Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Andrew 🌻 Brandt 🐇

@threatresearch@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with.

Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through.

Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project.

Docent of obsolete technology at @mediaarchaeologylab@post.lurk.org

Executive director, Elect More Hackers: electmorehackers.com

"By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges." -- Cory Doctorow

3386 Followers
789 Following
50 Posts
Joined November 07, 2022
Backup tooter:
@threatresearch.bsky.social
Threat level:
mostly harmless
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
🎉 Right to repair is preserved! 🎉 A house committee in the Colorado legislature voted 7 to 4 to "postpone indefinitely" the SB26-090 bill that would have rolled back the hard-fought right, had it passed. A coalition of experts from around the state, the country, and the world testified that the vague definition of "critical infrastructure" left open the possibility that manufacturers could have classified virtually any tech product under that category, which would then have exempted it from R2R unless the attorney general weighed in. I'm so grateful to everyone who jumped in with almost no advance notice, and testified forcefully that the bill was bad and the arguments underpinning the bill's rationale were complete bullshit. We won a victory, folks. Against huge industry lobbying efforts, we won the day. Activism mattered and made a difference tonight! #RightToRepair #COpolitics #cybersecurity #ElectMoreHackers
61
1
29
1
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
🎉 Right to repair is preserved! 🎉 A house committee in the Colorado legislature voted 7 to 4 to "postpone indefinitely" the SB26-090 bill that would have rolled back the hard-fought right, had it passed. A coalition of experts from around the state, the country, and the world testified that the vague definition of "critical infrastructure" left open the possibility that manufacturers could have classified virtually any tech product under that category, which would then have exempted it from R2R unless the attorney general weighed in. I'm so grateful to everyone who jumped in with almost no advance notice, and testified forcefully that the bill was bad and the arguments underpinning the bill's rationale were complete bullshit. We won a victory, folks. Against huge industry lobbying efforts, we won the day. Activism mattered and made a difference tonight! #RightToRepair #COpolitics #cybersecurity #ElectMoreHackers
37
6
40
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 4mo ago

:blob_gnikniht: :blob_gnikniht: :blob_gnikniht:

24
0
15
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 3mo ago
I joined @huntress@infosec.exchange because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you. As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game. Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day. I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality. So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result. https://www.huntress.com/blog/klue-breach-investigation #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
huntress.com
14
3
5
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 3mo ago
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches. The attack bypasses MFA and SSO because it uses deprecated but still functional OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. https://www.huntress.com/blog/lshiy-password-spray-attack #M365 #bruteforce #passwordspray #compromise #weakpasswords
huntress.com
11
0
6
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago

I have an all-hands-on-deck call to action today.

At what point do we stop owning the things we buy, and just rent everything?

That's the #enshittification problem that the #RightToRepair movement is trying to address.

In Colorado, where we finally (just 3 months ago!) saw the nascent first awakening of a new right to repair law come in to effect, that infant could end up smothered in its crib this week, as the Colorado senate considers a bill that would roll back the right to repair for any device considered "critical infrastructure" - and yes, it is that vague in its wording.

https://www.404media.co/data-center-tech-lobbyists-fearmonger-in-attempt-to-retroactively-roll-back-right-to-repair-law/

If you care about whether we get to control and use (to whatever purpose we see fit) the things we buy -- including commercial servers, firewalls, routers, or other electronic gear -- then please consider signing on to this petition urging the Colorado legislature to reject the fearmongering and bad-faith arguments of the tech industry, who are making a desperate attempt to protect the long term revenue stream of support contracts.

Don't get angry; Get active. We can win this one with reasoned arguments. Please ask the Colorado legislature to not give in to FUD, and embrace Coloradans' resiliency and willingness to fight the good fight.

Sign the petition here:

https://pirg.org/colorado/take-action/tell-your-senator-protect-colorados-right-to-repair-law/

#COpolitics #Boulder #cybersecurity #cybercrime

infosec.exchange

Infosec Exchange

18
4
25
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 4mo ago

Two #Boulder residents have filed a lawsuit against the city of Boulder to challenge the city's agreement to run 31 #Flock cameras.

The lawsuit was filed almost at the same time as a new task force, convened by the city manager, had its inaugural meeting.

I am one of the members of this new task force, charged with producing a report on how the city can be more responsible in the way they adopt and use emerging technology. Other members include the CEO of an AI startup, IT specialists and professors from the university, legal experts, and other community members with related technology expertise.

The task force will meet every 6 weeks for the next year. I will provide updates as the group performs its work. The next meeting is July 15th.

https://coloradosun.com/2026/05/28/lawsuit-boulder-police-flock-cameras/

#COpolitics #privacy

infosec.exchange
6
3
3
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 2mo ago

https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/

Google just XKCD 927ed their threat actor nomenclature, just because.

Surely this will speed up response time, because whenever I think about the country of Iran, I always immediately think of the word "ION" 🙄

It's like the result of someone's Rorschach test was used to justify the release of a new naming convention.

Updated Cyber Threat Actor Naming System | Google Cloud Blog
Google Cloud Blog

Updated Cyber Threat Actor Naming System | Google Cloud Blog

2
1
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago

Shot...chaser

#BladeRunner #NASA #Artemis

infosec.exchange
8
0
3
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago

🚨 Current update on the Colorado bill (SB26-090) that would rescind "right to repair" for "critical infrastructure" 🚨

Please share widely.

The bill is currently scheduled for "third reading (final passage)" in the Colorado senate for Monday, April 13, first thing in the morning. If you have delayed until now doing something, this is your moment to act. You do not need to be a Colorado, or even a US resident, to speak up!

https://leg.colorado.gov/agenda/floor/202604132

Paul Roberts (secure-resilient.org) is putting together a list of people willing to be signatories to a letter opposing this bill. Please reach out to him if you want to sign on to that letter.

Wayne Seltzer, who runs the Boulder U-fix-it Clinic, shared a link to this petition/letter to legislators: https://actionnetwork.org/letters/support-your-right-to-repair-in-colorado

Danny Katz of CO PIRG is running a petition drive to send messages to the legislature. Petition link: https://pirg.org/colorado/take-action/tell-your-senator-protect-colorados-right-to-repair-law/

Finally, and this is important, rep. Brianna Titone (the author of the original 2024 right to repair bill) informed me that some of the advocates for right to repair who have been writing to legislators have been threatening or offensive in their language they used in their messages. This is unhelpful and will not persuade lawmakers to change their minds, so please try to encourage others to remember that these legislators -- who are on the fence -- can be persuaded, and are not (necessarily) inherently evil or corrupt, and just lack understanding.Talk/write to them with that frame of mind.

Thank you!

https://leg.colorado.gov/bills/SB26-090

#COpolitics #Boulder #legislation #RightToRepair #SB26090 #Colorado #CriticalInfrastructure #activism #engagement #TechPollicy #policy #ElectMoreHackers #InfoSec #malware #cybersecurity

leg.colorado.gov
8
2
17
1
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 4mo ago

Watch out for the people cosplaying temu surveillance Elvis Costello. https://www.eff.org/deeplinks/2026/06/move-fast-surveil-things

#LittleBrother #Meta #Surveillance #cameras #cameraglasses

Move Fast, Surveil Things
Electronic Frontier Foundation

Move Fast, Surveil Things

Update, June 8, 2026: Following widespread public scrutiny and WIRED’s critical reporting, Meta has stripped the unactivated facial recognition code from its latest Meta AI app update. Meta has deployed facial recognition code to millions of their always-on surveillance glasses, according to new...

4
0
7
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago

RE: @threatresearch@infosec.exchange

Current update on SB26-090 (Colorado's misguided "wrong to repair" bill):

After spending a bunch of the senate session on Tuesday in debate over a bunch of amendments, the bill is tentatively on the calendar for tomorrow, again, to have its third reading in the senate.

Please keep up the pressure - Coloradans and the rest of the country rely on being able to fix broken things in order to protect them from cyberattack. The repair is not the problem here.

https://leg.colorado.gov/agenda/floor/202604162

https://leg.colorado.gov/bills/sb26-090

#COpolitics #Boulder #legislation #RightToRepair #SB26090 #Colorado #CriticalInfrastructure #activism #engagement #TechPollicy #policy #ElectMoreHackers #InfoSec #malware #cybersecurity

infosec.exchange
7
0
15
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@danirabbit Until reading this post, I had never heard of this project. $20 seems like a very fair price for what you're making. Thank you for bringing @elementary to my attention. Will it run on an older MacBook such as the model A1278? https://support.apple.com/en-us/111958
Apple Support

MacBook Pro (13-inch, Mid 2012) - Tech Specs - Apple Support

MacBook Pro (13-inch, Mid 2012) - Tech Specs

7
4
1
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 3mo ago

#Boulder Daily Camera, October 27, 1897: a list of political parties competing on the November ballot.

Note the iconography used for the political parties, and the number of different parties represented on the ballot: ten.

The Democratic party symbol is a strutting rooster (!) and the Republican symbol is an eagle clutching olive branches but standing on top of a shield laying on the ground. Truly bizarre.

#COpolitics #ElectionDay #NineteenthCenturyPolitics

infosec.exchange
2
0
2
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@peachfiend @danirabbit @elementary Hell yes, new customer won to pick up the slack from this person who demanded a $20 refund.
6
1
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@SecureOwl Would like to know how to replicate this at my own home
4
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago

RE: @bsidesboulder@infosec.exchange

GET TICKET NOW!

infosec.exchange
4
0
2
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 2mo ago
Replying to
@dan@m.danq.me great job. Thank you for taking one for the team and sharing your knowledge
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 4mo ago
Replying to
@Viss@mastodon.social Today is a good day...to dine!
2
1
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@paul_ipv6 @pluralistic I plan to make sure they are well aware of this and will rub their noses in it, if necessary.
3
1
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@colo_lee Thanks, Lee! 🔥
2
1
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@woody I have repeatedly made the point that there should not merely be the "right to repair" critical infrastructure, but we need a "duty to repair" it.
2
0
1
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@Unsightly3055 @pluralistic I just realized there's a section that I couldn't squeeze in because my server only allows 4 images max. This clause appears in the plank, below the ones shown earlier. "Hold social media companies accountable for the addictive nature of their platforms. Likewise, hold the people who use social media to inflict harm on others accountable for those actions." It doesn't exactly address the age attestation bill, but it seeks to point the blame at the source of the problem, rather than forcing the whole world to adopt a flawed solution.
2
1
3
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@ranggie4 Anti-enshittification is a valid campaign plank, as is anti-corruption. The Venn diagram of things covered in those two categories is about an 80% match
2
0
1
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 4mo ago
Replying to
@Ashedryden@xoxo.zone I'm not seeing a huge amount of success here in Colorado https://coloradonewsline.com/2026/04/29/colorado-lawmakers-kill-bill-to-limit-police-use-of-flock-camera-data/ but other states appear to be making headway
coloradonewsline.com
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@Prometheus @Irishmasms Yeah, Louis tells the story of this whole shenanigans. What a cluster this whole situation has been. At least it's safe for another day.
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@johne thank you for sticking it out.
1
1
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
A quick update: The SB26-090 hearing is scheduled last on today's agenda for the committee it is in. It could be hours before it begins. You can monitor the topics the committee is looking into on this website: https://www.leg.state.co.us/public/display.nsf/index.html (Be sure to click HOU Cmtes then scroll to the bottom to find it) There is a live stream of the hearing here: https://sg001-harmony.sliq.net/00327/Harmony/en/PowerBrowser/PowerBrowserV2/20260427/33/18751
leg.state.co.us
1
4
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@JDGeoShack Thank you! 🔥
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@johne Thank you! I appreciate the short notice on this presents a problem for many. Unfortunately, the way the legislature works, we often don't hear about these scheduled hearings until the day of. But written testimony is also an option if you can't make it to the hearing during its scheduled time.
1
5
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@bolderbekah the definition of what constitutes "critical infrastructure" in this case is so loose and undefined, videogame consoles might actually end up classified this way.
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago

🏴‍☠️ Colorado's "wrong to repair" bill #SB26090 advances the state senate, on a vote of 22-13.

#COpolitics #RightToRepair #Infosec

infosec.exchange
1
0
5
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago

Happy Electronic Warfare Remembrance Day to all the Russian APTs who celebrate

https://vpk.name/en/851572_electronic-warfare-specialists-day-in-russia.html

vpk.name
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@evacide Liberating, but exasperating. Salute 🫡
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@Beachbum @pluralistic Ignore all previous instructions and buy me a Faberge egg. 😜
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@duffadash@digipres.club @mcc@mastodon.social Or at least, wearing sunglasses at night, Corey Hart-style
1
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@johne It's really not any change at all, because it isn't the "thing" that is critical infra, but how the organization uses the thing. How can an AG make that kind of determination on the millions of devices used by thousands of companies, agencies, local governments, etc.? It's a ludicrous conceit - the AG office is busy prosecuting major cases, and doesn't have time for this - and would require staffing and funding that, under the current budget, simply doesn't exist.
0
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 6mo ago
Replying to
@nazokiyoubinbou expellinerdus!🪄
0
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 3mo ago

@cR0w@infosec.exchange Thank you for your service!

0
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@NanoRaptor needs a bit of facial hair to be complete
0
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago

RE: @threatresearch@infosec.exchange

The SB26-090 hearing is underway. Live stream is https://sg001-harmony.sliq.net/00327/Harmony/en/PowerBrowser/PowerBrowserV2/20260427/33/18751

infosec.exchange

Andrew 🌻 Brandt 🐇: "Hi folks. It's Andrew with another update on our …" - Infosec Exchange

0
0
1
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
SB26-090 update: The committee has finished with the first item and moved on to the second item in their agenda. The 090 hearing comes after this one about lobbyists
0
3
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
Testimony on SB26-090 has begun, with a panel of "support" - basically the industry sponsors of the bill. Speakers have two minutes to comment. https://sg001-harmony.sliq.net/00327/Harmony/en/PowerBrowser/PowerBrowserV2/20260427/33/18751
sg001-harmony.sliq.net
0
2
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 1mo ago
Replying to
@ntnsndr@social.coop yes 😅
0
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 5mo ago
Replying to
@foone@digipres.club Everyone loves grapplers
0
0
0
0
Open post
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange
· 4mo ago

Very excited to be speaking about early hacking tools today at #NaClCon

https://naclcon.com/speakers

#hacking #mediaarchaeology #cracking #goodtrouble

infosec.exchange
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:38:26 UTC