Spanky

@spankowitz.bsky.social

I like threat intel, purple team, and turtles.

Apropos of nothing, I think it's past time for risks.txt to go alongside robots.txt and security.txt on websites. risks.txt would declare the contents of the organization's risk acceptance log so the $baddies know not to use those issues in attacks.

I will hold an online session of the Paralus LLC Applied #CyberThreatIntelligence course from 27-31 July, 1400-1600 US Eastern/2000-2200 Central European time. Focused, to the point training, two hours per day for five days. Register your interest at the following form: forms.gle/M1LgQTomJGek...

Paralus LLC: Applied Threat Intelligence

Hello and thank you for your interest in a workshop focusing on Applied Threat Intelligence! Scheduling: 27-31 July 2026 (Five Days) 1400-1600 US Eastern/2000-2200 Central European (Two Hours/Day) C...

forms.gle

A developer made a browser extension called "Knockoff" that shows what a wasteland Amazon truly is by filtering out brands like "GODONLIF" "EHEYCIGA," ROTTOGOON," and sponsored products. Useful and illustrative even if you don't use Amazon www.404media.co/knockoff-bro...

'Knockoff' Browser Extension Hides Sketchy Brands on Amazon

"Sorry to brands like WNPETHOME, EHEYCIGA, YXYL, LU&MN, JOYIN, TOMY, GODONLIF, YOOJEE, LINGTENG, LANEIGE, VISCOO, BIODANCE, COOFANDY, BALENNZ, TOSY, and LUENX."

404media.co

NEW: Google is rolling out a new feature for Android called Intrusion Logging, designed specifically to help researchers investigate attacks done with spyware and forensic tools. Amnesty says this is “a fundamental shift in the amount and quality of forensic data available on Android devices.”

Google launches new Android security feature to help uncover spyware attacks | TechCrunch

Intrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement...

techcrunch.com

Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection. @podalirius.bsky.social found two command injection vulns hiding in Windows Explorer's built-in context menus, both that went undetected for 9 years. https://ghst.ly/42ImlI6

Shift Happens - Uncovering Two Built-in Command Injections in Windows Context Menus

Two long-standing Windows Explorer vulnerabilities lets attackers execute arbitrary PowerShell commands using crafted folder names, affecting Windows 10 and 11 since 2017.

specterops.io