Greg Lesnewich's Avatar

Greg Lesnewich

@greg-l

oh great, now I’m on bluesky

547
Followers
366
Following
1,531
Posts
22.11.2024
Joined
Posts Following

Latest posts by Greg Lesnewich @greg-l

Can someone smarter than me tell me if the cyber strategy for america from the regime means anything for me personally?

07.03.2026 01:08 👍 2 🔁 0 💬 2 📌 0

nearly sued the previous owners of our last residence over this exact thing

04.03.2026 18:51 👍 2 🔁 0 💬 0 📌 0

Christopher Kempczinski bit into that burger like it was the first time he'd every tasted a McDonalds burger

AND...

This is actually a case study on how American companies no longer promote within

04.03.2026 16:15 👍 324 🔁 47 💬 12 📌 17
Preview
Niplodram Fame GIF ALT: Niplodram Fame GIF

They don't see grandpa, until they look over at the crowd of kids getting their NASCAR gear signed by “Big Al”

kids didn’t know the old dude in the fishing hat WASN’T a team owner, so grandpa took his chance to be hilarious and sign like 6 autographs as Big Al, and BS’d about how the race went

02.03.2026 23:56 👍 2 🔁 0 💬 0 📌 0

Fast forward to them deciding to leave

Story goes that my uncle lost track of grandpa towards the gated exit to the parking lots

They wander to the exit where a bunch of kids are waiting on the other side of the fence hawking autographs …

02.03.2026 23:56 👍 1 🔁 0 💬 1 📌 0
Preview
a race car with the number 20 on the front ALT: a race car with the number 20 on the front

So one race he brings along my grandpa and my old man. Happenstance, one of the cars they sponsored, Tony Stewart, wins!

So the three of them, having no business being there, end up in the winners circle

There’s a ton of people there - they get a free beer but don’t meet anyone fr

02.03.2026 23:56 👍 0 🔁 0 💬 1 📌 0
Preview
a race car is driving down a track with spike written on the bottom of the screen ALT: a race car is driving down a track with spike written on the bottom of the screen

Since things are #rough out here right now, I figured I’d share a fun story

Back in the early 00’s, my uncle worked at some manufacturer that sponsored a bunch of NASCAR cars and would regularly get tickets to the events

02.03.2026 23:56 👍 3 🔁 1 💬 1 📌 0

Anthropic just got a life time subscriber based off this one screen wow

02.03.2026 23:48 👍 6 🔁 0 💬 1 📌 0

i personally loved the one where he subtweeted Anthropic and said they were committing treason

02.03.2026 22:57 👍 8 🔁 0 💬 1 📌 0

Staying off socials to keep my mentals in order but had to come in here to say that I’m certain Bad Bunny had more yards from scrimmage than the Pats in that first half

09.02.2026 01:37 👍 6 🔁 0 💬 3 📌 0

#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5

23.01.2026 16:30 👍 35 🔁 30 💬 1 📌 5

You fear innovation

22.01.2026 13:54 👍 22 🔁 4 💬 0 📌 1
Preview
We Are Witnessing the Self-Immolation of a Superpower With Donald Trump’s actions in Greenland, Minneapolis, and Venezuela, a foreign enemy could not invent a better chain of events to wreck the standing of the United States.

"A superpower is choosing to self-immolate and torch its remaining global trust and friendships, including and especially NATO...at the precise moment when it had been reinvigorated and renewed...in the wake of Russia’s large-scale invasion of Ukraine in 2022" - by @vermontgmg.bsky.social

22.01.2026 13:55 👍 48 🔁 18 💬 0 📌 1
Preview
Minneapolis church has delivered more than 12,000 boxes of groceries to families in hiding DHH church has hundreds of volunteers packing and delivering groceries to families who have been too scared to leave their homes during the immigration operation.

They have quite an operation going.
www.mprnews.org/episode/2026...

16.01.2026 13:02 👍 6615 🔁 1914 💬 116 📌 231

Appreciate the tip! Will see if it takes down the champ!

16.01.2026 00:15 👍 0 🔁 0 💬 0 📌 0

We have not! Worth giving a go?

16.01.2026 00:10 👍 0 🔁 0 💬 1 📌 0

I don’t think we’ve collectively paid enough attention to the fact that Annie’s is now the regent of boxed Mac and cheese

Kraft got their chain snatched and now it just tastes like dog water compared to Annie’s

16.01.2026 00:00 👍 4 🔁 0 💬 3 📌 0

I for one am excited for the Hoth Takes episode on this one to help me digest this news

15.01.2026 23:51 👍 1 🔁 0 💬 0 📌 0
Post image

#100daysofYARA - day 12
VirusTotal uses CAPE sandbox to identify many malware families and determine if they can extract the malware's configuration. Since they use CAPE, we can often see their logic. Today, we'll suggest edits to a rule for AgentTesla.

Rule at end.
1/10

14.01.2026 12:38 👍 7 🔁 6 💬 1 📌 0

words don't mean anything anymore

13.01.2026 14:30 👍 3 🔁 0 💬 0 📌 0

Imagine publishing a blog on "Lazarus" in the year of our lord 2026

13.01.2026 14:27 👍 6 🔁 2 💬 4 📌 0
Post image

#100DaysofYARA - Day 11
In looking at automatic YARA generation, yarGen-Go is a must. Just released by @cyb3rops, it is a rewrite and advancement from the original yarGen.

We'll look at the same malware from day 10; a targeted HavocC2 loader with decoy.

rule at bottom
1/5

12.01.2026 14:27 👍 6 🔁 2 💬 1 📌 0
Preview
100DaysofYARA/Squiblydoo/Day9.yara at main · Squiblydoo/100DaysofYARA Rules shared by the community from 100 Days of YARA 2026 - Squiblydoo/100DaysofYARA

This scripts are deceptive as they contain 10,000 empty lines. BTW #malcat loads scripts like these better than most text editors.

If I get the chance, I may revise it to see how to find ones without the matching text or if you have ideas, hmu.

github.com/Squiblydo...
3/3

10.01.2026 19:17 👍 4 🔁 1 💬 0 📌 0
Preview
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.

The rule is fairly simple but it seems that at least one DPRK team is using the same consistent message in the header. I validated this using ReversingLab's YARA scanning.

A slightly different header is seen in Huntress' analysis: www.huntress.com/blo...
2/3

10.01.2026 19:17 👍 1 🔁 1 💬 1 📌 0
Post image

#100DaysofYARA - Day 9
YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems.

Script is delivered to victims disguised as a Zoom meeting launcher.
e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892

Rule at end
1/3

10.01.2026 19:17 👍 3 🔁 2 💬 1 📌 0
Post image

#100DaysofYARA - Day 8
For many years, many attackers tried to keep their binaries small. However, the others found the opposite works too: extremely large binaries can cause problems with analysis.

What can be done about these large executables?

Rule at end
1/6

08.01.2026 17:48 👍 1 🔁 2 💬 1 📌 0

The same people spent the last decade justifying Black folks being choked to death on camera… they’ve been practicing

08.01.2026 13:23 👍 741 🔁 193 💬 7 📌 1

congress should behave like a co equal branch

impeachment
defunding
filing suits
subpoenas
writing laws
hearings, hearings, hearings

what else?

07.01.2026 20:53 👍 16 🔁 5 💬 1 📌 3
Preview
GRU-Linked BlueDelta Evolves Credential Harvesting Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.

Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...

07.01.2026 15:39 👍 7 🔁 5 💬 1 📌 0

#100DaysofYARA - Day 7
@malwrhunterteam identified a suspicious file signed by "Xiamen Jialan Guang Information Technology Service Co., Ltd."

While we have a pretty good idea it'll be abused, it hasn't been yet.
So, lets watch for it to be abused.

Rule at end
1/5

07.01.2026 14:32 👍 2 🔁 1 💬 1 📌 1