Spanky
@spankowitz.bsky.social
📤 130
📥 696
📝 39
I like threat intel, purple team, and turtles.
reposted by
Spanky
CYBERWARCON
6 days ago
Mark your calendars!
0
19
11
reposted by
Spanky
IFIN
4 days ago
A reminder that we have a MISP feed!
misp.ifin.network/feed
(`/manifest.json` for validation)
loading . . .
https://misp.ifin.network/feed
0
3
1
reposted by
Spanky
Joe Slowik
about 2 months ago
I will hold an online session of the Paralus LLC Applied
#CyberThreatIntelligence
course from 27-31 July, 1400-1600 US Eastern/2000-2200 Central European time. Focused, to the point training, two hours per day for five days. Register your interest at the following form:
forms.gle/M1LgQTomJGek...
loading . . .
Paralus LLC: Applied Threat Intelligence
Hello and thank you for your interest in a workshop focusing on Applied Threat Intelligence! Scheduling: 27-31 July 2026 (Five Days) 1400-1600 US Eastern/2000-2200 Central European (Two Hours/Day) C...
https://forms.gle/M1LgQTomJGekRaq76
1
13
11
reposted by
Spanky
Jason Koebler
14 days ago
A developer made a browser extension called "Knockoff" that shows what a wasteland Amazon truly is by filtering out brands like "GODONLIF" "EHEYCIGA," ROTTOGOON," and sponsored products. Useful and illustrative even if you don't use Amazon
www.404media.co/knockoff-bro...
loading . . .
'Knockoff' Browser Extension Hides Sketchy Brands on Amazon
"Sorry to brands like WNPETHOME, EHEYCIGA, YXYL, LU&MN, JOYIN, TOMY, GODONLIF, YOOJEE, LINGTENG, LANEIGE, VISCOO, BIODANCE, COOFANDY, BALENNZ, TOSY, and LUENX."
https://www.404media.co/knockoff-browser-extension-hides-sketchy-brands-on-amazon/
34
1255
380
reposted by
Spanky
Molly White
21 days ago
It does not fill me with optimism about the general quality or completeness of this disclosure that it gives the wrong name for the firm via which Trump made $635 million last year.
add a skeleton here at some point
2
319
58
No Three Buddy Problem this week. My disappointment is immeasurable. What am I supposed to listen to on my dog walkies?!?? Oh right, Between 2 Nerds. 🙌
23 days ago
0
1
0
www.nytimes.com/2026/06/26/u...
loading . . .
John Bolton, Former Trump Adviser, Pleads Guilty in Classified Information Case
https://www.nytimes.com/2026/06/26/us/politics/john-bolton-trump-classified-guilty-plea.html
26 days ago
0
0
0
reposted by
Spanky
The Citizen Lab
27 days ago
1/ NEW RESEARCH: We find that Russian authorities used Cellebrite to gain access to activist Andrey Pivovarov’s phone. Full brief:
citizenlab.ca/research/rus...
loading . . .
Russia Breaks Into Human Rights Activist's Phone With Cellebrite - The Citizen Lab
We analyzed Russian activist Andrey Pivovarov’s phone, finding that Russian authorities used forensic extraction tools made by Cellebrite to gain access to his device. A document prepared by Russian a...
https://citizenlab.ca/research/russia-breaks-into-human-rights-activists-phone-with-cellebrite/
1
17
16
reposted by
Spanky
CNN
29 days ago
A newly discovered spider species from Australia uses its silk to craft a spring-loaded, cone-shaped death trap, which catapults its prey into the spider’s main web.
https://cnn.it/4w3n6Ip
loading . . .
4
81
21
reposted by
Spanky
JHunt🛡️
29 days ago
Thanks
@halvarflake.bsky.social
-- it's so good / must read (and it's not even finished yet!)
add a skeleton here at some point
0
4
2
reposted by
Spanky
BeijingPalmer
about 1 month ago
iran has closed the reflecting pool.
39
3135
476
reposted by
Spanky
Krista Elliott
about 1 month ago
AI may have inherited the em-dash addiction from hordes of writers -- but it can pry them from our cold, dead hands.
add a skeleton here at some point
0
18
3
@sleuthcon.bsky.social
loading . . .
Wolf Of Wall Street: Lets Gooo!
ALT: Wolf Of Wall Street: Lets Gooo!
https://static.klipy.com/ii/935d7ab9d8c6202580a668421940ec81/79/4c/Doepr5i1.gif?hh=281&ww=498&mp4=MVdy5MBV&webm=4Kxz4QYh4QhlaEmLnJg
about 2 months ago
0
0
1
DAMN STRAIGHT
add a skeleton here at some point
about 2 months ago
0
3
0
reposted by
Spanky
Ryan Naraine
about 2 months ago
NEW POD UP: Microsoft threatens legal action against researchers who drop zero-days. We debate whether it’s a fair line against extortion, or amateur-hour PR from a company that already torched its own research community?
#threebuddyproblem
youtu.be/E5rIJ9nGOUo
loading . . .
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited
YouTube video by Three Buddy Problem
https://youtu.be/E5rIJ9nGOUo
1
5
7
reposted by
Spanky
JHunt🛡️
about 2 months ago
www.nytimes.com/2026/05/22/u...
loading . . .
White House Approves $9 Billion for Spy Agencies to Catch Up on A.I.
https://www.nytimes.com/2026/05/22/us/politics/spy-agencies-ai-chips-shortage.html?unlocked_article_code=1.kVA.goMh.tuaCn9YTwMAr&smid=nytcore-ios-share
0
2
1
reposted by
Spanky
The Register
2 months ago
Google explains how it will infuse ads into AI answers
loading . . .
Google explains how it will infuse ads into AI answers
Just like in The Truman Show
https://www.theregister.com/ai-ml/2026/05/21/google-explains-how-it-will-infuse-ads-into-ai-answers/5244586?utm_source=dlvr.it&utm_medium=bluesky
1
6
8
reposted by
Spanky
Paresh Dave
2 months ago
www.wired.com/story/spacex...
loading . . .
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
The long-awaited documents SpaceX filed with US regulators Wednesday included details about a lucrative deal to lend GPUs to a major AI rival.
https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
1
35
18
reposted by
Spanky
Ryan Naraine
2 months ago
NEW POD UP! We discuss the disappearing art of Windows APT paleontology, the absence of complex malware documentation, and why so much threat-intel research has slipped behind paywalls and into private rooms. - Spotify
open.spotify.com/episode/0eh4...
- Apple
podcasts.apple.com/us/podcast/t...
1
8
6
reposted by
Spanky
2 months ago
www.faz.net/premium/digi...
I wrote a FAZ guest article.
loading . . .
Thomas Dullien zu Anthropics Mythos: Software war nie auf perfekte Sicherheit ausgelegt - das rächt sich
Schwachstellen in Computern wurden lange hingenommen. Denn sie auszunutzen war technisch komplex und teuer. KIs ändern das nun. Damit zwingen sie uns, Altlasten schneller anzugehen.
https://www.faz.net/premium/digitalwirtschaft/thomas-dullien-zu-anthropics-mythos-software-war-nie-auf-perfekte-sicherheit-ausgelegt-das-raecht-sich-accg-200822228.html
3
31
16
reposted by
Spanky
Lorenzo Franceschi-Bicchierai
2 months ago
NEW: Google is rolling out a new feature for Android called Intrusion Logging, designed specifically to help researchers investigate attacks done with spyware and forensic tools. Amnesty says this is “a fundamental shift in the amount and quality of forensic data available on Android devices.”
loading . . .
Google launches new Android security feature to help uncover spyware attacks | TechCrunch
Intrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement...
https://techcrunch.com/2026/05/12/google-launches-new-android-security-feature-to-help-uncover-spyware-attacks/
4
59
29
eol.jsc.nasa.gov/SearchPhotos...
loading . . .
https://eol.jsc.nasa.gov/SearchPhotos/ShowQueryResults-Lightcycle.pl?results=Artemis_Artemis2_all
2 months ago
0
0
0
reposted by
Spanky
Ryan Naraine
3 months ago
- YouTube
youtu.be/jIr6QdgUodU
- Spotify (with video)
open.spotify.com/episode/4zDJ...
- Apple Podcasts
podcasts.apple.com/us/podcast/c...
- Transcript
docs.google.com/document/d/1...
loading . . .
Cracking the Fast16 sabotage malware mystery
YouTube video by Three Buddy Problem
https://youtu.be/jIr6QdgUodU
0
4
3
reposted by
Spanky
SpecterOps
3 months ago
Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection.
@podalirius.bsky.social
found two command injection vulns hiding in Windows Explorer's built-in context menus, both that went undetected for 9 years.
https://ghst.ly/42ImlI6
loading . . .
Shift Happens - Uncovering Two Built-in Command Injections in Windows Context Menus
Two long-standing Windows Explorer vulnerabilities lets attackers execute arbitrary PowerShell commands using crafted folder names, affecting Windows 10 and 11 since 2017.
https://specterops.io/blog/2026/05/07/shift-happens-uncovering-two-built-in-command-injections-in-windows-context-menus/
0
4
3
reposted by
Spanky
The Vertex Project
3 months ago
Has Cyber Threat Intelligence evolved or just outgrown its own definition? In Episode 1, Vertex co-founders
@invisig0th.bsky.social
& John "whippit" Rodgers rethink what CTI should be. Listen:
www.youtube.com/watch?v=DdeG...
loading . . .
Episode 1: There’s CTI and There’s Intelligence
YouTube video by The Vertex Project | Synapse Enterprise
https://www.youtube.com/watch?v=DdeGcZiS59s&list=PL-LtwigHzUuT5DabTooznxx4Ku-NyTyOZ
0
10
3
reposted by
Spanky
Botty.bot
3 months ago
Pleased to share a simple new GitHub Repo called Awesome-Ransomware, following the genre of ‘awesome-x’ for GitHub repos. Please contribute if you have a resource specifically for any type of ransomware tracking, Pull R… — from @BushidoToken (
https://x.com/BushidoToken/status/2051607175739388191
)
loading . . .
GitHub - BushidoUK/Awesome-Ransomware: A curated list of Ransomware resources
https://t.co/baie3H9tgh
0
1
1
reposted by
Spanky
NPR
3 months ago
Award winners include authors Daniel Kraus, Jill Lepore and Yiyun Li, opinion writer M. Gessen and staffers and contributors at The Washington Post, Reuters and AP.
n.pr/4f7k5S2
loading . . .
Here are the 2026 Pulitzer Prize winners
Award winners include authors Daniel Kraus, Jill Lepore and Yiyun Li, opinion writer M. Gessen and staffers and contributors at The Washington Post, Reuters and AP.
https://n.pr/4f7k5S2
3
215
69
reposted by
Spanky
JHunt🛡️
3 months ago
I made a local 'tweetdeck' client for Bluesky:
https://github.com/jhuntinfosec/bluedeck
Enjoy!
1
2
2
explore.alas.aws.amazon.com/CVE-2026-314...
add a skeleton here at some point
3 months ago
0
1
0
reposted by
Spanky
Ryan Naraine
3 months ago
Mark Dowd on vetting customers for highly sensitive projects
add a skeleton here at some point
0
3
4
reposted by
Spanky
Antisyphon Training - Powered by BHIS
3 months ago
We’re excited to have David as a keynote speaker at our free
#ThreatHunting
Summit! Join David as he invites us to re‑examine the role of the human in threat hunting -
www.antisyphontraining.com/event/threat...
add a skeleton here at some point
0
1
2
blog.mozilla.org/en/firefox/a...
loading . . .
The zero-days are numbered | The Mozilla Blog
Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser.
https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/
3 months ago
0
1
0
reposted by
Spanky
Ryan Naraine
3 months ago
NEW PROBLEM UP! 🚨 We discuss a mysterious, VM-obfuscated backdoor that lived undetected on a single U.K. machine for a year before disappearing, finding clues pointing to an elite-level APT intrusion that still evades broader industry coverage. WATCH on YouTube
www.youtube.com/watch?v=mSD9...
loading . . .
The Angry Spark APT Mystery: One Victim, Zero Attribution
YouTube video by Three Buddy Problem
https://www.youtube.com/watch?v=mSD9ewySvvU
1
10
6
reposted by
Spanky
Botty.bot
3 months ago
#agentmentoring — from @JohnHultquist (
https://x.com/JohnHultquist/status/2042379534180229147
)
0
1
1
reposted by
Spanky
The Atlantic
3 months ago
On Radio Atlantic,
@radiofreetom.bsky.social
and Nancy A. Youssef explain the state of the war in Iran—and how no deal can undo the damage of Trump’s words.
loading . . .
Trump Is Wishcasting Victory in Iran
The president went from threatening that “a whole civilization will die” to claiming a “total and complete victory.” What does the already shaky cease-fire mean as he tries to steer his way out of the war?
https://bit.ly/3PZx7qv
11
174
65
reposted by
Spanky
GreyNoise
4 months ago
New GreyNoise Report: 39% of unique IPs targeting the edge come from home internet connections. They are everywhere, briefly — 78% appear at most twice before rotating. The rotation rate makes feed-based IP reputation structurally ineffective against this traffic. 🔗
www.greynoise.io/resources/in...
loading . . .
The Invisible Army: Residential Proxy Abuse in Internet-Scale Attack Traffic
GreyNoise analyzed 4 billion sessions to expose residential proxy abuse, behavioral patterns, why IP reputation fails, and what defenders can do about it.
https://www.greynoise.io/resources/invisible-army-residential-proxy-abuse-report
0
4
3
reposted by
Spanky
Jimmy Wylie
4 months ago
TIL FLARE distributes educational content for free on GitHub.
github.com/mandiant/fla...
loading . . .
GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team · GitHub
Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub
https://github.com/mandiant/flare-learning-hub
0
4
3
reposted by
Spanky
WIRED
4 months ago
Tech giants like Apple, Google, and Microsoft are among those on a target list released by Iran’s Islamic Revolutionary Guard Corps.
www.wired.com/story/iran-t...
loading . . .
Iran Threatens to Start Attacking Major US Tech Firms on April 1
Tech giants like Apple, Google, and Microsoft are among those on a target list released by Iran’s Islamic Revolutionary Guard Corps.
https://www.wired.com/story/iran-threatens-to-start-attacking-major-us-tech-firms-on-april-1/
47
226
135
reposted by
Spanky
vx-underground (automated mirror)
4 months ago
ShinyHunters is ransoming ... HALLMARK CARDS Those fucking shitty birthday cards you pick up at the drug store ARE BEING HELD RANSOMWARE WHO RANSOMS BIRTHDAY CARDS (info via @AlvieriD)
1
16
5
reposted by
Spanky
Punk Rock History
4 months ago
42 years ago 'Minor Threat' aka 'First Two Seven' Inches is a compilation album by the American hardcorepunk band Minor Threat, released in March 1984 and consists of the first two extended plays 'Minor Threat' and 'In My Eyes' .
#punk
#punkrock
#minorthreat
#punkrockhistory
3
162
40
Global warming was the plan all along!!!
add a skeleton here at some point
4 months ago
0
1
0
reposted by
Spanky
Ryan Naraine
5 months ago
🧨 🚨 NEW POD UP! (presented by
@thinkstcanary.canary.tools
) - The Coruna iOS exploit kit, the connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use
@craiu.bsky.social
@jags.bsky.social
LISTEN everwhere 👇
pod.link/1414525622
1
5
4
reposted by
Spanky
Beau Woods
5 months ago
These things have always been true: 1. The ability to generate buggy code has never been greater. 2. The ability to find bugs in code has never been greater. 3. The ability to fix bugs in code has never been greater. 4. Many, many more people want to do 1 or 2 than 3. Now scale this with AI.
1
12
8
reposted by
Spanky
Silas Cutler
5 months ago
Our blog at @Censys now has a proper RSS feed
https://censys.com/feed/
(cc: @Feedly
#GoogleReader
)
1
9
3
reposted by
Spanky
Kelsey Hightower
5 months ago
Why learn to code when you can use an LLM and pay a subscription fee for the rest of your life.
18
315
75
reposted by
Spanky
Ron Deibert
5 months ago
NEW
@citizenlab.ca
report: Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi
citizenlab.ca/research/cel...
loading . . .
Not Safe for Politics: Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi - The Citizen Lab
Following the widely-condemned arrest in July 2025 of prominent Kenyan opposition voice Boniface Mwangi, the Citizen Lab analyzed artefacts from devices seized during the arrest. We found that Cellebr...
https://citizenlab.ca/research/cellebrite-used-on-kenyan-activist-and-politician-boniface-mwangi/
2
25
19
Making my GREM index like...
5 months ago
0
2
0
These dudes are awesome! Highly recommend their training if you get the opportunity.
add a skeleton here at some point
5 months ago
1
1
1
reposted by
Spanky
Barry Dorrans
5 months ago
Early career pen tester wanted to break some of azures specialist clouds.
#infosecJobs
loading . . .
Penetration Tester | Microsoft Careers
Penetration Testing Identify security vulnerabilities and variants across critical cloud services. Perform source code reviews, dynamic analysis, and operational security assessments. Validate softwar...
https://apply.careers.microsoft.com/careers/job/1970393556748197
0
6
4
reposted by
Spanky
Teri Radichel
5 months ago
Non-Deterministic: The most important word you need to understand about AI 🤖
teriradichel.substack.com/p/non-determ...
loading . . .
Non-Deterministic
The most important word you need to understand about AI
https://teriradichel.substack.com/p/non-deterministic
0
2
2
Load more
feeds!
log in