Security Person @ Perpetual | Catching badness, calming nerves | Opinions mine, detections shared

Austin, TX
Jim Saveker retweeted
Shodan Membership sale is live until 2026-08-09 00:00 UTC (~48 hours from now): account.shodan.io/billing/me…
76
491
1,443
499,482
/dev/null is not a detection strategy. Ingest everything. Investigate what matters. Less fatigue, more intrigue.
22
Commoditizing cognition on silicon feels like the final boss of industrial capitalism 😕
13
Jim Saveker retweeted
EDRUnChoker😀registers a permanent WMI subscription with a 5-second timer runs embedded VBScript (fileless) that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles. github.com/sbousseaden/EDRUn…
5
42
219
18,965
Interlock operators are running Volatility... the defender's memory-forensics tool against their own victims. {windows.hashdump} on a dump file → creds extracted, zero LSASS access. RunAsPPL / Credential Guard don't fire. Interesting finding from the DFIR Report.
58
Claude + Obsidian = 10x usefulness unlocked. Vault goes from static notes to thinking partner overnight. 🤯
1
36
I am reasonably reserved with respect to the AI hype train but tmux + Claude agent swarm? Absolute BEAST mode. Got my lead Claude bossing a squad of AI teammates, shared tasks, direct chit-chat via mailboxes, no race condition nightmares. Wow just wow.
44
Jim Saveker retweeted
A VS Code extension for a "Clawdbot Agent" was fake; it was actually malware that installed ScreenConnect on a target computer to be used as a remote access trojan! YouTube video walking through the extension source code & Rust-based loader by DLL hijacking: piped.video/7GS6Xs4hdvg Hat tip to Aikido Security and Charlie Eriksen for catching this thing in the wild -- one of the domains looks to also be hosting a panel for Evelyn Stealer malware, so we reference some other research from Trend Micro and Koi Security as well to note the similarities in the Lightshot EXE and DLL naming & abuse of VS Code extensions for fake AI coding assistants. While I was recording, the extension was changed and updated to a new version in real-time -- so we take a look at both and actually fire off the sample to see it work. ... it didn't work. (???) Looking more closely at the syntax of the extension, even recreating how it is invoked, the logic seemed wrong. Was the whole thing vibecoded? Maybe I missed something, so I need your eyes! (Or your Clawdbot Moltbot Robot Botbot bot "eyes"😜) piped.video/watch?v=7GS6Xs4h…
18
60
328
49,794
Attackers are now using Microsoft's own App-V scripts as a LOLBin to proxy PowerShell and slip past your defenses. The payload? Amatera infostealer, served via fake CAPTCHA. Microsoft really said "here, have a trusted binary" and threat actors said "don't mind if I do." bleepingcomputer.com/news/se…
55
Prohibited at NYC inauguration: Flipper Zero and Raspberry Pi. Permitted: Notebook computers running Kali Linux, cellphones with full pentesting toolchains and SDR apps. Classic security theater: banning specific hobbyist devices while allowing far more capable general-purpose hardware. bleepingcomputer.com/news/se…
65
With #DGXSpark, my time goes into fine tuning LORAs and NVFP4 quantization instead of debugging the stack. That’s real progress...nicely done #NVIDIA, Bravo!
1
58
UNC6395 abused compromised OAuth tokens from the Salesloft Drift integration to exfiltrate data from Salesforce, including AWS keys/Snowflake creds. So what: SaaS integrations expand your attack surface as much as your own code, but with far less visibility or control. cloud.google.com/blog/topics…
1
286
Bad actors are straight‑up ghosting your EDR by using Windows internals folks rarely monitor. No SYSTEM, no write‑to‑disk, just NtOpenKeyEx + SeBackupPrivilege + RegQueryMultipleValuesW = creds exfiltration in stealth mode. #Cybersecurity #EDRevasion
72