Realized three messages in that my east coast ass should not be messaging folks at 0700 during summer camp. Oops. My bad. Sorry y’all.
Ian Campbell
@neurovagrant.bsky.social
Security ops engineer and investigator @ DomainTools, writer, voracious reader. he/him. Opinions here mine only. Autistic/depressed/anxious/hungry. https://dti.domaintools.com
An EFF investigation has found that some advertising SDKs enable location data collection by default. The findings aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app.
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing users’ location by default when embedded in apps granted location ...
eff.org
Beacon CRM is the company that was hacked. The company has an "incident guidance" page that you probably wouldn't be able to find through a search engine, because the company added a "noindex" tag code to the page's code, preventing it from being indexed. www.beaconcrm.org/incident-gui...
Massive CRM used by many UK charities hacked . @campuscodi.risky.biz @grahamcluley.com BBC News - English National Ballet suffers customer data hack www.bbc.co.uk/news/article...
First Apples “Hide my Email” was proven to be broken, now “Private Relay” - this tech has been the backbone of Apples privacy commitments for years and now we know they’ve been broken for god knows how long. Reminder: Apple and Google’s MAID products are the backbone of global data brokers. ⛈️⚖️🖖🏻
New from 404 Media: Apple's 'Private Relay' is exposing users' real IP addresses. Private Relay is supposed to protect all your browsing in Safari. But researchers found a bunch of issues that are exposing real IPs. I verified they do. Not fixed, a live issue www.404media.co/apples-priva...
Get the look: shop.ifin-intel.org
The IFIN Store
The official store for IFIN. Support the organization with your purchase!
shop.ifin-intel.org
Coffeeing up for the day. If you see me, say hi. Repping the @ifin-intel.org tee that says “Threat intel is mutual aid” today because well, because threat intel is mutual aid. We’re an ecosystem of ecosystems, and the more sharing we do at our roots, the more our core and branches thrive.
I've always thought of cyber security as a kind of public health discipline
Coffeeing up for the day. If you see me, say hi. Repping the @ifin-intel.org tee that says “Threat intel is mutual aid” today because well, because threat intel is mutual aid. We’re an ecosystem of ecosystems, and the more sharing we do at our roots, the more our core and branches thrive.
-wakes up in east coast early riser -light streaming through curtain breaks -oh good, must be morning! -0100 in Vegas, baby.
…y’all i just noticed something I cannot unsee. In hackertracker, red team village is yellow, and blue team village is green.
BSides NoVA was so fun to speak at last year. Their CFP is now open, y’all should join me! sessionize.com/bsidesnova-2...
BsidesNoVa 2026: Call for Speakers
BSidesNoVa 2026 – Call for PapersBSides NoVA turns 10 this year, and the CFP is officially open. We're expecting 1,000+ attendees across multiple trac...
sessionize.com
I'm so tired of writing this post again and again.
Here's our coverage of the current ongoing keyv/cacheable NPM attack. We've included a list of known Ethereum RPC endpoints as indicators, since the malware looks up second stage data from that blockchain. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Cyber defense is adversarial. Swagger for every block, strut like you own it for every detection, dance for every threat uncovered. Don’t let attackers have all the fun. We are the adversaries. Defend and hunt like you damn well mean it. Happy hacker summer camp, friends.
I reckon they can skip most of the diagnostic battery for autism on this one
The more I use it and the more I learn about it, almost every LLM use case in enterprises does one thing well: it signals exactly where the company that’s deployed it is intent on underspending.
Gonna be a hot one in Vegas, unsurprisingly. An important reminder: certain medications, including and especially some antidepressants (SNRIs and some SSRIs) increase your heat sensitivity deeply. Some also increase your alcohol sensitivity deeply. Please take care.
I'll be talking about DNS & domain investigations in geopolitical contexts at the Boston Security Meetup on August 20! #infosec #cybersecurity www.meetup.com/the-boston-s...
Good morning. We're observing an intensifying set of campaigns targeting credentials to facilitate data exfiltration and ransom. I've pulled some initial thoughts together over at @ifin-intel.org #threatintel #infosec #cybersecurity Cohesive writeup: discourse.ifin.network/t/newly-obse...
Newly-observed vishing/phishing campaign targeting retail/finance/fintech/more
On the threat intelligence side as well as the Very Concerned Customer side, seeing rising talk of an emergent campaign consistent with previous Com-related voice phishing. Domains include terms like ...
discourse.ifin.network
Wait are we competing to see how many crimes we can admit to in public now? Did I miss the memo?
thinking about blackhat/defcon, and some year i want my org to sponsor a quiet reading party. maybe low-key waitstaff taking care of drinks and snacks, and handing out warm washcloths. "no eye contact chill rager; unless someone's wearing a green sign they get left alone to rest"
Oh this is a good one. Physical letters being mailed out by a threat actor pretending to be the IRS, trying to get folks to "declare" their cryptocurrency holdings in a fake portal that auths to and drains the wallets. www.coinbase.com/blog/consume...
Consumer Protection Tuesday: A Fake IRS "Digital Asset Compliance Portal" Letter Is Targeting Crypto Holders
Coinbase is a secure online platform for buying, selling, transferring, and storing cryptocurrency.
coinbase.com
One of the things that became clear in the yearlong investigation we released yesterday at @domaintools.bsky.social is that the UAE is a committed partner to money laundering of all sorts. So Binance is now routing law enforcement requests through the UAE government, naturally.
Binance has changed an internal policy and appears to intentionally delay all law enforcement requests related to scammers and money laundering investigations www.nytimes.com/2026/07/28/u...
Did some analysis on a customer ask today and went from a few dozen domains to tens of thousands. Looks like Vigorish Viper activity, including a huge cluster centering around FIFA and the World Cup. Infoblox wrote the book on 'em: www.infoblox.com/threat-intel... #threatintel
Vigorish Viper - Cybercriminal Using Football to Fuel Gambling Ops
Infoblox Threat Intel spotted this persistent DNS threat actor leveraging an advanced RDGA to create very large numbers of domains for use in malware.
infoblox.com
We've worked on this investigation for more than a year, and it led us from a single domain to a multi-billion dollar IRGC sanctions evasion network. Please enjoy the report! dti.domaintools.com/research/the...
DomainTools Investigations | Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities.
Uncover how the Zedxion Corporate Nexus and Babak Zanjani network deploy UK shell companies, digital tokens, and UAE trade entities for IRGC sanctions evasion.
dti.domaintools.com
I don't think this is the same call you're talking about, but it's a very similar situation that the dispatcher had to pick up on. www.cnn.com/2019/11/23/u...
Woman calls 911 to report domestic violence allegation under the guise of pizza order | CNN
Tim TenEyck, a 911 dispatcher in Oregon, Ohio, has answered a lot of 911 calls in his 14 years on the job. When he first got a call on the evening of November 13th asking to order a pizza, he figured ...
cnn.com
I was a 911 dispatcher for a decade. To really understand how terrible an idea it is to have AI answer 911 calls, I'll present you with a single real-life call: Upon answer, the caller calmly began ordering a pizza. Large, pepperoni. Side order of chicken wings. To be delivered promptly.
AI has no place in 911 calls. From Mystery AI Hype Theater 3000’s latest episode “State of Emergency”. (with @emilymbender.bsky.social)