Dave Aitel
@daveaitel.bsky.social
📤 1096
📥 467
📝 294
reposted by
Dave Aitel
Matthew Stiegler
about 16 hours ago
Let me let you in on a secret, most federal judges don't believe that other federal judges higher up the food chain are one bit smarter, or any more faithful to the law, than they are. And yet, by and large, they fully accept the legitimacy of review and potential reversal of their decisions. Why?
3
125
38
reposted by
Dave Aitel
InfoSec
about 16 hours ago
Iran-Linked Hackers Target Europe With New Malware
loading . . .
Iran-Linked Hackers Target Europe With New Malware
"Nimbus Manticore" is back at it, this time with improved variants of its flagship malware and targets that are outside its usual focus area.
https://www.darkreading.com/cyberattacks-data-breaches/iran-linked-hackers-europe-new-malware
0
19
7
reposted by
Dave Aitel
TechCrunch
about 21 hours ago
OpenAI and Nvidia agreed to deploy 10 gigawatts worth AI chips to power the next generation of ChatGPT.
loading . . .
Nvidia plans to invest up to $100B in OpenAI | TechCrunch
OpenAI and Nvidia agreed to deploy 10 gigawatts worth AI chips to power the next generation of ChatGPT.
https://techcrunch.com/2025/09/22/nvidia-plans-to-invest-up-to-100b-in-openai/
4
9
7
reposted by
Dave Aitel
Zack Whittaker
about 21 hours ago
For TechCrunch, I wrote about Unit 221B, a cybersecurity company that's recently made a name for itself by tracking today's top English-speaking hacking groups, including Scattered Spider, and helping to disrupt their operations. Now the company has raised $5 million to focus on the threat.
loading . . .
Unit 221B raises $5 million to help track and disrupt today’s top hacking groups | TechCrunch
The seed funding raise will help Unit 221B expand its threat intelligence platform, which tracks the English-speaking youth hacking phenomenon.
https://techcrunch.com/2025/09/22/unit-221b-raises-5-million-to-help-track-and-disrupt-todays-top-hacking-groups/
1
26
13
reposted by
Dave Aitel
Margi Murphy
4 days ago
For more than a year I’ve spoken with Scattered Spider “caller” Noah Urban from a Florida jail. I wanted to know how they chose victims, their methods and how Noah became entangled in a virtually and physically violent world. We’re publishing his story today:
www.bloomberg.com/news/feature...
loading . . .
‘I Was a Weird Kid’: Jailhouse Confessions of a Teen Hacker
Noah Urban’s role in the notorious Scattered Spider gang was talking people into unwittingly giving criminals access to sensitive computer systems.
https://www.bloomberg.com/news/features/2025-09-19/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1ODI4MTkwMSwiZXhwIjoxNzU4ODg2NzAxLCJhcnRpY2xlSWQiOiJUMlUyTVNHUTFZWVUwMCIsImJjb25uZWN0SWQiOiIwNUVDNUJDRTNFOTA0ODQ0OThBOTc5MkM0MDIwNkUzNyJ9.hZarEq-EdSn6zXTfZnJEI870hLN66BhFQhLN7kqmKds
2
32
21
reposted by
Dave Aitel
Eric Geller
about 22 hours ago
Don't get too excited about AI's ability to find software vulnerabilities,
@rgblights.bsky.social
said today — we'll never be able to keep up w/ the patching, esp. for unsupported & poorly maintained software. My report from Google's Cyber Defense Summit:
www.cybersecuritydive.com/news/ai-vuln...
1
12
4
reposted by
Dave Aitel
Matt Burgess (WIRED)
1 day ago
NEW from me: It's been three weeks since JLR shut down factories after a cyberattack—losing tens of millions as a result. We know little about the specifics of that hack, but the shutdown is on the verge of creating a full-blown crisis for hundreds of JLR suppliers, who are laying off staff
loading . . .
A Cyberattack on Jaguar Land Rover Is Causing a Supply Chain Disaster
The UK-based automaker has been forced to stop vehicle production as a result of the attack—costing JLR tens of millions of dollars and forcing its parts suppliers to lay off workers.
https://www.wired.com/story/jlr-jaguar-land-rover-cyberattack-supply-chain-disaster/
2
103
55
reposted by
Dave Aitel
Daniel Gordon
4 days ago
This is absolute CTI bait, great job ESET
www.welivesecurity.com/en/eset-rese...
loading . . .
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/
0
4
1
reposted by
Dave Aitel
Chris Wysopal
4 days ago
Teen hackers aren’t villains-in-waiting, they’re untapped defenders. We can intercept talent early, show real career paths, and turn curiosity into cyber defense. My take on building ethical on-ramps for
#cybersecurity
www.forbes.com/councils/for...
loading . . .
Intercepting Talent: Turning Hackers Into Cyber Defenders
Teen hackers are reshaping cybersecurity. Channeling their curiosity into ethical hacking could transform risks into the next wave of defenders.
https://www.forbes.com/councils/forbestechcouncil/2025/09/19/intercepting-talent-turning-hackers-into-cyber-defenders/
1
23
10
reposted by
Dave Aitel
puppy
4 days ago
Hey,
#ruby
folks! I've been one of the
#RubyGems
maintainers for the last decade. Ruby Central has forcefully taken control of the RubyGems organization on GitHub, the `rubygems-update` and `bundler` gems on rubygems[.]org, and more. You can read the details here:
pup-e.com/goodbye-ruby...
loading . . .
RubyGems.org | your community gem host
https://rubygems.org
15
293
193
www.bloomberg.com/news/feature...
great article
loading . . .
‘I Was a Weird Kid’: Jailhouse Confessions of a Teen Hacker
Noah Urban’s role in the notorious Scattered Spider gang was talking people into unwittingly giving criminals access to sensitive computer systems.
https://www.bloomberg.com/news/features/2025-09-19/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions
4 days ago
0
2
0
reposted by
Dave Aitel
Tim Krief
7 days ago
loading . . .
80
10135
4535
reposted by
Dave Aitel
El Jefe De Security
6 days ago
filing this under the, "this is why we can't have nice things" folder...
add a skeleton here at some point
5
18
8
reposted by
Dave Aitel
Infosecsie (ツンデレ)
6 days ago
I was homeless as a teenager and, let me tell you, it can happen to most Americans faster than they’d like to believe.
add a skeleton here at some point
1
14
3
reposted by
Dave Aitel
Joseph Cox
8 days ago
New from 404 Media: airlines are selling *5 billion* ticketing records to the government for warrantless searching, per new docs we obtained. ARC is a data broker owned by United, American, Delta, etc. Then sells peoples' travel info to ICE, Secret Service, FBI etc
www.404media.co/airlines-sel...
loading . . .
Airlines Sell 5 Billion Plane Ticket Records to the Government For Warrantless Searching
New documents obtained by 404 Media show how a data broker owned by American Airlines, United, Delta, and many other airlines is selling masses of passenger data to the U.S. government.
https://www.404media.co/airlines-sell-5-billion-plane-ticket-records-to-the-government-for-warrantless-searching/
96
2743
2081
reposted by
Dave Aitel
Ele Willoughby
8 days ago
Day 15
#SciArtSeptember
prompt spawn. I’m sharing my portrait of self-taught trail-blazing Irish
#marineBiologist
Maude Delap (1866 – 1953), 1st to successfully breed jellyfish in captivity & document their full lifecycle. 🧪🐡👩🏼🔬
#histsci
She is surrounded by blue jellyfish (Cyanea lamarckii) life 🧵
2
87
25
reposted by
Dave Aitel
Robert Graham
8 days ago
Japanese 7-11s are a much better experience than American convenience stores, but maybe that's because they sell better stuff, like Pocari Sweat and Calpis.
add a skeleton here at some point
1
5
1
reposted by
Dave Aitel
Sung Kim
9 days ago
Post-training 101: A hitchhiker's guide into LLM post-training by Han Fang and Karthik Abinav Sankararaman
tokens-for-thoughts.notion.site/post-trainin...
loading . . .
Post-training 101 | Tokens for Thoughts
A hitchhiker's guide into LLM post-training, by Han Fang and Karthik A Sankararaman
https://tokens-for-thoughts.notion.site/post-training-101
2
27
8
reposted by
Dave Aitel
Greg Otto
11 days ago
DHS failed to effectively implement a critical retention incentive program for cyber talent, according to a report from the agency’s inspector general, which found that federal funds meant for the Cybersecurity and Infrastructure Security Agency were used incorrectly.
fedscoop.com/cisa-cyber-i...
loading . . .
DHS watchdog finds mismanagement in critical cyber talent program
CISA was paying employees without mission-critical cybersecurity backgrounds as part of a program for retaining cyber talent.
https://fedscoop.com/cisa-cyber-incentive-program-dhs-inspector-general-report/
0
3
1
reposted by
Dave Aitel
Ben Recht
12 days ago
This new center strikes the right tone in approaching the AI alignment problem.
alignmentalignment.ai
loading . . .
Center for the Alignment of AI Alignment Centers
We align the aligners
https://alignmentalignment.ai/
4
59
19
reposted by
Dave Aitel
Allan “Ransomware Sommelier” Liska
12 days ago
Great article by
@kimzetter.bsky.social
about Mandiant and APT1. The behind-the-scenes look at how the report came together and the assessment of what Mandiant was willing to expose in order to publish the report. Well done...
loading . . .
How the Infamous APT 1 Report Exposing China’s PLA Hackers Came to Be
This is the first in a series of pieces I’ll publish that take an in-depth look at significant events, people and cases in security and surveillance from the past. If there’s something you think would...
https://www.zetter-zeroday.com/how-the-infamous-apt-1-report-exposing-chinas-pla-hackers-came-to-be/?ref=zero-day-newsletter
1
14
7
reposted by
Dave Aitel
404 Media
13 days ago
Scientists have discovered a gnarly undocumented reproductive strategy: Ant queens that produce offspring from two entirely different species by cloning the “alien genome” of males from another lineage. This behavior has been dubbed “xenoparity,” 🔗
www.404media.co/the-biologic...
loading . . .
The Biological Rulebook Was Just Rewritten—by Ants
Iberian harvester ant queens clone males of a different species in a never-before-seen case of reproduction and domestication.
https://www.404media.co/the-biological-rulebook-was-just-rewritten-by-ants/
6
142
44
reposted by
Dave Aitel
Bree (Freeze Drying Era)
13 days ago
Doctors ignored my reports if pain for years. In high school my mom would have to come pick me up because I was puking from agony. I'd pass out at work. I was told some discomfort is normal. At 23 a (cis woman!) doctor told me if I did not stop complaining the only solution was a hysterectomy.
add a skeleton here at some point
17
449
150
youtu.be/by53T03Eeds?...
13 days ago
0
1
0
reposted by
Dave Aitel
The Associated Press
14 days ago
An AP investigation finds that Silicon Valley companies sold surveillance technology to Chinese police and security contractors, ignoring warnings that the tools were being used to quash dissent, persecute religious sects and target minorities.
loading . . .
US tech companies enabled the surveillance and detention of hundreds of thousands in China
U.S. technology firms such as IBM, Dell and Cisco largely designed and built China’s surveillance state, an AP investigation finds. The tech companies deny wrongdoing.
https://bit.ly/4m9vBMP
13
157
114
Great talk from
@ollieatnowhere.bsky.social
youtu.be/UVNMozEgYtY?...
loading . . .
The Wicked Problems and Opportunities of Cyber - Ollie Whitehouse
YouTube video by BSides Bournemouth
https://youtu.be/UVNMozEgYtY?si=FLuPi2D4z5f-Dt06
14 days ago
1
4
1
www.royensoc.co.uk/plenary-spea...
14 days ago
1
0
0
reposted by
Dave Aitel
Allan “Ransomware Sommelier” Liska
14 days ago
Cyberattack on Jaguar Land Rover threatens to hit British economic growth via
@alexmartin.bsky.social
& @there
loading . . .
Cyberattack on Jaguar Land Rover threatens to hit British economic growth
The disruption is the latest to hit a high-profile brand in the United Kingdom, and follows repeated delays in the British government introducing cybersecurity regulations that would require businesse...
https://therecord.media/cyberattack-jaguar-land-rover-economic-growth-uk-government
1
6
3
reposted by
Dave Aitel
Alexander Martin
14 days ago
Peter Kyle raised eyebrows last year when he said he was made, just hours into office, “very very aware that there was a cybersecurity challenge that our country faced that I simply wasn’t aware of before.” We report a secret briefing by intel chiefs was responsible:
therecord.media/cyberattack-...
1
7
11
This is a surprisingly great book IMHO
a.co/d/cBin4DW
loading . . .
The Sound of a Wild Snail Eating
Buy The Sound of a Wild Snail Eating on Amazon.com ✓ FREE SHIPPING on qualified orders
https://a.co/d/cBin4DW
16 days ago
0
2
1
Worth a read for the co-op
trust.salesloft.com?uid=Update+o...
loading . . .
Salesloft Trust Portal
Portal providing information and documentation related to Salesloft's security, privacy, and compliance.
https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations
16 days ago
1
3
0
This is like sterling silver humor written for maybe ten people.
add a skeleton here at some point
17 days ago
0
0
0
reposted by
Dave Aitel
Catalin Cimpanu
17 days ago
Live streams from the OrangeCon 2025 security conference, which took place on Friday, are available on YouTube:
www.youtube.com/@OrangeCon/s...
0
7
1
reposted by
Dave Aitel
Cynthia Brumfield
20 days ago
In a DoD shake-up, Ashley Manning, the principal deputy assistant secretary of Defense for cyber policy, and Jonathan Owen, the acting deputy assistant secretary of Defense for homeland defense integration and defense support to civil authorities, have left the Pentagon.
thehill.com/policy/defen...
loading . . .
https://thehill.com/policy/defense/5482734-top-cyber-officials-leave-defense-department/
0
3
2
These videos are so good.
youtu.be/BmCWryz3dsU?...
loading . . .
Trail of Bits' AIxCC Final Submission | 01E CTF Radiooo
YouTube video by CTF Radiooo
https://youtu.be/BmCWryz3dsU?si=q_VFPdsUHcgZg1g-
20 days ago
1
5
1
reposted by
Dave Aitel
BEAN YEAR
20 days ago
First harvest of honey crisps have just started coming in from yakama , here’s why don’t taste like you used to remember
www.seriouseats.com/how-honeycri...
loading . . .
How Honeycrisp Apples Went From Marvel to Mediocre
An investigation into the Honeycrisp apple and how a complex string of events led to a decline in the quality of a beloved apple variety.
https://www.seriouseats.com/how-honeycrisp-apples-went-from-marvel-to-mediocre-8753117
10
96
39
reposted by
Dave Aitel
priscilla page
21 days ago
once again tapping the sign
add a skeleton here at some point
122
6669
1591
reposted by
Dave Aitel
Interrupt Labs
20 days ago
Senior Vulnerability Researchers, we have currently have roles available in our iOS and Browsers teams. Both can be based in the UK, USA or Australia 🌍 Find out more and apply at
www.interruptlabs.co.uk/careers
loading . . .
Careers | Interrupt Labs
Interrupt Labs are always on the lookout for people to join the team. We are at the forefront of vulnerability research and want to bring you along with us. Looking for experienced vulnerability…
https://www.interruptlabs.co.uk/careers
0
1
1
reposted by
Dave Aitel
Erik Jonker
22 days ago
"Citrix Netscaler backdoors — Part One — May 2025 activity against governments", This is not a ransomware group; it’s espionage.
doublepulsar.com/citrix-netsc...
#cybersecurity
#espionage
#governments
loading . . .
Citrix Netscaler backdoors — Part One — May 2025 activity against governments
A look at initial access and webshell deployment earlier this year.
https://doublepulsar.com/citrix-netscaler-backdoors-part-one-may-2025-activity-against-governments-f48037199c3f
0
12
8
reposted by
Dave Aitel
Catalin Cimpanu
22 days ago
TP-Link failed to patch a vulnerability in its routers for more than a year. The bug is in a protocol that allows ISPs to manage routers deployed at customer premises, also known as CWMP or TR-069. TP-Link was notified of the bug in May last year.
medium.com/@mehrrun/zer...
loading . . .
ZERO-DAY ALERT: Automated Discovery of Critical CWMP Stack Overflow in TP-Link Routers
Critical Zero-Day Discovery
https://medium.com/@mehrrun/zero-day-alert-automated-discovery-of-critical-cwmp-stack-overflow-in-tp-link-routers-0bc495a08679
1
15
9
reposted by
Dave Aitel
SwiftOnSecurity
22 days ago
Normie cyber people it brings me no pleasure to announce the aerospace cyber people absolutely cooked us
loading . . .
21
697
151
reposted by
Dave Aitel
Dan420247
8 months ago
This was the laugh I needed! 😂😂😂
4
26
13
reposted by
Dave Aitel
Nad
25 days ago
Cisco ASA honeypot blew up Aug 28: – 200k probes in 20h – 3 ASNs only: NYBULA / CHEAPY-HOST / GCS – Each IP ~10,102 reqs (scripted) likely prepping for CVE-2025-20182/20134 (DoS), disclosure bugs, or legacy RCEs. Report:
medium.com/@Nadsec/hone...
OTX Pulses:
otx.alienvault.com/user/conrat
loading . . .
Honeypot Report: A Coordinated Reconnaissance Wave Against Cisco ASA Appliances
Author: Rat5ak https://otx.alienvault.com/user/conrat45/pulses
https://medium.com/@Nadsec/honeypot-report-a-coordinated-reconnaissance-wave-against-cisco-asa-appliances-ddc49b6664ae
2
1
3
reposted by
Dave Aitel
The Lesbian Review
23 days ago
Why do sapphic books offer something extra? Hear how representation, fresh voices & new angles create more powerful reading experiences. Sept 27 | Online
#Lesfic
#BookEvent
#lesfic
#lesbianbooks
Get your tickets
thelesbianreview.com/nice-genres-...
@anakwrenn.bsky.social
@cjeandowner.bsky.social
0
7
4
reposted by
Dave Aitel
Patrick C Miller
23 days ago
New zero-click exploit allegedly used to hack WhatsApp users
loading . . .
New zero-click exploit allegedly used to hack WhatsApp users
WhatsApp warns users targeted by advanced spyware, sending threat notifications to affected individuals from the past 90 days.
https://ift.tt/JswW0ay
0
8
5
reposted by
Dave Aitel
Soatok
23 days ago
"What the hell is Freon?" I do have a blog post about it!
soatok.blog/2025/08/09/i...
TL;DR - Imagine code-signing where your secret key is held by no one, but requires the cooperation of several trusted parties to generate a signature. (Like torpedoes requiring 2 keys, except not destructive.)
loading . . .
Improving Geographical Resilience For Distributed Open Source Teams with FREON - Dhole Moments
In a recent blog post, I laid out the argument that, if you have securely implemented end-to-end encryption in your software, then the jurisdiction where your ciphertext is stored is almost irrelev…
https://soatok.blog/2025/08/09/improving-geographical-resilience-for-distributed-open-source-teams-with-freon/
0
12
4
reposted by
Dave Aitel
Drew Harwell
23 days ago
New: I looked at 90 porn sites to test the new age-verification law rewriting the web. The ones following the rules, and scanning visitors' faces, are crumbling, while the lawbreakers are doubling or tripling their traffic. One of many unintended consequences for an experimental tech
wapo.st/47QuttW
loading . . .
‘Scan your face’ laws for the web are having unexpected consequences
The new age-verification laws in the United States and United Kingdom have brought some surprising downsides, including soaring traffic to seedy parts of the web.
https://wapo.st/47QuttW
108
1243
512
reposted by
Dave Aitel
Gady Epstein
30 days ago
America now
add a skeleton here at some point
96
5716
2491
Load more
feeds!
log in