Sign in

Risky Mr. Kim

@riskim.bsky.social
13 followers 123 following 34 posts

Threat modeling, reverse engineering and general infosec. Awful chess player, dad, expat.

PostsRepliesMedia
Reposted by Risky Mr. Kim
honkers_enjoyer @epicharis.bsky.social · 07/08/2026
#DEFCON may have taken a stand against pervert glasses but celebrating the other most fash-coded accessory is fine I guess
A photo from DEFCON displaying a sponsor banner from Zyn, owned by Philip Morris.
133
Reposted by Risky Mr. Kim
Mrs. Betty Bowers @mrsbettybowers.bsky.social · 08/06/2026
"Apple, Google, and Meta are very excited to announce the release of new AI-driven products. We guarantee that they will respect your privacy. Unfortunately, these products are not available in Europe, as they have laws to protect your privacy."
8343901390
Reposted by Risky Mr. Kim
Jason Koebler @jasonkoebler.bsky.social · 28/05/2026
New: Regretful cities are literally covering their Flock cameras with black trash bags because they cannot figure out how to immediately exit their surveillance contracts or get the cameras taken down: www.404media.co/cities-are-c...
404media.co
Cities Are Covering Flock Cameras With Trash Bags
Regretful cities aren't sure how to cancel their surveillance contracts, so they are literally covering their cameras.
12142331481
Reposted by Risky Mr. Kim
XBOW @xbow.com · 18/05/2026
“XBOW found that Mythos was ‘good, but less powerful, at validating exploits’ and that the model could be ‘too literal and conservative,’ sometimes overstating the practical significance of its findings,” writes Sam Sabin in @axios.com. More on our analysis of Mythos Preview: bit.ly/4tA87Eo
bit.ly
The next phase of AI cybersecurity still needs humans
The new phase of AI-powered cybersecurity depends on how effectively humans can direct these models.
012
Reposted by Risky Mr. Kim
cje @cje.io · 15/05/2026
This is *really* cool work by David Brumley, Seunghyun Lee, and the CMU crew. Instead of benchmarking against vuln discovery, ExploitBench evaluates the full F3AD pipeline m.cje.io/4wztnN7
exploitbench.ai
ExploitBench
How far up the exploitation ladder can an agent climb on a production JS engine? ExploitBench measures frontier LLMs on full-control V8 exploit synthesis with 16 capabilities measured per run and…
084
Reposted by Risky Mr. Kim
Catalin Cimpanu @campuscodi.risky.biz · 22/04/2026
"Bundestag President Julia Klöckner is among the victims of the current wave of attacks on Signal users" www.spiegel.de/politik/deut...
spiegel.de
(S+) Julia Klöckner ist Opfer des Signal-Hacks
Nach SPIEGEL-Informationen gehört Bundestagspräsidentin Julia Klöckner zu den Opfern der aktuellen Angriffswelle auf Signal-Nutzer. Auch das Handy des Bundeskanzlers wurde bereits untersucht.
165
Reposted by Risky Mr. Kim
Mark Dowd @mdowd.bsky.social · 09/04/2026
Brief announcement: Launching Unprompted.au later this year in Sydney — a new conference focused on offensive and defensive security research using AI, and on how AI is reshaping the field. Sister conference to Unprompted. More updates coming soon
183
Reposted by Risky Mr. Kim
TechCrunch @techcrunch.com · 06/04/2026
“We’re on the side of humans against machines, which sounds a little bit like science fiction, but that’s very concretely what we do.” A mission against malware has turned into a battle against drone warfare for Mikko Hyppönen, and @lorenzofb.bsky.social explores why in his latest feature.
spr.ly
After fighting malware for decades, this cybersecurity veteran is now hacking drones | TechCrunch
Mikko Hyppönen is one of the most recognizable faces of the cybersecurity industry. After fighting computer viruses, worms, and malware, for more than 35 years, he tells TechCrunch why he is now working on systems to stop killer drones.
0126
Reposted by Risky Mr. Kim
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 24/03/2026
Please send me the best Sora obituaries for my schadenfreude needs.
1156
Reposted by Risky Mr. Kim
Sander van der Linden @profsanderlinden.bsky.social · 16/03/2026
Meta and TikTok let harmful content rise after evidence outrage drove engagement, say whistleblowers. Fascinating deep dive 👇 www.bbc.com/news/article...
bbc.com
Meta and TikTok let harmful content rise after evidence outrage drove engagement - whistleblowers
Companies allowed more harmful content on user’s feeds, knowing their algorithms ran on outrage, BBC hears.
13210
Reposted by Risky Mr. Kim
XBOW @xbow.com · 16/03/2026
The International AI Safety Report 2026 concludes that fully autonomous attacks aren’t here yet…the experiences of teams deploying real-world autonomous offense tell a different story. Explore the gap between assumption and operational reality in our latest blog: bit.ly/4sjKrnN
002
Risky Mr. Kim @riskim.bsky.social · 05/03/2026
www.buchodi.com/your-duoling...
buchodi.com
Your Duolingo Is Talking to ByteDance: Cracking the Pangle SDK's Encryption
When you open Duolingo to practice Spanish, BeReal to share a photo, or Character.AI to chat with a bot, you probably don't expect your battery level, storage capacity, and internal IP address to be s...
000
Reposted by Risky Mr. Kim
Lea Kissner @leak.bsky.social · 02/03/2026
Are you selling a security product? Can you please do us both a favor and just tell me what it is? Just explain literally what it does and how. Risky Business was kind enough to start a catalogue with useful descriptions for their advertisers, but can we please normalize this? risky.biz/catalog/
risky.biz
Catalog - Risky Business Media
Catalog
2163
Reposted by Risky Mr. Kim
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/02/2026
NEW: For months, I’ve been working on the story of Peter Williams, the former U.S. defense contractor who stole several hacking tools and then sold them to a Russian broker. Here’s what we know about the case, what we still don’t know, and a peek behind the scenes at how I reported this story.
techcrunch.com
Inside the story of the US defense contractor who leaked hacking tools to Russia | TechCrunch
The former boss of a U.S. hacking tools maker was jailed for selling highly sensitive software exploits to a Russian broker. This is how we first learned of his arrest, reported the story, and some of...
13729
Reposted by Risky Mr. Kim
TechCrunch @techcrunch.com · 24/02/2026
Peter Williams, the former head of U.S. hacking tools maker L3Harris Trenchant, was sentenced to seven years in prison for stealing and selling his former company’s hacking and surveillance tools to a Russian firm.
techcrunch.com
Former L3Harris Trenchant boss jailed for selling hacking tools to Russian broker | TechCrunch
Peter Williams, the former head of U.S. hacking tools maker L3Harris Trenchant, was sentenced to seven years in prison for stealing and selling his former company’s hacking and surveillance tools to a Russian firm.
0204
Reposted by Risky Mr. Kim
nitasha tiku @nitasha.bsky.social · 04/02/2026
My story on Elon Musk cutting safeguards at xAI is on the front page of today's @washingtonpost.com. I’m also among 100’s of reporters laid off. I absolutely loved my job my brilliant coworkers & the thrill of reporting @ the center of forces upending the world: AI & Silicon Valley’s political power
cover of The Washington Post on Wednesday Feb 4, 2026. Headline on bottom, right: Musk wanted to hook users; his chatbot got more sexual
15666112109
Reposted by Risky Mr. Kim
Best of r/cybersecurity @cybersecurity.page · 23/01/2026
Curl is ending its bug bounty program due to a surge of low-quality AI-generated reports.
reddit.com
Curl ending bug bounty program after flood of AI slop reports
View post on Reddit.
012
Reposted by Risky Mr. Kim
Little Fury Fellah @elnosnusk.bsky.social · 23/01/2026
@vonderleyen.ec.europa.eu and (I can’t reach Starmer here), perhaps something could be done? russia is using that money to fight a war against Europe after all.
131
Reposted by Risky Mr. Kim
auonsson @auonsson.bsky.social · 23/01/2026
This one, just minutes old. A flagless Putin-tanker entering Baltic Sea. There is 0 legal reasons to not stop these ones. Law is clear, any navy can stop them for inspection anywhere. bsky.app/profile/pa.n...
214836
Reposted by Risky Mr. Kim
Bellingcat @bellingcat.com · 23/01/2026
Don’t know what to trust on your feed? How did we get here? Next Thursday, @eliothiggins.bsky.social and @cward1e.bsky.social unpack the rise, backlash and future of counter-disinformation. Join us for a live Q&A on Discord. 11am EST / 5pm CET discord.gg/ApEnkSK6?eve...
How we got here: the rise, backlash and future of counter disinformation. Bellingcat Stage Talk , Thursday 29/1, 5pm CET/11am EST Discord.com/invite/bellingcat . Eliot Higgins founder Bellingcat, Claire Wardle, Associate Professor Cornell University
2322117
Reposted by Risky Mr. Kim
Suzanne Smalley @suzannesmalley.bsky.social · 22/01/2026
Spanish judge closes probe into NSO in wake of Pegasus hack of several govt officials, incl the PM. Court says Israel ignored five requests for information and probe can't proceed as a result. NSO has historically been shielded from accountability by the Israeli govt therecord.media/spanish-judg...
therecord.media
Spanish judge closes NSO Group spyware probe due to lack of cooperation from Israel
The case dates to May 2022, when the court launched a probe into the alleged spying on devices belonging to Prime Minister Pedro Sánchez and Defence Minister Margarita Robles.
01215
Reposted by Risky Mr. Kim
Jayson E. Street💜🤗💜 @jaysonstreet.bsky.social · 22/01/2026
I was recently laid off, so I’m officially open to new opportunities. If you need a Hacker, or a teachable moment using Red Team tactics. I can also be a trainer, community builder & liaison. I want more than a job I need a company & purpose I can believe in. Please share! 💜🤗💜
35027
Reposted by Risky Mr. Kim
Eliot Higgins @eliothiggins.bsky.social · 18/01/2026
Boycott the World Cup - Growing sense of embarrassment at Fifa over Donald Trump peace prize www.theguardian.com/football/202...
theguardian.com
Growing sense of embarrassment at Fifa over Donald Trump peace prize
There is a growing sense of embarrassment among mid-level and senior officials within Fifa over the awarding of the peace prize to Donald Trump
42529137
Reposted by Risky Mr. Kim
Romain Thomas (@rh0main) @rh0main.bsky.social · 05/01/2026
I reverse engineered DexProtector, the security solution protecting applications like Revolut and other banking apps. From custom ELF loaders to vtable hooking, here is an insight into how these protections work and their limitations. www.romainthomas.fr/post/26-01-d...
romainthomas.fr
A Glimpse Into DexProtector | Romain Thomas
This blog post provides a high-level overview of DexProtector's security features and their limitations
13412
Reposted by Risky Mr. Kim
Catalin Cimpanu @campuscodi.risky.biz · 04/01/2026
"Flights across Greece were grounded on Sunday after a collapse of radio frequencies crippled air traffic communication, stranding thousands of travellers and bringing airport operations to a halt." www.reuters.com/world/europe...
reuters.com
Radio frequency loss grounds flights in Greece, stranding thousands
"For some reason all frequencies were suddenly lost .. We could not communicate with aircraft in the sky," the head of Greece's air-traffic controllers association told the state broadcasters.
193
Reposted by Risky Mr. Kim
Daniel Cuthbert @dcuthbert.bsky.social · 07/12/2025
Crypto, queens and taking notes on a massive criminal conspiracy. Smashing Zhimin Qian’s 5 Billion empire Good insights into money laundering at this scale youtu.be/EymtOOJmRpo?...
youtu.be
Crypto Queen | Dismantling a £5 Billion Bitcoin Empire
YouTube video by Metropolitan Police
021
Reposted by Risky Mr. Kim
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 04/12/2025
“AI is helping to identify over 70% of targets. Sometimes AI is hallucinating targets. So we always need humans in the loop.” - Heli Tiirmaa-Klaar in her SANS CyberThreat keynote “Cyber war by proxy: What Ukraine teaches us about defense coalitions and digital policy at scale”
Heli Tiirmaa-Klaar a blonde woman dressed in black with a pink blazer delivers a keynote on stage at CyberThreat London 2025
0206
Reposted by Risky Mr. Kim
evacide @evacide.bsky.social · 06/11/2025
Because iOS stalkerware tends to work by requiring the target's AppleID and covertly making backups, which means that the stalkerware does not live on the phone.
1133
Reposted by Risky Mr. Kim
Catalin Cimpanu @campuscodi.risky.biz · 26/10/2025
A recent study has found that while 95% of respondents are confident about their ability to recover from a ransomware attack using their backups, only 15% of those who were attacked managed to do so investors.opentext.com/press-releas...
1197
Reposted by Risky Mr. Kim
Social Media Lab @socialmedialab.ca · 19/10/2025
The Dutch General Intelligence and Security Service has stopped sharing certain information with the United States: “Sometimes we no longer share things,” officials say, because the information has been finding its way into Kremlin hands. www.volkskrant.nl/binnenland/n...
volkskrant.nl
Nederlandse diensten delen minder informatie met de VS: ‘Soms vertellen we dingen niet meer’
Het aantal dreigingen dat op Nederland afkomt is groot, zien de hoofden van de AIVD en de MIVD elke dag: niet alleen Russische agressie, maar ook de opmars van China als digitale macht en binnenlands ...
10260139
Reposted by Risky Mr. Kim
Marc Owen Jones @marcowenjones.bsky.social · 16/10/2025
AI is learning disinfo. A fake quote about Hamas spread on X… and now Google’s Gemini is repeating it as fact. From rumour → news → “AI truth.” Read how it happened How Google’s Gemini AI is Learning Pro-Israel Disinformation From Social Media open.substack.com/pub/marcowen... #Dysinfluence
open.substack.com
How Google's Gemini AI is Learning Pro-Israel Disinformation From Social Media
A fake quote attributed to Hamas official Khalil Al Hayya is being regurgitated by Gemini AI
13316
Reposted by Risky Mr. Kim
Heather Adkins @argv.bsky.social · 08/10/2025
Stop what you’re doing and read this… don’t get surprised by what’s coming. It’s time to rethink everything you’re doing on cyber defense. H/T to Gadi and Bruce for partnering on this opinion piece. www.csoonline.com/article/4069...
csoonline.com
Autonomous AI hacking and the future of cybersecurity
AI agents are automating key parts of the attack chain, threatening to tip the scales completely in favor of cyber attackers unless new models of AI-assisted cyberdefense arise.
064
Reposted by Risky Mr. Kim
Alan Jagolinzer @jagolinzer.bsky.social · 04/10/2025
Stanford neuroscientist Anna Lembke on dopamine addiction, including from social media. www.youtube.com/watch?v=J4jT...
youtube.com
Stanford neuroscientist Prof Anna Lembke discusses dopamine addiction, that applies to social media
YouTube video by Cambridge Disinformation Summit
01410
Reposted by Risky Mr. Kim
Sharon 🪳🌹 @sharonk.bsky.social · 14/09/2025
korean reporting is nightmarish on the conditions Korean workers were contained in
Their waists and hands were tied together, forcing them to bend down and lick water to drink. The unscreened bathrooms contained only a single sheet to cover their lower bodies. Sunlight barely penetrated through a fist-sized hole, and they were only allowed access to the small yard for two hours. Detained by US immigration authorities for eight days, the workers and their families expressed shock, describing human rights violations and absurdities they could not have imagined as ordinary Koreans living in 2025.
892485010088
Reposted by Risky Mr. Kim
Catalin Cimpanu @campuscodi.risky.biz · 02/09/2025
Jaguar Land Rover says a cyber-attack has "severely disrupted" vehicle production as well as its retail operation www.bbc.com/news/article...
bbc.com
Jaguar Land Rover production severely hit by cyber attack
Staff were sent home and the company shut down its IT systems in an effort to minimise the damage done.
032
Reposted by Risky Mr. Kim
Justin Hendrix @justinhendrix.bsky.social · 20/08/2025
Chatbots are not people and should not be treated as such. But the companies providing services that mimic the services provided by people have to be responsible for the services they provide, writes Mark MacCarthy. www.techpolicy.press/ai-companies...
techpolicy.press
AI Companies Should be Liable for the Illegal Conduct of AI Chatbots | TechPolicy.Press
Companies providing services that mimic those provided by people have to be responsible for the services they provide, writes Mark MacCarthy.
13518
Reposted by Risky Mr. Kim
evacide @evacide.bsky.social · 19/08/2025
The founders of the Tea app tried to recruit a female co-founder and face for the app, telling her "Tea has all the safety measures that Facebook lacked and more to ensure that only women are in the group." www.404media.co/how-teas-fou...
404media.co
How Tea’s Founder Convinced Millions of Women to Spill Their Secrets, Then Exposed Them to the World
A 404 Media investigation reveals how the man who started Tea, the ‘women dating safety’ app, tried to hire a female ‘face’ for the company and then hijack her grassroots community.
17417
Reposted by Risky Mr. Kim
Heather Adkins @argv.bsky.social · 02/07/2025
Good article out from @danielmiessler.bsky.social on using AI properly. danielmiessler.com/blog/how-to-...
danielmiessler.com
Why Prompt Engineering and Context Engineering Both Miss the Point
The debate between prompt and context engineering misses what really matters: clear thinking and vision
141
Reposted by Risky Mr. Kim
XBOW @xbow.com · 24/06/2025
XBOW is now generally available. See it in action → Book a demo with our team. www.xbow.com
xbow.com
XBOW
Boosting offensive security with AI
121
Reposted by Risky Mr. Kim
Alan Jagolinzer @jagolinzer.bsky.social · 22/06/2025
When there's a seemingly coordinated influencer campaign.
43710
Reposted by Risky Mr. Kim
The New Yorker @newyorker.com · 16/06/2025
Of the hundreds of thousands hit by the atomic bombings in Hiroshima and Nagasaki, 10 to 20 per cent were Korean. Though they had much in common with Japanese victims, they were denied specialized medical coverage and sidelined.
newyorker.com
The Atomic Bombs’ Forgotten Korean Victims
Survivors of the nuclear blasts in Hiroshima and Nagasaki are still fighting for recognition.
19565195
Reposted by Risky Mr. Kim
Nathan Hamiel @nhamiel.bsky.social · 12/06/2025
I present to you the power and possibility of using AI for entertainment. All it takes is an idea. Trust me, it's going to get a lot worse from here on out. Enjoy 😆 www.youtube.com/watch?v=lTcU...
youtube.com
Back to the Future 4 (2025) - First Trailer | Tom Holland, Robert Downey Jr.
YouTube video by KH Studio
001
Reposted by Risky Mr. Kim
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 11/06/2025
NEW: Someone has defaced a U.S. Department of Health and Human Services with gay and LGBTQ+-themed AI slop spam. The site has been defaced since at least mid-May, and it appears to be part of wider spam campaign. techcrunch.com/2025/06/11/u...
techcrunch.com
US government's vaccine website defaced with AI-generated content | TechCrunch
The content of a vaccines information website owned U.S. Department of Health and Human Services was swapped with gay-themed spam.
262
Reposted by Risky Mr. Kim
Stefano Zanero @raistolo.bsky.social · 11/06/2025
While people blabbed about “alignment” and “super intelligence”, the much shorter-term, obvious from the start, devastating damages of chatbots powered by LLMs are here on full display. And no one built safeguards for them.
084
Reposted by Risky Mr. Kim
🇬🇾🗽Sydette The Dreaded Gorgon🗽🇬🇾 @blackamazon.bsky.social · 02/06/2025
They killed the DOG . The lit their HOUSE on fire They were targeting these men for TWO YEARS There’s no big tent for this . They want the power to do this and their willing to KILL for it
181221416
Reposted by Risky Mr. Kim
Techmeme @techmeme.com · 25/05/2025
A security researcher details how he discovered a zero-day vulnerability in the Linux kernel's SMB implementation by analyzing the code using OpenAI's o3 API (Sean Heelan/Sean Heelan's Blog) Main Link | Techmeme Permalink
0156
Reposted by Risky Mr. Kim
Best of r/cybersecurity @cybersecurity.page · 24/05/2025
A website attempted to trick a user into executing Windows commands as part of a CAPTCHA verification. The user was directed to press key combinations involving (win + r), (ctrl + v), and (enter), which they suspected might be a hacking attempt. They plan to test it in a VM later.
reddit.com
Web site tried to trick me into running windows commands to complete CAPTCHA
I visited this site while doing some research on CSRF attempts in html iframes. The site popped up with the usual cloud flare CAPTCHA, I just clicked verify without thinking to much about it and to...
001
Reposted by Risky Mr. Kim
Marietje Schaake @marietjeschaake.bsky.social · 22/05/2025
OMG, Trump Administration revoked the certification for Harvard to enroll international students! ↘️ www.nytimes.com/2025/05/22/u...
nytimes.com
Trump Administration Halts Harvard’s Ability to Enroll International Students
034
Reposted by Risky Mr. Kim
Women's Chess Coverage @onthequeenside.bsky.social · 22/05/2025
TAN ZHONGYI JUST BEAT RICHARD RAPPORT!!!!!!! 🤩🥳🎉😃👏👏 IT'S THE FIRST TIME TAN HAS EVER BEATEN A SUPER-GM (!!), AND IT'S NOT JUST ANY SUPER-GM, IT'S RICHARD RAPPORT (2722)! 🤯 lichess.org/broadcast/te... 📷: Mikael Svensson #chess #womeninchess
1151