Sign in

AndrewMohawk

@andrewmohawk.bsky.social
212 followers 176 following 74 posts

Just another noob.

PostsRepliesMedia
AndrewMohawk @andrewmohawk.bsky.social · 18/08/2026
DC34 Badge hackin' andrewmohawk.com/2026/08/16/d... (for both flags) DC34 app to modify your badge colours: genemate.andrewmohawk.xyz Thanks @bunnie.org !
andrewmohawk.com
DC34: Badge hackin'
Hacking the DC34 badge: a shared loader-jump foothold, different temporary-Xous routes for K0 and Flag1, and an IFR instruction-reconstruction extension.
000
Reposted by AndrewMohawk
SentinelOne @sentinelone.com · 17/03/2026
$9 billion. That’s how much Crypto crime has amassed approximately in illicit funds. In this LABScon 2025 video, @privyio.bsky.social’s @andrewmohawk.bsky.social breaks down how attackers steal and launder billions through modern crypto ecosystems. 🧵👇
111
AndrewMohawk @andrewmohawk.bsky.social · 09/09/2025
Since i'm still on the hellsite, here is my thread on the NPM dependency issues: x.com/AndrewMohawk... But TL;DR there is so much FUD This would only impact you if -FRESH install between 9am-11.30am ET -OR Package-lock.json created in that time -Vuln packages in direct or transient dependencies
x.com
AndrewMohawk⁽ⁿᵘˡˡ⁾ on X: "Lot of chatter about the QIX NPM compromise. TL;DR -- Dev was compromised ~9am ET ( https://t.co/bgOwN57xyz ) -- Malicious packages removed at ~11.30 ET ( https://t.co/XApcXgcQoK ) If you installed in this time please check your codebase." / X
Lot of chatter about the QIX NPM compromise. TL;DR -- Dev was compromised ~9am ET ( https://t.co/bgOwN57xyz ) -- Malicious packages removed at ~11.30 ET ( https://t.co/XApcXgcQoK ) If you installed in this time please check your codebase.
021
AndrewMohawk @andrewmohawk.bsky.social · 24/07/2025
Feels so good to interact with the infosec community as a whole, I cant imagine why we have bad reputation as not being welcoming!
020
AndrewMohawk @andrewmohawk.bsky.social · 20/07/2025
expel.com/blog/poisons... pretty interesting using cross device sign in ( www.passkeycentral.org/design-guide... ) to bypass fido2 hurdle, effectively turning the hardware token into QR code and asking the user to scan it
020
AndrewMohawk @andrewmohawk.bsky.social · 24/06/2025
I made a submission!
030
Reposted by AndrewMohawk
Kym Possible @kympossible.bsky.social · 19/06/2025
My firstborn is trans 🏳️‍⚧️ nonbinary ⚧️ and a tattoo artist that now lives in California. They’re in Seattle for their brother’s graduation this week and brought their gear to give me a tattoo. There is a my other two tattoos are decorative but there is a meaningful story behind what I had them do. 1/
A blonde tattooed person tattooing the forearm of a woman
1251
Reposted by AndrewMohawk
David Buchanan @retr0.id · 05/06/2025
here's a framebuffer graphics demo (this has no practical purpose and I can't prove I'm not just like, playing a youtube video or something)
301281266
AndrewMohawk @andrewmohawk.bsky.social · 03/06/2025
Finally one of the models is useful to me. I give you my stance on WebAuthN. cc @Yubico (Everyone at orgs I work at has a 5C + 5C NFC for phone and your org should as well)
000
AndrewMohawk @andrewmohawk.bsky.social · 28/05/2025
Whats the worst that could happen?
000
Reposted by AndrewMohawk
Jake @tonymagoni.bsky.social · 12/05/2025
Its finders keepers for one of these f-18s right?
2940019
AndrewMohawk @andrewmohawk.bsky.social · 12/05/2025
@kurtopsahl.bsky.social just said "The journey to stronger opsec begins with reducing the number of steps" and I fucking love it.
011
Reposted by AndrewMohawk
Red Durkin @daedsider.bsky.social · 10/05/2025
She thinks the Library of Congress is like a local public library because it's got "Library" in the name and I can't emphasize enough that our country is being run by the stupidest people alive on the planet today.
161073228
Reposted by AndrewMohawk
Blaise Ulysse Bernard Collins @wittywebhandle.bsky.social · 11/04/2025
One Hole per beverage

A coke machine at a fast food place from befor the 2010s is shown next to a big green check mark

Unholy drink cloaca

A coke machine with a single dispenser and an screen for choice is shown
11481411833
AndrewMohawk @andrewmohawk.bsky.social · 07/04/2025
You wont know when I am absolutely destroying my docker swarm, but there will be signs.
000
AndrewMohawk @andrewmohawk.bsky.social · 03/04/2025
I got Manus access and errr.. its struggling with a docker project, but the filenames are hilarious! Manus.. its just like us!
000
AndrewMohawk @andrewmohawk.bsky.social · 03/04/2025
The life of crime is calling me!
020
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Another day, another 9.x critical vuln that bypasses authentication/authorization flow :( thehackernews.com/2025/03/crit... But dont worry it's just the kubes ingress-nginx and not the nginx ingress controller often used for kubes. Stay safe out there 🙃
thehackernews.com
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code execution.
000
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Meme stolen from @yaelwrites.com
171
Reposted by AndrewMohawk
Shane Harris @shaneharris.bsky.social · 24/03/2025
In 25 years of covering national security, I’ve never seen a story like this: Senior Trump officials discussed planning for the U.S. attack on Yemen in a Signal group--and inadvertently added the editor-in-chief of The Atlantic. www.theatlantic.com/politics/arc...
theatlantic.com
The Trump Administration Accidentally Texted Me Its War Plans
U.S. national-security leaders included me in a group chat about upcoming military strikes in Yemen. I didn’t think it could be real. Then the bombs started falling.
774165096441
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Found a cool animatronic eye 3D print and spent the weekend making it follow me around
341
AndrewMohawk @andrewmohawk.bsky.social · 21/03/2025
I really hate that this is the release details we get for a *9.1 critical vuln* in a common js stack: www.cve.org/CVERecord?id... I will be blocking all requests with the header `x-middleware-subrequest` rather than risk deploying a > 5pm release for something without any real details.
cve.org
Common vulnerabilities and Exposures (CVE)
010
AndrewMohawk @andrewmohawk.bsky.social · 21/03/2025
Tornado cash is back. home.treasury.gov/news/press-r...
home.treasury.gov
Tornado Cash Delisting
WASHINGTON — Based on the Administration’s review of the novel legal and policy issues raised by use of financial sanctions against financial and commercial activity occurring within evolving technolo...
000
AndrewMohawk @andrewmohawk.bsky.social · 21/03/2025
Vibe coding my own rust ui for the rayhunter ( github.com/EFForg/rayhu... )
121
AndrewMohawk @andrewmohawk.bsky.social · 13/03/2025
A short story in 4:
011
AndrewMohawk @andrewmohawk.bsky.social · 10/03/2025
Twitter is down! Maybe DOGE finally did something people agree with
000
AndrewMohawk @andrewmohawk.bsky.social · 09/03/2025
Looking at some of the other recent DPRK attacks I noticed docker being used with `--privileged` flag. I also know that on mac there is a current issue with docker ( github.com/docker/for-m... ) and the workaround is to move things to /Library/PrivilegedHelperTools/.
100
AndrewMohawk @andrewmohawk.bsky.social · 05/03/2025
Whats the best way for me to post things to both bluesky and the dark site whose name we do not mention?
220
AndrewMohawk @andrewmohawk.bsky.social · 28/02/2025
I put up a few words about the recent Bybit hack, I got so annoyed with companies shilling solutions or punching down. As a security community we should be and expect better. privy.io/blog/bybit-l...
privy.io
Privy Blog | On hindsight and risk assessment
010
AndrewMohawk @andrewmohawk.bsky.social · 23/02/2025
Reminder that bybit is not the first nor likely the last attack we will see using this method-similar to previous attacks: DMM ($308m, May 2024) WazirX ($230m, July 2024) Radiant ($55m, Oct 2024) medium.com/@RadiantCapi... www.fbi.gov/news/press-r... www.liminalcustody.com/blog/update-...
medium.com
Radiant Capital Incident Update
2024–12–06
021
Reposted by AndrewMohawk
The Tennessee Holler @thetnholler.bsky.social · 22/02/2025
WYOMING: “Thank you, Madam chairman.” “I prefer ‘Mister’ chairman.” “Well you all voted preferred pronouns cannot be compelled speech.”
1413400749537
AndrewMohawk @andrewmohawk.bsky.social · 10/02/2025
9gb? what exactly is going on with @burpsuite.bsky.social these days! I just restarted it and im browsing a local next js app!
120
Reposted by AndrewMohawk
Sonia Cuff @soniacuff.com · 01/02/2025
Rest in peace:
A grassy church graveyard which contains, in the foreground, a rectangular concrete slab inscribed with the words "IT SECURITY."
018430
AndrewMohawk @andrewmohawk.bsky.social · 01/02/2025
I dont often have to help someone secure outlook, mostly deal with Google workspace, but I found this guide really well done. Props to Australian Signals Directorate for actionable security. Gold security star. www.cyber.gov.au/sites/defaul...
cyber.gov.au
010
AndrewMohawk @andrewmohawk.bsky.social · 27/01/2025
www.cell.com/device/fullt... Okay I really want one.
cell.com
SpiRobs: Logarithmic spiral-shaped robots for versatile grasping across scales
SpiRobs morphologically replicate the logarithmic spiral that is ubiquitous in natural organisms. They are easy and fast to build across scales via 3D printing. They are actuated by cables, which allo...
000
AndrewMohawk @andrewmohawk.bsky.social · 21/01/2025
gist.github.com/hackermondev... Fun writeup on figuring out cloudflare traffic!
gist.github.com
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform - research.md
033
Reposted by AndrewMohawk
Ron’s Computer Videos 🧍‍♂️🖥️📼 @ronscompvids.bsky.social · 19/01/2025
I wonder how much of this is Luigi related?
2143
AndrewMohawk @andrewmohawk.bsky.social · 18/01/2025
This is simply a super useful free tool, if you are using github and not running this you are making life more difficult for yourself
010
AndrewMohawk @andrewmohawk.bsky.social · 15/01/2025
I will kill for these 3!
010
Reposted by AndrewMohawk
Jerry Chen @jcsalterego.bsky.social · 07/01/2025
why'd they name this app bluesky when Elders Scroll was right there
2587649629
Reposted by AndrewMohawk
posts inspector @pippy.bsky.social · 07/01/2025
for anybody wondering what the flag will look like if we added greenland as a state
a picture of the US flag with the map of greenland put on top of it
1452533161
Reposted by AndrewMohawk
Madeley @madeley.bsky.social · 07/01/2025
Being sentient is so weird. You run an electrical charge through some meat and suddenly anxiety exists.
492903410
AndrewMohawk @andrewmohawk.bsky.social · 07/01/2025
Nvidia really letting rip at CES2025! Damn, I want all their things
media.tenor.com
a man with glasses is holding a burning dollar bill and says ha
ALT: a man with glasses is holding a burning dollar bill and says ha
010
AndrewMohawk @andrewmohawk.bsky.social · 06/01/2025
Here. The elevators, the number order? 1,3,2,5,4 of course.
000
Reposted by AndrewMohawk
S🌟tella @havishaf.bsky.social · 02/01/2025
A simple way to let go of the past and redirect your negative energy is to add more cheese to your pasta
973404521
Reposted by AndrewMohawk
Cats and Fortunes @catsandfortunes.bsky.social · 02/01/2025
You'll feel much better once you've given up hope.
You'll feel much better once you've given up hope.
011
AndrewMohawk @andrewmohawk.bsky.social · 30/12/2024
Feature request for venmo: give us a random emoji option so service workers don't have to do this (or heck, pay people so they don't rely on tips!)
110
AndrewMohawk @andrewmohawk.bsky.social · 29/12/2024
The simpler times en.wikipedia.org/wiki/MOPy_fish
en.wikipedia.org
MOPy fish - Wikipedia
010
Reposted by AndrewMohawk
Filippo Valsorda @filippo.abyssdomain.expert · 22/12/2024
The TLS Protocol Version 1.0 RFC, January 1999, in ugly meme form.

Top text:
I am not a toy
I am not a Christmas present
I am a 30+ years commitment

Bottom text:
Please think hard before you give someone
an Internet standard this Christmas
61100213