B'ad Samurai :ifin:
badsamurai@infosec.exchange
<p><a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a> <a href="https://infosec.exchange/tags/automation" class="mention hashtag" rel="tag">#<span>automation</span></a> <a href="https://infosec.exchange/tags/soar" class="mention hashtag" rel="tag">#<span>soar</span></a> <a href="https://infosec.exchange/tags/iac" class="mention hashtag" rel="tag">#<span>iac</span></a> and <a href="https://infosec.exchange/tags/tay" class="mention hashtag" rel="tag">#<span>tay</span></a></p><p>I love the PacNW / BC. When I'm not doing security shenanigans, you'll find me on a glacier, volcano, ski lot or sketching mushrooms on the trail.</p><p>I believe the outdoors heal and are for EVERYONE.</p><p>Keyoxide: aspe:keyoxide.org:6FO76WXKQECSKSK6
Posts
-
Post #4423590
Whale watching always makes me so happy. I highly recommend this for a team activity. #seattle #orca
-
Post #4378979
Palo: "Almost Half of Malware Samples Communicate Direct to IP" Also Palo: "We don't understand why you want to Block-by-ASN." https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/ #blueteam #asn #paloaltonetworks #unit42
-
Post #4376405
RE: https://infosec.exchange/@bobdahacker/117037360462544912 Block and monitor these absurdly high-risks. Here’s a list to get you started. https://github.com/BadSamuraiDev/bs-lists/blob/main/ai-meeting-notetakers.md
-
Post #4248059
My Moon Picnic with my goth & Wiccan spouse was really nice. Thanks kick-ass 99.7% moon and clear WA skies!
-
Post #4104152
Hearts in trees.#timber #tolt
-
Post #3978074
Boba buddy. #dogsofmastodon #goldenretriever
-
Post #3965959
https://nvd.nist.gov/vuln/detail/cve-2026-63795 #cve202663795 #cve #linux #cve_2026_63795
-
Post #3927163
Henry Jimothy! Jimothy. the hero we needed. l've decided to give 100 percent of the money made from this painting to Ballard food bank, a place that helped me through some of my hardest times. Make your offer in my DMs and the highest bid by midnight will get the painting and the ballard food bank will get a hook up they deserve. https://www.instagram.com/p/Da8opgCh6GS/ #ballard #jimothy
-
Post #3890080
https://www.theregister.com/off-prem/2026/07/17/billing-software-error-sends-billion-dollar-aws-estimates/5274521 #aws
-
Post #3850280
RE: https://live.acarsdrama.com/@acarsdrama/116927482262587381 They’re both named Oliver, are dating and someone put meat scraps in the vermicompst. The culprit was in fact their room mate Liam, again.
-
Post #3848158
RE: https://infosec.exchange/@urldna/116918452809633800 How Geoshitties are added: X Free sign-up with [@]duck email X No email verification X Custom images and AI generation X Allow redirects and links off-site And some good things: [+] No subdomains [+] Abuse contact form exists Mitigation of low-regret? Highly likely for most orgs since real use by partners and vendors would likely be behind a domain and use their paid hosting integrations to Google or Wix. https://github.com/BadSamuraiDe...
-
Post #3815995
Well good thing the American federal government doesn’t rely on a single privately-owned third-party digital identity provider operating on .me! #dns
-
Post #3796347
Anyway, 9 Webhooks-aaS and 7 LOTTs added to BS Lists. LOTT .tunnelapi.in/ (LOTT Download and Webhook-aaS) .free-tunnelapi.app/ (LOTT) .remote.it/ (LOTT) .optimistixtunnel.com/ (LOTT) .localcan.com/ (LOTT) .localcan.dev/ (LOTT) .ssh-j.com/ (LOTT) https://github.com/BadSamuraiDev/bs-lists/blob/main/living-off-trusted-tunnels.txt Webhook-aaS .tunnelapi.in/ .h00k.dev/ .hookray.com/ .hookrelay.dev/ (100 free/month) .webhookwizard.com/ .posthook.io/ (Webhook-aaS: 1000 free/month) .spiderhash.io/ .g...
-
Post #3727179
Long overdue. On-going collection of Cloudflare abuse in one place. Domains and URLs to start, then I’ll get hunts added for tunnels and other shenanigans. https://github.com/BadSamuraiDev/bs-lists/blob/main/cloudflare.md #cloudflare
-
Post #3720852
The state of software in 2026: Progress asking their customers to turn off their products, again. https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/
-
Post #3684768
#cloudflare #originStory
-
Post #3676125
My 30-year old Nas CD skips in my boombox. 🎵If I ruled .. the .. world .. imagine that 🎵 I like to think of it as earned patina.
-
Post #3552475
RE: https://mastodon.social/@bagder/116854899225802291 Presenting the first software supply chain attack via snail mail.
-
Post #3482132
RE: https://mastodon.social/@arstechnica/116835005737504430 In case y’all missed Yahoo and MSN Music, here’s a third memo.
- Post #3122389
-
Post #3122388
#ai #meta
-
Post #3122387
RE: https://vmst.io/@intrepidhero/116681172160789282 The outdoors are for everyone and a place folx can heal. https://www.queermountaineers.com/ https://qpochikers.com/ https://www.outventures.org/
-
Post #3122386
When a vendors intel doc has no IOCs and references esoteric product and org-specific tags/TAs. #threatintel
- Post #3122385
-
Post #3122384
RE: https://infosec.exchange/@anyrun_app/116686468018998328 If you have the analytics available, demonstrate little-to-no use of mshta in your environment and then completely block this in your EDR/MDM. Then do this for finger.exe too. Deterministic, reliable, no overhead, and free; how I like my security. #clickfix
-
Post #3122383
Remember Python Bootcamps? Now everyone in IT is expected to automate their job! But it largely resulted in just saved creds to management planes in clients.
-
Post #2709123
Happy Verizon DBIR day to all who celebrate! #DBIR
-
Post #2709122
Love it! https://science.nasa.gov/specials/your-name-in-landsat/ (Weirdly I have been to 3 of 6 of my sur name letters)
-
Post #1111326
Public disclaimer: Bad puns and rebus are my coping mechanism.
-
Post #1111325
Looks like someone rattle-can’d this mushroom gold. #fungi #mushrooms #mushtodon