Offline Vaults + Device Pinning for Proton Pass = real data sovereignty.
Local-only storage, no forced cloud sync.
A must-have for high-risk + privacy-focused users.
Your move, @ProtonPrivacy. 🔐
EXCLUSIVE: How the track foreigners in China - We got rare access to demo system developed by the Ministry of Public Security in China for the prefecture of Zhangjiakou, to track and surveil foreigners visiting or being residents ( actually it applies to most nationals as well, but in this case it seems to be aimed at foreigners ). It is officially known as "Dynamic control platform for overseas personnel". 1/12
how to set up your Hermes Agent control room
send this image + the repo below to your agent and it will configure itself based on the blueprint
https://t.co/Bb2nEm96i8
this is the same architecture I use to run specialist agents across both my agencies
🤓 How many times did you questioned yourself about a claims in a threat report?
The "Trust me bro" is not always reliable!
The Admiralty System also known as the NATO System, is a method used to evaluate collected intelligence.
I created an Agent Skill for it!
Mini thread👇
The known activity and capabilities of three Access-as-a-Service firms – Israel’s NSO Group, Russian contractor ENFER, and the UAE firm DarkMatter – show how offensive cyber capabilities proliferate, and how we can shape & limit them. Read more here: https://t.co/wdongdvmL8
Huh.
Am I the only one who didn't know that Microsoft makes a tool called EventLogExpert that is supposed to be an improved version of event viewer for IT/helpdesk people?
https://t.co/HzSzG1zSO0
Sci-Hub is an evil website that pirated 85M+ research papers and made them freely available
And now they've added AI to their database to make Sci-Bot.
It answers your questions using latest, full-text articles.
But DO NOT use it. We should all try to make billion-dollar academic publishers richer.
I'm putting the link below so you know how to avoid it.
Here's a cool trick for y'all looking to create new Nuclei templates for exploitable CVEs!
Using CVEmap you can get a list of CVEs with public proofs of concept, that have been marked as exploitable by CISA, are remotely exploitable AND don't have a Nuclei template (yet)!
Flags:
-k / -kev: Marked as exploitable vulnerabilities by CISA
-t=false / -template=false: Has no public Nuclei templates
-poc: Has public published POC
-re / -remote: is remotely exploitable
Good luck! 🤞
#nuclei #hacking #pentesting #bugbounty #CVEmap
[1/7]I've spent the last several years researching declassified CIA records for two books on Cold War intelligence operations. Along the way, I built a tool I wish had existed when I started.
It's called Intelligence Archive. https://t.co/MNRvvE0Z0K
#Sandworm group leverages nested SSH-TOR tunnels to build a double-encrypted anonymous direct elevator between victims and attackers.
This highly evasive attack enables unrestricted sensitive data theft and persistent remote control.
https://t.co/YkHn7CWCaC
New Blog Post: How browser exploits actually work on iOS – written for beginners who've never read a browser exploit writeup. We use Google's DarkSword chain as a case study to explain Safari's JIT, the PAC bypass, and how attackers escape the WebContent sandbox. No prior knowledge needed.
https://t.co/Uswat1TEka
Stay updated with @8kSec for more blogs like this
The CIA ran a psychic spy program during the Cold War. I got my hands on the original documents … and was blown away by what they achieved. Science has no way of explaining this.
Project Stargate is a program that lasted over two decades which used remote viewing to gain military intelligence. Viewers sit in a dark room, are given nothing but an anonymized reference number — a hash corresponding to a military target — and try to psychically “tap into” the target. They draw out whatever sensory signals they receive to be analyzed later.
I thought this was all voodoo nonsense, a complete psy-op, until I spent a few days digging through the original, declassified files now housed at Rice university. The amount and accuracy of successful “hits” (see next tweet for examples) were uncanny. The personnel leading the program were secular physicists. This is not something that can be explained away by sheer chance.
What’s even weirder is that the Soviet Union and China had (have?) their own psychic military units! Behind the well-known spy battles of the Cold-War was a secret game of psychic espionage and counter-espionage.
But the Soviet Union were communists, and communists are materialists. How did a materialist superpower legitimize starting a psychic division within their intelligence apparatus? They disliked even psychoanalysis for not being “materialist” enough. It turns out that there is a heated and fascinating philosophical debate about how remote viewing actually works, and even key leaders of the program on the American side remained materialists, convinced that there was a “physical” explanation. This is why Stargate is worth investigating today, for the philosophical “payoff” on fundamental questions of ontology.
In this episode, I will take you through the highlights from the original documents of Stargate and, more importantly, discuss what this means philosophically for the world we live in.
Timestamps:
2:12 The Best “Hits” from Stargate
9:36 Is Stargate a Psy-Op?
12:04 Why Christians Shutdown Stargate
15:01 Is Remote Viewing Nature or Nurture?
18:26 How Consciousness Influences Matter
21:07 How the Army Chose Remote Viewers
26:23 The Materialist Explanation for Remote Viewing
30:18 Remote Viewers Could See the Past
35:08 Why was Stargate Declassified?
🤓 I recently came across a nice post published on Feedly by Ondra Rojčík, who talks about the process of profiling threat actors using 5W1H and the Diamond Model.
I loved it. I wanted to incorporate it into my pipeline.
So I created an Agent Skill but not to generate another lengthy report that I will never read.
It actually creates a nice visual in no time using Claude custom visuals.
Check out what you can do with it. 👇
1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.
I spent long hours going through all of it, none of which has ever been publicly released.
It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion.
Enjoy the findings!
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at https://t.co/bGCIjBfD3C. Launched with:
- Malware Analysis Crash Course
- Go Reversing Reference
- Intro to TTD
Share this video with EVERYBODY
⇒ Go to your Sister, Father, Aunt & Grandpa. Show it to all of them!
The best explanation of what's wrong with the fiat system: