NeuroWinter
NeuroWinter@infosec.exchange
<p>Blog on random learning in tech: neurowinter.com</p><p>Reformed <a href="https://infosec.exchange/tags/ai" class="mention hashtag" rel="tag">#<span>ai</span></a> / <a href="https://infosec.exchange/tags/MLOps" class="mention hashtag" rel="tag">#<span>MLOps</span></a> engineer now working as an <a href="https://infosec.exchange/tags/SRE" class="mention hashtag" rel="tag">#<span>SRE</span></a> at a company that specialises in data and backing up <a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="tag">#<span>opensource</span></a> databases and <a href="https://infosec.exchange/tags/kafka" class="mention hashtag" rel="tag">#<span>kafka</span></a>.</p><p>Long time <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="tag">#<span>appsec</span
Posts
-
Post #4182720
Next post in my Wool series is now live, this time its looking at the scene as a whole, and how to perform OSINT on repos, and how trying to hide your tracks is a singal on its own! https://neurowinter.com/security/2026/07/28/the-cast-and-crew/
-
Post #3979067
Was just looking into Kimi since k3 just dropped. Turns out all their memberships are sold out ! Guess I’ll have to wait for the public models https://www.kimi.com/code/
-
Post #3924261
I think I really want to start sponsoring a few small security conferences, so when they are thanking all the different company’s in the middle with be “thanks to ahh Neuro?”
-
Post #3922776
1/ it started with a grep.app link a friend sent me. i went hunting for leaked password prefixes and landed on one github repo. by the end of the weekend i’d mapped a 16-actor chinese reward-farming underground. this is the whole story 🧵 #InfoSec #ThreatIntel #CTI #ReverseEngineering
-
Post #3922145
whats this? another post on the chinese wool-farming underground, and this time the targets are state-owned media and govt-adjacent civic apps :P turns out a pile of these apps share one reward + lottery backend, and the secret thats meant to make claims unforgeable is just… sitting in the client. recover it and you can forge a valid claim the backend accepts. read-only, walked it from one github repo. part of an ongoing series. https://neurowinter.com/security/2026/07/16/forging-the-government-...
-
Post #3669754
I have been working on this series of posts in my blog. I went from a single grep.app search to finding out and driving into the rabbit hole that is the Chinese “wool farming” underground. Basically a bunch of peeps sharing scripts to defraud rewards systems in websites, from their version of Amazon (jd.com) to state media sites and local government sites. https://neurowinter.com/security/2026/06/23/a-weekend-in-the-wool/