Thomas C

@thomasc@infosec.exchange
14 Followers
144 Following
100 Posts
Active Directory Architect, PKI engineer and Wireshark geek for a Fortune 20 company in my former life. I like Raspberry Pi's, Docker and playing Factorio among many, many other things.

Drop what you are doing and read this incredible story from Wired, if you can. After that, come back here.

https://www.wired.com/story/edward-coristine-tesla-sexy-path-networks-doge/

It mentions that a 19 y/o man who's assisting Musk's team and who has access to sensitive government systems is Edward Coristine. Wired said Coristine, who apparently goes by the nickname "Big Balls," runs a number of companies, including one called Tesla.Sexy LLC

"Tesla.Sexy controls dozens of web domains, including at least two Russian-registered domains. One of those domains, which is still active, offers a service called Helfie, which is an AI bot for Discord servers targeting the Russian market.While the operation of a Russian website would not violate US sanctions preventing Americans doing business with Russian companies, it could potentially be a factor in a security clearance review."

The really interesting part for me is Coristine's work history at a company called Path Networks, which Wired describes generously as a company "known for hiring reformed black-hat hackers."

"At Path Network, Coristine worked as a systems engineer from April to June of 2022, according to his now-deleted LinkedIn resume. Path has at times listed as employees Eric Taylor, also known as Cosmo the God, a well-known former cybercriminal and member of the hacker group UGNazis, as well as Matthew Flannery, an Australian convicted hacker whom police allege was a member of the hacker group LulzSec. It’s unclear whether Coristine worked at Path concurrently with those hackers, and WIRED found no evidence that either Coristine or other Path employees engaged in illegal activity while at the company."

The founder of Path is a young man named Marshal Webb. I wrote about Webb back in 2016, in a story about a DDoS defense company he co-founded called BackConnect LLC. Working with Doug Madory, we determined that BackConnect had a long history of hijacking Internet address space that it didn't own.

https://krebsonsecurity.com/2016/09/ddos-mitigation-firm-has-history-of-hijacks/

Incidentally, less than 24 hours after that story ran, my site KrebsOnSecurity.com was hit with the biggest DDoS attack the Internet had ever seen at the time. That sustained attack kept my site offline for nearly 4 days.

https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/

Here's the real story behind why Coristine only worked at Path for a few months. He was fired after Webb accused him of making it known that one of Path's employees was Curtis Gervais, a serial swatter from Canada who was convicted of perpetrating dozens of swattings and bomb threats -- including at least two attempts on our home in 2014. [BTW the aforementioned Eric Taylor was convicted of a separate (successful) swatting against our home in 2013.

https://krebsonsecurity.com/2017/09/canadian-man-gets-9-months-detention-for-serial-swattings-bomb-threats/

https://krebsonsecurity.com/2017/02/men-who-sent-swat-team-heroin-to-my-home-sentenced/

In the screenshot here, we can see Webb replying to a message from Gervais stating that "Edward has been terminated for leaking internal information to the competitors."

Wired cited experts saying it's unlikely Coristine could have passed a security clearance needed to view the sensitive government information he now has access to.

Want to learn more about Path? Check out the website https://pathtruths.com/

DOGE Teen Owns ‘Tesla.Sexy LLC’ and Worked at Startup That Has Hired Convicted Hackers

Experts question whether Edward Coristine, a DOGE staffer who has gone by “Big Balls” online, would pass the background check typically required for access to sensitive US government systems.

WIRED

BREAKING: UnitedHealth has confirmed the ransomware attack and data breach on its Change Healthcare subsidiary in February 2024 now affects around 190 million people — almost double the previous estimate.

https://techcrunch.com/2025/01/24/unitedhealth-confirms-190-million-americans-affected-by-change-healthcare-data-breach/

UnitedHealth confirms 190 million Americans affected by Change Healthcare data breach | TechCrunch

The number of individuals confirmed to be affected by the data breach is almost double the company's previous estimate.

TechCrunch
Best snow truck name ever.

Pretty cool but also terrifying..

Voyager 1 is now about one light day from Earth! And that took about half a century

While the nearest star besides the sun is about 4 light years away from us

What I’m trying to say is.. space is terrifyingly big

Just because you know how to use a password manager, it doesn’t mean that most people ever have a hope of understanding even the best version of password management. Passkeys are a break from that world and a concept that lots more people can understand: you sign in to websites and apps the same way you unlock your phone. And in the process, you’ll be safe from the forms of phishing that plague us all today and from servers leaking passwords.

How people think AI is going to kill them: terminator robots.

How AI is actually going to kill them: by destroying their habitat and drinking all their water.

How embarrassingly ironic that we let a minuscule minority of #sociopaths destroy the habitability of our #planet in their quest to profit from machines that think better than we do -- when the most important moral, ethical, and subjective questions can't be answered by machines because they mimic the sociopaths that built them.

#Morality #Ethics #Subjectivity #ClimateChange #ClimateCrisis #AI #uspol #QuantumComputing

Here's something that happened yesterday:

My wife photoshopped a person's head onto another photo to make a funny image. Many of us have done something similar.

But here's the thing I noticed: she was laughing and giggling the WHOLE time she was making it. It was 20 minutes of pure fun.

Could she have made a better image in a fraction of the time using generative AI? Of course.

But often the journey is the reward.

And all of the folks who are promoting this technology just don't get that.

Oh look, Starlink is continuing to screw up the sky in every way possible.

"Second-Generation Starlink Satellites Leak 30 Times More Radio Interference, Threatening Astronomical Observations"

https://www.astron.nl/starlink-satellites/

It's going to be "hilarious" when Starlink messes up the radio sky so badly that radio astronomers can't even use quasars to calibrate GPS anymore. There are so many consequences from all these stupid, cheaply built, disposable satellites. https://www.universetoday.com/105160/navigating-the-cosmos-by-quasar/

Second-Generation Starlink Satellites Leak 30 Times More Radio Interference, Threatening Astronomical Observations | ASTRON

Observations with the LOFAR (Low Frequency Array) radio telescope last year showed that first generation Starlink satellites emit unintended radio waves that can hinder astronomical observations.

ASTRON
If it takes 10,000 hours to achieve expertise in a skill, you can cut that down to 20,000 hours with the help of AI.
×

Drop what you are doing and read this incredible story from Wired, if you can. After that, come back here.

https://www.wired.com/story/edward-coristine-tesla-sexy-path-networks-doge/

It mentions that a 19 y/o man who's assisting Musk's team and who has access to sensitive government systems is Edward Coristine. Wired said Coristine, who apparently goes by the nickname "Big Balls," runs a number of companies, including one called Tesla.Sexy LLC

"Tesla.Sexy controls dozens of web domains, including at least two Russian-registered domains. One of those domains, which is still active, offers a service called Helfie, which is an AI bot for Discord servers targeting the Russian market.While the operation of a Russian website would not violate US sanctions preventing Americans doing business with Russian companies, it could potentially be a factor in a security clearance review."

The really interesting part for me is Coristine's work history at a company called Path Networks, which Wired describes generously as a company "known for hiring reformed black-hat hackers."

"At Path Network, Coristine worked as a systems engineer from April to June of 2022, according to his now-deleted LinkedIn resume. Path has at times listed as employees Eric Taylor, also known as Cosmo the God, a well-known former cybercriminal and member of the hacker group UGNazis, as well as Matthew Flannery, an Australian convicted hacker whom police allege was a member of the hacker group LulzSec. It’s unclear whether Coristine worked at Path concurrently with those hackers, and WIRED found no evidence that either Coristine or other Path employees engaged in illegal activity while at the company."

The founder of Path is a young man named Marshal Webb. I wrote about Webb back in 2016, in a story about a DDoS defense company he co-founded called BackConnect LLC. Working with Doug Madory, we determined that BackConnect had a long history of hijacking Internet address space that it didn't own.

https://krebsonsecurity.com/2016/09/ddos-mitigation-firm-has-history-of-hijacks/

Incidentally, less than 24 hours after that story ran, my site KrebsOnSecurity.com was hit with the biggest DDoS attack the Internet had ever seen at the time. That sustained attack kept my site offline for nearly 4 days.

https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/

Here's the real story behind why Coristine only worked at Path for a few months. He was fired after Webb accused him of making it known that one of Path's employees was Curtis Gervais, a serial swatter from Canada who was convicted of perpetrating dozens of swattings and bomb threats -- including at least two attempts on our home in 2014. [BTW the aforementioned Eric Taylor was convicted of a separate (successful) swatting against our home in 2013.

https://krebsonsecurity.com/2017/09/canadian-man-gets-9-months-detention-for-serial-swattings-bomb-threats/

https://krebsonsecurity.com/2017/02/men-who-sent-swat-team-heroin-to-my-home-sentenced/

In the screenshot here, we can see Webb replying to a message from Gervais stating that "Edward has been terminated for leaking internal information to the competitors."

Wired cited experts saying it's unlikely Coristine could have passed a security clearance needed to view the sensitive government information he now has access to.

Want to learn more about Path? Check out the website https://pathtruths.com/

Oh, and the other founder of the DDoS protection company BackConnect is a guy named Tucker Preston, who in 2020 pleaded guilty to paying a DDoS-for-hire service to launch attacks against others.

https://krebsonsecurity.com/2020/01/ddos-mitigation-firm-founder-admits-to-ddos/

DDoS Mitigation Firm Founder Admits to DDoS – Krebs on Security

@briankrebs something something door to door vacuum salesman busting in and throwing dirt on your rug
@briankrebs a #techbro doing crime? Now #trump will say nothing wrong, just building customer demand
@briankrebs this is like a story straight out of Darknet Diaries. Where is Jack Rhysyder?

I almost forgot this detail about about the other Path employee, Eric Taylor: He was involved in a website called Exposed[.]su, which hard doxed a ton of celebrities and people working in top government jobs, including the FBI director, the First Lady, and others.

Taylor was part of a crew that would alert TMZ when they were about to dox and then swat a celebrity, so that cameras could be on the scene when the police arrived in force.

https://krebsonsecurity.com/2013/03/credit-reports-sold-for-cheap-in-the-underweb/

https://krebsonsecurity.com/2013/04/swatting-incidents-tied-to-id-theft-sites/

Credit Reports Sold for Cheap in the Underweb – Krebs on Security

@briankrebs that tracks. I was flipping through channels a few weeks ago and paused on TMZ for a few minutes. They were ecstatic about Trump getting elected.

@briankrebs So they are criminals.

Shocking. Let me get my big boy pants.

You should probably let the Felon-in-Chief know, you know the only person who possibly could do something to fix that.

Trump45 would probably not pass the background checks for the security clearance for the job of the POTUS.

Trump47 almost certainly does not pass.

So I think they stopped the practice in this administration.

@briankrebs But imagine the benefits of the "no background, we take everyone" policy.

People can list their FSB training when they apply to a US intelligence agency, that's a great career boost. Before they had to do all the complicated agent stuff to hide where they were from, where they learned stuff, potentially be placed years early in foreign countries for infiltration. Now they can have their Russian references just translated.

That's DOGE style efficiency in government.

@yacc143 @briankrebs Security protocols are optional. Wild. So all the talk about the invasion at the border was just for the rubes that can't read

@BLTpizza
But of course. Yes politicians are not always completely honest.

But compared to the flood of misinformation the #GOP has been dishing out in the past decade , there is a qualitative difference. So "every politician lies" does not correctly describes the situation.

That's like comparing jay walking with being a drug kingpin. Sure both is criminal. Yet not really the same thing.
@briankrebs

@briankrebs What is the bracket around the period for?
@anselmschueler it's to defang the domain (make it not easily clickable)

@briankrebs
I see. My client doesn't make bare domains clickable, I think.

Just wait though for some stupid application that uses some LLM to generate clickable links to topics…

@briankrebs Looking forward to comprehensive reporting on this. Great work Brian.
@briankrebs .su domain is a red flag on its own
@briankrebs wtf, that's scummier than scummy, that's concentrated municipal waste.
@vandorb12 @briankrebs Scummy as the scum scrapped from the bottom of the wastewater settling pond.

@briankrebs

So a bunch of people which have absolutely no business being anywhere near critical national infrastructure 🫤🤦‍♂️

@briankrebs so this whole op is just musk trying to impress his gamer bros with his rented hacker cred. cool, cool.
Does Elon Musk Cheat at Video Games? an Investigation. - the Washington Post

Link to: https://www.washingtonpost.com/technology/2025/01/29/elon-musk-video-games-diablo-path-exile/?pwapi_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJyZWFzb24iOiJnaWZ0IiwibmJmIjoxNzM4MTI2ODAwLCJpc3MiOiJzdWJzY3JpcHRpb25zIiwiZXhwIjoxNzM5NTA5MTk5LCJpYXQiOjE3MzgxMjY4MDAsImp0aSI6ImE5NzNiNzFmLWZhY2ItNDM1OC04MzVjLTgxMDllYzRlOTRmZiIsInVybCI6Imh0dHBzOi8vd3d3Lndhc2hpbmd0b25wb3N0LmNvbS90ZWNobm9sb2d5LzIwMjUvMDEvMjkvZWxvbi1tdXNrLXZpZGVvLWdhbWVzLWRpYWJsby1wYXRoLWV4aWxlLyJ9.6bhaQaNRUCuNxmd60eJAcRSeK6MxHzLlHhzT1E7HbZ4

Daring Fireball

@briankrebs

Musk hiring people with dubious past... Why is this a surprise to anyone, considering everything that's happened in the last couple of weeks ?

How the tactics Musk brought to Washington backfired at Twitter

When Elon Musk bought Twitter in 2022, he laid off thousands of employees, stopped paying rent and auctioned off coffee makers and office chairs in hopes of a big turnaround. Now the world’s richest man has brought the same slash-and-burn strategy to the federal government. Some people who experienced Musk’s takeover at Twitter have a warning: Expect chaos, cuts driven by ideology as much as by cost concerns, intimidation and plenty of lawsuits. Since assuming leadership of the Department of Government Efficiency, Musk has consolidated control over large swaths of the government, sidelined career officials, gained access to sensitive databases and invited a constitutional clash over the limits of presidential authority.

AP News
@briankrebs Holy 💩! Undoubtedly he's totally reformed now and only working for the good of the country 🤔 🤯 🙁

@briankrebs holy crap. I wish I read this before I called my congressperson.

Brian, can you please consider posting this on your site? I want something official to point to when contacting my reps.

⚯ Michel de Cryptadamus ⚯ (@cryptadamist@universeodon.com)

@gcluley@mastodon.green one of the other DOGE bros (Gautier Cole Killian) came from #JumpTrading. I suspect (but have not confirmed) he came from the recently disbanded (woulde explain why he's not there any more) #JumpCrypto subsidiary which was hit with $123 million in fines for financial crimes, some of them related to the Terra/Luna collapse. #ColeKillian #DOGE #elonmusk #uspol #TerraLuna

Universeodon Social Media
@briankrebs sorry to say, but it is too late to expect any rules to be followed.
@tha @briankrebs So what do you suggest?
@starluna @tha @briankrebs they have to go outside sometime
@joe @starluna @tha @briankrebs Republicans also *really* need Democrats' votes to pass the budget, and to (snort) raise the debt ceiling. This may be the last, best leverage Democrats have. https://talkingpointsmemo.com/edblog/wheres-the-real-power-nexus-how-does-the-opposition-get-to-it
Where’s the Real Power Nexus? How Does the Opposition Get To It?

I’ve made this point a few times in passing in other posts....

TPM - Talking Points Memo
@briankrebs The terrorists are literally "in the cockpit" here
@briankrebs interesting, thanks for the share. Also odd wording in that screenshot. "Liquidated"??? Never heard that term for firing someone
@briankrebs I don't know. I think maybe the flag flying outside the state department upside down yesterday was someone putting it up there for exactly the reason someone at the state department would.

@briankrebs I think I triggered eyes on me. I sent out this memo attached to two emails:

https://america2.news/content/files/2025/02/Musk-NRx-Memo-February-5-2025.pdf

google additionally attached this video to those emails:

https://www.youtube.com/watch?v=ZluMysK2B1E&t=1s

I've been freaking out for the last couple hours now. Learned this right after posting this comment.

I do have mental illness though.

@briankrebs #AdolfMusk and the #MuskYouth modelled on the youth organization of the Nazi party in Germany control Americans. #HitlerYouth was the sole official boys youth organization in Germany, and it was a paramilitary organization. In 1945, the #HitlerYouth and its subordinate units were outlawed by the allied council along with other Nazi party organizations. It was labelled an unconstitutional organization. Sound familiar USA?
@briankrebs this is the worst Hackers sequel I've ever seen
@briankrebs Worth encouraging people to spend $12 for a subscription
https://www.wired.com/v2/offers/wir307
WIRED - The Latest in Technology, Science, Culture and Business | WIRED

Power up with unlimited access to WIRED.| Best-in-class reporting that's too important to ignore - plus gear reviews, podcasts, and more | Plus, get a FREE WIRED Tote!

@briankrebs i can't believe in how many layers of banana republic we are into already, yet the recursion keeps going. It is disheartening, but we have all to be the adults in the room and silently move things back towards sanity again.

@dsp @briankrebs

Oh, we're not gonna be silent about it at all.

@briankrebs thank you for your service 

@briankrebs

"Wired cited experts saying it's unlikely Coristine could have passed a security clearance"

The only question on the current security clearance form seems to me to be:

Do you swear absolute fealty until death to the new Christian America Empire? Y/n.

And in small script: You hereby donate your body after or during death, or at any other designated moment, to Brainlink or any other Musk medical experiment. Also you submit unreservedly to any judgments of the Dept. of Inquisition.

@briankrebs It's getting so much worse every day oof..
@stux @briankrebs I feel like, in hindsight, I was invited to exactly the right Mastodon instance cc @jerry
@briankrebs I paid the $12 for both digital and print. Thanks for sharing
@briankrebs so can we just call DOGE Disciples of Greedy Elon or something.
@briankrebs Sorry, as great the job is that you are doing, but in the context that #Trump & Co are currently shredding the Constitution and are basically trying out how far they can go with establishing a "Führerstaat" (leader state) without the rule of law, where #Trump can simply change the "constitution" via an EO (the Nazis called these "Führererlass" https://de.wikipedia.org/wiki/F%C3%BChrererlass ) makes it not THAT exciting.
Führererlass – Wikipedia

@briankrebs I regret that I have but one repost to give.
@briankrebs has anyone started looking into the vote tabulation systems? If they have hackers on the payroll, why wouldn't they have started prior to this endeavor?
@briankrebs - feel free to use my image if you want to.
@briankrebs pathtruths.com has a TORRENTMAGNET.TXT file that contains a torrent magnet link for all the site content. I think it's a good idea to seed this so that stuff like this cannot be memory-holed.
@briankrebs I can view your site, but I'm getting 403s on your articles.
@briankrebs Nice so yah that social security info probably got sold to scammers.