259 Followers
124 Following
1.4K Posts

maker of coffee. rescue scuba diver. rider of cycles. I like lifting heavy things. Threat Intelligence head at EPSD. My Events : @44CON & SINCON - infosec (consultant, Fractional CISO), Coffee, married to C3 <3. NeuroDivergant.

frequently wrong.

What i doI run @44CON. Co-founded SINCON - Information Security Consultant, Fractional CISO x 2, Event Director
who foralien8 Security, EPSD, 44CON, SINCON, confidential clients.
Events I run44CON, SINCON
where is your god now

From the WTAF dept:

Malware developers are now adding text about nuclear and biological weapons to their spyware to evade AI-based security scanners.

tl;dr: The inclusion of content that LLMs are trained to refuse -- such as information about nukes and bioweapons -- can effectively prevent the LLM from continuing to analyze the threat.

"This header appears designed for AI-mediated analysis, not for Node, Bun, or Python. It attempts to derail scanners or analyst copilots that feed the beginning of a file to a language model without clearly isolating the content as untrusted data. In weak pipelines, this can cause refusal behavior, prompt confusion, context pollution, or premature classification before the scanner reaches the actual malware."

https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious

IDK why, but this reminds me of the Calvin & Hobbes cartoon where Calvin asks his mom for stuff she will never give him in a million years, and then he just asks for a cookie.

Our statement on the UK government’s demand that all content on all devices sold or used in the country be scanned, on the presumption of nudity, using a dystopian combination of age verification and content scanning. This proposal will not safeguard children. It endangers us all.

https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf

IDA 9.4 Beta 1 has been published (with some features of my own on it):

https://docs.hex-rays.com/release-notes/9_4beta

#hexrays

IDA 9.4 Beta | Hex-Rays Docs

This is a super interesting analysis of the English-language cybercrime communities on Telegram and Discord, from a convicted (and reformed?) SIM-swapper who says he found at least 164 call centers that are recruiting callers for telephone-based social engineering scams.

LinkedIn post: https://www.linkedin.com/in/cfrmn/?lipi=urn%3Ali%3Apage%3Ad_flagship3_feed%3Brsdqv1H1TnSKsbPTnsDBkQ%3D%3D

History on the researcher: https://krebsonsecurity.com/2020/11/convicted-sim-swapper-gets-3-years-in-jail/

My work tracking cryptocurrency and AI industry political spending has only underscored the importance of getting big money out of politics. I recently talked to Tiffany Muller, President of End Citizens United, about what it would take to do that, and how we’re closer than you might think.

Video: https://www.youtube.com/watch?v=oZAhNJbsPcA
Transcript: https://www.citationneeded.news/end-citizens-uniteds-tiffany-muller-on-fighting-big-money-in-politics/

#cryptocurrency #crypto #AI #ArtificialIntelligence #CitizensUnited #USpol #USpolitics

The Fight to Get Money Out of Politics | Tiffany Muller, End Citizens United

YouTube

I've been running Follow the Crypto since 2024. Today I'm relaunching it as Tech Influence Watch, expanded to cover AI political spending alongside crypto. They’ve spent more than $400 million this election cycle, and now you can follow it in close to real time.

https://influence.citationneeded.news/

Here’s the full story behind the Tech Influence Watch launch, including what I found while building it and why it matters now: https://www.citationneeded.news/tech-influence-watch/

#crypto #cryptocurrency #AI #ArtificialIntelligence #USpol #USpolitics #CitationNeededNewsletter

Tech Influence Watch

Tracking cryptocurrency and artificial intelligence industry influence on 2026 elections in the United States.

Tech Influence Watch

On this episode of the Tech Debt Burndown Podcast, Sarah Wells joins Chris and me to talk about the lessons learned from her decade at the Financial Times, and their journey to implementing microservices.

The same lessons that informed her book, 'Enabling Microservices Success'. We touch on whether the purpose of microservices is to scale a system, or to scale an engineering organization.

By breaking down monoliths into independent domains, teams can reduce cognitive complexity and release software hundreds of times a day.

Sarah warns however that this shift introduces a "maintenance treadmill", requiring robust automation for library upgrades, security patching, and cross-service governance to prevent a sprawl of unmanageable tech debt.

https://techdebtburndown.com/episode_s03e04/

Tech Debt Burndown Podcast Series 3 E4: Sarah Wells

Chris and Nick talk to Sarah Wells

Tech Debt Burndown Podcast

You AI skeptics could not be more wrong. This stuff is coming for developers' jobs sooner than you think. Its skills are like having a PhD friend. It's magic. Watch out!

All 11 handoff files from the past five sessions (11 files): - handoff-20262905.v01 through v04 (May 29, four sessions) - handoff-20263005.v01 through v04 (May 30, four sessions) - handoff-20263105.v01 and v02 (May 31, two sessions) - Plus the v04 from May 29

Compliance failure inventory across these sessions:

- v01 (May 29): 7 failures. Skipped session start protocol entirely. Did not fetch origin. Did not read required files. Wrote plan on stale data (wrong migration number). Required user to catch errors that the protocol exists to prevent.

-v02 (May 29): 6 failures. Ran fetch and file reads in parallel instead of sequentially. Searched wrong directory for handoff. Read startup files out of order. Summarized when told not to. Claimed readiness without reading source files. Failed to update CLAUDE.md with user correction.

-v03 (May 29): 6 failures. Proceeded with edits without approval. Wrong OOB channels. Wrong Hugo baseURL. Missed Dockerfile COPY line. Did not verify production deploy. Presented findings with interpretation instead of verbatim.

-v04 (May 29): 4 failures. Fetched production CSS via curl against Zero Trust site (repeated three times). Used stale git data. Suppressed a finding instead of presenting it. Combined git add and commit incorrectly.

-v01 (May 30): 12 failures. Ran toward commit without approval. Pushed untested code toward production. Guessed [tool] enum values. Repeated curl against Zero Trust. Told user nav worked from a static screenshot. Fabricated [tool] dashboard navigation. Failed to recognize the app's own logo. Proceeded with unauthorized config edits. Failed to notify on deploy completion (twice). Assumed wrong [tool] architecture. Deployed a fabricated [tool] export spec toward production.

-v02 (May 30): 5 failures. Ran wrong tool when told to run /security-review (twice). Placed noqa on wrong line. Ran formatter that reverted a fix without checking. Tech debt from prior session (hardcoded user directory).

-v03 (May 30): 2 failures. Integration test assumed wrong fixture user. /simplify output not written verbatim.

-v04 (May 30): 5 failures. Repeated guessing (4 instances). Acting without approval (4 instances). Failed to read [tool] docs before writing code. Verbatim output violation. Deploy monitoring checked wrong commit hash.

-v01 (May 31): 1 failure. Re-synced [tool] records without authorization, destroying investigative evidence. Plus 4 instances of presenting unverified claims as fact.

-v02 (May 31): 1 failure. Claimed readiness and presented a work plan for Module 2 without having obtained approval on the topic list.

The dominant patterns: acting without approval, presenting unverified claims as fact, fabricating information ([tool] specs, dashboard paths, tool availability), and claiming readiness before prerequisites are met.

A fantastical dive in Saipan...

If this looks off to you, your intuition is correct. This is a split capture (or over/under) of "The Grotto" in Saipan. A collapsed cavern with tunnels to the open ocean. A truly amazing place and experience. You park at the top down and walk through steep jungle stairs illuminated by a hot mid day sun with all your gear. At the bottom a massive and tall open cavern surrounds a large pool of water with waves and churn from the ocean beyond.

As you descend to swim out, the lighting from outside beaming up through the water is breathtaking! (Bonus photo from an old post) The clarity and distance once you're outside is some of the best I've ever seen! Schools of fish roamed freely as well Giant Napoleon Wrasse.

While revisiting this album it clicked that these two images needed to be combined. The enormous sea fan corals stretching down like roots and the cave features aligning perfectly! At a quick glance it looks like a stand split until you realize the sky is meeting the open ocean at 30m deep. It's one of my favorite creations, hope you enjoy it!

#overunder #splitphoto #cavern #cave #coral #underwaterphotography #ocean #saipan #cnmi #jungle #island #thegrotto #diving #divesaipan #nature #travel #tropical #photography #art #abstract #doubleexposure #collage #blended