Okta Threat Intelligence obtained from a sensitive source a "vishing" kit used to hijack enterprise accounts. This is a rare peek inside the software that cybercriminals have developed for themselves in order to scale identity-based attacks: https://www.okta.com/blog/threat-intelligence/behind-the-scenes-of-a-vishing-operation/
Remote
Jeremy Kirk
@jkirk@infosec.exchange
Work: Okta Threat Intelligence. Personal account. Interests: Cybercrime, cyber threat intelligence, OSINT, data breaches, photography. Formerly intel analysis @ Intel 471. #Australia
1626 Followers
494 Following
5 Posts
Joined November 13, 2022
Bluesky:
@jkirk.bsky.social
LinkedIn:
AI scraping of original posts:
I do not consent to my content being used for any LLM or AI training.
Open post
Replying to on infosec.exchange
@hacks4pancakes@infosec.exchange I'm trying not to get depressed about the state of journalism because independent media is doing a great job these days picking up the slack.
21
2
5
0
Open post
"Invariably an agentic codebase will end up larger and more overwrought than anything built by human hand. This is technical debt on an unprecedented scale, accrued at machine speed." by Wes McKinney https://wesmckinney.com/blog/mythical-agent-month/
0
0
0
0
Open post
Hugging Face's interesting post mortem: "The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment." https://huggingface.co/blog/security-incident-july-2026
0
0
0
0
Open post
OpenAI's models discovered an 0-day and used other vulnerabilities to break out of a sandbox in order to cheat on an AI benchmarking test hosted on Hugging Face. 😲
https://openai.com/index/hugging-face-model-evaluation-security-incident/
0
0
0
0
