Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Tim (Wadhwa-)Brown :donor:

@timb_machine@infosec.exchange
  • Open on infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

0 Followers
0 Following
50 Posts
Joined November 01, 2022
Papers and presentations:
https://scholar.google.co.uk/citations?user=vx_iiGYAAAAJ&hl=en
Blogs:
https://blogs.cisco.com/author/timwadhwabrown | https://labs.portcullis.co.uk/author/tmb/
GitHub repos:
https://github.com/CiscoCXSecurity | https://github.com/timb-machine
Twitter:
https://twitter.com/timb_machine
LinkedIn:
https://www.linkedin.com/in/timb-machine
Web site:
https://www.nth-dimension.org.uk/

Posts

Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · 6d ago
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
"Our AI broke out of the sandbox" is the new "my dog ate my homework".
1
1
1
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Aug 02, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Pleasantly surprised that onedriver's auth_tokens.json has sensible permissions.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 30, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Spent some time today, discussing reverse engineering, encouraging my mentee to dig into the next level of Ghidra and explaining how IDA search worked and why not everything was a string... Also how FUN_ and LAB_ are derived.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 28, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Some people will tell you that PQC resilience is a maths issue, but I'm arguing it's a hygiene issue.
0
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 27, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
RE: https://mastodon.social/@sellathechemist/116992339665635678 It's not really random if it's not from from the location of getrandom(), instead it's just sparkling CPU state data...
Quoting
SellaTheChemist @sellathechemist@mastodon.social
Message for the day – Commit a random act of maintenance! Listen to it, look at it, wipe it, clean it, lube it, brush it, tighten it, grease it, turn it, check it, test it, sweep it, mop it, paint it, tape it, sand it, tweak it, tune it, adjust it, wash it, oil it, dust it, align it, scrub it, wind it, fill it, seal it…
Open quoted post
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 25, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
What a good time to be coming back to Debian: https://www.debian.org/vote/2026/vote_002 Hope it passes. #debian
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 24, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
mera Hover or focus to reveal Sensitive
Forgot how much I enjoy DJ Shadow. Reminded myself by sticking the Entroducing CD on...
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 23, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange
Been tinkering with https://github.com/timb-machine/bookkeepr Adding support for Akregator and "interesting links of the week". It's Perl, so not for everyone but still fun.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 22, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange
Might go bug hunting KDE later for the full 2010'ish experience. The big questions: 1) Are IOSlaves still a problem? 2) Is DBUS any better than DCOP?
0
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 22, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange
Also went with KDE which I'd not used since ~3.something and now Akregator is being loaded with all my "interesting links"...
0
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 22, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
I'd kinda forgotten what games can be like. but building my first personal laptop in the last decade or so, I've installed vitetris and the rogue-like angband.
2
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 21, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
meta Hover or focus to reveal Sensitive
Curry.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 20, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Thank you to all the resistors, capacitors, ICs et al for your hard work last week and for not failing when we needed you most. #emfcamp, #emfcamp2026
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 20, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Don't get me wrong, the food at #emfcamp is fucking excellent but nothing beers waking up in your own bed, making a cup of tea and the scarfing down bacon sarnies. #emfcamp2026
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 19, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
@badge@social.emfcamp.org If I buy all the spare parts from the online store and the new 2026 bits (both already done), do I need the 2024 green front board or will it work without? If I do, do you have any spares on site? Asking as I gave my 2024 badge to someone who missed out and I'm trying to bootstrap a replacement from the spare parts...
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 19, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange
Could do with some saying you are number X in the queue. That would be very #emfcamp :bloblaugh:..
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 19, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
On hold music "I want to break free..." whilst in the queue for the shower :) #emfcamp, #emfcamp2026
0
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 19, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Found a wristband, so if you could all check the whereabouts of yours before I have to involve orga, @info@social.emfcamp.org, lost property and site security... #emfcamp, #emfcamp2026
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 19, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
meta Hover or focus to reveal Sensitive
Sore feet. #emfcamp, #emfcamp2026, #nullsector
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 18, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
At the end of the beginning (shower queue) and can confirm that it /is/ finite. #emfcamp, #emfcamp2026
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 17, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Fun fact, there are over a hundred Meshtastic nodes at #emfcamp (113 at last count) and not yet a use case for them... A field of nerds and still nothing useful, tells a story :). Good fun tho'...
0
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 14, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange
A one line patch fixes the underlying issue but the layers of packaging and obscurity in the installer pissed me off no end, so fuck Ubuntu for this box.
0
2
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 14, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Where's my "I am not surprised" face? https://www.gov.uk/government/publications/childrens-circumvention-behaviours-online
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 14, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange

Thank you for calling The Void. All our operators are cursed right now but please hold the line and leave your scream after the tone.

Also:

  • https://infosec.exchange/@timb_machine/116914235375705991
  • https://infosec.exchange/@timb_machine/115567791797424014

(not exactly a fan...)

0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 13, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Replying to @timb_machine@infosec.exchange
Things that touch machine-id in Debian: https://codesearch.debian.net/search?q=%2Fetc%2Fmachine-id&literal=1
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 13, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
A little bit on machine-id from a friend: https://ransomware.sh/posts/machine-id/ #linux, #blueteam
0
2
0
2
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 12, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
The hilarity that Ubuntu Server installer still can't handle a preexisting LUKS partition without shitting itself.
1
3
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 11, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Just ordered Alan Packah's business cards for #emfcamp. Those that know, know.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 11, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
That time of the week, where I go through all the crazy ideas on the timeline proposed for #emfcamp to pick out the scavenger hunt challenges for @emfctf@infosec.exchange.
1
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 11, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Walk thought: I wonder what would happen if you needed to demonstrate harm for the CMA to be applicable. It's always frustrated me that we can't price cyber crime in more effectively.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 08, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Vote Binface!
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 04, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Ended up talking to Jag about history of friends and it's fun to think that there are at least two from university, several from Indymedia, a couple from Portcullis and various others from different places, all hanging out here on the Fediverse. It always tickles me when I see the overlaps.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 04, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Interesting Git repos of the week:

Strategy:

  • https://github.com/mr-r3b00t/ai_usage_mitre_analysis - AI abuse through an ATT&CK lens with @UK_Daniel_Card@infosec.exchange 🤖

Detection:

  • https://github.com/citizenlab/bluecoat-investigations investigating Blue Coat device breaches with @citizenlab@mastodon.social
  • https://github.com/andreicscs/HoneyWire - F/OSS deception

Bugs:

  • https://github.com/sgkdev/ipv6_frag_escape - another Linux LPE

Exploitation:

  • https://github.com/x86byte/Obfusk8 - obfuscation library
  • https://github.com/bee-san/RustScan - a port scanner in Rust
  • https://github.com/t0thkr1s/gpp-decrypt - dumping GPP cpassword
  • https://github.com/kernelstub/Nox - attack surface management in Go
  • https://github.com/JVBotelho/skewrun - abusing time in AD
  • https://github.com/db0109/AI-Red-Team-Scripts-And-Checklist - tips and tricks for red teaming AI 🤖
  • https://github.com/jonaslykkegaard9-ops/m - remapping Windows memory

Hard hacks:

  • https://github.com/pinkflawd/MIPSReverseEngineeringWorkshop - @pinkflawd@mastodon.social's MIPS training

Nerd:

  • https://github.com/ripienaar/free-for-dev - free hosting for developers 🤖
  • https://github.com/dockur/macos - OS X in Docker

#code, #security.#research

0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 04, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Interesting links of the week:

Strategy:

  • https://ecs-org.eu/policy/nis2-directive-transposition-tracker/ - following along at home with NIS2 enactment
  • https://mr-r3b00t.github.io/org_cyber_attack_sim/ - what does it really feel life to defend, @UK_Daniel_Card@infosec.exchange has built a sim to find out

Standards:

  • https://www.w3.org/TR/security-disclosure/ - @w3c@w3c.social weighs in on disclosure

Threats:

  • https://anuragbhatia.com/post/2026/06/telegram-bgp-hijack-and-blackholing/ - some reporting on a BGP hijack of Telegram

Detection:

  • https://www.huntress.com/blog/ldap-active-directory-detection-part-six - more from @huntress@infosec.exchange on LDAP detection
  • https://tradecraftgarden.org/ - from the people that brought you Cobalt Strike
  • https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html - incident satire from @andrewnez@mastodon.social
  • https://blog.sentry.security/log-curation-101/ - a subject after my own heart, useful logs...
  • https://www.deathcon.wales/ - here be dragons

Bugs:

  • https://askar.so/blogs/chaining-isc-dhcp-server-features-for-unauthenticated-root-remote-code-execution/ - poppin' DHCP
  • https://pop.argus-systems.ai/advisory/adv-040.html - OpenBSD is too open 🤖

Data:

  • https://intheweights.com/ - which models are you in? 🤖

Nerd:

  • https://fediverse.info/explore/people - people of the Fediverse
  • https://fedidb.com/welcome - find your perfect Fediverse platform

#security, #research

1
0
1
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 04, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

What's the best bit of post-exploitation? #redteam, #blueteam

Persistence?
14.3% (2)
Privilege Escalation?
21.4% (3)
Defense Evasion?
7.1% (1)
Lateral Movement?
35.7% (5)
Command and Control?
0.0% (0)
Exfiltration?
0.0% (0)
Impact?
14.3% (2)
Something else?
7.1% (1)
14 votes Poll closed
View on infosec.exchange
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 03, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
This year's mentee is coming to #emfcamp...18 and already a massive hardware hacking nerd. Abusing PCI is his jam although I had him break into a TP-Link camera today with an 0day he found, which was fun.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jul 03, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
Age catches up with everyone. Just seen an "old" person carrying off skinny fit denim shorts... That'll be me one day, but with massively baggy...
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jun 28, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
"Who do I file bugs with?" enquired the ghost. "That one down there is faulty", they continued, pointing at a politician on the earth below. #microfiction
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jun 27, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
I've never done an "interesting links" from @emf@social.emfcamp.org, it could be a big one...
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jun 27, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Interesting Git repos of the week:

Detection:

  • https://github.com/hasamba/DFIR-Companion - incident support 🤖
  • https://github.com/GyulyVGC/sniffnet - that packer smells kinda funny 👃

Bugs:

  • https://github.com/0xHossam/UnCanny - the bullying of NTLM must stop!
  • https://github.com/prdgmshift/usbliter8 - A12/A14 SecureROM exploit
  • https://github.com/rub-softsec/onelogon - stealing AD creds via Netlogon
  • https://github.com/bikini/exploitarium - fresh bugs today

Exploitation:

  • https://github.com/MazX0p/LACUNA-Chain - build your own stack and profit
  • https://github.com/Shac0x/Wonka - like picking LSASS's wallet for tickets
  • https://github.com/netinvent/windows_tools - there's a snake coming through the window
  • https://github.com/mitre/grid-watch - MITRE's CTID lab for OT 🤖

Hard hacks:

  • https://github.com/datalocaltmp/Peepo - @datalocaltmp@infosec.exchange's primitive attacks on watchOS 🤖
  • https://github.com/hacefresko/forticrack_v8 - unpack that Fortinet firmware

Data:

  • https://github.com/idaholab/raven - tools for risk modeling

Development:

  • https://github.com/uellenberg/Insert - you wanna write self modifying code? how about a language where it's a first class feature?

Nerd:

  • https://github.com/maestro-os/maestro - a Linux-like kernel in Rust

#security, #research, #code

0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · Jun 27, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange
todayonai Hover or focus to reveal Sensitive
When you demonstrate that "long term memory" is just another way to say "contamination between queries is permitted". Asked an AI about 1 topic and got related but inappropriate information from an unrelated query from 3 weeks ago.
0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 10, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

For all the AI hype, I'm absolutely fascinated to see more bug content that focusses on the mass of internal, commercial, compiled code that runs businesses. Most of the disclosures thus far appear to be for open source, where we should assume the models know the code, have seen the bug reports and have access to the patches but that's really not the reality of "interesting" enterprise software.

4
1
2
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 10, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Interesting links of the week:

Strategy:

* https://cset.georgetown.edu/article/chinas-pla-challenges-and-competitions/ - analysing .cn PLA strategy
* https://ccdcoe.org/news/2026/locked-shields-2026-united-the-power-of-41-nations-to-defend-cyberspace/ - Locked Shield 2026 reporting
* https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board - post-incident review is necessary, ya galah
* https://dukesecurity.ai/incidents - SEC disclosed incidents
* https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference - how .ru trains their spies on fiddling with elections
* https://arxiv.org/abs/2509.00462 - AI, stealing all the jobs
* https://arxiv.org/abs/2604.01637 - but first they need job specs
* https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring - NCSC guidance on DFIR and protective monitoring
* https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ - thought piece from Mozilla on Mythos
* https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities - UK AI Security Institute review of GPT 5.5
* https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/ - behind the Mythos curtain with Mozilla
* https://uktl.org.uk/news-events/uktl-ncsc-and-ericsson-strengthen-the-security-of-uk-mobile-networks/ - improving UK telco security

Threats:

* https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html - Trend write up on .cn attacks in Asia
* https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/comment-page-221/ - TETRA abuse in the wild
* https://home.s2grupo.es/hubfs/Informe%20LAB52-%20EasterBunny_Complete.pdf - new reporting on APT29
* https://i.blackhat.com/Asia-26/Presentations/AS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf - reporting on Tropic Trooper from BlackHat Asia 2026
* https://www.catonetworks.com/blog/global-campaign-discovered-with-modbus-plcs-targeted/ - attacks on CNI intensify

Detection:

* https://righteousit.com/2026/03/27/linux-forensic-scenario/ - @hal_pomeranz@infosec.exchange's Linux investigation (there are a number of follow on posts)

Bugs:

* https://retr0.zip/blog/cve-2026-31431-copy-fail.html - more on copy.fail
* https://seclists.org/oss-sec/2026/q2/332 - winning a race with Rust
* https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability - more on the FreeBSD dhclient whoopsie
* https://copy.golf/ - copy.fail.golf
* https://visit.suspect.network/reversing-adventures/inadvertent-injections - accidentally injecting shells

Exploitation:

* https://fuzzinglabs.com/exploring-nvidia-linux-drivers-internals-basics-ioctls/ - exploring NVIDIA's LKM attack surface
* https://www.blackhillsinfosec.com/the-p-in-pam-is-for-persistence-linux-persistence-technique/ - @blackhillsinfosec@infosec.exchange discuss persisting in PAM
* https://www.group-ib.com/blog/pluggable-authentication-module/ - why PAM matters
* https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/ - solutions to @trailofbits@infosec.exchange's C challenges
* https://ipurple.team/2026/05/04/cross-session-activation/ - cross session lateral moment in Windows with @netbiosX@infosec.exchange
* https://heyitsas.im/posts/drinking-llms/ - bug hunting the Linux kernel with LLMs
* https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/ - fuzzing Microsoft RPC

Hard hacks:

* https://labs.taszk.io/articles/post/tapocalypse/ - TP-Link whoppers
* https://tantosec.com/blog/2026/04/route-to-root-in-4g-industrial-router/ - hacking a 4G router

Hardening:

* https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/ - @jwildeboer@social.wildeboer.net's approach to beating copy.fail
* https://www.secwest.net/copyfail-mitigation - more on copy.fail mitigations

Nerd:

* https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-problem - be mindful of who you mix with
* https://di.day/en - declare your independence

#security, #research

6
0
3
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 10, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Interesting Git repos of the week:

Strategy:

* https://github.com/center-for-threat-informed-defense/attack-flow - mapping ATT&CK flows

Detection:

* https://github.com/timb-machine-mirrors/ddamenova-IRQL.md - KQL for IR
* https://github.com/ridgelinecyberdefence/vanguard - Go toolkit for IR
* https://github.com/SharonBrizinov/Holy-Grail-PCAP - new food for Packet Monkey
* https://github.com/Nextron-Labs/surface-watch - @cyb3rops@infosec.exchange's code to keep an eye on the front door
* https://github.com/keydet89/RegRipper3.0 - @keydet89@infosec.exchange's seminal IR toolkit in Perl

Bugs:

* https://github.com/V4bel/dirtyfrag - more Linux sadness

Exploitation:

* https://github.com/azqzazq1/SunnyDayBPF - imagine that, a kernel that lies
* https://github.com/BlackSnufkin/LitterBox - red teamer's sandbox
* https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper - dump Edge passwords from memory
* https://github.com/her3ticAVI/PAMSkeletonKey - a skeleton key for PAM
* https://github.com/segmentati0nf4ult/linux-pam-backdoor - an earlier version of the same code
* https://github.com/Kudaes/Puzzle - abusing Windows minifilters
* https://github.com/diemoeve/oxide - a new C2 framework
* https://github.com/TwoSevenOneT/DefenderWrite - enumerate AV whitelisted executables for LPE with @TwoSevenOneT@infosec.exchange

Hardening:

* https://github.com/wgnet/wg.copyfail.patch - a nice little eBPF patch for copy.fail
* https://github.com/atgreen/block-copyfail - another eBPF approach to copy.fail from @atgreen@hachyderm.io 🤖

#security, #research, #code

GitHub

GitHub - center-for-threat-informed-defense/attack-flow: Attack Flow helps executives, SOC managers,

Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack ...

8
0
3
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 09, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Citations are nice. Thank you anon.

1
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 07, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Long old week but 5 happy customers, two commuting to renewals makes it all worthwhile. I shall sleep well tonight.

0
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 06, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Provided genuine and nuanced feedback on AI slop on AI slop. Comments all deleted and article published. That'll teach me to spend time making suggestions to improve an article.

3
0
1
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 06, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Stumbled into a channel where everyone is replacing themselves with their AI pets and well, if you're the kind that needs an agent to do anything then no wonder you're having trouble installing an agent...

1
1
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 05, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

The statement "lies, lies and statistics" could have been written by an AI, and now thanks to LLM, it will be.

3
0
0
0
Open post
timb_machine
Tim (Wadhwa-)Brown :donor: @timb_machine@infosec.exchange · May 04, 2026
Tim (Wadhwa-)Brown :donor:
@timb_machine@infosec.exchange

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

infosec.exchange

Congratulations to Canonical on poor life choices:

https://seclists.org/oss-sec/2026/q2/332

#threatintel, #non-GNUcoreutils

10
0
6
1

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:02:32 UTC