I’m hiring a sr principal threat researcher. When big things happen on the internet, you’ll lead the threat research to hunt across our vast telemetry & write the threat briefs. Senior role w/ strong comms & collab experience.
https://t.co/MXe2nEHz4f
Today, we’re officially launching fully customizable multiview on @YouTubeTV.
Our @youtube teams made one of our most popular features even better. The new multiview builder gives you full control to mix and match live streams (including add-ons like @nfl Sunday Ticket), and build the personalized viewing experience you've been asking for.
A 77-year-old Ukrainian grandmother fleeing the war was spotted by a drone while walking alone under fire.
They sent a UGV to rescue her.
To avoid frightening her, the ground robot was covered with a blanket bearing the message:
"Grandma, get on."
@ImposeCost Generally I advocate for yes, but the reality is some degree of collaboration varying with consumer maturity/familiarity. CTI is accountable for collections IRL, so no buck passing. Only wholly applies if the consumer is providing consistent feedback, though. Generally speaking.
@ImposeCost Every end consumer has two very robust requirements: “tell me everything I need to know for my job” and “tell me everything I don’t need to know but could get me fired anyways.” Everything else is on us.
The Department of Justice, through U.S. Attorney Jeanine Ferris Pirro and Assistant Attorney General A. Tysen Duva of the Criminal Division, together with its partners, today announced a series of coordinated actions by the Scam Center Strike Force against Southeast Asian criminal organizations operating scam centers that have defrauded Americans of billions of dollars.
Read More Here: https://t.co/vxVgUlx8wC
@USAttyPirro@FBI@SecretService@USTreasury@StateDept
Had an interview with a “crypto” recruiter. We talked for about 40 minutes, and then they asked me to look at some code.
Their first instruction was to clone the repo. I didn’t. They seemed surprised, so I told them I wanted a moment to check whether it was safe first.
I ran a quick analysis with Claude.
Turns out the code had a backdoor. It would copy my environment variables and send them to a remote server.
The recruiter went speechless and ended the call pretty quickly.
Be careful who you talk to. Scammers are real.
Seeing western-based ransomware negotiators & incident responders deploying ransomware at victims & playing both sides of negotiation is sickening 🤮
21st century version of the 1990’s movie Backdraft
https://t.co/O69rz22NPu
It’s nice to fantasize about a comprehensive integration into CI/CD pipelines to the point where we all get to hold hands and sip daiquiris on the beach, but you are still a river of fire and brimstone away from that level of tool and patch adoption.
If your response to a highly competent, but imperfect and resource sensitive, vulnerability hunting tool is to conclude this favours *defence*, you and your networks are ngmi.
One does not bug hunt their way to a defendable network. AI does not change that.
If there are any Delve customers left on @ZackKorman’s list, this should be some sort of blunt force instrument. A brand new “How cooked are we?” metric.
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at https://t.co/bGCIjBfD3C. Launched with:
- Malware Analysis Crash Course
- Go Reversing Reference
- Intro to TTD
Our blog on the Axios NPM supply chain attacks. We are attributing the incident to a suspected North Korean threat actor we track as UNC1069. That actor is financially motivated and DPRK historically leveraged supply chain attacks to target crypto. https://t.co/F4dRfij58R
We are still looking at the axios supply chain compromise, but we’ve attributed it to UNC1069, a suspected DPRK actor, who we covered in a blog this February. They are financially-motivated and historically DPRK uses these incidents to target crypto. https://t.co/RIeOp14UNU
We want to hear from YOU 🫵 Got something you think would make a great talk at SLEUTHCON this year?
Full-talk speakers get a $500 honorarium, ALL speakers get the best swag!
Don't wait - submissions close April 17th at 11:59 (ET)! Learn more about our CFP and submit yours today
Hong Kong: On March 23, 2026, the Hong Kong government changed the implementing rules relating to the National Security Law. It is now a criminal offense to refuse to give the Hong Kong police the passwords or decryption assistance to access all personal electronic devices including cellphones and laptops. This legal change applies to everyone, including U.S. citizens, in Hong Kong, arriving or just transiting Hong Kong International Airport. In addition, the Hong Kong government also has more authority to take and keep any personal devices, as evidence, that they claim are linked to national security offenses. Read more: https://t.co/K5w2tETFu5