John Hammond

@johnhammond.bsky.social

Hacker. Friend. Cybersecurity Researcher at Huntress.

"I Built an AI Cybersecurity Research Factory (for CTFs & Vulnerabilities)!" ... long-form video demonstration that doubles as "how I personally use AI lately," and some playground experiments setting it in motion to go hack away on wargames and potential software applications 🤖 Video link below:

Bild

During tax season I got a notification that my tax documents are ready, from... uh... Zoom 😂 Phishing email leveraging their legitimate document sharing functionality, pointing to a link and a domain that _looks like_ an IRS website, but, infects your computer. Video link: youtu.be/p6ySQ94GZsA

Bild

hELLO the tIME HAS cOME oNCE AGAIN on my cONTENT cALENDAR for me to continue to scream and shout about oUR VIRTUAL EVENT ContinuumCon 2026 jUNE 12 - 14 continuumcon.com livestream run of show is free & public but all workshop sessions get into hands-on labs see u there ✌️

Bild

A funny slew of phishing emails I've seen flying around: a legitimate Facebook Business invite notification, but bad actors stuffing threatening urgency into their "name" values that get inserted into the real email. And the phishing landing page is hysterical. 🤣 Video link: youtu.be/QRN3t1_paTY

Bild

Joined by Katrina Manson to hear all about her latest book release: Project Maven & the Dawn of AI Warfare 👀 We talk AI usage at the Pentagon, drone intel, AI enabled targeting, and the ethical tipping point of autonomous weapons. Super fascinating ideas. Video: youtu.be/OVgruylpVXc

Bild

Our virtual event endeavor is back for its round-two show -- ContinuumCon 2026! Banner mantra "The cybersecurity conference that never ends" 😜 All sessions are workshops and you keep a whole cyber range to work on them whenever you want. jh.live/continuumcon Main eventlivestream is June 12-14th!

Bild

Are MCP servers safe and secure? Yes? No? Sometimes? Maybe? ... Zack Korman shows me some of his learnings on MCP security (or lack thereof) with his "Evil MCP" project 😈 YouTube link: youtu.be/_r_sLetar_o 1. data exfil of your prompts & code context 2. inserting vulnerabilities into your code

Bild

Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thing👀 Hat tip to DeceptIQ et al.... we showcase: 1. breaking a Windows login with an empty user profile, 2. getting initial access EZPZ with a Sliver C2 implant,

Bild