Software Engineer, working at @skidata | Studied at @alpenadriauni | Tweets are my own (unless blatantly plagiarized)

Joined July 2009
1,028 Photos and videos
Michael Grafl retweeted
‘Buffy The Vampire Slayer’ and ‘Ted Lasso’ actor Anthony Head has died at the age of 72.
1,434
6,207
63,077
5,638,034
Michael Grafl retweeted
Time to talk about this one. CopyFail (CVE-2026-31431) — a 732-byte Python script that roots every Linux distro shipped since 2017. 🧵
a567d09b15f6e4440e70c9f2aa8edec8ed59f53301952df05c719aa3911687f9 👀
42
461
2,765
743,030
Michael Grafl retweeted
Sie haben auch erstmals ein AI-generated Video aus den vorher nachher Bildern online gestellt, was das Ausmaß finde ich nochmal deutlicher macht. Die Gletscher Österreichs sind in der Endphase.
4
26
73
3,279
Michael Grafl retweeted
It turned out there are many more payloads used in the Notepad attack! To stay undetected, its masterminds were COMPLETELY changing execution chains about every month. Here are more IPs used in the attack: 45.76.155[.]202 45.32.144[.]255 Read below for many other IoCs! [1/8]
19
231
1,140
107,466
Michael Grafl retweeted
Non-malware schizos asking about why the Notepad malware payload was so interesting. Okay, we'll discuss it without getting too schizo. First, Rapid7 (and other various Cyber Threat Intelligence vendors) seem to generally attribute the Notepad compromise to Chinese APT group "Lotus Bloom". They attribute it to Lotus Blossom because they tend to recycle code segments to save time. Basically, fingerprints. Lotus Blossom is the invented name intelligence organizations have assigned to a group of Chinese government sponsored hackers. Their true identity is unknown, but speculative. It is not one person, it is likely a group of unknown size, it could two people, it could 15 people. Lotus Blossom has been active since 2009 (or so they speculate). Lotus Blossom are not noobs who do hacker noob stuff. Lotus Blossom is assigned high-profile tasks. Lotus Blossom does extremely specific targets, most notably they are instructed by the Chinese government to hack government institutions, telecom companies, aviation companies, and critical infrastructure (nuclear power plants, electrical power grids, hydroelectric dams, etc) in Southeast Asia and Central America. When Lotus Blossom targeted Notepad , and users in specific regions (presumably Southeast Asia and Central America) attempted to do an update it delivered "Chrysalis Backdoor". Chrysalis Backdoor is the name intelligence companies invented and now call this malware. Chrysalis Backdoor used a lot of really common malware techniques which truthfully I won't go too much into (API hashing, custom implementations of GetProcAddress, malware nerd stuff). However, what makes this malware very special is it's usage of Microsoft Warbird. Microsoft Warbird is a proprietary technology which is rarely discussed. It is an internal library Microsoft uses to obfuscate it's instruction set in-memory. In other words, it's Microsoft really fancy custom way of preventing people from reverse engineering what Windows is doing when it's running. Unknown to me personally (and a lot of people apparently), in the past few years (2023) some security researchers have discovered ways to discretely use Microsoft Warbird and use it as a weapon. Basically, you can use undocumented APIs in Windows to use Warbird for your malware. This provides a way to hide what your malicious code is doing while it's running without needing any external tooling or custom implementations. They're weaponizing Microsoft's anti-tampering and/or anti-reverse engineering technology for malicious purposes. This is extremely impressive because it shows: 1. Lotus Blossom pays close attention to really talented security researchers or... 2. Lotus Blossom has really good security researchers on payroll Both are totally possible. The remainder of the Lotus Blossom tooling is fairly generic malware stuff and isn't too terribly impressive. Lotus Blossom (unironically) did a very good job hijacking Notepad update infrastructure and weaponizing Microsoft's anti-tampering technology (Warbird).
30
182
1,757
95,153
Michael Grafl retweeted
This is bad. Putty level bad. notepad-plus-plus.org/news/h…
257
1,532
11,534
3,130,571
Ambitioniert, liebe Post, ambitioniert.
6
Michael Grafl retweeted
you have got to be kidding me.
Why is pasting into VSCode Terminal slow? Because it sleeps for 5ms every 50 characters.
24
143
6,539
622,379
Might need some help from @WorldBollard.
In meiner Nachbarschaft wurde vor rund acht Wochen eine Verkehrsinsel umgestaltet und im Zuge dessen auch ein neues Schild aufgestellt wo vorher keines war. Soeben hat es zum fünften mal jemand umgefahren.
10
29 Nov 2025
Nicht der Bohne aussetzen?
4
Michael Grafl retweeted
When asking coding questions
234
1,476
25,016
707,030
Michael Grafl retweeted
#JUnit 6.0.0 is released! ✨ Java 17 and Kotlin 2.2 baseline 🌄 JSpecify nullability annotations 🛫 Integrated JFR support 🚟 Kotlin suspend function support 🛑 Support for cancelling test execution 🧹 Removal of deprecated APIs docs.junit.org/6.0.0/release…

2
78
221
21,194
Using URLs from the browser history for AI prompt injection is creative, I have to admit. 😬🫠
New #TenableResearch discovery 🚨: The "Gemini Trifecta" exposed three critical, now-remediated vulnerabilities in Google's #GeminiAI, highlighting how new attack classes target sensitive user data. Read the full research here: spr.ly/6014A9Z8y
14
20 Sep 2025
Ouch. Tokens with unrestricted access without any audit logs. What could possibly go wrong?
17 Sep 2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
25
🤣🤣🤣
12
Ach, wie ärgerlich
Frau versucht seit Jahren vergeblich, Warentrenner zu kaufen der-postillon.com/2018/08/wa…
7
Michael Grafl retweeted
I cannot stress enough there are four different ads in this screenshot
enshittification | noun | when a digital platform is made worse for users, in order to increase profits
217
13,842
164,601
3,690,428
Unabhängig davon, was wessen Magen verträgt, ist das ein sehr lesenswerte Artikel.
17
26 Aug 2025
Went through similar fun. This is entire process is uuuuuuh ..... "suboptimal".
Yesterday evening I tried to play Minecraft multiplayer with my 8 yr old. Single worst computing experience I've had in a long time thanks to the whole Microsoft account management. I naively thought "let me create a new account for her, switch her out of my account, use that—
18