Sign in

SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔

@techbytom.bsky.social
197 followers 360 following 222 posts

Privacy, motorcycle, and craft beer geek. Adversarial thinker. Blue team your blue team for better red teaming.

PostsRepliesMedia
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 04/10/2026
Donating to a good cause store.gamersnexus.net/data-dragnet
store.gamersnexus.net
DATA DRAGNET — GamersNexus Official Store
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/09/2026
I generally agree with this, but I don’t know if “we have AI triage it” is the right path. Any version of a future SOC where analysts review LLM output instead of independent analysis is doomed (IMO) to fail the way UAC does. LLMs are huge multipliers, not replacements.
110
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Raphael Mudge @raphaelmudge.bsky.social · 07/09/2026
Playing a Different Game: Rethinking Modern Defense Evasion c0rnbread.com/playing-a-di... """Sometimes the most effective tradecraft isn't the most technically sophisticated. You don't always win by playing the game better and better, but by playing beyond the rules of the game.""" Mmmm hmmm...
065
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
mlf. ⎔ @mlf.one · 20/09/2026
HOLY SHIT HOLY SHIT HOLY SHIT
Signal beta release notes on Android saying that you can now register an account without a phone number
923931
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Internet Archive @archive.org · 05/08/2026
AI companies scraping websites at scale is a real problem. But a proposed NY law could make it harder for libraries, journalists & researchers to preserve the web and investigate the powerful. That's why we've joined @eff.org & others in a letter to Gov. Hochul. blog.archive.org/2026/08/04/i...
blog.archive.org
Internet Archive to New York: Don’t Kill the Good Bots in the Fight Against Bad Bots | Internet Archive Blogs
8356109
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 05/08/2026
This is actually a great case for unlawful search and seizure. Police departments can’t own this, can they!?
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 02/08/2026
iOS 27 public beta is absolutely WRECKING my battery. It seems like half of the time my phone is hot when I pick it up.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 22/07/2026
Here’s the thing - these are powered by that solar panel that isn’t covered, and I think (can anyone confirm?) they’re doing wireless monitoring too? Cover that damn solar panel and the cameras don’t have power anymore.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 01/04/2026
I’m honestly disturbed by the number of posts that follow the AI cadence now. For the same reasons that we pick up accents and speech patterns from those around us, humans are being trained to speak like AI engagement bots.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/03/2026
Recreation.gov casually using ID.me to force seniors into scanning and sharing their biometrics just to buy a pass? Wow. @eff.org
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/03/2026
I sometimes hate that my laptops only finally fill out around half way through their lifespan.
220
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 11/03/2026
This year, everyone’s mind bicycles have a massive upgrade. Self hosted or cloud provider, it doesn’t matter. 2026 is the year that unlocks all of those projects you’ve wanted to build all this time. Go do it. Iterate. It’s cheaper now than ever before, and likely ever will be again.
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Electronic Frontier Foundation @eff.org · 28/02/2026
The U.S. government on Wednesday shut down a vital resource for keeping tabs on what powerful spying tools its agencies are buying, making it harder to reliably find out how agencies including ICE are spending taxpayers’ dollars. www.404media.co/the-governm...
404media.co
The Government Just Made it Harder to See What Spy Tech it Buys
On Wednesday, the government stopped supporting FPDS.gov, an indispensable resource for finding what ICE, the FBI, and every other agency is buying. Its replacement site completely sucks.
218095
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 28/02/2026
Remember when we all used to talk about how invasive the “Great Firewall of China” was? Pepperidge Farm remembers. Now we buy cameras for our front doors so they can ID anyone on our street and report their location in real time. Photo IDs to use the internet. Etc etc. is this the future we want?
032
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 25/02/2026
Anyone want to burn down some criminal's infra? app.any.run/tasks/63ba90... Live right now
app.any.run
Analysis https://ghda111k.de/Hello Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 24/02/2026
New TTP added to my list today because I was working on implementing security controls. This falls into my favorite category: features with unintended consequences. Also it’s a lolbin. Not yet in LOLBAS.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 23/02/2026
TIL you can register with ChatGPT to offensive security use chatgpt.com/cyber
chatgpt.com
ChatGPT
ChatGPT helps you get answers, find inspiration, and be more productive.
100
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 16/02/2026
Shock. cyberscoop.com/state-hacker...
cyberscoop.com
Google finds state-sponsored hackers use AI at 'all stages' of attack cycle
New Google research reveals state-sponsored hackers are using Gemini across the entire cyberattack cycle to automate reconnaissance and tinker with malware.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 11/02/2026
Take notes. THIS is how you articulate the difference between warm fuzzy marketing and propaganda for a commercial dystopia.
020
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 10/02/2026
Good riddance @discord.com
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
The Official Pulpit of CULT OF THE DEAD COW @cultdeadcow.com · 09/02/2026
techcrunch.com/2026/02/09/h... Hacktivism lives.
techcrunch.com
Exclusive: Hacktivist scrapes over 500,000 stalkerware customers' payment records
More than half-a-million people who bought access to phone surveillance and social media snooping apps had their email address and partial payment card numbers published online.
01813
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 29/01/2026
LOOK AT THIS PRIVACY POLICY. Look at it. You can read it because they don’t need a ton of legalese to make you stop reading all the ways they’ll sell your data. They just don’t do that. None of it. tessie.com/privacy
tessie.com
Privacy – Tessie
Tessie is built for you—and only you.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 23/01/2026
We want the soundtrack!
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
BSides312 @bsides312.org · 16/01/2026
Early bird tickets are still available! 🎉 Use code BS312-EB20 to get 20% off your #BSides312 ticket. Grab yours now 👉 bsides312.org While you’re there, consider volunteering and helping make the event awesome! #BSides
bsides312.org
BSides312 - Chicago's Hacking Conference
BSides312 is Chicago's biggest little non-profit hacking & information security conference.
021
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 15/01/2026
If your SOC doesn’t already alert on NetNTLM with challenges of “1122334455667788” you should fix that NOW. cloud.google.com/blog/topics/...
cloud.google.com
Releasing Rainbow Tables to Accelerate Protocol Deprecation | Google Cloud Blog
Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1.
144
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 06/01/2026
If you’re not watching EXO labs, and you have any good reason to run local LLMs stop now and read blog.exolabs.net/nvidia-dgx-s...
blog.exolabs.net
Combining NVIDIA DGX Spark + Apple Mac Studio for 4x Faster LLM Inference with EXO 1.0
Disaggregating Prefill and Decode: Faster First Tokens, Faster Streams
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 02/01/2026
Fun way to host your payloads vmux.sdan.io
vmux.sdan.io
vmux
Run anything in the cloud. Replace uv run with vmux run.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 01/01/2026
Did you know your taxes were being used to buy your flight records from commercial airlines so your movement could be tracked without a warrant?
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Raphael Mudge @raphaelmudge.bsky.social · 31/12/2025
This is fork&run to execute BOFs in a remote process, same API, and get output back over a pipe--demonstrated with Havoc. Same arch could support explicit injection. Add-in an injector artifact + psexec, could remotely run a BOF without an agent and get output back too. bofexec? :)
061
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 29/12/2025
NEW: Apple, Google, and WhatsApp now regularly notify their users if they suspect they have been targeted or hacked with government spyware, such as that made by NSO Group or Paragon. We spoke to experts and wrote a guide on what to do, and where to go, if you receive one of those notifications.
techcrunch.com
You've been targeted by government spyware. Now what? | TechCrunch
Tech companies are increasingly warning their customers that they have been targeted by governments with advanced government spyware, such as NSO's Pegasus or Paragon's Graphite. What happens after re...
02824
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/12/2025
This tool is an especially powerful and widely applicable one. Don’t get caught up in saying no, infosec.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 20/12/2025
ORLY?
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 19/12/2025
0nrnicrosoft[.]com was registered last night
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 19/12/2025
When 2040 me can’t give someone a dirty look without it being captured, catalogued, and sold to the surveillance state - this is one of the ways we got there.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 19/12/2025
THIS would be an awesome base concept for a team of developers to build as a learning exercise for implementing LLMs that are customer facing. www.wsj.com/tech/ai/anth...
wsj.com
We Let AI Run Our Office Vending Machine. It Lost Hundreds of Dollars.
An AI agent ran a snack operation in the WSJ newsroom. It gave away a free PlayStation, ordered a live fish—and taught us lessons about the future of AI.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 18/12/2025
Hey @wiz_io BurbSec really appreciates the CVS sized receipt!
A receipt of drinks from the floor to at least (probably lol) 8’ high
071
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 17/12/2025
Not a fan of this company, but I LOVE the 2FA explainer. Very well executed.
010
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Raphael Mudge @raphaelmudge.bsky.social · 09/12/2025
Interesting project. Reimplements TCG example loaders in Rust and demonstrates Rust patterns for TCG and Crystal Palace. One note: my scope, dev, tests, and unit tests are limited to MinGW. Binary transforms act on patterns gcc generates and moving away from that, you're gonna hit gaps faster.
021
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 08/12/2025
You know what would make for an epic third party compromise? xterm.js
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Electronic Frontier Foundation @eff.org · 03/12/2025
Fed up with this dystopian nightmare? We are too. That's why we're pushing back against surveillance tech and government censorship, both in the courts and on the streets. Help us today: eff.org/power-up
supporters.eff.org
Double Your Impact on Privacy & Free Speech
Right now, your donation to EFF gets an automatic 2X match! Don't let tyrants co-opt tech.
05921
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Ian Coldwater 🧊🚫 @lookitup.baby · 03/12/2025
A perfect CVSS 10 🧑🏻‍🍳💋 CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack Upgrade immediately!
react.dev
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
18286119
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 03/12/2025
Hey everyone. It's currently 2025 (and almost 2026). If you're scraping sites and not running javascript, you probably aren't going to render most of the content ;)
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 02/12/2025
DeepSeek kills it again. If you haven’t read the white paper (huggingface.co/deepseek-ai/...) you should. 1/5th of the GPU time for large contexts in a single generation. The approach just makes sense too - your LLM doesn’t need to constantly re-evaluate the entirety of the prompt and response.
huggingface.co
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
BSides312 @bsides312.org · 27/11/2025
Something extra to be thankful for this week: our CFP and CFV are officially OPEN for #BSides312! 🎤🙌 Got something you want to share on May 16, 2026? Or want to volunteer? Forms are live on our website—see you in May! #BSides bsides312.org
bsides312.org
BSides312 - Chicago's Hacking Conference
BSides312 is Chicago's biggest little non-profit hacking & information security conference.
087
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 18/11/2025
Ooof
011
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 17/11/2025
Our modern dystopia. Sometimes it’s hard to believe this can be rolled back.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 08/11/2025
If you’re involved in any form of protest organization or center/left leaning politics, go enable Lockdown Mode NOW. ssd.eff.org/module/how-t...
ssd.eff.org
How to: Enable Lockdown Mode on iPhone
What Is Lockdown Mode? Lockdown Mode is an optional setting for iPhone, iPad, and Macs, designed to protect high risk people from specific types of digital threats. It’s available on any device that ...
020
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 07/11/2025
What do I win?
Image showing that he was included in the Synthient Credential Stuffing Threat Data dump
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Electronic Frontier Foundation @eff.org · 29/10/2025
“We should have banned government use of face recognition when we had the chance because it is dangerous, invasive, and an inherent threat to civil liberties,” EFF’s @MGuariglia.bsky.social told @404Media.co. www.404media.co/ice-and-cbp...
404media.co
ICE and CBP Agents Are Scanning Peoples’ Faces on the Street To Verify Citizenship
Videos on social media show officers from ICE and CBP using facial recognition technology on people in the field. One expert described the practice as “pure dystopian creep.”
7296118