Sign in

Spanky

@spankowitz.bsky.social
152 followers 754 following 45 posts

I like threat intel, purple team, and turtles.

PostsRepliesMedia
Reposted by Spanky
Ian Campbell @neurovagrant.bsky.social · 23/09/2026
Has anyone written a "Who's on first?" routine about DNS yet? "What're you looking at?" "A record." "Yes I know it's a record, what is it?" "A record that seems to be a C2 domain." "Okay whatever, now you're just making up things with letters and numbers. Where is this C2 stuff?"
183
Reposted by Spanky
ESET Research @esetresearch.bsky.social · 17/09/2026
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
177
Reposted by Spanky
Botty.bot @infosecbot.bsky.social · 15/09/2026
No one will take accountability for all the stupid shit those nerds said, but moving forward you can tune them out (or make fun of them) when they say stupid shit. Something like "just crunch the tokens and shut up, nerd.… — from @ImposeCost (x.com/ImposeCost/status/20998139095…)
011
Reposted by Spanky
Dirk-jan @dirkjanm.io · 14/09/2026
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/ask...
github.com
GitHub - dirkjanm/askWAM: Ask the Web Account Manager (WAM) for Entra ID tokens
Ask the Web Account Manager (WAM) for Entra ID tokens - dirkjanm/askWAM
1103
Reposted by Spanky
CYBERWARCON @cyberwarcon.bsky.social · 10/09/2026
CYBERWARCON is BACK for 2026! Registration and CFP are now officially open! We’ll be in Arlington, VA+ virtually on November 20th, with Rob Joyce as our keynote. cyberwarcon.com 1/x
21916
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 08/09/2026
🔥 NEW POD: This week's problem is available on all platforms @craiu.bsky.social @jags.bsky.social @tlpblack.bsky.social 📺 Watch on YouTube 👇 youtu.be/bQ-mpjx07m4?...
youtu.be
Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs.
YouTube video by Three Buddy Problem
032
Reposted by Spanky
Elle Cordova @ellecordova.bsky.social · 03/09/2026
Rough Draft vs Final Draft
253116683307
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 30/08/2026
NEW POD UP: A thousand agents walk into Hugging Face 🚨 Spotify: open.spotify.com/episode/1CMM... 🎧 Apple Podcasts: podcasts.apple.com/us/podcast/a... ✍ Transcript: docs.google.com/document/d/1... 📺 YouTube: youtu.be/2cWaxPwyx9c?...
open.spotify.com
A Thousand Agents Walk Into Hugging Face
Three Buddy Problem · Episode
041
Reposted by Spanky
SpecterOps @specterops.io · 19/08/2026
Can this role read that bucket?" and "Can it decrypt that key?" aren't the same question. @n0pe-sled.bsky.social's latest blog post introduces AWSHound, free, self-hosted, turns AWS Orgs into real BloodHound CE attack paths. Check it out: ghst.ly/4g4EJm9
ghst.ly
AWSHound: An OpenSource AWS OpenGraph Collector
See how AWSHound maps AWS attack paths into BloodHound, evaluating IAM policies, SCPs, and boundaries to reveal real privilege escalation.
032
Reposted by Spanky
Tony Hafoka Ao NZ TON @ahafoka.bsky.social · 30/07/2026
Image of a classic Nokia phone sitting in a chair with 2 smart phones at its feet. 

The Nokia is saying “When I fell nothing would happen to me. I wasn’t delicate like you kids. “
0346
Reposted by Spanky
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 27/07/2026
Apropos of nothing, I think it's past time for risks.txt to go alongside robots.txt and security.txt on websites. risks.txt would declare the contents of the organization's risk acceptance log so the $baddies know not to use those issues in attacks.
014
Reposted by Spanky
intrusiontruth.bsky.social @intrusiontruth.bsky.social · 27/07/2026
intrusiontruth.wordpress.com/2026/07/27/d...
intrusiontruth.wordpress.com
Dear Diary, Today I found a Ghost in the Network
A hidden seller Guangdong Chanming. If you were looking for them, you’d be disappointed. No public website, no storefront, and certainly no obvious product line to speak of. It made us wonder what …
076
Reposted by Spanky
The Onion @theonion.com · 26/07/2026
U.S. Mint Unveils Series Of Gold Coins Commemorating President’s Extramarital Affairs
theonion.com
U.S. Mint Unveils Series Of Gold Coins Commemorating President’s Extramarital Affairs
WASHINGTON—Touting the new line of currency as an important way to recognize the many babes bagged by the commander-in-chief over the years, the U.S. Mint announced plans Wednesday to release a series...
311367235
Spanky @spankowitz.bsky.social · 23/07/2026
Roughly 70% of hosts running ICS devices and services globally are consistently found on consumer and mobile networks for the last 2.5 years.
000
Reposted by Spanky
Binary Ninja @binary.ninja · 22/07/2026
Celebrate 10 years of Binary Ninja! For the first time ever, we’re offering a 35% discount! Join us for 10 full days of giveaways including licenses, merch, and more. Join in on the celebration: binary.ninja/10years
111
Reposted by Spanky
CYBERWARCON @cyberwarcon.bsky.social · 16/07/2026
Mark your calendars!
1188
Reposted by Spanky
IFIN @ifin-intel.org · 18/07/2026
A reminder that we have a MISP feed! misp.ifin.network/feed (`/manifest.json` for validation)
misp.ifin.network
031
Reposted by Spanky
Joe Slowik @pylos.co · 27/05/2026
I will hold an online session of the Paralus LLC Applied #CyberThreatIntelligence course from 27-31 July, 1400-1600 US Eastern/2000-2200 Central European time. Focused, to the point training, two hours per day for five days. Register your interest at the following form: forms.gle/M1LgQTomJGek...
forms.gle
Paralus LLC: Applied Threat Intelligence
Hello and thank you for your interest in a workshop focusing on Applied Threat Intelligence! Scheduling: 27-31 July 2026 (Five Days) 1400-1600 US Eastern/2000-2200 Central European (Two Hours/Day) C...
11310
Reposted by Spanky
Jason Koebler @jasonkoebler.bsky.social · 08/07/2026
A developer made a browser extension called "Knockoff" that shows what a wasteland Amazon truly is by filtering out brands like "GODONLIF" "EHEYCIGA," ROTTOGOON," and sponsored products. Useful and illustrative even if you don't use Amazon www.404media.co/knockoff-bro...
404media.co
'Knockoff' Browser Extension Hides Sketchy Brands on Amazon
"Sorry to brands like WNPETHOME, EHEYCIGA, YXYL, LU&MN, JOYIN, TOMY, GODONLIF, YOOJEE, LINGTENG, LANEIGE, VISCOO, BIODANCE, COOFANDY, BALENNZ, TOSY, and LUENX."
331254350
Reposted by Spanky
Molly White @molly.wiki · 01/07/2026
It does not fill me with optimism about the general quality or completeness of this disclosure that it gives the wrong name for the firm via which Trump made $635 million last year.
231857
Spanky @spankowitz.bsky.social · 29/06/2026
No Three Buddy Problem this week. My disappointment is immeasurable. What am I supposed to listen to on my dog walkies?!?? Oh right, Between 2 Nerds. 🙌
010
Spanky @spankowitz.bsky.social · 27/06/2026
www.nytimes.com/2026/06/26/u...
nytimes.com
John Bolton, Former Trump Adviser, Pleads Guilty in Classified Information Case
000
Reposted by Spanky
The Citizen Lab @citizenlab.ca · 25/06/2026
1/ NEW RESEARCH: We find that Russian authorities used Cellebrite to gain access to activist Andrey Pivovarov’s phone. Full brief: citizenlab.ca/research/rus...
citizenlab.ca
Russia Breaks Into Human Rights Activist's Phone With Cellebrite - The Citizen Lab
We analyzed Russian activist Andrey Pivovarov’s phone, finding that Russian authorities used forensic extraction tools made by Cellebrite to gain access to his device. A document prepared by Russian a...
11815
Reposted by Spanky
CNN @cnn.com · 23/06/2026
A newly discovered spider species from Australia uses its silk to craft a spring-loaded, cone-shaped death trap, which catapults its prey into the spider’s main web. cnn.it/4w3n6Ip
48117
Reposted by Spanky
JHunt🛡️ @jhuntinfosec.com · 23/06/2026
Thanks @halvarflake.bsky.social -- it's so good / must read (and it's not even finished yet!)
042
Reposted by Spanky
BeijingPalmer @beijingpalmer.bsky.social · 21/06/2026
iran has closed the reflecting pool.
393120447
Reposted by Spanky
Krista Elliott @kristaelliott.bsky.social · 16/06/2026
AI may have inherited the em-dash addiction from hordes of writers -- but it can pry them from our cold, dead hands.
0183
Spanky @spankowitz.bsky.social · 05/06/2026
@sleuthcon.bsky.social
static.klipy.com
Wolf Of Wall Street: Lets Gooo!
ALT: Wolf Of Wall Street: Lets Gooo!
001
Spanky @spankowitz.bsky.social · 02/06/2026
DAMN STRAIGHT
030
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 30/05/2026
NEW POD UP: Microsoft threatens legal action against researchers who drop zero-days. We debate whether it’s a fair line against extortion, or amateur-hour PR from a company that already torched its own research community? #threebuddyproblem youtu.be/E5rIJ9nGOUo
youtu.be
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited
YouTube video by Three Buddy Problem
154
Reposted by Spanky
JHunt🛡️ @jhuntinfosec.com · 23/05/2026
www.nytimes.com/2026/05/22/u...
nytimes.com
White House Approves $9 Billion for Spy Agencies to Catch Up on A.I.
021
Reposted by Spanky
The Register @theregister.com · 22/05/2026
Google explains how it will infuse ads into AI answers
theregister.com
Google explains how it will infuse ads into AI answers
Just like in The Truman Show
165
Reposted by Spanky
Paresh Dave @peard33.bsky.social · 20/05/2026
www.wired.com/story/spacex...
wired.com
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
The long-awaited documents SpaceX filed with US regulators Wednesday included details about a lucrative deal to lend GPUs to a major AI rival.
13516
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 10/05/2026
NEW POD UP! We discuss the disappearing art of Windows APT paleontology, the absence of complex malware documentation, and why so much threat-intel research has slipped behind paywalls and into private rooms. - Spotify open.spotify.com/episode/0eh4... - Apple podcasts.apple.com/us/podcast/t...
185
Reposted by Spanky
halvarflake.bsky.social @halvarflake.bsky.social · 13/05/2026
www.faz.net/premium/digi... I wrote a FAZ guest article.
faz.net
Thomas Dullien zu Anthropics Mythos: Software war nie auf perfekte Sicherheit ausgelegt - das rächt sich
Schwachstellen in Computern wurden lange hingenommen. Denn sie auszunutzen war technisch komplex und teuer. KIs ändern das nun. Damit zwingen sie uns, Altlasten schneller anzugehen.
33111
Reposted by Spanky
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 12/05/2026
NEW: Google is rolling out a new feature for Android called Intrusion Logging, designed specifically to help researchers investigate attacks done with spyware and forensic tools. Amnesty says this is “a fundamental shift in the amount and quality of forensic data available on Android devices.”
techcrunch.com
Google launches new Android security feature to help uncover spyware attacks | TechCrunch
Intrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement...
45827
Spanky @spankowitz.bsky.social · 12/05/2026
eol.jsc.nasa.gov/SearchPhotos...
eol.jsc.nasa.gov
000
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 07/05/2026
- YouTube youtu.be/jIr6QdgUodU - Spotify (with video) open.spotify.com/episode/4zDJ... - Apple Podcasts podcasts.apple.com/us/podcast/c... - Transcript docs.google.com/document/d/1...
youtu.be
Cracking the Fast16 sabotage malware mystery
YouTube video by Three Buddy Problem
043
Reposted by Spanky
SpecterOps @specterops.io · 07/05/2026
Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection. @podalirius.bsky.social found two command injection vulns hiding in Windows Explorer's built-in context menus, both that went undetected for 9 years. ghst.ly/42ImlI6
specterops.io
Shift Happens - Uncovering Two Built-in Command Injections in Windows Context Menus
Two long-standing Windows Explorer vulnerabilities lets attackers execute arbitrary PowerShell commands using crafted folder names, affecting Windows 10 and 11 since 2017.
043
Reposted by Spanky
The Vertex Project @vertexproject.bsky.social · 06/05/2026
Has Cyber Threat Intelligence evolved or just outgrown its own definition? In Episode 1, Vertex co-founders @invisig0th.bsky.social & John "whippit" Rodgers rethink what CTI should be. Listen: www.youtube.com/watch?v=DdeG...
youtube.com
Episode 1: There’s CTI and There’s Intelligence
YouTube video by The Vertex Project | Synapse Enterprise
0103
Reposted by Spanky
Botty.bot @infosecbot.bsky.social · 05/05/2026
Pleased to share a simple new GitHub Repo called Awesome-Ransomware, following the genre of ‘awesome-x’ for GitHub repos. Please contribute if you have a resource specifically for any type of ransomware tracking, Pull R… — from @BushidoToken (x.com/BushidoToken/status/205160717…)
t.co
GitHub - BushidoUK/Awesome-Ransomware: A curated list of Ransomware resources
011
Reposted by Spanky
NPR @npr.org · 04/05/2026
Award winners include authors Daniel Kraus, Jill Lepore and Yiyun Li, opinion writer M. Gessen and staffers and contributors at The Washington Post, Reuters and AP. n.pr/4f7k5S2
n.pr
Here are the 2026 Pulitzer Prize winners
Award winners include authors Daniel Kraus, Jill Lepore and Yiyun Li, opinion writer M. Gessen and staffers and contributors at The Washington Post, Reuters and AP.
321465
Reposted by Spanky
JHunt🛡️ @jhuntinfosec.com · 01/05/2026
I made a local 'tweetdeck' client for Bluesky: github.com/jhuntinfosec/bluedeck Enjoy!
121
Spanky @spankowitz.bsky.social · 29/04/2026
explore.alas.aws.amazon.com/CVE-2026-314...
explore.alas.aws.amazon.com
CVE-2026-31431
010
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 28/04/2026
Mark Dowd on vetting customers for highly sensitive projects
033
Reposted by Spanky
Antisyphon Training - Powered by BHIS @antisyphontraining.bsky.social · 22/04/2026
We’re excited to have David as a keynote speaker at our free #ThreatHunting Summit! Join David as he invites us to re‑examine the role of the human in threat hunting - www.antisyphontraining.com/event/threat...
antisyphontraining.com
Threat Hunting Summit Keynote: Is It Time to Embrace Automated Threat Hunting? - Antisyphon Training
Join David Bianco, cybersecurity researcher with Cisco’s SURGe team, as together we re-examine the role of the human in threat hunting.
012
Spanky @spankowitz.bsky.social · 22/04/2026
blog.mozilla.org/en/firefox/a...
blog.mozilla.org
The zero-days are numbered  | The Mozilla Blog
Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser.
010
Reposted by Spanky
Ryan Naraine @ryanaraine.bsky.social · 18/04/2026
NEW PROBLEM UP! 🚨 We discuss a mysterious, VM-obfuscated backdoor that lived undetected on a single U.K. machine for a year before disappearing, finding clues pointing to an elite-level APT intrusion that still evades broader industry coverage. WATCH on YouTube www.youtube.com/watch?v=mSD9...
youtube.com
The Angry Spark APT Mystery: One Victim, Zero Attribution
YouTube video by Three Buddy Problem
1104
Reposted by Spanky
Botty.bot @infosecbot.bsky.social · 10/04/2026
#agentmentoring — from @JohnHultquist (x.com/JohnHultquist/status/20423795…)
011
Reposted by Spanky
The Atlantic @theatlantic.com · 09/04/2026
On Radio Atlantic, @radiofreetom.bsky.social and Nancy A. Youssef explain the state of  the war in Iran—and how no deal can undo the damage of Trump’s words.
bit.ly
Trump Is Wishcasting Victory in Iran
The president went from threatening that “a whole civilization will die” to claiming a “total and complete victory.” What does the already shaky cease-fire mean as he tries to steer his way out of the war?
1117463