Advertisement · 728 × 90

Posts by Runa Sandvik

Preview
Stabbings, kidnap threats and arson attacks: how the Iranian regime targets UK journalists Staff at outlets critical of Tehran have faced chilling intimidation and violence, amid calls for greater protection and support

Iranian journalists in London “say they fear for their lives after a recent spate of threats and physical attacks,” and I’m willing to bet the regime is leveraging digital attacks against critics too. www.theguardian.com/global-devel...

1 day ago 9 11 0 0
Vicky Peláez Vicky Peláez is a Peruvian journalist, currently writing for The Moscow News and Sputnik.

Updated my post about journalist and spy Vicky Peláez yesterday to include some quotes from @gordoncorera.bsky.social’s book, including that the FBI listened in as she discussed Moscow’s feedback on her husband’s intelligence reports. www.journalistandspy.com/p/vicky-pelaez

2 weeks ago 8 1 0 0

She was forced to comply, I don’t know that Denmark or Sweden would be the same.

3 weeks ago 0 0 0 0
Post image

Have there been any cases in Denmark or Sweden where the authorities have gained access to a journalist’s device using Touch ID or Face ID? Ref: the FBI and WaPo in January.

3 weeks ago 11 4 1 0
Preview
Billion-kroner project: Technology failure concerns ­

An investigation by journalists with NRK in Norway and SVT in Sweden found that a multimillion-dollar, prestige ferry project in Lofoten, Norway relies on hydrogen fuel cell technology that "cannot live up to what it promises." www.nrk.no/trondelag/xl...

3 weeks ago 7 1 1 0
Preview
Four things to know about Lockdown Mode Earlier this week, Apple notified a number of individuals that state-sponsored actors may be targeting their iPhones.

You have to install the profile before you turn Lockdown Mode on, after that it all works together nicely. www.glitchcat.xyz/p/four-thing...

3 weeks ago 2 1 0 0

What’s the issue?

3 weeks ago 0 0 1 0
Preview
Apple says no one using Lockdown Mode has been hacked with spyware | TechCrunch The tech giant's claim that it has not seen any successful spyware attacks targeting Apple devices with Lockdown Mode enabled comes amid a leak of hacking tools targeting users running devices with ol...

Apple’s Lockdown Mode feature is the best defense we have against spyware on iOS, macOS, watchOS, and iPadOS. Apple launched the feature four years ago and has not yet seen a device with Lockdown Mode on be compromised. techcrunch.com/2026/03/27/a...

3 weeks ago 55 32 1 1
Advertisement
Post image

We still don't know if Trenchant and L3Harris notified Apple once it learned its iPhone-hacking toolkit had been stolen/leaked. The toolkit was later used to target people in China and Ukraine. techcrunch.com/2026/03/09/a...

1 month ago 8 0 0 0
Preview
Russian Woman Who Drunk-Texted FBI Agent Pleads to Spying for FSB Nomma Zarubina heading U.S. prison for spying for Russian intelligence after a few tumultuous months in which her bail was revoked for harassing an investigator on her case.

Nomma Zarubina, who once drunk-texted an FBI agent saying "Catch me baby. So many spies," is heading to U.S. prison for spying for Russian intelligence. www.occrp.org/en/news/russ...

1 month ago 13 5 1 0
Post image

Worth noting that while the judge rejected the DOJ's request to search the devices seized from Washington Post reporter Hannah Natanson, they did decide that the court "will conduct an independent judicial review of the seized materials" instead. storage.courtlistener.com/recap/gov.us...

1 month ago 10 2 1 0
Post image

Huge win for Hannah Natanson and the Washington Post today: the judge ruled that the government cannot search the devices they seized from her. www.washingtonpost.com/national-sec...

1 month ago 204 59 6 1
Post image

Trenchant and L3Harris had an exec steal internal tools for three *years* — and sell them to a Russian broker — before anyone noticed. cyberscoop.com/l3harris-exe...

1 month ago 6 2 0 1

Thank you! Happy to chat anytime.

2 months ago 4 0 0 0
Preview
Prominent Angolan journalist targeted with Predator spyware An Amnesty International investigation has established that prominent, Angolan journalist, Teixeira Cândido was targeted with Predator spyware in 2024.

A new investigation from @amnesty.org found that a journalist in Angola was targeted with Predator spyware in 2024. We also know that @citizenlab.ca found links to Predator infrastructure in Angola in 2023, and links to FinFisher infrastructure in 2015. www.amnesty.org/en/latest/ne...

2 months ago 11 5 0 0
Preview
Not Safe for Politics: Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi - The Citizen Lab Following the widely-condemned arrest in July 2025 of prominent Kenyan opposition voice Boniface Mwangi, the Citizen Lab analyzed artefacts from devices seized during the arrest. We found that Cellebr...

Latest research from @citizenlab.ca shows @cellebrite.bsky.social tech used for human rights abuse in Kenya. Imagine if the company spent more time discussing who *not* to sell to. citizenlab.ca/research/cel...

2 months ago 15 4 0 0
Advertisement
Preview
Researcher skeptical of ‘Havana syndrome’ tested secret weapon on himself The CIA investigated a Norwegian government experiment with a pulsed-energy machine in which a researcher built and tested a “Havana syndrome” device on himself.

Two years ago, a Norwegian researcher skeptical that pulsed-energy weapons could do damage to human brains — aka “Havana syndrome” — built a device and tested it on himself. It didn’t go well. Someone from FFI, perhaps? www.washingtonpost.com/national-sec...

2 months ago 18 6 1 0

Decided to try Claude by revisiting a malware analysis project that I originally presented at OBTS in 2021: the CIA's OS X implant called Green Lambert. It's amazing what you can do with a terminal and ~15 min of free time these days.

2 months ago 21 1 1 0

My understanding is the emails are only encrypted if sent from one Proton user to another Proton user. So in that case they only have metadata to hand over.

2 months ago 3 0 0 0

Proton is required to comply with valid legal orders and has a track record of doing so.

2 months ago 4 0 1 0

The issue here isn’t Signal, but the use of biometrics on the work laptop.

2 months ago 2 0 0 0
Preview
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...

Former exec at exploit development firm Trenchant, owned by L3Harris, admitted to selling internal hacking tools to a Russian broker. Did the company notify the vendors whose products were exploited so that they could be patched? techcrunch.com/2026/02/11/d...

2 months ago 24 10 3 2
Preview
Russian Sandworm group attacks energy company in Poland with DynoWiper, ESET Research discovers ESET researchers identified new data-wiping malware that ESET named DynoWiper, used against an energy company in Poland.

Yeah, and this from ESET. www.eset.com/us/about/new...

2 months ago 1 0 0 0

Ah! I was going by work done by the ESET folks, but maybe they only linked Sandworm to parts of the attack?

2 months ago 1 0 1 0
Preview
The Story of Sandworm, the Kremlin's Most Dangerous Hackers For three years, WIRED has tracked the elite and shadowy Russian vanguard of cyberwar.

Russia’s Sandworm is back in the news, having recently been linked to the late December attack on Poland’s power grid. I recommend reading @agreenberg.bsky.social's work on the hacking group, starting with these WIRED articles and his 2019 book. www.wired.com/story/sandwo...

2 months ago 24 11 2 1
Advertisement

Correct. And because she had linked Signal on the phone to the desktop app, the FBI was able to access her messages.

2 months ago 1 0 0 0

If you've been laid off by the Washington Post this week and have any questions re: digital security, please email me on runa@granitt.io. I'll help you pro-bono for the rest of the month.

2 months ago 83 40 2 2
DEF CON 33 - Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings  - Andrew Logan
DEF CON 33 - Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings - Andrew Logan YouTube video by DEFCONConference

We’ve heard a lot about use of AI to clone the voices of celebrities, execs, and politicians. Here’s a @defcon.bsky.social talk from @helicoptersofdc.bsky.social about cloning the voices of air traffic controllers to give false instructions to pilots. www.youtube.com/watch?v=JKwx...

2 months ago 16 6 1 3

The issue here was not Signal, but the use of Touch ID for authentication. The agents were able to access her Signal messages because they were able to access the laptop, and she’d linked the mobile app to the desktop app.

2 months ago 3 0 1 0
Preview
FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled Lockdown Mode is a sometimes overlooked feature of Apple devices that broadly make them harder to hack. A court record indicates the feature might be effective at stopping third parties unlocking some...

The FBI has so far been unable to get into Washington Post reporter Hannah Natanson’s iPhone because it’s using Lockdown Mode — one of my favorite iOS features. You can turn it on for iPadOS, macOS, and watchOS too! www.404media.co/fbi-couldnt-...

2 months ago 54 21 0 0