Elektrine lite

โ† Feed

Andrew ๐ŸŒป Brandt ๐Ÿ‡

threatresearch@infosec.exchange

<p>Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with.</p><p>Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through.</p><p>Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project.</p><p>Docent of obsolete technology at <span class="h-card" translate="no"><a href="https://post.lurk.org/@mediaarchaeologylab" class="u-url mention">@<span>mediaarchaeologylab</span></a></span></p><p>Executive director, Elect More Hackers: electmorehackers.com</p><p>&quot;By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED ag

Posts

  • Post #4221225

    @cR0w Thank you for your service!

  • Post #4221224

    #Boulder Daily Camera, October 27, 1897: a list of political parties competing on the November ballot. Note the iconography used for the political parties, and the number of different parties represented on the ballot: ten. The Democratic party symbol is a strutting rooster (!) and the Republican symbol is an eagle clutching olive branches but standing on top of a shield laying on the ground. Truly bizarre. #COpolitics #ElectionDay #NineteenthCenturyPolitics

  • Post #4221223

    https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/ Google just XKCD 927ed their threat actor nomenclature, just because. Surely this will speed up response time, because whenever I think about the country of Iran, I always immediately think of the word &quot;ION&quot; ๐Ÿ™„ It&#39;s like the result of someone&#39;s Rorschach test was used to justify the release of a new naming convention.

  • Post #3631513

    I joined @huntress@infosec.exchange because I want to do my part to save the world. That&#39;s not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we&#39;re watching your back so you can concentrate on those things that you excel at, and make life better for those around you. As an industry we&#39;re now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us -...

  • Post #3498154

    Microsoft 365 users and admins, beware! There&#39;s a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches. The attack bypasses MFA and SSO because it uses deprecated but still functional OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were...

  • Post #3179666

    :blob_gnikniht: :blob_gnikniht: :blob_gnikniht:

  • Post #3179665

    Two #Boulder residents have filed a lawsuit against the city of Boulder to challenge the city&#39;s agreement to run 31 #Flock cameras. The lawsuit was filed almost at the same time as a new task force, convened by the city manager, had its inaugural meeting. I am one of the members of this new task force, charged with producing a report on how the city can be more responsible in the way they adopt and use emerging technology. Other members include the CEO of an AI startup, IT specialists an...

  • Post #3179664

    Very excited to be speaking about early hacking tools today at #NaClCon https://naclcon.com/speakers #hacking #mediaarchaeology #cracking #goodtrouble

  • Post #3179663

    Watch out for the people cosplaying temu surveillance Elvis Costello. https://www.eff.org/deeplinks/2026/06/move-fast-surveil-things #LittleBrother #Meta #Surveillance #cameras #cameraglasses

  • Post #2040054

    RE: https://infosec.exchange/@bsidesboulder/116496658300979468 GET TICKET NOW!

  • Post #1840788

    Shot...chaser #BladeRunner #NASA #Artemis

  • Post #1770735

    RE: https://infosec.exchange/@threatresearch/116477454960438426 The SB26-090 hearing is underway. Live stream is https://sg001-harmony.sliq.net/00327/Harmony/en/PowerBrowser/PowerBrowserV2/20260427/33/18751

  • Post #1735746

    ๐ŸŽ‰ Right to repair is preserved! ๐ŸŽ‰ A house committee in the Colorado legislature voted 7 to 4 to &quot;postpone indefinitely&quot; the SB26-090 bill that would have rolled back the hard-fought right, had it passed. A coalition of experts from around the state, the country, and the world testified that the vague definition of &quot;critical infrastructure&quot; left open the possibility that manufacturers could have classified virtually any tech product under that category, which would then have...

  • Post #1724279

    Hi folks. It&#39;s Andrew with another update on our battle over the &quot;wrong to repair&quot; bill that continues to move through the Colorado legislature, SB26-090. I am asking anyone, but especially those with a background as a cybersecurity practitioner, to please consider submitting written or live/virtual testimony TODAY to the committee who will be hearing this bill, starting at 1:30pm mountain time. This afternoon, in a little under four hours, a House committee will be hearing test...

  • Post #1683668

    #Paypal is changing its privacy policy. If you have an account, here&amp;#39;s what you need to do: โœ… Log in (you *are* using TOTP multifactor authentication, right?) โœ…Click the Gear icon in the upper right corner. โœ…Click &amp;quot;Data &amp;amp; Privacy&amp;quot; Follow the link under that category to &amp;quot;Personalized Shopping&amp;quot; โœ…Click the slider switch to disable data sharing with advertisers and retailers based on your purchase history. #privacy #dataprivacy #PCIDSS #userpriva...

  • Post #1541840

    Happy Electronic Warfare Remembrance Day to all the Russian APTs who celebrate https://vpk.name/en/851572_electronic-warfare-specialists-day-in-russia.html

  • Post #1541839

    ๐Ÿดโ€โ˜ ๏ธ Colorado&#39;s &quot;wrong to repair&quot; bill #SB26090 advances the state senate, on a vote of 22-13. #COpolitics #RightToRepair #Infosec

  • Post #1192742

    RE: https://infosec.exchange/@threatresearch/116387050505018174 Current update on SB26-090 (Colorado&#39;s misguided &quot;wrong to repair&quot; bill): After spending a bunch of the senate session on Tuesday in debate over a bunch of amendments, the bill is tentatively on the calendar for tomorrow, again, to have its third reading in the senate. Please keep up the pressure - Coloradans and the rest of the country rely on being able to fix broken things in order to protect them from cyberattac...

  • Post #1135512

    Germany&amp;#39;s BSI, their equivalent of CISA, rates #Firefox as the only browser that meets all of their minimum standards for data security, privacy, and integrity. (in English) https://www.bsi.bund.de/EN/Themen/Oeffentliche-Verwaltung/Mindeststandards/Web-Browser/Web-Browser_node.html (in German) https://www.bsi.bund.de/DE/Themen/Oeffentliche-Verwaltung/Mindeststandards/Webbrowser/Webbrowser_node.html

  • Post #1129708

    ๐Ÿšจ Current update on the Colorado bill (SB26-090) that would rescind &quot;right to repair&quot; for &quot;critical infrastructure&quot; ๐Ÿšจ Please share widely. The bill is currently scheduled for &quot;third reading (final passage)&quot; in the Colorado senate for Monday, April 13, first thing in the morning. If you have delayed until now doing something, this is your moment to act. You do not need to be a Colorado, or even a US resident, to speak up! https://leg.colorado.gov/agenda/floor/2026...

  • Post #1107865

    I have an all-hands-on-deck call to action today. At what point do we stop owning the things we buy, and just rent everything? That&#39;s the #enshittification problem that the #RightToRepair movement is trying to address. In Colorado, where we finally (just 3 months ago!) saw the nascent first awakening of a new right to repair law come in to effect, that infant could end up smothered in its crib this week, as the Colorado senate considers a bill that would roll back the right to repair fo...

  • Post #1061650

    It has been a busy winter so far for me, which is why I haven&#39;t been posting a lot here. But today I&#39;m proud to share with you the fruits of some of that labor: The Colorado Democratic Party&#39;s platform for 2026. For those unfamiliar, a platform (in the US) is a statement of values that a political party stands for, generally agreed upon by people who stand for election as representatives of the party. I was elected during last year&#39;s party re-org to the Platform Committee. The c...