Zach Edwards

@thezedwards.bsky.social

data supply auditor | privacy & ad tech expert | internet threats Personal @ victorymedium.com Work @ Staff Threat Researcher @ Infoblox.com Co-Founder @ DecryptAds.com

First Apples “Hide my Email” was proven to be broken, now “Private Relay” - this tech has been the backbone of Apples privacy commitments for years and now we know they’ve been broken for god knows how long. Reminder: Apple and Google’s MAID products are the backbone of global data brokers. ⛈️⚖️🖖🏻

Joseph Cox@josephcox.bsky.social · 5h ago

New from 404 Media: Apple's 'Private Relay' is exposing users' real IP addresses. Private Relay is supposed to protect all your browsing in Safari. But researchers found a bunch of issues that are exposing real IPs. I verified they do. Not fixed, a live issue www.404media.co/apples-priva...

Me and a couple cool folks are cooking up something extra special at DecryptAds.com for everyone who wants to better understand data sharing from publisher websites / apps & ad tech companies...a real research tool for hunting the programmatic ecosystem... (and this tool isn't vibe coded).⛈️⚖️🖖

What DecryptAds analyzes — and why it matters — DecryptAds

How DecryptAds helps researchers and the public understand the programmatic advertising ecosystem — auto-investigation, publisher and ad-system profiles, geo-risk, data brokers, declaration fingerprin...

decryptads.com

great visual investigation into how your data flows from a credit check through a private company and into the hands of the government. These systems are lynchpins for the modern economy but without guardrails on using the data for gov investigations, the 4th amendment is essentially for sale.

Joseph Cox@josephcox.bsky.social · 2w ago

You opened a credit card. ICE now knows where you live. Here's how when you open a credit card your address leaves your bank, goes through middlemen companies, and ends up with ICE. ICE plans to use this data for immigration and 'voter fraud'. No warrant More: www.404media.co/you-opened-a...

I was in Yellowstone park for a week and a half and just got back a few days ago. We actually camped in that Bridge Bay campground where that recent bison attack occurred. The park is beautiful and extremely special but it’s super important to appreciate the animals are wild and can be dangerous. 🖖🏻

How many of your favorite publishers do you think are partnering w/ ad tech data brokers & foreign ad tech orgs based in risky jurisdictions? How do you think the global mobile location data brokers get their data? Via secret partners sharing via black helicopters? Or via disclosed ad partners? 👀

David Dayen@ddayen.bsky.social · 4mo ago

Starting today, @prospect.org has removed all programmatic ads, because we believe that respecting you as readers rather than monetizing your attention will earn trust. This is what the site looks like, with all space reserved for stories about ideas, politics and power. prospect.org/2026/04/06/w...

Prospect.org homepage, now programmatic ad-free.

As someone who worked on the investigation to better understand how U.S. spies were likely doxxed & killed due to hundreds of websites launched by the CIA on obscure topics w/ a secret encrypted messaging tool built into them for spy comms (www.reuters.com/investigates...), this is vvv dangerous.

How the CIA failed Iranian spies in its secret war with Tehran

Gholamreza Hosseini got caught spying for the CIA in Iran. The story of how he was burned casts light on an epic U.S. intelligence failure.

reuters.com

Eli Omen@eliomen.bsky.social · last mo.

Here's the story: www.nytimes.com/2026/06/29/u... To recap; he wants a master spy list and he's also about to engage in mass declassification. Our adversaries didn't even dream of putting something this absurd in their wish list.

Some new research from me and the team at Infoblox on a Chinese open source framework being used in hundreds of thousands of scam websites called DCloud Uni-app - lots of good pivots to work off from the indicators we shared! www.infoblox.com/blog/threat-...

DCloud Uni-App: One Framework, 236,000+ Scam Sites

How a Chinese open-source framework fuels 236,000+ scam sites across major cloud providers and bulletproof hosts, spread via social engineering.

infoblox.com

I'd like to see the U.S. government spending hundreds of millions *every year* in various advertising formats educating the public & especially senior citizens about scams. U.S. victims lost over $20 billion last year and this continues to get worse, and threat actors have so much money to scale up.

Great work on this by @dmehro.bsky.social and @dell.bsky.social - just further proves the original story had legs and was accurate.

Andrew Couts@couts.bsky.social · 2mo ago

NEW: On Thursday, @wired.com reported that Meta had quietly added code for a face recognition system to Meta AI, its smart glasses companion app. On Friday, code for the face rec system was removed. @dmehro.bsky.social and @dell.bsky.social with the scoop: www.wired.com/story/meta-r...

Keep an eye on this Google Adwords ruling in India... could have significant impacts on search targeting if Google is required to change policies outside of India too... www.reuters.com/business/med... This would be a *gamechanger* for stopping malvertising campaigns which target major brand names.

Indian court ruling on Google keyword ads could reshape online advertising

An Indian court ruling that Google infringed the trademark rights of a bathroom fittings maker by ​allowing rivals to use its name as an ‌advertising keyword could reshape the online ads market, India...

reuters.com

Excellent reporting, alarming findings. Bloomberg's @dmehro.bsky.social et al found U.S. state government health websites are sharing people's personal info (sex, citizenship & race data) with tech giants via pixel-sized webpage trackers. Several states pulled the trackers after Bloomberg disclosed.

State Healthcare Sites Are Sharing Personal Data with Big Tech

Race, location and immigration information has been sent to TikTok, Meta and others.

bloomberg.com