Sign in

イヴラド

@kevinreddot.bsky.social
45 followers 135 following 144 posts

Coffee lover. Security nerd. I’ve seen things you would believe (if you do DFIR). APT operators have shitty bosses, annoying in-laws, rising school fees, and teenage kids with questionable music taste. Be kind while burning their C2 infra to the ground.

PostsRepliesMedia
Reposted by イヴラド
Emmanuel Thomé @emmanuelthome.bsky.social · 21/09/2026
Forging 1024-bit RSA signatures in nearly SNFS time Hand over your HSM for some time, and we can forge signatures for its key. Arbitrary signatures. Forever. github.com/ucsd-hacc/NS...
github.com
GitHub - ucsd-hacc/NSNFSSSFSFN: Nearly SNFS-Speed Signature Forgery Sans Factoring N
Nearly SNFS-Speed Signature Forgery Sans Factoring N - ucsd-hacc/NSNFSSSFSFN
13013
Reposted by イヴラド
mechazany @mechamcscringle.bsky.social · 20/09/2026
Ghost in the Shell 1995 garbage man who’s ghost hacked with falsified memories of having a family while lovingly reminiscing on them out loud
3570531853
Reposted by イヴラド
Micah Lee @micahflee.com · 16/09/2026
I've got a lot of work to do today but I'm getting absolutely nerdsniped by the new Flock dataset. You can download it here. It's all of the Android partitions extracted from a Flock device ddosecrets.org/article/floc...
ddosecrets.org
Flock ALPR camera - Distributed Denial of Secrets
Filesystem images of the partitions on an in-use Flock ALPR camera, including custom Android APK files installed on the device, as well as its recorded media. The data reveals how the devices track bo...
181551568
Reposted by イヴラド
AFP Fact Check @factcheck.afp.com · 16/09/2026
As scientists investigate the deadly floods that swept through Nepal and Tibet, online posts baselessly claim the disaster was caused by a Chinese dam collapse. We reviewed forensic evidence and spoke to five experts to break down the sequence of events behind the devastation 🧵
Infographic showing the route that the China-Nepal floods took through the Himalayas
176
Reposted by イヴラド
Internet Archive @archive.org · 15/09/2026
“Fix the Wayback Machine!” We’ve heard you. The Wayback Machine has been dealing with waves of high-volume automated traffic. Mark Graham, director of the Wayback Machine, explains what’s happening and what we’re doing about it. ➡️ blog.archive.org/2026/09/15/a...
Internet Archive Wayback Machine logo.
4584172
イヴラド @kevinreddot.bsky.social · 15/09/2026
Cybercriminals hacking into Berlin federal state network reads as a silly joke but it’s not: www.heise.de/en/news/Berl... Even funnier, the attackers exfiltrated almost 6 terabytes of data. It should have taken days if not weeks, and nobody noticed.
heise.de
Berlin: Passwords exfiltrated, 12,000 systems scanned
The Berlin Senate administration has confirmed that passwords were also stolen in the August cyberattack. All systems are being checked.
000
Reposted by イヴラド
Daniel Gordon @validhorizon.bsky.social · 13/09/2026
Eyal is exactly right. It has long been the case that threat actors would adopt the tools of pentesters. Now adversaries using LLMs are telling them that this is an authorized pentest and the LLM will often leave traces of that.
You can detect some AI-enabled attacks by searching for explicit indications of penetration testing. This happens because threat actors tell their LLMs they are performing authorized engagements even when using open weight models, or use pentesting harnesses like cyberstrikeAI, PentAGO, Hexstrike.
0116
Reposted by イヴラド
Zack Whittaker @zackwhittaker.com · 27/08/2026
Australian police say they have arrested two people involved in the TeamPCP hacks, which hit GitHub, OpenAI and others. Brian Krebs has the full back story with one of the hackers, and it's one hell of a read. I audibly gasped at least twice.
krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
12416
イヴラド @kevinreddot.bsky.social · 13/08/2026
I turned up to be passkeys hater, lol. And I remember, how fascinated I was with U2F and early FIDO implementations. The future looked so bright! )
000
Reposted by イヴラド
European Space Agency @esa.int · 12/08/2026
Eclipse day! ☀️ Today's total solar eclipse is visible from Greenland, Iceland, northeastern Portugal and Spain. Most of the rest of Europe, northern North America and western Africa will witness a partial solar eclipse. More info: www.esa.int/Science_Expl... #EuropeanSolarEclipse
Map of Earth shown as a globe, with the focus on its northern hemisphere. A red, C-shaped arc marked 'total eclipse' reaches from northeast Russia, past the North Pole, Greenland, Iceland and the Iberian Peninsula. An orange oval surrounds this arc, marked 'partial eclipse', covering most of Europe, Canada and parts of the USA, the western edge of Africa and the northeastern corner of Russia.
1249111
イヴラド @kevinreddot.bsky.social · 11/08/2026
Somehow I seem to have 10Gbps internet at home with GUA IPv6 prefix delegated via DHCP-PD, and I did not have to do anything extraordinary for that. It’s rather surprising how … normal this is. It just works. What annoys me now, is how unstable Matter over Thread is.
010
イヴラド @kevinreddot.bsky.social · 29/07/2026
Paradigm Shift just published usbliter8, a new unpatchable SecureROM exploit for Apple A12/A13 CPUs, affects iPhone XS through iPhone 11. Physical access required. Tye exploit is interesting, why did it went undetected for years is more interesting
100
Reposted by イヴラド
WebDesignMuseum @webdesignmuseum.org · 27/07/2026
Web Design trends in 1995 – Apple – Adobe – Pizza Hut – Netscape #WebDesignHistory
Apple website in 1995Adobe website in 1995Pizza Hut website in 1995Netscape website in 1995
1129665
Reposted by イヴラド
Nose Stuck in a Book Blog @nsiabblog.bsky.social · 28/07/2026
I feel attacked #booksky
You’re doing a lot of scrolling for someone who has a book to read
2835568837
Reposted by イヴラド
Damien Miller @damienmiller.bsky.social · 03/07/2026
A few people have asked me recently about how OpenSSH sshd implements privilege separation after the changes of the last couple of years, such as splitting sshd into multiple binaries. I finally got around to writing it up - please take a look if you're curious. github.com/openssh/open...
github.com
openssh-portable/README.privsep at master · openssh/openssh-portable
Portable OpenSSH. Contribute to openssh/openssh-portable development by creating an account on GitHub.
04612
イヴラド @kevinreddot.bsky.social · 29/06/2026
You won’t believe it, but Rob Joyce Enigma Talk is somehow 10 years old: youtu.be/bDJb8WOJYdA It was quite impactful.
youtu.be
USENIX Enigma 2016 - NSA TAO Chief on Disrupting Nation State Hackers
YouTube video by USENIX Enigma Conference
000
Reposted by イヴラド
Pure Chaos Central @chaoscentral.bsky.social · 26/06/2026
I’ve never seen anything more accurate. #PCC #ChaosCentral
021557
イヴラド @kevinreddot.bsky.social · 27/06/2026
For me, the most useful DFIR tool was always awk, not grep or Excel. Occasionally, gnuplot. This might explain why I would prefer Loki over Elastic every single time. I met quite a few people who said, “forget you SIEM, just let me grep”. 🤷‍♂️ It’s not a hot take
100
Reposted by イヴラド
Access Now @accessnow.org · 25/06/2026
A Citizen Lab investigation found evidence that Russian authorities used Cellebrite’s forensic technology to access the iPhone of activist and former political prisoner Andrey Pivovarov. ⚠️🔽 citizenlab.ca/research/rus...
citizenlab.ca
154
Reposted by イヴラド
Shifty Kinect @shiftykinect.bsky.social · 19/06/2026
This artwork is titled "Point of Crossing 1" and was created by the contemporary artist Rozanne Hermelyn Di Silvestro.
413023
Reposted by イヴラド
Zack Whittaker @zackwhittaker.com · 19/06/2026
New at this.weekinsecurity.com: I analyzed America's top companies (aka Fortune 100) and found dozens don't have any easy way to report security flaws. Of the companies that *do* have vulnerability disclosure policies, half don't actually pay for bug submissions. My blog breaks down the data:
this.weekinsecurity.com
Dozens of America's largest companies have no simple way to report security flaws
New analysis shows that around one-third of America's Fortune 100 companies do not have a vulnerability disclosure policy, bug bounty, or a dedicated email address for reporting security flaws.
1229
イヴラド @kevinreddot.bsky.social · 20/06/2026
“Zen and the art of risk acceptance” is a book I should write
110
イヴラド @kevinreddot.bsky.social · 20/06/2026
The auditors were not happy that the risk assessment report was a PDF rendered from a set of Markdown and CSV files prepared by scripts, and not Excel. They were also not happy that the list of accounts was a YAML file from the Ansible repo and not a screenshot of an Active Directory snap-in.
000
Reposted by イヴラド
European Space Agency @esa.int · 17/06/2026
Mission success for the most powerful Ariane 6 yet. ✅ Flight #VA269 launched 36 Amazon Leo satellites using upgraded boosters carrying 14 tonnes more propellant each. A new record for Europe’s heaviest payload in a single launch. 🔗 esa.int/Enabling_Sup... @transport.esa.int
esa.int
Ariane 6 launches with more powerful boosters: a new record for Europe
420838
Reposted by イヴラド
DesTROY McClure 🧟‍♂️ @trozen.bsky.social · 16/06/2026
Just a reminder, the company you work for does not care about you. You could drop dead today while working and they will replace you in a short amount of time. I say this only because we collectively need to stop giving these companies all of our energy even when we’re off the clock.
1159941153
Reposted by イヴラド
auntyr.bsky.social @auntyr.bsky.social · 15/06/2026
A world-class education is now completely free — MIT has opened its entire vault of more than 2,500 courses to the public online. source: Massachusetts Institute of Technology. (2026). About Us: MIT OpenCourseWare. MIT Open Learning. 😊
277130414447
Reposted by イヴラド
The Kimono Gallery @roger1952.bsky.social · 14/06/2026
Nara, Japan. Photography by Rajeev’s Red Carpet on Flickr
the colossal, solitary cherry blossom tree positioned dead-center within the lower-middle register. The tree erupts in an expansive, wide-flaring canopy of dense pink and lavender blossoms, its massive form acting as a brilliant explosion of light against a dark background. Rising directly behind this floral monument is a steep, towering hillside covered in a dense, primeval forest of Japanese cedars (sugi) or cypresses. This mountain canopy is rendered in deep, velvety forest greens and near-black shadows, providing a massive, monochromatic curtain that pushes the delicate, luminous pink of the sakura dramatically forward into high relief.

The lower register introduces a powerful, meditative symmetry through a flawless reflection on the water's surface. Resting in the immediate foreground is a calm, dark pond or flooded rice paddy (tanbo), its glassy surface acting as a natural mirror. The entire pink canopy of the cherry tree, along with the gnarled architecture of its dark trunk and branches, is cast upside down into the water. This reflection is rendered with a slightly softer, painterly texture and a warmer, earth-toned tint due to the underlying soil of the pond bed, anchoring the ethereal blossom to the literal earth.

The upper third of the canvas is dominated by an extraordinary, highly textured sky that injects a powerful sense of atmospheric motion into the serene landscape. A heavy blanket of altocumulus clouds stretches across the sky in a series of sweeping, rhythmic ripples or waves.
07011
イヴラド @kevinreddot.bsky.social · 05/06/2026
I liked this talk abou the IPv6-mostly networks as a transition path to the IPv6-only future: ripe92.ripe.net/programme/me... I agree we (as the industry) tried a multiple transition mechanisms and NAT64 seems to be the only working approach.
ripe92.ripe.net
Talk details: The year of IPv6-only desktop, Ondřej Caletka - RIPE 92
Talk details for 'The year of IPv6-only desktop' by Ondřej Caletka at RIPE 92
020
Reposted by イヴラド
Jorge Liboreiro @jorgeliboreiro.bsky.social · 03/06/2026
🚨🚨 Huge breaking news from Brussels: Hungary has lifted its two-year-long veto on Ukraine's EU accession. Ukraine and Moldova will soon be able to open the first cluster of the accession process. The saga is over.
212183521
Reposted by イヴラド
イヴラド @kevinreddot.bsky.social · 28/05/2026
Pegasus relies on *online* exploitation, eg, via Messages, WhatsApp or Safari. The problem with online exploitation is that with the device being online it (at least, in theory) could send a signal to home base. For example, it could send a minified crash reports that would be sufficient …
111
Reposted by イヴラド
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 26/05/2026
Here is a look at all the special security features that Apple, Google, and WhatsApp offer to protect you from spyware all in one place. We looked at what these features do, and how to turn them on. We highly recommend them for anyone who's worried about government spyware.
techcrunch.com
These special phone and app features can help protect you from spyware | TechCrunch
Apple, Meta, and Google offer special security modes that provide your devices more secure against targeted spyware attacks. Here are how those modes work, what they do, and how to switch them on.
11913
Reposted by イヴラド
The Kimono Gallery @roger1952.bsky.social · 19/05/2026
A monumental modern art kimono designed by the legendary avant-garde Japanese artist Taro Okamoto (1911–1996). Displayed at the prestigious KIMONO: Fashioning Identities special exhibition held at the Tokyo National Museum Heiseikan in 2020
a monumental modern art kimono designed by the legendary avant-garde Japanese artist Taro Okamoto (1911–1996). Displayed at the prestigious KIMONO: Fashioning Identities special exhibition held at the Tokyo National Museum Heiseikan in 2020, this garment represents a radical departure from traditional textile design. Okamoto, a towering figure in post-war modern art famous for his philosophy that "Art is Explosion," treats the classical kimono silhouette not as a conventional garment, but as a three-dimensional, living canvas for his signature abstract expressionist vocabulary.

The composition is an absolute explosion of kinetic energy, dominated by a vivid, saturated cadmium red background that instantly charges the piece with emotional intensity. Breaking across this fiery surface are massive, sweeping calligraphic brushstrokes and bold, organic fields of color that run seamlessly across the garment's panel seams. Heavy, swirling ribbons of deep black ink cut diagonally through the center and shoulders, creating a powerful, twisting rhythm. These dark, gestural bands are countered by vibrant, interlocking patches of electric blue, golden yellow, bright violet, and pristine white, evoking the raw, primitive forces of nature, flame, and cosmic energy.

Okamoto’s distinct artistic iconography is heavily integrated into the lower skirt and sleeves. On the lower half, the fiery red field dissolves into an intricate, abstract cluster of shifting shapes, featuring bold circular motifs—reminiscent of his famous stylized "eyes"—and layered, flame-like points in shades of indigo and teal. His discrete signature, "TARO," is visible on the lower right quadrant of the main body, cementing the garment's status as a wearable masterpiece.
04917
Reposted by イヴラド
Kim Zetter @kimzetter.bsky.social · 16/05/2026
Exclusive: Fast16 malware has raised questions about what it was designed to do. Researchers at Symantec finally confirm it was subverting software used to simulate nuclear weapons explosions. Nuclear experts also tell me Iran was the likely target and explain how it impacted nuclear weapons tests
zetter-zeroday.com
Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran
Fast16 didn't predate Stuxnet but was contemporaneous with it. It also wasn't aimed at altering nuclear weapons but was simply feeding false data to engineers about the nuclear detonation tests they w...
211263
イヴラド @kevinreddot.bsky.social · 12/05/2026
I like this take: arunninghacker.substack.com/p/the-cyber-... Russia repeats the Soviet Union playbook with nuclear technology and weapons: in 1940s they needed a load of engineers and scientists to work on nuclear, so they built Phystech - a university dedicated to physics and technology.
arunninghacker.substack.com
The Cyber Reality States Don’t Want to Admit
Just me ranting about the irrational Western reaction to Russia’s actual cyber capacity builing pipeline being revealed by the Bauman University leak.
110
Reposted by イヴラド
Rowdy Rebel @rowdyrebel.bsky.social · 27/04/2026
The local laundromat here does the same. I picked up novel whilst waiting on Sunday morning, haven’t put it down since. 📖🤗
1364421918
イヴラド @kevinreddot.bsky.social · 01/03/2026
Ground station
000
Reposted by イヴラド
The Kimono Gallery @roger1952.bsky.social · 26/02/2026
Torii Shinto shrine on Lake Shinji-ko, Shimane, Japan. Photography The Sankei Shimbun
Torii Shinto Shrine on Lake Shinji-ko
This evocative sunset photograph by The Sankei Shimbun captures the iconic torii gate of Yomegashima Island on Lake Shinji-ko in Shimane Prefecture. The composition is defined by a dramatic, fiery red palette, with the low-angled sunlight reflecting intensely off the gentle ripples of the water's surface in the foreground. In the distance, the small, tree-covered silhouette of the island sits anchored in the lake, centered around the white stone torii gate that glows brightly against the dark foliage. The sky above is filled with long, horizontal bands of orange and crimson clouds, creating a sense of vastness and spiritual serenity. This location is renowned as one of Japan's most beautiful sunset spots, where the architectural symbol of Shintoism meets the profound natural beauty of the lake.
04313
Reposted by イヴラド
David Aerne @meodai.bsky.social · 21/02/2026
Built a “3D” sphere (SVG) to show RYB transformations. Over-iterated in @codepen.io 10% optimization, 90% procrastination. codepen.io/meodai/full/...
191369217
Reposted by イヴラド
The Kimono Gallery @roger1952.bsky.social · 17/02/2026
Theater Signboard Depicting Scenes from the Play Nishikigi Sakae Komachi Attributed to: Torii School 1758, Japan William Sturgis Bigelow Collection, MFA The bold outlines, flat areas of color, and exaggerated expressions were designed to catch the eye of passersby from outside the theater.
This vibrant and dynamic theater signboard, attributed to the Torii School and dating to the 8th month of 1758, depicts a climactic scene from the Kabuki play Nishikigi Sakae Komachi. The composition is split between an interior veranda and an outdoor setting, featuring several prominent actors in highly stylized poses and elaborate costumes. On the upper level, characters in bold checkered and floral kimonos engage in an intense dialogue, while the lower level features a dramatic encounter involving a figure with a red-painted face and a large straw hat, and another holding a traditional oiled-paper umbrella over a seated woman. The use of bold outlines, flat areas of color, and exaggerated expressions is characteristic of the Torii School's yakusha-e (actor print) style during the Edo period, designed to catch the eye of passersby from outside the theater.
0258
Reposted by イヴラド
Catalin Cimpanu @campuscodi.risky.biz · 20/02/2026
-RPKI infrastructure sits on shaky ground -Breach at the French Economy Ministry -UK wants tech platforms to take down revenge porn in 48h -ClickFix linked to half of malware infections -Angolan journalist hacked with Predator Podcast: risky.biz/RBNEWS528/ Newsletter: news.risky.biz/risky-bullet...
4186
Reposted by イヴラド
Matt Burgess (WIRED) @mattburgess1.bsky.social · 16/02/2026
“If Mastercard and Visa were turned off, it would send us back to the 1950s,” before cards dominated the UK economy, and businesses wholly relied on cash, one executive familiar with the project told the Guardian. “Of course, we need a sovereign payments system.”
theguardian.com
UK bank bosses plan to set up Visa and Mastercard alternative amid Trump fears
Exclusive: First meeting to be held over domestic payments system aimed at reducing reliance on US networks
67520
Reposted by イヴラド
Bipedal Meatbag @bipedalmeatbag.bsky.social · 16/02/2026
Someone captured my colleagues an I servicing the cameras during Kīlauea’s episode 42. We stopped to discuss what we were seeing, but because I talk with my hands it looks like I’m fixing to push someone in… Credit: Volcano Hideaways
A zoomed in look at 4 scientists working with the a lava fountain covering the entire background. A very tall lava fountain with tiny dots (people) near the base. The image is a bit forced perspective and we are not as close as it looks
952262330
Reposted by イヴラド
The Verge @theverge.com · 09/01/2026
Tim Cook and Sundar Pichai are cowards
buff.ly
Tim Cook and Sundar Pichai are cowards
Once you’ve traded your principles for proximity to power, do you even run your own company?
14426110
イヴラド @kevinreddot.bsky.social · 02/01/2026
Deers in Nara park, Japan
000
Reposted by イヴラド
Rudbeckia @rudbeckia.bsky.social · 01/01/2026
uh holy SHIT?
157233110
イヴラド @kevinreddot.bsky.social · 13/11/2025
After 25 years, we now mostly know how to secure Active Directory - with PAWs, Red Forest, JEA, disabling NTLM, hardening LSA with VBS, the list goes on. Unfortunately, Microsoft pushes everyone away from it and we may need another 25 years to learn how to secure clouds.
110
Reposted by イヴラド
The Kimono Gallery @roger1952.bsky.social · 04/10/2025
Suzuki Harunobu Title: Woman Running to Escape a Sudden Shower, Edo period, circa 1765-1770, Japan Date: Edo period, Middle, 1704-1789
0319
Reposted by イヴラド
Bodleian Libraries @bodleian.ox.ac.uk · 15/09/2025
Our medieval curator Alison Ray introduces Rawlinson Bodleian Library MS. Rawl. D. 252...a 15th Century necromancer's journal. This manuscript contains spells written in Latin and Middle English, and would have served as a reference for a professional sorcerer. #MedievalMonday
22791230
Reposted by イヴラド
Internet Archive @archive.org · 08/09/2025
☕ Monday morning? We’re already scanning. Start your week with the #InternetArchive’s microfiche livestream: #lofi beats, archival preservation, & tiny sheets of history. 📡 Tune in ➡️ www.youtube.com/live/aPg2V5R... #LiveStream #bookscan #LiveNow
111716
Reposted by イヴラド
Catalin Cimpanu @campuscodi.risky.biz · 05/02/2025
Germany's cybersecurity agency has discovered multiple vulnerabilities in the Nextcloud cloud file syncing and sharing platform that can be used to bypass 2FA security systems www.bsi.bund.de/DE/Service-N...
bsi.bund.de
BSI untersucht Open Source Software "Nextcloud"
Im Rahmen eines Projektes zur Codeanalyse von Open Source Software (CAOS) hat das BSI die Open Source Kollaborationssoftware "Nextcloud" auf ihre Sicherheitseigenschaften untersucht.
13019