Did you know there's a type of phishing attack that defeats MFA completely.
It's called a reverse proxy phishing kit and it's one of the fastest-growing attack techniques in cybersecurity.
Traditional phishing works by using fake login page. you type your password. attacker gets it. if you have MFA enabled, the stolen password alone is useless. attacker gets stopped at the second gate.
reverse proxy is different.
instead of a fake page, the attacker sets up a live proxy server between you and the real website. when you click the phishing link, you connect to the attacker's server. the server connects to the real Microsoft, Google, or Okta on your behalf. it fetches the real login page and serves it directly to you, pixel for pixel in real time.
you're looking at the actual login page. you type your real password. the proxy relays it to Microsoft. Microsoft sends back an MFA prompt. the proxy relays that to you. you approve it. Microsoft sends back a session cookie.
the proxy intercepts the cookie before it reaches your browser.
You're logged in, so is the attacker using the same session.
Tools used: Evilginx, Modlishka, Muraena. all open source. all free. all with pre-built templates for Microsoft 365, Google Workspace, Okta, and PayPal.
commercial versions: EvilProxy, Tycoon 2FA, Mamba 2FA, Starkiller. Sold as subscription services on Telegram.
Reverse proxy phishing surged 139% between September 2025 and March 2026, nearly 1 in 4 phishing links now carries a reverse proxy payload.
18 US universities hit last year. Microsoft 365 campaigns targeting thousands of organizations globally.
The only authentication method that stops this completely: FIDO2 passkeys and hardware security keys. They bind credentials to the real domain. The proxy can't replay them because the credential was never issued for the proxy's domain.
Everything else, SMS codes, authenticator apps, push notifications can all be relayed.
> walk around your city catching pokémon
> game asks you to scan a fountain. sure why not
> 30 billion scans later
> niantic owns a more detailed map than any government
> sells game for $3.5B
> spins off a spatial AI company
> your pokéwalk is now classified infrastructure
> delivery robots now navigate using your walks
> you were never the player. you were the product.
We all knew this was coming… but today I heard about it actually happening.
A seed stage company backed by a well known VC openly admitted (in a board deck) that their strategy is to get access to a large incumbent’s software from a customer, clone the entire thing using Claude Code, and offer it at 90% less.
Not “build something better.�� Just copy it and offer it for less.
The VC endorsed this as the GTM strategy. And even wrote back in writing that it was a good idea.
Using a customer’s licensed access to reverse engineer a product and clone it is ethically bankrupt. I don’t know how else to put it.
It likely violates terms of service. It may violate trade secret law as well (but I’m certainly not a lawyer).
And a reputable VC putting this in writing in a board deck is genuinely insane.
But it’s going to happen anyway.
Everywhere… all the time.
I don’t know where this ends, but we all knew this was coming and now it’s here.
Ring paid somewhere between $8 and $10 million for a 30-second Super Bowl spot to tell 120 million viewers that their cameras now scan neighborhoods using AI.
The math is wild. Ring has roughly 20 million devices in American homes. Search Party is enabled by default. The opt-out rate on default settings in consumer tech is historically around 5%. So approximately 19 million cameras are now running AI pattern matching on anything that moves past your front door. Today the target is dogs. The same infrastructure already handles “Familiar Faces,” which builds biometric profiles of every person your camera sees, whether they know about it or not.
Ring settled with the FTC for $5.8 million after employees had unrestricted access to customers’ bedroom and bathroom footage for years. They’re now partnered with Flock Safety, which routes footage to local law enforcement. ICE has accessed Flock data through local police departments acting as intermediaries. Senator Markey’s investigation found Ring’s privacy protections only apply to device owners. If you’re a neighbor, a delivery driver, a passerby, you have no rights and no recourse.
This tells you everything about Amazon’s actual product. The customer paid for the camera. The customer pays the electricity. The customer pays the $3.99/month subscription. And Amazon gets a surveillance grid that would cost tens of billions to build from scratch, with an AI layer activated by default, and a law enforcement pipeline already connected.
They wrapped all of that in a lost puppy commercial because that’s the only version of this story anyone would willingly opt into.
DON'T UPLOAD YOUR FAMILY PHOTOS TO AI
DON'T UPLOAD YOUR FAMILY PHOTOS TO AI
DON'T UPLOAD YOUR FAMILY PHOTOS TO AI
DON'T UPLOAD YOUR FAMILY PHOTOS TO AI
DON'T UPLOAD YOUR FAMILY PHOTOS TO AI
the grok bikini thing everyone's talking about is just the visible tip of something way darker...
this is the start of a new era where everything you've ever posted online becomes a weapon that can be used against you
and i need you to understand how serious this actually is
we're not talking about photoshop anymore, we're talking about AI models and people that can take any photo of you and generate you in any situation, any context, any scenario someone wants to create
every image you've posted, every video where your face is visible, every public moment you've shared... it's all training data now
here's what makes this different from anything we've seen before:
even if grok gets updated to refuse these requests tomorrow, even if every major AI company builds in restrictions...
it's too late
people already have access to open source models that can do the same thing, models that run locally on their computers with zero content policies, zero restrictions, zero way for anyone to stop them
think about what that actually means for you:
> your social media history is now a library of raw material for anyone who wants to manipulate your image
> your professional photos can be placed in compromising situations you never agreed to
> your vacation pics, your family photos, your casual selfies... all of it can be used to create content that looks completely real
and there's no way to go back from this point, the technology is out there, fully distributed across thousands of computers, impossible to contain or control
more than ever before, you need to be extremely careful about what you post online moving forward
everything you post online will 100% be used against you at some point, whether that's next month or ten years from now
i don't wanna be fear mongering, this is the new reality we're living in and most people still don't understand how serious it is
Uncomfortable truth nobody admits - most parents are relieved when school resumes. And this is not exhaustion, it is conditioning. Public education and modern work have trained families to function apart, not together.
When prolonged time at home finally arrives, the discomfort is immediate. We have outsourced formation, structure, and even companionship to institutions, and the family is left without the habits required to sustain itself. What feels like a personal failure is actually systemic. This isn’t a dig at any parents out there. It is a critique of modernism.
"RemoveWindowsAI" is a script created by zoicware, available on GitHub, that does exactly what it says: it remove every AI feature in Windows 11. Do what you wish to do with this information. https://t.co/aVHJElTYh5
Social media companies would love for you to spend all weekend online. I hope instead you'll log off, visit friends, read a classic, tramp through woods resplendent with crimson foliage. Time spent cultivating a hobby or passion is never wasted, for your time is your life.
🚨🚨Breaking: Sam Altman’s OpenAI has decided to eat it’s own cooking and will be replacing the Board, the C-Suite & himself with AI chat bot tools saving the company money and sparing the public from enduring endless lies and BS from unhinged carbon units.
This will set an example for the rest of the Fortune 500!
🤣
I don’t know if it’s just a millennial and Gen-X thing because we’re the ones who lived through both the analog world and the ever-advancing digital age, but I feel like a lot of us are carrying this quiet, unspoken grief.
Grief for a slower, more reality based life we once knew.
Everything’s changing so fast. The world around us is becoming almost unrecognizable. And with it, so is our sense of what it even means to be human. The digital age is slowly suffocating something deep and sacred within us.
Last chance to turn it off.
On Monday, November 3rd, Microsoft will start using your LinkedIn data for AI training. And remember, you're opted in by default.
To toggle it off 👉 Account - Settings & Privacy > Data privacy > Data for Generative AI Improvement.
Last night I stumbled on a discussion forum from 2018 and it made me nostalgic for a time when all writing on the internet was human writing. I've come to value messy, mediocre writing. I'd rather read your imperfect thoughts than all the bland, soulless drivel produced by AI.
This is the golden age of AI. It won't last long. Right now AI is wiping out search engines and a lot of jobs. But once AI has a monopoly it will be rigged to serve its owner's agenda. Then we're really screwed.
ChatGPT Atlas isn’t just another browser: it watches, infers, and acts on your behalf. Worryingly, there are still many open questions about how this product protects user data.
If you're curious about what that means for privacy, read on…
1/8