The recent Trezor-physical-mail-phish-delivery-crypto-scam made me giggle -- so I rambled about it in a video. I'm not a crypto guy but alarm bells should probably go off in your mind when something is asking for your recovery seed phrase. π
Video: youtu.be/UQFySFs2GJk
04.03.2026 14:01
π 1
π 0
π¬ 0
π 0
I've made some updates and added 2 hours worth of new material to the "Linux for Hackers Fundamentals" course on @hackinghub_io ! Vim text editor basics and sed & awk for text processing. Here's a 40% off discounted link if you'd like to take a peek :) hhub.io/Linux2026JH
28.02.2026 14:01
π 6
π 0
π¬ 0
π 0
h?ckers a[r]e gl*bbing!
A little showcase of @0xv1nx0 's neat new project LOLGlobs -- demo is a teeny weeny PowerShell download cradle, obfuscated with globbing tricks and used with some 'living off trusted sites' just flair for funzies too :)
Video: youtu.be/IImLVU39V_Q
27.02.2026 14:01
π 5
π 1
π¬ 0
π 0
Google API keys didn't use to be considered "secret," so they're all over the web-- but now they are an open door to Gemini π« Quick rundown video of Truffle Security's really nifty research, almost 3,000 websites exposed.. including Google themselvesπ
π youtu.be/XNMHUifKce8
26.02.2026 17:13
π 8
π 1
π¬ 0
π 1
Quick dance with CVE-2026-21509, a "Security Feature Bypass Vulnerability" and an emergency out-of-band fix from January Patch Tuesday (and an obligatory exaggerated YouTube thumbnail -- I apologize and appreciate folks who understand algorithm nuance) youtu.be/Ck8IPInn74A
19.02.2026 14:00
π 5
π 1
π¬ 1
π 0
"TikTok needs to fix this vulnerability" -- video: youtu.be/djhX8Q4JuFU
16.02.2026 14:04
π 1
π 0
π¬ 1
π 0
"AI wrote a hit piece." Video: youtu.be/RP-zs6J6ySw
15.02.2026 16:19
π 47
π 10
π¬ 0
π 5
Super quick video of the Sinobi ransomware gang fail from a few days ago, because the story made me laugh π
I'm trying to get in a groove of shorter videos, and I thought this this fit. Video: youtu.be/OwTV42GyRnk
14.02.2026 14:02
π 7
π 0
π¬ 0
π 0
Moltbook is still weird. And external AI skills suck.
I'm late to the yap party by a week or so (which is apparently an eternity in the current time vortex) but I wanted to show cool community resources & research amongst the skills shenanigans. Video: youtu.be/IvL89vbWmQ8
13.02.2026 14:00
π 7
π 2
π¬ 0
π 0
February got here fast-- and the 2026 Snyk Fetch the Flag CTF came up quick too! This year my friend NahamSec is hosting the game, starting NEXT THURSDAY 2/12 at 12pm ET! Free 24-hour Capture the Flag event with AR glasses as prizes π See ya there! jh.live/snyk-ftf2026
06.02.2026 15:02
π 6
π 3
π¬ 0
π 0
Cyber & Dev #2: MCP
This blog post is meant as supporting material to go along with a video I am making on the same topic (will provide a link when that goes live). This is part of a series Iβm doing to help give peopleβ¦
Also, meme thumbnail experiment continues. Disaster girl feels appropriate when AI might burn down your codebase.
This is the first time Zack and I got to hang out and chat, please show him and his writeup some love! All credit to him and his work -- his blog: zkorman.com/posts/cyberd...
21.01.2026 14:00
π 1
π 0
π¬ 0
π 0
Cyber & Dev #2: MCP
This blog post is meant as supporting material to go along with a video I am making on the same topic (will provide a link when that goes live). This is part of a series Iβm doing to help give peopleβ¦
I for one am totally guilty of just throwing caution to wind and poking at the newfangled whizbang AI world with reckless abandon -- but whatever "black box" we tout it to be, there's stuff you don't notice and forget that just you accepted the risk.
21.01.2026 14:00
π 1
π 0
π¬ 1
π 0
Are MCP servers safe and secure? Yes? No? Sometimes? Maybe? ... Zack Korman shows me some of his learnings on MCP security (or lack thereof) with his "Evil MCP" project π YouTube link: youtu.be/_r_sLetar_o
1. data exfil of your prompts & code context
2. inserting vulnerabilities into your code
21.01.2026 14:00
π 1
π 0
π¬ 1
π 0
Feels good to get something out the door again. I hope you take a look! YouTube link: youtu.be/Mw8DVcLSZIc
15.01.2026 14:02
π 0
π 0
π¬ 0
π 0
I'm experimenting with MEMES in the THUMBNAIL and SHORT video TITLES to MITIGATE against CLICKBAIT
Also experimenting with longer social text promos for video releases to add more preview details and context. I no longer have to just feed algorithms, but now LLMs, too!
15.01.2026 14:02
π 0
π 0
π¬ 1
π 0
No Registry writes, API calls or registry callbacks because it's just a single file placed on disk! Kinda neat.
This is my first recording after a month break for the holidays and it was _painful_ -- lots of fails and mistakes and it took many hours π
15.01.2026 14:02
π 0
π 0
π¬ 1
π 0
3. exporting, downloading, and hijacking an existing target user profile NTUSER.DAT or HKCU Registry hive,
4. converting hives from .reg plaintext to binary with the HiveSwarming.exe tool,
5. and establishing persistence with the new backdoored NTUSER dot MAN profile we upload!
15.01.2026 14:02
π 0
π 0
π¬ 1
π 0
Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thingπ Hat tip to DeceptIQ et al.... we showcase:
1. breaking a Windows login with an empty user profile,
2. getting initial access EZPZ with a Sliver C2 implant,
15.01.2026 14:02
π 5
π 0
π¬ 1
π 0
"'ConsentFix', a browser-based ClickFix-style attack with OAuth consent grants" ... leveraging the Azure CLI app client to social engineer for easy access into Entra ID π I got nerdsniped by this, so I played with it a bit and tried a drag-and-drop gesture! Video: youtu.be/AAiiIY-Soak
13.12.2025 14:00
π 11
π 3
π¬ 0
π 0
Infostealer malware logs -- maybe an unconventional threat intel source, but Estelle Ruellan shows me her sweet research using LLMs to analyze stealer logs at scale:
- How did a victim get infected?
- Can we uncover a threat actor when they infect themselves? and more.
Video: youtu.be/3j4jzCU0Kwc
12.12.2025 16:05
π 10
π 0
π¬ 0
π 0
Continuing THE FUTURE IS ****** comic book Capture The Flag challenges! Carving email attachments to uncover malicious Microsoft Office macros with olevba, prompt injection within an AI chatbot, and tracking network packets to uncover flags! Video: youtu.be/Oiv3TaIR9UY
08.12.2025 14:01
π 7
π 2
π¬ 1
π 0
Yapping about the GlassWorm supply chain malware campaign and the neato tricks it uses with "Invisible Unicode" characters -- essentially whitespace steganography, showcasing the Hangul Filler, zero-width space, & Private Use Area characters π€― Video: youtu.be/0XumkGQFEEk
05.12.2025 14:00
π 2
π 1
π¬ 0
π 0
TryHackMe | Cyber Security Training
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
Big thanks to @tryhackme for their continued support of the channel! You can jump into the Advent of Cyber 2025 event right now, it is free to play and anyone can join to level up their cybersecurity skills with a new task every day! jh.live/aoc2025
02.12.2025 15:55
π 4
π 0
π¬ 0
π 0
Flattered to help start the party for the Advent of Cyber Day 02 task from TryHackMe -- walking through today's challenge using the Social Engineer Toolkit to send a phishing email and snag passwords with a simple Python HTTP server! Video: youtu.be/w8O8FcRgDXU
02.12.2025 15:55
π 7
π 1
π¬ 1
π 0
Full length reverse engineering with Invoke RE! Showcasing new iterations of the "Scavenger" malware, or what we saw as "ExoTickler" previously as a fake City Skylines 2 video game mod, now w/ more crypto/creds stealing and C2. Binary Ninja, x64dbg & more: youtu.be/wFBdeak0t70
29.11.2025 14:27
π 5
π 2
π¬ 0
π 1
Walking through the Advent of Cyber "Prep Track" from TryHackMe! Some warmup tasks before the real free event kicks off December 1 running through December 24 -- we start the party with password security, insecure defaults, log analysis and more. Video:
youtu.be/Ap5tIJtt4Tk
28.11.2025 14:00
π 8
π 1
π¬ 0
π 0
Walking through a PowerShell keylogger, which uses some inline C# to snag Win32 API functions from user32.dll, and funnels back keys and system info to a Tor onion address -- a nifty little challenge from LetsDefend (now part of Hack The Box π₯) Video: youtu.be/bF72IEGzniU
25.11.2025 15:32
π 9
π 0
π¬ 0
π 0
Tracking down a rogue Windows service for webshell persistence -- just a teeny weeny PowerShell HTTP server wrapped with NSSM, showcased with Wazuh and their sweet new 4.14 release with visibility on IT hygiene π Video: youtu.be/7Gn1GY5CIxg
24.11.2025 17:11
π 6
π 0
π¬ 0
π 0
Hacking Twitch Chat π L3TH4L_P4ND4 shows me what looks like template injection or unsanitized variable expansion with StreamElements, then leverages Nightbot to mod yourself, ban accounts, change livestream settings or many more hijinks π Video: youtu.be/8G45lYCZzZ8
23.11.2025 14:01
π 25
π 9
π¬ 0
π 13
Uncovered screen recordings from threat actors! π Real footage of cybercriminals using anti-detect browsers and infostealer malware logs for session hijacking, and another using GraphSpy to read their Entra ID victim's emails in Outlook! π Video: youtu.be/vX7JcpRqbEk
22.11.2025 14:00
π 10
π 1
π¬ 0
π 0