Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

‘Twas the night before InfoSec

A festive cybersecurity poem

by The Gurus
December 24, 2020
in Featured, Guru's Picks, Media
Holiday phishing scam surge aimed at small business
Share on FacebookShare on Twitter
‘Twas the night before Christmas, and fresh off the LAN

The packets were coming fast out of the span. 

My wireshark was up with my templates in place, 

In hopes that I’d find an IP I could trace. 

The smart home was snug in its /28

With a meager allow-list, and a lock on the gate.

With a few hours to setup and wrap this year’s catches

I’d been charging them up, and applying their patches,

When down in the VLAN there’d been such a spike 

I’d opened the logs to see what it looked like.


Away to the dashboard I stumbled and flew; 

Most days I’m on Red, but tonight, I was Blue. 

The DST in the headers was a weird bogon range. 

“Two oh three... zero? You can’t route there... how strange.” 

When what, to my wondering eyes, should come back 

But a TCP handshake -- not a RST, but an ACK! 


A cool sweaty IR-like calm to me came, 

As the nightmares and malwares, I ruled out by name:

“The SPIDERs and PANDAs don’t care about me,

It’s not running Windows, so it’s not IcedID… 

Not Trickbot, not Ryuk, not Buer or Clop, 

Not Scarab or Locky, no second-stage drop.”


A session had opened on port 443, 

And a download began - not one started by me. 

I looked back to ensure that the capture was on,

And stood by to cut comms once the vandal was gone.

But the session closed up just as fast as it came

And the download just sat there - “GIFT.BIN” was its name.

I’d retrieved a live sample! And without any warning, 

Had got something fun to unwrap Christmas morning. 

I checked on the rulesets, configs, and permissions,

And rebooted each box for the sake of tradition.

I waited for more but there wasn’t a peep,

So I finished my wrapping and popped off to sleep. 


And after the coffee and presents and nog,

The matching pajamas, the pickle, the grog, 

Video calls with our family and friends,  

Things had settled, so I went to tie up the loose ends.

I ran strings right away and my jaw opened wide,

For there, unencrypted, a message I spied: 

“2020’s been awful, with so much that you’ve missed

Just to keep others healthy - so you made the Good List! 

And like all of your friends, I have had to stay distant,

But your record’s been stellar, so the elves were insistent.

You already have surplus gadgets that light up

So I got you this PoC, and a CVE writeup.

The binary is an iPhone zero-day,

And I’ve left enough out that you’ll have room to play.

And once you’ve dissected and filled in the blanks,

And disclosed it responsibly, you can cash in my thanks! 

Thanks for staying inside this year, hunkering down,

Thanks for wearing your mask, though you felt like a clown,

Thanks for not hoarding groceries, and for learning to cook,

Or for trying a language, or reading a book.

And following rules from your state and your county.

Now warm up your debugger, and cash in that bounty!”


This poem was written by J.R Parsons for AT&T Cybersecurity. You can read more of their blogs here 
ShareTweet
Previous Post

Millions stolen from online bank accounts following large-scale fraud operation

Next Post

Customers’ call records access in T-Mobile breach

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol