Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

timb_machine@infosec.exchangeT

timb_machine@infosec.exchange

@timb_machine@infosec.exchange
About
Posts
10
Topics
9
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Interesting links of the week:
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Interesting links of the week:

    Strategy:

    * https://www.marisec.ca/reports/the-wrong-fix-why-the-fccs-router-ban-misses-the-real-threat - an alternate view on prioritising the supply chain
    * https://cybertoolkit.service.ncsc.gov.uk/ - so you're a small business and you want to improve your posture?
    * https://how.complexsystems.fail/ - courtesy of @russss
    * https://eepublicdownloads.blob.core.windows.net/public-cdn-container/clean-documents/Publications/2025/iberian-blackout/Final%20Report%20on%20the%20Grid%20Incident%20in%20Spain%20and%20Portugal%20on%2028%20April%202025.pdf - an Iberian oopsie
    * https://www.theregister.com/2026/03/20/jlr_bailout_cmc/ - @theregister shares a point of view on bailing out JLR
    * https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf - US intelligence community's annual threat assessment
    * https://cyber.gouv.fr/actualites/nis-2-lanssi-poursuit-et-renforce-sa-dynamique-daccompagnement/ - hot new NIS2 action from ANSSI

    Threats:

    * https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/ - how does AI affect STRIDE?
    * https://united24media.com/latest-news/russian-spy-devices-found-inside-ukrainian-drone-developers-office-17243 - attack of the drones
    * https://www.elastic.co/security-labs/illuminating-voidlink - another look at VoidLink
    * https://ctrlaltintel.com/threat%20research/FancyBear/ - FancyBear fucks up
    * https://netaskari.substack.com/p/chinas-massive-data-leak-of-military - .cn springs a leak

    Detection:

    * https://rogolabs.net/Talks/BSides-Galway-Open-Source-Intelligence.pdf - my colleague @jgamblin talks open source intelligence
    * https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-logging - @trustedsec look at logging PowerShell
    * https://righteousit.com/2026/03/27/linux-forensic-scenario/ - @hal_pomeranz sets us a little challenge

    Bugs:

    * https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ - this reminds me of when I first showed @ha888t AIX
    * https://itm4n.github.io/cve-2026-20817-wersvc-eop/ - when errors go rogue with @itm4n

    Exploitation:

    * https://dev.to/numbpill3d/showdev-can-playground-a-local-first-can-bus-analysis-tool-4ap6 - @numbpilled shows how you CAN play with busses
    * https://agentseal.org/blog/mcp-server-security-findings - hands up if you have a secure MCP?

    Hardening:

    * https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf - enclave backed SSH for OS X from @arianvp

    Nerd:

    * https://www.theguardian.com/culture/2026/mar/24/punk-masks-walkmans-and-choppers-museum-of-youth-culture-to-open-in-london - eras...
    * https://www.data.gov.uk/ - UK specific datasets from HMG
    * https://www.sambent.com/the-engineer-who-tried-to-put-age-verification-into-linux-5/ - today in Linux daftness
    * https://blog.rice.is/post/doom-over-dns/ - everyone's favourite vanity PoC payload comes to DNS

    #security, #research

    Uncategorized security research

  • Coding with LLMs and agents is a generational opportunity to throw the last few decades of hard won lessons on secure coding and appsec out the window.
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Coding with LLMs and agents is a generational opportunity to throw the last few decades of hard won lessons on secure coding and appsec out the window. Definitely something that trust and safety teams, threat actors and possibly even your parents are seizing on with glee when they bypass all of your policies and procedures around installing new software, data governance, validated designs, code reviews, principles of least privilege and regular security assessments. Best of luck.

    Uncategorized

  • For all the unrelated (with varying degrees of validity) screetching, this is one hell of an oopsie by Companies House:
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    For all the unrelated (with varying degrees of validity) screetching, this is one hell of an oopsie by Companies House:

    Link Preview Image

    favicon

    X (formerly Twitter) (x.com)

    #threatintel, #ukplcltd

    Uncategorized threatintel ukplcltd

  • Database kurfuffle:
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Database kurfuffle:

    Link Preview Image
    PostgreSQL: CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code

    favicon

    (www.postgresql.org)

    #threatintel, #postgres

    Uncategorized threatintel postgres

  • Pro-tip: You can still be supportive of women and girls tomorrow, next month, next year etc. Don't limit yourself to just treating them decently for one day!
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Pro-tip: You can still be supportive of women and girls tomorrow, next month, next year etc. Don't limit yourself to just treating them decently for one day!

    Uncategorized

  • The window falling starts on Monday.
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Good news, emails to their MSSP to start the exercise bounce. No TI injects for you then....

    Uncategorized

  • We've hit that point in the timeline when our generation start to EOF :(. stealth, FX, christer, roy...
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    We've hit that point in the timeline when our generation start to EOF :(. stealth, FX, christer, roy...

    Uncategorized

  • Interesting Git repos of the week:
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Interesting Git repos of the week:

    Strategy:

    * https://github.com/jacobdjwilson/awesome-annual-security-reports - all you can eat annual reports, thanks @jacobdjwilson

    Detection:

    * https://github.com/EFForg/rayhunter - hunting cell site simulators with @eff

    Exploitation:

    * https://github.com/wietze/lnk-it-up - make your own malicious links
    * https://github.com/dievus/ADPulse - more fun with the AD identity graph
    * https://github.com/trustedsec/Titanis - build your own Microsoft RPC clients
    * https://github.com/RantaSec/golinhound - graphing Linux trust paths
    * https://github.com/praetorian-inc/nerva - fingerprint that service
    * https://github.com/cisco-ai-defense/skill-scanner - check whether an agentic skill is malicious
    * https://github.com/Logisek/EvilMist - red team tools for the cloud
    * https://github.com/praetorian-inc/GitPhish - phish with GitHub
    * https://github.com/Antonlovesdnb/TTPRunner - automate your BAS with @Antonlovesdnb's LLM generated TTPs
    * https://github.com/praetorian-inc/augustus - TTPs for testing LLMs
    * https://github.com/ricardojoserf/AutoPtT - another way to automated ticket-passing attacks
    * https://github.com/0xsh3llf1r3/ColdWer - enough BOF to send your EDR to sleep
    * https://github.com/sliverarmory/malasada - convert your .so to shell code
    * https://github.com/subat0mik/Misconfiguration-Manager - abusing SCCM misconfigurations
    * https://github.com/dazzyddos/lsawhisper-bof - BOF to chat with LSA

    Hard hacks:

    * https://github.com/dmaynor/airdrop-observatory - spy on AirDrop with @Dmaynor

    Data:

    * https://github.com/Siguza/tld - @siguza helps you understand who owns that TLD?

    Nerd:

    * https://github.com/rbanffy/fun-with-old-mainframes - @rbanffy's tips on messing with big green screen
    * https://github.com/mitchellh/vouch - building community trust

    #security, #research, #code

    Uncategorized security research code

  • The window falling starts on Monday.
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    The window falling starts on Monday. Operation tiny dolls.

    Uncategorized

  • Watching one of our best red teams battle with his own soul cause I'm asking him to focus on artefact creation rather than defense evasion or trade craft.
    timb_machine@infosec.exchangeT timb_machine@infosec.exchange

    Watching one of our best red teams battle with his own soul cause I'm asking him to focus on artefact creation rather than defense evasion or trade craft.

    Like, what kinds of things inhibit these techniques, let's see which ones the customer has in play and how well they are integrated with the SOC.

    #purpleteam

    Uncategorized purpleteam
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups