Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Marcus Hutchins :verified:

@malwaretech@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Cybersecurity

80721 Followers
92 Following
42 Posts
Joined November 05, 2022
Website:
https://marcushutchins.com
Security Blog:
https://malwaretech.com
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 3w ago
Cybersecurity has an AI doomer problem https://www.youtube.com/watch?v=KMf2RDC5Dyg The AI industry's proximity to cybersecurity is causing clueless AI doomers to flood the zone. Experts and real issues are now being drowned out by increasingly absurd cyber-apocalypse fantasies imagined by people with no real world experience. From self-replicating AI models, to turning the entire internet into a botnet. The doomers are losing their minds and taking the cybersecurity industry with them.

Cybersecurity Has An AI Doomer Problem.

123
8
69
2
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 1mo ago
Machine Speed is a lie: stop trying to fight AI with AI Marketing departments are screaming that attackers are moving at "machine speed" and only AI-powered defenses can stop them. But cyberattacks have always been automated, and proactive defense beats reactive AI. https://malwaretech.com/2026/09/machine-speed-is-a-lie-stop-trying-to-fight-ai-with-ai.html
malwaretech.com
248
1
177
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Listening to cybersecurity people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.
1087
84
636
7
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
My take on the story about OpenAI's model going rogue and hacking a competitor's systems, why it matters. Also probably the fastest turnaround time for a video that I've managed so far. I'd just got off a 12h flight when the story dropped. https://youtu.be/GB8gaeI0fLs?si=ss3hD78xG2XUREYn

OpenAI Claims Their AI 'Went Rogue'. It Didn't.

103
10
72
2
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 3mo ago
I think it’s hilarious that I now have my first CVE because I got annoyed with an unresponsive vendor and just posted the zero day exploit I was trying to report to them on my GitHub 😆 https://nvd.nist.gov/vuln/detail/CVE-2026-49494
nvd.nist.gov
174
4
66
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 7mo ago

It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

There is, however, some useful (but more nuanced) information here:

Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

559
67
431
9
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 7mo ago

We plan to decrease operational costs for our AI model by building custom servers that are immune to cosmic radiation, then spending trillions of dollars launching them into space. Yes, our CFO did tech themselves math using ChatGPT, why do you ask?

504
25
242
1
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Boosted by @hypebot@goingdark.social
I found a zero day in a security vendor's firewall software that allows you to remotely crash the entire system by sending it a single malicious packet. Since the firewall is responsible for inspecting traffic prior to the operating system handling it, no ports even need to be open for it to work.
221
30
100
2
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 8mo ago

I can’t believe we’re doing this again. It’s just a bot that generates the text you ask it for. If you put it in charge of critical decisions, it will kill people. Not because it’s secretly evil, but because it’s a word generator. It’s like putting your toaster in charge of air traffic control.

513
57
260
3
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago

I spent nearly 4 months investigating the inner workings of a North Korean state-sponsored hacking group. Here's what I found:

- The group used generative AI tools to aid in almost every part of their operations.

- They exfiltrated 26,584 cryptocurrency wallets from victim systems, with a combined value totaling as much $12 million dollars.

- In several cases, the threat actors set up entire front companies to lure in developers via fake job posting, then infected them with malware.

- The threat actors successfully pulled off a supply-chain attack by compromising a VS Code extension developer's system.

🔗 Full article: https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/

expel.com
193
10
165
5
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 4mo ago

Slowly setting up my video/livestream studio again. The amount of tech required for even a half decent experience is crazy

105
7
12
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 4mo ago

My thoughts on Microsoft's threat to prosecute researchers for dropping zero day exploits

https://www.youtube.com/watch?v=gCkfWo5rie8

Microsoft Wants To Throw Researcher In Jail

94
6
71
1
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 6mo ago

I'm convinced this technology was invented purely just to troll me

162
12
58
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 8mo ago
When the state sponsored threat actor has vibe coded their entire control server, all the login code is client-side, and they’ve infected themselves with their own malware.
202
10
54
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 7mo ago

To prove you’re not a robot, please select all the Mar-a-lago SCIFs

154
14
70
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 3mo ago
My deep-dive technical analysis of a zero-day exploit being used by The Gentlemen ransomware group to disable EDR products https://expel.com/blog/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/
expel.com
36
0
19
1
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Boosted by @hypebot@goingdark.social
I built an AI that autonomously finds zero day exploits https://www.youtube.com/watch?v=BLqRiL_GY3A
69
17
45
2
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 4mo ago

It's been a while since I did a vulnerability research article. How about a little DoS zero-day as a treat?

https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html?1

malwaretech.com
46
1
24
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 1mo ago
Replying to
@flyingpenguin@infosec.exchange None of those model were viable for automating cyber attacks, and the first reported case of threat actors using AI to automate attack was GPT 3.5
3
1
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 8mo ago

I've been researching some malware that uses Blockchain Smart Contracts as Command-and-Control infrastructure. Since blockchain data is public, I was able to write code to track how many new systems the malware infects each day. Blog post coming next week.

114
5
47
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 4mo ago

ComoDoS - Exploiting a Remote Kernel Zero-Day Vulnerability in Comodo Internet Security

How an IP parsing vulnerability makes it possible to remotely crash systems with a single TCP/IP packet

https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html

malwaretech.com
29
0
16
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 6mo ago

After years of planning a potential collab, I finally got to sit down with fellow cybersecurity YouTuber David Bombal for an in person interview! Below you can check out the video from what will hopefully be the first of many more collaborations 😃 :
https://www.youtube.com/watch?v=KsXzTz5H2QQ

66
5
33
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 8mo ago

Just checking in on my investment portfolio, because apparently computers are appreciating assets now.

97
8
32
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 1mo ago
Replying to
@flyingpenguin@infosec.exchange No, because a reasonable reader is not going to pretend stable diffusion models or GitHub CoPilot preview were launching cyber attacks just to push some dates back. That is the behavior of a professional nit picker whose views I am not going to move one bit. The fact that AI is not responsible for the reduction in attack times is an important case to make, or the people making it are just going to continue poisoning the discourse with their nonsense.
2
1
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 1mo ago
Replying to
@flyingpenguin@infosec.exchange I feel like you're trying too hard to make widespread AI cyberattacks a thing. I deliberately structured my entire argument around the fact that people would still attempt to resurrect their AI-boogeyman no matter what I said. "For argument’s sake, let’s take CrowdStrike’s AI-enabled claims at face value, assume AI is driving the drop in breakout times, and that trend does continue as a result of it. The core argument of this piece still stands, regardless of opinions on why breakout times are dropping."
2
1
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 7mo ago

Great crowd at Zero Trust World today. Thanks for everyone who came to my keynote and for all the great hallway conversations! 😃

58
0
6
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 4mo ago

@GossiTheDog@cyberplace.social That is indeed oddly specific

23
2
3
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 8mo ago

My latest blog post investigating a malware campaign which infects victims by utilizing only legitimate infrastructure. The malicious activity spans hundreds of hacked websites, the BSC blockchain, and a popular CDN.

https://expel.com/blog/clearfake-new-lotl-techniques/

expel.com
44
2
45
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 8mo ago

Since the decline of peer-to-peer botnets it's been difficult to track malware infections externally. But smart contract based C2 infrastructure provided us with unique insights into this campaign.

https://expel.com/blog/clearfake-new-lotl-techniques/

expel.com
30
0
11
1
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 7mo ago
Replying to
@AT1ST No, Apple just outright refused and has enough money to tie most of the federal government lawyers up in court for the rest of their careers
13
1
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Replying to
@johnbrown I have less than zero interest in justifying 4 months of my own extensive intelligence work to some dipshit tankie
5
1
1
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Replying to
@Lee_Holmes Thank you 🙏
5
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
Replying to
@muddle@infosec.exchange I forgot how insufferable people on this platform are
1
1
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Replying to
@gimulnautti Before Mythos is was zero day exploits in general. Cybersecurity has always been fixated on novel, rare, and unrealistic attacks while ignoring the hacks that happen on a daily basis
4
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 5mo ago
Replying to
@hsza Please untag me and stop schizo posting in my replies
3
1
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 3mo ago
Replying to
@haicen@infosec.exchange I’ve never requested or submitted a CVE before
0
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
Replying to on infosec.exchange
@muddle@infosec.exchange yup, and that's why it got 10,000 views in less than 24h, instead of if I'd used my alternate headline option of: "A deep dive into OpenAI's claim that their model escaped a sandboxed and hacked hugging face, where I debunk said claim and talk about OpenAI's reckless behavior and also include my life story in this headline because why not and also I had eggs for breakfast btw"
0
2
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
Replying to
@failedLyndonLaRouchite@mas.to Respectfully, nobody asked. Either watch the video and critic the content, or stfu.
0
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
Replying to on infosec.exchange
@muddle@infosec.exchange No, I just think you're an idiot. I make videos for an audience who wants to hear my takes on mainstream cybersecurity news. You are either one of them, or you're not. If it's the latter, then you can just scrolled past instead of leaving your uninformed opinion. A very important media literacy skill is knowing when some media is intended for you. If it's not intended for you and you respond as if it were tailored for you specifically, you just end up looking like a fool like you do now.
0
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
Replying to
@muddle@infosec.exchange there's no "sorry that you think that". You came in and accused me of having no self-awareness, then backtracked to try and claim I was doing something that I did not do. You're a grade A clown. I title my YouTube videos so people watch them, not to appeal to 1 weird nerd on a niche social media platform.
0
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 1mo ago
Replying to
@flyingpenguin@infosec.exchange the cause doesn't matter to the argument, but you're also wrong about the cause. Two things can independently be true at the same time. Those arguments don't overlap in any way, one does not refute the other.
0
0
0
0
Open post
Marcus Hutchins :verified: @malwaretech@infosec.exchange
· 2mo ago
Replying to on infosec.exchange
@muddle@infosec.exchange Only to people who aren't smart enough to at least watch the first 5 seconds of the video before commenting
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:23:12 UTC