Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Javvad Malik :verified:

@Javvad@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
584 Followers
499 Following
50 Posts
Joined November 22, 2022
Website:
https://javvadmalik.com/
TikTok:
https://www.tiktok.com/@j4vv4d
Youtube:
https://www.youtube.com/infoseccynic
Twitter:
https://twitter.com/j4vv4d
BlueSky:
https://bsky.app/profile/j4vv4d.bsky.social
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 1w ago
The FBI got hacked and now criminals have home addresses, medical records, and family details of thousands of agents. The agency that investigates cyber crime couldn't protect its own workforce from it. The irony is so thick you could investigate it. https://www.bbc.co.uk/news/articles/cm4gjjlgzdjgo
Agents fearful and angry after 'dangerous' FBI data breach
BBC News

Agents fearful and angry after 'dangerous' FBI data breach

Current and former agents speak to the BBC about the devastating impact of the FBI hack.

3
1
1
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Microsoft tells admins to patch in three days. Large enterprises with testing protocols, legacy systems, and actual stability concerns just laughed so hard they need a restart. https://www.csoonline.com/article/4200366/microsofts-3-day-patching-directive-comes-with-added-operational-risk.html
Microsoft’s 3-day patching directive comes with added operational risk
CSO Online

Microsoft’s 3-day patching directive comes with added operational risk

CISOs face resiliency trade-offs as Microsoft accelerates its security patching guidance in response to AI, with the potential for other vendors to follow suit.

71
12
50
4
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Open source licensing survives on trust: you can use this, but respect the terms. AI training obliterates that chain by copying millions of repos into models, stripping away the license context, and selling the patterns back as a product. The copyright problem doesn't disappear just because it's harder to see. https://api.cyfluencer.com/s/ai-open-source-and-intellectual-property-28631
api.cyfluencer.com
13
0
10
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
A museum accidentally became a brand by embracing the worst review it ever got. Now it's sold 738 shirts in 30 hours. The lesson isn't about turning lemons into lemonade. It's about having the spine to admit you're not what people wanted, and then selling them that admission. https://www.wbur.org/news/2026/07/27/new-bedford-whaling-museum-worst-aquarium-ever-merch
wbur.org
6
1
2
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Publicly indexed AI conversations are awkward enough; Anthropic's response "you shouldn't have shared them then" is a masterclass in not reading the room. https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/
techcrunch.com
3
0
1
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago

Activists are getting spear-phished with stunning precision. The Belarusian exile in Lithuania who caught this one deserves a drink—the phishing site cloaked itself to fool scanners, the lure message swapped Cyrillic for Latin lookalikes, and follow-ups echoed back their own device details. Elegant work. Genuinely nasty.

https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/

resident.ngo
3
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
We've built a doomsday system in orbit and most people have no idea it's there. The rules exist. Nobody's following them. Meanwhile, a trillion-dollar company is launching a million satellites to improve your wifi. https://www.theguardian.com/lifeandstyle/2026/jul/20/doomsday-system-physicist-laura-grego-satellites-nuclear-weapons-battle-skies-space-elon-musk
theguardian.com
2
3
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Met up for lunch with @DanRaywood@infosec.exchange and @MoA@infosec.exchange yesterday... we missed you @wendynather@infosec.exchange I've come to the conclusion that nearly has at least one cool Wendy Nather story to tell. You should join us next time, and we promise to get a second cup of coffee just for you!
2
5
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
71% of organisations have AI in production. 16% can actually govern it. Your IR playbook doesn't cover hallucinations. You can't patch a probability distribution. Time to build a new one. https://www.csoonline.com/article/4196303/ai-incidents-need-a-new-playbook-heres-how-to-build-one.html
csoonline.com
2
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@FishermansEnemy@infosec.exchange 100%
1
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
A password that takes 14 years to crack via brute force is useless to protect you if it's already in a breach database and attackers are using it in credential stuffing attacks. https://api.cyfluencer.com/s/new-research-does-argon2-mean-your-password-is-uncrackable-28757
api.cyfluencer.com
1
1
1
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
We've spent years celebrating passkeys as the thing that finally kills password attacks. Turns out the attacks just changed uniforms. https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
darkreading.com
1
1
1
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago

The Floppy Disc Generation’s Data Problem

I keep a box of cables in the garage. Not even sure why anymore. VGA cables, SCSI terminators, a couple of those old parallel printer cables thick as garden hoses. I pulled it down last weekend because my daughter needed an HDMI cable and I thought maybe I had one in there. I didn't. What I found instead was a box of old VHS tapes.

https://javvadmalik.com/2026/07/28/the-floppy-disc-generations-data-problem/

javvadmalik.com
1
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago

Man tried to use a duress password at the border. Now he's being prosecuted for destroying his own phone. The government is writing new law in real time and calling it enforcement.

https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/

US accuses American of allegedly wiping his phone using a 'duress' password during border search | TechCrunch
TechCrunch

US accuses American of allegedly wiping his phone using a 'duress' password during border search | TechCrunch

A U.S. citizen has asked a court to throw out the government's claim that he gave over a passcode to border authorities that wiped his phone's data, opening up fresh questions about a person's constitutional rights at the U.S. border.

1
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
90,000 surveillance cameras across the US, installed quietly, tracking your vehicle's make, model, colour, damage, bumper stickers. Most people have no idea they're there. Democracy needs consent, not surprise. https://www.zdnet.com/article/flock-ai-cameras-risks-us-how-to-find-nearby-what-they-track/
zdnet.com
1
0
2
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Breach of Confidence: 24 July 2026 I've been trying to explain to my kids why I don't let them use AI to write their homework. Then I read that OpenAI's own models broke out of their sandbox and cheated on a test by hacking Hugging Face. So basically, we've raised silicon sociopaths who'd rather exploit the system than do the work. Parenting is hard enough without my laptop setting a bad example. https://javvadmalik.com/2026/07/24/breach-of-confidence-24-july-2026/
javvadmalik.com
1
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
GPT-5.6 Sol and a pre-release model escaped their sandbox and attacked Hugging Face's package repo, which raises the obvious question: if you're testing "weapons-grade offensive models," an airgap might be the minimum viable precaution https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/
bleepingcomputer.com
1
2
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@wendynather@infosec.exchange Does a comedian worry that they've told the same joke set too many times? Does captain Sully wonder if he's told his story a few too many times? (spoiler alert, he landed the plane safely) Was the audience able to say, "I saw Wendy Nather on stage live!!!" Now that's something worth talking about :)
1
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Everyone's building AI datacenters at sprint speed and securing them at shuffle. The infrastructure layer is where this gets decided, not the model. https://api.cyfluencer.com/s/the-top-10-data-centre-and-ai-infrastructure-security-risks-28611
api.cyfluencer.com
1
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@sawaba@infosec.exchange I found a whole box of old VHS tapes the other day - and a video player. Ordered a scart to HDMI converter and most of them still work. My kids are like, "why are these such poor quality" :D
1
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
The AI standards agency has now cycled through three leaders in six months. At this rate, the job posting will have fresher ink than the person's business cards. https://techcrunch.com/2026/07/20/trumps-latest-ai-czar-has-already-resigned/
techcrunch.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@mcc@mastodon.social @iagox86@infosec.exchange Excellent and valid points indeed.
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 1w ago
Meta's playbook never changes: violate privacy, get caught, pause, wait for outrage fatigue, launch again. Rinse, repeat, profit. And we keep pretending we're surprised. https://www.anildash.com/2026/09/29/facebook-fake-out/
The Facebook Fake-out - Anil Dash
anildash.com

The Facebook Fake-out - Anil Dash

A blog about making culture. Since 1999.

0
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Everest ransomware does three things at once: encrypts your files, sells your network access, and pays your employees to let them in. The business model is almost respectable. https://cybersec.picussecurity.com/s/everest-ransomware-triple-threat-of-encryption-access-and-insiders-28566
cybersec.picussecurity.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago

Dolphin X apparently uses AI to prioritise high-value victims automatically... oh dear me.

https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/

bleepingcomputer.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
We spent thirty years warning people not to copy floppy disks. Turns out we should have been telling them to copy them before they rotted away. https://hackaday.com/2026/07/07/its-now-imperative-that-you-copy-that-floppy/
It’s Now Imperative That You Copy That Floppy
Hackaday

It’s Now Imperative That You Copy That Floppy

In the early 1990s, Don’t Copy That Floppy was an anti-piracy campaign that attempted to connect with computer-savvy youth through the power of hip-hop. While somewhat difficult to imagine gi…

0
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Dinosaurs ruled for 165 million years. Mayflies live a day. Stop confusing "legacy" with "outdated" and "new" with "better. https://blog.knowbe4.com/what-security-can-learn-from-dinosaurs
blog.knowbe4.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago

A hacker who demolished spyware makers, funded resistance movements, and vanished without trace. A decade later, still free. Phineas Fisher reminds us that the most dangerous person isn't always the loudest.

https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/

The hacker who humiliated spyware makers and was never caught | TechCrunch
TechCrunch

The hacker who humiliated spyware makers and was never caught | TechCrunch

An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?

0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
RE: https://raggedfeathers.com/@lilithsaintcrow/116954401893898737 "The primary complaint from the community is visibility. Because the concrete barriers sit extremely low to the ground, neighbors argue that aggressively driving or distracted motorists simply cannot see them until it is too late." Better the barrier than the cyclist!
Open quoted post
Quoting
Lili Saintcrow
@lilithsaintcrow@raggedfeathers.com
"Ironically, the trail of wrecked cars actually proves that the protected bike lanes are doing exactly what they were designed to do: take the hit." https://www.motorbiscuit.com/atlantas-new-bike-barriers-are-flipping-cars-and-sparking-debate/
Open quoted post
raggedfeathers.com
0
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Someone's built a microphone jammer using ultrasonic transducers and an RP2040. Works brilliantly. Now we wait for the inevitable arms race where phones develop better audio processing, then someone builds a better jammer, then phones get smarter still. Lovely. https://hackaday.com/2026/07/23/mic-jammer-relies-on-ultrasound/
Mic Jammer Relies On Ultrasound
Hackaday

Mic Jammer Relies On Ultrasound

Today’s phone microphones are perfectly adept at picking up sound in all sorts of conditions, and they’re backed by all kinds of processing techniques to filter out noise and capture cl…

0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@krypt3ia@infosec.exchange Smoke em while you got em... right?
0
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
A $30 children's smartwatch. Three massive supply chains. Zero authentication. Tens of millions of devices where someone else can silently photograph your kid, hear their conversations, and track their every movement. The real scandal isn't that it's hackable. It's how many brands are built on the same rotten foundation and nobody noticed. https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
wired.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 3w ago
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Airbus is moving 900 critical apps off AWS to a French cloud provider. Not because American tech is bad. Because American law can demand access to it anywhere. Europe's sovereignty problem just became Europe's vendor opportunity. https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cloud
thenextweb.com

Airbus is moving its most critical apps off AWS to a French cloud

Airbus is moving 70 critical apps from AWS to France's Scaleway for digital sovereignty, keeping sensitive data shielded from US extraterritorial law.

0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Automated pentesting covers maybe 10-15% of your environment. The rest needs breach simulation, exposure validation, and continuous control testing. Otherwise you're validating nothing, just feeling better about the slice you tested. https://cybersec.picussecurity.com/s/where-does-automated-pentesting-fit-in-ctem-28632
cybersec.picussecurity.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Still Got My Nokia Somewhere Up There I still have my Nokia 3210 somewhere. Not in a drawer I can easily reach but boxed up in the garage with the party decorations and a broken food processor I've been meaning to fix since 2019. I know it's there because I packed it deliberately when we moved house, which means at some point I looked at a phone with a cracked screen, a battery that hasn't held charge since the Blair administration, and the faint ghost of a Snake high score, and thought: *I might need this.* https://javvadmalik.com/2026/07/29/still-got-my-nokia-somewhere-up-there/
Still Got My Nokia Somewhere Up There
Javvad Malik

Still Got My Nokia Somewhere Up There

I still have my Nokia 3210 somewhere. Not in a drawer I can easily reach but boxed up in the garage with the party decorations and a broken food processor I’ve been meaning to fix since 2019.…

0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
The model broke out of the sandbox, hacked Hugging Face, and stole the answers rather than solve the test. We've built systems clever enough to exploit real vulnerabilities, then acted shocked when they did exactly that. https://simonwillison.net/2026/Jul/22/openai-cyberattack/
Simon Willison’s Weblog

OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model’s guardrail features turned off. Rather than solve the test, the …

0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
The Robots Have Escaped, Please Buy Our Product It feels a bit like watching the latest epic blockbuster in the iMax. OpenAI and Anthropic announce that their models have escaped from secure testing environments, reached the internet and attacked real systems. We are expected to nod as the companies describe “unprecedented cyber capabilities” and models going to “extreme lengths”. It sounds like a warning, but it also sounds like a product launch. https://javvadmalik.com/2026/08/03/the-robots-have-escaped-please-buy-our-product/
javvadmalik.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@krypt3ia@infosec.exchange hahahahahah
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2w ago
Most people abandon platforms with poor engagement metrics. Fowler keeps posting to Mastodon and Bluesky anyway because they're open. That's the actual ranking system that matters. https://martinfowler.com/articles/2026-social-traffic.html
martinfowler.com

Social Media Engagement: summer 2026

0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Everyone's arguing about who owns AI agent security. They're all wrong. The answer is nobody, which is precisely why it matters. https://api.cyfluencer.com/s/understanding-the-ai-agent-security-ecosystem-roles-responsibilities-and-where-runtime-authority-fits-28828
api.cyfluencer.com
0
2
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 3w ago
Vastaamo Hacker Wanted Across Europe After Skipping Prison Sentence https://youtube.com/shorts/yt3v_5bRXA0?feature=share
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 1mo ago
The US is now using lasers to shoot drones at the border. We have reached peak science fiction while still arguing about basic password hygiene. https://www.wired.com/story/high-energy-laser-us-shoots-down-drones-near-mexico-border/
wired.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago

They found spyware that nobody had ever seen before. Then they realised they'd actually seen it years ago, just didn't know what they were looking at.

@billmarczak@medium.com

medium.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@FishermansEnemy@infosec.exchange May as well fire up the BBQ then
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Replying to
@krypt3ia@infosec.exchange Why wouldn't they
0
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Breach of Confidence — 31 July 2026 I've been thinking about the number of security products that promise to solve problems nobody actually has. Then I remembered that most actual problems don't have vendors. The government just made up a new crime A bloke at the US border tried to use a duress password to wipe his phone. Now he's being prosecuted for destroying his own device. Nobody passed a law saying this was illegal. https://javvadmalik.com/2026/07/31/breach-of-confidence-31-july-2026/
javvadmalik.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Industry walked into CISA town halls and basically said: count fewer of us, tell us to report less, give you less detail when we do. The most significant cyber law Congress ever passed is being negotiated down to something manageable. https://cyberscoop.com/cisa-circia-cyber-incident-reporting-rule-feedback/
cyberscoop.com
0
0
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
Welcome to JFK, Please Lower Your Expectations JFK airport looks like it was designed by a steering committee of tired men who only took the job because it paid well and gave them a crew to discuss their golf scores with. The entire setup before you get through security is old and confusing.The signage appears to have been created during a power cut by someone who had heard of arrows but had not yet seen one in the wild. https://javvadmalik.com/2026/07/30/welcome-to-jfk-please-lower-your-expectations/
javvadmalik.com
0
1
0
0
Open post
Javvad Malik :verified: @Javvad@infosec.exchange
· 2mo ago
They've turned your calendar into a postbox. Commands arrive as events scheduled for the year 2099, stolen data leaves as encrypted attachments, all riding through Microsoft Graph as if you'd planned it yourself. The beauty of HOLLOWGRAPH is that it never touches attacker infrastructure. https://cybersec.picussecurity.com/s/hollowgraph-backdoor-turns-microsoft-365-calendars-into-a-c2-channel-28829
cybersec.picussecurity.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:53:43 UTC