As a former developer, Iโm primarily focused on offensive Application Security nowadays. Currently building some things in C++ and Qt as I enjoy desktop development as a break from the state of the modern web.
He/him
As a former developer, Iโm primarily focused on offensive Application Security nowadays. Currently building some things in C++ and Qt as I enjoy desktop development as a break from the state of the modern web.
He/him
RE: https://mathstodon.xyz/@johncarlosbaez/116400087406782310
More of this please!
Community colleges around Detroit offer construction/skilled trades associates' degrees.
If you're sorta healthy and don't have felonies, you can get a tuition+books+some living expenses scholarship for the first year. It's not all construction classes: they make sure you can balance a checkbook, read the instructions on med bottles, and understand how credit card interest works.
The second year of study comes with a living wage paid internship.
The jobs are there, and can't be outsourced overseas.
TL;DR North Korean-linked threat actors pulled off a $285M heist against crypto exchange Drift using IN-PERSON social engineering. They deployed proxies to global conferences to befriend Drift contributors, spent 6 months building a relationship as customers, and even deposited $1M of their own funds to prove they were legitimate.
โจ๏ธโจ๏ธโจ๏ธ
Here is what happened:
๐น Starting in the fall of 2025, a group of individuals (later linked to North Korea) started attending international crypto conferences, with a goal in mind. These proxies were technically fluent, had fully constructed professional identities, with employment histories, and looked nothing like a North Korean.
๐น This group, posing as employees of a quantitative trading firm, first ๐๐ฉ๐ฉ๐ซ๐จ๐๐๐ก๐๐ ๐ฌ๐ฉ๐๐๐ข๐๐ข๐ ๐๐ซ๐ข๐๐ญ ๐๐จ๐ง๐ญ๐ซ๐ข๐๐ฎ๐ญ๐จ๐ซ๐ฌ ๐๐ญ ๐ ๐ฆ๐๐ฃ๐จ๐ซ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ ๐๐จ๐ง๐๐๐ซ๐๐ง๐๐ ๐๐๐๐-๐ญ๐จ-๐๐๐๐. They wanted to discuss integrating with the platform.
๐น After the initial discussions, they moved their conversations to Telegram, where they spent months discussing legitimate trading strategies.
๐น "What a pleasant coincidence running into you again!"
Over the next 6 months, the attackers deliberately sought out these same contributors at multiple global conferences. They wanted to continue building trust and credibility.
๐น Dec. 2025 - Jan. 2026: To checkmate the game, the group onboarded an Ecosystem Vault on Drift. They engaged with the Drift contributors in working sessions, asked relevant & informed questions and eventually, they ๐๐๐ฉ๐จ๐ฌ๐ข๐ญ๐๐ ๐จ๐ฏ๐๐ซ $1 ๐ฆ๐ข๐ฅ๐ฅ๐ข๐จ๐ง ๐จ๐ ๐ญ๐ก๐๐ข๐ซ ๐จ๐ฐ๐ง ๐๐ฎ๐ง๐๐ฌ ๐ข๐ง๐ญ๐จ ๐ญ๐ก๐ ๐ฉ๐ซ๐จ๐ญ๐จ๐๐จ๐ฅ.
๐น (excerpt from Drift's Incident Update): "Integration conversations continued through February & March 2026. (...) By this point, the relationship was nearly half a year old. ๐๐ก๐๐ฌ๐ ๐ฐ๐๐ซ๐ ๐ง๐จ๐ญ ๐ฌ๐ญ๐ซ๐๐ง๐ ๐๐ซ๐ฌ; ๐ญ๐ก๐๐ฒ ๐ฐ๐๐ซ๐ ๐ฉ๐๐จ๐ฉ๐ฅ๐ ๐๐ซ๐ข๐๐ญ ๐๐จ๐ง๐ญ๐ซ๐ข๐๐ฎ๐ญ๐จ๐ซ๐ฌ ๐ก๐๐ ๐ฐ๐จ๐ซ๐ค๐๐ ๐ฐ๐ข๐ญ๐ก ๐๐ง๐ ๐ฆ๐๐ญ ๐ข๐ง ๐ฉ๐๐ซ๐ฌ๐จ๐ง. (...) Links were shared for projects, tools, and apps they claimed to be building"
๐น ๐ ๐ซ๐๐ฅ๐๐ญ๐ข๐จ๐ง๐ฌ๐ก๐ข๐ฉ ๐ก๐๐ ๐๐๐๐ง ๐๐ฌ๐ญ๐๐๐ฅ๐ข๐ฌ๐ก๐๐, ๐๐จ๐ง๐ญ๐ซ๐ข๐๐ฎ๐ญ๐จ๐ซ๐ฌ ๐๐ข๐๐ง'๐ญ ๐ญ๐ก๐ข๐ง๐ค ๐ญ๐ฐ๐ข๐๐ ๐ฐ๐ก๐๐ง ๐๐จ๐ฅ๐ฅ๐๐๐จ๐ซ๐๐ญ๐ข๐ง๐ ๐๐ข๐ ๐ข๐ญ๐๐ฅ๐ฅ๐ฒ. Drift presumes there may have been multiple technical attack vectors: One contributor may have been compromised after cloning a code repository shared by the group as part of efforts to deploy a frontend for their vault. A second contributor was persuaded into downloading a wallet product via Apple's TestFlight to beta test the app.
On April 1, 2026, as the $285 million was drained, the attackers scrubbed their Telegram chats and vanished.
(Full Incident Background Update from Drift is on X.)
\o/ VLC in space
"Why are there almost no Republican scientists? Itโs not a mystery. GOP political orthodoxy includes positions that are at odds with the scientific consensus on multiple issues, ranging from the validity of the theory of evolution, to the reality of climate change, to the efficacy and safety of vaccines. In each case the scientific consensus is solidly grounded in evidence."
~ Paul Krugman
#Trump #Repubicans #science #research #facts #truth
/1
https://paulkrugman.substack.com/p/maga-is-winning-its-war-against-us
I am currently looking for Senior Software Engineers positions in Vienna. I am most proficient in Rust and C++, but I have worked with other languages as well (Python, Go, Typescript) and I have done some DevOps/Infra work too (Kubernetes, Docker, Terraform). If you stumble into something that may be a match, don't hesitate to reach
There is a fresh thing going around about LinkedIn scanning extensions installed in Chrome/Chromium:
https://browsergate.eu/
The website claims "LinkedIn is Illegally Searching Your Computer", and implies the purpose is to find "religious beliefs, political opinions, disabilities".
tl;dr:
- yes, LinkedIn is scanning through a list of 6k+ extensions on Chrome;
- yes, this is bad;
- but the website is disingenuous in making unnecessarily overblown claims.
๐งต
Microsoft is running one of the largest corporate espionage operations in modern history. Every time any of LinkedInโs one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedInโs servers and to third-party companies including an American-Israeli cybersecurity firm. The user is never asked. Never told. LinkedInโs privacy policy does not mention it. Because LinkedIn knows each userโs real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world.