John Scott-Railton

@jsrailton.bsky.social

Chasing digital badness. Senior Researcher at Citizen Lab, but words here are mine.

NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order "safety" is risky. 1/

Bild

The plane with the hantavirus-ill passenger has done a lot of flying since April 25th. Airlink's ZS-YAD spends tonight in Nairobi, with scheduled return to Johannesburg tomorrow morning. I'm curious about what cleaning it might've gotten from Airlink. Here are some more deets 1/

BildBildBildBild

PULITZER ALERT: to the team at @apnews.com on how US tech helped turbocharge Chinese surveillance & repression. And fueled surveillances abuses everywhere. Even at home. Took years & faced serious pushback. Tenacious journalism matters & gets us truth despite very long odds.

Zack Whittaker@zackwhittaker.com · 3mo ago

"The Pulitzer Prize for International Reporting is shared by journalists Dake Kang, Garance Burke, Byron Tau, Aniruddha Ghosal and Yael Grauer." Incredibly well deserved. @yaelwrites.com @byrontau.bsky.social @dakekang.bsky.social

Prolific Russian gov phishing operation now using the DarkSword exploits. Predictable: lots of threat actors have been exploit poor but with great infrastructure for social engineering. When exploits leak from governments they are best positioned to almost immediately start using them 1/

ThreatInsight@threatinsight.proofpoint.com · 4mo ago

Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵

6/ In 2022 I warned Congress that commercially-developed exploits would leak. I testified to House Intelligence that the tech would go to adversaries and criminal organizations. That has now happened with #Coruna. And as the commercial offensive industry grows, it will happen again.

The #FCC is reviewing a proposal for space mirrors to blast sunlight at the earth at night. Sounds awful. Anyone who that been to the far north or tried to sleep under lights knows how disorienting 24h of light is. Everybody gets insomnia. It's also an ecological disaster machinery 1/

BildBild

We're about to see a new surveillance trap: "Plaid for AI" This will look like slick middleware that seamlessly hooks CRMs to Claude, gmail to GPT-5 etc, etc. UX will be great & founders well-meaning. Then the VCs ask: what else can we do with this sick tokenflow data? 1/

NEW: US just sanctioned a network of exploit brokers trafficking in stolen US hacking tools First-ever use of #PIPA (Protecting American Intellectual Property Act) by Treasury. Here's the wild backstory of how Operation Zero got US-taxpayer funded exploits. 1/

BildBild

UPDATE: Paragon calls OPSEC fail a tiny price to pay for "female empowerment." Peak cringe. And nonsense. Entire world learned from this pic that their spyware is more invasive than previously known. 1/

Bild
John Scott-Railton@jsrailton.bsky.social · 6mo ago

Epic OPSEC fail by Paragon exposing Graphite spyware capabilities. Annotated pic from what we know. Please help me figure out the other apps in in this pic that the spyware can access: #WhatsApp #Telegram #Signal ? #Line? ? #Snapchat? #TikTok? 1/