Tim (Wadhwa-)Brown :donor:'s Avatar

Tim (Wadhwa-)Brown :donor:

@timb-machine.infosec.exchange.ap.brid.gy

push(@fediverse, "Adversarial Engineer"); # i hack in Perl ๐ŸŒ‰ bridged from โ‚ https://infosec.exchange/@timb_machine, follow @ap.brid.gy to interact

83
Followers
8
Following
1,094
Posts
11.11.2024
Joined
Posts Following

Latest posts by Tim (Wadhwa-)Brown :donor: @timb-machine.infosec.exchange.ap.brid.gy

[meta]

Tune, mayo and pasta. Quick and easy and I'll never tire of the taste.

07.03.2026 15:20 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Half thinking of proposing a couple of sessions on threat modelling and cyber exercises for @emf... Content is already written and it seems a shame to waste it.

#emfcamp

07.03.2026 10:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

New leader on my EIC benchmark exam and it's my latest 17 year old T-Level student mentee.

06.03.2026 22:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

<take temperature="hot">If AI was so great at pen testing, none of the AI would have vulnerabilities.</take>

06.03.2026 21:17 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

[meta]

The number of new tabs is inversely proportional to the amount of time spent in online meetings.

06.03.2026 18:33 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

[meta]

I participated in under the legal age use of SunOS...

04.03.2026 22:17 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

s/q/n/g; # Quick patch to comments on US foreign policy

04.03.2026 21:55 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Tim's observation: in every organisation, there is a gap between enterprise security visibility and what funds the business/brings in customers/turns a profit. Understand your business' application stack and close that gap.

03.03.2026 16:31 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Good news, emails to their MSSP to start the exercise bounce. No TI injects for you then....

02.03.2026 17:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

We've hit that point in the timeline when our generation start to EOF :(. stealth, FX, christer, roy...

02.03.2026 09:09 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the week:

Strategy:

* https://github.com/jacobdjwilson/awesome-annual-security-reports - all you can eat annual reports, thanks @jacobdjwilson

Detection:

* https://github.com/EFForg/rayhunter - hunting cell site simulators with @eff

Exploitation:

* [โ€ฆ]

28.02.2026 15:16 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting links of the week:

Strategy:

* https://www.enisa.europa.eu/publications/the-enisa-cybersecurity-exercise-methodology - dressing up as a 17 year old or Russian, the EUropean way
* https://storage.pardot.com/898251/1772108192Ii5PhZV6/Annual_Cyber_Security_Research_Report_2025.pdf - [โ€ฆ]

28.02.2026 10:46 ๐Ÿ‘ 0 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Ethical AI pivot. Providing the compute and data to track, evidence, prosecute wacriminals.

28.02.2026 18:50 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

We have always been at war with Meglomania.

#microfiction

06.01.2026 10:07 ๐Ÿ‘ 0 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Anyone fuzzing Wayland yet?

28.02.2026 15:37 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the week:

Strategy:

* https://github.com/jacobdjwilson/awesome-annual-security-reports - all you can eat annual reports, thanks @jacobdjwilson

Detection:

* https://github.com/EFForg/rayhunter - hunting cell site simulators with @eff

Exploitation:

* [โ€ฆ]

28.02.2026 15:16 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting links of the week:

Strategy:

* https://www.enisa.europa.eu/publications/the-enisa-cybersecurity-exercise-methodology - dressing up as a 17 year old or Russian, the EUropean way
* https://storage.pardot.com/898251/1772108192Ii5PhZV6/Annual_Cyber_Security_Research_Report_2025.pdf - [โ€ฆ]

28.02.2026 10:46 ๐Ÿ‘ 0 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

The window falling starts on Monday. Operation tiny dolls.

27.02.2026 19:37 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

[ukpolitics]

How good a leader he'll make for the country, we're still yet to really see but Zac Goldsmith is a politician of our generation. Some of his shit posting has been truely epic.

27.02.2026 07:50 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
NI Education: Schools told to set up SEN classes to reduce places shortfall The Education Minister Paul Givan says the provision must now be put in place for all mainstream schools.

[ukpolitics]

Another car crash:

https://www.bbc.co.uk/news/articles/cedzv4xen99o

My wife taught SEN for over a decade, the government should be listen to to experts and not trying to cram already disadvantaged kids into mainstream education.

26.02.2026 22:59 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Watching one of our best red teams battle with his own soul cause I'm asking him to focus on artefact creation rather than defense evasion or trade craft.

Like, what kinds of things inhibit these techniques, let's see which ones the customer has in play and how well they are integrated with the [โ€ฆ]

26.02.2026 18:41 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

A couple of interesting links on SD-WAN security:

* https://www.mplify.net/wp-content/uploads/MEF_88.pdf - securing application flows in SD-WAN solutions (vendor neutral)
* https://arxiv.org/pdf/1811.04583 - focusses on orchestration, management and control (iterates through all the various [โ€ฆ]

25.02.2026 22:35 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616 Cisco Talos is tracking the active exploitation of CVE-2026-20127, a vulnerability in Cisco Catalyst SD-WAN Controller, formerly vSmart, that allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges.

Today's oofness is on us :(:

https://blog.talosintelligence.com/uat-8616-sd-wan/

#threatintel, #sdwan

25.02.2026 17:58 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

[meta]

Spoke to 2 of my old Portcullis team today and both are well (in one case 16 years on). There will come a time when I'll hear some sad news but today is not that day.

25.02.2026 17:43 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Got any plans to seize control and create an army from any household IoT today?

25.02.2026 07:58 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

LLM thought: Move quickly and delete inbox.

23.02.2026 19:09 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the (last 2) week(s):

Threats:

* https://github.com/AssoEchap/stalkerware-indicators - stalkerware IOCs
* https://github.com/AmnestyTech/investigations - @AmnestyTech investigations

Detection:

* https://github.com/spaceraccoon/vulnerability-spoiler-alert-action - [โ€ฆ]

22.02.2026 15:13 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Seeding a Git repo for the cyber exercise in a few weeks...

22.02.2026 17:57 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

What if it turns out we've *all* already been recruited by CIA and we just don't know it yet?

#microfiction

30.11.2025 19:35 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the (last 2) week(s):

Threats:

* https://github.com/AssoEchap/stalkerware-indicators - stalkerware IOCs
* https://github.com/AmnestyTech/investigations - @AmnestyTech investigations

Detection:

* https://github.com/spaceraccoon/vulnerability-spoiler-alert-action - [โ€ฆ]

22.02.2026 15:13 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0