Detecting OpenClaw using advanced posture checks
Personal AI assistants like OpenClaw present interesting new challenges for security teams. Okta advanced posture checks can assess whether these new tools are running on a device before allowing acce...
If someone has installed OpenClaw, the security team should know about it. Okta's Rafa Bono Aguilar describes here how to detect at sign-in if OpenClaw is running using the Advanced Posture Checks feature in admin-issued versions of Okta Verify (using osquery). www.okta.com/blog/threat-... #infosec
11.02.2026 22:17 β π 2 π 0 π¬ 0 π 0
Interesting prediction from Recorded Future: "2026 will be the first year the number of new ransomware actors outside Russia exceeds those emerging within it", which reflects "how dramatically the global ransomware ecosystem has expanded." #infosec
09.02.2026 05:34 β π 1 π 1 π¬ 0 π 0
Detecting and Monitoring OpenClaw (clawdbot, moltbot)
Detecting and Monitoring OpenClaw (clawdbot, moltbot), Author: Johannes Ullrich
An AI security and governance company, Knostic, has written some scripts to detect OpenClaw and also monitor what it's up to. Via the SANS blog: isc.sans.edu/diary/rss/32...
05.02.2026 10:00 β π 1 π 1 π¬ 0 π 0
No - the reason wasn't in that statement.
05.02.2026 08:23 β π 1 π 0 π¬ 1 π 0
Spotlighting The World Factbook as We Bid a Fond Farewell - CIA
The CIA announced it will no longer maintain the CIA World Factbook. Fun fact about the factbook: CIA officers contributed personal travel photos for it, which under U.S. law are copyright free: www.cia.gov/stories/stor...
05.02.2026 05:44 β π 12 π 2 π¬ 1 π 4
Agents run amok: Identity lessons from Moltbookβs AI experiment
AI "butler" OpenClaw and an agentic AI social network, Moltbook, are here. What are the identity lessons that can be drawn from AI agents running amok? Okta's view here: www.okta.com/newsroom/art...
05.02.2026 05:40 β π 1 π 0 π¬ 0 π 0
Nope! π
25.01.2026 11:09 β π 0 π 0 π¬ 0 π 0
He is believed to be a long-time ransomware actor. Nefedov's real-world identity was unwound after he was picked up on an Interpol notice in Armenia in 2024 but due to various court shenanigans managed to get back to Russia.
18.01.2026 20:33 β π 1 π 1 π¬ 0 π 0
The Germans have added Russian man Oleg Nefedov to its Most Wanted list. Nefedov is alleged to be the leader of the Black Basta ransomware group and went by monikers including tramp, kurva, gg and Washingt0n. #infosec www.bka.de/DE/IhreSiche...
18.01.2026 20:33 β π 2 π 2 π¬ 1 π 0
106.57 MB file on MEGA
Latest episode: mega.nz/file/9I8gxJz...
18.12.2025 11:42 β π 2 π 0 π¬ 0 π 0
Malicious hackers often get caught. But here's the story of a Russian man involved in cybercrime from the Angler exploit kit through today who slipped away. Audio preview of @intel471.bsky.social's Cybercrime Exposed podcastπ. Episode on Spotify and Apple. #infosec www.intel471.com/resources/po...
17.12.2025 00:54 β π 2 π 1 π¬ 1 π 0
Online Safety Act: Age assurance industry must be regulated
Open Rights Group has written to the Secretary of State for Science, Innovation and Technology, Liz Kendall MP calling for regulation of age assurance providers operating under the Online Safety Act.
The age verification industry is booming with the new regulations in the U.K. and Australia. In the UK, the @openrightsgroup.org is calling for stronger security standards since online platforms may opt for the cheapest, less vigilant vendors, www.openrightsgroup.org/press-releas... #infosec
13.12.2025 23:51 β π 4 π 1 π¬ 1 π 0
The Last Video Rental Store Is Your Public Library
Audio-visual librarians are quietly amassing large physical media collections amid the IP disputes threatening select availability.
Hats off to @404media.co for creating a public library beat. I worked at two public libraries in the past, and access to information has never been more fraught and delicate than now. π This latest one about AV collections from @clurrese.bsky.social a great read: www.404media.co/the-last-vid...
05.12.2025 22:41 β π 17 π 14 π¬ 0 π 1
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
Developer attempts to replicate "Liquid Glass" in CSS, and once finished realizes what she'd actually created is an exploit for a fundamental, previously unknown, and rather serious browser vulnerability
lyra.horse/blog/2025/12...
"CSS hack accidentally becomes regular hack"
05.12.2025 02:03 β π 2044 π 585 π¬ 25 π 38
Pics now please.
04.12.2025 03:18 β π 0 π 0 π¬ 0 π 0
I find that if I have to rewrite something for one reason or another it usually reads better.
03.12.2025 05:34 β π 0 π 0 π¬ 0 π 0
π€£
14.11.2025 19:46 β π 1 π 0 π¬ 0 π 0
Anthropic's AI cyberespionage report feels as odd as the last one. Just 13 pages, it has none of the traditional components of a usual threat intel report (IoCs, payload hashes, etc.) and it seems to bury the lead re: technical sophistication. I wonder if a target will come forward. #infosec
14.11.2025 07:40 β π 30 π 17 π¬ 1 π 0
Ugh! Did you have your email displayed?
12.11.2025 10:04 β π 0 π 0 π¬ 1 π 0
Probably should have tagged @christogrozev.bsky.social in this. Is your research into this going to become public soon?
06.11.2025 23:21 β π 6 π 0 π¬ 1 π 0
I find it highly improbable as well. But then again, if you'd briefly told me about any of the crazy-as-hell spy stories @christogrozev.bsky.social has done, I would have said the same thing until seeing his meticulous reporting. Maybe that will be forthcoming?
06.11.2025 23:20 β π 2 π 0 π¬ 2 π 0
Famed Russian spy hunter Christo Grozev claimed on this podcast four months ago that North Korea hacked the Democratic National Committee in 2016 and passed the info to Russia, which in exchange divulged access to Bangladesh Bank. π€ #infosec Passage at 13m 31s:
www.youtube.com/watch?v=dimh...
06.11.2025 21:11 β π 16 π 9 π¬ 3 π 9
πππ
05.11.2025 23:15 β π 0 π 0 π¬ 0 π 0
Accused ALPHV/BlackCat ransomware affiliate Ryan Goldberg made US$214,000 a year working in incident response for Sygnia but told the FBI he was in debt as the reason for getting involved in ransomware, according to court documents. He initially denied involvement in the attacks. #infosec
05.11.2025 23:09 β π 0 π 1 π¬ 1 π 0
Winnie wanted to lay on the keyboard so I guess this is the second-best position. π
03.11.2025 23:30 β π 4 π 1 π¬ 0 π 0
Independent AI researcher, creator of datasette.io and llm.datasette.io, building open source tools for data journalism, writing about a lot of stuff at https://simonwillison.net/
tracking only some of the many disasters happening in crypto, defi, NFTs, and other blockchain-based projects since 2021 β’ created by @molly.wiki
web3isgoinggreat.com
Melbourne, Australia π¦πΊ based software developer. And hobby photographer.
Hacker, Rapper, Developer, dade.
https://0xda.de
Cybersecurity & Information Technology Leader | Former TV News Guy
Writer, actor, audiobook narrator, notorious tryhard
DC-based humor writer and public health data scientist; writing @ the New Yorker and other outlets. Health data nerd. PhD in public health. Writing at https://www.aliruth.com/
β―οΈ Tech & Arts Fusionist
ποΈ Music-Producing Entity
π» Software Imagineer
π https://linktr.ee/zenibako
Domina Nostra Perpetuae Desperationis
NΓ©e Half-Blind Trust/Grandmaβs High Again. Please no DMs.
https://5calls.org/
*not all
Academic in Security Studies | PhD in National and International Security Strategies (Turkish War Colleges) | MA in European Studies (UBC) | BA in Public Administration (Istanbul University, Turkey) | DiyarbakΔ±r native & Galatasaray Fan.
Cybersecurity | Saxophon and Synth
Are you shittin me?!?!! No, but you'll print that and I'll probably be investigated
Posts mine, but if you see something you think you can use to get me in trouble I did it on my own time and my own device, so good luck
writer β’ narrative designer β’ lesbian β’ nyc
Partner at Blackthorne Consulting; Former Red Team Director at GE and US Navy; Advisory Board member; US Navy Veteran.β¨β¨Keynote speaker; featured in Tribe of Hackers - Red Team (published by Wiley)β¨β¨My opinions are my own. Links are not endorsements.
Rusty Gopher π¦πΉ. Part-time OSS dev. Former TruffleHog maintainer. Security-ish π. Builder always. Amazon by day, allegedly serving 93% of all bytes.
infosec! personal account. views are that of rustic australian countryside. nothing is an endorsement. everything is awkward.
Engineer turned programmer. I try to make useful applications, such as Iceberg Accounting Suite, a Python project that gives users a set of books and basic invoicing. Check out my projects, you may find something helpful
Tech journalist and author, who increasingly also talks on TV and radio. Interested in the sparks that happen when the online and offline worlds collide
@stokel on the other place. Buy my book: How AI Ate the World!
Repeat founder, investor, hacker. Advisor for Exodus Intelligence and Mozilla's 0din.ai. Previously founded the Zero Day Initiative and OpenRCE. NYC born, Austin transplant.