Lesley Carhart :unverified:

I am eminently qualified to speak from experience about a variety of dumpster fires.

Director of Incident Response at Dragos, ICS cybersecurity person, @pancakescon organizer, martial artist, marksman, humanist, level 14 Neutral Good rogue, USAF retired. Speaker available for gigs.

Gin connoisseur. Rodent parent. Some dipshit from Chicago. Now an immigrant in Melbourne.

I post *very serious* things about infosec. Thoughts are entirely my own.

'they/them' šŸ³ļøā€šŸŒˆ :nonbinary_flag: :asexual_flag:

Lesley Carhart :unverified: boosted:
2025-12-11

A Developer Accidentally Found #CSAM in #AI Data. #Google #Banned Him For It

Google suspended a mobile app developer’s accts after he uploaded AI #training data to his #GoogleDrive. Unbeknownst to him, the widely used dataset, which is cited in a number of academic papers & distributed via an #academic file sharing site, contained child #sexualAbuse material. The developer reported the dataset to a child safety org, which eventually resulted in the dataset’s removal

404media.co/a-developer-accide

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-12-06

@stark there isn’t any OT cybersecurity conference I’m aware of in Vegas.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-12-06

I mean if I hadn't moved to another hemisphere I would never feel safe speaking in my own small industry on my area of expertise, again.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-12-06

This isn't a jab at anyone but I really wish there was a single OT cyber conference in America not held in Florida or Texas.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-24

@ben šŸ‘€šŸ‘€šŸ‘€

Lesley Carhart :unverified: boosted:
deilann v -0.2.1. :neodog_hyper: :neodog_nom_verified:deilann@tech.lgbt
2025-11-24

@hacks4pancakes

not only can you not do that, but it's visa fraud

and visa fraud makes it very hard to emigrate

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-24

@varx I shall shrivel into a corncob

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-24

I should add two things:
Fucking up a visa and getting refused or turned away at the border can impact your travel for decades, and banned from that country for years.

In the modern world of computers you will not be able to get most essential services on a visitor visa at all.

Lesley Carhart :unverified: boosted:
2025-11-24

New from 404 Media: X has shown where accounts are actually being run from, revealing many MAGA accounts are actually grifters in Eastern Europe, Asia, etc. But the situation is much, much worse. Entire guides specifically on how to squeeze US audiences with AI.

404media.co/americas-polarizat

Lesley Carhart :unverified: boosted:
2025-11-24

New, by me: Is your Android TV streaming box part of a botnet?

"On the surface, the Superbox media streaming devices for sale at retailers like BestBuy and Walmart may seem like a steal: They offer unlimited access to more than 2,200 pay-per-view and streaming services like Netflix, ESPN and Hulu, all for a one-time fee of around $400. But security experts warn these TV boxes require intrusive software that forces the user’s network to relay Internet traffic for others, traffic that is often tied to cybercrime activity such as advertising fraud and account takeovers."

The story looks closely at what Superbox is, how it operates, and what it appears to do on the sly. Spoiler: A Censys researcher found that installing the apps that allow these channels to stream enrolls the user's IP in a residential proxy service, and that these devices include powerful network discovery and remote access tools like Tcpdump and Netcat.

Overall, the Superbox is just one brand in an ocean of no-name Android-based TV boxes that are widely available and that either come pre-infected with malware or require malicious apps to use.

krebsonsecurity.com/2025/11/is

A screenshot of the Walmart website shows 397 results for Superbox devices. They look like small wireless routers, include a remote, and come in bright metallic blue or black.
Lesley Carhart :unverified: boosted:
2025-11-24

@hacks4pancakes As I told stupid people over 20 years ago: walls work both ways.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-24

Oh my gods people - did you think that the hundreds of thousands of grads in poor countries you’re competing with didn’t think of either of those ā€œhacksā€??? White / USA privilege is not a safe protective measure, do things right.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-24

This isn’t targeted at anyone in specific - I have had the conversation like 6 times this week,
Americans -
You need a work visa to work in another country, -even remote- unless they allow digital nomad
You can’t just go to most countries on a tourist visa and start looking for a visa sponsor & job

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-23

@TomSeppert they took it down for hours, presumably while some people remembered VPN existed.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-23

@neurovagrant @Rajiv it’s just such a wonderful illustration. Every social network should unmask countries of origin, vpn or not.

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-23

@GossiTheDog or that they care

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-23

@Pinchy63 from an OSINT perspective it’s a great curtain peek though!

Lesley Carhart :unverified: boosted:
2025-11-23

@hacks4pancakes curious if we are going to discover same for left influencers and realize that it's just bunch of bots fighting with one another that has led to downfall of murica

Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-11-23

Nobody really knows what screenshots are real or fake, nobody knows what’s just broken on geolocation because X fired their engineers, but a statistically improbable bunch of ā€œAmericanā€ alt right accounts popped up as created in Thailand and Nigeria.

It’s pretty expected 2025 bananagrams.

Lesley Carhart :unverified: boosted:

@tofugolem

Q; What if one exposes a high spy guilty of high treason, and nothing change?
A: the collapse will come faster.

An example?
Ok:

From Daractenus (X account)

After it turned out that about
two thirds of Twitter's MAGA and
far-right accounts are based in
Russia, Nigeria and Bangladesh,
Musk has now shut down the
location feature.
Last edited 18:23 - 22 Nov 25

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst