Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jake Williams

@malwarejake@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Breaker of software, investigator of incidents | GSE #150 | Faculty at IANS Research | Stuff: jake at malwarejake dot com | He/him

0 Followers
0 Following
35 Posts
Joined December 16, 2022
Open post
Jake Williams @malwarejake@infosec.exchange
· 6mo ago
Boosted by @hypebot@goingdark.social
ICE was checking IDs at the Atlanta airport today. The.guy said "your DL photo is super light, so facial recognition might not work." I snapped back "that's so you know not to illegally deport me." His buddy said "we can find a reason" and NOTHING could be more on-brand for an encounter with ICE.
337
9
224
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Anthropic having Fable be export controlled is a self-inflicted wound. If you spend a bunch of time telling people how dangerous your technology is, don't be surprised when some of them agree with you.
59
0
30
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago

When discussing AI safety, it's critical to understand:

  1. Models can only act on the world when we give them a path with which to do so
  2. Everyone understands prompts aren't guardrails
  3. Anyone discussing a real-world safety issue must admit it flowed from a lack of their own technical controls
24
3
19
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Apple fumbled the implementation of its USB controller on A12 and A13 devices so it's possible to compromise the boot loader. Exploit code has been published. This can't be patched with a software update. https://ps.tc/pages/blog-usbliter8.html
ps.tc

Paradigm Shift - Unavailable

This page is taking an unexpected detour...

38
2
35
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 20mo ago

Only those wanting to scam consumers are threatened by the existence of the CFPB.

I said what I said.

426
4
267
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

That Iranian Navy ship we torpedoed had no ammunition on board because that was a requirement to participate in the MILAN 2026 exercise (organized by the Indian Navy).

The US Navy knew this because IT ALSO PARTICIPATED IN THE EXERCISE. What a national embarrassment.
https://newrepublic.com/post/207429/us-attack-iran-naval-ship

The Most Chilling Detail in the U.S. Attack on an Iranian Naval Ship
The New Republic

The Most Chilling Detail in the U.S. Attack on an Iranian Naval Ship

The Iranian warship was taking part in an international exercise with many other countries—including the United States.

53
0
72
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

RE: https://infosec.exchange/@malwarejake/116149477150967871

It's confirmed that Khamenei is dead. Intentionally killing a country's sitting leader, especially the religious leader in a theocracy, is NOT how you go about regime change.

This will NOT end well.
https://www.reuters.com/world/iran-crisis-live-explosions-tehran-israel-announces-strike-2026-02-28/

infosec.exchange

Jake Williams: "Given reports that Israeli intelligence assesses …" - Infosec Exchange

46
8
43
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 6mo ago

Looks like doggo is getting ready to take flight :)

39
0
9
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Words to live by...
10
2
3
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 5mo ago
I laughed so hard at this that I snorted more than once. https://www.youtube.com/watch?v=WAUnmQt2Z7Y

AI CEO vs Engineer (2026).

18
1
8
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 6mo ago

When life hands you lemons, squeeze lemon juice in the eyes of your enemies.

22
0
14
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

The administration is getting US service members killed over the fucking Epstein files. I am livid. I hope to live to see Hegseth and every other member of the administration enabling this hanging on a wall.

This is so triggering for my PTSD. Fuck man. This is not okay. I am not okay.

29
5
13
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

I couldn't get rid of this pop-out without submitting an email, so I did the only responsible thing I could think of...

27
1
6
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 5mo ago

Most clients struggling with AI governance are struggling because they haven't fully defined their enterprise data governance requirements.

You can't code "people will use their judgment" into coherent AI governance, as much as you might want to.

18
0
7
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

I may be in full mid life crisis mode. But on the plus side, I just got this glorious hat.

27
1
2
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
Who's got two thumbs and is going to SAINTCON again this year? This freaking guy, that's who. See you degenerates there!
4
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

Cymbalta is a wonder drug.

I am still in pain and still have PTSD symptoms, but I am legit the happiest I've been in as long as I can remember.

23
2
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

Not a week passes that I don't find more evidence that Copilot was a rush job from Microsoft and has serious limitations for enterprises.
https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about

Microsoft Purview DLP for Microsoft 365 Copilot and Cowork
learn.microsoft.com

Microsoft Purview DLP for Microsoft 365 Copilot and Cowork

Learn how Microsoft Purview DLP protects Microsoft 365 Copilot, Copilot Chat, and Cowork by blocking sensitive prompts, web search, and labeled content.

14
0
6
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

Iran is a theocracy. It is likely to stay a theocracy. There is no viable replacement for Khamenei that is friendly to the US/Israel.

Killing Khamenei takes us from bad to likely worse. The Iranian people don't want this and that's critical for regime change.
https://www.reuters.com/world/middle-east/prior-iran-attacks-cia-assessed-khamenei-would-be-replaced-by-hardline-irgc-2026-02-28/

reuters.com
14
1
6
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 6mo ago

It is frankly infuriating that our alcoholic SECDEF couldn't plan to adequately support our service members and families evacuated due to a war of choice and left that work to community groups instead.
https://www.npr.org/2026/04/03/nx-s1-5770491/evacuation-bahrain-norfolk-troops

Evacuation of U.S. troops from Mideast base sends community groups scrambling to help
NPR

Evacuation of U.S. troops from Mideast base sends community groups scrambling to help

Troops and their families have been pushed back to the United States after their bases in the Middle East were threatened by Iranian counterattacks. Community groups are scrambling to react.

7
0
3
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

Given reports that Israeli intelligence assesses Khamenei was killed, I assess with high (extreme) confidence that cyber was used to:
1. Confirm his location and direct the attacks.
2. Using collection on Iranian gov officials (e.g., email) reactions of the strike.

9
1
3
1
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

I've already had questions from a FinServ client about Iran replicating Operation Ababil (2012-2013 DDoS targeting FS orgs).

My assessment is that is not likely to happen. Iran has limited capacity for cyberattacks and given the current situation, they have MUCH higher priorities for cyberattacks. Realistically, they are FAR more likely to use their limited cyber resources for intelligence collection instead of destructive attacks that would have limited impacts. They are likely unable to perform another Shamoon-style attack either, since that requires significant prepositioning. In any case, it's unlikely they have enough prepositioning in US orgs (especially FS) to create that type of impact.

One other note, is that FS orgs are in a much different position today to deal with any DDoS attacks that Iranian-linked threat actors might attempt. Operation Ababil was a wakeup call for the whole industry and they've definitely become more resilient to DDoS in the last decade+ since.

9
3
2
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago
Surround yourself with good people. Pay it forward. Hug your friends every chance you get. Purge toxic people from your life.
9
0
8
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
In our latest episode of Breach Please, me and @Secitup@infosec.exchange about Anthropic having "issues" with a their agents, BMC vulns, and SentinelOne *definitely* fscking it up at Hacker Jeopardy. In a world where you can be anything, don't be a SentinelOne... youtu.be/BKvGTTTB1vs
0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 7mo ago

@krypt3ia@infosec.exchange Yes - that and IRGC QF.

0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
Spent all day writing a report for a client from raw notes. Somehow the damn thing is 96 pages. Lots of tables, but not a screenshot in sight (just not that kind of report). If I never type again, it will be too soon...
0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Replying to
@val@infosec.exchange This is the way.
0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Again seeing that Copilot is anything but a productivity engine. I would seriously be embarrassed if I shipped a product this bad.
0
1
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
In this episode of Breach Please, me and @Secitup@infosec.exchange talk about AI agents social engineering victims. We pose ethical questions about duty to investigate. Then, we discuss how Grokipedia can serve as a cautionary tale in AI workflows silently breaking down. https://youtu.be/4poq__R0MCg
0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Join me at 1pm ET to talk about practical workflows for detection and response. Attacks are changing and we need to change our tactics too. https://dr-resources.darkreading.com/free/w_rapj26/
dr-resources.darkreading.com
0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
"Our disaster recovery environment is so complex that you can't possibly understand it without this 100++ page read ahead document" is not nearly the flex some people seem to think. If you can't impart that knowledge to another industry expert, the problem is you.
0
1
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a threat actor? Me and @Secitup@infosec.exchange discuss this and SO MUCH more as we dissect the (excellent) Hugging Face post mortem. https://youtu.be/uK-SGExDGOo

Is Your API Secure? Lessons from the Hugging Face Incident

0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
You know what "fearing for public safety" means? Fuck all, that's what it means. This is murder without the pretense of "they tried to run the ICE officer down with their vehicle."
0
1
1
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 3mo ago
Business financing *starting at* 1% monthly? That's approaching loan shark numbers...
0
0
0
0
Open post
Jake Williams @malwarejake@infosec.exchange
· 2mo ago
Thanks to some recent high profile agent containment failures, I've made the difficult decision to release something I've been working on a bit early. I say difficult because I had a couple CFPs in for conferences this fall and was in licensing discussions, but this is better for the community. The CUSTODY framework helps standardize nomenclature around agentic risk and provides pillars for containment. Instead of needing to write pages about your agent for me to understand what's what, you can say "L4/Operational/R2" and I can immediately know the types of risk your agent creates. The framework is vendor agnostic and uses a machine-readable schema suitable for operating (and containing) at agentic speed. https://www.custody-framework.org/ https://github.com/malwarejake/CUSTODY-framework
custody-framework.org
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 01:16:03 UTC