Jeremy Kirk

@jkirk.bsky.social

Okta Threat Intelligence. Personal account. Interests: Cyber threat intelligence, OSINT, data breaches, AI. Formerly intel analysis @ Intel 471. jeremykirk.com

Behind adverts for suspiciously cheap AI subscriptions for Anthropic's Claude, OpenAI's ChatGPT, Cursor, Gemini, etc., is an ecosystem of fakery and fraud. Okta Threat Intelligence profiled the account signup fraud TTPs and took disruptive action: www.okta.com/en-gb/blog/t...

Free tokens for sale: How fake signups drive AI fraud

Bad actors are registering fake accounts to resell discounted and trial AI services from Anthropic, Google and Amazon for profit. Here's the lowdown.

okta.com

Come work with us at Okta ! We're looking for a new member of Okta's Threat Intelligence team. This role is one in which if you have a good idea that fits our mission, you can run with it. Plus, we're nice people. 😀 North Korean IT workers need not apply. www.linkedin.com/jobs/view/44...

Okta hiring Director, Okta Threat Intelligence in Bellevue, WA | LinkedIn

Posted 1:35:03 AM. Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta…See this and similar jobs on LinkedIn.

linkedin.com

Good post on OpenAI's security controls around Codex: Sandboxing, approvals, limited network access, OAuth for CLI/MCP, dangerous shell commands blocked, OpenTelemetry log exports for prompts, tools, MCP usage, etc. centralized in SIEM. openai.com/index/runnin...

Running Codex safely at OpenAI

How OpenAI runs Codex securely with sandboxing, approvals, network policies, and agent-native telemetry to support safe and compliant coding agent adoption.

openai.com

Device code phishing is exploding, and AiTM actors are getting in on it. We found ODx phishing-as-a-service providing device code capabilities in addition to their AiTM offerings. ODx is one of the most popular AiTM kits currently. It's also tracked as Storm-1167 and FlowerStorm.

Ran a two-hour Spotlight OSINT workflow using Deepseek-V4-Pro via its API with Claude as a harness. Quite fast. Cost US$.33 versus probably at least $5 on extra usage w/ Sonnet. No charge for using Claude as an orchestration layer. Worked very well. spotlight.buriedsignals.com

Spotlight — OSINT investigation system for journalists

Turn your agent into an investigative system. Methodology, investigator and fact-checker loops, human review gates, local-first workflows.

spotlight.buriedsignals.com

Over several weeks, we at Okta tested OpenClaw with various AI models to see how agents handle API keys, OAuth tokens, credentials and other secrets. The short of it is agents can't be trusted, and it's easy to talk agents into skirting their guardrails. More here: www.okta.com/newsroom/art...

Phishing the agent: Why AI guardrails aren’t enough

AI agents are being handed the "keys to the kingdom," but research shows they can't be trusted to hold them. Learn how agent guardrails can fail.

okta.com

Tested a powerful OSINT tool last night by Buried Signals called Spotlight. Qwen 3.6 was being finicky on Ollama so ran it with Sonnet. Spotlight is an amazing investigative tool -- finds, confirms, reconfirms, dispels -- all incredibly fast. spotlight.buriedsignals.com

Spotlight — OSINT investigation system for journalists

Turn your agent into an investigative system. Methodology, investigator and fact-checker loops, human review gates, local-first workflows.

spotlight.buriedsignals.com

Moxie Marlinspike's Confer project — which aims to bring end-to-end encryption to protect the privacy of AI chats that are now usually being consumed by AI companies for training — will work to integrate it with Meta AI. #infosec confer.to/blog/2026/03...

Confer is bringing foundational AI privacy to Meta

I started building Confer because I saw how amazing LLMs are, and as a result, how much of our data is flowing through them. Already, AI chat apps have become some of the largest centralized data lake...

confer.to