Bongoknight

@bongoknight@ioc.exchange
226 Followers
1,040 Following
92 Posts

OSINT, CTI, adict to graphs and python scripts. ISO 3103 compliant.

Love to learn, learning is the beginning towards becoming a better human.

Not an English native, hope I don't sound too harsh.

He/him - 30 - Cyber Threat Analyst

Mottohttps://www.youtube.com/watch?v=8yyAgk9der4
GitHubhttps://github.com/BongoKnight
Profil picturehttps://ko-fi.com/winomas

For about a month, I have been mentoring an intern. It's disappointing to see AI being used for everything:

- Writing an advisory on an ongoing threat? AI. Everything is rephrased, and as a reader, it's impossible to understand the point of the advisory.
- Not understanding computer science concepts? AI. It's poorly explained and inaccurate.
- Adding a new feature in code? AI. The task was easy and should have taken five minutes by copying and adjusting another part of the code. I've seen three versions of the same code, all with a strange use of the library it relies on and nonsensical comments.

I'm only 30 and I already feel like a boomer, even though I need to work for that many more years. Is learning new things and trying to understand them so boring?

Not to mention OpenClaw, Moltbook, and other recent insanities. What a pleasure to see the planet burn for that.

#AiIsShit #slop

This study—from Anthropic, no less—is rather damning of the entire generative AI project. In code creation, the realm where it should shine, not only were the time gains marginal, but developers understood their code far, far less. And they didn't even have more fun doing the work!

But to me the most concerning part of this study is the fact that Anthropic could not get the control (non-AI) group to comply. Up to 35% of the "control" in the initial studies used AI tools despite instructions not to. What kind of behavior does that sound like?

UPDATE: See below for important counterpoints as to the validity of the study.

https://arxiv.org/html/2601.20245v2#S5

Holy shit. TIL that Janet Jackson is the only Grammy-winning artist with a CVE.

CVE-2022-38392 indicates that playing Rhythm Nation near certain hard drives will cause a crash, because the song contains a resonate frequency with a 5400RPM spinning disk of a certain diameter and construction.

Neat.

#music #infosec

Cursor lies about vibe-coding a web browser with AI

Here’s an awesome tweet from Michael Truell, CEO of Anysphere, who make vibe code editor Cursor: [Twitter, archive] We built a browser with GPT-5.2 in Cursor. It ran uninterrupted for one week. It&…

Pivot to AI
Dear cybersecurity companies,
When your sources contain OpenAI references I totally lost trust in what you are saying. I wonder if your article have been proofread or just AI-generated and posted directly.
Regards.

The WSJ reports that Google has moved to seize dozens of domains belonging to IPIDEA, a Chinese residential proxy service and the largest by far with ~10M proxies for rent. Google has also taken steps to remove hundreds of apps affiliated with the company from Android devices

https://www.wsj.com/tech/google-aims-knockout-blow-at-chinese-company-linked-to-massive-cyber-weapon-3c3fdc40?st=tzboX3

Earlier this month, we broke the news about how the world's biggest botnet -- Kimwolf -- grew very quickly to well more than 2 million devices by exploiting a weakness in IPIDEA that allowed them to probe the local networks of proxy endpoints, and infect unofficial Android devices like TV boxes.

https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/

IPIDEA's proxy service has become synonymous with these Android TV boxes, which generally come backdoored at purchase. According to Synthient, the proxy tracking startup that figured out how Kimwolf was spreading, the majority of traffic being funneled through IPIDEA proxies is for account takeover activity and ad fraud.

Here's the announcement from Google: https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network

TL;DR A botnet of 10 millions of devices is taken down.

If you never heard of BadBox, Kimwolf or IPIdea, you may want to read Brian Krebs recent articles or this one from WSJ.

https://www.wsj.com/tech/google-aims-knockout-blow-at-chinese-company-linked-to-massive-cyber-weapon-3c3fdc40?st=4ZVFX2&reflink=desktopwebshare_permalink

Else this is pretty cool!

https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network?hl=en

#ThreatIntel #cybersecurity #proxy

AhnLab published an analysis of a campaign observed by the CertGraveyard in December. Great to see more details.

An actor using signer "CÔNG TY TNHH XB FLOW TECHNOLOGIES" leveraged a range of RMM tools and regularly contested abuse complaints.

Blogpost in thread
1/2

Principe d'incertitude managériale de Heisenberg : un.e manager peut savoir en permanence l'état du travail d'un.e employé.e, ou alors l'employé.e peut avancer dans son travail.
La nature même du reporting permanent change la productivité de manière irréversible.