881 Followers
141 Following
565 Posts

cyber(punk) threat intel, guided by "shape, not deter." #FUZZYSNUGGLYDUCK-in-chief. founder, Centre for Unilateral Analysis. neophyte teacher, teaching neophytes.

deep thoughts: counterintelligence, cyber operations, Russia, Iran.
real talk: Dune, Robert Ritter, Beff Horn, drilangleton.

I see kanly today in everything.

opinions are my own.

Twitterhttps://twitter.com/WylieNewmark
Bloghttps://horkos.medium.com/
I’m so sorryhttps://bsky.app/profile/wylienewmark.bsky.social
straight up, I would trade every single moment of professional accomplishment and triumph I’ve experienced for one more day together with my family where everyone was healthy and we were all having a nice time.
sanderling inn, duck, north carolina, 1985
prigozhin is in his scamp arc. he’s mischief-maxxing. he’s hijinks-pilled. he’s shifted into rascal mode.
watching prigozhin talk shit about shoigu and the russian military:
proud to announce that yevgeny prigozhin has personally offered to give me $86 (USD) and a bottle of jewel of russia if i act as his champion in a slap duel with defense minister shoigu, streaming live this SUNDAY SUNDAY SUNDAY from a dirty alley behind a club in kitay-gorod at 0430 local time

Two myths that I often see repeated:

1. If a malware sample has 0 detections on VirusTotal it means it's undetectable by AVs.
2. If a sample has X+ detections on VirusTotal it means it's a malware.

Lots of well deserved remembrances of Ellsberg’s heroism today. I’ll just post my favorite passage from his incredible memoir, Secrets. He’s telling Henry Kissinger (who as many have noted is somehow still alive) what access to truly secret information can do to a person’s mind.

if i was a FVEY CI officer, my first thought on a RU-based company publishing on FSB ops wouldn’t be “look at the analytic freedom!” — it would be “why is the FSB comfortable with the world knowing about this now? did they figure out we were onto it in some way?”

keep in mind that foreign intelligence entities plan for a percentage of their ops to get detected/monitored/burned by either other governments or private industry. with that built into the cost model, laundering self-disclosure via controllable third-party can amount to a viable offensive counterintelligence tactic.

i routinely say “no” to the authoritarian government i live under that arrests my employees and kidnaps my family members using off-duty police officers. they respect my independence.
it may surprise some people to learn that CISA’s Joint Ransomware Task Force (JRTF; a federal interagency body established by Congress to unify and strengthen efforts against the ongoing threat of ransomware) and IST’s Ransomware Task Force (RTF; a public-private group run by a think tank to work on non-binding policy “deep thoughts” about ransomware) are not — in fact — the same thing.