The job market is already stressful enough without spending three hours trying to find that one career resource you remember me posting eight months ago.
So I put the useful stuff together.
Resume help.
Salary tools.
Interview resources.
Job-search systems.
Career guidance.
Black folks, save the Vault somewhere you can actually find it later.
https://t.co/lH2hXvsOaC
Introducing the US Gov Graph - a complete map of the people and positions of power in the federal government.
To fix our institutions we must understand how they work, so we are using AI to model and monitor every government in America. This is Palantir for The People.
Check it out here: https://t.co/bRXZfEt8ud
We exist to set the conditions for an era of civic excellence unmatched since the Founding. We will need nothing less to navigate the age of AI.
I'm looking for exceptional engineers and designers to work with me in San Francisco. If that's you, inquire here: https://t.co/8hpHt2MhVu. Self-governing civilization is counting on you.
1/
๐ข Your Conditional Access policies aren't protected by Conditional Access. Unless you turn this on.
There's a feature called protected actions that's worth knowing about. By default, an admin can edit or delete your CA policies using whatever auth they used at their last sign-in - which, under Entra's 90-day default sign-in frequency, could be weeks old.
Protected actions fixes this: Attach a CA policy directly to specific permissions (like creating, updating, or deleting CA policies themselves) so the action is challenged in real time, no matter which role granted the permission.
We now know the Iran war price tag is more like $50 billion - hundreds of dollars per household - and counting.
It's enough to cover all the health insurance premium credits that the Republicans got rid of for this year, and next. It could save rural hospitals, pay teachers, fix roads.
Don't let this White House insult your intelligence by blowing your money on war, then saying America can't afford nice things.
DocuSign Personal: $10 to $15 per month.
DocuSign Standard: $25 to $45 per user per month.
DocuSign Business Pro: $40 to $65 per user per month.
A 10-person team on Business Pro pays $4,800 to $7,800 a year. To put signatures on PDFs.
A team of 50 pays $24,000 to $39,000 a year.
And there is a 100-envelopes-per-year cap on most plans. Send more contracts and you pay extra.
Need SMS delivery? $0.40 per send.
Need ID verification? $2.50 per attempt.
Need premium support? $5,000 to $50,000 per year add-on.
You are rationing digital signatures in 2026.
DocuSign is a $10 billion company built entirely on this pricing model.
Now meet DocuSeal.
A free and open source alternative to DocuSign.
Created in 2023 by a Ruby developer named Alex who was simply trying to sign one document and realised every solution online was overpriced or required a subscription.
Three weeks later he had a working alternative. He pushed it to GitHub under the AGPL-3.0 license.
Today it has 11,800+ stars and over 1,000 forks. Bootstrapped. No VCs. No paywalls.
Here is what DocuSeal does:
- Upload any PDF and turn it into a fillable, signable form
- Drag and drop signature fields, dates, checkboxes, file uploads, and 13 field types
- Send to multiple signers with custom signing order
- Automated email reminders
- Mobile signing on any device
- PDF signature verification built in
- Audit trail for every document
- Bulk send and templates
- Full API access
- Self-host with one Docker command
Here is what DocuSeal costs:
Zero. Forever. Unlimited documents. Unlimited signers. Unlimited storage.
DocuSign limits envelopes. DocuSeal doesn't.
DocuSign charges per SMS. DocuSeal doesn't.
DocuSign charges for ID checks. DocuSeal doesn't.
DocuSign sees your contracts on their servers. DocuSeal doesn't.
Here is the wildest part:
The median DocuSign contract per Vendr is $17,250 per year. One Reddit thread has people saying "they want me to pay $4.80 per e-signature."
Self-host DocuSeal on a $5 cloud server and a 50-person team can sign as many contracts as they want without paying a single dollar.
Your contracts never leave your server. Your client lists. Your NDAs. Your employment agreements. None of it touches a third-party company.
For individuals who only sign a few contracts a year, you save $180.
For small teams of 10, you save up to $7,800 a year.
For a 50-person company, you save up to $39,000 a year.
Your documents. Your signatures. Your server.
100% Open Source. (Link in the comments)
Age verification sounds reasonable until you realize it means every adult hands over their ID just to go online.
We wrote about why this is a terrible idea and what should happen instead.
https://t.co/vj0bjwHn1J
Itโs absurd that American authorities can purchase personal data โ that theyโre not allowed to gather themselves without a warrant โ directly from data brokers. This violates the Fourth Amendment, and itโs time to close the data broker loophole.
Today, @RepThomasMassie, @RepBoebert and @naomibrockwell at the @LudlowInstitute introduced the Surveillance Accountability Act. It requires warrants based on probable cause for all government surveillance and data access. You can read more about it at https://t.co/iFX17ELSLA
Tools the internet doesn't want you to find ๐
1. Shodan
A search engine for internet-connected devices. You can find cameras, servers, and routers exposed online.
2. Archive. ph
Saves a permanent snapshot of any webpage. Useful when articles go behind paywalls.
3. Similarsites
Enter any website and instantly find dozens of similar ones. Great for discovering alternatives.
4. Mailtrack
Shows you when someone opens your email. You see the exact time it was read.
5. Hunter. io
Type in a company name and it finds employee email addresses linked to that domain.
6. Photopea
A free Photoshop that runs entirely in your browser. No download needed.
7. 12ft .io
Removes paywalls from most news articles. Just paste the link and read for free.
8. Carbon
Turns your code into beautiful shareable images. Popular among developers.
9. Explainshell
Paste any Linux command and it explains exactly what every part does.
10. Tineye
Reverse image search that shows where a photo has appeared on the internet.
11. Namecheckr
Check if a username is available across all social media platforms at once.
12. Untools
A collection of thinking frameworks and mental models to help you make better decisions.
13. BuiltWith
Shows the exact technologies, tools, and software any website is built with.
14. GeoGuessr
Drops you anywhere in the world on Google Street View. You guess the location.
15. Virustotal
Upload any file or paste any link and it scans it with over 70 antivirus engines instantly.
๐ Secure Bits ๐ก
๐ฌ๐ผ๐๐ฟ ๐๐ฒ๐ป๐ฎ๐ป๐ ๐ต๐ฎ๐ ๐๐ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป. ๐๐๐ฒ๐ฟ๐ ๐ฎ๐ฑ๐บ๐ถ๐ป ๐ถ๐ ๐น๐ผ๐ฐ๐ธ๐ฒ๐ฑ ๐ผ๐๐. ๐๐ผ ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐ฎ ๐๐ฎ๐ ๐ฏ๐ฎ๐ฐ๐ธ ๐ถ๐ป?
Most organizations donโt โ or think they do, until they discover their break-glass accounts are untested, unmonitored, or built on outdated guidance. You donโt want to find that out the hard way, and you definitely donโt want to go through Microsoftโs Tenant Recovery process.
๐ค ๐ช๐ต๐ ๐ฐ๐ฎ๐ฟ๐ฒ?
A lockout from a bad CA policy, a compromised admin, or a personnel emergency means opening a support ticket with Microsoft and waiting. In urgent situations, you donโt have 14 days for that process.
๐ง ๐ช๐ต๐ฎ๐ ๐๐ฒ ๐๐ฒ๐ฒ ๐ถ๐ป ๐๐ต๐ฒ ๐ณ๐ถ๐ฒ๐น๐ฑ
โข๐๐ฟ๐ฒ๐ฎ๐ธ-๐ด๐น๐ฎ๐๐ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐ ๐ฎ๐ฟ๐ฒ ๐บ๐ถ๐๐๐ถ๐ป๐ด โ Two geographically separated accounts is the baseline.
โข๐๐ฒ๐ป๐ฒ๐ฟ๐ถ๐ฐ ๐ป๐ฎ๐บ๐ฒ๐ โ admin@โฆ, info@โฆ are not break-glass accounts.
โข๐๐๐น๐น ๐๐ ๐ฒ๐ ๐ฐ๐น๐๐๐ถ๐ผ๐ป ๐ถ๐ ๐ฑ๐ฒ๐ฎ๐ฑ โ MFA is now enforced by Microsoft regardless.
โข๐ช๐ฒ๐ฎ๐ธ ๐ฎ๐๐๐ต ๐บ๐ฒ๐๐ต๐ผ๐ฑ๐ โ Phone or certificate-based auth will fail exactly when you need it.
โข๐จ๐ป๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ฒ๐ฑ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐ โ Any admin can edit or delete them.
โข๐ก๐ผ ๐บ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด โ If someone touches these accounts, you should know immediately.
๐ ๏ธ ๐๐ฟ๐ฒ๐ฎ๐๐ฒ ๐๐๐ผ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐
Use descriptive names on onmicrosoft[.]com with a random string โ e.g. [email protected]. Assign ๐๐น๐ผ๐ฏ๐ฎ๐น ๐๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ as a direct, permanent, active role. No eligibility.
๐ ๏ธ ๐๐ผ๐ฐ๐ธ ๐๐ต๐ฒ๐บ ๐ฑ๐ผ๐๐ป
Place both accounts and their group inside an ๐ฅ๐ ๐๐จ (requires Entra P1). Manage access via a custom PIM role โ max 1-hour activation, approval required, auth context enforced (requires Entra P2).
๐ ๏ธ ๐๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ ๐ฎ๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป
Scope a passkey profile to the break-glass group with specific AAGUIDs for your hardware keys (YubiKey, Token2). Enforce via a custom authentication strength in a dedicated CA policy. Exclude the group from all other CA policies โ run a What If to verify only your two break-glass policies apply.
๐ ๏ธ ๐ฆ๐ฒ๐ ๐๐ฝ ๐ฎ๐น๐ฒ๐ฟ๐๐ถ๐ป๐ด
Stream AuditLogs and SignInLogs to a Log Analytics Workspace (requires Azure subscription). KQL alert rule on the break-glass Object IDs โ any event fires immediately.
๐ก๏ธ ๐ฆ๐๐ผ๐ฟ๐ฒ, ๐๐ฒ๐๐, ๐ฑ๐ผ๐ฐ๐๐บ๐ฒ๐ป๐
Each passkey + PIN in a separate physical location. Define who can trigger the procedure and under what circumstances. Test end-to-end at minimum every 180 days โ Microsoft recommends 90. Pick your cadence, but validate.
๐ฌ When was the last time you tested these accounts?
๐๐ถ๐๐ฉ๐ฐ๐ณ: Martin Strnad
PS: We will soon ๐ฝ๐๐ฏ๐น๐ถ๐๐ต ๐ณ๐๐น๐น ๐ด๐๐ถ๐ฑ๐ฒ on this topic!
#EntraID #IdentitySecurity #ConditionalAccess #SecureBits #HorizonSecured
We are very happy that today Apple issued a patch and a security advisory. This comes following @404mediaco reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.
Appleโs advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release. You can read more here: https://t.co/yE8ufSTQHk
Note that no action is needed for this fix to protect Signal users on iOS. Once you install the patch, all inadvertently-preserved notifications will be deleted and no forthcoming notifications will be preserved for deleted applications.
Weโre grateful to Apple for the quick action here, and for understanding and acting on the stakes of this kind of issue. It takes an ecosystem to preserve the fundamental human right to private communication.
Age verification is moving off websites and into your operating system (yes, even you, Linux).
California just passed a law requiring it. The UK already has it. More states are following.
Here's why that's a much bigger deal than it sounds. ๐งต
1/6
What I learned from 1,000 hours of internal pentesting in 2025.
- LAPS is not as common as youโd think
- The built-in domain Administrator account is often misused as a service account
- Flat, non-segmented networks are the norm
- Too much stock is put into EDR alone
- File shares are never checked for credentials
- Many IT admins donโt know they have ADCS
I could go on.
On the bright side, I truly believe these are some of the most solvable IT security issues.
If we canโt eliminate credentials from shares how do we expect to defend against more serious issuesโฆ
Curious what else I see during internal pentest? I wrote more about this on my blog.
Read more: https://t.co/Qc49zMhil9
๐จ Top 5 Live Intelligence Dashboards You Should Be Watching
If you're tracking cyber threats, geopolitical tensions, or OSINT signals in real time, these platforms provide a powerful โsingle pane of glassโ into whatโs happening globally:
๐ LiveUAmap โ Real-time conflict and geopolitical event tracking
๐ https://t.co/HV7wR0jxD4
๐ GDELT Project โ Global event monitoring powered by AI across dozens of languages
๐ https://t.co/Y3468LUhoI
๐ WorldMonitor โ Live global incidents, disasters, and security alerts
๐ https://t.co/1qMzK0Dtaq
๐ก๏ธ SOCRadar Cyber Conflict Dashboard โ Focused cyber threat intelligence (IranโIsrael context)
๐ https://t.co/d4MNtnQ1OM
๐ง Pizzint โ OSINT-driven monitoring of leaks, dark web activity, and threat signals
๐ https://t.co/GutduD8Bif
These dashboards highlight how OSINT + real-time data + visualization are reshaping situational awareness for both cyber and physical threats.
๐ If you know other high-quality live intelligence dashboards, drop them in the comments โ always looking to expand the list.
#OSINT #CyberThreatIntelligence #ThreatIntel #Geopolitics #DarkWeb #CyberSecurity #DDW #InfoSec #OpenSourceIntelligence
Discord is secretly running at Real Time priority on your PC.
This causes frametime spikes in CS2, Valorant, and basically every competitive game.
Fix: Task Manager โ Details โ Discord.exe โ Set Priority โ Normal
One change. Instant smoother gameplay.
Scientists just cracked the multiple sclerosis code after decades of searching.
Two specific gut bacteria are triggering the disease, and they've proven it using identical twins and mice.
This changes everything we know about MS:
THE WHEELS ARE FULLY TURNED AWAY FROM THE OFFICER.
Watch in SLOW MO.
No intention IMO to hit anyone.
Sole intention based on wheel/steering wheel to LEAVE the scene
NOT A THREAT.
Look at the wheel.
๐จWARNING: GRAPHIC VIDEO
This is video showing the ICE agent shooting a woman in the face as she attempted to leave.
This is disgraceful, horrific, and must be denounced by ALL.
In a few days, you may be notified that your health insurance premiums will double, because of Republican cuts to health care. Democrats are fighting to change that before it's too late.
So far, Republicans would rather shut down the government. So Americans face flight delays, reduced services, and mounting economic damage.
It's time for Trump and Republicans to change course on health care and reopen the government.