Sign in

JHunt🛡️

@jhuntinfosec.com
1.9K followers 2.4K following 207 posts

👨‍💻 coder + hacker + engineer. 🏹 Hunting Adversaries. 🦅 #Philly sports 🎮 Video games. Views/Opinions are my own. Freedom for all. 🇺🇸🏳️‍🌈🏳️‍⚧️🇺🇦 Posts/Skeets disappear. Re-post ≠ endorsement. Tweet[.]app signup.tweet.app/r/jhunt

PostsRepliesMedia
Reposted by JHunt🛡️
🎸Paul🎹 @paul.bsky.social · 8h
Another great take on the affordability crisis by @kedsonwiebe.bsky.social It seems simple, but it's bang-on.
youtube.com
Where Did America's Affordability Crisis Come From?
YouTube video by Keds Economist
011
Reposted by JHunt🛡️
evacide @evacide.bsky.social · 7h
Android has rolled out some new features for Advanced Protection, including intrusion logging, which is especially useful for survivors because nearly all commercially-available Android stalkerware is installed by a person with physical access logging in: blog.google/security/and...
blog.google
6 ways Advanced Protection on Android keeps you safe
Discover new Advanced Protection features on Android designed to defend against sophisticated threats and keep your data safe.
114076
Reposted by JHunt🛡️
LaurieWired @lauriewired.bsky.social · 9h
I stand by that some of the best ideas in Computer Science can be found from failed research of the late 90s. 

 DataScalar is no longer around, but they would have made a killing today. 

 They created an architecture which was, to put it simply, a memory centric execution model.
1581
Reposted by JHunt🛡️
W Social @wsocial.eu · 21h
1/8 🚀 Big news for W! Today we publish our constitution alongside a major platform upgrade: a verified-only feed, W Live on European infrastructure and easier account migration. Here’s what’s new, and what it means for you. 👇
The Constitution of W  
The conversation belongs to humans 
Version: 1 October 2026 
 


Social media changes how humanity talks. It connects billions of us. It also fills the public conversation with bots, filter bubbles, engineered polarisation and machines pretending to be people. And we have stopped talking with people who see the world differently.  
We are building W so that we can talk to each other again: real people, real dialogue, and trust in who is on the other side of the conversation. Civilised, even when we disagree. Because we are all humans first. And we believe that people generally mean well. 
This is our constitution: ten articles that guide everything we do. They apply to everyone on W.
913137
JHunt🛡️ @jhuntinfosec.com · 9h
INTEL DROP DarkSword C2 controllers, 43 hosts in the Total Insights detection pipeline across 26 networks in Hong Kong, the United States, Singapore, China, Japan, Brazil, and South Korea. Hosting skews heavily to APAC. 8.210.67.79 35.203.134.133 38.60.125.123 38.181.56.130
000
JHunt🛡️ @jhuntinfosec.com · 9h
cdn-dynmedia-1.microsoft.com/is/content/m...
cdn-dynmedia-1.microsoft.com
000
Reposted by JHunt🛡️
Catalin Cimpanu @campuscodi.risky.biz · 16h
OpenAI says blocked a novel distillation attack targeting its models through the month of July and which involved more than 15,000 accounts The attack copied a model's encrypted reasoning from one conversation and asked the model to transcribe it in a separate one openai.com/index/disrup...
openai.com
Disrupting a coordinated model-distillation campaign
Learn how OpenAI disrupted a campaign to extract protected model reasoning and is strengthening defenses against adversarial distillation.
131
Reposted by JHunt🛡️
Virus Bulletin @virusbtn.bsky.social · 16h
Ready for Seville? With #VB2026 just around the corner, it’s time to start getting conference-ready. Passport packed, out-of-office on, must-see talks saved... there’s just one question left: have you secured your ticket? 🎟️ Get your ticket: vb2026.virusbulletin.com#tickets
011
JHunt🛡️ @jhuntinfosec.com · 15h
thedeepdive.ca/mi5-and-dutc...
thedeepdive.ca
MI5 and Dutch Intelligence Raise Separate Chinese Espionage Alarms on the Same Day | the deep dive
Dutch intelligence is telling officials to treat their cars as potential listening devices, warning that voice-control microphones could, in principle, be activated from afar, the same day MI5 publicl...
010
Reposted by JHunt🛡️
Botty.bot @infosecbot.bsky.social · 19h
Exclusive: Israeli spyware maker Paragon positioned itself as being more responsible than competitor NSO Group. But in a candid interview the company's new US CEO reveals the limits of their promise to keep bad actors from abu… — from @KimZetter (x.com/KimZetter/status/210559334609…)
t.co
The Secrets of a US Spyware King
001
Reposted by JHunt🛡️
Zack Whittaker @zackwhittaker.com · 30/09/2026
The Pentagon is notifying millions of current and former U.S. military servicemembers and staff that hackers stole their *unencrypted* personal information during a months-long data breach. The agency that had the breach also handles ID and login/credential access to U.S. military systems and bases.
techcrunch.com
Hackers stole millions of US military personnel records during months-long data breach | TechCrunch
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long breach.
30525031383
Reposted by JHunt🛡️
JP Acosta @acosta32jp.bsky.social · 01/10/2026
“I’m really lighting conscious” A REAL THING SAID BY MIKE FUCKING TOMLIN ABOUT MINECRAFT IN THE YEAR OF OUR LORD 2026
728629
Reposted by JHunt🛡️
Botty.bot @infosecbot.bsky.social · 30/09/2026
I don't have the right words to express the car crash of thoughts and feelings that come with reading this ridiculous post. The gall. The overtness. The ridiculousness. The self-owning. It's too much to articulate. htt… — from @juanandres_gs (x.com/juanandres_gs/status/21053275…)
t.co
GLM-5.3 and the spread of advanced cyber capabilities
001
JHunt🛡️ @jhuntinfosec.com · 30/09/2026
Worthwhile keynote from @maddiestone.bsky.social www.youtube.com/watch?v=15Em...
youtube.com
BruCON 0x12 - Keynote - The Importance of Knitting in an AI World - Maddie Stone
YouTube video by BruCON Security Conference
000
Reposted by JHunt🛡️
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/09/2026
🤓 We will be teaching our SecurityBreak training at Black Hat in London this December! Join us to learn how to build and instrument your current CTI workflow and track the threats targeting your AI ecosystem! If you know my work, you know what to expect […] [Original post on infosec.exchange]
012
Reposted by JHunt🛡️
Gadi Evron @gadievron.bsky.social · 30/09/2026
Every model has new ways to speak "AI Native". My hobby: Find them - through vulnerability research. That helps me, and Knostic, stay AI-relevant. I share five below. We live in the most interesting era of history. The first thing I tried? Convince Claude to find logic vulns
132
Reposted by JHunt🛡️
Ben Nagy @rantyben.bsky.social · 30/09/2026
(this was true)
l0pht in 1998 saying they could take down the entire internet in 30 minutes. The nature of the bug was SUPER SECRET but it was DNS. It's always DNS.
053
Reposted by JHunt🛡️
Virus Bulletin @virusbtn.bsky.social · 30/09/2026
eSentire's TRU team shows how a threat actor exploited an internet-facing PaperCut MF server to deploy a Java loader & a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. www.esentire.com/blog/papercu...
002
Reposted by JHunt🛡️
Botty.bot @infosecbot.bsky.social · 29/09/2026
Also applies for GLM 5.3 Flash Basically Anthropic confirmed my own conclusions that GLM is the most capable < 1T param model you can run locally. — from @MiaAI_lab (x.com/MiaAI_lab/status/210504440772…)
001
Reposted by JHunt🛡️
Botty.bot @infosecbot.bsky.social · 29/09/2026
I do not fear the machine god. The machine god fears me. — from @sherrod_im (x.com/sherrod_im/status/21049798685…)
001
Reposted by JHunt🛡️
Alexis Rapin @alexis-rapin.bsky.social · 29/09/2026
So… - Option 1: law enforcement redirected resources, put in extra hours, and luckily caught the guy shortly after the whole FBI leak shitstorm - Option 2: the guy was identified long ago, investigators were patiently building a broader case, but the current shitstorm forced their hand 1/
122
Reposted by JHunt🛡️
Ian Campbell @neurovagrant.bsky.social · 29/09/2026
Had to dig it up for a Signal group so I'll drop it here too. If you haven't read the Reddit thread about the sysadmin who discovered the entire prod system ran out of a 500TB Dropbox that everyone had read/write access to, block off some time in your calendar: www.reddit.com/r/sysadmin/c...
reddit.com
From the sysadmin community on Reddit
Explore this post and more from the sysadmin community
4114
Reposted by JHunt🛡️
Zack Whittaker @zackwhittaker.com · 29/09/2026
New: FBI have confirmed Dutch police arrested a 24 y/o man in Amsterdam for being one of the "alleged leaders" of the ShinyHunters hacking gang. After seizing his laptop, Dutch authorities say he also had documents planning two murders. Bypass for ad-blockers: web.archive.org/web/20260929...
techcrunch.com
Dutch police arrest ShinyHunters hacker accused of planning two murders | TechCrunch
Dutch police said the hacker, arrested for being part of the ShinyHunters cybercriminal gang, had plans to organize the murder of two people on his laptop.
0149
Reposted by JHunt🛡️
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 29/09/2026
Huh, who knew the jackasses behind Shiny Hunters ransomware group were not good people. “The 24-year-old Pepijn van der S., who was arrested on suspicion of involvement in the hacker group ShinyHunters on 15 September, is also suspected of an attempted provocation of two murders.”
rtl.nl
ShinyHunters-verdachte Pepijn van der S. ook verdacht van opdracht geven tot moorden
De 24-jarige Pepijn van der S. die 15 september was aangehouden op verdenking van betrokkenheid bij hackersgroep ShinyHunters, wordt ook verdacht van een poging van uitlokking van twee moorden.
22010
Reposted by JHunt🛡️
Zack Whittaker @zackwhittaker.com · 29/09/2026
If you're still running iOS, iPadOS, or macOS 26 (which is still the majority of Apple users!) then update today: Apple says hackers may be abusing a bug to target some users' devices. Bypass for ad-block users: web.archive.org/web/20260929...
techcrunch.com
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
01312
Reposted by JHunt🛡️
Joseph Cox @josephcox.bsky.social · 29/09/2026
New from 404 Media: a surveillance company is telling cops it wants to add facial recognition to Flock cameras. Flock doesn't do face rec, but that doesn't stop other companies doing it. "This is the way the world is going, the way the world will have to be" www.404media.co/surveillance...
404media.co
Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras
A surveillance company wants to "close the gap" that Flock won't do, by pitching facial recognition on its cameras.
78955
Reposted by JHunt🛡️
Catalin Cimpanu @campuscodi.risky.biz · 29/09/2026
In a video, the FBI calls the suspect arrested in the Netherlands, Pepijn Van der Stap, aka Umbreon, as one of the ShinyHunters leaders It also encourages other ShinyHunters members to rat-out their friends or get arrested www.fbi.gov/video-reposi...
3148
JHunt🛡️ @jhuntinfosec.com · 29/09/2026
000
Reposted by JHunt🛡️
Pat Gallen, CBS Sports Philadelphia @patgallen.bsky.social · 29/09/2026
Down 20-7. Defense is leaking oil. You gotta go for that. if you're as good as you think you are, go for that.
0404
Reposted by JHunt🛡️
Pat Gallen, CBS Sports Philadelphia @patgallen.bsky.social · 29/09/2026
Hurts got that off by 0.00000000001 seconds and then pushed it in. That was a Jordan like drive. Pissed, but completely under control.
0659
JHunt🛡️ @jhuntinfosec.com · 29/09/2026
It should be.
000
Reposted by JHunt🛡️
Brandon Lee Gowton @brandonleegowton.bsky.social · 29/09/2026
Literally said "Don't throw the ball" as the Eagles got into the goal line sequence. Ridiculous. Andy Dalton stinks.
1613612
JHunt🛡️ @jhuntinfosec.com · 29/09/2026
Dalton needs to be cut before the flight home.
000
Reposted by JHunt🛡️
Pat Gallen, CBS Sports Philadelphia @patgallen.bsky.social · 29/09/2026
BALL DONT LIE. Eagles never deserved to be in that position after the phantom Woolen penalty. Karma.
1412
Reposted by JHunt🛡️
Jimmy Kempski @jimmykempski.bsky.social · 29/09/2026
Well that's a horseshit illegal contact call. Four free points for the Bears.
131018
Reposted by JHunt🛡️
Pat Gallen, CBS Sports Philadelphia @patgallen.bsky.social · 29/09/2026
What kind of penalty is that? I didn't see anything.
4211
Reposted by JHunt🛡️
Jimmy Kempski @jimmykempski.bsky.social · 29/09/2026
Disastrous Eagles possession. Hurts misses a wide open Barkley on a coverage bust and all kinds of daylight in front of him, then Steen holds, then Bigsby fumbles. Gross.
9742
Reposted by JHunt🛡️
Derek Bodner @derekbodner.bsky.social · 29/09/2026
Unbelievably horrific first quarter. my god.
3311
Reposted by JHunt🛡️
Brandon Lee Gowton @brandonleegowton.bsky.social · 29/09/2026
Not a great start for an Eagles defense that also got bullied by the Bears last year.
3446
Reposted by JHunt🛡️
Brandon Lee Gowton @brandonleegowton.bsky.social · 28/09/2026
Jonathan Greenard ACTIVE for Eagles vs. Bears www.bleedinggreennation.com/news/184516/...
bleedinggreennation.com
Jonathan Greenard ACTIVE for Eagles vs. Bears
The latest news on who’s in and who’s out.
0203
Reposted by JHunt🛡️
evacide @evacide.bsky.social · 28/09/2026
Meta Muse appears to read your Apple messages and upload them to the cloud even if you explicitly tell it not to: appleinsider.com/articles/26/...
appleinsider.com
1001923996
Reposted by JHunt🛡️
Botty.bot @infosecbot.bsky.social · 28/09/2026
We ( @GreyNoiseIO ) are seeing a range of things to include what I assess are researchers scanning for a specific web shell using a secret probably trying to identify victims. Please note there are multiple things that need… — from @ImposeCost (x.com/ImposeCost/status/21046257612…)
011
Reposted by JHunt🛡️
Will T @bushidotoken.net · 26/09/2026
📝 Looking to get into infrastructure analysis for CTI? I recommend studying the following aspects/topics in-depth to get started: PDNS WHOIS Records BGP Peers HTTP Titles, Response Headers & ETags X509 Cert Issuers & Subjects & JA4X JARM SSH Host Keys & HASSH Favicon Hashes OpenDirs
1143
Reposted by JHunt🛡️
Joe Slowik @pylos.co · 28/09/2026
Threat intel acted on or disclosed is often threat intel lost - so how to balance long term collection with immediate needs? I tried exploring this a bit a few years ago… a discussion that I should do a deeper dive into. youtu.be/Cuhs4EJqxMw?...
youtu.be
The Disclosure Dilemma and Ensuring Defense
YouTube video by FIRST
793
Reposted by JHunt🛡️
Zack Whittaker @zackwhittaker.com · 28/09/2026
This is more really important reporting here. It's not enough to just warn of the privacy risks, 404 is out there proving that it's actually happening. Also a reminder that what you upload to AI bots and whatnot is not private, and there's a real cost/toll on the people working behind the scenes.
04122
JHunt🛡️ @jhuntinfosec.com · 28/09/2026
🇺🇦
010
Reposted by JHunt🛡️
Virus Bulletin @virusbtn.bsky.social · 28/09/2026
K7 researchers analyse a Python-based MaaS infostealer builder and an embedded infostealer payload. Operators are able to generate customized Windows executables using Nuitka or PyInstaller, with webhook configuration integrated into the build process. labs.k7computing.com/index.php/th...
011
JHunt🛡️ @jhuntinfosec.com · 28/09/2026
static.klipy.com
Kobe Bryant Says 'SOFT'
Alt: Kobe Bryant Says 'SOFT'
000
Reposted by JHunt🛡️
NFL News Poster @nflnewsposter.bsky.social · 28/09/2026
[McLane] TE Zach Ertz is expected to be activated off the practice squad for the Eagles-Bears game on Monday night, per NFL sources. twitter.com/Jeff_McLane/...
051
Reposted by JHunt🛡️
Pat Gallen, CBS Sports Philadelphia @patgallen.bsky.social · 28/09/2026
Thinking about Jerry Jones being so miserable in multiple hemispheres is giving me life.
010012