Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

hakan “:verified:”

@hatr@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Hi there. I. am working as a reporter and covering cybersecurity, mostly I'm interested in APT-related research. I'm with "paper trail media" and Der Spiegel.

If you want to check out the work I'm doing, here are some useful links: https://linktr.ee/hakantanriverdi

1956 Followers
369 Following
20 Posts
Joined November 06, 2022
twitter:
https://twitter.com/hatr/status/1589374562957156352
articles etc.:
linktr.ee/hakantanriverdi
Open post
hakan “:verified:” @hatr@infosec.exchange
· 1mo ago

Bit late to this

"If you optimize a model to find exploits, you should expect it to find them — and prepare for that. OpenAI did not. They built a model, took the safeguards off, gave it the ExploitGym task, let it run, and didn't even monitor it. That's human decision-making."
https://mail.cyberneticforests.com/models-dont-go-rogue/

mail.cyberneticforests.com
5
0
5
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 1mo ago

"The pair said they found more than 15,000 edits carried out by AI agents on a German-language wiki site, DseWiki, that is geared toward programmers and accepts communal edits along ‌the lines of ⁠Wikipedia."

https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/

reuters.com
3
0
1
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 7mo ago

If you're following the situation in Iran, this one is of interest to you.

Today, we're publishing a story that I find very important for many reasons.

We can prove how the regime in Iran is using facial recognition software to surveil its citizens. We have obtained videos showing the software in a live-scenario, at metro stations in Teheran. We have contracts, and we have had a look at the code, built by the Russian company Ntechlab whose algorithms are deemed to be best-in class.

We spoke with a dozen people who know the regime, either because they had to flee after being imprisoned or from a technical point of view.

All of this, and more, you can find in our reporting, #EyesOfIran. Here are the links:

SPIEGEL: https://www.spiegel.de/ausland/iran-so-gnadenlos-spaeht-regime-die-eigene-bevoelkerung-aus-ein-insider-packt-aus-a-7990ef28-3c9d-427b-be9a-5f46d06bea6c?giftToken=7fdb6b96-b2f1-4799-b8ff-e55fed5496d1

Standard: https://www.derstandard.at/story/3000000310751/ein-regime-im-ueberlebensmodus-leak-zeigt-irans-massive-ueberwachung-im-land?ref=niewidget

ZDF: https://www.zdf.de/play/magazine/frontal-das-magazin-100/datenleak-iran-ueberwachung-gesichtserkennung-software-100

Forbidden Stories: https://forbiddenstories.org/iran-regime-monitors-citizens/

infosec.exchange
86
16
146
1
Open post
hakan “:verified:” @hatr@infosec.exchange
· 1mo ago

RE: @CCC@social.bau-ha.us

Ich weiß noch, wie viel Kritik Florian Flade und ich bekommen haben als wir 2020 auf diese Form der Überwachung (damals durch das BKA) hingewiesen hatten.

Dass man ja ein großer Trottel sein müsse, um auf so etwas reinzufallen. Dass wir unnötig Panikmache betreiben würden, weil Whatsapp ja nicht per Trojaner umgangen wird, sondern per Whatsapp Web.

Jahre später stellt sich heraus:
"Demnach hat „sich das Einsatzmittel bewährt und zu erheblichen Ermittlungserfolgen im Bereich der schweren und organisierten Kriminalität geführt“."

social.bau-ha.us
2
0
1
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 1mo ago

"The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit."

https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

krebsonsecurity.com

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

2
0
1
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 2mo ago
We published a follow-up to the Pegasus-spyware today Some links: https://forbiddenstories.org/projects_posts/pegasus-project-inside-moroccos-spying-machine/ Spiegel, gift link https://www.spiegel.de/ausland/marokko-wie-das-land-die-digitale-monsterwaffe-gegen-unliebsame-kritiker-einsetzte-a-eb2b79dd-2365-49c7-bdd4-04c43de75a5f?giftToken=e2d77355-20cb-4c43-897f-27039e29b27c Guardian https://www.theguardian.com/news/2026/jul/16/morocco-intelligence-insider-reveals-widespread-use-hacking-software-pegasus
forbiddenstories.org
7
1
6
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 9mo ago
Boosted by @octothorpe@mastodon.online
"Die Zeit" reveals that German foreign intelligence, in a multi-year campaign, intercepted Barack Obama's phone calls while aboard Air Force One because the encryption was flawed. Angela Merkel didn't know about it. https://www.zeit.de/politik/ausland/2026-01/bnd-barack-obama-air-force-one-angela-merkel
DIE ZEIT

Spionage: BND hörte jahrelang US-Präsident Barack Obama ab

Der deutsche Geheimdienst überwachte regelmäßig Telefonate des damaligen US-Präsidenten an Bord der Air Force One. Erlaubnis von Angela Merkel hatte der BND nicht.

39
4
36
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 9mo ago

So, Enisa, the cybersecurity agency of the EU, releases a yearly Threat Landscape. In the 2025 edition, they've used AI. And the AI introcuded loads of errors. Five percent of all the links end up 404

One of the researchers.(@wavehackr@infosec.exchange) told me: "You just had to click once", to check whether the links are valid or not. Upon closer inspection, you'd notice something was amiss just by looking, i.e., Enisa referenced a blogpost by MSFT. The link has "APT29" in it. Microsoft is very picky about those names.

They even have a blogpost about their naming convention (https://learn.microsoft.com/en-us/unified-secops/microsoft-threat-actor-naming) What other companies call APT29, MSFT calls "Midnight Blizzard". The AI apparently didn't dig those subtleties.

Here's the story
https://www.derstandard.at/story/3000000303214/peinliche-panne-bericht-der-eu-agentur-fuer-cybersicherheit-mit-ki-verfasst-und-fehlerhaft

How Microsoft names threat actors - Unified security operations
learn.microsoft.com

How Microsoft names threat actors - Unified security operations

Learn how Microsoft names threat actors using a weather-based taxonomy. Find the full list of tracked actors with previous names and origin details.

29
1
39
1
Open post
hakan “:verified:” @hatr@infosec.exchange
· 5mo ago

"Marketing agencies are pitching influencers deals such as $5,000 per TikTok video to amplify Build American AI’s messaging about how China’s technological rise should be seen as a threat"

https://www.wired.com/story/super-pac-backed-by-openai-and-palantir-is-paying-tiktok-influencers-to-fear-monger-about-china/

wired.com
9
0
19
1
Open post
hakan “:verified:” @hatr@infosec.exchange
· 2mo ago

“I wish the frontier labs spent as much time on teaching their models to write secure infrastructure as they are spending on them exploiting vulnerabilities.”
https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/

wired.com
1
0
0
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 23mo ago

"The computer contained a complex system of individually encrypted hard drives with 33 terabytes of stolen data, carefully organized into more than 4,000 folders. "

https://www.bloomberg.com/features/2024-dutch-hacking-spree/?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTczMTUxMTkxMCwiZXhwIjoxNzMyMTE2NzEwLCJhcnRpY2xlSWQiOiJTTTdGOVFUMEcxS1cwMCIsImJjb25uZWN0SWQiOiJENTY5QzIyNzE4NUM0NkM4OTgxMjBGMUI2QTBFNDIwQSJ9.qp8pWdoFyUk9Gk2N1nhayQCvrMhDQbk5RQK8ASZ2uMM

bloomberg.com
29
0
29
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 30mo ago

I’ve been writing a lot of stories about state-sponsored cyberespionage by China. The case we’re revealing today is a prime example of this, telling the story of a five-year campaign against one of the key players in 🇩🇪 the Volkswagen group

The hackers started back in 2010, with initial mapping of the infrastructure and then, until 2015, tried to siphon data out of VW networks – repeatedly and successfully so. Even though VW removed the hackers, they kept coming back.

Very often companies do not know what the hackers were after because the hackers have deleted their traces until the time anoybody notices their presence. In this case, it was different: Volkswagen CERT was able to restore RAR-archives, giving rare insight into the tasking.

SPIEGEL:
https://www.spiegel.de/netzwelt/web/volkwagen-vw-konzern-wurde-jahrelang-ausspioniert-von-china-a-f9971315-c342-42b5-b97b-8650b91d60d4 (€)

ZDF:
https://www.zdf.de/nachrichten/wirtschaft/volkswagen-china-hacking-industriespionage-emobilitaet-100.html

(S+) Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausgespäht – von China?
spiegel.de

(S+) Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausgespäht – von China?

Über Jahre hinweg wurde der Volkswagen-Konzern immer wieder ausgespäht, mutmaßlich von chinesischen Staatshackern. Die Angreifer hatten es auf deutsches Know-how zu Motoren und Getrieben abgesehen.

24
0
24
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 5mo ago

"The report describes “high alert” in the Kremlin “since the beginning of March 2026” about “the risk of a plot or coup attempt against the Russian president.”

https://www.occrp.org/en/news/security-tightens-around-putin-amid-coup-and-assassination-fears-according-to-european-intel-agency

Security Tightens Around Putin Amid Coup and Assassination Fears, According to European Intel Agency
OCCRP

Security Tightens Around Putin Amid Coup and Assassination Fears, According to European Intel Agency

OCCRP’s Russian partner, Important Stories, obtained a report by an EU intelligence agency that describes extreme new security measures, rising tension among security services, and fears of assassination by drone.

1
0
1
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 47mo ago

Hey. got a quick announcement. Starting next month, i'll join "paper trail media", a german media startup focused on investigative journalism.

They're the ones who did
– Panama Papers
– Xinjiang Police Files
– Pegasus Project (NSO and hacking smartphones)

Their stories are mainly published with Der Spiegel. I'm incredibly excited.

I'll still write about cybersecurity. So, reach out to me anytime if you want to talk about attribution, intrusions, DFIR and all that.

40
3
11
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 39mo ago

While working on #VulkanFiles, I received a tip: an interesting file had been dropped on Virustotal. It turned out to be the master’s thesis by Evgenii Serebriakov, the person who’s heading infamous Sandworm team, part of Russia's military agency GRU. Titled “Information confrontation in World politics”, Serebriakov lays out his worldview, describing how 🇷🇺 is on the defensive and has to protect itself against the West. Controlling flows of information is one way of doing that, he writes.

Story here
https://www.spiegel.de/netzwelt/netzpolitik/sandworm-der-mann-hinter-der-gefaehrlichsten-hackergruppe-der-welt-a-b56c715e-e856-4a21-9865-0ce17f1ba2a9

Thread here
https://twitter.com/hatr/status/1673653667734380546

twitter.com
23
0
10
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 46mo ago

Researchers with the Chaos Computer Club bought items on eBay that turned out to have stored iris scans of 2,632 people, mostly from people living in Iraq and Afghanistan. But also data from members of the U.S. Army:

From the NYT:
"detailed descriptions of individuals in addition to their photograph and biometric data, could be enough to target people who were previously unknown to have worked with U.S. military forces should the information fall into the wrong hands"

NYT has a writeup here: https://www.nytimes.com/2022/12/27/technology/for-sale-on-ebay-a-military-database-of-fingerprints-and-iris-scans.html?unlocked_article_code=AAAAAAAAAAAAAAAACEIPuonUktbfqYhlSlUZBCbJUNMnqBqCgvfeh7I7nDrlJSyYDDFEiukfCpnF8gLIZK5ie9IpznGXTcNIOrY0Sbl1wKpRPkpiRhOwuJqChI9AKiM57IOpX3hzxJnEW6t-8SPvaiPxDtZD84CFnkDMNimsU7rCgTZnfFw79Y1mcln53X1YlLPHErV2xtV_2vs-D814FiNRbHXZ6KXoXxooa9-Wf1qLvFlNLuJcWTzTnNOd6atRM1kBTAKbEw4spDo0-9heO9gIPK3gLBBGecv2hbQZCGwAP57-TtRqBNCSz-M2xOaL_R-cy8O2xeE0FLFXvd7Gu2W9PVUuQNCGLdh1nu1h24vFimy7MldCiUA (the utm ensures you can read the article without subscription)

My former colleagues at BR have been working on this story for many months now. If you understand the German language, I encourage you to listen to their hourlong feature on #biometry https://www.ardaudiothek.de/episode/ard-radiofeature/verraeterische-daten-doku-ueber-die-gefahren-der-biometrie/ard/12204469/ It includes the case of the military database but much more as well

nytimes.com
29
5
34
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 47mo ago

Re-sharing this over here because it might be of interest to the people on this instance (also, it's sort of an introduction :ablobcool:​).

I recently gave a talk at the Virusbulletin-conference on how reporters find and fact-check stories on hacking incidents.

I'm talking about looking at PassiveDNS data to find relevant domains connected to ongoing hacking campaigns but also on re-discovering information that was made public years ago to connect it to a campaign that is still active.

Some of the answers might be obvious, others not so much (at least, that's what I was aiming for.)

The talk is titled: "Why are you telling me this?" and all I'm doing is to answer that question for 40 minutes

https://www.youtube.com/watch?v=rtlTF1Ajjdw

(I have posted this yesterday, but just now saw (I think!) that I've sent it to just myself, it popped up in my DMs. STILL LEARNING! Apologies if this shows up twice.)

21
2
5
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 2mo ago
Going to be interesting to see if any of the three companies are going to sue https://www.nytimes.com/2026/07/30/technology/anthropic-ai-hack.html
nytimes.com
0
0
0
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 2mo ago
"The incident, which Meta says occurred during an evaluation by an independent company, is the fourth recent incident of its kind disclosed by AI companies." https://www.bbc.com/news/articles/cx2kgdnyk2po
bbc.com
0
0
0
0
Open post
hakan “:verified:” @hatr@infosec.exchange
· 1mo ago
"These traders typically opened an account ​and quickly placed a highly successful long-shot bet in niche markets where insiders may have an informational edge, before in many cases cashing out and disappearing." https://www.reuters.com/business/finance/more-than-150-polymarket-wallets-may-have-traded-military-secrets-research-finds-2026-08-20/
reuters.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:27:11 UTC