Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-08
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-07
Tim (Wadhwa-)Brown :donor: boosted:
2026-02-07

@drajt @Enthalpiste @codebyjeff @pluralistic Just throwing it out there, but there is a UK government petition that would mandate any MPs need to pass the citzenship test to keep their job. I dont see it ever becoming law, but I'd love if enough people signed that it got to the debate and they had to weasel their way out of it while still maintaining that it is an effective test for new citizens. petition.parliament.uk/petitio

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-07

This year's T-Level mentee enjoys chips off hardware hacking and DMA attack. This will be fun.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-07

Seen an interesting trend in UK FSI over the last months, with multiple requests for specific support in hampering network-centric aspects of discovery, lateral movement, C2 and exfiltration. I wonder what it's attributed to.

#threatintel, #fsi

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-07
Tim (Wadhwa-)Brown :donor: boosted:
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-07

Interesting links of the week:

Strategy:

* x-c3ll.github.io/posts/Rant-Re - @XC3LL talks red teaming trends
* arstechnica.com/security/2026/ - finally settled, the poor testers with a faulty get out of jail card

Threats:

* stratcomcoe.org/pdfjs/?file=/p - STRATCOM talks influence operations
* github.com/blackorbird/APT_REP - threat research report from Qihoo 360
* greynoise.io/blog/unmasking-ci - @greynoise discuss hidden signals in KEV
* rapid7.com/blog/post/tr-chrysa - @rapid7's excellent analysis of notepad++
* community.plone.org/t/plone-se - another supply chain woopsie
* cert.pl/en/posts/2026/01/incid - reporting on the .pl power problems
* zenodo.org/records/18444900 - content based risk analysis of Moltbook (not for the faint-hearted)

Detection:

* zeek.org/2026/01/how-to-use-ja - @zeek discuss how to leverage JA4
* blog.jmhill.me/deploying-an-op - @jmhill describes how to deploy OpenCTI
* huntress.com/blog/ldap-active- - the latest of @huntress's excellent blogs on what an attack on LDAP can actually look like
* leanpub.com/suri_operator - @da_667's survivors guide to @suricata

Bugs:

* labs.watchtowr.com/someone-kno - @index continue their streak of popping fun bugs in the wild
* zeroleaks.ai/reports/openclaw- - nice technical write up on OpenClaw

Exploitation:

* scriptjunkie.us/2026/01/tracki - leaking Signal IDs from @sj
* splintersfury.github.io/mal_bl - reversing Netfilter
* alfiecg.uk/2024/09/24/Kernel-e - Alfie pops iOS
* secure.dev/securing_ggml_rpc.h - attack and defend on GGML

Hard hacks:

* hexkyz.blogspot.com/2021/11/je - an oldie on popping NVIDIA's Falcon

Hardening:

* itsfoss.com/news/amutable-linu - @pid_eins triggers systemctl restart
* fosdem.org/2026/schedule/event - how to get land locked

#security, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-06

Interesting that there is no way to ship books to the UK on NERP CIP. There are current reasons why this is infuriating.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-05

Interesting links of the week:

Strategy:

* x-c3ll.github.io/posts/Rant-Re - @XC3LL talks red teaming trends
* arstechnica.com/security/2026/ - finally settled, the poor testers with a faulty get out of jail card

Threats:

* stratcomcoe.org/pdfjs/?file=/p - STRATCOM talks influence operations
* github.com/blackorbird/APT_REP - threat research report from Qihoo 360
* greynoise.io/blog/unmasking-ci - @greynoise discuss hidden signals in KEV
* rapid7.com/blog/post/tr-chrysa - @rapid7's excellent analysis of notepad++
* community.plone.org/t/plone-se - another supply chain woopsie
* cert.pl/en/posts/2026/01/incid - reporting on the .pl power problems
* zenodo.org/records/18444900 - content based risk analysis of Moltbook (not for the faint-hearted)

Detection:

* zeek.org/2026/01/how-to-use-ja - @zeek discuss how to leverage JA4
* blog.jmhill.me/deploying-an-op - @jmhill describes how to deploy OpenCTI
* huntress.com/blog/ldap-active- - the latest of @huntress's excellent blogs on what an attack on LDAP can actually look like
* leanpub.com/suri_operator - @da_667's survivors guide to @suricata

Bugs:

* labs.watchtowr.com/someone-kno - @index continue their streak of popping fun bugs in the wild
* zeroleaks.ai/reports/openclaw- - nice technical write up on OpenClaw

Exploitation:

* scriptjunkie.us/2026/01/tracki - leaking Signal IDs from @sj
* splintersfury.github.io/mal_bl - reversing Netfilter
* alfiecg.uk/2024/09/24/Kernel-e - Alfie pops iOS
* secure.dev/securing_ggml_rpc.h - attack and defend on GGML

Hard hacks:

* hexkyz.blogspot.com/2021/11/je - an oldie on popping NVIDIA's Falcon

Hardening:

* itsfoss.com/news/amutable-linu - @pid_eins triggers systemctl restart
* fosdem.org/2026/schedule/event - how to get land locked

#security, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-05
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-05

Product idea:

Recognise Connections

Tagline: "Nothing says meaningful thanks more than having a bot write the card..."

Functional requirements:

* Bot scans your emails each month and then decides what/how much to recognise you
* HR wire the agent into Amazon's gift recommendation API

Business outcome:

"This was so good, you deserve a box of tissues."

#microfiction

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-04

We will do a spreadsheet style UI, incredibly badly.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-04
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-02

Another day, another threat model. Credit card company wants to know what they should be on the lookout for by way of discovery, lateral movement and c2 and exfiltration from their micro-segmentation solution as easy wins..

#threatmodelling

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-02

When you delete a vendor library to resolve a symbols issue on a commercial Linux product...

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-02

And again, OpenClaw's not that much better if you look at it from a more technical standpoint:

zeroleaks.ai/reports/openclaw-

#threatintel, #aislop

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2026-02-02

One of our AI threat team pointed me at this:

zenodo.org/records/18444900

Interesting analysis of Moltshite.

#threatintel, #aislop

Tim (Wadhwa-)Brown :donor: boosted:
🦋ShouldbeWriting🦋vanellopemint@mastodon.art
2026-02-01

"I must admit," said Lady Chatterly, "that your operation of the Wyrmhaven Deep Dungeon is most impressive. However, I am not certain I feel safe investing my money with you - you goblins are so very ugly."

Nyx Gritbottom, head of the Wyrmhaven Deep Dungeon Improvement Committee, drew himself up to his full height of just under four feet. "And you Madam, are drunk. But in the morning I shall be..." His voice trailed off. He frowned. "Wait, I think we started that off wrong...."

#microfiction

Tim (Wadhwa-)Brown :donor: boosted:
Juanma FernandezXC3LL
2026-02-01

A small rant:

The State of Art in Red Team is whatever you want to believe

x-c3ll.github.io/posts/Rant-Re

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst