hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 09/08/2026@f2harrell.bsky.social Hey Dr. Harrell! Did you recently start using your Mastodon account? — mastodon.social/@Frrell There's been a spate of fake accounts and account takeovers of RStats folks.mastodon.socialFrank Harrell (@Frrell@mastodon.social)88 Posts, 110 Following, 4 Followers · Professor of Biostatistics, Vanderbilt University School of Medicine Expert Biostatistics Advisor, FDA Center for Drug Evaluation and Research Member, R Foundati... 102
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈Tanya Shapiro @tanyashapiro.bsky.social · 15/07/2026oh no, the bots have arrived on here welp, it was only a matter of time 151
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 06/07/2026that's how we end up with the (D) version of Trump. thanks but no thanks. 0110
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 12/06/2026With all of the [Mini] Shai Hulud ops of just the past few months, are there any stories of SBOMs "saving" or at least "radically helping" orgs get a handle on exposure and remediation? 020
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 31/05/2026The HoneyLabs blog (which you shld be 👀 if you're a defender) — honeylabs.net/blog — didn't have a detectable RSS feed so I made a programmatic one via @val.town — hrbrmstr--019e7d68e38e747786809794f66af76f.web.val.run 1 of now 5 programmatic RSS-feed Vals. It takes less than 90s to make new ones.honeylabs.netBlog · HoneyLabsFindings, write-ups, and notes from the HoneyLabs honeypot network. 040
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈Robert Evans (the Only Robert Evans) @iwriteok.bsky.social · 04/05/2026Knowledge Fight was and remains one of the all-time great podcasts. It is the rarest kind of thing: a show that entertains while having a real-life impact. Dan and Jordan helped defang and neuter elements of a powerful propaganda network. Excited to see what both do next. 872742487
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈Lynn Cherny @arnicas.bsky.social · 02/05/2026Alright!- don't know if your heart was "no one will notice, you're right" or "we're supporting you staying in and writing it" 😅 So latest free newsletter, with many three.js web games, some more splats/3d stuff, image model that can't do sprites, narrative news open.substack.com/pub/arnicas/...open.substack.comTITAA #78: Little City BuildersThree.js Cities - 360 Images & Splats - Variorum - FlipBook - Talkie - LLM Philosophy 174
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 13/04/2026I am late to the 0900 time, but actually sleeping kind of throws off the "todo" schedule a bit. Today, I start as a Distinguished Engineer @ @censys.bsky.social !!!!! More info on the "what" I'll be doing when a certain partner in crime crosses the threshold in a few weeks. #GuessWho 080
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 13/04/2026😠 #RStats Core member Tomáš Kalibera passed away. 082
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 10/04/2026$ rm -rf $CURRENT_GIG $ sleep $(( $(TZ="America/New_York" date -d "2026-04-13 09:00:00" +%s) - $(date +%s) )) && echo $NEW_GIG 1120
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 05/02/2026(saw this in RSS) I've had various Ollama models write CLAUDE[.]md and skills, and also had minimax m2.1 (which is just amaze) do it and they're all pretty good at it. 120
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/01/2026The infrastructure ties back to established CVE exploitation operations. h/t to Defused for their report as well: xcancel.com/DefusedC... www.greynoise.io/blo... 2/2 010
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/01/2026New research: Threat actors are actively mapping LLM infrastructure. Our Ollama honeypots captured 91K+ attack sessions. One campaign systematically probed 73+ model endpoints—GPT-4o, Claude, Llama, Gemini, and more—across 80K sessions in 11 days. www.greynoise.io/blo... 1/2greynoise.ioThreat Actors Actively Targeting LLMsOur Ollama honeypot infrastructure captured 91,403 attack sessions between October 2025 and January 2026. Buried in that data: two distinct campaigns that reveal how threat actors are systematically mapping the expanding surface area of AI deployments. 150
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/01/2026If your systems were hit during this window, the vulnerability data may already be for sale. Links to IoCs are in the post. 4/4 000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/01/2026* The IAB Model: This wasn't a direct hit; it was a "restocking" of the Initial Access Broker market. * Infrastructure: The activity originated from a suspicious hosting provider (CTG Server Limited) with a history of phishing and abuse. 3/4 100
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/01/2026A single operator systematically scanned the internet, testing 240+ different exploits to build a fresh inventory for 2026 ransomware attacks. Key Takeaways: * Timing is everything: Attackers used the holiday skeleton crew window to scan unimpeded for 4 days. 2/4 100
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/01/2026That which was originally a private customer threat intel share in our weekly At The Edge reports is now a public blog post! www.greynoise.io/blo... This is a deep dive into a massive reconnaissance campaign that unfolded between December 25–28. 1/4greynoise.ioThe Ransomware Ground Game: How A Christmas Scanning Campaign Will Fuel 2026 AttacksOver four days in December, one operator scanned the internet with 240+ exploits, logging confirmed vulnerabilities that could power targeted intrusions in 2026. 110
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 01/01/2026#macOS folks!! Today is a *great* day to: ```bash brew update && brew upgrade && brew cleanup && brew doctor ``` then: ```bash brew bundle dump --file=~/Brewfile --describe --force ``` to create a `Brewfile` you can use to "quickly" restore the Homebrew bits that you rely on. 0110
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 22/12/2025I ran it when I got to #2.1/#2.2's house and hopefully the networks you visit will be equally as clean. Lifehacker does a bang-up job explaining it, too. NPR has some more background on this new type of consumer exposure, too. www.npr.org/2025/11/... 2/2 010
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 22/12/2025🙏🏽 Lifehacker for introducing GreyNoise Check to a broader population! 👉 lifehacker.com/tech/... If you haven't used GreyNoise Check — check.labs.greynoise.io — this is the perfect time to do so, especially if you're visiting friends/fam over the holidays. 1/2 110
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/12/2025I also took the opportunity to make fun of some very incompetent attackers. Hey, if they can attack, so can I! www.greynoise.io/blo... 3/3greynoise.ioReact2Shell Payload Analysis: A Look at Selected Opportunistic and Possibly AI-"Enhanced" Probes and AttacksOver the past ~1.5 weeks, the React2Shell campaign has unleashed a flood of exploitation attempts targeting vulnerable React Server Components. Analyzing the payload size distribution across these attacks reveals a clear fingerprint of modern cybercrime, and a landscape dominated by automated scanners with a handful of sophisticated outliers. 010
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/12/2025We've captured over 50K (some, barely) "unique" #React2Shell payloads, and a few caught our eye as potentially being some of the more nascent "AI"-created or enhanced ones. We took the opportunity to dig into five of them and see what makes them tick. 2/3 130
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/12/2025"There's Payloads, And Then There's pAIloads: A Look At Selected Opportunistic (And Possibly AI-"Enhanced") React2Shell Probes and Attacks" www.greynoise.io/blo... 1/3greynoise.ioReact2Shell Payload Analysis: A Look at Selected Opportunistic and Possibly AI-"Enhanced" Probes and AttacksOver the past ~1.5 weeks, the React2Shell campaign has unleashed a flood of exploitation attempts targeting vulnerable React Server Components. Analyzing the payload size distribution across these attacks reveals a clear fingerprint of modern cybercrime, and a landscape dominated by automated scanners with a handful of sophisticated outliers. 141
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈GreyNoise @greynoise.io · 11/12/2025Just in: Watch #React2Shell exploitation unfold over time in the map below (geo of source IPs attempting to exploit CVE-2025-55182). #GreyNoise #ThreatIntel #CVE202555182 #Nextjs #Cybersecurity 084
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 09/12/2025Whilst spelunking through React2Shell traffic and associated initial access payloads, I came across a late-to-the party attacker attempting to deploy a MeshCentral agent for C2. Thanks to Censys, we poked a bit harder, and boy howdy are we on the precipice of a real mes[hs].labs.greynoise.ioReact2Shell Side Quest: Tracking Down Malicious MeshCentral Nodes – GreyNoise LabsWhile spelunking through React2Shell initial access payloads, MeshCentral entered the building, so we decided to see just how Mesh-y GreyNoise Data Is 030
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 05/12/2025This is textbook opportunistic exploitation—not novel, but serious. These campaigns lead to credential theft, cryptomining, ransomware staging, & access brokering. Patch if you haven't. DO NOT RELY ON WAFs ALONE. Block IPs using GN feeds & monitor for IoCs in the post. 3/3 010
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 05/12/2025What we're seeing: Automation-heavy traffic (Go clients, scanner UAs) PoE validation via PowerShell math commands Encoded stagers downloading secondary payloads AMSI bypass attempts via reflection ~50% of IPs first seen in December 2025 Early migration into Mirai botnets 2/3 110
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 05/12/2025I had the [mis?]fortune of being awake just as attackers decided to slam the public internet with React2Shell exploits. GreyNoise had a tag up for it yesterday afternoon. Full write-up of the initial spate of attacks: www.greynoise.io/blo... 1/3greynoise.ioCVE-2025-55182 (React2Shell) Opportunistic Exploitation In The Wild: What The GreyNoise Observation Grid Is Seeing So FarGreyNoise is already seeing opportunistic, largely automated exploitation attempts consistent with the newly disclosed React Server Components (RSC) “Flight” protocol RCE—often referred to publicly as “React2Shell” and tracked as CVE-2025-55182. 140
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 29/11/2025Got 30s of public media "fame" on NPR yesterday www.npr.org/2025/11/28/n...npr.orgHoliday cyber scams are getting more inventiveHackers are hoping to take advantage of the holiday season, and they're not just stealing money or data. 181
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 25/11/2025Perfect for holiday tech support season—check your relatives' networks in 30 seconds instead of doing the awkward "let me look at your computer" thing. For devs: `curl -s check.labs.greynoise...` returns JSON. No auth, no limits. Full story: www.greynoise.io/blo... 3/3check.labs.greynoise.ioGreyNoise IP CheckCheck if your IP address has been observed by GreyNoise sensors. Instantly detect malicious activity, compromised devices, and security threats affecting your network. 030
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 25/11/2025Our Labs team built a free tool to check: visit check.labs.greynoise.io and see instantly if your IP has been caught scanning the internet. No signup. No email harvesting. Just answers from our global sensor network that sees billions of IPs. 2/3check.labs.greynoise.ioGreyNoise IP CheckCheck if your IP address has been observed by GreyNoise sensors. Instantly detect malicious activity, compromised devices, and security threats affecting your network. 131
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 25/11/2025🔍 New tool alert: GreyNoise IP Check Your home network might be compromised and you'd never know. Residential proxies, IoT botnets, and router malware are everywhere—turning regular internet connections into attack infrastructure. 1/3 1103
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/11/2025¹ I apologize for anyone who ended up with tea on their keyboards after reading that word when associated with the EU. 5/5 040
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/11/2025While others look through "legal documents" we got receipts right from the network packets. You can read the whole thing @ "When Bulletproof Hosting Proves Bulletproof: The Stark Industries Shell Game" 👉 www.greynoise.io/blo... 4/5greynoise.ioThe Stark Industries Shell Game - When Bulletproof Hosting Proves BulletproofEU sanctions hit Stark Industries in May 2025. GreyNoise data shows how the group quietly rebranded to THE.Hosting and kept its malicious infrastructure running. 130
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/11/2025As a result, Stark did a series of stunningly adroit "business", organizational, & network infrastructure moves that not only let them completely avoid punishment, but also come back even stronger and more dangerous than they were before. 3/5 100
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/11/2025Back in May, the EU decided to wield its mighty¹ fist & drop some sanctions on Stark. Except…they (the EU) suck @ OPSEC & the impending sanctions leaked. 2/5 120
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 17/11/2025There once was an organization called Stark Industries (no, not *that* one! this one is real!). They emerged around the time Russia decided to invade Ukraine. Oddly enough, their ASN real estate was the source of scads of Russian state-sponsored cyber ops. 1/5 130
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈Karen Attiah @karenattiah.bsky.social · 15/11/2025Good morning. This is your reminder to get to the gym so that you can beat up racists if you have to. 601492231
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 21/10/2025The protocol is cool. Relying on Bluesky for storage, authentication, etc. is stupid. Really, really, really, really stupid,. 020
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 21/10/2025Nobody (nobody) should trust the 110% centralized record store that is Bluesky's ATproto dumping ground. There is zero sign of a plan for having $ to keep it independent of any malicious entity. It is a centralized store that can purge your record tomorrow on a billionaire's whim. 240
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 08/10/2025Bari Weiss can and should (repeatedly) go REDACT herself. 020
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 06/10/2025Bonkers Palo Alto Login Scanner activity has continued through the weekend. We coordinated with/Palo on Fri, so they know aboot it & have the backs of their customers. tzulo, inc. & 3xK Tech GmbH continue to be the primary network sources (both need a spanking/null route). viz.greynoise.io/tag... 021
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈Caroline Ledbetter @carolineledbetter.bsky.social · 04/10/2025bsky.app/profile/caro... 011
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 04/10/2025Bonus Drop #99: Duly Noted THE DROPS ARE BACK! Today, we tackle 3 note-taking tools: Blinko, Piles, and Memos. Blinko is an AI-integrated self-hosted system; Piles is a minimal web clipper; while Memos offers a lightweight, self-hosted knowledge base focused on simplicity and data privacy.dailydrop.hrbrmstr.devBonus Drop #99 (2025-10-04): Duly NotedTHE DROPS ARE BACK! Today, we tackle three note-taking tools: Blinko, Piles, and Memos. Blinko is an AI-integrated self-hosted system with features for task management and Markdown support. Piles i… 020