Sign in

Joseph

@eflags.bsky.social
232 followers 890 following 40 posts

Forensic Analyst, Reverse Engineer. Opinions mine

PostsRepliesMedia
Reposted by Joseph
Electronic Frontier Foundation @eff.org · 28/05/2026
Applying for a government job shouldn't trigger a nationwide location tracking search. Yet EFF identified multiple law enforcement agencies in Missouri, Texas, Mississippi, and Illinois using Flock ALPR networks to run background checks. www.eff.org/deeplinks/2...
eff.org
More License Plate Reader Mission Creep: School Residency
An EFF analysis of millions of searches of Flock Safety automated license plate reader (ALPR) data by police has uncovered a troubling pattern: in the absence of a warrant requirement to search ALPR
112037
Reposted by Joseph
Patrick Chovanec @prchovanec.bsky.social · 28/05/2026
A President ordering the Justice Department to criminally investigate a woman who won a sexual assault lawsuit against him makes Watergate look like an unpaid parking ticket.
207143113858
Reposted by Joseph
Giovanni Colantonio @marioprime.bsky.social · 27/05/2026
look. is everything more expensive now? yes. but you have to look on the bright side too. now every time you open a computer, it doesn't work
4377111840
Reposted by Joseph
Eliot Higgins @eliothiggins.bsky.social · 26/05/2026
In addition, literal stacks of M4000 chemical bombs, used by the Assad regime to drop sarin on civilians in 3 recorded incidents, were found and photographed. Yet more evidence everything we published at Bellingcat based on our open source investigations of chemical attacks was accurate.
182134689
Reposted by Joseph
Catalin Cimpanu @campuscodi.risky.biz · 25/05/2026
Google Cloud found a zero-day in KnowledgeDeliver, an LMS popular in Japan This was being exploited to take over servers and then show a fake security alert and infect site visitors with other malware cloud.google.com/blog/topics/...
084
Reposted by Joseph
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 26/05/2026
Here is a look at all the special security features that Apple, Google, and WhatsApp offer to protect you from spyware all in one place. We looked at what these features do, and how to turn them on. We highly recommend them for anyone who's worried about government spyware.
techcrunch.com
These special phone and app features can help protect you from spyware | TechCrunch
Apple, Meta, and Google offer special security modes that provide your devices more secure against targeted spyware attacks. Here are how those modes work, what they do, and how to switch them on.
11913
Reposted by Joseph
Catalin Cimpanu @campuscodi.risky.biz · 24/05/2026
Microsoft has banned Nightmare Eclipse from GitHub: github.com/Nightmare-Ec... This is the researcher who disclosed several zero-days after Microsoft also deleted his MSRC account They now moved on GitLab: deadeclipse666.blogspot.com
820559
Reposted by Joseph
Socket @socket.dev · 21/05/2026
Attackers took over the art-template npm package and used it to deliver a Coruna-like iOS Safari exploit framework. Socket Threat Research breaks down the package takeover, device fingerprinting, and exploit delivery chain: socket.dev/blog/coruna-...
socket.dev
Coruna Respawned: Compromised art-template npm Package Leads...
Compromised npm package art-template delivered a Coruna-like iOS Safari exploit framework through a watering-hole attack.
041
Reposted by Joseph
Andy Greenberg @agreenberg.bsky.social · 18/05/2026
Mohammad Muzahir, aka Red Bull, the scam compound whistleblower and human trafficking victim whose incredible bravery made possible the story below, now has a GoFundMe: www.gofundme.com/f/support-wh... I'm in touch with the creator, who is legit. Grateful to her and to anyone who can donate.
gofundme.com
Donate to Help Scam Compound Whistleblower Rebuild His Life, organized by Jonna Higgins-Freese
Red Bull was trafficked, tortured, and forced to work as a scam… Jonna Higgins-Freese needs your support for Help Scam Compound Whistleblower Rebuild His Life
04633
Reposted by Joseph
Socket @socket.dev · 11/05/2026
84 TanStack npm package artifacts were compromised in the ongoing Mini Shai-Hulud supply chain attack, adding suspected CI credential-stealing malware. Socket flagged every malicious version within six minutes of publication. Details: socket.dev/blog/tanstac...
socket.dev
Tanstack npm Packages Compromised in Ongoing Mini Shai-Hulud...
Socket detected 84 compromised TanStack npm packages modified with suspected CI credential-stealing malware.
56735
Reposted by Joseph
Signal @signal.org · 11/05/2026
To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal. More changes are on the way.
New changes to help you stay safe in Signal. Look out for the name not verified notice. Signal can't verify profile names.Screenshot showing an additional confirmation step for accepting message requests.A screenshot showing more detailed safety tips.A screenshot showing a reminder to never respond to a chat pretending to be Signal.
834978
Reposted by Joseph
George Wallace @mrgeorgewallace.bsky.social · 05/05/2026
12487961608
Reposted by Joseph
Rep. Joe Neguse @neguse.house.gov · 05/05/2026
My resolution proposing a constitutional amendment to overturn the Supreme Court’s Citizens United decision now has 79 co-sponsors. You can view the full list at: www.congress.gov/bill/119th-c.... I’ll keep fighting to get it across the finish line!
625168134753
Reposted by Joseph
midudev · Miguel Ángel Durán @midu.dev · 01/05/2026
Yo usando Claude Code con Opus 4.7 para mover el margen de un div 2px.
5763385
Reposted by Joseph
Socket @socket.dev · 30/04/2026
🚨 BREAKING: Mini Shai-Hulud has spread to Packagist. We detected a malicious intercom/intercom-php@5.0.2 package artifact tied to this campaign. This is the third supply chain attack we've reported on today, and we're continuing to monitor the campaign: socket.dev/blog/mini-sh...
socket.dev
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP...
Socket found a malicious Intercom PHP package on Packagist using Composer plugin execution to steal credentials and spread across ecosystems.
032
Reposted by Joseph
Tim Blazytko @mrphrazer.bsky.social · 30/04/2026
The recording of my second Binary Cartography webinar is public: Agentic Malware Analysis: From Task Automation to Deep Analysis Topics: string decryption, API hashing, unpacking & pipeline building Recording: youtu.be/azej1P17w9E Slides & samples: github.com/mrphrazer/bi...
youtu.be
Agentic Malware Analysis: From Task Automation to Deep Analysis
YouTube video by Tim Blazytko
031
Reposted by Joseph
Jameel Jaffer @jameeljaffer.bsky.social · 24/04/2026
This wild document is the basis for the State Department's decision to cancel the visas and green cards of tech researchers who study the social media platforms and of tech regulators who enforce privacy and transparency laws. Disclosed to us last night in @thecoalition.bsky.social v. Rubio.
542555999
Reposted by Joseph
Don Moynihan @donmoyn.bsky.social · 24/04/2026
fuuuuuuck
On the agenda that day: the future of nuclear energy in the Trump era. The meeting was convened by 31-year-old lawyer Seth Cohen. Just five years out of law school, Cohen brought no significant experience in nuclear law or policy; he had just entered government through Elon Musk’s Department of Government Efficiency team.

As Cohen led the group through a technical conversation about licensing nuclear reactor designs, he repeatedly downplayed health and safety concerns. When staff brought up the topic of radiation exposure from nuclear test sites, Cohen broke in.

“They are testing in Utah. … I don’t know, like 70 people live there,” he said.
11636091383
Reposted by Joseph
shauna @goldengateblond.bsky.social · 24/04/2026
i’ve worked in tech more than 20 years. it has never been more ridiculous.
exchange on X 

Christoffer Bjelke @chribjel 
We hired a junior developer to write the simple code, so we don't have to spend a ton of money on tokens for those basic/primitive tasks

Sameer goel @sameer_goel
Great, so now we're optimizing LLM costs by inventing employees again.
Full circle innovation.
101167023378
Reposted by Joseph
makena kelly @makenakelly.bsky.social · 23/04/2026
SCOOP: Palantir's 22-point manifesto is alarming even its own employees—but it's just the latest move by leadership that's incensed workers. More on the internal dissent growing inside the company: wired.com/story/palantir-employees-are-starting-to-wonder-if-theyre-the-bad-guys/
wired.com
Palantir Employees Are Starting to Wonder if They're the Bad Guys
Interviews with current and former Palantir employees, along with internal Slack messages obtained by WIRED, suggest a workforce in turmoil.
691404533
Reposted by Joseph
ProPublica @propublica.org · 24/04/2026
When DOGE arrived at the Nuclear Regulatory Commission, the operatives had no real background in nuclear issues. They boxed out experienced hands, forcing resignations and massive exodus of talent. Over 400 people have since left or been forced out. Our full story: propub.li/3OBQMwk
Graphic displaying how hundreds of staff who do work related to nuclear reactors and their safety have left and not been replaced. The data is categorized into six sections: Nuclear Reactor Regulation, Nuclear Material Safety and Safeguards, Nuclear Regulatory Research, Nuclear Security and Incident Response, Regional offices, and Other offices. Each orange square underneath a category represents a loss in staff, while each gray square represents an addition of staff. The graphic shows that there have been 443 losses and 57 arrivals across all six of these categories. Note: The data is from the week ending Jan. 24, 2025, through Feb. 13, 2026. Source: Weekly Information Reports from the Nuclear Regulatory Commission.
5723281086
Reposted by Joseph
Signal @signal.org · 22/04/2026
We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.
111789474
Reposted by Joseph
Signal @signal.org · 22/04/2026
Apple’s advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release. You can read more here: support.apple.com/en-us/127002
support.apple.com
About the security content of iOS 26.4.2 and iPadOS 26.4.2 - Apple Support
This document describes the security content of iOS 26.4.2 and iPadOS 26.4.2.
123025
Joseph @eflags.bsky.social · 24/04/2026
More ransomware and commodity malware blogs! Screw the reusable APT tooling
110
Joseph @eflags.bsky.social · 24/04/2026
The APT researchers yearn to provide shareholder value
000
Reposted by Joseph
Socket @socket.dev · 22/04/2026
🚨 Breaking: Namastex Labs, the team behind Automagik[.]dev, hit with a supply chain attack affecting its npm packages. The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation. socket.dev/blog/namaste...
socket.dev
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
196
Reposted by Joseph
Socket @socket.dev · 22/04/2026
We published technical analysis of the Checkmarx compromise, including how malicious extensions silently fetched a second-stage payload from Checkmarx’s own GitHub repo. Our analysis also shows the malware stole developer credentials and used them for exfiltration and propagation.
012
Reposted by Joseph
TechCrunch @techcrunch.com · 15/04/2026
Objection, a Thiel-backed startup, aims to use AI to judge journalism, letting users pay to challenge stories. Critics warn it could chill whistleblowers and reshape how media accountability works.
techcrunch.com
Exclusive: Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers
Objection, a Thiel-backed startup, aims to use AI to judge journalism, letting users pay to challenge stories. Critics warn it could chill whistleblowers and reshape how media accountability works.
62412
Reposted by Joseph
Nick Dearden @nickdearden.bsky.social · 14/04/2026
“If you criticise Palantir’s platform one more time, you are going to lose your job.” Solidarity to all NHS workers opposing this toxic corporation. Shame on those bullying them. But they won’t stop us. We’re going to ditch Palantir. www.ft.com/content/ff70...
ft.com
Senior NHS officials warned staff over criticising rollout of Palantir platform
Ethical objections and uneven adoption have made the tech group’s contract a divisive issue within English health service
244104893598
Reposted by Joseph
Joseph Cox @josephcox.bsky.social · 13/04/2026
This is a great interview about how we ended up with the internet being hell, and how that results in today's politics, including the role journalists have played. Watch, subscribe here: www.youtube.com/watch?v=gp_n...
310533
Reposted by Joseph
9to5Mac @9to5mac.com · 11/04/2026
OpenAI says to update Mac apps including ChatGPT and Codex as security precaution
9to5mac.com
OpenAI says to update Mac apps including ChatGPT and Codex as security precaution
OpenAI is asking users of its Mac software to update to the latest releases from today “out of an abundance of caution.” This is due to a security issue with a third-party developer tool, Axios, that was used by OpenAI. more…
081
Reposted by Joseph
David Buchanan @retr0.id · 11/04/2026
when disassembling a complex device, at some point you reach the Swift threshold. this thing is never, ever, ever, going back together.
615416
Reposted by Joseph
Albert Pinto @70sbachchan.bsky.social · 10/04/2026
Absolutely remarkable statement from Pope Leo today. One for the history books www.theguardian.com/world/2026/a...
291146003884
Reposted by Joseph
Rebekah Valentine @duckvalentine.bsky.social · 08/04/2026
Good morning! I highly recommend anyone who thinks they might possibly interested to apply for my job at IGN. It is a fantastic (UNION!!!!!) job working with the absolute best people. I have loved it with all my heart. You will too. www.ziffdavis.com/careers/jobs...
ziffdavis.com
Search Jobs - Ziff Davis
We hire only the best and brightest because we know it takes great people to make a great company. We embrace the power of collaboration, have an entrepreneurial spirit and promote a work environment ...
55944225
Reposted by Joseph
ProPublica Guild @propublicaguild.org · 08/04/2026
We’re on strike today! Support our fight for a fair contract by NOT visiting the @propublica.org website or engaging with ProPublica stories today. Tell ProPublica’s management you won’t cross the picket line: actionnetwork.org/petitions/te...
We're on strike! Don't visit propublica.org on April 8
6349172894
Reposted by Joseph
Mehdi Hasan @mehdirhasan.bsky.social · 08/04/2026
Just wanted to remind folks, especially the GOP and the FDD, that Barack Obama’s 2015 nuclear deal didn’t give Iran control of the Strait of Hormuz or allow it to keep 60% enriched uranium. It sent $1.7 billion to Iran versus the tens of billions Iran will now make from tolls. 🤷🏽‍♂️
800208976663
Reposted by Joseph
Thomas Lecaque @tlecaque.bsky.social · 07/04/2026
"History will judge-" let me stop you right fucking there, history doesn't do fucking shit, I'm a historian, let's be clear here: elected officials need to do their fucking jobs, right now, before it happens, or future historians will judge THEM. Everyone knows and knew who Trump was.
7999752951
Reposted by Joseph
Eliot Higgins @eliothiggins.bsky.social · 07/04/2026
Just in time for Trump's scheduled war crimes, Bellingcat has updated our tool for identifying damaged buildings and structures in satellite imagery, ideally for investigating atrocities in Iran. Full details here: www.bellingcat.com/resources/20...
bellingcat.com
When Satellite Imagery Goes Dark: New Tool Shows Damage in Iran and the Gulf - bellingcat
Bellingcat is introducing an updated damage assessment tool — called the Iran Conflict Damage Proxy Map — focused on destruction in Iran and the Gulf .
7641281
Reposted by Joseph
magic @magicswordk.ing · 05/04/2026
Just as a reminder:
Comprehensive instructions for disabling or otherwise countering these cop droids.

PSA: if you or someone nearby are being brutalized by a police Spot robot and can get a hand or something underneath, grab this handle and yank it forward. This releases the battery, instantly disabling the robot.

Keep your hands away from joints, Spot WILL crush your fingers.

If you are a bystander and can get BEHIND spot, don't hit the power button, hit the OTHER button - it physically disconnects the motors.

Spot can also be countered with booby traps easily.

If you're armed, shoot center-of-mass as normal. The lithium pack is huge and not armored
201108781
Reposted by Joseph
vx-underground (automated mirror) @vxundergroundre.bsky.social · 05/04/2026
Around 2 hours ago (01:22EST) it appears ILSpy WordPress domain was compromised to deliver malware. Someone caught it on video. ILSpy WordPress domain (as of this writing) is currently returning 502. Attempting to download ILSpy, instead of directing to GitHub, redirected to a domain
1123
Reposted by Joseph
404 Media @404media.co · 08/10/2025
BREAKING: Apple removed an app for preserving TikToks, Instagram reels, news reports, and videos documenting abuses by ICE 🔗 www.404media.co/apple-banned...
404media.co
Apple Banned an App That Simply Archived Videos of ICE Abuses
Eyes Up's purpose is to "preserve evidence until it can be used in court." But it has been swept up in Apple's crackdown on ICE-spotting apps.
55901542
Reposted by Joseph
Joseph Cox @josephcox.bsky.social · 08/10/2025
New: Apple banned an app that simply archived videos of ICE abuses. Rather than other apps that record ICE official's real-time location, Eyes Up is to "preserve evidence until it can be used in court." Videos from TikTok etc. Every submission manually reviewed www.404media.co/apple-banned...
404media.co
Apple Banned an App That Simply Archived Videos of ICE Abuses
Eyes Up's purpose is to "preserve evidence until it can be used in court." But it has been swept up in Apple's crackdown on ICE-spotting apps.
521296653
Reposted by Joseph
Joseph Cox @josephcox.bsky.social · 03/10/2025
New from 404 Media: Apple just removed ICEBlock, the app for reporting sightings of ICE, from its App Store after DOJ pressure. ICEBlock's developer tells me "we are determined to fight this." "Capitulating to an authoritarian regime is never the right move." www.404media.co/iceblock-own...
404media.co
ICEBlock Owner After Apple Removes App: ‘We Are Determined to Fight This’
Apple removed ICEBlock reportedly after direct pressure from Department of Justice officials. “I am incredibly disappointed by Apple's actions today. Capitulating to an authoritarian regime is never t...
611277563
Reposted by Joseph
404 Media @404media.co · 03/10/2025
ICEBlock Owner After Apple Removes App: ‘We Are Determined to Fight This’ 🔗 www.404media.co/iceblock-own...
404media.co
ICEBlock Owner After Apple Removes App: ‘We Are Determined to Fight This’
Apple removed ICEBlock reportedly after direct pressure from Department of Justice officials. “I am incredibly disappointed by Apple's actions today. Capitulating to an authoritarian regime is never t...
24433128
Reposted by Joseph
Greg Otto @gregotto.bsky.social · 24/09/2025
🚨🚨🚨 Google released a report on "Brickstorm" this morning — a next-level, suspected China-linked campaign targeting U.S. firms. Ultra-stealthy, 400+ day dwell times, focus on stealing IP, finding zero-days, and focused on long-term cyberespionage. cyberscoop.com/chinese-cybe...
cyberscoop.com
Brickstorm malware powering ‘next-level’ Chinese cyberespionage campaign
Mandiant and Google have identified “Brickstorm,” a sophisticated, suspected China-linked hacking campaign targeting U.S. tech firms, legal organizations, and BPOs. The operation often goes undetected...
86646
Reposted by Joseph
Patrick De Klotz @patdeklotz.bsky.social · 22/09/2025
Holy shit
11934551223
Reposted by Joseph
Ann Marie Awad @anntastic.bsky.social · 22/09/2025
if you’re canceling your Disney and worried about what your kids will watch…might i suggest supporting your local PBS station, which gets you streaming access to all their content via PBS passport
592129556
Reposted by Joseph
Joseph Cox @josephcox.bsky.social · 22/09/2025
New: 404 Media is suing ICE. We have filed a lawsuit demanding ICE release its $2 million contract with Paragon, a company that makes powerful spyware to break into phones and read encrypted messages. This is expensive for a small outlet but this info is important www.404media.co/were-suing-i...
404media.co
We’re Suing ICE for Its $2 Million Spyware Contract
404 Media has filed a lawsuit against ICE for access to its contract with Paragon, a company that sells powerful spyware for breaking into phones and accessing encrypted messaging apps.
7067142307
Joseph @eflags.bsky.social · 18/09/2025
Excited to speak at FTSCon next month!
032
Reposted by Joseph
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Joseph Edwards (@eflags.bsky.social) is presenting “The Forensics of Zoom's Remote Control” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
014