Cindʎ Xiao 🍉

898 Followers
2.2K Following
3.3K Posts

professional strings(1) operator

rust reverse engineering training -> @decoderloop

personal account, personal views
🏳️‍🌈😎

pronounsshe/her | they/them
post languagesen-CA/zh-CN/fr-CA
websitehttps://cxiao.net
githubhttps://github.com/cxiao
bskyhttps://bsky.app/profile/cxiao.net
I couldn't cover the DHS shutdown hearing because I was at RSAC, but I found this detail about CISA to be pretty striking: "in a single day a few weeks ago[,] six members of a highly technical threat hunting and incident response team submitted their resignation." therecord.media/cisa-acting-...

Interview with Wang Yaqiu about how Chinese human rights groups can get support and funding in the current political environment

This has become a key issue after the Trump administration cut funding to organisations such as Radio Free Asia and USAID

https://www.chinafile.com/reporting-opinion/media/how-be-chinese-and-progressive-2026

#China #HumanRights #USpol

How to Be Chinese and Progressive in 2026

What does it mean to be a Chinese human rights advocate in 2026? Yaqiu Wang watched DOGE cuts gut reporting on political prisoners, refugee assistance networks, and labor rights work abroad, and argued in ChinaFile that the human rights community must urgently diversify away from U.S. government money. ChinaFile’s Jeremy Goldkorn recently chatted with Wang about the future of human rights work in China and how it will be funded, politics in the Chinese diaspora, women’s rights progress in China that is not captured by indicators, and how the internet and AI are challenging our notions of free speech. Wang exemplifies how being a Chinese person of conscience right now means navigating between two forces that both want to define you—and finding agency in refusing both definitions.

ChinaFile

Reposting this article by @ericgeller, about concerns with AI usage undermining trust in threat intel, with alt text in screenshot: https://www.cybersecuritydive.com/news/ai-isacs-threat-intelligence-information-sharing-trust/815499/

The ease of breaking trust here with AI is the really key thing. There's enough noise and FUD in threat intelligence already

#infosec #isac #ThreatIntelligence #cybersecurity

At #RSAC on Monday, representatives of three critical infrastructure information-sharing groups pondered how best to use AI without degrading the quality of their threat intelligence or jeopardizing members' trust. My story: www.cybersecuritydive.com/news/ai-isac...
New artwork, obtained from https://tinney.net/ - the artist died last year but the prints are still available!
Big merger just announced via the phishing world, just tremendous
22 files worth of bot detection, but they still didn't detect mine 💅
Alright I'm speeding up my review of the phishing kits that my project, Phossil, collected. My current estimate is that over the last 5 years I've collected about 1,200 kits. I'm going to review these in two passes - first, just to identify whether they're legit phishing kits (not other malware, webshells, etc.). Later I'll review them for contents - leaked info, trends, targeted companies, etc. I'll be shitposting in this thread with anything funny that I see.
Fun to be part of a #taichi flash mob at the #Yellowknife Snow Castle yesterday.

From last month, a few birds that dropped by our backyard feeder during a snow storm.

#birds