oh no, the bots have arrived on here welp, it was only a matter of time
hrbrmstr πΊπ¦ π¬π± π¨π¦ π³οΈβπ
@hrbrmstr.dev
a.k.a. boB Rudis β’ πΊπ¦ Pampa β’ Don't look at meβ¦I do what he doesβjust slower. #rstats #js #duckdb #goavuncularβ’π¨βπ³β’βοΈβ’ π€β’ https://dailydrop.hrbrmstr.dev β’ Maineπ¦
way too little. way too late.
In other "excellent news from religious bodies", the US Presbyterian General Assembly has formally voted to start the process to (correctly) declare white Christian nationalism a theological error incompatible with the teachings of Jesus: pres-outlook.org/2026/07/pcus...
With all of the [Mini] Shai Hulud ops of just the past few months, are there any stories of SBOMs "saving" or at least "radically helping" orgs get a handle on exposure and remediation?
The HoneyLabs blog (which you shld be π if you're a defender) β honeylabs.net/blog β didn't have a detectable RSS feed so I made a programmatic one via @val.town β hrbrmstr--019e7d68e38e747786809794f66af76f.web.val.run 1 of now 5 programmatic RSS-feed Vals. It takes less than 90s to make new ones.
Blog Β· HoneyLabs
Findings, write-ups, and notes from the HoneyLabs honeypot network.
honeylabs.net
Knowledge Fight was and remains one of the all-time great podcasts. It is the rarest kind of thing: a show that entertains while having a real-life impact. Dan and Jordan helped defang and neuter elements of a powerful propaganda network. Excited to see what both do next.
I'm just now reading about the end of @knowledgefight.bsky.social. We 100% would not have been able to get this deep into this journey of taking over InfoWars without their scrupulously deep research about the worst guy in the world Thank you, Dan and Jordan. Excited to hear what's next.
Alright!- don't know if your heart was "no one will notice, you're right" or "we're supporting you staying in and writing it" π So latest free newsletter, with many three.js web games, some more splats/3d stuff, image model that can't do sprites, narrative news open.substack.com/pub/arnicas/...
TITAA #78: Little City Builders
Three.js Cities - 360 Images & Splats - Variorum - FlipBook - Talkie - LLM Philosophy
open.substack.com
I am late to the 0900 time, but actually sleeping kind of throws off the "todo" schedule a bit. Today, I start as a Distinguished Engineer @ @censys.bsky.social !!!!! More info on the "what" I'll be doing when a certain partner in crime crosses the threshold in a few weeks. #GuessWho
π #RStats Core member TomΓ‘Ε‘ Kalibera passed away.
$ rm -rf $CURRENT_GIG $ sleep $(( $(TZ="America/New_York" date -d "2026-04-13 09:00:00" +%s) - $(date +%s) )) && echo $NEW_GIG
New research: Threat actors are actively mapping LLM infrastructure. Our Ollama honeypots captured 91K+ attack sessions. One campaign systematically probed 73+ model endpointsβGPT-4o, Claude, Llama, Gemini, and moreβacross 80K sessions in 11 days. www.greynoise.io/blo... 1/2
Threat Actors Actively Targeting LLMs
Our Ollama honeypot infrastructure captured 91,403 attack sessions between October 2025 and January 2026. Buried in that data: two distinct campaigns that reveal how threat actors are systematically mapping the expanding surface area of AI deployments.
greynoise.io
That which was originally a private customer threat intel share in our weekly At The Edge reports is now a public blog post! www.greynoise.io/blo... This is a deep dive into a massive reconnaissance campaign that unfolded between December 25β28. 1/4
The Ransomware Ground Game: How A Christmas Scanning Campaign Will Fuel 2026 Attacks
Over four days in December, one operator scanned the internet with 240+ exploits, logging confirmed vulnerabilities that could power targeted intrusions in 2026.
greynoise.io
#macOS folks!! Today is a *great* day to: ```bash brew update && brew upgrade && brew cleanup && brew doctor ``` then: ```bash brew bundle dump --file=~/Brewfile --describe --force ``` to create a `Brewfile` you can use to "quickly" restore the Homebrew bits that you rely on.
ππ½ Lifehacker for introducing GreyNoise Check to a broader population! π lifehacker.com/tech/... If you haven't used GreyNoise Check β check.labs.greynoise.io β this is the perfect time to do so, especially if you're visiting friends/fam over the holidays. 1/2
"There's Payloads, And Then There's pAIloads: A Look At Selected Opportunistic (And Possibly AI-"Enhanced") React2Shell Probes and Attacks" www.greynoise.io/blo... 1/3
React2Shell Payload Analysis: A Look at Selected Opportunistic and Possibly AI-"Enhanced" Probes and Attacks
Over the past ~1.5 weeks, the React2Shell campaign has unleashed a flood of exploitation attempts targeting vulnerable React Server Components. Analyzing the payload size distribution across these attacks reveals a clear fingerprint of modern cybercrime, and a landscape dominated by automated scanners with a handful of sophisticated outliers.
greynoise.io
Just in: Watch #React2Shell exploitation unfold over time in the map below (geo of source IPs attempting to exploit CVE-2025-55182). #GreyNoise #ThreatIntel #CVE202555182 #Nextjs #Cybersecurity
Whilst spelunking through React2Shell traffic and associated initial access payloads, I came across a late-to-the party attacker attempting to deploy a MeshCentral agent for C2. Thanks to Censys, we poked a bit harder, and boy howdy are we on the precipice of a real mes[hs].
React2Shell Side Quest: Tracking Down Malicious MeshCentral Nodes β GreyNoise Labs
While spelunking through React2Shell initial access payloads, MeshCentral entered the building, so we decided to see just how Mesh-y GreyNoise Data Is
labs.greynoise.io
I had the [mis?]fortune of being awake just as attackers decided to slam the public internet with React2Shell exploits. GreyNoise had a tag up for it yesterday afternoon. Full write-up of the initial spate of attacks: www.greynoise.io/blo... 1/3
CVE-2025-55182 (React2Shell) Opportunistic Exploitation In The Wild: What The GreyNoise Observation Grid Is Seeing So Far
GreyNoise is already seeing opportunistic, largely automated exploitation attempts consistent with the newly disclosed React Server Components (RSC) βFlightβ protocol RCEβoften referred to publicly as βReact2Shellβ and tracked as CVE-2025-55182.
greynoise.io
Got 30s of public media "fame" on NPR yesterday www.npr.org/2025/11/28/n...
Holiday cyber scams are getting more inventive
Hackers are hoping to take advantage of the holiday season, and they're not just stealing money or data.
npr.org
π New tool alert: GreyNoise IP Check Your home network might be compromised and you'd never know. Residential proxies, IoT botnets, and router malware are everywhereβturning regular internet connections into attack infrastructure. 1/3
There once was an organization called Stark Industries (no, not *that* one! this one is real!). They emerged around the time Russia decided to invade Ukraine. Oddly enough, their ASN real estate was the source of scads of Russian state-sponsored cyber ops. 1/5
Good morning. This is your reminder to get to the gym so that you can beat up racists if you have to.
Nobody (nobody) should trust the 110% centralized record store that is Bluesky's ATproto dumping ground. There is zero sign of a plan for having $ to keep it independent of any malicious entity. It is a centralized store that can purge your record tomorrow on a billionaire's whim.
atmosphere devs! π§βπ just published a protocol checkin: docs.bsky.app/blog/protoco... tl;dr expect to see a lot of updates from us in the next few months. we're hard at work on making AT easier to build on & ensuring the network remains a resilient foundation for the future of open social
Bari Weiss can and should (repeatedly) go REDACT herself.
Bonkers Palo Alto Login Scanner activity has continued through the weekend. We coordinated with/Palo on Fri, so they know aboot it & have the backs of their customers. tzulo, inc. & 3xK Tech GmbH continue to be the primary network sources (both need a spanking/null route). viz.greynoise.io/tag...
Bonus Drop #99: Duly Noted THE DROPS ARE BACK! Today, we tackle 3 note-taking tools: Blinko, Piles, and Memos. Blinko is an AI-integrated self-hosted system; Piles is a minimal web clipper; while Memos offers a lightweight, self-hosted knowledge base focused on simplicity and data privacy.
Bonus Drop #99 (2025-10-04): Duly Noted
THE DROPS ARE BACK! Today, we tackle three note-taking tools: Blinko, Piles, and Memos. Blinko is an AI-integrated self-hosted system with features for task management and Markdown support. Piles iβ¦
dailydrop.hrbrmstr.dev
Visibility Brigade making good trouble in Bangor, Maine!
Prediction: πΆοΈπΆοΈπΆοΈ
πΊ Live Webcast: Fixing a Broken System π Oct 29 β’ 2PM ET Legacy vuln mgmt leaves 25β40% of assets invisible. Join @ hdm.io, @todb.hugesuccess.org & @sawaba.bsky.social as they unpack blind spots, failed scans, & whatβs next. π www.scworld.com/cybercast/fi...
Microsoft steals content for their AI training data but doesn't want others to do the same thing. Odd. therecord.media/linkedin-sue...
LinkedIn sues software company allegedly scraping data from millions of profiles
ProAPIs, a software company, and its CEO Rahmat Alam allegedly run an operation which LinkedIn says charges customers up to $15,000 per month for scraped user data taken from the social media platform...
therecord.media