Advertisement · 728 × 90

Posts by Kyle Ehmke

The dark money group’s democracyunmuted[.]org domain is almost certainly administered using the same Cloudflare account as demfluencers[.]com.

The latter—originally registered in June 2025 and operational in the Nov/Dec timeframe—claims to provide paid opportunities and access for influencers.

1 month ago 2 1 0 0
Post image

Now hosting content for a Senate resolution proposed by CHD, Autism Action Network, Health Freedom Defense Fund, Stand For Health Freedom, and The Brownstone Institute. TLDR: it’s a lot of anti-vax advocacy’s greatest hits.

1 month ago 1 1 1 0
Preview
Voting as a college student | Vote.gov Find out where and how to register and vote in national, state, and local elections as a college student.

The linked guide to voting page for college students was removed and currently returns a Page not found error.

Most recent available entry from early September available here:
web.archive.org/web/20250903...

2 months ago 0 0 0 0
Post image Post image Post image

Between 10 and 11 September 2025, the “Know your voting rights” entry for college students was removed from vote.gov.

While not definitively related, this coincides with the timeframe—8 September 2025 per the earliest cert—when National Design Studio ostensibly began working on the site.

2 months ago 0 0 1 0
Post image Post image Post image Post image

New toadie site in the works: 47compliance[.]org

Highly likely administered using the same Cloudflare account as a number of other pro Trump/GOP and anti Dem sites, including:
insidebidensbasement[.]org
kamalaskoup[.]org
protect47[.]org

2 months ago 1 0 0 0
Post image Post image

New Children's Health Defense site registered on 1/9/26 and currently in development:
covidjustice[.]org
covidjustice[.]metalteam[.]dev (69.16.249[.]248, dev site)

2 months ago 2 2 1 0
Post image

Suspicious domain ms-driversync[.]com was registered through Njalla on 10/14/25 and resolves to 192.166.82[.]94.

6 months ago 2 1 0 0
Post image

Suspicious domain mfa[.]directory was registered through Njalla on 10/15/25 and resolves to 149.33.2[.]67.

6 months ago 4 2 0 0
Preview
Forecasting Typhoons: Volt Typhoon Next Steps in OT Disruption — CYBERWARCON

Looking forward to finally presenting this research into Volt Typhoon in a public forum - and I can't think of a better one than @cyberwarcon.bsky.social
www.cyberwarcon.com/forecasting-...

6 months ago 34 8 0 0
Preview
Oil Into The Fire — CYBERWARCON

Have you ever wanted to see two terminally online nerds really (and I mean *really*) get into the SVR deep lore while continuing the eternal goal of making 2016 last forever?

Gosh does @cyberwarcon.bsky.social have a talk for you!

6 months ago 44 8 2 3
Advertisement

We've got some good submissions flowing into the @CYBERWARCON CFP, but there's still time for more. If you have good content, and you're worried the honorarium won't cover your travel, please submit, and we'll work it out. We do this because we believe this research matters.

7 months ago 5 3 0 0

Kim John Un rolls off the tongue nicely

7 months ago 1 0 0 0

Best conference in the industry is back! cyberwarcon.com

7 months ago 10 2 1 0
Post image Post image

Suspicious domains micrsosft-netupdate[.]net (109.107.172[.]123) and micrsosft-netupdate[.]net (146.103.115[.]183) were co-registered through Njalla on 8/14/25.

8 months ago 0 0 1 0
Post image

Suspicious domain adobereader[.]cc was registered through MonoVM on 8/5/25 using freewanatoly@2mail[.]co. Currently resolves to M247 IP 84.252.95[.]40.

8 months ago 2 0 0 0
Post image

Suspicious domain sophossec[.]com was registered through MonoVM on 7/15/25 using kehmar.maung@proton[.]me and resolves to 146.70.247[.]55.

9 months ago 1 1 0 0

Of all my professional accomplishments, I think I’m proudest of this.

9 months ago 54 5 6 2
Advertisement
Post image Post image

Likely related domains drowingaws[.]com (13.217.161[.]160) and drowingazur[.]com (20.163.58.252) were co-registered through Njalla on 6/20/25.

9 months ago 1 0 0 0
Post image Post image

Suspicious domains awsonlineserch[.]com and azuronlineserch[.]com were co-registered through Njalla on 6/19/25. Currently resolving to 34.204.12[.]191 and 20.83.167[.]25, respectively.

10 months ago 1 1 1 0
Post image Post image

Suspicious domain windowsntp[.]com was registered through Njalla on 5/22/25 and then began using Cloudflare. Domain itself does not resolve, but subdomain www.windowsntp[.]com indicates MSFT Azure use.

10 months ago 1 1 0 0
Post image Post image Post image

Suspicious domain m365sessionlogin[.]com was registered through Njalla on 5/18/25. Domain itself does not resolve, but subdomains login, logon, and office365 indicate hosting at 80.78.30[.]154.

11 months ago 8 3 1 0
Preview
16 Ways to Reverse 30x30 - American Stewards of Liberty Share this page...

Most of the latter policy positions are copied from the American Stewards of Liberty page here:

web.archive.org/web/20250516...

11 months ago 1 0 0 0
Post image Post image Post image

Highly likely Parscale / Nucleus-administered domain congressstrongaction[.]org was registered on 9/23/24 and recently began hosting content. The org's stated policy positions appear largely aimed at curtailing laws and protections related to natural resources.

11 months ago 1 1 1 0
Post image Post image Post image Post image

Set of suspicious domains co-registered through Njalla on 4/24/25:
esxiupdate[.]com
threatbook[.]cloud

Not currently resolving, but worth keeping an eye on.

11 months ago 1 1 0 0
Post image Post image Post image

Set of suspicious domains registered on 4/2/25 (unclear through which reseller) and administered using the same Cloudflare account:

googlealert[.]net
microsoft365signin[.]net
microsoftalert[.]net
outlooksecurity[.]net
outlooksignin[.]net

1 year ago 5 2 0 0
Post image

Suspicious domain analytics[.]airforce was registered through Njalla on 4/2/25 and resolves to BL Networks IP 64.52.80[.]61.

1 year ago 2 1 0 0

The Children's Health Defense staging site associated with realcdc[.]org indicates they are setting it up to pose as a legitmate CDC site questioning vaccine safety, complete with parent testimonials. Currently no overt indication the site is run by CHD.

1 year ago 4 2 1 1
Advertisement
Post image

Suspicious domain chromeupdate[.]net was registered through Njalla on 3/11/25. Not currently resolving, but worth keeping an eye on.

1 year ago 3 2 0 0
Post image

Suspicious domain nvidia-installer[.]com was registered through Njalla on 3/10/25 and resolves to 51.44.166[.]225.

1 year ago 4 2 0 0

Again, not saying that's what is happening here. Nor am I stating the conclusions in the SFS site are incorrect or that there is malicious intent behind it. Unfortunately, it is a concerning vulnerability to IO predicated on shortsighted reactivity that we have to consider these days. (4/4)

1 year ago 3 0 1 0