"AI powered botnet" sounds like a goofy alarmist news headline, but it's interesting it's pretty feasible now --
John Hammond
@johnhammond.bsky.social
Hacker. Friend. Cybersecurity Researcher at Huntress.
A Linux backdoor is being sold on the dark web for $1,600 USD. The developer called it "PamDOORa", while it abuses the Linux PAM stack for persistent SSH access, credential harvesting, and wiping logs. YouTube Video: youtu.be/3YB4XGy8xwE
"I Built an AI Cybersecurity Research Factory (for CTFs & Vulnerabilities)!" ... long-form video demonstration that doubles as "how I personally use AI lately," and some playground experiments setting it in motion to go hack away on wargames and potential software applications 🤖 Video link below:
Hey-o, I'm jumping in to host a show to demystify the dark web alongside Women in Cybersecurity (WiCyS) (huge thanks to Lynn Dohm for letting me join the party) this Thursday, April 30 at 12pm CT! Should be fun, hope to see you there too 😊 Link: jh.live/wicys-webinar
During tax season I got a notification that my tax documents are ready, from... uh... Zoom 😂 Phishing email leveraging their legitimate document sharing functionality, pointing to a link and a domain that _looks like_ an IRS website, but, infects your computer. Video link: youtu.be/p6ySQ94GZsA
hELLO the tIME HAS cOME oNCE AGAIN on my cONTENT cALENDAR for me to continue to scream and shout about oUR VIRTUAL EVENT ContinuumCon 2026 jUNE 12 - 14 continuumcon.com livestream run of show is free & public but all workshop sessions get into hands-on labs see u there ✌️
A funny slew of phishing emails I've seen flying around: a legitimate Facebook Business invite notification, but bad actors stuffing threatening urgency into their "name" values that get inserted into the real email. And the phishing landing page is hysterical. 🤣 Video link: youtu.be/QRN3t1_paTY
More ConsentFix -- a "V3" some might say, shared amongst a dark web/cybercrime forum, and a treasure trove of tradecraft to see how bad actors leverage third-party sites and services to do their dirty work. 👀 Video: youtu.be/T3oVdPCMDJw
Joined by Katrina Manson to hear all about her latest book release: Project Maven & the Dawn of AI Warfare 👀 We talk AI usage at the Pentagon, drone intel, AI enabled targeting, and the ethical tipping point of autonomous weapons. Super fascinating ideas. Video: youtu.be/OVgruylpVXc
Wild story on a big AI-powered social engineering campaign, leveraging Device Code phishing to steal Entra ID/Microsoft accounts -- all with entirely unique and personalized per-victim lures from vibecode-crafted infrastructure 🤯 Video: youtu.be/9b3kirR8s2U
Real treat to catch up with Joe Tidy and hear more behind the scenes deets about his book Ctrl+Alt+CHAOS: How Teenage Hackers Hijack the Internet 🤩 Insight into "the most hated hacker in history" and the rise and fall of teenage hacking gangs. Video: youtu.be/GUzD_ShRKYE
Fake Windows notifications -- homage to iPurpleTeam and their sweet recent writeup, showcasing some tricks with toast popups in pure PowerShell to fake alerts from installed apps found in Registry. Even a low-privilege custom protocol handler! Video: youtu.be/wrAFZLa1TAk
Our virtual event endeavor is back for its round-two show -- ContinuumCon 2026! Banner mantra "The cybersecurity conference that never ends" 😜 All sessions are workshops and you keep a whole cyber range to work on them whenever you want. jh.live/continuumcon Main eventlivestream is June 12-14th!
heyyyyyy In case you missed it, I got to chat with Fletcher Heisler about the cool stuff he's been cooking up with @authentik ! And I met Fletcher at BsidesSF -- really awesome guy 🤩😊 Video: youtu.be/2ttrqnw5kDE
If you're waking up to the Internet and your world on fire from the new NPM and axios package supply chain attack, I have a short 15 minute video to hopefully catch you up to speed. Links to further resources included -- video: www.youtube.com/watch?v=A58c...
Vibecoding -- err... 🌈 AI assisted programming ✨ -- a "ChatGPT for the dark web!" Natural language chat interface backed by threat intel API, for a Golang tool with a TUI (in spirit of the current command-line coding harnesses 😜). Fun project. Video: youtu.be/oqU41QwtAGE
NahamSec teaches me bug bounty basics! He fills me in on the platforms, programs, and how the scope has grown so much now. Ben walked me through threat modeling and had a slick demo of his real-world bugs found with Red Bull and others 😎 Video: youtu.be/lNuvI48ysVo
GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE
The recent Trezor-physical-mail-phish-delivery-crypto-scam made me giggle -- so I rambled about it in a video. I'm not a crypto guy but alarm bells should probably go off in your mind when something is asking for your recovery seed phrase. 😅 Video: youtu.be/UQFySFs2GJk
I've made some updates and added 2 hours worth of new material to the "Linux for Hackers Fundamentals" course on @hackinghub_io ! Vim text editor basics and sed & awk for text processing. Here's a 40% off discounted link if you'd like to take a peek :) hhub.io/Linux2026JH
h?ckers a[r]e gl*bbing! A little showcase of @0xv1nx0 's neat new project LOLGlobs -- demo is a teeny weeny PowerShell download cradle, obfuscated with globbing tricks and used with some 'living off trusted sites' just flair for funzies too :) Video: youtu.be/IImLVU39V_Q
Google API keys didn't use to be considered "secret," so they're all over the web-- but now they are an open door to Gemini 🫠 Quick rundown video of Truffle Security's really nifty research, almost 3,000 websites exposed.. including Google themselves😅 🔗 youtu.be/XNMHUifKce8
Quick dance with CVE-2026-21509, a "Security Feature Bypass Vulnerability" and an emergency out-of-band fix from January Patch Tuesday (and an obligatory exaggerated YouTube thumbnail -- I apologize and appreciate folks who understand algorithm nuance) youtu.be/Ck8IPInn74A
Super quick video of the Sinobi ransomware gang fail from a few days ago, because the story made me laugh 😅 I'm trying to get in a groove of shorter videos, and I thought this this fit. Video: youtu.be/OwTV42GyRnk
Moltbook is still weird. And external AI skills suck. I'm late to the yap party by a week or so (which is apparently an eternity in the current time vortex) but I wanted to show cool community resources & research amongst the skills shenanigans. Video: youtu.be/IvL89vbWmQ8
February got here fast-- and the 2026 Snyk Fetch the Flag CTF came up quick too! This year my friend NahamSec is hosting the game, starting NEXT THURSDAY 2/12 at 12pm ET! Free 24-hour Capture the Flag event with AR glasses as prizes 😎 See ya there! jh.live/snyk-ftf2026
Are MCP servers safe and secure? Yes? No? Sometimes? Maybe? ... Zack Korman shows me some of his learnings on MCP security (or lack thereof) with his "Evil MCP" project 😈 YouTube link: youtu.be/_r_sLetar_o 1. data exfil of your prompts & code context 2. inserting vulnerabilities into your code
Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thing👀 Hat tip to DeceptIQ et al.... we showcase: 1. breaking a Windows login with an empty user profile, 2. getting initial access EZPZ with a Sliver C2 implant,