Graham Helton (too much for zblock) @grahamhelton.bsky.social · 14/09/2025Behold, the greatest thinkpad propaganda you will ever see 010
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 11/09/2025Testing out live terminal session replays on my blog. Same "easy viewing" of a proof of concept as a gif/video except: 1. Super easy to record `asciinema rec file.cast` 2. Super easy to host on my site 3. The best part.... you can copy/paste the text from the terminal replay 🤯 020
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 11/09/2025I'm always a little happy when I have to build something from source and see it's written in rust. Cargo is so nice :) 120
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 07/09/2025Yeah im just gonna go to bed after that one 140
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 07/09/2025lofi hip hop devices to relax/study to 030
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 06/09/2025She keeps the creepers away 000
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 30/08/2025Cat not enjoying the new record player 240
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 28/08/2025TIL: there doesn't seem to be a way to read a raw file from a remote repository using pure git commands without first cloning the repo 🤨 ("Well acktchually 😐☝️" comments welcome) 111
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 28/08/2025When looking for obscure issues I always end up with tons files like: poc_final_final2.sh I don't always have time to organize things without the potential of losing my train of thought so I've been trying to find an easy solution. This is my most recent attempt: 211
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 27/08/2025Look how beautiful this code-block is on this person's blog ertt.ca/nix/shell-sc... 020
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 26/08/2025don't be like me and try listening to the nix evangelists 100
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 26/08/2025Anyone successfully using both markdown and silverbullet? Interested in hearing about your workflows for either but specially interested in silverbullet 000
Reposted by Graham Helton (too much for zblock)Taggart @taggart-tech.com · 09/06/2025Happy Monday, all! ICYMI, there's a new version of my comprehensive guide to DevOps-based homelabbing available! 173
Reposted by Graham Helton (too much for zblock)ricky 🎶💜🍄 @0xpsilocyber.com · 08/05/2025hi, to anyone impacted at Crowdstrike. please feel free to reach out if I can help you land a role at Google or any other shop. happy to do resume reviews, coaching, or referrals. we're always looking for skilled dfir, CTI, SecOps, and many other disciplines! happy to help if I can. 122
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 02/03/2025POV: You're a Linux admin working at TikTok 2283
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 06/01/2025POV: Me (allegedly) gaining write access to the internal container registry and setting all container images to mine crypto 020
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 29/12/2024I learned so much writing Gubble. Can't wait to release it this week! Any ideas what it could be? 020
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 28/12/2024Pass is a really cool CLI and GPG based password manager that follows the Unix Philosophy. Do one thing and do it well. Project: passwordstore.org Setup Guide: ryan.himmelwright.net/post/setting... 021
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 21/12/2024As a zoomer, this is what my filesystem looks like 210
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 16/12/2024 Every week I post a summary of what security ideas I've been thinking about. This week it's mostly ideas from myself discussing the threats and opportunities of AI as well as why I think we're seeing a shift away from the cloud. loworbitsecurity.com/radar/radar7/ 130
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 15/12/2024All this time put into learning cyber security and I can't stop my girlfriend from downloading a sketchy rewrite of moshi monsters off githubmedia.tenor.coma close up of a smiley face with a hand behind itALT: a close up of a smiley face with a hand behind it 110
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 14/12/2024Some invaluable Linux tools I've used this week and some of my personal notes on how to use them in the future: 120
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 11/12/2024"Although Cleo published an update and advisory for CVE-2024-50623—which allows unauthenticated remote code execution—Huntress security researchers have recreated the proof of concept and learned the patch does not mitigate the software flaw." www.huntress.com/blog/threat-... 000
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 08/12/2024I'm releasing this a day earlier than normal because I'm quite proud of this: This week's topics include: Downstream Impacts of the Telco Breaches, 2024 Insider Threat Report with A Stern Talking To About Branding, and Chasing The Ghost In The Wire loworbitsecurity.com/radar/radar6/ 110
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 08/12/2024NPM and PyPi "firewall" for preventing the installation of known malicious packages. A very cool idea. github.com/DataDog/supp...github.comGitHub - DataDog/supply-chain-firewall: A tool for preventing the installation of malicious PyPI and npm packages :fire:A tool for preventing the installation of malicious PyPI and npm packages :fire: - DataDog/supply-chain-firewall 011
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 01/12/2024I'm taking netwars for my masters which came with an OVA file. I was messing around with Incus recently so I took some quick notes on using Incus to run a .OVA File grahamhelton.com/blog/incusova/grahamhelton.comQuick Notes on using Incus to run a .OVA File · Graham HeltonIncus Recently I’ve been exploring Incus as a quick and lightweight VM/container hosting solution. One of the requirements I had for Incus was to quickly run a .ova file within it. It’s no... 000
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 30/11/2024Some small businesses I enjoy: @ugmonk.bsky.social: High quality items, I own and love most of the desk organizational pieces from the Gather collection. ugmonk.com/collections/... 131
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 26/11/2024NO CYBER ATTACKS THIS WEEK PLEASE 032
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 26/11/2024In case you missed it, here are my thoughts on some news that hit my radar recently. In this week's post I go over 2024 CISO Salary Data, The Nearest Neighbor Attack, Federated Security Training, and more. Enjoy! loworbitsecurity.com/radar/radar5/loworbitsecurity.comRadar #5: Week of 11/25/2024Radar #5: This week's topics: 2024 CISO Salary Data, The Nearest Neighbor Attack, Federated Security Training, and more 020
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 25/11/2024Cyber security related black Friday deals: github.com/0x90n/InfoSe...github.comGitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black FridayAll the deals for InfoSec related software/tools this Black Friday - 0x90n/InfoSec-Black-Friday 000
Reposted by Graham Helton (too much for zblock)yoda66.bsky.social @yoda66.bsky.social · 23/11/2024Hello my #infosec friends. I have come aboard BlueSky. Would love some follows! :). 4104
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 18/11/2024Morning! Here are some of my thoughts on recent security trends. This week's topics: Python Digital Attestations, The Fate of CISA, and more. I post these every Monday to help inspire informed discussions of the events I find useful, check it out! loworbitsecurity.com/radar/radar4/loworbitsecurity.comRadar #4: Week of 11/18/2024Radar #4: This week's topics: Python Digital Attestations, The Fate of CISA, and more 041
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 17/11/2024Just unboxed a stat trak factor new fade toothbrush. Willing to trade for a karambit. No lowball offers, I know what I've got. 020
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 11/11/2024Anecdotally, Ubuntu 24.04 has had major performance issues on desktop for me. I suspect it has something to do with app armor. 010
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 10/11/2024Thinking of checking out brighter shores, has anyone spent time checking it out? Worth it? 000
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 10/11/2024I typically don't send these out until Monday, but if you're interested in my thoughts on security news, here is tomorrow's post. loworbitsecurity.com/radar/radar3/loworbitsecurity.comRadar #3: Week of 11/11/2024Radar #3: This week's topics: Private equity gobbling up certification companies and the consequences of Apple introducing an inactivity reboot to iPhones 131
Reposted by Graham Helton (too much for zblock)Ryan Basden @ryanbasden.com · 08/11/2024The more I talk to other security consultants, the more I realize that the industry deserves a shake-up. FTE seems more and more like an inevitable path to burnout every day. 021
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 08/11/2024You should follow Ricky, he's an incredible security professional and an ever more wonderful human. 220
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 28/10/2024The adoption of LLMs that can be used to pump out platitudes that lack any actual security analysis makes it increasingly difficult to have productive security discussions about news and trends. I couldn't find many sources I trusted so I'm starting my own: loworbitsecurity.com/radar/radar1/loworbitsecurity.comRadar #1: Week of 9/28/2024The DataDog Cloud Security Report, The SEC Charging 4 Companies For Misleading Cyber Disclosures, and Apple Releasing Open-Sourcing Private Cloud Compute Resources. 071
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 26/10/2024This is a really interesting move from Apple. Challenging researchers via a $1,000,000 bug bounty for their new Private Cloud Compute technology, releasing source code, architecture docs, and tooling means apple is VERY confident in this tech. 1/? security.apple.com/blog/pcc-sec...security.apple.comBlog - Security research on Private Cloud Compute - Apple Security ResearchPrivate Cloud Compute (PCC) fulfills computationally intensive requests for Apple Intelligence while providing groundbreaking privacy and security protections — by bringing our industry-leading device... 100
Reposted by Graham Helton (too much for zblock)Matthew Green @matthewdgreen.bsky.social · 24/10/2024Passkeys remain mysterious and confusing to me, a cryptographer. I want to use them but every time I interface with them they do something weird. 1816514
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 24/10/2024never attribute to malice what can be attributed to CYBERATTACKS 010
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 23/10/2024I do wonder if this report suffers from some level of survivorship bias. The data from the report is collected from companies that can afford Datadog. It's hard to collect data from companies that do not have the expensive security services, potentially skewing the data. 110
Reposted by Graham Helton (too much for zblock)Ryan Basden @ryanbasden.com · 22/10/2024If your company gives you a training budget but no business hours to do the training, they don't actually care about professional development. 031
Graham Helton (too much for zblock) @grahamhelton.bsky.social · 22/10/2024Just read the phenomenal "2024 State Of Cloud Security" report from DataDog www.datadoghq.com/state-of-clo... Biggest takeaway is secure by default settings makes a massive impact and violations of the principles of least privilege are really hard problems to solve. Here are my thoughts:datadoghq.comState of Cloud SecurityFor our 2024 report, we analyzed data from thousands of organizations to understand the latest trends in cloud security posture. 110
Reposted by Graham Helton (too much for zblock)Rory McCune @mccune.org.uk · 21/10/2024Datadog’s new State of Cloud security report is out. Lots of interesting insights from some of my colleagues! www.datadoghq.com/state-of-clo...datadoghq.comState of Cloud SecurityFor our 2024 report, we analyzed data from thousands of organizations to understand the latest trends in cloud security posture. 0134