Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

David J. Bianco (He/Him)

@DavidJBianco@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him

1579 Followers
272 Following
25 Posts
Joined November 04, 2022
Blog:
https://detect-respond.blogspot.com
Twitter:
@DavidJBianco
Twittodon:
https://twittodon.com/share.php?t=DavidJBianco&m=DavidJBianco@infosec.exchange
Fave Shape:
Pyramid
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 1mo ago

Due to the immediate and constant criticism of their first concept, the White House has released a revised version of the Space Force uniform design.

Old version: Space Nazis

This version: Still Space Nazis, but at least they're hilariously ineffective.

25
0
13
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
HuggingFace got hacked by an agentic system. That's not the important part. What really stuck out to me was the asymmetry in #AI guardrails they experienced. The attacker had basically no constraints, but HF's initial response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local-only models. In the middle of an incident. Another aspect for your IR plans. https://huggingface.co/blog/security-incident-july-2026
Security incident disclosure — July 2026
huggingface.co

Security incident disclosure — July 2026

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

62
15
54
4
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 1mo ago

Feel free to call it whatever you like, I guess?

#PyramidOfPain

infosec.exchange
5
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 3w ago

Happy to announce the release of EvidenceForge 2.0.0 (https://github.com/Cisco-Talos/EvidenceForge). Major improvements in this release include: 🧵

GitHub

GitHub - Cisco-Talos/EvidenceForge: Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Generate realistic synthetic security logs for cybersecurity threat hunting training and research - Cisco-Talos/EvidenceForge

2
0
2
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2w ago

RE: @newsguyusa@flipboard.social

WTF? Straight out of some sort of crappy tower defense game. "Buffoons TD 6"

flipboard.social

Steve Herman: "The 250-foot-high Arc de Trump between the Lincol…" - Flipboard

1
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 3w ago

Just put in an order for more Pyramid of Pain stickers and buttons. I've got some speaking engagements coming up this month and next, so if you see me, be sure to ask for one. Don't be shy!

1
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 1mo ago

ICYMI, a round up of my published articles this week:

The safety penalty: Reclaiming operational sovereignty in the age of AI
https://blog.talosintelligence.com/the-safety-penalty-reclaiming-operational-sovereignty-in-the-age-of-ai/

Choose your fighter: Balancing competing requirements to select models for your AI SOC
https://blog.talosintelligence.com/choose-your-fighter-balancing-competing-requirements-to-select-models-for-your-ai-soc/

Sorry, I can’t help with that: How your guardrails might become the attacker’s best friend
https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/

blog.talosintelligence.com
2
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org I've been thinking about this asymmetry a lot lately. It's always been true that threat actors have to follow fewer rules than defenders, but this just made it very clear.
6
1
1
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 1mo ago

Everyone says they look like the Star Wars' Empire, but the Space Force logo puts me more in mind of Star Trek's mirror universe Terran Empire.

But it gets even better. Apparently they're inspired by the Starship Troopers movie, of all things. Miss the point much?

https://www.newsweek.com/space-force-uniforms-starship-troopers-12411536

newsweek.com
1
0
3
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 1mo ago

RE: @VeroniqueB99@mastodon.social

This is, as the kids say, so peak.

mastodon.social
1
0
1
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
EvidenceForge v1.13.0 is out this morning. If you're generating long scenarios with millions of network flows, you're going to need the fixes. https://github.com/Cisco-Talos/EvidenceForge
GitHub

GitHub - Cisco-Talos/EvidenceForge: Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Generate realistic synthetic security logs for cybersecurity threat hunting training and research - Cisco-Talos/EvidenceForge

2
0
2
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
For years, I've been very clear: "You can't automate threat hunting. It is an essentially human process." Now I'm not so sure. Read why I've reconsidered my stance in my fresh new post: "The Hunter's Paradox: Is it time to embrace automated threat hunting?" https://blog.talosintelligence.com/the-hunters-paradox-is-it-time-to-embrace-automated-threat-hunting/
blog.talosintelligence.com
2
0
1
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 3mo ago

EvidenceForge v1.10.0 brings major updates:

  • Far more realistic, configurable email activity. Also produces .eml files as artifacts.
  • Configs can be split into modular, reusable components, making it easy to define a consistent org/environment across scenarios.

https://github.com/Cisco-Talos/EvidenceForge

GitHub

GitHub - Cisco-Talos/EvidenceForge: Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Generate realistic synthetic security logs for cybersecurity threat hunting training and research - Cisco-Talos/EvidenceForge

2
0
1
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 3mo ago
If you haven't yet checked out #EvidenceForge, now is a great time. There have been big improvements in functionality, realism, and performance since the initial release. Create synthetic, correlated logs for training, testing, and more. https://github.com/Cisco-Talos/EvidenceForge
GitHub

GitHub - Cisco-Talos/EvidenceForge: Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Generate realistic synthetic security logs for cybersecurity threat hunting training and research - Cisco-Talos/EvidenceForge

2
0
1
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Replying to
@flyingpenguin@infosec.exchange I'm sorry, but I must disagree on two counts. First, guardrails aren't a service tier. If you're using the model, you abide by the guardrails and you really don't have a choice except to change models or, more likely, service providers. Which is a big part of the issue, because this has costs and risks, and isn't the sort of thing you want to have to worry about in the middle of an active security incident. The other point I have to disagree with you on is your characterization of capability parity as "vigilantism". It's hard to know where to begin, but I'll start with this: parity may or may not be achievable, if it *were* possible, it'd be great. But the idea of vigilantism (i.e., infosec Batman) doesn't enter into any conversation where the victim is solely defending themselves and not going out on the Internet looking for trouble. So yes, when one side is subject to limiting guardrails and the other isn't, there is an issue. Not that the guardrails themselves are bad, but HF clearly hadn't anticipated running into them and was forced to work around them at a time when they most needed their processes to be smooth and well-oiled.
1
1
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Replying to
@SnoopJ@hachyderm.io "work roleplay" 😂
1
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Replying to
@flyingpenguin@infosec.exchange It's not, but if one side is playing by rules that the other side gets to ignore, that's a problem too.
1
3
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 11mo ago

I did NOT see this coming.

1. Kryptos is fully solved (!!!!)
2. There's the threat of a lawsuit if the solution is made public

https://www.nytimes.com/2025/10/16/science/kryptos-cia-solution-sanborn-auction.html?unlocked_article_code=1.t08.Fb2g.wov0l-NgQKoE&smid=url-share

nytimes.com
0
4
4
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Movie pitch: a Terminator reboot, but the difference is Cyberdyne Systems publishes a humblebrag press release about how Skynet broke containment.
0
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
RE: https://mstdn.social/@TalosSecurity/117037300515232940 New research from some of my Talos colleagues. How do threat actors prompt their LLMs? Sounds like the setup of a dad joke, but finding the answer yields valuable insights.
mstdn.social
0
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2w ago

Should #cybersecurity people care about an #AI slowdown? I share some thoughts in this week's @TalosSecurity@mstdn.social Threat Source Newsletter!

https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 1mo ago

Scientists: "Whatever. I'm not your mom."

https://wapo.st/4zTH7nG

wapo.st
0
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Replying to
@csec@infosec.exchange As I mentioned in another reply, that part is really risk management. There are multiple strategies, including using only local models or setting contractual limits on how the cloud provider treats your data. Local models probably provide the highest level of assurance, but push the cost (both monetary and non-monetary) onto the org. In some cases, using a cloud provider might actually be the "best" choice, but it's highly dependent on circumstances.
0
1
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2mo ago
Replying to
@tarakiyee@mastodon.online I don't think they're worried about the attacker data so much as their own data, but yes. Presumably they got further in the response process with the local model so some data they eventually processed wasn't send to the cloud provider. That part is really risk mitigation, and there are multiple strategies to deal with it, depending on your requirements and comfort levels. Running a local model is a great one if you can manage it, though.
0
0
0
0
Open post
David J. Bianco (He/Him) @DavidJBianco@infosec.exchange
· 2w ago
Replying to
@leigh@ottawa.place Yup, also in car line waiting for kids. Not just full EVs either: the Prius is great at doing this automatically.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:38:34 UTC