Christoffer S.
nopatience@swecyb.com
<p>๐ช๐บ Father, husband, Swedish and cyber. Oh man, all the things cyber but mostly threat Intelligence. Dabble with Python. In the cybersecurity field as a professional since 2001.</p><p>Cybersecurity all the way... let's go!</p>
Posts
-
Post #4093386
I love CSS about as much as I love stepping in dog shit, driving amongst cyclists, cycling amongst drivers, attempting to convince my kids that TikTok is shite, and trying to explain to my wife what I do for a living. Love it.
-
Post #3736383
Good morning, good afternoon and good evening fellow fedizens. What's going on? Saturday and the sun is shining, at least here in the northern parts of Europe. Expectations of the coming week is even hotter weather which suggests that the inflatable pool should be ... Inflated. What will you be doing?
-
Post #3565427
For the past 2 months or so I've been building something that I'm both unable and unwilling to name yet. AI companion would be trivializing it, and calling it a human brain model would over complicate it. It's something else. I wanted to settle a curiosity after having tried OpenClaw (which didn't do it for me at all). I wanted to see how far I could push using LLMs to model my version of ... something with volition, emotions and a continuous memory system. I'm not a neuros...
-
Post #2226303
The IOCTA 2026 report has been published by Europol: https://www.europol.europa.eu/cms/sites/default/files/documents/IOCTA-2026.pdf #Cybersecurity
-
Post #2226302
Spoke with a friend in the US regarding AI and LLMs. He said that in the startup, entrepreneur circles if you&#39;re doing anything AI you&#39;re assumed to be using a frontier model, there&#39;s just no mental alternative. I&#39;ve gone the other route and even assuming that frontier models will disappear and we&#39;ll be left with smaller, &quot;local&quot;, models in 2-3 years time. I also find that frontier models are used for even the most trivial of tasks wher...
-
Post #2226300
Experimenting with a column based &quot;timeline&quot; like view of articles. Each column is dynamic in what content appears based on a combination of topics and tags extracted from each article. I kinda like this, like Mastodon timelines but for articles ๐
-
Post #2226299
It&#39;s this kind of &quot;threat landscape&quot; monitoring I&#39;ve always wanted. Curated topics, articles delivered to me when they appear and bundle with others talking about the same thing: Things are &quot;finally&quot; starting to come together.
-
Post #2226298
Spring. There&#39;s nothing quite like it. The magic of the season. The horror of time speeding up for a few months. The duality of it all. Sunshine and wonderful feelings, never ending rain and depression over a period soon gone. Sweden most certainly have seasons. A long and dark period from November until March. The snow can help lighten things up, but without it it&#39;s ... dark. Come spring and things comes alive. People, nature, and promises of fulfilling dreams and ambitions....
-
Post #2226273
Quite happy with an update for the: https://threat.cstromblad.com/dashboard where the &quot;Threat Actor&quot; details have been significantly updated. This is all derived automatically, no hands on keyboard to generate. Each named actor comes with extracted aliases, and a set of &quot;Archetypes&quot; which is basically my attempt to characterise the threat actor based on what documented &quot;goals&quot; they appear to have had. Each archetype lists the most recently...
-
Post #1421952
ANDROID APP ๐ No, it&#39;s not beautiful. No it&#39;s not entirely useful. NO it doesn&#39;t have any features beyond scrolling and viewing individual articles. But boy... it&#39;s an Android app, talking to my API. BOOM!
-
Post #1421950
RE: https://swecyb.com/@orlysec/116408668841445773 I thought it was curious with a JAVA RAT, and observed the following: Blackbasta JAVA RAT: https://blog.rapid7.com/2025/06/10/blacksuit-continues-social-engineering-attacks-in-wake-of-black-bastas-internal-conflict/
-
Post #1421948
Very excited to try the new map coming to #ARCRaiders and by recent scout reports it looks to be a banger of a map! Once they are done with the new map, I&#39;m hoping for an ambitious update to loot and gear. It needs to feel more &quot;special&quot; to loot, to find cool and unique gear. Why not &quot;sets&quot; granting special abilities? Or rad attachments? Basically we need moaaaar of everything, kinda... https://arcraiders.com/news/riven-tides-map-scout-report
-
Post #1421947
Has anyone experimented with intent based SQL query statements? I did this, because of... reasons. Have all this semi-structured data in JSON. Lots of fields for different purposes. Used a cheap LLM to generate descriptions of what each field contains. Now I have a table with fields and a textual description for what is contained (typically) within the field. Then I used an LLM to translate user intent to appropriate fields and constructed appropriate SQL queries based on best match for the...
-
Post #1005886
Alright friends, I&#39;ve got a real need. I want a collaboration suite for myself and a few others. I don&#39;t want Teams, or Slack. Ideally I&#39;d like a hosted option in Europe as I will not have time to manage a self-hosted installation, it&#39;s not where my energy should be directed right now. Collaboration, for me, means Chat + Video, calendars and simple file-sharing options. I&#39;m currently using Proton privately, and could consider using this for a business a...
-
Post #891906
I&#39;ve got roughly 18 months worth of collected OSINT (from primary sources) which has been processed quite extensively. Last night and today I&#39;ve been spending time exploring ways to ... visualize the threat landscape based on what I have. Here&#39;s the most recent iteration of &quot;my dashboard&quot;. Each individual little bar is clickable. It will list the articles relevant for that week/bar, the most popular tags for the articles. The purpose is to give me a d...
-
Post #782864
I&#39;ve finally gotten around to adding the final touches to the @orlysec &quot;bot&quot; account. It should very soon begin to write more Toots. And just to reiterate. The ORLYSEC account will publish from a very strict set of sources, always attributing to original source and no redirects, tracking links etc. The very purpose of the account is to contribute a fairly high-quality feed of stuff that you probably would like to read/skim. Let me know if there&#39;s something yo...
-
Post #762918
RE: https://swecyb.com/@orlysec/116252614096584883 Amazon TI team does something I have not seen any other team do - explain whether or not an IOC is still valid. That sort of &quot;transparency&quot; of IOCs really should inspire others to do the same.
-
Post #762917
Oh, exciting progress on my new processing/analytical &quot;engine&quot;. I&#39;ve built a system to break down complex processing and analytical jobs into more &quot;atomic&quot; tasks. These tasks are defined as simple JSON-data structures and can then be sent to an LLM-engine of choice. For example one thing I often do when reading articles it to try and figure out which entities are the attackers and victims. Then I tag this in order to be able to quickly understand co...
-
Post #762915
Whenever there is a recent attack campaign reported across multiple articles I always wish for there to be a &quot;sum of all the pieces&quot; to try and get a better understanding. I tried something new today with regards to TeamPCP and the recent CanisterWorm and Kubernetes Wiper campaign. Let me know if you like the format. https://cstromblad.com/posts/threat-actor-profile-teampcp/ #ThreatIntel #Cybersecurity
-
Post #762911
And now #Swecyb is running the latest version of Mastodon which is version v4.5.8. A few security fixes, changes and other fixes. Security - Fix insufficient checks on quote authorizations (GHSA-q4g8-82c5-9h33) - Fix open redirect in legacy path handler (GHSA-xqw8-4j56-5hj6) - Updated dependencies https://github.com/mastodon/mastodon/releases/tag/v4.5.8