Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Caitlin Condon

@catc0n@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Adventurer. Takes a lot of photos, calls many places home. VP of research @vulncheck@infosec.exchange. Previously vulnerability research director @ Rapid7 + @metasploit@infosec.exchange. Opinions mine, etc. She/her.

1331 Followers
713 Following
38 Posts
Joined October 30, 2022
Website:
caitlincondon.com
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1w ago

@darfplatypus@infosec.exchange

14
0
4
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1w ago

@darfplatypus@infosec.exchange can’t stop won’t stop (none of these are mine, I’m stealing them all from one person who is very cool but shall remain nameless)

9
0
3
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1w ago

So it turns out Strasbourg is real effing pretty and also extremely chill

9
0
1
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1w ago

Happy hour in the States: 4-6 PM, the six cheapest items on the menu. Everyone is still at work. Keep ordering or gtfo you impoverished pieces of shit.

Happy hour in France: 3 PM - 10 PM. Or midnight. Have all the wines. Have all the cocktails. We do not believe in food. Stay forever, we don’t really care.

5
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3w ago

After disclosing ENDLESSDOORS this month, @albinolobster@infosec.exchange began researching the global ZBT router supply chain. He expected to find more ENDLESSDOORS.

Instead, he found two totally different implants: #DARKLANTERN and #SPEAKINGSTONE.

DARKLANTERN is a backdoor that listens on the WAN and executes arbitrary commands. VulnCheck Target Intelligence found DARKLANTERN in 22 countries worldwide, primarily in the United States.

SPEAKINGSTONE is a phone-home implant that can execute commands as root, redirect DNS traffic, and open remote-access tunnels. It had a hard-coded C2 backup domain that was unregistered at time of discovery. So @albinolobster@infosec.exchange registered it, and hundreds of implants started calling in.

Callbacks to the VulnCheck-sinkholed domain came almost exclusively from China (83% came from China Mobile's network). In other words, SPEAKINGSTONE is domestic surveillance technology that made its way into the global supply chain.

https://www.vulncheck.com/blog/zbt-darklantern-speakingstone

5
0
6
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago
"AI is going to explode vulnerability exploitation!!!111!!" Not yet, friends. Not yet. https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
17
2
6
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3w ago

If you've missed any super dope research from @lobsterjerusalem@infosec.exchange recently, pleez don't miss it anymore:

Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: https://www.vulncheck.com/blog/death-by-20k-pocs

SharePoint RCE:
https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

4
0
2
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3w ago

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

4
0
4
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago

New vulnerability disclosure from
@chocapikk_@bird.makeup:

CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.

https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce

6
0
4
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4w ago

VulnCheck curated 20K+ public exploits and vulnerability analyses in 2025. As of mid-August 2026, we’ve already incorporated 17,800+ PoCs and write-ups, putting us 87% of the way to 2025’s numbers with another 4+ months left to go in the year.

Our team wrote about what the acceptance rate looks like for GitHub exploits (a bellwether for broader exploit trends), and surprise surprise! AI slop is leading to noticeably higher rejection rates.

The vulns might be real, but that doesn't mean the exploits are.

https://www.vulncheck.com/blog/death-by-20k-pocs

4
0
2
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago

Interviewing candidates used to be like, "I hope this person can computer good and isn't a psychopath." Now it's like, "This threat actor is slightly less qualified than the threat actor from last week, they should pair."

7
1
1
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3w ago

@cR0w@infosec.exchange @Sempf@infosec.exchange 😂

:rainbowCrow: (@cR0w@infosec.exchange) - Infosec Exchange

2
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago

Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster@infosec.exchange discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.

The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.

The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).

https://www.vulncheck.com/blog/zbt-endlessdoors

3
0
4
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago

The VulnCheck CVE Numbering Authority has issued thousands of CVEs over the past year for vulnerabilities reported to us by researchers and the community. We're looking for a US-based senior vulnerability analyst to join our CNA team, which vets community researcher reports, coordinates disclosure across researchers and suppliers (and sometimes CERTs), and publishes (a lot of) CVEs.

If you care about coordinated vulnerability disclosure (CVD) and have experience coordinating disclosures for vulns reported to you by third parties, we want to talk to you! The VulnCheck CNA team is highly engaged with both the research community and our peers in the #CVE and #CVD space. This role is a hands-on operational role doing day-to-day CVD, but you'll also have the opportunity to give input into global CVE and CVD efficacy in the age of AI.

https://job-boards.greenhouse.io/vulncheck/jobs/4328006009

2
0
2
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 2mo ago
Heyoo, there's a #wp2shell WordPress core RCE situation going on. The @vulncheck@infosec.exchange research team sussed out what we could determine from patches and public info, and so far, while it ain't *good*, it could maaaybe be worse. I guess we'll see come Sunday/Monday what details and exploitation status looks like, but it feels like we're gonna see attacks start basically now. https://www.vulncheck.com/blog/wp2shell
5
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago
Replying to @catc0n@infosec.exchange
In all seriousness, good grief.
3
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4mo ago

"That's the dumbest shit I've read in a bit"

- Quote from the team exploit mines 2026-05-16T00:06:00Z

9
1
2
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4mo ago
Replying to @catc0n@infosec.exchange
Also, for the love of sky chicken, do NOT send me AI-generated resumes. I get so many of them. So, so many of them. I do not care if you match every single bullet point in the job description — if that's all your CV is doing, it doesn't stand out anymore and it goes straight in the trash. I get thousands of resumes for these roles. If you want to stand out, write it as a gd* human, please. Robots are a dime a million. Actual brains aren't. Show me you have one, and I'll listen.
9
1
3
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 2mo ago
New vuln disclosure out from @chocapikk_@bird.makeup: Unauth SSRF in Monsta FTP (CVE-2026-60105), makes for a nice primitive. Silently fixed a couple weeks ago, go figure. Full details + PoC out on the @vulncheck@infosec.exchange blog: https://www.vulncheck.com/blog/monsta-ftp-ssrf-ipv6-blocklist-bypass
2
0
2
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3mo ago

Happy place

3
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4mo ago

👋 There's been a lot of discussion recently about the volume of vulnerability reports that PSIRTs, open-source maintainers, and technology producers are receiving. The CVE Program's Researcher Working Group (RWG), which I've been chairing for the last 9 months, is developing guidance for security researchers on how to most effectively report new vulnerabilities to supplier organizations.

👉 We're seeking input from the community on the data points, report characteristics, and reporting practices that help reduce time-to-verification for new vulnerabilities. If you're a researcher, a PSIRT, a VM or SecOps practitioner, or a bug bounty provider who's been on the hook for looking at or validating vulnerability reports in your career, we want your feedback on what works — and what doesn't!

🗓️ The discussion will stay open through (at least) June 5, 2026. Feedback is best submitted by commenting on the GitHub issue below!

https://github.com/CVEProject/researcher-working-group/discussions/29

5
0
4
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4mo ago
Replying to @paul_ipv6@infosec.exchange
@paul_ipv6@infosec.exchange I am told that if I bury my computer in a lead-lined concrete tomb and run into the woods (never to return), I can reduce my pain by 100% or more 🧠
3
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4mo ago

New list! 2026 routinely targeted vulnerabilities (so far)

https://www.vulncheck.com/blog/routinely-targeted-vulnerabilities-may-2026

2
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 5mo ago
After 2+ weeks of semi-painful exploit development, @yeslikethefood@infosec.exchange and team have a full RCA out for Cisco Secure Firewall Management Center (FMC) CVE-2026-20079. The bug is a CVSS 10, but there are significant prerequisites that may limit exploitability in real-world scenarios. There are between 300 and 700 FMC systems on the public internet as of today. https://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079
CVE-2026-20079 - Cisco FMC Authentication Bypass RCE Analysis  | Blog | VulnCheck
VulnCheck

CVE-2026-20079 - Cisco FMC Authentication Bypass RCE Analysis | Blog | VulnCheck

VulnCheck

3
1
1
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3mo ago

Someone should tell the North Korean IT workers to stop using the Golden Gate bridge as their Zoom backgrounds.

1
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 4mo ago
Replying to @catc0n@infosec.exchange
This was a team gem, for the record, definitely not my own
1
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 8mo ago
It's been a while since I was on public transit after 10 PM (I'm old), and seeing The Youth all out and about doing Youthful Things is unexpectedly heartwarming and reassuring.
3
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 21mo ago

Full Rapid7 analysis of #Cleo CVE-2024-55956 now available c/o @stephenfewer@bird.makeup. It's neither a patch bypass of CVE-2024-50623 nor part of a chain after all — totally new bug, different exploitation strategies across the two issues (though the same endpoint gets used either way).

I'm not sure it's been mentioned much yet that Cleo evidently released IOCs related to CVE-2024-50623 in October 2024, implying the older bug's been exploited for a minute. Would sure be helpful to know more about who was doing that exploiting, particularly now that Cl0p has claimed credit for last week's attack.

https://attackerkb.com/topics/geR0H8dgrE/cve-2024-55956/rapid7-analysis

8
2
6
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 20mo ago
Replying to @jerry@infosec.exchange
@jerry ignore request denied.
4
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 15mo ago
Replying to @GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social I am so very sorry, Kevin — my heart goes out to your whole family.
1
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 3w ago

🙄 I see the AI hype machine is AI hype machining real hard today.

0
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 7mo ago
Replying to @jvoisin@infosec.exchange
@jvoisin This is a very cool idea.
0
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1w ago

@darfplatypus@infosec.exchange everyone else is going to be v confused by this thread 😂 Here’s one req: https://job-boards.greenhouse.io/vulncheck/jobs/4397769009

0
0
0
0
Open post
Caitlin Condon @catc0n@infosec.exchange
· 1mo ago
Replying to @amuse@infosec.exchange
@amuse@infosec.exchange oh no, I’m going to enjoy this way too much
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:35:07 UTC