Zach Edwards
@thezedwards
data supply auditor | privacy & ad tech expert | internet threats Personal @ victorymedium.com Work @ Staff Threat Researcher @ Infoblox.com Co-Founder @ DecryptAds.com
This Koi report on an alleged Chinese espionage campaign seems to be a complete dumpster fire AI hallucination … ⛈️⚖️ “Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage” www.theregister.com/legal/2026/0...
I’ve always loved that picture of President Obama so like a decade ago I commissioned an artist to paint a version of it on this giant rolling tray.
The Former Jordan Lake Air Force Space Surveillance Station (AFSSS) in Alabama is available for purchase until May 11th... a great opportunity for a 1,032 +/- ft horizontal antenna if you're in the market for that type of thing... fun hacker campground? realestatesales.gov/asset-detail... 📡🛰️🏕️🎉
It's taken ~5 years but Brave browser is the first browser to come up w/ a solution to prevent device fingerprinting being done by y2u[.]be on their YouTube spam campaigns. It's a subtle fix but the browser now takes their URls and rewrites to youtube directly. issue @ github.com/brave/brave-...
Today our team at @silentpush.bsky.social released research we’ve been working on all year – a magnum opus 39-page report on the state of Bulletproof Hosting Providers. Brief thread with some details Read the report @ www.silentpush.com/white-papers...
Found a "great deal" in about 30 seconds of hunting -- 1k abuse reports on YouTube for $100 - a mere 10 cents per report! This is the type of bot farm product that shit birds use when they want to harass researchers and other folks.
YouTube suspended my ~15+ year old account and all my videos due to a video I recorded about scammers targeting US government and military offices, which was embedded into articles like @ www.vice.com/en/article/w... from @josephcox.bsky.social I was likely targeted by a mass reporting campaign.🤡
a 5+ year old bug ticket was finally closed by Google - this was actually the last significant investigation into Chrome extensions that I did because the feedback loop was so challenging definitely still a place with research opportunities and threat actors regularly doing weird stuff! 🖖
fun to see my mom in this crowd shot from the No Kings rally in Houston featured by the Houston Chronicle @ www.houstonchronicle.com/projects/202...
I’ve got this 100+ year old copy of an old play about Abraham Lincoln’s life which was owned by someone named Alden Nash who had an interesting personal emblem that he screen printed & glued onto the cover page. The play was shown at the Birmingham Repertory Theatre then the Hammersmith Playhouse.📚
Our team @silentpush just dropped a definitive look at SocGholish (operated by TA569) and the initial access broker ecosystem they are facilitating. Big thanks to past researchers who have worked on SocGholish! We've got details about our visibility @ www.silentpush.com/blog/socghol... 🖖🏻
This AI Agent from Cluep[.]com claims to scrape data from: Twitter, Youtube, Linkedin, Pinterest, Reddit, Tumblr and TikTok They claim that they are scraping these networks then using "APIs" to further scrape "the user’s geographic coordinates, device type and demographic data" how? WTF?
21 year-old money launderer for a $265 million crypto theft ring was helping members exchange crypto for cash and mailing $25k in cash through the mail put inside "Squishmallow" stuffed animals www.cnbc.com/amp/2025/05/... 🫧🐰
It was an honor and a pleasure to speak at Bsides SF - totally love that they had an artist draw my presentation ⬇️
...and the “solution” is an easy “click fix” copy and paste trick, which leads to malware if the unsuspecting developer completes the process.
cheers ya it's an interesting definition. i played w/ Gemini awhile ago and confirmed it still doesn't give you lists of URls but if you click the "Retry with Google Search" it does.. any ruling broadly covering this search concept could impact Gemini - would also impact Programmable Search Engine
The singular organization who has prevented WWIII for decades is being attacked by this administration. We're losing allies, losing trade deals and becoming less safe due to how these folks see Russia as allies and all our traditional allies as enemies. This is completely backwards global diplomacy.
I had to triple check this was accurate, that the President of the United States is endorsing three garbage crypto tokens tied to countless scandals, and likely untold numbers of investors got a heads up and made bank off the announcement. In the end, this will lose people money & hurt our country.
X specifically setup bot defenses so that viewing tweets requires having an account. You can see in this video if you open a tweet in an incognito / non-logged-in state, then click "replies" you immediately are prompted w/ a login, then blocked from reading more.
The top downloaded / viewed PDF across the .gov ecosystem yesterday was for the OPM forking memo @ www.opm.gov/media/cbklse... according to analytics.usa.gov
... to connect up their criminal client websites through a series of CNAME records they control, which are then mapped to hundreds of IP addresses that are hosted at a variety of providers. You can see this DNS data flow via the chart attached:
You can see this exact same behavior on their app-ads.txt file @ www.nytimes.com/app-ads.txt -- all DIRECT accountIDs, all owned by NYtimes directly. If you are a publisher, this is the best way to prevent 3rd parties from selling your user data. But it's also complex and requires a big team.
All websites and apps need to appreciate that all vendors they list within their ads.txt + app-ads.txt are being given enough data about your users to sell it. That's why really serious orgs who really know what the fuck is going on with the bid stream like the NYTimes, have ZERO 3rd party vendors:
What annoys me the most about this beyond the macro privacy concerns of RTB? It's 2025 & app companies who have faced some of the biggest data privacy scandals in the world are still responding to reporters and sharing their "list of data partners" without including a link to their app-ads.txt file.
imo it's really important to not muddle that Apple settled this case because Siri can unintentionally record conversations *but* Apple also said numerous times that the lawsuit's argument of "and the audio data was sold + used for ads" was basically laughable... Apple doesn't admit to this! ⤵️
Our team believes that threat actors abusing cracked versions of Acunetix is a new threat vector for numerous enterprise organizations. Keep your eyes peeled for that scanner hitting your endpoints!
Our team was able to acquire additional details about how Araneida works, and can report that the threat actors behind this are openly bragging in a Telegram channel about how many successful attacks the software has facilitated. You can see the interface here in this video.
The most prominent effort to abuse a cracked copy of Acunetix is a tool called “Araneida scanner” – this was first mentioned publicly last year as having the SSL certificate from Acunetix from Chris Duggan at TLP R3D Intelligence Ltd.
100% of the domains launched from this campaign are hosted across 2 IP addresses -- and there are dozens of similarly named domains mapped to these IP addresses.