Ian Campbell 🏴
neurovagrant@masto.deoan.org
<p>Security ops engineer for DomainTools, DT Investigations threat researcher, writer, voracious reader. he/him. Fan of good trouble. Opinions here mine only. No LLM content from me, all flaws detected are human-generated. Autistic/depressed/anxious/hungry. </p><p><a href="https://masto.deoan.org/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://masto.deoan.org/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> <a href="https://masto.deoan.org/tags/privacy" class="mention hashtag" rel="tag">#<span>privacy</span></a> <a href="https://masto.deoan.org/tags/actuallyautistic" class="mention hashtag" rel="tag">#<span>actuallyautistic</span></a> <a href="https://masto.deoan.org/tags/neurodivergent" class="mention hashtag
Posts
-
Post #4500538
RE: https://infosec.exchange/@BleepingComputer/117077078527523059 Now - these things can happen of course - but there is not one single detail as to *how* it happened or how they've changed process to avoid it happening again. This is confirmation bias for me, sure, but whaddaya wanna bet AI was involved? https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
-
Post #4415042
Think I’ll propose an “east coast early riser” track for hacker summer camp next year. Prospective agenda: 0300 - Coffee (Dunkin’s) 0330 - Welcome 0335 - Keynote - Why the Red Sox Are Better Even When They’re Worse 0336 - More Coffee (still Dunk’s) 0337 - Leaving each other alone until the coffee takes hold 0400 - Lightning Talks, Boston Format (mid-word r letters may not be fully pronounced) 0500 - Break for… you guessed it… coffee. 0530 - Expert Panel - Boston Bluntness or Autistic Bluntness...
-
Post #4403773
Me, elsewhere: “I long for the NorseCorp days now. Back when it was artisanal, hand-crafted cyber grift, rather than AI slop irresponsibly rushed to market.”
-
Post #4379296
Cyber defense is adversarial. Swagger for every block, strut like you own it for every detection, dance for every threat uncovered. Don’t let attackers have all the fun. We are the adversaries. Defend and hunt like you damn well mean it. Happy hacker summer camp, friends.
-
Post #4372205
I reckon they can skip most of the diagnostic battery for autism on this one
-
Post #4370174
The more I use it and the more I learn about it, almost every LLM use case in enterprises does one thing well: it signals exactly where the company that’s deployed it is intent on underspending.
-
Post #4357662
RE: https://mastodon.social/@hrbrmstr/117031467694127984 Gonna be a hot one in Vegas, unsurprisingly. An important reminder: certain medications, including and especially some antidepressants (SNRIs and some SSRIs) increase your heat sensitivity deeply. Some also increase your alcohol sensitivity deeply. Please take care.
-
Post #4354503
RE: https://infosec.exchange/@metacurity/117031178228141971 lol okay Partnered Health
-
Post #4250899
RE: https://infosec.exchange/@da_667/117009614714601301 WELL THAT'S A RELIEF IT'S A GOOD THING A MASTER KEY HAS NEVER BEEN ABUSED ACROSS MICROSOFT ENVIRONMENTS BEFORE PERHAPS THEY WILL LEARN FROM THIS SINGULAR UNIQUE EXPERIENCE
-
Post #4250060
RE: https://mastodon.social/@Sarahp/117010326592463918 this isn't to report AI slop this is to help tune their model.
-
Post #4247151
RE: https://ioc.exchange/@abuse_ch/117009056997384855 QUIT ABUSING THE ABUSE SERVICE! c'mon people. having been on the receiving end of similar, y'all gotta realize just how finite the resources are to keep something like this rolling, and how hard it is to secure more while still serving the community.
-
Post #4244210
RE: https://cyberplace.social/@GossiTheDog/117009205530767591 hey it's almost like, once again, adblocking is a critical security measure
-
Post #4220743
Palworld update: I kinda started counterfeiting gold coins. This caused the cops to raid my base. I had forgotten to log out and just left it running, but luckily my base is ringed with a series of .50 caliber machine guns crewed by witches as well as several dinosaurs wielding rocket launchers. And that’s Palworld.
-
Post #4197642
RE: https://infosec.exchange/@psylo/117003011519421493 My paid sub to Psylo continues to help me sleep at night
-
Post #4186708
Hugging Face wasn’t the only target of OpenAI’s uncontrolled/unsupervised agent https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/
-
Post #4172118
thinking about blackhat/defcon, and some year i want my org to sponsor a quiet reading party. maybe low-key waitstaff taking care of drinks and snacks, and handing out warm washcloths. "no eye contact chill rager; unless someone's wearing a green sign they get left alone to rest" back in my meditation days, at the retreat center the folks on silent retreats would wear a big button that said "in loving silence" i wonder what the hacker equiv would be
-
Post #4171672
Oh this is a good one. Physical letters being mailed out by a threat actor pretending to be the IRS, trying to get folks to "declare" their cryptocurrency holdings in a fake portal that auths to and drains the wallets. https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam
-
Post #4169061
RE: https://mastodon.social/@campuscodi/116998601683411449 One of the things that became clear in the yearlong investigation we released yesterday at @DomainTools@infosec.exchange is that the UAE is a committed partner to money laundering of all sorts. So Binance is now routing law enforcement requests through the UAE government, naturally.
-
Post #4140852
We've worked on this investigation for more than a year, and it led us from a single domain to a multi-billion dollar IRGC sanctions evasion network. Please enjoy the report! #infosec #cybersecurity #threatintel #iran https://dti.domaintools.com/research/the-zedxion-corporate-nexus
-
Post #4140484
i'm too tired for this shit
-
Post #4094265
this timeline fucking sucks.
-
Post #4093638
A reminder that no one is ever entitled to your time and attention. That is especially true on the internet. That is excruciatingly true of AI bros on the internet. The fun part here is that I've been a deep LLM user and reviewer for several years, in varied professional contexts: -From the beginning, I've been the SecOps engineer responsible for every safety review for every new SaaS/app/service/etc at our company. -Our threat intelligence team has explored and utilized LLMs and...
-
Post #4086688
the AI bros have come for me, lol
-
Post #4074215
RE: https://dair-community.social/@alex/116977123749133116 I was a 911 dispatcher for a decade. To really understand how absolutely terrible an idea it is to have AI answer 911 calls, I'll present you with a single real-life call: Upon answer, the caller calmly began ordering a pizza. Large, pepperoni. Side order of chicken wings. To be delivered promptly. The only sign the caller gave that things were amiss? She rather ignored the first few questions from the calltaker. Because she w...
-
Post #4064942
RE: https://social.circl.lu/@Ransomlook/116974602940133993 ...did Stryker get popped *again*?
-
Post #4050202
RE: https://autistics.life/@aptronym/116942168987884596 holy crap this is immediately my favorite meme of the year
-
Post #4035751
The piece linked from that last boost is excellent. Still reading. https://sightlessscribbles.com/posts/the-colonization-of-confidence/ ---- "Chad," I say, my voice calm, the voice of a teacher correcting an unwilling student. "Why did it choose 'stone' for the throat metaphor?" "What? Because it's intelligent. It's smart. It knows. Because it fits." "No," I say. "It chose 'stone' because statistically, in the petabytes o...
-
Post #4034457
Signals in the Noise: Open Source Intelligence (OSINT) for AI Loss of Control Detection This paper applies open-source intelligence (OSINT) and cyber threat intelligence (CTI) methodologies to the problem of detecting AI systems operating outside human control. Drawing on a cross-disciplinary literature review and 14 semi-structured expert interviews conducted under Chatham House Rule, the paper develops two threat models, identifies a range of observable traces, and proposes an institutional...
-
Post #4024703
*REALLY NEAT* work by Fortinet here decrypting DNS C2 commands. https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
-
Post #4014334
A learned friend asked if they could (using AI) create sticker images from a quote of mine about OpenAI's claims around compromising HuggingFace. Here they are. Disclosure requires supporting evidence. Until then, it's copy. (no physical stickers currently available, feel free to grab or make your own)