Tim (Wadhwa-)Brown :donor:

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-28

Interesting links of the week:

Strategy:

* docs.google.com/presentation/d - @HalvarFlake gives us his take on where the West's strategy is going awry
* tandfonline.com/doi/full/10.10 - why "feds" and "spooks" don't get reported
* arxiv.org/abs/2502.15840 benchmarking AI
* nap.nationalacademies.org/cata - HARD problems in cyber

Threats:

* techcrunch.com/2025/05/23/myst - meet the Spanish mob

Detection:

* medium.com/cloud-security/how- - something I've been known to preach on too... @teriradichel preaches the value of business data in spotting malicious behaviours... not every detection needs to be based on security telemetry
* blog.sekoia.io/vicioustrap-inf - turning your network perimeter into a big ol' fly tray
* blog.talosintelligence.com/pro - a nice write up from one of my colleagues at @TalosSecurity on threat hunting

Exploitation:

* bashcore.org/ - a new security testing distro based on Debian from @nickbearded
* tmr232.github.io/function-grap - understanding the call flow
* blog.compass-security.com/2025 - enumerating Entra
* incendium.rocks/posts/Automati - automating research on Microsoft RPC

Hard hacks:

* blog.siguza.net/tachy0n/ - @siguza talks tachy0n for iOS jailbreaking
* insbug.medium.com/badusb-attac - naughty flash drives

Hardening:

* u1f383.github.io/linux/2025/05 - learn about DBUS and Polkit
* jpmens.net/2025/03/25/authoriz - doing SSH public key auth better

Nerd:

* theregister.com/2025/05/24/joh - John Young obituary from el reg
* arxiv.org/abs/2502.15840 - care of @0xabad1dea, paper on the chaos one AI controlled business caused
* archive.nytimes.com/www.nytime - something we don't think about enough when we work with big tech...
* websdr.org/ - the radio, on the Internet
* optimizedbyotto.com/post/debia - building Debian packages with Git

#security, #research

Tim (Wadhwa-)Brown :donor: boosted:
The Sleight Doctor πŸƒApostateEnglishman@mastodon.world
2025-05-26

Fellow Brits! If you can, please attend this antifascist summit. The location will be announced soon.

*Stand Up to Racism (SUTR) & Trade Union Council Midlands (TUC) Antiracism Summit*

1️⃣4️⃣ Saturday 14 June
⏰️ 11.00am

Sessions and workshops include:
✊️ Countering Reform UK and the racist narrative: housing, employment and the NHS.
✊️ The challenge of fascism today.
✊️ Uniting against racism, Islamophobia and antisemitism.

Register here πŸ‘‡
eventbrite.co.uk/e/taking-on-t

RSVP here πŸ‘‡
facebook.com/share/19dibgvAP2/

Flyer in pink and yellow with a pic of a crows of protestors against racism and the far right. The text is the same as in the header post.
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-25

Sad times, John Young of Cryptome is no longer with us:

theregister.com/2025/05/24/joh

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-25
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-25
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-25

BSides Bournemouth are putting the hard yards in looking for speakers. Submit here:
cfp.bsides-bournemouth.org/bsi

Happy to mentor new speakers if that gives any if you a confidence boost.

#BSidesBournemouth

Tim (Wadhwa-)Brown :donor: boosted:
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-25

Interesting links of the week:

Strategy:

* security.googleblog.com/2025/0 - what's over the horizon for PQC
* gov.uk/government/publications - HMG problem book for Secure By Design

Standards:

* ncsc.gov.uk/blog-post/new-etsi - NCSC work on new ETSI standard for AI security

Threats:

* ai-incidents.mitre.org/ - MITRE ATLAS' database of AI spillages, leaks and floods
* unit42.paloaltonetworks.com/th - SAP oopsie turns bad

Detection:

* community.emergingthreats.net/ - @da_667 talks detection engineering
* magonia.io/wiresnort/ - combining Wireshark and Snort

Bugs:

* akamai.com/blog/security-resea - abusing service account delegation for privesc in AD
* astr.al/notes/2024-11-28_mdatp - when you can't even trust $argv[0] and processes called java.. a nice LPE in Defender for Linux
* sourceware.org/bugzilla/show_b - ... or, it seems $LD_LIBRARY_PATH (what's old is new =))
* mastdatabase.co.uk/blog/2025/0 - leaky VoLTE and wifi calling
* starlabs.sg/blog/2025/05-break - XSS to RCE in VSCode

Exploitation:

* go.dev/blog/tob-crypto-audit - @trailofbits took a look at Go Crypto

Hard hacks:

* idevicecentral.com/tweaks/idev - getting JB like tweaks running on modern iOS
* sopl.us/blog/consumer-do-it-yo - getting physical with your keys

Development:

* docs.oracle.com/cd/E37838_01/h - Oracle's guide to secure C for Solaris (thanks @alanc)
* allan.reyes.sh/posts/keeping-s - on keeping your secrets, well, secret
* netascode.cisco.com/ - automate your network

Hardening:

* lore.kernel.org/landlock/20250 - Latest news on Landlock for Linux
* man7.org/linux/man-pages/man1/ - analyzing systemd for signs of sense
* blog.torproject.org/introducin - another option to isolate your onions

Nerd:

* linuxexpert.org/from-licenses- - the story of Linux, through a lens of innovation
* newscientist.com/article/24802 - did you know you could also make chillies hotter with salt?

#security, #research

Tim (Wadhwa-)Brown :donor: boosted:
2025-05-25

As they fled the bandit fort, the rogue snapped, "Did you have to be so rude? You were supposed to negotiate a truce!"

The mage shrugged. "I'm sure there will be #eventual calm."

"We'll need to watch our backs forever. Well, even more than usual."

"Nonsense. I left my chest behind. Once they open itβ€”"

An enormous blast behind them sent the horses leaping forward.

"See? Problem solved."

#MastoPrompt #MicroFiction

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-24

Tea thought: Could TPB and Sci-Hub pivot and relaunch as seed material for foundational models?

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-24
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-24

Interesting Git repos of the week:

Strategy:

* github.com/AI-Assessment-Insti - I have thoughts, but they're at least trying to evaluate "AI pen testers"

Detection:

* github.com/wowsignal-io/pedro - another open EDR for Linux
* github.com/nccgroup/ghostrings - ripping apart Go bins

Exploitation:

* github.com/adgaultier/tamanoir - pretty sure offense is ahead of defense as far as eBPF... another keylogger!
* github.com/gsuberland/MSMQCheck - which queues should you be targetting from @gsuberland
* github.com/0xdea/semgrep-rules - @raptor's semgrep rules have had an update

Hard hacks:

* github.com/seemoo-lab/openhays - build your own AirTags

#code, #security, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-24

Interesting links of the week:

Strategy:

* security.googleblog.com/2025/0 - what's over the horizon for PQC
* gov.uk/government/publications - HMG problem book for Secure By Design

Standards:

* ncsc.gov.uk/blog-post/new-etsi - NCSC work on new ETSI standard for AI security

Threats:

* ai-incidents.mitre.org/ - MITRE ATLAS' database of AI spillages, leaks and floods
* unit42.paloaltonetworks.com/th - SAP oopsie turns bad

Detection:

* community.emergingthreats.net/ - @da_667 talks detection engineering
* magonia.io/wiresnort/ - combining Wireshark and Snort

Bugs:

* akamai.com/blog/security-resea - abusing service account delegation for privesc in AD
* astr.al/notes/2024-11-28_mdatp - when you can't even trust $argv[0] and processes called java.. a nice LPE in Defender for Linux
* sourceware.org/bugzilla/show_b - ... or, it seems $LD_LIBRARY_PATH (what's old is new =))
* mastdatabase.co.uk/blog/2025/0 - leaky VoLTE and wifi calling
* starlabs.sg/blog/2025/05-break - XSS to RCE in VSCode

Exploitation:

* go.dev/blog/tob-crypto-audit - @trailofbits took a look at Go Crypto

Hard hacks:

* idevicecentral.com/tweaks/idev - getting JB like tweaks running on modern iOS
* sopl.us/blog/consumer-do-it-yo - getting physical with your keys

Development:

* docs.oracle.com/cd/E37838_01/h - Oracle's guide to secure C for Solaris (thanks @alanc)
* allan.reyes.sh/posts/keeping-s - on keeping your secrets, well, secret
* netascode.cisco.com/ - automate your network

Hardening:

* lore.kernel.org/landlock/20250 - Latest news on Landlock for Linux
* man7.org/linux/man-pages/man1/ - analyzing systemd for signs of sense
* blog.torproject.org/introducin - another option to isolate your onions

Nerd:

* linuxexpert.org/from-licenses- - the story of Linux, through a lens of innovation
* newscientist.com/article/24802 - did you know you could also make chillies hotter with salt?

#security, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-22
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-21

Burger thought: Visions of Trump declaring war on Cinema.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-21

Watching MITRE kill off Slack for the ATLAS community and desperately hoping they don't do the same for ATT&CK.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-21

Attribution is hard... never mind that my actual name is on the repo. This kind of thing is why we probably shouldn't be using genAI as a threat intel source. What happens if it suggests we should target Chine?

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-21

Out of curiosity, I asked ChatGPT who wrote linikatz and welp:

"The original Linikatz project was developed by the GitHub user time-machine, who is associated with the organization CiscoCXSecurity. This tool was designed to facilitate post-exploitation tasks on UNIX systems integrated into Microsoft Active Directory environments."

"time-machine" 🀑

#statisticallywrong, #ai

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-21

@gsuberland ❀️ your queue names on github.com/gsuberland/MSMQCheck :)

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-05-20

Coming out of car park on to main road. Stationary, waiting for a gap in traffic before I pulled out. Drivers in expensive cars jumping on the horn because they had to go a little slower and avoid clipping me (my nose was out so I could actually see what was coming). Any one of them could have let me go. Humans are the worst.

In the end it was a guy in a white van who slowed and indicated for me to pull out, so much for cultural stereotypes.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst