I help secure the cryptocurrency ecosystem and provide support to those fighting human trafficking.

Joined September 2023
39 Photos and videos
Pinned Tweet
May 12

2
17
47,871
dobs retweeted
🔐 LUKSbox v0.3.0 is here! 🎉 Your FIDO2 security key now works EVERYWHERE 🌍 (@Yubico YubiKeys, @nitrokey, @SoloKeysSec, @Google Titan, and more) Enroll it once, unlock the same encrypted vault on 🐧 Linux, 🍎 macOS AND 🪟 Windows. No more platform-locked keyslots. Free & open source (Apache 2.0) 🦀
11
66
654
42,975
Jun 16
Kimi K2.7 on Hermes Agent (via @AskVenice ) is impressive.
38
يستخدم تنظيم القاعدة في جزيرة العرب مؤسسة يقين المناصرة له كأداة لتنفيذ عمليات التجنيد الرقمي،خصوصا تجاه المقيمين في الدول الغربية وذلك عبر طريقتين الأولى من خلال حسابات ظل تقوم بالتواصل مع المنضمون حديثا داخل المجموعات المغلقة التابعة للمؤسسة علي ،سيجنال وواتساب وروكيت شات 3/1👇
2
5
16
15,664
dobs retweeted
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky. When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit. We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted. In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation. H/T to colleagues that shared this with me socket.dev/blog/mini-shai-hu…
225
2,162
12,663
1,560,676
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency Proofpoint Threat Research "North Korea-aligned threat actors have made a concerted effort not only to target cryptocurrency and decentralized finance organizations, but specifically to target developers using fake recruiter personas..." proofpoint.com/us/blog/threa… @proofpoint
2
6
20
1,777
dobs retweeted
RTL-SDR Now Runs on iPad M-Series Devices Directly via USB Without Jailbreak rtl-sdr.com/rtl-sdr-now-runs…
7
78
629
41,530
dobs retweeted
I love seeing this kind of surveillance-disrupting experimentation. github.com/Meltedd/scarecrow
53
538
4,228
150,641
dobs retweeted
Jun 3
One hour until we go live! See you there 👇
Jun 2
Ethereum security is an ecosystem effort 🛡️ Tomorrow we'll hear from @wintermute_t, @Quantstamp, @sigp_io , @Certora, and @chain_security on why they supported the round and where Ethereum security funding should go next. 👇 x.com/i/spaces/1YxNrrvEqYNxw…
5
22
763
dobs retweeted
It's finally happening! SEAL Certifications are now open for business. 🎉
15
24
131
27,558
I do believe I've warned y'all for years about this exact thing.
Enjoy! "SignalTrace is designed to help law enforcement identify people of interest by the signals emitted from their electronic devices they travel with, such as fitness trackers, smartwatches, RFID tags, and local signals from their mobile phones...
11
27
205
8,584
Jun 1
Using AI to fix random Linux hiccups I run into….is probably the best use case for AI so far. That alone has saved me days and days of time.
43
dobs retweeted
May 29
Someone found a way to see inside the X phishing panel I shared earlier. Indeed confirms what I thought the capabilities and impact are. Interesting to see how they leverage the OAuth token via the panel directly for controlling the accounts. Thanks for the ping.
I hacked back this phishing kit and found X accounts with millions of followers I could control. I received this email yesterday. Obviously a phishing attempt for an X account take over. Most likely a compromised email or SMTP server.
2
13
80
12,073
dobs retweeted
Worth noting that the junta reportedly told the US that scam centers near the border would be dismantled before june
BBC rumors the Myanmar regime are going to restart demolitions in Shwe Kokko (no longer using explosives after injuries in KK Park & warning from the Thai side). Demolitions at SKK quietly & abruptly ceased without explanation in December. I wrote here: sheehanistan.substack.com/p/…
8
18
1,340
dobs retweeted
Looks like a threat actor under the name BlackTigerAlliance" has released personal information on the executives of Integrity Tech, the Chinese cyber security company accused by the US Treasury department of intrusion into US victims IT infrastructure. 1/2
4
45
151
34,866
dobs retweeted
Greg Maxwell used to send us updated lists of malicious spy nodes that Bitcoin peers should ban. I reached out to him asking for the latest list, and this was his reply:
15
23
162
17,456
May 25
I have a gripe about @X that I wish @nikitabier could fix, but may be impossible. Recently, RuView went viral. You probably remember it - the Github project that allows you to see through walls with WiFi. It was all over my "For You" and big accounts posted about it. But....Do you recall anyone actually deploying the project? Plenty of folks posted about it...but very few actually posted about using it. Let's look at that briefly. These are the people actually putting in the work and getting near-zero traction. x.com/VladislavGqrxq/status/… - 9 followers, 50 views on his post. x.com/ozansozuoz/status/2058… - 7 followers, 343 views of his reply (to a post with 125k views) After seeing one hype post about the project, I'm more interested in whether it works. But I had to go to @grok to find these posts (thanks bud). Am I doing something wrong, or can @X find a way to surface simple, low-view high-impact posts related to content that gets substantial views?

May 24
Replying to @sharbel
Ruview is a little gimmicky. Tried it with 3x ESP32-S3 sensors and it requires more sensors than i thought
1
59
dobs retweeted
Organized crime is evolving into a global, tech-enabled threat. From cyber scams to drug trafficking, criminals are expanding their reach & causing real harm. A new UNODC research brief examines how these groups operate and profit: ow.ly/72fe50Z3JoG
15
112
185
11,961
May 21
1) Avoid KYC 2) Use a commercial mailbox provider (such as UPS Store) for crypto-related shipping 3) Have a plan.
A common trend we’ve seen in crypto kidnappings is attackers will go after family members who are “softer” targets If you don’t include your family in your physical security planning, you’re missing a huge part of the equation
2
609
May 18
Cyber warfare is not independent from cyber crime. “Authorities are also investigating whether foreign syndicates were involved in a recent cyberattack on the Sri Lankan treasury that resulted in around $2.5 million in losses.”
Crackdown in Southeast Asia pushes scam networks to #SriLanka - @AFP reports thedailystar.net/news/world/…
1
130