Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

David J. Bianco (He/Him)

@DavidJBianco@infosec.exchange
  • Open on infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

0 Followers
0 Following
14 Posts
Joined November 04, 2022
Blog:
https://detect-respond.blogspot.com
Twitter:
@DavidJBianco
Twittodon:
https://twittodon.com/share.php?t=DavidJBianco&m=DavidJBianco@infosec.exchange
Fave Shape:
Pyramid

Posts

Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Aug 04, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
RE: https://mstdn.social/@TalosSecurity/117037300515232940 New research from some of my Talos colleagues. How do threat actors prompt their LLMs? Sounds like the setup of a dad joke, but finding the answer yields valuable insights.
0
0
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 31, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Movie pitch: a Terminator reboot, but the difference is Cyberdyne Systems publishes a humblebrag press release about how Skynet broke containment.
0
0
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 29, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
EvidenceForge v1.13.0 is out this morning. If you're generating long scenarios with millions of network flows, you're going to need the fixes. https://github.com/Cisco-Talos/EvidenceForge
1
0
2
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Replying to @csec@infosec.exchange
@csec@infosec.exchange As I mentioned in another reply, that part is really risk management. There are multiple strategies, including using only local models or setting contractual limits on how the cloud provider treats your data. Local models probably provide the highest level of assurance, but push the cost (both monetary and non-monetary) onto the org. In some cases, using a cloud provider might actually be the "best" choice, but it's highly dependent on circumstances.
0
1
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Replying to @tarakiyee@mastodon.online
@tarakiyee@mastodon.online I don't think they're worried about the attacker data so much as their own data, but yes. Presumably they got further in the response process with the local model so some data they eventually processed wasn't send to the cloud provider. That part is really risk mitigation, and there are multiple strategies to deal with it, depending on your requirements and comfort levels. Running a local model is a great one if you can manage it, though.
0
0
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Replying to @flyingpenguin@infosec.exchange
@flyingpenguin@infosec.exchange I'm sorry, but I must disagree on two counts. First, guardrails aren't a service tier. If you're using the model, you abide by the guardrails and you really don't have a choice except to change models or, more likely, service providers. Which is a big part of the issue, because this has costs and risks, and isn't the sort of thing you want to have to worry about in the middle of an active security incident. The other point I have to disagree with you on is your characterization of capability parity as "vigilantism". It's hard to know where to begin, but I'll start with this: parity may or may not be achievable, if it *were* possible, it'd be great. But the idea of vigilantism (i.e., infosec Batman) doesn't enter into any conversation where the victim is solely defending themselves and not going out on the Internet looking for trouble. So yes, when one side is subject to limiting guardrails and the other isn't, there is an issue. Not that the guardrails themselves are bad, but HF clearly hadn't anticipated running into them and was forced to work around them at a time when they most needed their processes to be smooth and well-oiled.
1
1
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Replying to @SnoopJ@hachyderm.io
@SnoopJ@hachyderm.io "work roleplay" 😂
0
0
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Replying to @flyingpenguin@infosec.exchange
@flyingpenguin@infosec.exchange It's not, but if one side is playing by rules that the other side gets to ignore, that's a problem too.
1
1
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
Replying to @neurovagrant@masto.deoan.org
@neurovagrant@masto.deoan.org I've been thinking about this asymmetry a lot lately. It's always been true that threat actors have to follow fewer rules than defenders, but this just made it very clear.
6
1
1
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 17, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
HuggingFace got hacked by an agentic system. That's not the important part. What really stuck out to me was the asymmetry in #AI guardrails they experienced. The attacker had basically no constraints, but HF's initial response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local-only models. In the middle of an incident. Another aspect for your IR plans. https://huggingface.co/blog/security-incident-july-2026
62
11
54
5
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 16, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
For years, I've been very clear: "You can't automate threat hunting. It is an essentially human process." Now I'm not so sure. Read why I've reconsidered my stance in my fresh new post: "The Hunter's Paradox: Is it time to embrace automated threat hunting?" https://blog.talosintelligence.com/the-hunters-paradox-is-it-time-to-embrace-automated-threat-hunting/
0
0
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jul 06, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange

EvidenceForge v1.10.0 brings major updates:

  • Far more realistic, configurable email activity. Also produces .eml files as artifacts.
  • Configs can be split into modular, reusable components, making it easy to define a consistent org/environment across scenarios.

https://github.com/Cisco-Talos/EvidenceForge

0
0
0
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Jun 29, 2026
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange
If you haven't yet checked out #EvidenceForge, now is a great time. There have been big improvements in functionality, realism, and performance since the initial release. Create synthetic, correlated logs for training, testing, and more. https://github.com/Cisco-Talos/EvidenceForge
2
0
1
0
Open post
DavidJBianco
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange · Oct 16, 2025
David J. Bianco (He/Him)
@DavidJBianco@infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

infosec.exchange

I did NOT see this coming.

1. Kryptos is fully solved (!!!!)
2. There's the threat of a lawsuit if the solution is made public

https://www.nytimes.com/2025/10/16/science/kryptos-cia-solution-sanborn-auction.html?unlocked_article_code=1.t08.Fb2g.wov0l-NgQKoE&smid=url-share

0
2
4
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:59:11 UTC