FOLLOWS YOU • “Wir müssen wissen, wir werden wissen” -Hilbert • (he/they/him/them) • infosec and privacy aficionado • mage

@da5ch0 || wishabitchwoods 😉
Joined February 2011
—————————————————————————————————————————dash🏴‍☠️ retweeted
Our software factory.
2
13
1
62
3,122
—————————————————————————————————————————dash🏴‍☠️ retweeted
It's Co-Pilot's time! MSFT going higher. Big move coming
2
3
50
2,233
i feel personally attacked
9 am: i can’t wait till bedtime 10 pm: i’ve always wanted to write my own operating system
1
5
1
49
1,094
—————————————————————————————————————————dash🏴‍☠️ retweeted
9 am: i can’t wait till bedtime 10 pm: i’ve always wanted to write my own operating system
78
11,265
202
106,608
867,775
—————————————————————————————————————————dash🏴‍☠️ retweeted
Hey just to let you know I am not taken. I'm available. Just like the ports on the open net your MSP uses to administer your domain controller
29
7
185
13,906
—————————————————————————————————————————dash🏴‍☠️ retweeted
anybody hiring?
60
39
2
417
35,964
—————————————————————————————————————————dash🏴‍☠️ retweeted
If they ban open weights, we’ll be trading LLMs like ’90s warez. We did it before, we can do it again.
They’re going to ban open weight models because they’re dangerous. No, that won’t stop threat actors from using them, but it will stop enterprises. And that’s the whole point.
8
15
1
60
1,775
—————————————————————————————————————————dash🏴‍☠️ retweeted
Periodic reminder: Good security architecture minimizes the number of bugs and CVEs you have to care about.
9
45
10
233
17,998
—————————————————————————————————————————dash🏴‍☠️ retweeted
Periodic reminder: Good security architecture minimizes the number of bugs and CVEs you have to care about.
2
6
41
3,692
—————————————————————————————————————————dash🏴‍☠️ retweeted
Probably a good time to point you all to a tool I released not to long ago called SecretsStalker. If you have found an exposed client ID and secret to s service principal, SecretsStalker will authenticate you into the environment and recon the exact rights that it has. github.com/rootsecdev/Secret…
Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes. Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations. Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
3
22
1
144
18,310
—————————————————————————————————————————dash🏴‍☠️ retweeted
Hello, Little People Living Inside My Computer, I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous. youtube.com/@MalwareForFun
129
381
8
5,129
147,110
—————————————————————————————————————————dash🏴‍☠️ retweeted
Yooooo. I'm hiring. Senior Consultant role on my Human Threats team. Social Engineer w/ lots of physical assessment experience 🔐 careers.coalfire.com/career-…
17
55
5
152
14,256
—————————————————————————————————————————dash🏴‍☠️ retweeted
Regular reminder… this hardening series by Jerry Devore is super awesome. There’s no way you won’t learn things by reading these. Part 1 - Disabling NTLMv1 Part 2 - Removing SMBv1 Part 3 - Enforcing LDAP Signing Part 4 - Enforcing AES for Kerberos Part 5 - Enforcing LDAP Channel Binding Part 6 - Enforcing SMB Signing Part 7 - Implementing Least Privilege Link to all articles 👇 techcommunity.microsoft.com/…
12
413
8
1,852
113,725
—————————————————————————————————————————dash🏴‍☠️ retweeted
34
130
8
1,614
40,813
—————————————————————————————————————————dash🏴‍☠️ retweeted
When my wife asks me why I need night vision goggles I send her this:
257
4,294
191
58,049
2,693,264
—————————————————————————————————————————dash🏴‍☠️ retweeted
Introducing GLM-5.3: Built to Code. Ready for Cyber Defense. - Top-tier coding and agentic capabilities, achieved through post-training on the 743B base model - A major leap in cybersecurity, setting a new standard among open models Tech Blog: z.ai/blog/glm-5.3
10
17
1
74
9,989
—————————————————————————————————————————dash🏴‍☠️ retweeted
we call this the Chronically Online Hunch
12
3
1
610
13,408
ngl i lowkey want this so bad
Wondering what a 100-key macro pad is for? 💼 Work — open apps, launch websites, take screenshots, mute meetings, automate tasks 🎬 Create — cut clips, switch tools, change layers, adjust timelines, export projects 🎙️ Stream — switch scenes, mute mic, start recording, control OBS 🎮 Play — open Discord, control music, launch games, trigger in-game shortcuts Your command center. Every key, your way.
2
5
350
—————————————————————————————————————————dash🏴‍☠️ retweeted
Replying to @notajungman
VPNs are just jump boxes for attackers
2
17
1,833
—————————————————————————————————————————dash🏴‍☠️ retweeted
If you are constantly correcting AI and can't believe people trust it, I have good news for you You might be smarter than the average person
16
9
98
4,429