MR.e

@MR_E@infosec.exchange
98 Followers
607 Following
350 Posts

Hey there! I'm someone who loves trying out different open-source software, creating awesome graphic designs, 3D printing cool stuff, making animations, and writing. My biggest passion is creating top-notch security products. I'm really interested in the nitty-gritty details of technology and privacy issues. I believe that if product management and security teams work together, we can make amazing products that solve big problems. Right now, I'm done with my graduate studies and can't wait to attend more BSides and other events in the near future.

#fedi22 #tech #technology

Pronounsthey/them
Bloghttps://cyberexperience.io/

Today in vulnerability coordination:

Vendor: "That's not a vulnerability, it requires X level of access and nobody should expose that according to our hardening guide"

Me: "Okay, so if I publicly disclose the backdoor password needed to exploit this, you are comfortable with that?"

Vendor: "You can't do that, it would put customers at unnecessary risk."

Hello :)

Loving the latest scamming-the-scammers video from @kitboga, which delves into the sprawling industry of fake trademark and publishing companies. He even features a screenshot at the beginning showing my recent story about a giant scam enterprise operating out of Texas and Pakistan that is also the subject of a synthetic opioids investigation by the feds.

https://www.youtube.com/watch?v=cnFIMot6QuM

https://krebsonsecurity.com/2025/05/pakistani-firm-shipped-fentanyl-analogs-scams-to-us/

In other news, the subjects of that story recently sued for defamation in Pakistan. Their crack attorneys named "Krebson Security" (lol) and included our contact at our speakers bureau. They also are going after Danny De Hek, who recently published an investigation into the same group.

https://www.dehek.com/general/ponzi-scheme-scamalerts/azneem-bilwani-junaid-mansoor-burhan-mirza-abtach-ltd-exposed-karachis-digital-crime-syndicate/

https://www.dehek.com/wp-content/uploads/intersys-bilwani-1/intersys-limited-vs-techjuice-pk-abdul-wasay-danny-de-hek-krebson-security.pdf

I Tried Hiring Scam Law Firms

YouTube

A 600-year-old Chaucer mystery may finally be solved

A medieval sermon packed with 'memes' and simple spelling mistakes could explain a baffling line in 'The Canterbury Tales.'

By Andrew Paul

https://www.popsci.com/science/chaucer-canterbury-tales-mystery-solved/

Cantebury Tales at PG:
https://www.gutenberg.org/ebooks/search/?query=Canterbury+Tales

#Books #OldManuscript

“Move fast and break things.”

The things:

- Human rights
- Our habitat
- Democracy

#BigTech #SiliconValley #ventureCapital https://mastodon.social/@freakonometrics/114860155869573459

I keep seeing this sentiment that desktop Linux has become woke and gay.

Desktop Linux has been woke and gay the whole time. Y’all just for some reason decided you suddenly have a problem with it. We didn’t change, you did. Okay some of us came out of the closet. But we’ve been talking about diversity and inclusion for decades and equity has been the entire focal point of the free software movement since like the 70s! It’s woke gay anarcho-communism and you fucking loved it until 2016

ICE Block “is not uploading your location at all, when you make a report that report isn’t associated with your device in any way, and there are no third party services that it talks to or sends data to,” EFF’s @cooperq told @404mediaco. https://www.404media.co/immigration-raid-tracking-app-ice-block-keeps-your-data-private-researcher-finds/
Immigration Raid Tracking App ‘ICE Block’ Keeps Your Data Private, Researcher Finds

The app, which jumped to the top of an App Store chart, lets users report sightings of ICE officials.

404 Media

This administration is saying that "people should have to prove that they deserve health care" as justification for kicking millions off Medicaid. That's eugenics.

Health care is a human right, and everyone deserves access to health care no matter who they are, what they do, or how they live.

So an alliance of 20+ tow truck operators have come together in #LosAngeles. They’re having people follow ICE vehicles around, actively reporting their locations.

As soon as ICE parks their car ANYWHERE, usually improperly… the tow trucks quickly swoop in, tag the ICE vehicle for illegal parking, and tow their cars away as quickly as possible. LAPD is letting it happen, unchallenged.

They’re estimating over 30+ ICE vehicles being towed in the last week alone.

I love LA.
I really do.

×

New, at KrebsOnSecurity.com: Marko Elez, a 25-year-old employee at Elon Musk's Department of Government Efficiency (DOGE), has been granted access to sensitive databases at the U.S. Social Security Administration, the Treasury and Justice departments, and the Department of Homeland Security. So it should fill all Americans with a deep sense of confidence to learn that Mr. Elez over the weekend inadvertently published a private key that allowed anyone to interact directly with more than four dozen large language models (LLMs) developed by Musk's artificial intelligence company xAI.

https://krebsonsecurity.com/2025/07/doge-denizen-marko-elez-leaked-api-key-for-xai/

From the story:

Philippe Caturegli, “chief hacking officer” at the security consultancy Seralys, said the exposed API key allowed access to at least 52 different LLMs used by xAI. The most recent LLM in the list was called “grok-4-0709” and was created on July 9, 2025.

Grok, the generative AI chatbot developed by xAI and integrated into Twitter/X, relies on these and other LLMs (a query to Grok before publication shows Grok currently uses Grok-3, which was launched in Feburary 2025). Earlier today, xAI announced that the Department of Defense will begin using Grok as part of a contract worth up to $200 million. The contract award came less than a week after Grok began spewing antisemitic rants and invoking Adolf Hitler.

Mr. Elez did not respond to a request for comment. The code repository containing the private xAI key was removed shortly after Caturegli notified Elez via email. However, Caturegli said the exposed API key still works and has not yet been revoked.

@briankrebs spectacular.
@briankrebs i really really hope that we can refer to this sort of bullshit when anybody tries to hock something with "military grade" in its description, or "government security" or any of the other phrases that they think to use in an effort to say 'the government does it so obviously that means its the best and most secure and most efficient and overall the most well thought out possible option'
@Viss @briankrebs I would venture to suggest that government grade security meant a lot more than it does now that these private sector imbeciles are fucking around inside government.
Dare Obasanjo (@carnage4life@mas.to)

Anthropic, Google, OpenAI and xAI have all been granted contracts worth up to $200M by the U.S. Department of Defense to accelerate its adoption of “advanced AI capabilities to address critical national security challenges.” It seems your AI calling itself “MechaHitler” isn’t a dealbreaker for defense contracts. https://www.cnbc.com/2025/07/14/anthropic-google-openai-xai-granted-up-to-200-million-from-dod.html

mas.to
@briankrebs the idiot's feud with Musk may actually be the best chance of these characters being forced back out of government systems given their almost guaranteed conflicts of interest/ loyalty to Elon not Donny
@fencepost @briankrebs Considering that the feud with Musk didn't stop xAI from getting that $200 million contract with DoD, I wouldn't hold my breath.
@kcivey @fencepost @briankrebs maybe the feud is a sham? After all Palpatine did run both sides of the clone war so as to divert eyes and accumulate even more power for himself...
@etenil @kcivey @briankrebs given the egos and issues of the individuals involved? Maybe I'm wrong but I think it's more likely that they'd be challenged by checkers than it is that they're playing 3d chess.

@briankrebs

Dear Doge Moron Marko Eliz,

Dogs sniff each others asses, so have another colleague sniff your code (as well as everything you touch).... It should smell the same. By the way, I have read about your racism. Disco your sessions, return your devices, data, and property, and go away. Play with tinker toys.

@briankrebs Incident Response is woke

"the exposed API key still works and has not yet been revoked"

@briankrebs
"It's ok. The NPC don't know what a private key does." -BigBalls
@briankrebs
Ten guesses how Caturegli knew exactly which and how many systems the key worked on.
He stopped counting at 52....
@briankrebs America is going out with quite the whimper at the hands of the least intelligent people it has to offer. I'd almost feel proud if it were a bunch of geniuses born and raised here that were carrying out the country's destruction. Instead, it's Brick from the movie "Anchorman" with a bad spray tan, and a South African immigrant that lived here illegally in the 90s, and has now hired some random douchebros off the side of the road to dismantle Social Security, Medicare, Medicaid, the Department of Education... basically everything being tracked on https://www.project2025.observer/
Project 2025 Tracker

Track the progress on Project 2025

@Avitus

"...hired some random douchebros off the side of the road..." 🙂 you do have a way with words, concepts too! Thanks for the black laughter.

@briankrebs

@briankrebs This. Is. Sensational.

@briankrebs

Is he the one they call, sorry, who calls himself, "Big Balls"?
🙂

@Su_G @briankrebs No. This is "tiny balls" Elez.

@wcbdata @briankrebs

Oh, thanks for clarifying, my mistake! 😂

@briankrebs who ever would have guessed a #DOGE bro wouldn't have the best security hygiene?

https://cryptadamus.substack.com/p/the-crypto-grifters-of-doge

The Crypto Grifters Of DOGE

How many crypto grifters does it take to screw up the machinery of state?

The Cryptocalypse Chronicles

@briankrebs

Could we make it easier? Maybe adverserial hackers would enjoy a refreshment & shoulder massage as they're led comfortably into every aspect of government infrastructure?

@briankrebs the banal, incompetent face of evil, eh?
@briankrebs We shall now refer to him as Dorko E-loser.
@briankrebs 52 different LLMs , eh? I wonder what they're different in.

@fst @briankrebs have you ever heaed abaout AlphaGo zero. tl;dr: it learned playing Go by playing against itself.

let me introduce xAi, where it learns facts and history by talking to itself

@briankrebs This!

“If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors,” Caturegli told KrebsOnSecurity.

@briankrebs Fun thing about chatbots is how naive they are. If you just ask politely enough and it will tell you info that you shouldn't have access to.
@briankrebs this myth of the private sector geniuses needs to end. Musk should surely be evidence enough that it’s often just smoke and mirrors, chutzpah and paid PR. Ok. And gullible fans and investors.

@briankrebs
> However, Caturegli said the exposed API key still works and has not yet been revoked.

> While still at Treasury, Elez resigned after The Wall Street Journal linked him to social media posts that advocated racism and eugenics. When Vice President J.D. Vance lobbied for Elez to be rehired, President Trump agreed and Musk reinstated him.

If you're a racist, you're stupid by definition.

(Does not rule our being harmful and dangerous.)

@briankrebs

What could possibly go wrong?

@briankrebs

Does Musk deliberately employ total fucking idiots or is this a side-effect of other selected for employee attributes? 🤦‍♂️🙄

@briankrebs Hi. Do you block VPN connections? I get an 403 error on your site.
@briankrebs If there was ever a time to insist on paper bank statement, it is now.
@briankrebs Alt text - man learning how to smile
@briankrebs Why is absolutely everything so very very stupid.

@briankrebs

It’s nice to know that I would be overlords not only enjoy hiring and competent white people to cabinet positions and government largely because they’re over government and they intend to destroy it and replace it with their own ideas.. (ahem), but they’re chosen foot soldiers also live in a world of arrogance, and with it comes indifference and incompetence.

@briankrebs Perfect opportunity for some nation state actor to do some rubber hose breaking of cryptography to gain access to such systems. And the body can be kept alive duct taped to a chair, fed intravenously, and continuously interrogated for information until the KGB finds a suitable building where he will fall out a window.
@briankrebs I say, jail for life for Marko. But very early release if jail for life for Elon can come out of this.