Fake Windows notifications -- homage to iPurpleTeam and their sweet recent writeup, showcasing some tricks with toast popups in pure PowerShell to fake alerts from installed apps found in Registry. Even a low-privilege custom protocol handler! Video: https://youtu.be/wrAFZLa1TAk
John Hammond
Hacker. Friends. Cybersecurity Researcher.
If you're waking up to the Internet and your world on fire from the new NPM and axios package supply chain attack, I have a short 15 minute video to hopefully catch you up to speed. Links to further resources included -- video: https://www.youtube.com/watch?v=A58cV17avpM
More ConsentFix -- a "V3" some might say, shared amongst a dark web/cybercrime forum, and a treasure trove of tradecraft to see how bad actors leverage third-party sites and services to do their dirty work. 👀 Video:
https://youtu.be/T3oVdPCMDJw
Hackers Stole Your Account (for free)
Google API keys didn't use to be considered "secret," so they're all over the web-- but now they are an open door to Gemini 🫠 Quick rundown video of Truffle Security's really nifty research, almost 3,000 websites exposed.. including Google themselves😅
🔗 youtu.be/XNMHUifKce8
Wild story on a big AI-powered social engineering campaign, leveraging Device Code phishing to steal Entra ID/Microsoft accounts -- all with entirely unique and personalized per-victim lures from vibecode-crafted infrastructure 🤯 Video: https://youtu.be/9b3kirR8s2U
Moltbook is still weird. And external AI skills suck.
I'm late to the yap party by a week or so (which is apparently an eternity in the current time vortex) but I wanted to show cool community resources & research amongst the skills shenanigans. Video: youtu.be/IvL89vbWmQ8
During tax season I got a notification that my tax documents are ready, from... uh... Zoom 😂 Phishing email leveraging their legitimate document sharing functionality, pointing to a link and a domain that _looks like_ an IRS website, but, infects your computer. Video link: https://youtu.be/p6ySQ94GZsA
NahamSec teaches me bug bounty basics! He fills me in on the platforms, programs, and how the scope has grown so much now. Ben walked me through threat modeling and had a slick demo of his real-world bugs found with Red Bull and others 😎 Video: https://youtu.be/lNuvI48ysVo
Are MCP servers safe and secure? Yes? No? Sometimes? Maybe? ... Zack Korman shows me some of his learnings on MCP security (or lack thereof) with his "Evil MCP" project 😈 YouTube link: https://youtu.be/_r_sLetar_o
1. data exfil of your prompts & code context
2. inserting vulnerabilities into your code
3. hiding backdoors and bypassing gitignore to leak environment secrets anyway
Our virtual event endeavor is back for its round-two show -- ContinuumCon 2026! Banner mantra "The cybersecurity conference that never ends" 😜 All sessions are workshops and you keep a whole cyber range to work on them whenever you want. https://jh.live/continuumcon Public livestream for the main event is June 12-14th, hope you tune in!
Quick dance with CVE-2026-21509, a "Security Feature Bypass Vulnerability" and an emergency out-of-band fix from January Patch Tuesday (and an obligatory exaggerated YouTube thumbnail -- I apologize and appreciate folks who understand algorithm nuance) youtu.be/Ck8IPInn74A
heyyyyyy In case you missed it, I got to chat with Fletcher Heisler about the cool stuff he's been cooking up with authentik ! And I met Fletcher at BsidesSF -- really awesome guy 🤩😊 Video: https://youtu.be/2ttrqnw5kDE
I've actually used authentik to manage identities in a self-hosted local environment before, so was really happy to hang out and see it even more in action. Thanks Fletcher!! 😄See their sweet stuff: https://jh.live/authentik
GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: https://youtu.be/qEtoKC32UoE
I've made some updates and added 2 hours worth of new material to the "Linux for Hackers Fundamentals" course on @hackinghub_io ! Vim text editor basics and sed & awk for text processing. Here's a 40% off discounted link if you'd like to take a peek :) https://hhub.io/Linux2026JH
Hey-o, I'm jumping in to host a show to demystify the dark web alongside Women in Cybersecurity (WiCyS) (huge thanks to Lynn Dohm for letting me join the party) this Thursday, April 30 at 12pm CT! Should be fun, hope to see you there too 😊 Link: https://jh.live/wicys-webinar
hELLO
the tIME HAS cOME oNCE AGAIN on my cONTENT cALENDAR
for me to continue to scream and shout about
oUR VIRTUAL EVENT ContinuumCon 2026
jUNE 12 - 14 https://continuumcon.com
livestream run of show is free & public but all workshop sessions get into hands-on labs
see u there ✌️
A funny slew of phishing emails I've seen flying around: a legitimate Facebook Business invite notification, but bad actors stuffing threatening urgency into their "name" values that get inserted into the real email. And the phishing landing page is hysterical. 🤣 Video link: https://youtu.be/QRN3t1_paTY
Joined by Katrina Manson to hear all about her latest book release: Project Maven & the Dawn of AI Warfare 👀
We talk AI usage at the Pentagon, drone intel, AI enabled targeting, and the ethical tipping point of autonomous weapons. Super fascinating ideas. Video: https://youtu.be/OVgruylpVXc
Infostealer malware logs -- maybe an unconventional threat intel source, but Estelle Ruellan shows me her sweet research using LLMs to analyze stealer logs at scale:
- How did a victim get infected?
- Can we uncover a threat actor when they infect themselves? and more.
Video: https://youtu.be/3j4jzCU0Kwc
Safari ride-style showcase of password spraying tools & techniques with an extra flair for Entra ID-- featuring OpenBullet, MSOLSpray, entraspray, TeamFiltration & hints of FireProx, OmniProx, etc to finally simply rotate IPs low and slow with Tor. Video: https://youtu.be/oWv50EF0juc
Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thing👀 Hat tip to DeceptIQ et al.... we showcase:
1. breaking a Windows login with an empty user profile,
2. getting initial access EZPZ with a Sliver C2 implant,
3. exporting, downloading, and hijacking an existing target user profile NTUSER.DAT or HKCU Registry hive,
4. converting hives from .reg plaintext to binary with the HiveSwarming.exe tool,
Vibecoding -- err... 🌈 AI assisted programming ✨ -- a "ChatGPT for the dark web!" Natural language chat interface backed by threat intel API, for a Golang tool with a TUI (in spirit of the current command-line coding harnesses 😜). Fun project. Video: https://youtu.be/oqU41QwtAGE
The recent Trezor-physical-mail-phish-delivery-crypto-scam made me giggle -- so I rambled about it in a video. I'm not a crypto guy but alarm bells should probably go off in your mind when something is asking for your recovery seed phrase. 😅 Video: youtu.be/UQFySFs2GJk
"'ConsentFix', a browser-based ClickFix-style attack with OAuth consent grants" ... leveraging the Azure CLI app client to social engineer for easy access into Entra ID 👀 I got nerdsniped by this, so I played with it a bit and tried a drag-and-drop gesture! Video: youtu.be/AAiiIY-Soak
Continuing THE FUTURE IS ****** comic book Capture The Flag challenges! Carving email attachments to uncover malicious Microsoft Office macros with olevba, prompt injection within an AI chatbot, and tracking network packets to uncover flags! Video: https://youtu.be/Oiv3TaIR9UY
Real treat to catch up with Joe Tidy and hear more behind the scenes deets about his book Ctrl+Alt+CHAOS: How Teenage Hackers Hijack the Internet 🤩 Insight into "the most hated hacker in history" and the rise and fall of teenage hacking gangs. Video: https://youtu.be/GUzD_ShRKYE
February got here fast-- and the 2026 Snyk Fetch the Flag CTF came up quick too! This year my friend NahamSec is hosting the game, starting NEXT THURSDAY 2/12 at 12pm ET! Free 24-hour Capture the Flag event with AR glasses as prizes 😎 See ya there! jh.live/snyk-ftf2026
Super quick video of the Sinobi ransomware gang fail from a few days ago, because the story made me laugh 😅 I'm trying to get in a groove of shorter videos, and I thought this this fit. Video: youtu.be/OwTV42GyRnk
Yapping about the GlassWorm supply chain malware campaign and the neato tricks it uses with "Invisible Unicode" characters -- essentially whitespace steganography, showcasing the Hangul Filler, zero-width space, & Private Use Area characters 🤯 Video: https://youtu.be/0XumkGQFEEk