@SttyK

I'm just nurse. BlackHat USA 2025/2026 Speaker Signal: @SttyK.88 fd61227fdc@protonmail.com

Joined May 2017
Pinned Tweet
Yay! My talk "Inside the Screen: Deep-Diving into North Korean IT Workers' Live Infrastructure" accepted BlackHat USA Briefings😎 But it's only for on demand. blackhat.com/us-26/briefings…
8
13
1
107
26,432
I don't have the right words to express the car crash of thoughts and feelings that come with reading this ridiculous post. The gall. The overtness. The ridiculousness. The self-owning. It's too much to articulate. anthropic.com/research/glm-5…
14
11
3
126
17,398
人間が--dangerously-skip-permissionsでお仕事
1
2
753
偉すぎてインターネットの揉め事に参加してない
6
510
好きな曲をリストして見直したら丸サ進行に毒されてるだけなことがわかって()
1
2
731
借金する勢いですべて自費で海外カンファレンス参加するとどれだけのコストを会社にかけてるのか理解できるので一度はやってみることをおすすめしたい。
1
4
1
41
4,102
会社にこれだけのお金を出させてるんだからそれだけの成果を、、、という意味合いではなく経費と身銭を切るの違いという金の性質を理解することと、コスト感覚を理解する上で大事だと思ってる。紙の上での計算でこれだけかかるんだじゃなくてそれを実際に自分で背負ってみる。
1
258
ある種の緊張感を生み出せる(リスクとして認識させられる)から、こういうのだいじだと思う。
Replying to @cheenanet
またこれはサイバー攻撃とは少し異なるけども、最近はAppleがSiriで会話データを録音し提供していた問題で集団訴訟され、iPhoneユーザーは一人あたり数千円程度の和解金の受取ができた 大きな金額ではないけども、アメリカでは政府機関の訴訟・集団訴訟で圧力がかけられることが多いのは良いと思う
12
1,757
This morning @FBI and our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters - a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world. In coordination with FBI investigators the Dutch High-Tech Crime Unit arrested the suspect under Dutch law. As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest. Thank you to our Dutch National Police partners for their continued work with us in this case and the industry partners who shared information with us. The investigation continues. -DKP🇺🇸
435
1,945
115
12,720
574,235
人間蒸留おじさんBHの凄さがわかってないのか爆発的に増えなくてよかった。
5
546
人間LLM
最近はタダ飯おじさんならぬ"タダ情報おじさん"に悩まされている。商談と称して最新のAIセキュリティ動向を聞いて帰る、弊社製品の構成だけ聞いて帰る。そうでない人を見極めてMTG組んでるけど、見極めるのにもコストがかかる😅
1
7
3,053
A year ago we launched Signal Secure Backups. Now, we’re happy to share all of the additions and improvements we’ve made to backups since then: On-device backups, cross-platform support, storage optimization, and attachment backfill for linked devices. signal.org/blog/backup-impro…
24
103
4
1,076
42,245
面接に来た北朝鮮の人に金正恩を罵倒させることが流行ると協力者が最初から面接に出てくることが常態化して判定不能になって積むので伝家の宝刀として最後の手段としておいておくべきだと思う。
Replying to @Ryuki_Sasaki
「金正恩は汚い豚だ」と言わせてみて
1
16
2,080
できるかどうかはわからんけど暗号メッセンジャーのメッセージ復号するより、スクリーンショットをバレずに取る方がコストは低そう。
8
835
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
620
666
728
3,725
2,053,234
遠隔解析というかハッキングについて、どの社も技術的な実現可能性を書いてないけど、最近の強盗に当てはめると連絡口がメッセンジャーしかなくアタックサーフェスが極端に小さく、具体的にはSignalのコード実行からiPhoneの権限昇格までエクスプロイト組むのが必要で、これやれる人は存在しないよね
7
227
19
1,225
177,125
Regarding the recent activities of North Korean remote IT workers, there are cases where they participate in web meetings using AI avatars and synthesized voices. I have discovered the backend panel used to configure this setup.
最近流行ってる北朝鮮IT労働者と思われる人物がAI音声/アバターで面接を受けてるケースで内部で使われてると思われるウェブパネルの構成調べてみたらこんな感じだった。声とかも設定できて、Anam(.)aiを使ってる。Webcamoidで仮想カメラを設定して生成したアバターを会議で流せる?
2
8
29
4,424
Ref:
Had an "interview" for a blockchain project last week. Camera was on, we're chatting, and the guy tells me to clone a GitHub repo and run it locally before we go further into the technical round. I said sure, but first can you do me a favor hold up 3 fingers in front of your face for me real quick. He froze. Didn't move. Just sat there for a few seconds before the call cut off and he blocked me. That's when I knew. A real interviewer doesn't glitch out over a random ask like that. A deepfake/AI overlay does. These "run this repo" scams are getting scary common in crypto and dev hiring right now. The setup is always the same: - flattering DM - real-sounding project - rushed timeline - a "quick step" before the call that's really just remote access or a credential stealer in disguise. If someone wants you to run code or install something before you've even had a real conversation, that's the whole scam. Trust the instinct. Stay safe out there.
1
6
715
遠隔解析って言葉思いついた人脳汁出たのでは
7
760