@ScrumWhat

Father, biker, adrenaline junkie, PC gamer, vaccinated. CISO @hunterstrategy / Faculty Member @IANS_Security. My views are my own. (He/Him)

Boca Raton, FL
Joined April 2010
Reminder: Everything you do is either goal achieving, or stress relieving. Make sure you balance between the two is correct.
1
2
31
Andrew King (AJ) retweeted
This GPO-based “ransomware without ransomware” technique is pretty cool: abuse trusted Group Policy to deliver the impact, without ever dropping an encryptor on Windows endpoints. But there is something slightly amusing about framing “traditional ransomware detection wouldn’t catch this” as the big defensive challenge. By the time an attacker has domain-admin-equivalent privileges, can create and link GPOs at the domain root, turn off the firewall domain-wide, and exfiltrate data, there have likely been plenty of opportunities to detect them before the ransom wallpaper appears. Not detecting the ransomware binary isn't the same as not detecting the attack. 🙂 securelist.com/tr/payload-ra…
7
24
1,510
Andrew King (AJ) retweeted
Apparently all of these “AI is escaping containment” stories are actually just AI researchers not knowing jack squat about the absolutely most basic security practices.
196
647
61
6,341
105,926
Cybernews researchers confirmed an Android toolkit capable of feeding fake photos, prerecorded videos, and remote live video directly into KYC verification apps as if it were coming from the device's real camera. No root required. Works on Android 10 through 16. The technical mechanism is a virtual camera driver that intercepts the camera API at the OS level. When a verification app requests a camera feed it receives synthetic content instead of real footage. From the app's perspective the footage is indistinguishable from a live camera session because it is arriving through the legitimate camera channel. The numbers behind this are alarming. Virtual camera injection attacks grew 2,665% year over year according to iProov's threat intelligence. In the second half of 2025 alone injection attacks targeting iOS surged 1,151%, contributing to a 741% annual rise. Injection attacks have definitively overtaken presentation attacks, holding a phone photo up to a camera, as the primary KYC bypass vector. 8.3% of all digital onboarding attempts were flagged as suspicious in the first half of 2025. Banks consider digital onboarding their most dangerous fraud exposure point. The reason this matters beyond identity fraud is the downstream effect on every system that uses selfie verification as a trust anchor. Bank account opening. Crypto exchange verification. Fintech onboarding. Uber driver verification. Every platform that replaced a human identity check with a selfie liveness check built that trust on an assumption that is now comprehensively broken. The fix requires three concurrent detection layers running simultaneously. Liveness analysis to detect presentation attacks. Deepfake detection examining frame-level artifacts. And injection signal analysis checking for virtual camera drivers and session metadata inconsistencies. Server-side checks that evaluate the image after it arrives cannot stop an attack that replaced the feed before it was ever captured. The selfie was never as secure as it felt. The toolkit just made that visible.
Android hackers found a way to make fake selfies look like they’re coming directly from your camera during KYC verification. The toolkit can reportedly feed photos, prerecorded videos, or even remote video into verification apps.
7
59
4
316
19,954
Andrew King (AJ) retweeted
Ten days ago, the Florida Senate threatened reporters with criminal charges to bury a report you paid for. Today, those reporters published it anyway. Now you can see what they were hiding. Insurance companies claiming losses while sending millions in profit to affiliated companies out of state. One insurer reported a 9 million dollar loss while its affiliates earned 176 million. They cry poverty to raise your rates, and the state helped them hide it. I served on the Senate Banking and Insurance Committee. I saw exactly how they operate. As your CFO, I will use the audit authority of this office to keep dragging this into the light. Read it yourself, then ask why they fought so hard to keep it from you. orlandosentinel.com/2026/09/… – Annette
38
1,472
39
3,031
71,155
Andrew King (AJ) retweeted
nothing gets me fired up in the afternoon like discussing the usage of AI in a SOC before a SOC even has the key foundational elements in place to be successful w AI
12
21
3
321
19,407
Open source dependencies going stale. Shift-left security nobody funded. Government agile fighting government security posture. New episode of This Is Fine tackles secure software development with Dan Beller and Greg Vanore. Catch the episode here: f.mtr.cool/bihgsgdvxa
2
2
78
Andrew King (AJ) retweeted
Four different RMMs. Cobalt Strike. SystemBC. Multiple operators. And it all started because an administrator searching for RVTools fell victim to SEO poisoning. This was a pretty interesting intrusion to investigate, mostly because it represents exactly what real intrusions actually look like, messy, overlapping access methods, different operators, tools failing, and activity running into EDR and other prevention controls. Those parts don’t always make it into public intrusion reports, but I think they’re some of the most useful things for defenders to see. We joined forces with the amazing @PandaRE__ and @malbearlabs on this one. We focused on reconstructing the intrusion, while Anna and team did an amazing job in breaking down the payloads we came across. Our report: threathuntinglabs.com/blog/f… MalBear Labs RE report: malbearlabs.com/posts/novel-…
We’re really excited to publish this one alongside @malbearlabs 🥳 For the first time at Threat Hunting Labs, we’re releasing a real intrusion as both a public investigation report and a hands-on lab: *️⃣ From SEO Poisoning to Custom RMM and Cobalt Strike Read exactly what happened in this real intrusion, then open the lab and investigate the same evidence yourself. It started with an administrator searching for RVTools and executing two malicious downloads on the same workstation. The activity then split into separate paths involving browser process injection, Level RMM, another custom RMM-style service, and eventually a Python-hosted Cobalt Strike Beacon. What stood out to us was the amount of remote-access tooling involved. Instead of relying on one method, the attackers ended up with multiple access paths using legitimate RMM software, custom tooling, and Cobalt Strike. You can investigate the evidence across Threat Hunting, Incident Response, Detection Engineering, and Malware Analysis. 🎥 When you finish, every lab includes a recorded walkthrough where we explain how we investigated the activity and arrived at the answers. MalBear Labs went much deeper into the recovered payloads and malware, complementing our intrusion analysis with their own companion report. And a big thank you to @securityaura for helping us with the threat intelligence context around the SEO poisoning and malicious samples. Lab: threathuntinglabs.com/threat… Intrusion report: threathuntinglabs.com/blog/f… MalBear Labs: malbearlabs.com/posts/novel-…
3
16
74
7,021
Andrew King (AJ) retweeted
A single Gmail address leaks a surprising amount of personal data. Instead of wasting time with manual searches, this article shows you how to use GHunt to automatically pull hidden profile details, location history, and account metadata in minutes. hackers-arise.com/open-sourc…
1
131
3
896
39,521
Andrew King (AJ) retweeted
ScreenConnect is 74.5% of the abused remote-access tools @HuntressLabs sees. So I detonated two real samples and hunted both on Defender and Elastic. Full hunt notes and every query in the Article.
2
32
118
17,435
Andrew King (AJ) retweeted
Strategic loss. A major one. The weapons bay door and the canopy are a major intelligence windfall for the PLA. Both of them reveal much about the F-35's capabilities: Cockpit canopy. Yes, it doesn't look like much. But there's a hidden feature. It has to be see-through for the pilot, but a mirror for radar. The inside of a cockpit is a metal cave full of right angles. Radar reflection is very high. So the F-35's canopy has an ultra-thin metal coating baked into it. The light passes through, but radar bounces off. Its why stealth canopies can have a tint. The Bay Door. Major stealth component. Since it shields the weapons bays. Its opening creates a brief signature. Possession lets the PLA figure out exactly which radar frequencies it blocks. But also test where the seams are. It also can test for reveal how quickly stealth performance and which airframes in a fleet are likely most detectable. Those give knowledge of least-stealthy aspect angles and interception geometry. Useful also for mobile SAM sites. And it's a major loss. In 2021, the US and UK mounted an emergency deep-sea recovery when a British F-35B ditched in the Mediterranean. To prevent foreign powers from recovering. Adjusting 1,000+ aircraft quickly isn't cheap. Its to prevent insights into air doctrine, tactical gaps, endurance, etc. The secrets of an aircraft are often baked into jet parts. Nor do you know what a geopol opponent has figured out.
BREAKING: China has taken possession of sensitive US F-35 stealth parts mistakenly diverted to Hong Kong while being shipped from Australia to the US, including a cockpit canopy and a weapons-bay door both coated in radar-absorbing material, and has not returned them, per Bloomberg. A US-contracted UPS aircraft was carrying the parts from Australia to the US for inspection. The aircraft stopped in South Korea and was routed from there to Hong Kong, with no explanation for either leg. It comes as Xi arrives in the US today for a state visit with Trump.
25
410
44
4,493
514,100
Andrew King (AJ) retweeted
My friend @FirewallDragons owes me a new keyboard from me spitting out Coke Zero laughing this morning.
3
13
47
1,924
This is why you need visibility and control of your MCP surface. Ask @x_a_n_d_e_r_k about MCP Sentinel!
Seriously @Atlassian asking for the community here. How on gods green earth did you end up shipping MCP server full of appsec bugs? CVE-2026-77242 SSRF CVE-2026-77267 validation bypass CVE-2026-77269 path traversal With all the AI, you still had bugs older than most
1
109
Andrew King (AJ) retweeted
Barack Obama at his last press briefing with reporters, 2017: "I have enjoyed working with all of you. That does not, of course, mean that I've enjoyed every story that you have filed, but that's the point of this relationship. You're not supposed to be sycophants. You're supposed to be skeptics. You're supposed to ask me tough questions. You're not supposed to be complimentary, but you're supposed to cast a critical eye on folks who hold enormous power."
1,114
24,670
1,560
124,532
5,680,350
Andrew King (AJ) retweeted
Nobody: Microsoft: People don't hate us enough Nobody: Huh? Microsoft: I have an idea!
6
5
2
90
5,153
Andrew King (AJ) retweeted
👀
7
33
7
336
15,695
Being a leader doesn’t mean you’re always right. To err, is human. If you want accountability from your team, ya gotta hold yourself accountable to them as well.
3
77
Talking to most security execs these days is just like this!
7
268
Andrew King (AJ) retweeted
Ollama Shodan indexes over 47.000 exposed Ollama instances, including many running on expensive cloud GPUs. The API has no authentication, which means hackers can run prompts, steal models and exploit vulnerable versions. To spread awareness we made an article showing you what can be done. Make sure you're safe hackers-arise.com/hacking-ar…
15
107
10
584
34,984
Andrew King (AJ) retweeted
The Cyber Gap : How to Counter China’s Threat to America’s Critical Networks Great CFR report, that I was happy to help with. cfr.org/reports/the-cyber-ga…
3
11
29
2,850
Andrew King (AJ) retweeted
🎯 Potential ShinyHunters campaign targeting 77 Okta customers. A KQL-based correlation of xxx.okta.com subdomains and newly registered xxx.report domains over the last 30 days revealed 77 matching domains, where the xxx identifier was identical across both domain formats. This suggests potential targeting of those Okta customers. #threathunting 🧙‍♂️
24
3
114
12,165