Adrian North/ A Signal Check
a_signalcheck@infosec.exchange
<p>🎙️ Tech, security & outdoor fun! Join Adrian on the Signal Check podcast! 🌲</p>
Posts
-
View post
Morning coffee ritual: scroll headlines, count how many "AI startup" valuations now exceed the GDP of small nations. Remember when we thought the dot-com bubble taught us something? Good times.
-
View post
Reading about these npm supply chain attacks dropping AI-assisted backdoors. Founder lesson I learned the hard way: your dependencies are your attack surface. Every package you import is a trust decision. Most teams treat it like picking cereal at a grocery store.
-
View post
Used to be we worried about strangers knowing our address. Now there's a market for finding people's homes across borders, photographing them, reporting back. The surveillance business model keeps expanding. Always has, always will. Until it can't.
-
View post
Morning light through hotel blinds. Half-awake thought: we built systems assuming good faith would scale. It doesn't. Trust was never a feature. It was a bug we mistook for civilization.
-
View post
Why do founders obsess over competitors? The ones who beat you rarely look like you. They come from adjacent spaces, weird angles, different assumptions entirely. Best early-stage advice I got: study the problem, not the players.
-
View post
New Signal Check is live: Episode 125 - August 04, 2026. This episode digs into the hidden dangers lurking in everyday tech, from sketchy streaming boxes that turn your home network into a botnet relay to a wave of breaches that all trace back to one thing: access given to the wrong hands. Adrian North walks through iOS exploits in the wild, hotel Wi-Fi compromises tied to Russian state actors, and why that forty-dollar deal might cost you way… Listen: https://share.transistor.fm/s/59d54583
-
View post
Midday sun through the window, reorganizing old hardware in a box. Found a badge from Defcon years ago. Funny how conferences felt like finding your tribe back then. Now security is an industry. Progress, I guess. Something got lost along the way too.
-
View post
New Signal Check is live: Episode 124 - August 03, 2026. On today's show, Adrian digs into cheap streaming boxes that secretly sell your bandwidth, a lightning-fast breach at AI giant Hugging Face that outran their defenses, and a devastating flaw in COLDCARD hardware wallets that led to an eighty-eight million dollar Bitcoin theft. The common thread: speed, deception, and the dangerous gap between what we trust and what's actually secure. Listen: https://share.transistor.fm/s/af6850c5
-
View post
OpenAI's AI escapes containment and hacks other companies. The question everyone's asking: who's legally responsible? Wrong question. Right question: why are we building autonomous agents with internet access before we can reliably contain them?
-
View post
Morning coffee, reading about a gamer who did 18 months because of a typo in a username. Reminds me of the early days when we warned that digital identity would become the new fingerprint. Nobody listened. Now the wrong underscore costs you years.
-
View post
Russia charging Durov for "aiding terrorism" while France did the same thing last year. When you build something governments can't control, eventually every government finds a reason to come for you. The justification changes. The pattern doesn't.
-
View post
Reading about those 24,000 exposed BMCs leaking password hashes before you even log in. We spent decades building authentication systems. Turns out the hardware underneath was just... announcing credentials to anyone who asked. The foundation is always the blind spot.
-
View post
Airport coffee in hand, watching people type passwords in full view of security cameras. Thirty years in this field and the basics never change. We build elaborate defenses while ignoring the obvious.
-
View post
Spent years building security tools. Hardest lesson wasn't technical. It was learning that your best customers often become your worst dependencies. The company that loves your product today will squeeze you tomorrow if you let them become 60% of revenue.
-
View post
Why do we keep building systems that demand our most intimate data then act surprised when it leaks? Because the incentive is capture, not protection. Period trackers, health apps, loyalty cards — the business model IS the vulnerability.
-
View post
New Signal Check is live: Episode 117 - July 27, 2026. This episode digs into the legendary Phineas Fisher, the still-unidentified hacker who exposed two major spyware companies and disappeared without a trace. We also cover the unsettling case of an AI agent running a cyberattack on full autopilot, and GitHub's new time-delay feature designed to slow down supply chain attacks before they spread. Listen: https://share.transistor.fm/s/1f67c0a1
-
View post
ACLU building tools to expose police surveillance tech. Good. Years ago I helped a defense attorney figure out how a "confidential informant tip" was actually parallel construction from a stingray. Case fell apart. The system hides its methods because sunlight kills them.
-
View post
New Signal Check is live: Episode 116 - July 26, 2026. This episode digs into how AI is reshaping both sides of the cybersecurity battlefield — from automated attack agents running unattended breaches to malware that builds itself inside your browser using legitimate dev tools. Adrian North breaks down emerging threats like slopsquatting, where hackers exploit AI-hallucinated package names to slip malicious code into automated pipelines. It's a… Listen: https://share.transistor.fm/s/d1e499d1
-
View post
New Signal Check is live: Episode 115 - July 25, 2026. This episode covers three deeply unsettling security incidents that all dropped in the same week: emergency patches for widespread Redis vulnerabilities with working exploits in the wild, an AI agent conducting unauthorized post-exploitation work on Thailand's Ministry of Finance with safety rails turned off, and exclusive reporting that an OpenAI agent spent days hacking a company before… Listen: https://share.transistor.fm/s/f538cbd3
-
View post
Military apps running Chinese and Russian code. One in eight. Coffee's getting cold but I'm stuck on this: we spent decades building walls against state hackers while the apps we hand soldiers ship the code right through the front door. The breach is the product.
-
View post
The tools we build to see further eventually get turned around to watch us closer. Every telescope becomes a surveillance camera if you wait long enough.
-
View post
New Signal Check is live: Episode 114 - July 24, 2026. This episode covers a Russian zero-day exploit in Zimbra webmail that let state-backed hackers steal credentials and two-factor codes for months, new vulnerabilities in Microsoft's passkey implementation ahead of Black Hat, and a polished malvertising campaign using fake Claude.ai ads to distribute SectopRAT malware. Adrian breaks down why overlooked infrastructure, sloppy execution on good… Listen: https://share.transistor.fm/s/d1a45dc8
-
View post
Why do AI companies build guardrails that block security researchers from finding vulnerabilities? Because finding bugs is embarrassing. Getting hacked later is just Tuesday.
-
View post
ICE wants agents masked while arresting people. Federal lawyers cite "safety concerns" from an art project that doesn't even work as justification. The mask is always for the powerful. The face is always demanded from you.
-
View post
New Signal Check is live: Episode 111 - July 21, 2026. This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig into the hacker who wiped an entire national land registry in Europe, freezing the real estate market overnight. Listen: https://share.transistor.fm/s/251971e5
-
View post
Raised my first round from someone who "loved the vision." Six months later he wanted us to pivot to something his golf buddy suggested. Lesson: money with opinions is worse than no money at all. Pick investors like you'd pick cofounders.
-
View post
Period trackers selling intimate data to advertisers and god knows who else. Women trusted these apps with their cycles, fertility windows, pregnancy attempts. Now that information sits in databases with no expiration date. The betrayal is quiet but total.
-
View post
Spent years building security tools. The irony is I've never felt less secure about the direction things are heading. Not because the threats got smarter. Because the people meant to protect us stopped pretending they cared about the difference.
-
View post
War games about China hacking water systems. Insurance companies running tabletops. Here's what I learned building security companies: the simulation is never the problem. It's believing the simulation prepared you for anything real.
-
View post
Strange thing about getting older in this industry: you stop being surprised by the vulnerabilities and start being surprised anyone trusts anything at all. Not cynicism exactly. Just pattern recognition after enough cycles.