tzomb1e
banner
tzomb1e.bsky.social
tzomb1e
@tzomb1e.bsky.social
Senior Incident Response Analyst, wannabe threat hunter, DFIR, and ethical hacker. Anything said or shared is my opinion.
Reposted by tzomb1e
Scathing, but all too obviously accurate, take on the AWS outage by @quinnypig.com.

You're engaging in professional malpractice if you don't share this with your stakeholders. Corey may be an engineer, but he communicates about the issues in an accessible manner.
www.theregister.com/2025/10/20/a...
Amazon brain drain finally caught up with AWS
column: When your best engineers log off for good, don’t be surprised when the cloud forgets how DNS works
www.theregister.com
October 22, 2025 at 5:47 AM
Reposted by tzomb1e
Fuck ICE.

If that offends you, we're not friends.
NEW: Des Moines schools superintendent Ian Roberts was told by his immigration attorney in March that his immigration case had "reached a successful resolution" and been closed.

On Friday he was arrested by ICE.
October 1, 2025 at 6:22 AM
Reposted by tzomb1e
TIL, there is a PlayStation 4 emulator for Windows, Linux and macOS written in C++. Currently, the emulator can successfully run games like Bloodborne, Dark Souls Remastered, Red Dead Redemption and many other games github.com/shadps4-emu/...
GitHub - shadps4-emu/shadPS4: PlayStation 4 emulator for Windows, Linux and macOS written in C++
PlayStation 4 emulator for Windows, Linux and macOS written in C++ - shadps4-emu/shadPS4
github.com
July 18, 2025 at 4:16 PM
Reposted by tzomb1e
It's dangerous to go alone.
July 8, 2025 at 8:59 PM
Reposted by tzomb1e
On Unix-like platforms, if you use git clone --recursive on an untrusted repo, it could achieve remote code execution. Update to a fixed version of git and other software that embeds Git (including GitHub Desktop) dgl.cx/2025/07/git-... #linux #security #infosec
CVE-2025-48384: Breaking git with a carriage return and cloning RCE
dgl.cx
July 8, 2025 at 6:38 PM
Reposted by tzomb1e
Let's just agree that if this works against a vendor, you should stop using that vendor.
Check Point discovered malware that embedded AI prompt injections in its code to evade detection by AI-based malware scanners.

The malware tried to order the AI scanner to "ignore all previous instructions" and return a "no malware detected" result.

research.checkpoint.com/2025/ai-evas...
New Malware Embeds Prompt Injection to Evade AI Detection - Check Point Research
Detected for the first time, malware attempts AI evasion by injecting a prompt to tell the LLM to label the file as benign
research.checkpoint.com
June 25, 2025 at 11:34 PM
Reposted by tzomb1e
June 20, 2025 at 10:47 AM
Reposted by tzomb1e
Sekoia has published a report looking at the AitM phishing kit landscape, its evolution, and today's largest providers.

blog.sekoia.io/global-analy...
June 12, 2025 at 12:23 AM
Reposted by tzomb1e
LumaStealer and DanaBot operators:
two men are standing next to each other and one is saying what is dead may never die
ALT: two men are standing next to each other and one is saying what is dead may never die
media.tenor.com
May 22, 2025 at 9:36 PM
Reposted by tzomb1e
LockBit v4 hacked, dump includes around 50k BTC addresses used by the gang and more

The defaced website shows the same message that was on the Everest RaaS earlier this year
May 7, 2025 at 11:41 PM
Reposted by tzomb1e
May 4, 2025 at 4:41 PM