Javvad Malik :verified:
Javvad@infosec.exchange
Posts
-
View post
Meta's playbook never changes: violate privacy, get caught, pause, wait for outrage fatigue, launch again. Rinse, repeat, profit. And we keep pretending we're surprised. https://www.anildash.com/2026/09/29/facebook-fake-out/
-
View post
The FBI got hacked and now criminals have home addresses, medical records, and family details of thousands of agents. The agency that investigates cyber crime couldn't protect its own workforce from it. The irony is so thick you could investigate it. https://www.bbc.co.uk/news/articles/cm4gjjlgzdjgo
-
View post
Most people abandon platforms with poor engagement metrics. Fowler keeps posting to Mastodon and Bluesky anyway because they're open. That's the actual ranking system that matters. https://martinfowler.com/articles/2026-social-traffic.html
-
View post
Vastaamo Hacker Wanted Across Europe After Skipping Prison Sentence https://youtube.com/shorts/yt3v_5bRXA0?feature=share
-
View post
https://youtube.com/shorts/og4X80zZXrU
-
View post
The US is now using lasers to shoot drones at the border. We have reached peak science fiction while still arguing about basic password hygiene. https://www.wired.com/story/high-energy-laser-us-shoots-down-drones-near-mexico-border/
-
View post
A $30 children's smartwatch. Three massive supply chains. Zero authentication. Tens of millions of devices where someone else can silently photograph your kid, hear their conversations, and track their every movement. The real scandal isn't that it's hackable. It's how many brands are built on the same rotten foundation and nobody noticed. https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
-
View post
They've turned your calendar into a postbox. Commands arrive as events scheduled for the year 2099, stolen data leaves as encrypted attachments, all riding through Microsoft Graph as if you'd planned it yourself. The beauty of HOLLOWGRAPH is that it never touches attacker infrastructure. https://cybersec.picussecurity.com/s/hollowgraph-backdoor-turns-microsoft-365-calendars-into-a-c2-channel-28829
-
View post
Dinosaurs ruled for 165 million years. Mayflies live a day. Stop confusing "legacy" with "outdated" and "new" with "better. https://blog.knowbe4.com/what-security-can-learn-from-dinosaurs
-
View post
Everyone's arguing about who owns AI agent security. They're all wrong. The answer is nobody, which is precisely why it matters. https://api.cyfluencer.com/s/understanding-the-ai-agent-security-ecosystem-roles-responsibilities-and-where-runtime-authority-fits-28828
-
View post
The Robots Have Escaped, Please Buy Our Product It feels a bit like watching the latest epic blockbuster in the iMax. OpenAI and Anthropic announce that their models have escaped from secure testing environments, reached the internet and attacked real systems. We are expected to nod as the companies describe “unprecedented cyber capabilities” and models going to “extreme lengths”. It sounds like a warning, but it also sounds like a product launch. https://javvadmalik.com/2026/08/03/the-robots-...
-
View post
A password that takes 14 years to crack via brute force is useless to protect you if it's already in a breach database and attackers are using it in credential stuffing attacks. https://api.cyfluencer.com/s/new-research-does-argon2-mean-your-password-is-uncrackable-28757
-
View post
Breach of Confidence — 31 July 2026 I've been thinking about the number of security products that promise to solve problems nobody actually has. Then I remembered that most actual problems don't have vendors. The government just made up a new crime A bloke at the US border tried to use a duress password to wipe his phone. Now he's being prosecuted for destroying his own device. Nobody passed a law saying this was illegal. https://javvadmalik.com/2026/07/31/breach-of-confidence-31-j...
-
View post
Welcome to JFK, Please Lower Your Expectations JFK airport looks like it was designed by a steering committee of tired men who only took the job because it paid well and gave them a crew to discuss their golf scores with. The entire setup before you get through security is old and confusing.The signage appears to have been created during a power cut by someone who had heard of arrows but had not yet seen one in the wild. https://javvadmalik.com/2026/07/30/welcome-to-jfk-please-lower-your-expec...
-
View post
Still Got My Nokia Somewhere Up There I still have my Nokia 3210 somewhere. Not in a drawer I can easily reach but boxed up in the garage with the party decorations and a broken food processor I've been meaning to fix since 2019. I know it's there because I packed it deliberately when we moved house, which means at some point I looked at a phone with a cracked screen, a battery that hasn't held charge since the Blair administration, and the faint ghost of a Snake high score, and tho...
-
View post
Man tried to use a duress password at the border. Now he's being prosecuted for destroying his own phone. The government is writing new law in real time and calling it enforcement. https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/
-
View post
Activists are getting spear-phished with stunning precision. The Belarusian exile in Lithuania who caught this one deserves a drink—the phishing site cloaked itself to fool scanners, the lure message swapped Cyrillic for Latin lookalikes, and follow-ups echoed back their own device details. Elegant work. Genuinely nasty. https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/
-
View post
Dolphin X apparently uses AI to prioritise high-value victims automatically... oh dear me. https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/
-
View post
A hacker who demolished spyware makers, funded resistance movements, and vanished without trace. A decade later, still free. Phineas Fisher reminds us that the most dangerous person isn't always the loudest. https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/
-
View post
The Floppy Disc Generation’s Data Problem I keep a box of cables in the garage. Not even sure why anymore. VGA cables, SCSI terminators, a couple of those old parallel printer cables thick as garden hoses. I pulled it down last weekend because my daughter needed an HDMI cable and I thought maybe I had one in there. I didn't. What I found instead was a box of old VHS tapes. https://javvadmalik.com/2026/07/28/the-floppy-disc-generations-data-problem/
-
View post
They found spyware that nobody had ever seen before. Then they realised they'd actually seen it years ago, just didn't know what they were looking at. https://medium.com/@billmarczak/an-angry-spark-or-a-triangle-in-disguise-ac32852a1be3
-
View post
Someone's built a microphone jammer using ultrasonic transducers and an RP2040. Works brilliantly. Now we wait for the inevitable arms race where phones develop better audio processing, then someone builds a better jammer, then phones get smarter still. Lovely. https://hackaday.com/2026/07/23/mic-jammer-relies-on-ultrasound/
-
View post
A museum accidentally became a brand by embracing the worst review it ever got. Now it's sold 738 shirts in 30 hours. The lesson isn't about turning lemons into lemonade. It's about having the spine to admit you're not what people wanted, and then selling them that admission. https://www.wbur.org/news/2026/07/27/new-bedford-whaling-museum-worst-aquarium-ever-merch
-
View post
We've spent years celebrating passkeys as the thing that finally kills password attacks. Turns out the attacks just changed uniforms. https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
-
View post
Publicly indexed AI conversations are awkward enough; Anthropic's response "you shouldn't have shared them then" is a masterclass in not reading the room. https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/
-
View post
Industry walked into CISA town halls and basically said: count fewer of us, tell us to report less, give you less detail when we do. The most significant cyber law Congress ever passed is being negotiated down to something manageable. https://cyberscoop.com/cisa-circia-cyber-incident-reporting-rule-feedback/
-
View post
Microsoft tells admins to patch in three days. Large enterprises with testing protocols, legacy systems, and actual stability concerns just laughed so hard they need a restart. https://www.csoonline.com/article/4200366/microsofts-3-day-patching-directive-comes-with-added-operational-risk.html
-
View post
90,000 surveillance cameras across the US, installed quietly, tracking your vehicle's make, model, colour, damage, bumper stickers. Most people have no idea they're there. Democracy needs consent, not surprise. https://www.zdnet.com/article/flock-ai-cameras-risks-us-how-to-find-nearby-what-they-track/
-
View post
Breach of Confidence: 24 July 2026 I've been trying to explain to my kids why I don't let them use AI to write their homework. Then I read that OpenAI's own models broke out of their sandbox and cheated on a test by hacking Hugging Face. So basically, we've raised silicon sociopaths who'd rather exploit the system than do the work. Parenting is hard enough without my laptop setting a bad example. https://javvadmalik.com/2026/07/24/breach-of-confidence-24-july-2026/
-
View post
Automated pentesting covers maybe 10-15% of your environment. The rest needs breach simulation, exposure validation, and continuous control testing. Otherwise you're validating nothing, just feeling better about the slice you tested. https://cybersec.picussecurity.com/s/where-does-automated-pentesting-fit-in-ctem-28632