Advertisement · 728 × 90

Posts by Spanky

The Angry Spark APT Mystery: One Victim, Zero Attribution
The Angry Spark APT Mystery: One Victim, Zero Attribution YouTube video by Three Buddy Problem

NEW PROBLEM UP! 🚨

We discuss a mysterious, VM-obfuscated backdoor that lived undetected on a single U.K. machine for a year before disappearing, finding clues pointing to an elite-level APT intrusion that still evades broader industry coverage.

WATCH on YouTube www.youtube.com/watch?v=mSD9...

2 days ago 10 4 1 2
Post image

#agentmentoring

— from @JohnHultquist (https://x.com/JohnHultquist/status/2042379534180229147

1 week ago 1 1 0 0
Preview
Trump Is Wishcasting Victory in Iran The president went from threatening that “a whole civilization will die” to claiming a “total and complete victory.” What does the already shaky cease-fire mean as he tries to steer his way out of the war?

On Radio Atlantic, @radiofreetom.bsky.social and Nancy A. Youssef explain the state of  the war in Iran—and how no deal can undo the damage of Trump’s words.

1 week ago 174 63 12 2
Preview
The Invisible Army: Residential Proxy Abuse in Internet-Scale Attack Traffic GreyNoise analyzed 4 billion sessions to expose residential proxy abuse, behavioral patterns, why IP reputation fails, and what defenders can do about it.

New GreyNoise Report: 39% of unique IPs targeting the edge come from home internet connections. They are everywhere, briefly — 78% appear at most twice before rotating. The rotation rate makes feed-based IP reputation structurally ineffective against this traffic.

🔗 www.greynoise.io/resources/in...

2 weeks ago 4 3 0 0
Preview
GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team · GitHub Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub

TIL FLARE distributes educational content for free on GitHub.

github.com/mandiant/fla...

2 weeks ago 4 3 0 0
Preview
Iran Threatens to Start Attacking Major US Tech Firms on April 1 Tech giants like Apple, Google, and Microsoft are among those on a target list released by Iran’s Islamic Revolutionary Guard Corps.

Tech giants like Apple, Google, and Microsoft are among those on a target list released by Iran’s Islamic Revolutionary Guard Corps. www.wired.com/story/iran-t...

2 weeks ago 227 67 47 69
Post image

ShinyHunters is ransoming ... HALLMARK CARDS

Those fucking shitty birthday cards you pick up at the drug store ARE BEING HELD RANSOMWARE

WHO RANSOMS BIRTHDAY CARDS

(info via @AlvieriD)

3 weeks ago 17 4 1 1
Post image

42 years ago
'Minor Threat' aka 'First Two Seven' Inches is a compilation album by the American hardcorepunk band Minor Threat, released in March 1984 and consists of the first two extended plays 'Minor Threat' and 'In My Eyes' .

#punk #punkrock #minorthreat #punkrockhistory

1 month ago 164 33 3 8
Advertisement

Global warming was the plan all along!!!

1 month ago 1 0 0 0
Post image

🧨 🚨 NEW POD UP! (presented by @thinkstcanary.canary.tools) - The Coruna iOS exploit kit, the connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use @craiu.bsky.social @jags.bsky.social

LISTEN everwhere 👇
pod.link/1414525622

1 month ago 6 4 1 0

These things have always been true:
1. The ability to generate buggy code has never been greater.
2. The ability to find bugs in code has never been greater.
3. The ability to fix bugs in code has never been greater.
4. Many, many more people want to do 1 or 2 than 3.

Now scale this with AI.

1 month ago 12 8 1 0

REKT

1 month ago 0 0 0 0

Our blog at @Censys now has a proper RSS feed https://censys.com/feed/
(cc: @Feedly #GoogleReader)

1 month ago 9 3 1 0

Could've had a Chomps, Dave.

2 months ago 0 0 0 0

Why learn to code when you can use an LLM and pay a subscription fee for the rest of your life.

2 months ago 315 65 18 10
Preview
Not Safe for Politics: Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi - The Citizen Lab Following the widely-condemned arrest in July 2025 of prominent Kenyan opposition voice Boniface Mwangi, the Citizen Lab analyzed artefacts from devices seized during the arrest. We found that Cellebr...

NEW @citizenlab.ca report: Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi

citizenlab.ca/research/cel...

2 months ago 26 19 2 0
Advertisement
Post image

Making my GREM index like...

2 months ago 2 0 0 0

These dudes are awesome! Highly recommend their training if you get the opportunity.

2 months ago 1 1 1 0
Preview
Penetration Tester | Microsoft Careers Penetration Testing Identify security vulnerabilities and variants across critical cloud services. Perform source code reviews, dynamic analysis, and operational security assessments. Validate softwar...

Early career pen tester wanted to break some of azures specialist clouds. #infosecJobs

2 months ago 7 4 0 0
Preview
Non-Deterministic The most important word you need to understand about AI

Non-Deterministic: The most important word you need to understand about AI 🤖

teriradichel.substack.com/p/non-determ...

2 months ago 2 2 0 0

My dog prefers that I listen to the podcast. She wants that 3 hour walk!

2 months ago 2 1 1 0
From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks
From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks YouTube video by Three Buddy Problem

This week's show is up on YouTube (presented by Thinkst Canary @thinkstcanary.canary.tools)

WATCH www.youtube.com/watch?v=fvKM...

2 months ago 6 5 1 0
Preview
Programming Languages and Serialization CVEs Taking a look at a recent critical Solar Winds CVE

If Pentesting, AppSec, Bug Bounties or Security Engineering is your focus the Security Bugs section of my blog may be for you. Here I explore a serialization CVE in SolarWinds and prevention methods

Programming Languages and Serialization CVEs

teriradichel.substack.com/p/programmin...

2 months ago 4 1 0 0
Preview
A destructive cyberattack in Poland raises NATO 'red-line' questions - Security Conversations (Presented by Material Security: We protect your company’s most valuable materials — the emails, files, and accounts that live in your Google Workspace and Microsoft […]

🔥 #ThreeBuddyProblem Ep83 has been pushed to your earholes. Poland CERT on Russian wipers, Sandworm or not Sandworm, new FortIvanti nightmares + some KasperSekrets chit-chat @craiu.bsky.social @jags.bsky.social

securityconversations.com/episode/a-de...

2 months ago 7 3 1 1

No.

3 months ago 0 0 0 1
Advertisement
a bald eagle surrounded by stars and stripes and the text "oh my god, what the fuck"

a bald eagle surrounded by stars and stripes and the text "oh my god, what the fuck"

3 months ago 2174 631 15 39
Post image

Today’s Daily Cartoon, by Teresa Burns Parkhurst. #NewYorkerCartoons

3 months ago 280 62 2 5
Preview
Jan. 6, 2021: A visual archive of the Capitol attack NPR’s Jan. 6 archive brings together reporting, video, documents and testimony to show what really happened during the Capitol riot. Explore the timeline, cases and evidence behind the attack.

NPR built a visual archive of the Jan. 6, 2021, attack on the Capitol, showing exactly what happened through the lenses of the people who were there. In "Chapter 2: Stop the Steal," we look at how false claims of a stolen election mobilized Trump supporters.

3 months ago 1151 554 21 77
Preview
Don't get angry, but the 2025 Oxford Word of the Year is 'rage bait' The 2025 selection follows its predecessors, "brain rot" from 2024, "rizz" from 2023 and "goblin mode" from 2022.

The 2025 selection follows its predecessors, "brain rot" from 2024, "rizz" from 2023 and "goblin mode" from 2022.

3 months ago 187 35 9 8
Preview
What's behind US gov push to 'privatize' cyber operations?

A fresh problem has been pushed to your podcast platforms! @craiu.bsky.social @jags.bsky.social

- Spotify open.spotify.com/episode/68US...

- Apple podcasts.apple.com/us/podcast/w...

Presented by our friends at ThreatLocker 😍

4 months ago 4 2 0 1