Founder of Lupovis

Joined December 2009
277 Photos and videos
I haven't been in academia for almost 5 years, but it's nice to see that my research hit a 1000 citations last year alone. For anyone out of academia, there are a couple of nice milestones I looked for and many others do too, the first citation, the first 100, the first 1000 etc. Most academics never reach 10k and 1k in a year is not bad at all. For those less familiar with it, a citation simply means another researcher has used and referenced your work in their own. It’s one of the signals that indicate that what you built is still being read, used, and shaping ongoing research somehow. btw citation is not impact ;-)
4
90
I went down a rabbit hole looking at kids @YouTube this evening with my nephews. I kept seeing the same videos over and over again… but on completely different channels. Same animations Same voiceovers Same titles Same shorts Sometimes just in a different order. And these aren’t small channels either. A lot of them have: 1M subscribers some closer to 10M millions of views on Shorts Here are a few I came across: Mini Yum Chef Quizzlepop-LearnPlay ThinkDoos Growziki BillyBlipBoss KittyToonZoo SmartJoLetsLearn KIDZOKI_official FundzyBits LittleFlipZoo PlayToon_Learn_Play dadadoo-learn-play VocaToonFun SmileToonKids EmilysPlayhouse-LearningVideos Fixy-Mixy ChupiChapa_ FriendToon- Learn & Play Leo’s Playtime BiBiLo Play Today PurrToonFun ChakaKidsPlay And honestly the list keeps going. If you search a bit, you start recognising the same clips everywhere. What it looks like (from the outside at least): One set of videos being reused across a lot of different channels. Each one tweaks things slightly: Different channel name Same titles clips reordered not even minor edits Then they just post a lot and see what sticks. And it works. Especially with kids content where repetition is normal and people don’t really question whether they’ve seen something before. I was wondering how this fits with the rules on @YouTubeCreators around reused or mass-produced content. Given this is a "network" From what I can tell, the network re-shares many videos, and I am assuming monetisation? So you end up with a lot of these channels networks doing well. They even have an identity Recognisable characters, I keep seeing the same "actors" volume and very very low variation. If you’re building in this space, it raises a pretty simple question: Do you try to compete on volume like this, or actually build something people recognise and come back to? Curious if others have noticed the same thing. oh and here is a small graph of channels sharing a common content pool
1
4
140
Here are some more 🔥
1
50
Great to see @GreyNoiseIO pushing this forward. We’ve been building in this space for 5 years and it’s exciting to see the industry catching up. The perspective you get from the attacker interaction is fundamentally different.
Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic compare what's hitting you to the GreyNoise global baseline. Join today! 🐝
4
122
No auth → full backup → decryption key handed to you. On this one, if it is exposed, you’re not being scanned. You’re being robbed.
We’re seeing CVE-2026-27944 hit our telemetry. Currently without a KEV inclusion. Unauthenticated access to /api/backup in Nginx UI versions lets an attacker download a full system bkp, and the response discloses the material needed to decrypt it via X-Backup-Security. Patch now
3
481
So @CiscoSecure went around all the rooms of the @Hilton at @OneRSAC at night to place one time use - small lcd video of their CEO delivering a message … loads of waste - let’s look what’s inside
30
30
590
95,780
BTW the V100 is a cool chip it supports 1.  Integrated high-speed 32bit MIPS processor, supporting DSP ASE instruction extension. 2.  Full format 1080P30 video decoding such as rmvb/avi/h.264/mpeg. 10.  Support DDR1 and DDR2 memory. 11.  Support WiFi module to realize network application. 12.  Operating system: ucos/linux. 13.  Package: lqfp128-epad, size: 16 * 16mm.
2
97
11,140
So here is where I am at with this sudo sh -c 'dd if=/dev/rdisk4 of=~/flash_dump.bin bs=4m'
1
56
10,604
Xavier Bellekens retweeted
🚨 Critical #Citrix #NetScaler Alert CVE-2026-3055 (CVSS 9.3)Out-of-bounds read lets unauthenticated attackers leak appliance memory, but only if configured as SAML IDP. Also patched: CVE-2026-4368 (session mix-up).
1
1
1
511
Xavier Bellekens retweeted
The Lupovis telemetry observed 1,322 unique attacker IPs originating from Iranian infrastructure targeting US networks during that short burst. More than any other NATO country, should we check the sectors next? #ThreatIntel #CyberSecurity
@symantec Threat Hunters @threatintel research highlights Iranian Seedworm (MuddyWater) activity inside US networks since early February. Interesting timing. The @LupovisDefence telemetry, we observed multiple spikes in activity originating from Iranian infrastructure the last one peaking Feb 12, heavily targeting US networks. This could indicate: • broader reconnaissance activity • infrastructure positioning Credit to Symantec Threat Hunter for the research. Article: security.com/threat-intellig… #threatintel #cybersecurity #Iran
1
1
269
Xavier Bellekens retweeted
CVE-2025-0282 activity just exploded across our sensors. For weeks we saw ~500–1500 tries/day. In the last 48h that jumped to 10k . When splitting by location, the spike is almost entirely targeting US infrastructure. Likely the vuln was automated or a better PoC is available
1
377
CVE-2025-0282 (Invanti Connect Secure) activity just exploded across our sensors. This pattern usually means the vulnerability has been integrated into automated scanning tooling or botnets, moving from opportunistic probing to mass exploitation attempts. Something clearly changed in the ecosystem. We'll be watching to see if the scanning expands globally. #threatintel #cybersecurity #honeypots
CVE-2025-0282 activity just exploded across our sensors. For weeks we saw ~500–1500 tries/day. In the last 48h that jumped to 10k . When splitting by location, the spike is almost entirely targeting US infrastructure. Likely the vuln was automated or a better PoC is available
1
209
Heavy exploitation from Russia this morning seen around the world. Mostly these 2 in the last hour or so. 193.24.123.58 91.215.85.104
We’re observing an increase in exploitation attempts for CVE-2026-20127 (@Cisco SD-WAN). Initial activity was first detected early last week, primarily from the US and the MEA. We are now seeing exploitation originating from Russia, suggesting the activity is spreading
1
137