Cybersec/AI expert | Hacker | Pilot | Lifter | OSCE3, CISSP, CCNP, CSIE | Top 20 Hack the Box | CTF Reviews and Writeups | meme magic 🐸

Joined September 2023
942 Photos and videos
Supply chain and dev tool compromises continue to be in the news week after week. Its becoming a question of when, not if. Vendor risk management is more important then ever as threat actors continue to move up the chain.
GitHub just confirmed that 3,800 internal repositories were stolen… through a single VS Code extension. Not a zero-day. Not ransomware. A developer plugin. This is TeamPCP’s FIFTH supply chain compromise in ~3 months, and it highlights a massive blind spot most organizations still ignore: IDE security. Most companies heavily govern: ✅ SaaS apps ✅ Cloud infrastructure ✅ Production environments …but allow developers to install extensions with virtually unrestricted access to: ⚠️ source code ⚠️ credentials ⚠️ cloud tokens ⚠️ local systems The attack surface has officially moved upstream, into the tools used to WRITE the code. If your organization hasn’t started governing developer tooling, extension usage, and workstation trust boundaries, now is the time. The GitHub breach wasn’t the anomaly. It was the warning shot. Read @jacob krells latest research here: na2.hubs.ly/H05FnMT0 #CyberSecurity #SupplyChainSecurity #DevSecOps #VSCode #GitHub #SoftwareSecurity #ThreatIntelligence #Infosec
6
784
I was quoted in Forbes, that's pretty cool! Microsoft does not seem to be having a good 2026 so far security wise, with Exchange being the most recent issue in the crosshairs: ...“attackers study mitigation guidance the same way defenders do,” meaning that such vulnerabilities can be turned into working exploits “much faster than most organizations can validate exposure.”'... forbes.com/sites/daveywinder…
1
1
5
235
Threat actors are security researchers in charge of revenue

ALT Thinking Think GIF

4
246
Soon
4
2
47
2,461
Jacob Krell retweeted
May 8
Uploaded a new video. The time I misidentified a finding on a pentest engagement and how I learned from it. Hope you like it. youtube.com/watch?v=EqYzRrBg…

3
12
567
An MCP server that gives AI assistants deep visibility into Windows internals: processes, ETW kernel traces, event logs, services, drivers, minifilters, and static PE analysis. github.com/0xhackerfren/Proc…
3
51
217
10,864
Mean Time to Exploit is now negative seven days. Yup, you read that right. Mandiant’s M-Trends 2026 report puts estimated mean time to exploit at -7 days, meaning vulnerabilities are now being exploited, on average, a week before patches are released. In 2018, defenders had roughly 63 days. The window did not just shrink. It inverted.
We said it first. Now Mandiant just confirmed it. 👉 Mean Time to Exploit is now negative. Not shortened. Not faster. Negative. Attackers are exploiting vulnerabilities before organizations can even respond. That changes everything. This isn’t about patching faster or scanning more. It’s a timing problem, and most security strategies are already behind. At Suzu Labs, we’re seeing the same thing Jacob Krell just outlined in our latest research: 👉 If you’re reacting, you’re too late 👉 If you’re waiting for alerts, you’ve already missed it 👉 If you’re relying on point-in-time testing, you’re exposed The only way forward? Simulate attacks before attackers do. Continuously validate what actually breaks. Because in a world of negative exploit timelines… you don’t get a head start anymore. 📖 Read the full breakdown: na2.hubs.ly/H05hMNP0 🔗 See how we help teams stay ahead: na2.hubs.ly/H05hNvb0
9
914
Can’t wait to talk about how Agentic AI has affected CTFs and what that means for the industry overall. I Hope to see some of you there!
I am very excited about CYBR.HAK.CON.. We finalized the agenda and speakers, and we have some amazing speakers. @Jhaddix from @arcanuminfosec is our opening keynote, and my BF and @Dallas_Hackers founder @DHAhole is our closing keynote. @TimMedin, @sociosploit, @Larci007, @dkfredde, and the CCN crew (@BarCodeSecurity, @hacker_213, @DistortionCyber), and @hackerfren, are some of the other speakers. Check out the full lineup and get your ticket here cybrhakcon.com! @CybrSecCon @thehackermaker
1
8
243
Ai Manga workflow in Comfy-ui created via MCP github.com/0xhackerfren/Comf…
1
2
348
LMAO I love AI
1
82
I am working on generative AI locally for some projects. Everything else I do is through AI agents, why not Comfy-UI. So I made an MCP to give agents the ability to generate and execute comfy UI workflows for simple things like txt to img to advanced generation pipelines like full shorts. github.com/0xhackerfren/Comf…
5
253
jacobkrell.com/research/tele… Just gonna drop this here. If I'm right in 100 years when we get around to figuring out teleportation, that is gonna be a hell of an intuition flex.

6
214
Jacob Krell retweeted
Apr 25
POV you are coding during the year of 2026.5
73
178
4,167
102,281
lobbex.org/ A sneak peak of some of the stuff I have in the pipeline, this is one of many subsites I plan to tie together with natural language LLM to allow users to quickly parse immense amounts of government data and automatically surface anomalies. Entity extraction and directed relationship graph all the things!
2
125