Sign in

Heinbrian

@heinbrian.bsky.social
755 followers 1K following 47 posts

#w00w00 #00m00m

PostsRepliesMedia
Heinbrian @heinbrian.bsky.social · 03/10/2026
True… not sure if they are interested…
110
Heinbrian @heinbrian.bsky.social · 03/10/2026
Hey @mubix.com we should get together and do this…
110
Reposted by Heinbrian
infosecgreybeard.bsky.social @infosecgreybeard.bsky.social · 03/10/2026
I'm tempted to set up a D-Sides event. No sponsors, no pretentious talks, just security professionals discussing whatever is on their minds.
351
Reposted by Heinbrian
Ian Campbell @neurovagrant.bsky.social · 24/09/2026
Humbled to have been presented @domaintools.bsky.social "Bad Actors Badger" Award this evening! Truth is, I am only the last mile, and can't do it w/o everyone in the chain - every bit of dev, every doc, every sale, every customer, we're all badgers. We are the adversaries - let's never let up.
Multicolored glass award in the shape of the DomainTools gear logo reading "Bad Actors Badger Award - Ian Campbell - 2026"
071
Reposted by Heinbrian
Hoodlum 🇺🇸 @nothoodlum.bsky.social · 19/09/2026
Mark Carney: “I would now like to inform you that the teleprompter has ceased to function. Unlike a certain world leader, I do not view this as a conspiracy.”
817261225402
Reposted by Heinbrian
Nicole Hoffman @threathuntergirl.bsky.social · 27/08/2026
ChatGPT make me some unwearable CTI shirts
141
Heinbrian @heinbrian.bsky.social · 18/08/2026
Take a nap!
011
Reposted by Heinbrian
DilDog 🅅 @dildog.l0pht.com · 16/08/2026
when you're really good at making stuff but only get halfway through before starting the next thing you're a black belt in partial arts
2306
Reposted by Heinbrian
The Vertex Project @vertexproject.bsky.social · 11/08/2026
Our webinar is TOMORROW! Join The Vertex Project and Team Cymru to see how graph-native analysis and global network telemetry help analysts move beyond IOC chasing to uncover connected infrastructure, hidden relationships, and faster investigative outcomes. 📅 Tomorrow! 🔗 Register: hubs.la/Q04rHr6S0
054
Reposted by Heinbrian
Brian Whelton @brianwhelton.bsky.social · 27/07/2026
The world’s most effective security tool was release on this day, 39 years ago! Many thanks for your service Rick Astley! youtu.be/dQw4w9WgXcQ?... #NeverGonnaGiveYouUp
youtu.be
Rick Astley - Never Gonna Give You Up (Official Video) (4K Remaster)
YouTube video by Rick Astley
12610
Reposted by Heinbrian
Emaldrien de Argutus @emaldrien.bsky.social · 16/07/2026
Der Song ist jetzt auf YT Das ZDF warnt davor, den Link anzuklicken und diesen Song zu hören. Das ZDF präsentiert euch gerne jeden Fascho in Talkshows und Nachrichten. Aber nicht diesen Song Dieser Song ist gefährlich! Verbotene Kunst! Entartet. Sollte verb(r)annt werden Das ZDF macht mir Angst.
youtube.com
Danger Dan - Keine Angst
YouTube video by Danger Dan
731323521
Reposted by Heinbrian
Deth Veggie @dethveggie.bsky.social · 23/06/2026
Bow to the Cow.
1183
Reposted by Heinbrian
Botty.bot @infosecbot.bsky.social · 18/06/2026
Today, as part of Operation Endgame, the FBI joins our international law enforcement partners in announcing the disruption of SocGholish malware. SocGholish, active since 2018, is a Java-script based… 🔁 RT @FBICyberDiv | reposted by @silascutler x.com/FBICyberDiv/status/2067623810…
012
Reposted by Heinbrian
Ben Collins @bencollins.bsky.social · 17/06/2026
Yessir.
wired.com
Tim Heidecker Wants to Turn Infowars Into Adult Swim for the Internet
Infowars’ would-be creative director talks Sandy Hook, comedy’s MAGA turn, and why the future of satire may look more like a streaming startup than a late-night show.
924052398
Reposted by Heinbrian
More Perfect Union @moreperfectunion.bsky.social · 15/06/2026
A German court has ruled that Google is liable for the false statements generated by its AI Overviews feature. The ruling could have massive impacts on the world's biggest search engine, which recently doubled down on giving users AI-generated results. www.wired.com/story/a-cour...
wired.com
A Court Has Ruled That Google Is Liable for False Statements Generated by AI Overviews
The ruling holds that a company that designs, trains, operates, and manages an AI system must assume legal liability for any damages caused by the responses it generates.
121389485
Reposted by Heinbrian
Daniel Gordon @validhorizon.bsky.social · 12/06/2026
My name is Daniel Gordon and I am writing to let you know that you have a serious problem. Next week I will be speaking at FirstCon about The Art of Notification. Distilled lessons learned from hundreds of victim notifications I’ve done over the years. www.first.org/conference/2...
first.org
38th Annual FIRST Conference: DENVER (US), June 14-19, 2026
38th Annual FIRST Conference - Denver (US), June 14-19, 2026.
042
Reposted by Heinbrian
Ian Campbell @neurovagrant.bsky.social · 11/06/2026
"If we don't have an impact as a group, as a company, as a security team, it doesn't really matter. It's theatre." - Well said by @heinbrian.bsky.social, one of my favorite people to talk to about punching bad guys over the internet. You should follow him if you don't yet.
011
Heinbrian @heinbrian.bsky.social · 11/06/2026
Last week I had the honour to do the closing Keynote for @elbsides.bsky.social together with CJ - the fantastic @dnsfilter.bsky.social team now published the slides, the recording and a transcript at www.dnsfilter.com/blog/who-com... A big shout out to the @elbsides.bsky.social team
063
Reposted by Heinbrian
Ian Campbell @neurovagrant.bsky.social · 10/06/2026
oh how did i miss this? excited to jump into it, mysk gives us the best iOS toys.
043
Heinbrian @heinbrian.bsky.social · 09/06/2026
Realtätsverweigerungsausgleichmoment Reality refusal equalization moment
051
Reposted by Heinbrian
Mrs. Betty Bowers @mrsbettybowers.bsky.social · 08/06/2026
"Apple, Google, and Meta are very excited to announce the release of new AI-driven products. We guarantee that they will respect your privacy. Unfortunately, these products are not available in Europe, as they have laws to protect your privacy."
8343881390
Reposted by Heinbrian
Terence Eden @edent.tel · 08/06/2026
New blog post: How many consecutive hyphens can you have in a domain name? shkspr.mobi/blog/2026/06/how-many-c… A seemingly simple question which sent me down into the murky depths of standards. How many consecutive hyphens can you have in …
shkspr.mobi
How many consecutive hyphens can you have in a domain name?
A seemingly simple question which sent me down into the murky depths of standards. How many consecutive hyphens can you have in a domain name? It probably isn't sensible to name your online presence a----------hyphen.com - but is there anything technically stopping you? Table of ContentsHistoryTLD RestrictionsAnomaliesSo What? History Let's do some history! This is 1978's "HOST NAMES…
1196
Reposted by Heinbrian
Kat Abughazaleh @katmabu.bsky.social · 01/06/2026
happy pride 💕
Fake news screencap of Gritty with the chyron, “BREAKING NEWS / Gritty announces it’s illegal to be straight in the month of June / No more straight people | See something | Say something”
77109412188
Reposted by Heinbrian
The Vertex Project @vertexproject.bsky.social · 28/05/2026
This episode explores representation in CTI, the impact of women leaders at Mandiant, and why diverse perspectives lead to better intelligence analysis. Really thoughtful conversation from the team. Listen here: www.youtube.com/watch?v=Aqqj... #ThreatIntelligence #WomenInCybersecurity
0115
Reposted by Heinbrian
Seth Cotlar @sethcotlar.bsky.social · 25/05/2026
If you’d told me 15 years ago that in 2026 Donald Trump would be the Republican president and that I would be reading papal encyclicals muttering “fuck yeah, this Pope really gets it,” I would have laughed in your face. And yet here we are.
251924364
Reposted by Heinbrian
Catalin Cimpanu @campuscodi.risky.biz · 24/05/2026
Security researcher Gadi Evron has open-sourced Honeyslop, a canary to detect and triage AI-hallucinated bug reports github.com/gadievron/ho...
github.com
GitHub - gadievron/honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports
Code canaries to quickly triage hallucinated ('slop') vulnerability reports - gadievron/honeyslop
1277
Reposted by Heinbrian
Jill Walker Rettberg @jilltxt.bsky.social · 20/05/2026
New dataset published: this is the audio + transcripts of AI-generated podcasts using NotebookLM to analyse how it "translated" source documents from different times and cultures. My favourites are the 20 podcasts generated from an empty PDF. The paper about it is in press. doi.org/10.18710/RNT...
doi.org
A dataset of AI-generated podcasts created using NotebookLM
Audio files and transcripts of AI-generated podcasts created using Google's NotebookLM. Four podcasts were created by uploading specific PDFs. Twen...
16698243
Reposted by Heinbrian
Chris Wysopal @weld.bsky.social · 19/05/2026
28 years ago today, 7 members of the hacking group L0pht Heavy Industries told the U.S. Senate they could "shut down the internet in 30 minutes."
45112
Heinbrian @heinbrian.bsky.social · 19/05/2026
That is a sticker - it’s good
010
Reposted by Heinbrian
halvarflake.bsky.social @halvarflake.bsky.social · 13/05/2026
www.faz.net/premium/digi... I wrote a FAZ guest article.
faz.net
Thomas Dullien zu Anthropics Mythos: Software war nie auf perfekte Sicherheit ausgelegt - das rächt sich
Schwachstellen in Computern wurden lange hingenommen. Denn sie auszunutzen war technisch komplex und teuer. KIs ändern das nun. Damit zwingen sie uns, Altlasten schneller anzugehen.
33111
Reposted by Heinbrian
John Hultquist @hultquist.bsky.social · 13/05/2026
If you've been laid off from a cyber threat intel position and would like to come to @SLEUTHCON this year, please reach out.
1129
Reposted by Heinbrian
Catalin Cimpanu @campuscodi.risky.biz · 10/05/2026
France arrested a cybersecurity executive for allegedly buying child sexual abuse material from the dark web Filigran (OpenCTI) founder Samuel Hassine is allegedly one of the 232 suspects identified by police as buyers on the "Alice with Violence CP" portal www.lelibrepenseur.org/samuel-hassi...
lelibrepenseur.org
Samuel Hassine patron de Filigran écarté du voyage de macron pour pédopornographie
Nouveau scandale de pédocriminalité des élites : chute brutale. Samuel Hassine, fondateur et patron de Filigran, pépite française de la cybersécurité, a
1136
Reposted by Heinbrian
alexjungle.bsky.social @alexjungle.bsky.social · 08/05/2026
Canada turned the Niagara Falls blue for the European Union! They also played Ode to Joy, the EU's anthem, an early celebration of Europe Day which is celebrated tomorrow. Europe & Canada, we are family ❤️ Join eYou the European social media similar to threads here: play.google.com/store/apps/d...
12417104
Reposted by Heinbrian
Victoria Walberg @vickyjo.bsky.social · 08/05/2026
On the 21st May, a wake for Thomas Fischer @fvt.bsky.social has been organised in London to remember, share and celebrate his life. Please only claim an attending ticket if you can attend, there is also a live stream if you wish to pay your respect from afar. www.eventbrite.co.uk/e/thomas-fis...
eventbrite.co.uk
Thomas Fischer aka @FVT wake
Wake for celebrating the life of our friend and colleague @FVT who left us way too early and left a massive void in our community.
053
Reposted by Heinbrian
Zack Whittaker @zackwhittaker.com · 06/05/2026
This cracks me up because kids just think up these things so brilliantly, but also this proves that age verification laws are complete dogshit and don't even work.
techcrunch.com
Some kids are bypassing age verification checks with a fake mustache | TechCrunch
A new survey found that kids find it easy to bypass age checks, despite a rise in age verification laws around the world.
23218
Reposted by Heinbrian
Ian Campbell @neurovagrant.bsky.social · 05/05/2026
Ransomware resource repo (say that three times fast) from an experienced Team Cymru threat intel analyst: github.com/BushidoUK/Aw...
github.com
GitHub - BushidoUK/Awesome-Ransomware: A curated list of Ransomware resources
A curated list of Ransomware resources. Contribute to BushidoUK/Awesome-Ransomware development by creating an account on GitHub.
041
Reposted by Heinbrian
andy jabbour @andyjabbour.bsky.social · 01/05/2026
ICYMI: Beyond 'Actionable': How @heinbrian.bsky.social and James Shank Want CTI to Actually Hurt Adversaries www.dnsfilter.com/blog/cti-bri... cc @gate15.bsky.social #cybersecurity
dnsfilter.com
Beyond 'Actionable': How Brian Hein and James Shank Want CTI to Actually Hurt Adversaries
James Shank and DNSFilter’s Brian Hein share their vision for CTI: influence business decisions, increase adversary costs, and drive real impact.
012
Heinbrian @heinbrian.bsky.social · 01/05/2026
Hugs - can’t wait to see you again soon Ian
110
Reposted by Heinbrian
The Official Pulpit of CULT OF THE DEAD COW @cultdeadcow.com · 29/04/2026
copy.fail THANKS, I HATE IT.
copy.fail
Copy Fail — 732 Bytes to Root
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
03815
Heinbrian @heinbrian.bsky.social · 29/04/2026
Let me order you some lederhosen off Temu
120
Heinbrian @heinbrian.bsky.social · 29/04/2026
You will be fine… unless you try to yodel it @andyjabbour.bsky.social
220
Reposted by Heinbrian
andy jabbour @andyjabbour.bsky.social · 29/04/2026
Okay, important question. Is Claude Mythos pronounced: - MY-thos, or -MYTH-os? @masnick.com @pfrazee.com @hailey.at @heinbrian.bsky.social help me out? And while we're at it... Kubernetes? I had a hard enough time with Azure and SANS, tbh.
341
Heinbrian @heinbrian.bsky.social · 29/04/2026
I go with MYT-HOSS boss @andyjabbour.bsky.social
110
Reposted by Heinbrian
Daniel Gordon @validhorizon.bsky.social · 29/04/2026
Dropping 0day is making a comeback! (Not really but this is another disclosure drama, albeit lower stakes than BlueHammer, etc) Disclosure: shittrix.moksha.dk Response: xcp-ng.org/forum/post/1... Patches w/shade: xenbits.xen.org/xsa/advisory...
shittrix.moksha.dk
89 vulnerabilities in XAPI / Citrix XenServer
Day-0 public disclosure of 89 independently exploitable vulnerabilities in Citrix's hypervisor management platform. 5 Critical, 28 High across 8 XAPI object types. Independent security research by Jak...
045
Reposted by Heinbrian
andy jabbour @andyjabbour.bsky.social · 27/04/2026
Glad to see my friend @heinbrian.bsky.social speaking on 'How NOT to Be Your Adversary’s Best Friend,' FIRST CTI 2026: 'cyber threat intelligence should be measured by impact, not by report volume, IOC counts, or other vanity metrics' youtu.be/SOi--TSyF3c?... #cybersecurity @gate15.bsky.social
youtu.be
How NOT to Be Your Adversary’s Best Friend | FIRST CTI 2026 Day 2
YouTube video by Hans-Petter Fjeld
132
Reposted by Heinbrian
Pop Crave @popcrave.com · 24/04/2026
Ticketmaster Canada will no longer allow tickets for concerts, sports, and other live events in Ontario to be resold above their original price under Ontario’s newly passed Bill 97.
946867
Reposted by Heinbrian
Robert Wilson @frcolumba.bsky.social · 25/04/2026
Excellent article by Joe Slowik. “Determining mechanisms to arrive at “good enough” information sooner, rather than “perfect” information later, thus becomes an acute need for modern security operations.” Every day of the week.
161
Reposted by Heinbrian
Camille Fournier @skamille.themanagerswrath.com · 16/04/2026
If bsky can't stay up I may be forced to read LinkedIn please help me
4371
Reposted by Heinbrian
Dan Hon @danhon.com · 14/04/2026
I too aspire to have an API limit and for you to either pay me more to keep working, or wait until after I've had a nap
542893