Sign in

AndrewMohawk

@andrewmohawk.bsky.social
212 followers 176 following 74 posts

Just another noob.

PostsRepliesMedia
AndrewMohawk @andrewmohawk.bsky.social · 18/08/2026
DC34 Badge hackin' andrewmohawk.com/2026/08/16/d... (for both flags) DC34 app to modify your badge colours: genemate.andrewmohawk.xyz Thanks @bunnie.org !
andrewmohawk.com
DC34: Badge hackin'
Hacking the DC34 badge: a shared loader-jump foothold, different temporary-Xous routes for K0 and Flag1, and an IFR instruction-reconstruction extension.
000
Reposted by AndrewMohawk
SentinelOne @sentinelone.com · 17/03/2026
$9 billion. That’s how much Crypto crime has amassed approximately in illicit funds. In this LABScon 2025 video, @privyio.bsky.social’s @andrewmohawk.bsky.social breaks down how attackers steal and launder billions through modern crypto ecosystems. 🧵👇
111
AndrewMohawk @andrewmohawk.bsky.social · 09/09/2025
Since i'm still on the hellsite, here is my thread on the NPM dependency issues: x.com/AndrewMohawk... But TL;DR there is so much FUD This would only impact you if -FRESH install between 9am-11.30am ET -OR Package-lock.json created in that time -Vuln packages in direct or transient dependencies
x.com
AndrewMohawk⁽ⁿᵘˡˡ⁾ on X: "Lot of chatter about the QIX NPM compromise. TL;DR -- Dev was compromised ~9am ET ( https://t.co/bgOwN57xyz ) -- Malicious packages removed at ~11.30 ET ( https://t.co/XApcXgcQoK ) If you installed in this time please check your codebase." / X
Lot of chatter about the QIX NPM compromise. TL;DR -- Dev was compromised ~9am ET ( https://t.co/bgOwN57xyz ) -- Malicious packages removed at ~11.30 ET ( https://t.co/XApcXgcQoK ) If you installed in this time please check your codebase.
021
AndrewMohawk @andrewmohawk.bsky.social · 24/07/2025
Feels so good to interact with the infosec community as a whole, I cant imagine why we have bad reputation as not being welcoming!
020
AndrewMohawk @andrewmohawk.bsky.social · 20/07/2025
expel.com/blog/poisons... pretty interesting using cross device sign in ( www.passkeycentral.org/design-guide... ) to bypass fido2 hurdle, effectively turning the hardware token into QR code and asking the user to scan it
020
AndrewMohawk @andrewmohawk.bsky.social · 24/06/2025
I made a submission!
030
Reposted by AndrewMohawk
Kym Possible @kympossible.bsky.social · 19/06/2025
My firstborn is trans 🏳️‍⚧️ nonbinary ⚧️ and a tattoo artist that now lives in California. They’re in Seattle for their brother’s graduation this week and brought their gear to give me a tattoo. There is a my other two tattoos are decorative but there is a meaningful story behind what I had them do. 1/
A blonde tattooed person tattooing the forearm of a woman
1251
Reposted by AndrewMohawk
David Buchanan @retr0.id · 05/06/2025
here's a framebuffer graphics demo (this has no practical purpose and I can't prove I'm not just like, playing a youtube video or something)
301281266
AndrewMohawk @andrewmohawk.bsky.social · 03/06/2025
Finally one of the models is useful to me. I give you my stance on WebAuthN. cc @Yubico (Everyone at orgs I work at has a 5C + 5C NFC for phone and your org should as well)
000
AndrewMohawk @andrewmohawk.bsky.social · 28/05/2025
Whats the worst that could happen?
000
Reposted by AndrewMohawk
Jake @tonymagoni.bsky.social · 12/05/2025
Its finders keepers for one of these f-18s right?
2940019
AndrewMohawk @andrewmohawk.bsky.social · 12/05/2025
@kurtopsahl.bsky.social just said "The journey to stronger opsec begins with reducing the number of steps" and I fucking love it.
011
Reposted by AndrewMohawk
Night of the Living Red Durkin @daedsider.bsky.social · 10/05/2025
She thinks the Library of Congress is like a local public library because it's got "Library" in the name and I can't emphasize enough that our country is being run by the stupidest people alive on the planet today.
161073228
AndrewMohawk @andrewmohawk.bsky.social · 23/04/2025
Friends, criminals, scoundrels, you rang?
020
Reposted by AndrewMohawk
Blaise Boo-lysse Bernard Collins @wittywebhandle.bsky.social · 11/04/2025
One Hole per beverage

A coke machine at a fast food place from befor the 2010s is shown next to a big green check mark

Unholy drink cloaca

A coke machine with a single dispenser and an screen for choice is shown
11481361832
AndrewMohawk @andrewmohawk.bsky.social · 07/04/2025
You wont know when I am absolutely destroying my docker swarm, but there will be signs.
000
AndrewMohawk @andrewmohawk.bsky.social · 03/04/2025
I got Manus access and errr.. its struggling with a docker project, but the filenames are hilarious! Manus.. its just like us!
000
AndrewMohawk @andrewmohawk.bsky.social · 03/04/2025
The life of crime is calling me!
020
AndrewMohawk @andrewmohawk.bsky.social · 25/03/2025
110
AndrewMohawk @andrewmohawk.bsky.social · 25/03/2025
000
AndrewMohawk @andrewmohawk.bsky.social · 25/03/2025
100
AndrewMohawk @andrewmohawk.bsky.social · 25/03/2025
Collection of stolen memes because this is incredible
100
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Another day, another 9.x critical vuln that bypasses authentication/authorization flow :( thehackernews.com/2025/03/crit... But dont worry it's just the kubes ingress-nginx and not the nginx ingress controller often used for kubes. Stay safe out there 🙃
thehackernews.com
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code execution.
000
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Meme stolen from @yaelwrites.com
171
Reposted by AndrewMohawk
Shane Harris @shaneharris.bsky.social · 24/03/2025
In 25 years of covering national security, I’ve never seen a story like this: Senior Trump officials discussed planning for the U.S. attack on Yemen in a Signal group--and inadvertently added the editor-in-chief of The Atlantic. www.theatlantic.com/politics/arc...
theatlantic.com
The Trump Administration Accidentally Texted Me Its War Plans
U.S. national-security leaders included me in a group chat about upcoming military strikes in Yemen. I didn’t think it could be real. Then the bombs started falling.
774165086440
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
And some skinnnnn
000
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Just needs this and then microcontroller and camera, I'm using a pretty wide camera cause it's just what I had lying around
000
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Even has a web interface to see what the fsck its up to
000
AndrewMohawk @andrewmohawk.bsky.social · 24/03/2025
Found a cool animatronic eye 3D print and spent the weekend making it follow me around
341
AndrewMohawk @andrewmohawk.bsky.social · 21/03/2025
I really hate that this is the release details we get for a *9.1 critical vuln* in a common js stack: www.cve.org/CVERecord?id... I will be blocking all requests with the header `x-middleware-subrequest` rather than risk deploying a > 5pm release for something without any real details.
cve.org
Common vulnerabilities and Exposures (CVE)
010
AndrewMohawk @andrewmohawk.bsky.social · 21/03/2025
Tornado cash is back. home.treasury.gov/news/press-r...
home.treasury.gov
Tornado Cash Delisting
WASHINGTON — Based on the Administration’s review of the novel legal and policy issues raised by use of financial sanctions against financial and commercial activity occurring within evolving technolo...
000
AndrewMohawk @andrewmohawk.bsky.social · 21/03/2025
Vibe coding my own rust ui for the rayhunter ( github.com/EFForg/rayhu... )
121
AndrewMohawk @andrewmohawk.bsky.social · 13/03/2025
A short story in 4:
011
AndrewMohawk @andrewmohawk.bsky.social · 10/03/2025
Twitter is down! Maybe DOGE finally did something people agree with
000
AndrewMohawk @andrewmohawk.bsky.social · 09/03/2025
Still the most common ways without exploitation to get root docker containers is bad mounts (-v /:/mnt), running with privileged flag, excessive capabilities (--cap-add=SYS_ADMIN this is basically root) and mounting the socket (-v /var/run/docker.sock:/var/run/docker.sock )
010
AndrewMohawk @andrewmohawk.bsky.social · 09/03/2025
Docker is not inherently insecure by default, it uses namespaces, seccomp, and cgroups to isolate containers from the host. A normal container doesn’t have access to system files, hardware, or kernel modules unless explicitly given it.
100
AndrewMohawk @andrewmohawk.bsky.social · 09/03/2025
I incorrectly thought this (PrivilegedHelperTools ) might be a path to use docker to gain root access WITHOUT the --privileged flag, but this is NOT true! Docker already runs with root privileges on macOS, using PrivilegedHelperTools is just to avoid the malware flag.
100
AndrewMohawk @andrewmohawk.bsky.social · 09/03/2025
Looking at some of the other recent DPRK attacks I noticed docker being used with `--privileged` flag. I also know that on mac there is a current issue with docker ( github.com/docker/for-m... ) and the workaround is to move things to /Library/PrivilegedHelperTools/.
100
AndrewMohawk @andrewmohawk.bsky.social · 09/03/2025
I incorrectly thought this might be a path to use docker to gain root access WITHOUT the --privileged flag, but this is NOT true! Docker already runs with root privileges on macOS, this is just to avoid the malware flag.
000
AndrewMohawk @andrewmohawk.bsky.social · 05/03/2025
Whats the best way for me to post things to both bluesky and the dark site whose name we do not mention?
220
AndrewMohawk @andrewmohawk.bsky.social · 28/02/2025
I put up a few words about the recent Bybit hack, I got so annoyed with companies shilling solutions or punching down. As a security community we should be and expect better. privy.io/blog/bybit-l...
privy.io
Privy Blog | On hindsight and risk assessment
010
AndrewMohawk @andrewmohawk.bsky.social · 23/02/2025
Reminder that bybit is not the first nor likely the last attack we will see using this method-similar to previous attacks: DMM ($308m, May 2024) WazirX ($230m, July 2024) Radiant ($55m, Oct 2024) medium.com/@RadiantCapi... www.fbi.gov/news/press-r... www.liminalcustody.com/blog/update-...
medium.com
Radiant Capital Incident Update
2024–12–06
021
Reposted by AndrewMohawk
The Tennessee Holler @thetnholler.bsky.social · 22/02/2025
WYOMING: “Thank you, Madam chairman.” “I prefer ‘Mister’ chairman.” “Well you all voted preferred pronouns cannot be compelled speech.”
1413400699534
AndrewMohawk @andrewmohawk.bsky.social · 11/02/2025
No, but its a localhost nodejs app and I'm not even logging in, was just using it to test some CSP things. Also turned off most of the plugins, I suspect I just have something b0rked
110
AndrewMohawk @andrewmohawk.bsky.social · 10/02/2025
9gb? what exactly is going on with @burpsuite.bsky.social these days! I just restarted it and im browsing a local next js app!
120
AndrewMohawk @andrewmohawk.bsky.social · 01/02/2025
I bought my cats a ball pit once, Sam was not impressed that I had completely filled up the lounge, but we all loved it.
020
AndrewMohawk @andrewmohawk.bsky.social · 01/02/2025
Mine did not have the same feeling no matter what we tried
150
Reposted by AndrewMohawk
Sonia Cuff @soniacuff.com · 01/02/2025
Rest in peace:
A grassy church graveyard which contains, in the foreground, a rectangular concrete slab inscribed with the words "IT SECURITY."
018430
AndrewMohawk @andrewmohawk.bsky.social · 01/02/2025
I dont often have to help someone secure outlook, mostly deal with Google workspace, but I found this guide really well done. Props to Australian Signals Directorate for actionable security. Gold security star. www.cyber.gov.au/sites/defaul...
cyber.gov.au
010