Advertisement Β· 728 Γ— 90

Posts by John Hammond

Post image

Joined by Katrina Manson to hear all about her latest book release: Project Maven & the Dawn of AI Warfare πŸ‘€

We talk AI usage at the Pentagon, drone intel, AI enabled targeting, and the ethical tipping point of autonomous weapons. Super fascinating ideas. Video: youtu.be/OVgruylpVXc

1 hour ago 1 0 0 0
Post image

Wild story on a big AI-powered social engineering campaign, leveraging Device Code phishing to steal Entra ID/Microsoft accounts -- all with entirely unique and personalized per-victim lures from vibecode-crafted infrastructure 🀯 Video: youtu.be/9b3kirR8s2U

1 week ago 2 3 0 0
Post image

Real treat to catch up with Joe Tidy and hear more behind the scenes deets about his book Ctrl+Alt+CHAOS: How Teenage Hackers Hijack the Internet 🀩 Insight into "the most hated hacker in history" and the rise and fall of teenage hacking gangs. Video: youtu.be/GUzD_ShRKYE

1 week ago 5 0 0 0
Post image

Fake Windows notifications -- homage to iPurpleTeam and their sweet recent writeup, showcasing some tricks with toast popups in pure PowerShell to fake alerts from installed apps found in Registry. Even a low-privilege custom protocol handler! Video: youtu.be/wrAFZLa1TAk

2 weeks ago 4 1 0 0
Post image

Our virtual event endeavor is back for its round-two show -- ContinuumCon 2026! Banner mantra "The cybersecurity conference that never ends" 😜 All sessions are workshops and you keep a whole cyber range to work on them whenever you want. jh.live/continuumcon Main eventlivestream is June 12-14th!

2 weeks ago 1 0 0 0
Preview
Welcome | authentik Bring all of your authentication into a unified platform.

I've actually used authentik to manage identities in a self-hosted local environment before, so was really happy to hang out and see it even more in action. Thanks Fletcher!! πŸ˜„See their sweet stuff: jh.live/authentik

2 weeks ago 0 0 0 0
Post image

heyyyyyy In case you missed it, I got to chat with Fletcher Heisler about the cool stuff he's been cooking up with @authentik ! And I met Fletcher at BsidesSF -- really awesome guy 🀩😊 Video: youtu.be/2ttrqnw5kDE

2 weeks ago 3 0 1 0
Post image

If you're waking up to the Internet and your world on fire from the new NPM and axios package supply chain attack, I have a short 15 minute video to hopefully catch you up to speed. Links to further resources included -- video: www.youtube.com/watch?v=A58c...

3 weeks ago 15 3 1 0
Advertisement
Post image

Vibecoding -- err... 🌈 AI assisted programming ✨ -- a "ChatGPT for the dark web!" Natural language chat interface backed by threat intel API, for a Golang tool with a TUI (in spirit of the current command-line coding harnesses 😜). Fun project. Video: youtu.be/oqU41QwtAGE

1 month ago 6 1 1 0
Post image

NahamSec teaches me bug bounty basics! He fills me in on the platforms, programs, and how the scope has grown so much now. Ben walked me through threat modeling and had a slick demo of his real-world bugs found with Red Bull and others 😎 Video: youtu.be/lNuvI48ysVo

1 month ago 6 1 0 0
Post image

GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🀩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🀯 Video: youtu.be/qEtoKC32UoE

1 month ago 3 0 0 0
Post image

The recent Trezor-physical-mail-phish-delivery-crypto-scam made me giggle -- so I rambled about it in a video. I'm not a crypto guy but alarm bells should probably go off in your mind when something is asking for your recovery seed phrase. πŸ˜… Video: youtu.be/UQFySFs2GJk

1 month ago 1 0 0 0
Post image

I've made some updates and added 2 hours worth of new material to the "Linux for Hackers Fundamentals" course on @hackinghub_io ! Vim text editor basics and sed & awk for text processing. Here's a 40% off discounted link if you'd like to take a peek :) hhub.io/Linux2026JH

1 month ago 6 0 0 0
Post image

h?ckers a[r]e gl*bbing!
A little showcase of @0xv1nx0 's neat new project LOLGlobs -- demo is a teeny weeny PowerShell download cradle, obfuscated with globbing tricks and used with some 'living off trusted sites' just flair for funzies too :)
Video: youtu.be/IImLVU39V_Q

1 month ago 5 1 0 0
Post image

Google API keys didn't use to be considered "secret," so they're all over the web-- but now they are an open door to Gemini 🫠 Quick rundown video of Truffle Security's really nifty research, almost 3,000 websites exposed.. including Google themselvesπŸ˜…
πŸ”— youtu.be/XNMHUifKce8

1 month ago 8 1 0 1
Post image

Quick dance with CVE-2026-21509, a "Security Feature Bypass Vulnerability" and an emergency out-of-band fix from January Patch Tuesday (and an obligatory exaggerated YouTube thumbnail -- I apologize and appreciate folks who understand algorithm nuance) youtu.be/Ck8IPInn74A

2 months ago 4 1 0 0
Post image

"TikTok needs to fix this vulnerability" -- video: youtu.be/djhX8Q4JuFU

2 months ago 1 0 1 0
Post image

"AI wrote a hit piece." Video: youtu.be/RP-zs6J6ySw

2 months ago 46 10 0 5
Advertisement
Post image

Super quick video of the Sinobi ransomware gang fail from a few days ago, because the story made me laugh πŸ˜… I'm trying to get in a groove of shorter videos, and I thought this this fit. Video: youtu.be/OwTV42GyRnk

2 months ago 7 0 0 0
Post image

Moltbook is still weird. And external AI skills suck.
I'm late to the yap party by a week or so (which is apparently an eternity in the current time vortex) but I wanted to show cool community resources & research amongst the skills shenanigans. Video: youtu.be/IvL89vbWmQ8

2 months ago 6 2 0 0
Post image

February got here fast-- and the 2026 Snyk Fetch the Flag CTF came up quick too! This year my friend NahamSec is hosting the game, starting NEXT THURSDAY 2/12 at 12pm ET! Free 24-hour Capture the Flag event with AR glasses as prizes 😎 See ya there! jh.live/snyk-ftf2026

2 months ago 6 3 0 0
Preview
Cyber & Dev #2: MCP This blog post is meant as supporting material to go along with a video I am making on the same topic (will provide a link when that goes live). This is part of a series I’m doing to help give people…

Also, meme thumbnail experiment continues. Disaster girl feels appropriate when AI might burn down your codebase.

This is the first time Zack and I got to hang out and chat, please show him and his writeup some love! All credit to him and his work -- his blog: zkorman.com/posts/cyberd...

3 months ago 1 0 0 0
Preview
Cyber & Dev #2: MCP This blog post is meant as supporting material to go along with a video I am making on the same topic (will provide a link when that goes live). This is part of a series I’m doing to help give people…

I for one am totally guilty of just throwing caution to wind and poking at the newfangled whizbang AI world with reckless abandon -- but whatever "black box" we tout it to be, there's stuff you don't notice and forget that just you accepted the risk.

3 months ago 1 0 1 0
Post image

Are MCP servers safe and secure? Yes? No? Sometimes? Maybe? ... Zack Korman shows me some of his learnings on MCP security (or lack thereof) with his "Evil MCP" project 😈 YouTube link: youtu.be/_r_sLetar_o

1. data exfil of your prompts & code context
2. inserting vulnerabilities into your code

3 months ago 1 0 1 0

Feels good to get something out the door again. I hope you take a look! YouTube link: youtu.be/Mw8DVcLSZIc

3 months ago 0 0 0 0

I'm experimenting with MEMES in the THUMBNAIL and SHORT video TITLES to MITIGATE against CLICKBAIT

Also experimenting with longer social text promos for video releases to add more preview details and context. I no longer have to just feed algorithms, but now LLMs, too!

3 months ago 0 0 1 0

No Registry writes, API calls or registry callbacks because it's just a single file placed on disk! Kinda neat.

This is my first recording after a month break for the holidays and it was _painful_ -- lots of fails and mistakes and it took many hours πŸ˜…

3 months ago 0 0 1 0

3. exporting, downloading, and hijacking an existing target user profile NTUSER.DAT or HKCU Registry hive,
4. converting hives from .reg plaintext to binary with the HiveSwarming.exe tool,
5. and establishing persistence with the new backdoored NTUSER dot MAN profile we upload!

3 months ago 0 0 1 0
Advertisement
Post image

Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thingπŸ‘€ Hat tip to DeceptIQ et al.... we showcase:

1. breaking a Windows login with an empty user profile,
2. getting initial access EZPZ with a Sliver C2 implant,

3 months ago 5 0 1 0
Post image

"'ConsentFix', a browser-based ClickFix-style attack with OAuth consent grants" ... leveraging the Azure CLI app client to social engineer for easy access into Entra ID πŸ‘€ I got nerdsniped by this, so I played with it a bit and tried a drag-and-drop gesture! Video: youtu.be/AAiiIY-Soak

4 months ago 11 3 0 0