Sign in

SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔

@techbytom.bsky.social
197 followers 360 following 222 posts

Privacy, motorcycle, and craft beer geek. Adversarial thinker. Blue team your blue team for better red teaming.

PostsRepliesMedia
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 07/10/2026
Now do Foxpro
020
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 04/10/2026
Donating to a good cause store.gamersnexus.net/data-dragnet
store.gamersnexus.net
DATA DRAGNET — GamersNexus Official Store
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/09/2026
Task orient your nonhuman SOC agents: What else do your analysts want to know when an alert fires? Provenance, other artifacts we might expect, evidence of similar activity across the org. It shouldn’t give a verdict unless your analysts are blind to that verdict until they arrive at their own.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/09/2026
I generally agree with this, but I don’t know if “we have AI triage it” is the right path. Any version of a future SOC where analysts review LLM output instead of independent analysis is doomed (IMO) to fail the way UAC does. LLMs are huge multipliers, not replacements.
110
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Raphael Mudge @raphaelmudge.bsky.social · 07/09/2026
Playing a Different Game: Rethinking Modern Defense Evasion c0rnbread.com/playing-a-di... """Sometimes the most effective tradecraft isn't the most technically sophisticated. You don't always win by playing the game better and better, but by playing beyond the rules of the game.""" Mmmm hmmm...
065
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
mlf. ⎔ @mlf.one · 20/09/2026
HOLY SHIT HOLY SHIT HOLY SHIT
Signal beta release notes on Android saying that you can now register an account without a phone number
923931
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 08/09/2026
How is any private entity built to sell a 4A bypass to government agencies not a violation of our Constitution?
110
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 29/08/2026
IS THAT A… SUPRA?!
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 16/08/2026
And then sued a British TV show that reviewed their car.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 10/08/2026
Watch me buy this $2M car and blow the engine.
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Internet Archive @archive.org · 05/08/2026
AI companies scraping websites at scale is a real problem. But a proposed NY law could make it harder for libraries, journalists & researchers to preserve the web and investigate the powerful. That's why we've joined @eff.org & others in a letter to Gov. Hochul. blog.archive.org/2026/08/04/i...
blog.archive.org
Internet Archive to New York: Don’t Kill the Good Bots in the Fight Against Bad Bots | Internet Archive Blogs
8356109
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 05/08/2026
This is actually a great case for unlawful search and seizure. Police departments can’t own this, can they!?
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 02/08/2026
iOS 27 public beta is absolutely WRECKING my battery. It seems like half of the time my phone is hot when I pick it up.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 22/07/2026
I mean, I guess. But only if you soak it in something that tastes like paint thinner first.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 22/07/2026
Barrel aged version now too please
100
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 22/07/2026
Here’s the thing - these are powered by that solar panel that isn’t covered, and I think (can anyone confirm?) they’re doing wireless monitoring too? Cover that damn solar panel and the cameras don’t have power anymore.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 21/07/2026
So much sushi
110
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 15/07/2026
Also our time zones are very clearly not aligned with the winter sun (which is when we would actually want this). Michigan maybe the worst offender because of how far North it goes in Eastern time zone.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 09/07/2026
Wait, you’re saying that you didn’t panic order one overnight and then find all four of the ones you stored somewhere when you put away the overnighted cable?
110
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 01/04/2026
I’m honestly disturbed by the number of posts that follow the AI cadence now. For the same reasons that we pick up accents and speech patterns from those around us, humans are being trained to speak like AI engagement bots.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 28/03/2026
They make some claims that imply they haven't released everything yet, and mention the FBI. That said, how are we feeling about Apple's refusal to give the FBI a backdoor it controls for all iOS devices?
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/03/2026
This is actually on a carbon fiber textured one of those!
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/03/2026
Recreation.gov casually using ID.me to force seniors into scanning and sharing their biometrics just to buy a pass? Wow. @eff.org
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/03/2026
I sometimes hate that my laptops only finally fill out around half way through their lifespan.
220
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 11/03/2026
This year, everyone’s mind bicycles have a massive upgrade. Self hosted or cloud provider, it doesn’t matter. 2026 is the year that unlocks all of those projects you’ve wanted to build all this time. Go do it. Iterate. It’s cheaper now than ever before, and likely ever will be again.
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Electronic Frontier Foundation @eff.org · 28/02/2026
The U.S. government on Wednesday shut down a vital resource for keeping tabs on what powerful spying tools its agencies are buying, making it harder to reliably find out how agencies including ICE are spending taxpayers’ dollars. www.404media.co/the-governm...
404media.co
The Government Just Made it Harder to See What Spy Tech it Buys
On Wednesday, the government stopped supporting FPDS.gov, an indispensable resource for finding what ICE, the FBI, and every other agency is buying. Its replacement site completely sucks.
218095
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 28/02/2026
Remember when we all used to talk about how invasive the “Great Firewall of China” was? Pepperidge Farm remembers. Now we buy cameras for our front doors so they can ID anyone on our street and report their location in real time. Photo IDs to use the internet. Etc etc. is this the future we want?
032
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 26/02/2026
This implies it can’t be used on patrol. Interesting.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 25/02/2026
Anyone want to burn down some criminal's infra? app.any.run/tasks/63ba90... Live right now
app.any.run
Analysis https://ghda111k.de/Hello Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 24/02/2026
Note: this is illegal in Illinois?
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 24/02/2026
New TTP added to my list today because I was working on implementing security controls. This falls into my favorite category: features with unintended consequences. Also it’s a lolbin. Not yet in LOLBAS.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 23/02/2026
And as long as you don't care about privacy at all, you should be good to go
100
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 23/02/2026
TIL you can register with ChatGPT to offensive security use chatgpt.com/cyber
chatgpt.com
ChatGPT
ChatGPT helps you get answers, find inspiration, and be more productive.
100
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 16/02/2026
Shock. cyberscoop.com/state-hacker...
cyberscoop.com
Google finds state-sponsored hackers use AI at 'all stages' of attack cycle
New Google research reveals state-sponsored hackers are using Gemini across the entire cyberattack cycle to automate reconnaissance and tinker with malware.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 11/02/2026
Take notes. THIS is how you articulate the difference between warm fuzzy marketing and propaganda for a commercial dystopia.
020
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 10/02/2026
Good riddance @discord.com
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
The Official Pulpit of CULT OF THE DEAD COW @cultdeadcow.com · 09/02/2026
techcrunch.com/2026/02/09/h... Hacktivism lives.
techcrunch.com
Exclusive: Hacktivist scrapes over 500,000 stalkerware customers' payment records
More than half-a-million people who bought access to phone surveillance and social media snooping apps had their email address and partial payment card numbers published online.
01813
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 02/02/2026
www.youtube.com/watch?v=Y5o3...
m.youtube.com
Automated Snow Removal for Truck Trailer Roofs | Scraper Systems™
YouTube video by Scraper Systems by Rite-Hite
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 29/01/2026
LOOK AT THIS PRIVACY POLICY. Look at it. You can read it because they don’t need a ton of legalese to make you stop reading all the ways they’ll sell your data. They just don’t do that. None of it. tessie.com/privacy
tessie.com
Privacy – Tessie
Tessie is built for you—and only you.
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 23/01/2026
We want the soundtrack!
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
BSides312 @bsides312.org · 16/01/2026
Early bird tickets are still available! 🎉 Use code BS312-EB20 to get 20% off your #BSides312 ticket. Grab yours now 👉 bsides312.org While you’re there, consider volunteering and helping make the event awesome! #BSides
bsides312.org
BSides312 - Chicago's Hacking Conference
BSides312 is Chicago's biggest little non-profit hacking & information security conference.
021
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 18/01/2026
cupholder.exe was one of my favorite memories when growing up.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 16/01/2026
To be clear. NetNTLMv1 support needs to go. But for the low security budgets, the companies that can’t navigate their way out from under this one, detection and effective response will be your saving grace (or it won’t be).
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 15/01/2026
If your SOC doesn’t already alert on NetNTLM with challenges of “1122334455667788” you should fix that NOW. cloud.google.com/blog/topics/...
cloud.google.com
Releasing Rainbow Tables to Accelerate Protocol Deprecation | Google Cloud Blog
Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1.
144
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 06/01/2026
If you’re not watching EXO labs, and you have any good reason to run local LLMs stop now and read blog.exolabs.net/nvidia-dgx-s...
blog.exolabs.net
Combining NVIDIA DGX Spark + Apple Mac Studio for 4x Faster LLM Inference with EXO 1.0
Disaggregating Prefill and Decode: Faster First Tokens, Faster Streams
000
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 02/01/2026
Fun way to host your payloads vmux.sdan.io
vmux.sdan.io
vmux
Run anything in the cloud. Replace uv run with vmux run.
010
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 01/01/2026
Did you know your taxes were being used to buy your flight records from commercial airlines so your movement could be tracked without a warrant?
000
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Raphael Mudge @raphaelmudge.bsky.social · 31/12/2025
This is fork&run to execute BOFs in a remote process, same API, and get output back over a pipe--demonstrated with Havoc. Same arch could support explicit injection. Add-in an injector artifact + psexec, could remotely run a BOF without an agent and get output back too. bofexec? :)
061
Reposted by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 29/12/2025
NEW: Apple, Google, and WhatsApp now regularly notify their users if they suspect they have been targeted or hacked with government spyware, such as that made by NSO Group or Paragon. We spoke to experts and wrote a guide on what to do, and where to go, if you receive one of those notifications.
techcrunch.com
You've been targeted by government spyware. Now what? | TechCrunch
Tech companies are increasingly warning their customers that they have been targeted by governments with advanced government spyware, such as NSO's Pegasus or Paragon's Graphite. What happens after re...
02824
SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom.bsky.social · 27/12/2025
This tool is an especially powerful and widely applicable one. Don’t get caught up in saying no, infosec.
010