We still don't know if Trenchant and L3Harris notified Apple once it learned its iPhone-hacking toolkit had been stolen/leaked. The toolkit was later used to target people in China and Ukraine. techcrunch.com/2026/03/09/a...
We still don't know if Trenchant and L3Harris notified Apple once it learned its iPhone-hacking toolkit had been stolen/leaked. The toolkit was later used to target people in China and Ukraine. techcrunch.com/2026/03/09/a...
Nomma Zarubina, who once drunk-texted an FBI agent saying "Catch me baby. So many spies," is heading to U.S. prison for spying for Russian intelligence. www.occrp.org/en/news/russ...
Worth noting that while the judge rejected the DOJ's request to search the devices seized from Washington Post reporter Hannah Natanson, they did decide that the court "will conduct an independent judicial review of the seized materials" instead. storage.courtlistener.com/recap/gov.us...
Huge win for Hannah Natanson and the Washington Post today: the judge ruled that the government cannot search the devices they seized from her. www.washingtonpost.com/national-sec...
Trenchant and L3Harris had an exec steal internal tools for three *years* β and sell them to a Russian broker β before anyone noticed. cyberscoop.com/l3harris-exe...
Thank you! Happy to chat anytime.
A new investigation from @amnesty.org found that a journalist in Angola was targeted with Predator spyware in 2024. We also know that @citizenlab.ca found links to Predator infrastructure in Angola in 2023, and links to FinFisher infrastructure in 2015. www.amnesty.org/en/latest/ne...
Latest research from @citizenlab.ca shows @cellebrite.bsky.social tech used for human rights abuse in Kenya. Imagine if the company spent more time discussing who *not* to sell to. citizenlab.ca/research/cel...
Two years ago, a Norwegian researcher skeptical that pulsed-energy weapons could do damage to human brains β aka βHavana syndromeβ β built a device and tested it on himself. It didnβt go well. Someone from FFI, perhaps? www.washingtonpost.com/national-sec...
Decided to try Claude by revisiting a malware analysis project that I originally presented at OBTS in 2021: the CIA's OS X implant called Green Lambert. It's amazing what you can do with a terminal and ~15 min of free time these days.
My understanding is the emails are only encrypted if sent from one Proton user to another Proton user. So in that case they only have metadata to hand over.
Proton is required to comply with valid legal orders and has a track record of doing so.
The issue here isnβt Signal, but the use of biometrics on the work laptop.
Former exec at exploit development firm Trenchant, owned by L3Harris, admitted to selling internal hacking tools to a Russian broker. Did the company notify the vendors whose products were exploited so that they could be patched? techcrunch.com/2026/02/11/d...
Ah! I was going by work done by the ESET folks, but maybe they only linked Sandworm to parts of the attack?
Russiaβs Sandworm is back in the news, having recently been linked to the late December attack on Polandβs power grid. I recommend reading @agreenberg.bsky.social's work on the hacking group, starting with these WIRED articles and his 2019 book. www.wired.com/story/sandwo...
Correct. And because she had linked Signal on the phone to the desktop app, the FBI was able to access her messages.
If you've been laid off by the Washington Post this week and have any questions re: digital security, please email me on runa@granitt.io. I'll help you pro-bono for the rest of the month.
Weβve heard a lot about use of AI to clone the voices of celebrities, execs, and politicians. Hereβs a @defcon.bsky.social talk from @helicoptersofdc.bsky.social about cloning the voices of air traffic controllers to give false instructions to pilots. www.youtube.com/watch?v=JKwx...
The issue here was not Signal, but the use of Touch ID for authentication. The agents were able to access her Signal messages because they were able to access the laptop, and sheβd linked the mobile app to the desktop app.
The FBI has so far been unable to get into Washington Post reporter Hannah Natansonβs iPhone because itβs using Lockdown Mode β one of my favorite iOS features. You can turn it on for iPadOS, macOS, and watchOS too! www.404media.co/fbi-couldnt-...
Epstein was a New York Times subscriber; in 2017 he received an invite to the first CryptoParty my colleagues and I organized in New York. I've got no memory of him attending, though. www.justice.gov/epstein/file...
The old phone number for Norwayβs crown princess is in the Epstein files. That number now belongs to a 14yo girl in Stavanger who says sheβs receiving creepy calls and messages. Iβm surprised the provider recycled the number and didnβt just archive it. www.dagbladet.no/nyheter/stav...
Reminds me of the time some people reported issues with SolarWinds, but couldnβt quite make sense of itβ¦ until six months later or something.
Between June and December 2025, a βlikely Chinese state-sponsored groupβ compromised the infrastructure used by Notepad++ and served malicious updates to selectively targeted users. notepad-plus-plus.org/news/hijacke...
ProPublica names the two federal immigration agents who fired on Minneapolis protester Alex Pretti last weekend: Jesus Ochoa and Raymundo Gutierrez. www.propublica.org/article/alex...
Remains to be seen. The devices were seized and material was archived, but has yet to be reviewed. www.washingtonpost.com/national-sec...
Hereβs the specific language from one of the other documents. Biometrics is something you have, which they can demand that you present. Password is something you know, which they canβt force you to share. bsky.app/profile/runa...
Like a cryptoparty?