access and such.

Kevin Beaumont
@GossiTheDog@cyberplace.social

Pinning this: if you DM me, I can’t see it, sorry - I have DMs disabled, they get yeeted into the abyss with the Star Wars Holiday Special.


Kevin Beaumont
@GossiTheDog@cyberplace.social

Remember that time I ended up in court with Elon Musk after he bet me the cave diver was a pedo?

Anyway, here’s Elon begging Jeffrey Epstein for crazy parties on his private island, several years after Epstein was convicted of sex trafficking girls.

Kevin Beaumont
@GossiTheDog@cyberplace.social

If you're wondering on xAI's stance on this, aside from Elon posting a crying with laughing emoji, Grok's creators have raised a further $20bn from Cisco and such yesterday.
https://www.reuters.com/business/musks-xai-raises-20-billion-upsized-series-e-funding-round-2026-01-06/

Kevin Beaumont
@GossiTheDog@cyberplace.social

Related.

Kevin Beaumont
@GossiTheDog@cyberplace.social

I find it interesting that there's loads of people who made a core part of their identity campaigning against trans women being in women's spaces and how it impacts women, who have gone completely silent about Grok being used to undress and brutalise women.

Kevin Beaumont
@GossiTheDog@cyberplace.social

Merry Christmas to everybody, except that dude who works for Elastic, who decided to drop an unauthenticated exploit for MongoDB on Christmas Day, that leaks memory and automates harvesting secrets (e.g. database passwords)

CVE-2025-14847 aka MongoBleed

Exp:
https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py

This one is incredibly widely internet facing and will very likely see mass exploitation and impactful incidents

Impacts every MongoDB version going back a decade.

Shodan dork: product:"MongoDB"

Kevin Beaumont
@GossiTheDog@cyberplace.social

https://replaceyourboss.ai/

Kevin Beaumont
@GossiTheDog@cyberplace.social

cybersecurity 2025

Kevin Beaumont
@GossiTheDog@cyberplace.social

When vulnerabilities influence product usage, Microsoft Exchange Server edition with @shodan@mastodon.shodan.io data.

272k OWA servers when ProxyLogon RCE vuln was revealed. With follow on vulns ProxyShell and ProxyNotShell, numbers fell to 96k and still falling.

Kevin Beaumont
@GossiTheDog@cyberplace.social

Bonus https://youtube.com/shorts/jbKb7U-Gz34

Kevin Beaumont
@GossiTheDog@cyberplace.social

This scene just happens randomly in a movie and is never discussed again https://youtu.be/awkiQlrSgGg