hrbrmstr πΊπ¦ π¬π± π¨π¦ π³οΈβπ (@hrbrmstr@mastodon.social)
Attached: 1 image
just focused on U.S. as destination and this is one of the most coordinated massive campaigns I've seen in quite a while.
GreyNoise at it again, picking up a massive, coordinated campaign targeting US-based Microsoft stacks starting a few days ago, sounds like. Some day Iβm gonna make @hrbrmstr.dev build me a morning dashboard I can just grab my coffee and shout βDamage report!β at.
mastodon.social/@hrbrmstr/11...
10.10.2025 12:56 β π 0 π 0 π¬ 0 π 0
SHAPIRO: OK, so you've spent your career creating television without Al, and I could imagine today you thinking, boy, I wish I had had that tool to solve those thorny problems...
SIMON: What?
SHAPIRO: ...Or saying...
SIMON: You imagine that?
SHAPIRO: ...Boy, if that had existed, it would have screwed me over.
SIMON: I don't think Al can remotely challenge what writers do at a fundamentally creative level.
SHAPIRO: But if you're trying to transition from scene five to scene six, and you're stuck with that transition, you could imagine plugging that portion of the script into an Al and say, give me 10 ideas for how to transition this.
SIMON: I'd rather put a gun in my mouth.
David Simon, creator of βThe Wireβ, being interviewed by Ari Shapiro (NPR)
09.10.2025 04:42 β π 27019 π 8575 π¬ 326 π 903
'When authoritarians seize power, it is crucial to recognize courageous defenders of freedom who rise and resist,' the Norwegian Nobel Committee said as it announced Maria Corina Machado as the winner of the 2025 Nobel Peace Prize
10.10.2025 09:30 β π 5096 π 1847 π¬ 140 π 409
YouTube video by SentinelOne
LABScon25 Replay | Auto-Poking The Bear - Analytical Tradecraft In The AI Age | Wendiggensen & Palm
YESSSSSS LABScon 2025 videos have started going up. This was a fantastic talk by two Dreadnode folks on the nuts and bolts of an agentic system built for Russian internet content analysis, as well as the limitations, ways to properly assess it, and further implications.
youtu.be/zZUKMrz7TNU
09.10.2025 14:09 β π 1 π 0 π¬ 0 π 0
Figma MCP Server Opens Orgs to Agentic AI Compromise
A bug (CVE-2025-53967) in a popular Web design tool's option for talking to agentic AI allows command injection leading to remote code execution (RCE).
I love how weβre all just pretending MCP can be patched like any other software and the problem solved.
The nondeterminism is what Nvidia AI red teamer Rich Harang very presciently calls a βuniversal anti-patternβ that allows for these vulnerabilities.
www.darkreading.com/vulnerabilit...
09.10.2025 13:59 β π 3 π 1 π¬ 0 π 0
Framework can make this right, but doubling down on supporting projects by a toxic dickhead that also gleefully celebrated mass tech worker layoffs βbecause DEIβ is not apolitical or βbig tent.β
Itβs just another bro show.
09.10.2025 12:58 β π 0 π 0 π¬ 0 π 0
In regards to Frameworkβs latest footgunning, two things:
1. Tech is and always has been political. Anyone saying otherwise simply wants to avoid being held accountable for their words and actions.
2. βBig tentβ policies loudly express that youβre perfectly okay becoming the neighborhood nazi bar.
09.10.2025 12:56 β π 1 π 0 π¬ 1 π 0
Addams family clip with Morticia repeating the family credo, which is the text above.
βWe gladly feast on those who would subdue us.β
Was reminded of this tonight and need to carry it forward.
09.10.2025 00:44 β π 6 π 2 π¬ 0 π 0
Weekly Geopolitical Risk Briefs
At Silobreaker, we understand the critical impact that geopolitical conflicts can have on your organization. That's why we're excited to introduce our latest Geopolitical Risk Briefs. Our research tea...
Shout out to Silobreaker for putting out *really* well-done weekly geopolitical briefs that provide substantial, timely, and relevant analysis without feeling like a chore to make time for.
#threatintel #infosec #cybersecurity
www.silobreaker.com/resources/re...
www.linkedin.com/newsletters/...
08.10.2025 15:13 β π 0 π 0 π¬ 0 π 0
βBut Captain,β I mutter to myself in the early morning quiet, βitβs only Tuesday.β
07.10.2025 11:38 β π 2 π 0 π¬ 0 π 0
APT Down - The North Korea Files
Click to read the article on phrack
This Phrack timeline of the Kimsuky dump is wiiiiiiild.
phrack.org/issues/72/7_...
(we did some deeper analysis of the dump, linked below, but wow...)
( dti.domaintools.com/inside-the-k... )
06.10.2025 14:53 β π 0 π 0 π¬ 0 π 0
DomainTools (@DomainTools@infosec.exchange)
New from DTI: A financially-motivated cluster of spoofed domains disguised as age 18+ social media content, government tax sites, consumer banking, and online gambling applications targeting Windows a...
If you need something to read this morning, we published research on Friday around an activity cluster targeting 18+ interests, especially gambling and porn.
Well. Also tax websites. Which I suppose is an adult interest. Sigh.
#threatintel #infosec
dti.domaintools.com/securitysnac...
06.10.2025 14:44 β π 0 π 0 π¬ 0 π 0
Prompt||GTFO Registration
Welcome to the Prompt Pit, where in a world of vibe slop, we're taking AI back from the marketers.
Next upcoming episode:
S02E01: Indiana Pit and the Raiders of the Lost Prompt
When:
25 September, 20...
Prompt||GTFO events have been extremely educational for me as an AI skeptic, as well as fun and entertaining. Worth checking them out.
Google Form for getting the invite (or applying to present):
docs.google.com/forms/d/e/1F...
LinkedIn post with more info:
www.linkedin.com/feed/update/...
06.10.2025 14:39 β π 0 π 0 π¬ 0 π 0
SecuritySnack: 18+E-Crime - DomainTools Investigations | DTI
Starting in September 2024, a financially motivated cluster of more than 80 spoofed domain names and lure websites began targeting users with fake applications and websites themed as government tax si...
New, from us, today: coordinated cluster of dozens of domains delivering infostealers or phishing credentials, targeting users of TikTok, YouTube, gambling apps, and more. Domain profiles and deeper IOCs provided.
#infosec #cybersecurity #threatintel
dti.domaintools.com/securitysnac...
03.10.2025 16:55 β π 0 π 0 π¬ 0 π 0
YouTube video by Radiohead - Topic
Everything In Its Right Place
Happy 25th birthday of Kid A to all those who celebrate (me) www.youtube.com/watch?v=NUnX...
02.10.2025 15:29 β π 44 π 5 π¬ 4 π 0
Fishing for Smishing: Understanding SMS Phishing Infrastructure and Strategies by Mining Public User Reports
-
UCL Discovery
UCL Discovery is UCL's open access repository, showcasing and providing access to UCL research outputs from all UCL disciplines.
Last paper I read from Agarwal & Vasek was great. New one:
Fishing for Smishing: Understanding SMS Phishing Infrastructure and Strategies by Mining Public User Reports
Agarwal, Sharad; Papasavva, Antonis; Suarez-Tangil, Guillermo; Vasek, Marie.
discovery.ucl.ac.uk/id/eprint/10...
02.10.2025 16:49 β π 0 π 0 π¬ 0 π 0
well played, M-W
01.10.2025 19:44 β π 1 π 0 π¬ 0 π 0
*checking inbox a little compulsively*
c'moooon, big money, no whammies, big money no whammies, BIGMONEYNOWHAMMIES
01.10.2025 19:43 β π 1 π 0 π¬ 0 π 0
Consumer Cyber Readiness Report
Today, @consumerreports.org @aspendigital.bsky.social @gca.bsky.social released the 4th Annual Consumer Cyber Readiness Report, co written by @gigastacey.bsky.social @jefflandale.bsky.social and I.
innovation.consumerreports.org/2025-Consume...
#CybersecurityAwarenessMonth 1/x
01.10.2025 17:26 β π 16 π 7 π¬ 1 π 1
Okay nerds, someone pointed me at BSidesSF's CFP, which is musical theatre-themed.
Get on it!
sessionize.com/bsidessf2026
30.09.2025 19:34 β π 1 π 0 π¬ 0 π 0
Hellllll yeah Infoblox!
30.09.2025 16:57 β π 0 π 0 π¬ 0 π 0
Cybersecurity Reading List - Week of 2025-09-29 - DomainTools Investigations | DTI
Commentary followed by links to cybersecurity articles that caught our interest internally.
Did that thing again where I reach deep into the DomainTools Investigations noosphere to mine our infosec egregores and present them on a monthly cadence.
or...y'know...drummed up a reading list of stuff that caught our attention.
#infosec #cybersecurity
dti.domaintools.com/cybersecurit...
29.09.2025 21:25 β π 2 π 1 π¬ 0 π 0
Vane Viper: RussiaβCyprus AdTech Nexus Delivering Malware
DNS analysis links Vane Viper's AdTech abuse to AdTech Holding and PropellerAds, delivering malware through fake software, APKs, and redirects.
In case you need more good weekend reading, make sure you've hit this Infoblox piece on Vane Viper.
It's absurdly well-done, weaving expert technical details with deep narrative to provide a thorough understanding of malicious adtech & related behavior.
blogs.infoblox.com/threat-intel...
26.09.2025 16:54 β π 0 π 0 π¬ 0 π 0
Tweet by @Joseph_Fasano_:| think about this student's email every day.
Below that is the screenshot of an email: "Professor Fasano, Like Hamlet, I have hesitated to act for reasons I cannot articulate even to myself. May I have an extension on the Hamlet paper?"
*stares in empathy and relatability*
26.09.2025 14:48 β π 2 π 0 π¬ 0 π 0
Workflow automation platform combining AI with business processes. Connect anything to everything. Fair-code, self-hostable.
CYBERWARCON is a one-day conference in Arlington, VA focused on the specter of destruction, disruption, and malicious influence on our society through cyber capabilities.
cyberwarcon.com
Cybersecurity reporter at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net
Journalist - cyber/natn'l security. Speaker. Georgetown adjunct prof. Author - COUNTDOWN TO ZERO DAY: Stuxnet and the Launch of the World's First Digital Weapon
Signal: KimZ.42
https://www.zetter-zeroday.com
Threat Intel, Threat Hunting and DFIR stuff. Weekly cyber quiz at www.socvel.com/quiz
ICS/OT security nerd in Scotland. Breaking computers in new ways since the age of 7. Often grumpy about the state of the world.
beer bottle castle enthusiast; too dead to bury.
tyrfingr-network.neocities.org
Information security, technology, policy/politics/philosophy/econ, society, fin.
Grad studies @uofdenver
Seeking solutions
Opinions are mine - not institutionally tied.
π» cybersecurity research at Consumer Reports
ποΈ independent investigative tech reporting
π£yaelwrites.com
βοΈ yael@yaelwrites.com
π₯#alwaysantifascist
π€opinions are mine, but you can have some
A new kind of private browser for iOS and iPadOS by @mysk.bsky.social
Isolated tabs β’ Antifingerprinting & Tracking Protection β’ 40+ Global Proxy Servers
https://apple.co/3G3W2o7
- [REDACTED]βs husband
- Bear's dad
- Recovering sysadmin
- Microsoft MVP (PowerShell/Identity)
- Forever student
- Open-Source Toolmaker
- Whisk(e)y fan
- College football fan (Go Blue!)
- Stuff: https://dotdot.horse
Distinguished Risk Pokemon will be my final form. Cthulhu cultist, lawful good. Yay Seattle! Opinions belong to my autocorrect, not my employer. /her
Also 0xdaeda1a@infosec.exchange
Reporter lady. MSNBC. Signal username: brandyzadrozny.53
Email if you must, from a non-work account: brandy.zadrozny@nbcuni.com
He sits motionless, like a spider in the center of its web, but that web has a thousand radiations, and he knows well every quiver of each of them. juliansanchez.com
CEO & Co-Founder at Knostic, CISO-in-Residence for AI at Cloud Security Alliance. Former Founder @Cymmetria (acquired). Host at Prompt||GTFO. Threat hunter, scifi geek, dance teacher. Opinions my own.
21st century digital attorney. cybersecurity & data counsel, privacy & compliance, FOSS, sometimes litigation; probably not your lawyer.
~~β~~
A global leader for internet #intel that enables security practitioners to proactively defend their organization in a constantly evolving threat landscape.
Father, husband, Swedish and cyber. Oh man, all the things cyber but mostly threat Intelligence. Dabble with Python. In the cyber field as a professional since 2001 [β¦]
π bridged from β https://swecyb.com/@nopatience, follow @ap.brid.gy to interact
The App for Connecting Open Social Web
Mastodon, Bluesky, Nostr, Threads in ONE app, in ONE feed β¨
https://openvibe.social