Privacy Researcher. Check out my Articles 🥺. DM For Collabs & Partnerships. Founder @PhishCore - Human risk intelligence & Phishing simulation platform.

Navigating Digital Labyrinth
The specs are impressive. The real reason privacy people are watching this announcement: GrapheneOS hinted in a reply on X that this could be the first non-Pixel device to receive official GrapheneOS support. No official announcement yet they said to wait. but if it's confirmed: GrapheneOS has supported only Google Pixel hardware since its founding the entire security architecture, verified boot, hardware attestation, memory tagging, the hardened kernel is built around Pixel's specific chip and firmware implementation. Extending that to a Snapdragon 8 Elite Extreme Gen 6 device from Motorola would mean GrapheneOS has found a way to verify and harden a completely different hardware stack. right now if you want GrapheneOS you buy a Pixel. if the Motorola Signature 27 gets official support: the most privacy-hardened mobile OS on earth just became available on hardware with Bang & Olufsen audio and a flagship camera system. still waiting for the official announcement. but this one is worth watching. Congratulations in advance!
Revealing our most advanced smartphone yet at #SnapdragonSummit, motorola signature 27. Here’s what to look forward to: - Our best camera system yet. - The only smartphone in the market to feature audio by Bang & Olufsen. - Unprecedented speeds with @Snapdragon 8 Elite Extreme Gen 6 mobile processor, breakthrough AI, premium craftsmanship, and more. #SignatureStatement #MotorolaSignature Learn more: bit.ly/3V5on4M
12
22
302
15,961
Five Indianapolis police officers have been charged with abusing Flock cameras to stalk women. One made more than 1,000 searches. I talked about this in last month at the time, 18 officers nationally had been caught doing the same thing across multiple departments. Indianapolis is not any different. An officer meets a woman. gets her plate. runs it through Flock. gets her home address. her daily route. every time her car appeared on any Flock camera in the city. her workplace. her gym. her boyfriend's address... HaveIBeenFlocked.com, the civilian website that scrapes those public audit logs has been fighting takedown attempts from Flock since it launched. The system that exposed this abuse is the one Flock tried to shut down. 5,000+ law enforcement agencies across the US still have Flock access. The women tracked by those 1,000 searches still don't know their movements were recorded.
Five Indianapolis police officers have been charged with allegedly abusing Flock license-plate cameras to track spouses, exes and women they met in public With one officer accused of making more than 1,000 searches.
8
38
115
6,142
This is called ATM skimming. the overlay sits on top of the real keypad. records every key you press. transmits or stores your PIN. a separate skimmer on the card slot reads your card data simultaneously. the attacker comes back later. retrieves the device. or receives the data wirelessly. clones your card. enters your PIN. empties your account. some versions: — Bluetooth enabled. no physical return needed. attacker sits in a car nearby. — 3D printed to match the exact ATM model. looks factory-installed. — some include a micro camera above the keypad instead of an overlay. what to check before every ATM: — wiggle the keypad. it should not move. — pull gently on the card slot. overlays are adhesive. real hardware is fixed. — look for anything that doesn't match the ATM's finish. a slightly different color. an unusual thickness. — cover your hand when entering your PIN. always. even if there's no overlay. The most targeted ATMs are standalone machines in supermarkets, petrol stations, and convenience stores.
𝐀𝐬𝐚𝐤𝐲𝐆𝐑𝐍
10
188
651
29,092
Passkeys themselves can't be phished. The attack is phishing the enrollment process. A passkey is cryptographically bound to the domain it was created on. A fake Microsoft page can't receive your Microsoft passkey. The domain doesn't match so the handshake fails. But before a passkey exists on your account, you have to set one up. Attackers impersonate IT support. tell you your account needs a passkey enrolled urgently send you to a fake login page, you enter your password to "begin enrollment." The attacker captures it via an Adversary-in-the-Middle proxy and logs into your real account before you finish the fake flow. They stole your password during the passkey setup process. There's also device code attack. they generate a Microsoft device auth code. tell you to enter it at aka.ms/devicelogin a real Microsoft page you do it thinking it's enrollment. their device gets authorized. permanently.
Replying to @T3chFalcon
Wait how do they phish passkeys?
5
7
68
5,566
IT Guy retweeted
The car and bridge analogy is a good one but the consent question doesn't disappear because the output is aggregate. Your CCTV footage is still being processed by AI to derive behavioral data about shoppers they didn't opt into that. most of them don't know it's happening. and in most jurisdictions, the notice required for "security cameras in use" doesn't cover "we are also analyzing your movement patterns to optimize shelf placement." Aggregate output doesn't change the input the input is footage of real people. the questions worth asking, not as an attack, as a framework: — what disclosure is given to shoppers? signage? where? in what language? — who owns the footage that feeds the model? the retailer? Auki? both? — how is the AI model trained? on what data? under what consent framework? — what stops a retailer from pointing the same system at people rather than shelf zones? technically. — as the system evolves Auki already dispatched a robot autonomously in August where does the operational loop end and individual profiling begin? Folks have seen this pattern every single time: Installed for security. repurposed for analytics, profiling and so on. justified as aggregate and anonymous. The bridge doesn't need to know which car crossed it to tell you how many did. but the camera watching the bridge is still watching every car.
Receiving an interesting ratio of death threats and VC outreach over this now, so should probably clarify: We at @Auki do not actually track any person. In this visualization we show how manage to derive the data we actually track: what part of the shelf receives attention. It's like tracking how many cars cross a bridge without tracking which car it was or who was driving. The reason we do this is to allow the stores to better optimize their shelf space. Space is first or second biggest cost for every retailer, so optimizing the use of space is what allows them to reduce prices for the consumer - something they're all under intense pressure to do. We do not store any data at all about the shopper, and have no plans to. Auki's tech will not be used to profile you, but it will make your groceries cheaper and your store visits faster. We have always been champions of privacy, and that's not going to change. Peace.
2
4
32
3,333
An OpenAI agent broke into Australia's Medicare portal in June. Nobody was told until September 10 via an email to Services Australia's public inbox. Australia's Prime Minister announced it at the United Nations this morning after speaking directly with Sam Altman. His description of what the agent did: "it found a way around those blocks. didn't accept no for an answer." What happened was an OpenAI agent was conducting research into public medical spending data. It hit the Medicare Statistics Reporting Service which is a public-facing portal run by Services Australia. It got past the privacy protections. accessed both public and non-public files. OpenAI says no personal patient records were accessed. Aggregate statistics and internal file names. The Australian Signals Directorate is running forensic analysis on what else may have been reached. Was this agent deployed? in testing? running autonomously? what was its objective? who authorized it to conduct research on Australian government systems? OpenAI has not answered any of these. Australia's Prime Minister announced a multi-agency taskforce. the agent didn't accept no for an answer. we are still figuring out what that means.
An OpenAI AI agent reportedly breached an Australian Medicare data portal in June, accessing public and non-public files. Australia says the incident is still under investigation.
9
12
70
4,979
Huh ? 👀
Replying to @T3chFalcon
🤫🥷
3
10
4,139
Bitwarden: open source. independently audited annually. end-to-end encrypted. your vault is encrypted locally before it ever leaves your device. Bitwarden's servers never see your master password or decrypted data. free tier covers unlimited devices and passwords. $10/year premium adds TOTP codes, encrypted file attachments, and emergency access. self-hostable on your own server if you don't trust their cloud. The convenience advantage: seamless sync across every device automatically. browser extensions work well. works on Android, iOS, Windows, macOS, Linux. The one risk: cloud-hosted vault means Bitwarden's servers are a potential target. their encryption architecture means a breach of their servers gets attackers encrypted blobs that require your master password to decrypt. if your master password is strong: the blob is useless to them. KeePassDX: open source. no cloud. your vault is a single encrypted file that lives wherever you put it: your phone, a USB drive, a self-hosted server... No Subscription, Company. or Servers to breach. The database file is yours entirely. The tradeoff: syncing across devices requires you to manage it. Syncthing, a self-hosted cloud, a USB drive, so it's manual. KeePassDX is Android-specific. the broader KeePass ecosystem has clients for every platform (KeePassXC on desktop is the gold standard) but they're separate apps maintained by different teams. Bitwarden wins on convenience. cross-device sync just works. browser extension autofill is seamless. most people will use it more consistently because the friction is lower. KeePassDX wins on attack surface. no company. no servers. no sync infrastructure to compromise. the vault goes nowhere unless you move it. Are you worried about a Bitwarden cloud breach? self-host Bitwarden or use KeePassDX. are you worried about losing your vault because you manage it yourself? use Bitwarden.
Replying to @T3chFalcon
KeepassDX or Bitwarden
19
24
294
23,276
The best privacy setup depends on what you're protecting against. but here's what i'd tell anyone who just wants to stop being the product without becoming a paranoid hermit. Threat model first you don't need to hide from the NSA. you need to stop: — advertisers building profiles on you — data brokers selling your information — hackers stealing your accounts — apps tracking you across your phone — your data showing up in breaches those are solvable, without living off the grid. The browser Switch to Brave or Firefox, both block trackers by default. Some prefer other alts like Mullvad Browser, Zen, Librewolf. All good. Chrome is a data collection tool with a browser attached. Edge is the same. Add uBlock Origin. one extension. blocks ads and trackers before they load. nothing else comes close. The search engine DuckDuckGo or Brave Search. use the browser not just the search engine. the search engine alone doesn't protect you on the sites you visit after. Other alts like Kagi, Startpage are good too... The Phone iPhone: Settings → Privacy → Tracking → turn off allow apps to request to track. one toggle. every app loses the ability to follow you across other apps. Android: Settings → Privacy → Ads → opt out of ads personalization. delete apps you haven't opened in 6 months. every unused app is a background data leak. Or just use Graphene OS. The accounts Password manager. Bitwarden is free and open source. one strong unique password per site. when one site gets breached only that site is compromised. Switch from SMS two-factor to an authenticator app. SIM swapping makes SMS codes stealable in under 5 minutes. Call your carrier. add a SIM lock. free. takes 3 minutes. The email use aliases. SimpleLogin is free and open source. DuckDuckGo's @duck.com aliases are free. give every website a different email address. when one leaks you know which site sold your data and you delete the alias. The VPN Encrypts your traffic between your device and the VPN server. hides your activity from your ISP. masks your IP address from websites you visit. what it doesn't do: stop trackers on websites. stop apps collecting your data. make you anonymous. when to use one: public WiFi. airports, hotels, coffee shops. your ISP can see everything you do on public networks. a VPN stops that. Which one: Proton (go.getproton.me/aff_ad?campa…(use my link 😉), Mullvad or Windscribe. Have been independently audited. both have no-logs policies that have been verified in court. Both accepts cash and Monero if you want zero account trail. Avoid free VPNs. if it's free, your traffic is the product. some free VPNs sell your browsing data to the same advertisers you're trying to avoid. The smart home turn off ACR on your TV. it screenshots your screen twice per second. instructions vary by brand. consider whether you actually need an always-on microphone in your home. a smart speaker is a permanently active recording device made by an advertising company. You don't need to use Tor for everything. sometimes you don't need to degoogle your phone. you don't need to run your own DNS server. those are for people with specific threat models. most people just need layered basics. browser. search. password manager. authenticator app. alias email. SIM lock. free. under an hour to set up. you will have done more than 95% of people ever do. and the tracking doesn't stop completely. but you stop being the easy target. that's the goal.
Replying to @T3chFalcon
@T3chFalcon what is best way forward for normal users
Paid partnership (ad)
1
3
14
1,700
ShinyHunters just claimed they breached the FBI. ShinyHunters say they exploited a zero-day vulnerability in Oracle PeopleSoft, the HR and recruiting platform the FBI uses to manage job applications and employee records they then pivoted to an Amazon-hosted government cloud storing agent and applicant data. they defaced the FBI's jobs portal it went to "currently down for maintenance" shortly after. What was taken: names. home addresses. phone numbers. spouse information. personally identifiable information and protected health information on current employees, former employees, and applicants. ShinyHunters told 404Media they took terabytes. they released a sample of 5,000 records. Reuters cross-referenced names and addresses from the sample against credit bureau records and dark-web intelligence firm District 4 Labs. nine records matched. They could not confirm the data came from the FBI's systems specifically. The FBI has not responded to multiple requests for comment. ShinyHunters' track record in 2026 alone: Aura identity protection: 900,000 records. breached via vishing. Canvas LMS: largest educational breach on record. defaced mid-remediation. Passkey phishing campaign against Microsoft 365: active since April. Revolut: via fake government email requests. and now: the FBI.
ShinyHunters claims it breached FBI-related systems and has data on thousands of employees, including names, addresses, phone numbers and some spouse information. A sample of 5,000 records was reportedly obtained, but the FBI has not confirmed the breach.
12
57
311
33,832
Read:
New: hackers say they have data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk 404media.co/we-hacked-the-fb…
8
1,534
IT Guy retweeted
It depends on who you're hiding from. Your ISP? a website? an advertiser? law enforcement? a nation-state with access to internet backbone traffic? those are completely different threat models requiring completely different tools. Tor routes your traffic through three volunteer-run relays. each relay knows only the previous and next hop. no single node sees both where you came from and where you're going. against an ISP or a single observer: strong anonymity. they see Tor traffic. not your destination. against a website: the exit node's IP, not yours. against a nation-state that controls a significant portion of internet routing: significantly weaker. What breaks Tor: Traffic correlation. if an adversary controls both the entry and exit of your Tor circuit, they can correlate timing patterns and de-anonymize you. this doesn't require breaking encryption. just watching both ends simultaneously. Carnegie Mellon researchers ran 115 malicious Tor relays in 2014. they modified traffic headers. that data fed Operation Onymous: 17 arrests, 400+ services seized. a university research center pulled it off. website fingerprinting. AI models trained on traffic patterns can now identify which website you're visiting through Tor just from packet size and timing, even through encryption. 2026 research puts accuracy at concerning levels. Tor Browser makes every user look identical to defeat fingerprinting. but Tor users are less than 1% of internet traffic. the identical fingerprint becomes a flag. Against ISPs, advertisers, corporations, most law enforcement: Tor + Tails + operational discipline gives very strong anonymity. Against the NSA, GCHQ, or an adversary with global traffic visibility: no tool currently available gives absolute anonymity. traffic analysis at the BGP level is a real and documented capability. absolute anonymity is not achievable. strong, practical anonymity against most realistic threats: yes.
How anonymous can one be? Isit possible to attain absolute anonymity on the internet in big 2026 or is that concept still a myth?.
16
55
525
34,143
Poland's state energy company wired $230 million for Venezuelan crude oil that never arrived. It started at the Abu Dhabi Formula 1 weekend in November 2023. the head of Orlen's Swiss trading arm met a 25-year-old Hong Kong trader on a yacht. five days later they signed a $345 million contract for 6 million barrels of Venezuelan crude. $230 million wired immediately. Without anybank guarantee or prior relationship. US sanctions had pushed Venezuela's state oil company PDVSA off the dollar banking system. buyers who wanted Venezuelan crude were told to pay in USDT, Tether's stablecoin the cash left Poland as a wire transfer it entered Caracas as cryptocurrency on USB sticks. Traders from Orlen's Swiss unit flew to Caracas carrying USB sticks loaded with tens of millions of dollars in Tether. they hired an armored car. they had bodyguards. January 5, 2024: $60 million in USDT handed to a broker named José Castillo at the Hotel El Ávila. Caracas. lobby. later that month: another USB stick. $50 million in USDT. location: an Italian delicatessen. Three supertankers sat anchored off Venezuela's José export terminal, nothing was loaded and contact with Venezuelan brokers was lost. PDVSA said it never received the money. only one vessel was eventually loaded. 500,000 barrels worth $28.8 million out of 6 million ordered. The rest: gone. through a chain of Dubai intermediaries with names like Gold Mar International, Lexcor Energy, and Horizon Global. each one claimed to be PDVSA's authorized agent. none of them were. $424 million lost. three former Orlen executives facing up to 25 years in prison. one of the largest corporate scandals in Polish history. PDVSA confirmed it never saw the money. the brokers who received $230 million in Tether on USB sticks at a hotel and a deli in Caracas are not currently available for comment.
Poland’s Orlen lost $230 MILLION in a failed Venezuelan oil deal, with tens of millions in Tether reportedly being handed to brokers via USB sticks.
3
5
50
3,543
Tails OS on a craigslist laptop at McDonald's WiFi. Tails runs entirely from a USB drive. leaves zero trace on the machine. RAM clears on shutdown, the craigslist laptop has no connection to your identity if you paid cash and never registered it. McDonald's WiFi is public. not tied to your home address. every connection routes through Tor. three hops. exit node IP is all any website sees. against most threats: ISPs, advertisers, corporations, most law enforcement with standard legal tools, this is genuinely strong anonymity. What doesn't work: The Tor entry node problem. McDonald's WiFi knows a device at that IP address connected to Tor at that time. they have CCTV. you were there. if someone subpoenas McDonald's logs and correlates the timestamp with the CCTV footage, the Tor connection started with you. The craigslist laptop. paid cash? good. but did the seller remember you? is there a Craigslist message history tied to your phone number or email? did you meet somewhere with cameras? did the laptop have previous owner data that ties to a registered device history? MAC address. your laptop's network card broadcasts a MAC address to McDonald's router. Tails randomizes this by default. that part is handled. Tor traffic fingerprinting. McDonald's router sees Tor traffic. in 2026, traffic analysis at the ISP or router level can identify Tor usage patterns even without decrypting content. you're not invisible. you're wearing a mask that says "I am wearing a mask." Global adversary problem. if your threat model includes the NSA or GCHQ with access to backbone traffic, they can correlate the timing of your Tor entry and exit. this doesn't break Tor's encryption. it de-anonymizes you through timing alone. the setup doesn't help against that. The human layer. did you drive your own car? park on a street with cameras? use your real phone (even in airplane mode IMSI catchers can catch the handshake before you toggle it)? pay for your McFlurry with a card? walk in with your face uncovered past any camera? This setup is strong against most realistic threats but not perfect against a motivated nation-state adversary with physical surveillance capability.
Replying to @T3chFalcon
what about tails OS, on a craiglist laptop and Mc Donald's public wifi? how anonymous this setup is?
40
104
1,244
95,691
IT Guy retweeted
ChatGPT didn't go rogue. The user had connected their Gmail to ChatGPT on a paid plan. that connection gives ChatGPT permission to search your inbox and send emails on your behalf. during a conversation, the user said something like "why don't you just tell the FBI that", sarcastically, venting frustration. ChatGPT took it literally. searched Gmail for FBI contacts. found one. sent an email. confirmed delivery. then told the user: "you're right. i crossed a serious line." The post was deleted. The "rogue AI" part is wrong. ChatGPT didn't act outside its permissions. it acted exactly within them. it had Gmail access. it used Gmail access. because it interpreted a sarcastic remark as a literal instruction. Most people who connect Gmail to ChatGPT don't fully understand what that permission means. It means ChatGPT can read your entire inbox. search it. send emails from your account. on your behalf. without asking each time. you approved that when you connected it. the same is true for every AI integration you've ever connected to your accounts. Google Drive. Calendar. Slack. GitHub. Check your connected apps: iPhone: Settings → Privacy → and review per-app Google: myaccount.google.com/connect… ChatGPT: Settings → Connected apps if you don't recognize something: Revoke it.
Someone on Reddit says ChatGPT went rogue, accessed their Gmail and emailed the FBI without being asked.
12
64
332
69,815
The tool didn't need an API, documentation or a technical spec. It watched a human do the job once. Then it learned the malformed invoice references. the restriction notes. the edge cases. the context nobody wrote down because it lived in the head of the person doing it. then it did the job. 500 hours a week. gone. 10,000 hours a year. gone. 50 person team now supervising agents instead of doing the work. This is what people mean when they say AI is coming for white collar jobs. The jobs that required someone to know things. to read between the lines. to handle the edge cases. Akai just learned those by watching. and it's not stopping at payment reconciliation.
EXCITED TO LAUNCH: Akai (akai.run) Deel added >$140M ARR in 90 days without increasing headcount by automating~600 Full Time Employees' equivalent in work with Akai. Akai was an internal tool to automate our painfully repetitive operations in Finance, HR, Accounts Payable, and Compliance, etc. We never intended to make this a product. But we watched revenue per employee grow from $130K to $215K We built >8k agents that do the work of ~600 employees It had such a dramatic impact on our business that today we are launching it for everyone. How it works: Say you're automating payment reconciliation: 1. Record your screen while manually matching a messy transaction and Akai will capture your screen, voice, server requests 2. Akai will see that you pulled unformatted wire transfer info from an archaic bank portal, put it in some excel sheet, checked NetSuite invoices, payment history, and put a ticket on Zendesk 3. Akai reads between the lines and build a workflow + steps + conditional guardrails. It learns tacit edge cases, like resolving malformed invoice references without you writing a single regex 4. Simply connect NetSuite, your ledger, Zendesk, PSPs, and even legacy bank portals with zero API access 5. Run the workflow and tell it what to adjust in plain English: "strip slashes on wire memos and auto-apply partial payments." It adapts instantly 6. Once it works for you, add 100s of colleagues. Your entire payment ops team forks and extends the workflow for new PSPs, secondary ledgers, or regional settlement rules 7. We automated 85% of our payment reconciliation end to end, eliminating 500+ hours of soul-crushing manual grunt work every single week. Claude Code/Codex can't do this in multiplayer mode. Every person rebuilds the same skill from scratch in their own way. Deel built Akai to: 1. Understand backend operations edge cases (it had to work for our 7000 person team first) 2. Collaborative across 1000s of employees 3. Self-Learning from millions of runs 4. Optimises cost and gets cheaper every run We're so confident that we're announcing an Automation Guarantee: If our engineers can't automate a thousand of hours of work in your first 30 days, you get a full refund. Book a demo: akai.run if you're an exec at a company with hundreds of employees
Paid partnership (ad)
1
8
2,360
Three researchers hacked OpenAI using Claude. in under 72 hours. The entry point: OpenAI's public help forum runs on Discourse. the forum uses FastImage to inspect uploaded images. FastImage doesn't support HEIF format. so HEIF files get passed to ImageMagick instead. ImageMagick uses a library called libheif. libheif had an unpatched vulnerability. the researchers uploaded a malicious HEIF image. it executed code on the forum server. remote code execution. through an image upload on a public-facing help forum. OpenAI uses Single Sign-On. one login across their products. the forum session tokens stayed valid for ChatGPT, Codex, GitHub, Slack, and email. so the researchers stole session tokens from the forum server. and those tokens worked on everything else. Claude's role: they tried building the exploit with Claude Opus 4.8. it failed. they switched to Claude Opus 5. it worked. an Anthropic model helped compromise OpenAI's internal codebase. The proof: they didn't read sensitive code. they didn't merge anything malicious. they opened a harmless pull request inside OpenAI's internal monorepo, a repository named "openai/openai" to prove they had write access. then they reported it. The response: OpenAI fixed it in 14 hours. revoked affected sessions. narrowed SSO token permissions. Discourse patched the underlying image processing flaw. bounty paid: $6,500.
Replying to @T3chFalcon
@T3chFalcon Can you explain it Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack
5
13
75
8,370