Kevin Beaumont: Naming Bugs and Challenging Microsoft
When a new Windows flaw is about to become everyone's problem, there's a decent chance it already has a nickname, a logo drawn in Microsoft Paint, and a blog post from Kevin Beaumont explaining why you should patch tonight.
Beaumont, known online as GossiTheDog, is the researcher who named BlueKeep and Follina, chronicled CitrixBleed, runs honeypots that catch exploits in the wild, and describes himself as a "cybersecurity weather person." More than 76,000 people follow him on Mastodon alone.
He's also worked inside the company he writes about most. In 2020 Microsoft hired him. By 2024 he was back outside, showing the world that its flagship AI feature stored everything you'd ever seen on your PC in a plain-text database.
Kevin Beaumont at a Glance
- Beaumont started in IT at an oil company whose staff thought "virus software" sounded like something bad, and spent decades building security programs and running security operations centers from scratch.
- On his blog, DoublePulsar, he wrote up the global honeypot networks he built to watch nation-state exploits being used in the wild.
- In May 2019 he nicknamed a Windows Remote Desktop flaw BlueKeep, and that November his honeypots caught it being exploited in the wild, which Microsoft confirmed with his help.
- In early 2020 he joined Microsoft Threat Protection as a senior threat intelligence analyst after five rounds of interviews.
- In 2022 he named Follina, a Microsoft Office zero-day, after an Italian area code, then named ProxyNotShell, a pair of Exchange zero-days.
- In October 2023 he documented the mass exploitation of CitrixBleed, a flaw that let attackers skip passwords and multi-factor authentication entirely.
- In May 2024 he showed that Microsoft's Recall feature could be looted with two lines of code. Microsoft delayed the feature within weeks.
- In 2026 he reported FortiBleed, in which admin passwords for 75,000 Fortinet firewalls were cracked, and tracked Citrix NetScaler zero-days being exploited around the world.
The Life of Kevin Beaumont
Virus Software
In July 2018, Beaumont wrote a post of advice for people entering the industry and opened it by admitting his age: "I'm old. Like super old. Like 36 old."
His youth, he wrote, was "a bunch of hanging out on IRC and visiting Vegas," when the idea of hiring a hacker "was laughable to most people." At his first job, an oil company, colleagues hearing him talk about deploying virus software would ask if he meant anti-virus software. "They were convinced it meant something bad," he wrote.
The jobs that followed were the unglamorous core of the field. Over the years, he later wrote, he'd implemented a security program from scratch, rolled out vulnerability management, run a security operations center and started security operations from the ground up.
The Honeypot Man
What made Beaumont different was that he set traps. His blog, DoublePulsar, which shares its name with the NSA-linked backdoor leaked in 2017, carried write-ups like "EternalPot," his lessons from building a global honeypot infrastructure to watch nation-state SMB exploits hit real machines.
When Microsoft patched CVE-2019-0708 in May 2019, a wormable flaw in Remote Desktop, Beaumont gave it a name. He called it BlueKeep "as exploitation would likely cause 'blue screen of death' (Windows to crash reboot) and a worm would lead to the Game of Thrones 'Red Keep' moment."
Then he built BluePot, a worldwide honeypot network running on Azure Sentinel and Sysmon, and waited. In early November 2019 he reported that the honeypots were crashing. Microsoft confirmed it'd worked with Beaumont and fellow researcher Marcus Hutchins to analyze the crashes, which turned out to be a BlueKeep exploit installing a coin miner.
Five Interviews
A few months later, the man who'd spent years sniping at vendors took a job with the biggest one. "I'm incredibly grateful, and a little scared, to say that soon I will be joining Microsoft Threat Protection as a Senior Threat Intelligence Analyst, working with the team in Redmond," he wrote in early 2020.
He admitted he'd been "largely suspect of the cybersecurity vendor industry and occasionally critical of Microsoft," and that the most obvious reason for the move was that "I applied for a job and they grilled me for five interviews and offered it to me." The deeper reason was scale: Microsoft was collecting trillions of signals a day, and spotting what attacks had in common was, he wrote, "fundamentally why I started looking at this job."
The post also contained the most Beaumont sentence ever written: "I finished Skyrim in 2011 and haven't recovered yet."
Follina and a Crap Logo
By 2022 he was back to naming Microsoft's bugs. On May 27 of that year, the research group Nao_sec spotted an odd Word document uploaded from Belarus. It used a remote template to pull in HTML that invoked the ms-msdt support tool and ran PowerShell, with macros disabled.
"Most importantly, we need to name this and give it a crap logo," Beaumont wrote two days later. He called it Follina because the sample referenced 0438, the area code of the Italian town of Follina, and noted that a similar file had been reported to Microsoft in April, which "decided it wasn't a security issue." Microsoft patched it in June.
Later that year, when a Vietnamese firm reported new Exchange zero-days that looked a lot like 2021's ProxyShell, he dug in, and once Microsoft issued two new CVEs he named the pair ProxyNotShell, with "the official logo, because why not."
He Didn't Want a Horse
In November 2022, Beaumont left Twitter, explaining in a post titled "I moved my Twitter account because I didn't want a horse" that he didn't want his social media presence owned by Elon Musk. "I'm now [email protected], which I own," he wrote.
The Mastodon account now has more than 76,000 followers and a bio that calls him a "cybersecurity weather person" and jokes that his favorite online pastime, a word we'll leave out, is an anagram of "Top Insights." Direct messages, it adds, are disabled.
Aaaaaaaa
On October 10, 2023, Citrix patched a memory-disclosure flaw in its NetScaler appliances. Weeks later Beaumont reported that the flaw, known as CitrixBleed, was under mass exploitation, including by a ransomware group.
The bug leaked session tokens, which attackers could replay to bypass passwords and multi-factor authentication. "You exploit the vulnerability by typing 'aaaaaaaaaaaaaaaaaaaaaaaa' a lot," he wrote, "which is at present my mood." Even patched systems stayed exposed until their sessions were killed, and his follow-ups tracked the fallout through credit unions and hospitals.
Total Recall
Microsoft's Recall feature, announced in May 2024 for Copilot+ PCs, takes screenshots of everything on screen and makes them searchable. Microsoft chief Satya Nadella pitched it as a photographic memory of your PC life. Beaumont got the software running on a machine without the required chip and looked inside.
On May 31 he published "Stealing everything you've ever typed or viewed on your own Windows PC is now possible with two lines of code." Recall stored its history in an easy-to-find database in the user's AppData folder, in plain text.
"I think they are probably going to set fire to the entire Copilot brand due to how poorly this has been implemented and rolled out," he wrote. "It's an act of self harm at Microsoft in the name of AI."
PCMag described him as "another security researcher and former Microsoft employee," and within two weeks Microsoft had promised encryption and opt-in by default, then on June 13 delayed Recall altogether for testing with Windows Insiders. Beaumont tested it again on a Copilot+ PC in April 2025, and in October 2025 reported that Gaming Copilot failed basic privacy tests.
Weather Report, 2026
The forecasts haven't slowed. In May 2026 he called Microsoft's stance on zero-day exploits "a dumpster fire of their own making."
In June he reported FortiBleed, with admin passwords for 75,000 Fortinet firewalls cracked, and followed up on what was happening to the victims. In July he documented an advertising platform, Adform, compromised to push a crypto stealer.
By September his Mastodon feed was tracking Citrix NetScaler zero-days that'd been exploited globally for weeks, and in October he was fingerprinting unpatched appliances remotely and refusing to say how, because "every time I do, Citrix patch out the methods." Patch rates, he noted, were still well below 50 percent.
His advice that week was characteristically unglamorous: have a playbook for "Advanced Persistent Teenagers," ransomware and extortion groups, and practice it, because you're far more likely to need it than a nation-state one.
Kevin Beaumont: Top Insights
Beaumont's value is speed and plain language. He watches the honeypots, names the thing, draws the bad logo and tells you what to do, often before the official advisory catches up.
He's been on both sides of the Redmond door. These days he writes from the outside, where, as his blog has always noted, the opinions are his alone.
The weather, as ever, is mostly bad. At least you'll hear about it first.
QUOTE:
"Amateurs hack systems, professionals hack people."