Sign in

Brian Clark

@deepthoughts10.infosec.exchange.ap.brid.gy
90 followers 11 following 500 posts

#InfoSec #Cybersecurity #threatintel and Politics. I try my best. Also @deepthoughts10@twitter.com Searchable 🌉 bridged from ⁂ infosec.exchange/@deepthoughts10, follow @ap.brid.gy to interact

PostsRepliesMedia
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 05/10/2026
Two very happy #cats #catsofmastodon
Two grey-ish cats snuggling together on a white comforter, one asleep, one not.
0132
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 05/10/2026
I really don’t understand these people. 🤷‍♂️
wandering.shop
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 28/09/2026
So glad I don’t have any Citrix Netscalers in my environment. SecOps hugs to those who do. 🤗
101
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 20/09/2026
RE: c.im/@nickrauchen/117304280530477897 🤯
c.im
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 16/09/2026
Interesting investigative report from ADAMnetworks applicable to those running websites using the Brevo tracker or Sibforms. You may have been serving up ClickFix! adamnet.works/blog/brevo-delivers-k… #cybersecurity
adamnet.works
Brevo delivered ClickFix through its own infrastructure
Brevo served KongTuke ClickFix from its own infrastructure. Altered tracker scripts, forms, and unsubscribe pages delivered to customer sites.
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 13/09/2026
Great talk by Ron Dilley @BlueTeamCon today “Why Incident Response Plans fail under pressure” with a shoutout to what tabletop exercises can and cannot prepare people for. Tabletops are effective and you should absolutely do them with your technical and […] [Original post on infosec.exchange]
Picture of a Slide from a conference talk on incident response which also shows the speaker, Ron Dilley
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 13/09/2026
Loved Steve Turner’s talk on Cloud Security at @BlueTeamCon He used a D&D RPG theme for the presentation which was highly enjoyable.
Conference slide on “Measuring success” of a cloud security program being presented by Steve Turner
021
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 12/09/2026
Hello all! @BlueTeamCon I am in you!
010
Reposted by Brian Clark
David Gerard @davidgerard.circumstances.run.ap.brid.gy · 12/09/2026
Fielder: You're a real PNG file, right?

Holmes, cut out on a background of grey and white squares: Why would I deceive you?
1713
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 11/09/2026
RE: mastodon.social/@arstechnica/117252… Kudos to Ars for writing this article and trying to get the word out to a non-security audience
mastodon.social
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 11/09/2026
Anyone play this #MapTap game? It’s kinda cool. www.maptap.gg September 10 96🏅 96🏅 100🎯 80✨ 80✨ Final score: 872
001
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 09/09/2026
RE: infosec.exchange/@james_inthe_box/1… I love blocking internet crap, and the .top TLD is absolute 💩 Please block it! #cybersecurity
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 09/09/2026
RE: infosec.exchange/@VirusBulletin/117… KnowBe4 has an excellent write-up on a phishing kit that employs extensive stealth capabilities through the use of legitimate Google services. You can help protect your users and reduce the risk of identity compromise and malware by […]
infosec.exchange
Original post on infosec.exchange
011
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 09/09/2026
RE: infosec.exchange/@ifin/117237255226… The best way to protect against the tactics enabled by this kit is to *require* phishing-resistant MFA to login (PassKeys, security keys like YubiKeys, or Windows Hello for Business). If it is required by your Conditional Access policy, then […]
infosec.exchange
Original post on infosec.exchange
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 07/09/2026
RE: infosec.exchange/@rmceoin/117203653… Re-upping this post as this is by far the best way to protect your users from malware using Etherhiding as its C2 channel. (Assumes you don’t need access to the various block chains from your company’s computers) #cybersecurity
infosec.exchange
001
Reposted by Brian Clark
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 06/09/2026
I’m seeing more than normal account takeovers. Please don’t click on telegram links and for the love of $deity, please use 2fa.
022
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 04/09/2026
RE: thepit.social/@20002ist/11720968173… RFK Jr. should go back to snorting cocaine off of toilet seats
thepit.social
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 04/09/2026
RE: mastodon.social/@arstechnica/117208… How long before RFK Jr. starts telling people to eat roaches to get more protein? #ignobel
mastodon.social
000
Reposted by Brian Clark
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/09/2026
If you're not blocking workers . dev at the proxy/perimeter, it's long overdue.
001
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 02/09/2026
RE: infosec.exchange/@BleepingComputer/… If you don’t use Faronics, block their domain: faronics.com This concludes another episode of simple solutions to cybersecurity problems 😉 #cybersecurity
infosec.exchange
011
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 02/09/2026
You should hunt for the MFA-Themed Domains referenced in Palo Alto’s repo: FQDN - FIRST DATE OBSERVED: mfaoptions[.]com - 8/26/26 mfa-options[.]com - 8/26/26 mfaregister[.]com - 8/27/26 register-mfa[.]com - 8/27/26 and this one too: mfa-register[.]com - 8/27/26 […]
infosec.exchange
Original post on infosec.exchange
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 31/08/2026
RE: infosec.exchange/@BleepingComputer/… Not just Exchange Online. Now affects Teams, OneDrive and Sharepoint too #outage #microsoft
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 31/08/2026
RE: infosec.exchange/@Nak/1171879444972… Nice share. I’m going to look into blocking .vu URLs first thing Monday morning #cybersecurity
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 31/08/2026
RE: mastodon.social/@arstechnica/117184… Is there literally *anything* Meta is doing that is not to the detriment of mankind?
mastodon.social
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 31/08/2026
RE: infosec.exchange/@BleepingComputer/… If you work in #cybersecurity at a company and use Intune to manage your desktop/laptop fleet, propose a project for next year to start managing browser extensions. It’s a fair amount of work to get started, but once under […]
infosec.exchange
Original post on infosec.exchange
121
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 31/08/2026
RE: infosec.exchange/@BlueTeamCon/11718… I’m looking forward to seeing this talk! #cybersecurity
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 31/08/2026
RE: cyberplace.social/@GossiTheDog/1171… One additional action you can take to help improve your defense is to block the top-level domain .su That’s the old Soviet Union TLD. No reason to allow traffic to it from a business network. #cybersecurity
cyberplace.social
001
Reposted by Brian Clark
Gil Durán @gilduran.com · 27/08/2026
We did it! “The Nerd Reich” is a New York Times Instant Bestseller! My book debuts at #3 on the non-fiction list. Thanks to all who pre-ordered /bought the book—or requested it at the public library or promoted it on social. Without you, I’m just an unemployed guy with a laptop. But with you…
Image: Nerd Reich book cover, a New York Times Instant Bestseller
1564234820
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 24/08/2026
RE: infosec.exchange/@PogoWasRight/1171… Defense-in-depth works. Nice write-up. #cybersecurity
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 21/08/2026
Use Defender and Intune? You should be auditing and alerting on high risk administrative actions. Here’s how to do that: jeffreyappel.nl/auditing-microsoft-… #cybersecurity
jeffreyappel.nl
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 19/08/2026
Simple but effective control to help prevent abuse of your business network: disable the remote debugging feature of Chrome and Edge. It disrupts the C2 capabilities described here (but used in other attacks as well) Look for these settings: RemoteDebuggingAllowed > Disabled (Intune: Microsoft […]
infosec.exchange
Original post on infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 19/08/2026
Good article on a Gen Digital-discovered #phishing campaign. More reason to block *.workers.dev (Cloudflare) as it is a key link in this campaign’s kill chain #cybersecurity www.gendigital.com/blog/insights/re…
gendigital.com
The phishing link that died on purpose
A single expired URL exposed a phishing campaign built around Mailer-Go, Cloudflare Workers and an EvilTokens OneDrive lure.
000
Reposted by Brian Clark
Beer Mat Movies @beer-mat-movies.mastodonapp.uk.ap.brid.gy · 16/08/2026
New release review: Sunny Dancer #Cinemastodon
112
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 12/08/2026
RE: infosec.exchange/@BleepingComputer/… Assuming you don’t need access to the Polygon blockchain from your business network, protect your systems by block the named public RPC endpoints using DNS, NGFW or web security proxy: polygon-bor-rpc.publicnode[.]com polygon […]
infosec.exchange
Original post on infosec.exchange
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 12/08/2026
Apparently #PumpkinSpice season has started
Bag of Starbucks Pumpkin Spice coffeeBox of Pumpkin Spice Cheerios
100
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 10/08/2026
RE: mastodon.social/@zackwhittaker/1170… Cliff Stoll’s talk was indeed epic! He came out into the audience during his talk and ended standing on a couple of chairs right in front of me. (Note: during his talk, Cliff gave his permission […] [Original post on infosec.exchange]
Cliff Stoll standing on chairs in the middle of the audience of his talk at DEFCON
030
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 10/08/2026
The folks @defcon did a nice job with the main track stages and audio this year. Some people had issues with the headphones but aside from a few short audio cutouts, they worked well for me. Also, the talk by Keanu Nys (redbyte1337) was really good. #defcon
DEFCON stage with speaker looking at his notes for the talk titled “This Message Was Sent by Microsoft”
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 09/08/2026
Goodbye #DEFCON thanks for a great time! Cc: @defcon
Large inflatable “Scully” DEFCON mascot hanging from the rafters of the conference floor
020
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 09/08/2026
Last night i had my first Japanese #Stout at Morimoto’s in Las Vegas — an Echigo Stout. It was really good! Smooth with a traditional “stout” flavor. #beer #beersofmastodon
Bottle and glass of Echigo Stout
031
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 04/08/2026
RE: mastodon.social/@zackwhittaker/1170… Maybe @wdormann was right about not using apps and only using websites #cybersecurity
mastodon.social
001
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 04/08/2026
I just saw HD Moore chug a Red Bull before his talk @BSidesLV This is going to be awesome. #bsideslv
Side on a screen with title “Mind the Gap”
010
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 04/08/2026
RE: infosec.exchange/@wdormann/11703913… Many @defcon and @BSidesLV talks are recorded and eventually posted to YouTube. If you can’t make it, follow those accounts to get notified when they post the recordings.
infosec.exchange
001
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 03/08/2026
Happy to be at @BSidesLV #bsideslv
BSidesLV badge sitting on top of a black backpack Picture of a large screen showing the BSidesLV logo
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 03/08/2026
RE: infosec.exchange/@SecureOwl/1170325… FFS
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 03/08/2026
Hey! @bsides312 representing at @BSidesLV !
BSides312 stickers on a table at the BSidesLV conference
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 02/08/2026
RE: infosec.exchange/@malwarejake/11702… Very excited to be going to Hacker Summer Camp this year!
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 28/07/2026
RE: mastodon.online/@streetartutopia/11… Perfect timing! See my earlier posts on this topic #cybersecurity
001
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 28/07/2026
RE: infosec.exchange/@DarkWebInformer/1… I’ve been waiting for this to be published …. #cybersecurity
infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 28/07/2026
RE: infosec.exchange/@ESETresearch/1169… For defenders, take a look at the free loldrivers.io to build automatic detection capabilities for vulnerable driver use in your organization. To move to prevention, take a look at magicsword.io to help you create […]
infosec.exchange
Original post on infosec.exchange
000
Brian Clark @deepthoughts10.infosec.exchange.ap.brid.gy · 28/07/2026
RE: infosec.exchange/@VirusBulletin/116… This is exactly why you should block access to Telegram from business networks. It’s too risky. If you have users that want or need it, create a Wi-Fi network that only has access to the Internet (no internal network access) to […]
infosec.exchange
Original post on infosec.exchange
000