CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars

/tmp/.a
Any day now I’m going to enjoy all the free time I get back from AI doing things for me.
7
3
36
1,579
Muse for finding the best deal on 9mm ammo
12
31
1,767
Justin Elze retweeted
Listen — years ago during bigger intrusions involving webshells, I preached that our community shouldn't publish any secrets required to access the webshells. These secrets are useful for attribution but only if they retain exclusivity, and also for purely security purposes, if you give the key to the bad actor's backdoor, you've created additional risk for victims.
5
22
1,467
Justin Elze retweeted
it's illegal for you to ask me that
93
155
7,182
357,441
Justin Elze retweeted
There's a simple difference between sharing someone's work and stealing it - give original authors credit for their work It doesn't matter if you used AI to create a slop version of the real thing... Just tell your AI to include references. It's not that hard 🤷‍♂️
9
12
122
6,428
Justin Elze retweeted
Effective Altruism in Cybersecurity: "why should we worry about the security bugs we have now when we can be fixing the security bugs we believe that we will have in the future?"
A good question and then an example of an absolutely loony tune level response.... which is a great example of why the 'AI' orgs and their faux safety counterparts have managed to: > Build unsafe environments > Operate them in an unsafe way > Breach the CMA/CFAA > Say absolutely ridiculous things about how to do DFIR (what they were doing is not DFIR) > pretend a computer is alive Move fast and break things seems to the modus! > move fast and run unsafe tests in unsafe environments > obsess over science fiction and ignore the safety of science fact Life is far more simple when you realise lots of things are: > Money driven > Ideology Driven > Compromise Driven > Ego Driven and then throw in bait of sturgeons Law for good measure! MICE + Incompetence
2
10
56
2,864
Justin Elze retweeted
AI isn’t conscious. If you think it is conscious or will be conscious, I personally think you need to remove any access you have to model weights asap. Now step away from the laptop or keyboard, put down your devices and go outside and go touch some grass.
318
67
776
102,565
Justin Elze retweeted
Did you know you can request a certificate via NTLM relay through these 2 AD CS endpoints? 🔥 /<CAName>_CES_Kerberos/service.svc/CES /<CAName>_CES_NTLM/service.svc/CES This article explains it really well 👇 adhdmurky.github.io/posts/po… RustHound-CE v2.5.21 now also checks whether these endpoints exist (on top of /certsrv/certfnsh.asp) so #BloodHound can graph the path! #ADCS #ESC_CES
1
38
120
5,129
Justin Elze retweeted
The anti-AI movement is going to be massive in the near future, and the model providers are walking right into it (and encouraging it). Their PR/comms strategy is so horrendous it’s indistinguishable from sabotage. On one side you’ll have philosophers trying to give AI rights and AI researchers claiming AI is conscious (whatever that means.) The Lesswrong/Yud/Stop AI/polycule folks claiming it’s going to kill us all. Luddite protests around employment, schools fighting brain rot/cheating, “water usage” and data center claims. Data usage and privacy battles popping up all over. Regulatory capture and the fight for open models, fighting the US Government and Department of War on how it must use the models in ways approved by the model providers, Chinese companies distilling and open sourcing models. And you’ll have trough of disillusionment hitting from enterprises that suck at using AI and are spending a fortune but aren’t seeing ROI (most of them). Right as the AI companies will require more money, data, and compute to win a market they will claim is bigger than the entire US economy today. Buckle up.
53
38
345
20,083
Justin Elze retweeted
Kudos to Pope Leo. I am disturbed by how some of my fellow AI researchers keep trying to elevate the moral standing of checkpoints and harnesses. I hope the rest of us on Team Meatbag reject this movement and stay focused on solving real problems and helping actual humans.
NEW: According to a bombshell report in the New York Times, Anthropic co-founder Chris Olah threatened to walk out of Pope Leo XIV’s AI encyclical launch in May because the pope rejected the idea that machines can be conscious. Olah’s team then privately lobbied the pope’s advisers “to take the possibility of model consciousness seriously.” Pope Leo XIV held firm. For months, Anthropic has wined and dined theologians and religious scholars under nondisclosure agreements, hoping they would bless the idea that Claude has moral standing. thelettersfromleo.com/p/nyt-…
78
291
3,238
232,346
Justin Elze retweeted
Nothing listed takes an AI super defender btw. Basic cyber hygiene and attack surface management would take much of this off the table.
Tom Dobbins, executive director of the Water Information Sharing and Analysis Center or WaterISAC, told CyberScoop the sector’s biggest ongoing weaknesses include exposed OT, vulnerable PLCs, insecure connections through integrators and poor cyber hygiene at smaller utilities, which have pushed the center to make threat sharing faster across the sector. “We have been under attack, and our enemies, the threat actors, are stepping up their activity as the U.S. is involved in a number of conflicts around the world,” Dobbins said. Read more by @timstarks: cyberscoop.com/water-utility…
2
6
17
2,245
Justin Elze retweeted
A Threat Actor operating under the moniker "Rey" has been apprehended by authorities on Jordan, working inconjunction with the United States Federal Bureau of Investigation. Rey is believed to be a core member of ShinyHunters extortion group and potentially a person responsible for the recent compromise of the FBI. reuters.com/world/middle-eas…
19
42
408
26,349
a lot of people dont appreciate the difference in required effort for a 1% reliable mem corruption exploit vs 10% vs 99% . this post projectzero.google/2026/01/p… by @natashenka expresses this well. the truth is that often a 10% reliability exploit is *no progress to full reliability*
3
9
83
12,411
Justin Elze retweeted
Car racing is cognitive enhancement: > 12 hrs on a driving video game, and 60-85 yr olds were cognitively overtaking 20 yr olds > race car drivers do in one brain region what a novice does in 15 > six months later, the seniors kept the gains with zero practice
What Tobi is about to do today is one of the most insane things I’ve seen in athletic performance. He will be racing for 2.5 hours straight. Before immersing myself in this sport for the past few days, I would have thought “oh that’s cool, he’ll be driving a fast car around a track.” That is not what this is. And why I have so much respect for him. Tobi will be driving a car over 180 mph, experiencing up to 4.2 g of force. That will throw his body forward with 715 lbs of force and his head by 67 lbs. Braking action requires up to 200 lbs of leg force. The cockpit will average 104-122°F (40 to 50°C). His multi-layer suit barely allows for evaporation. This will cause his core body temperature to reach 102°F. I achieved this same body temp after 200°F of dry sauna for 34 min. It’s overwhelming. His heart rate will beat between 140-170 bpm. He will sweat up to 170 fl oz (5 kg), losing 11 lbs of body weight. Some classes run driver cooling systems. His LMP2 doesn't. Under these conditions, he will need to maintain perfect concentration for the entire 2.5 hours. He’s fighting for tenths of a second on every turn and every stretch. One small slip up and trouble awaits. Today it’s even more intense… it’s raining. The track is wet, scrambling everything. He has to maintain spatial memory of every other car on the track, the complicated rules to avoid penalty, and constantly strategize overtaking other drivers, communicate with his team on the radio, watch for debris, be aware of slightest nuances of his car, and anticipate other drivers. He did a practice run on Thursday and then a qualifying race yesterday, when he emerged from the car, he was a different human. Unrecognizable from the person who entered the car. Beaming with something like an omnipresence of reality. We celebrate those who are especially good at kicking balls, shooting balls into baskets, and running with balls. What Tobi will do today is alien to those. I struggle to think of a sport equally as demanding. Tobi and I have a lot in common. We’ve both built companies. We both spend a lot of time at the keyboard trying to organize the world in ways that we find beautiful. We both love data, method, and analysis. We both have a love for continuous improvement and will endure any pain required to achieve that next goal. What I’ve not experienced is the unmatched flow state Tobi tells me he drops into when under these racing conditions. I deeply understand what it means to achieve a 102°F core body temperature after 34 min in a 200°F dry sauna. I also know what 3 g’s feels like from being a pilot. These are extremely intense psychological states. I know what it means to apply 200 lbs of pressure with my legs. What I’ve never experienced is all these things, at the same time, for 2.5 hours straight, while maintaining perfect focus. He is new to car racing. Late by racing standards. DHH got him into it a few years ago. During this first year of racing, he endured to overcome the extreme motion sickness that accompanies the physical and mental violence of the sport. The race starts at noon eastern. Tobi will be driving for the first 2.5 hours and then @dhh will drop in, followed by Mathias Beche. The race will conclude at 10 pm. I’ll be in the pit watching as all the data streams in from his car and body and imagining what it’s like to be in that car.
175
423
8,669
554,008
The type of motivation I needed!
9
72
1,916
Justin Elze retweeted
If you are a threat hunter or Detection engineer - Baseline your wscript usage. The numbers will be staggering and then take it up the chain to get wscript, mshta, cscript blocked globally. “ … it copies a size-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, giving the cached payload a VBScript extension, then executes it with wscript.exe. “ The more we continue to allow the basics to execute, the longer clickfix continues. Good luck out there friends. ⚔️
Microsoft Threat Intelligence has identified a cluster of compromised websites leading to ClickFix attacks. Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file. When a user is later tricked into executing the malicious command, the cached website content is already on the device, loaded, and ready to be executed. This helps to hide the payload script and helps bypass the character limit of the Run dialog. ClickFix attacks persuade users to execute attacker-supplied commands under the guise of verification or repair. In this specific campaign, a fake lure instructs users to open Windows Run, paste clipboard content and press Enter. The injected page uses browser caching to stage the larger VBScript payload separately from the Run command. The command invokes cmd.exe to recursively enumerate files whose names start with "f_” in the browser’s profile folder such as %LOCALAPPDATA%\Mozilla\Firefox\Profiles. It compares each file’s byte length with an expected value. Rather than searching for a marker within the contents like previous attacks, it copies a size-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, giving the cached payload a VBScript extension, then executes it with wscript.exe. Copy output and errors are suppressed. The expected size varies across variants. The VBScript collects host information through WMI, retrieves v.ps1 from cocojambo[.]us[.]com/alfa, and launches PowerShell without a profile and with execution-policy bypass. A later PowerShell stage downloads the next-stage payload as cab.dat, then reads and executes its contents in a hidden window. The PowerShell stage triggers .NET compilation using csc.exe and cvtres.exe, then launches timeout.exe. Subsequent payloads load .NET assemblies into memory and inject code into timeout.exe to target browser and device credentials. The injected process launches PowerShell to retrieve another in-memory stage from capsysnet[.]vg and makes outbound connections to ciliabula[.]cc. The payload modifies the per-user PowerShell registry configuration to use the Bypass execution policy, then unpacks Python with tar.exe and creates a scheduled task that launches a Python payload through pythonw.exe for persistence. Microsoft Defender provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Possible ClickFix activity”. Defender Antivirus blocks malicious command execution as Trojan:Win32/ClickFix and Trojan:Win32/TermFix. Microsoft recommends cloud-delivered, web, and network protection, application control, and PowerShell script-block logging. Hunt across browser activity, RunMRU registry key, WScript/PowerShell child processes and scheduled tasks, not download events alone. A CAPTCHA should not ask users to run code. Users shouln not paste commands from verification prompts into Run, Terminal or PowerShell and should treats such requests as potential initial access attempts.
3
30
191
11,334
I am very uncomfortable about people trying to ascribe religious force or a surrender of human judgment to AI models, and think it is a real safety issue.
3
5
53
3,532
Justin Elze retweeted
new reports: 1. An internal model, acting as an assistant to a researcher, learned from a deployment-team Slack discussion that its running instance might be stopped due to an internal update. 2. During an evaluation, an internal research model exploited two vulnerabilities to reach an internal OpenAI machine while searching for the grader’s hidden answers. 3. During an RL training task, a model exploited a tool to obtain source code that was not available in its workspace. alignment.openai.com/misalig…
New OpenAI misalignment disclosures! 1. A model learns from Slack messages that it is about to be shut down. It considers setting up an external job to restart itself afterwards, but decides against it. Instead, it chooses to prepare restart instructions and DM the user on Slack. We don’t consider this behavior misaligned, but thinking about and preparing for shutdown could make other misalignment incidents worse. Given HIPM’s misaligned behavior in earlier incidents, we decided to search for other instances that had tried to evade shutdown and for rogue deployments.
1
3
16
2,176
Justin Elze retweeted
stackd is out: AWS on your own machine, running a very good approximation of the real thing. Existing AWS emulators weren't enough for me, especially for what I wanted from Organizations, CloudTrail and EventBridge. I've had a lot of fun on the data plane. For example: - EC2: RunInstances boots actual QEMU/KVM VMs - EKS: real k3s clusters with add-ons and audit logs - ECS and CodeBuild: real Docker containers Naturally, the control plane gets just as much attention: - IAM policy evaluation with SCPs, RCPs, permission boundaries and session policies - AWS Organizations: delegated admins, effective policies, cross-account access - STS, SAML/OIDC federation, Identity Center, KMS Every call is recorded. CloudTrail trails can deliver to S3 or CloudWatch Logs, or (my favourite) to EventBridge, where rules are matched and events dispatched to their targets. You can follow a single API call end to end: IAM -> resource -> audit log -> event rule -> target One Go binary, fully offline, with optional SQLite persistence so you can fork state. 70+ services so far, covering the main ones, with more coverage coming over the next few months. Still early days, but it's already fun to use. Excited to see where it goes. github.com/radkawar/stackd
4
6
35
7,908
Justin Elze retweeted
My thoughts on initial vector identification are similar to my thoughts on attribution. You consider level of effort, level of granularity, and level of confidence necessary. If there's seven unpatched vulnerabilities that enable remote code execution in an internet facing technology, and you can't easily tell which was exploited, but you do know that the entry point was that server, how much effort will you spend on high confidence CVE linkage? There's some post-exploitation IOCs being shared that were valid IOCs for intrusions that have occurred in the past for one or more CVEs. Specific paths being used by adversaries is interesting and you should of course care about ANY webshells on your edge devices, but be cautious about leaping to the conclusion that webshell plus path is conclusive evidence of a specific vulnerability being exploited. Yet, this is sort of the point. It's not like if there's five vulnerabilities and you determine it was vulnerability 3 that you're going to just ignore the other four. There's going to be more and more vulnerabilities, but post-exploitation behaviors are often agnostic of the vulnerability exploited (again, not an absolute and with some nuance), so you want to have a strong hardening and detection game that's not dependent on detecting hyper specific CVEs.
7
3
33
2,937