Profile avatar
4lgorhythm.io
(she/they) 🇵🇭 bicolana in charlotte, nc | infosec red team + social engineering + wtm ambassador + disability advocacy + mechanical keyboards + synthesizers + #hackerfit + #redteamfit https://bio.link/4lgorhythm
19 posts 183 followers 262 following
Prolific Poster
Conversation Starter

All federal employees must respond to an email from a Nigerian prince with their bank account number or risk being terminated.

yeeeaaahhh i’m the social engineering lead at my firm. *sea shanty 2 intensifies*

Balatro launched one year ago today I often say I made this game for myself and friends, but seeing so many people connect with Balatro has filled this past year with joy. Thank you players, your love and support have kept Balatro thriving! I appreciate you all naneinf! 🍌

@hatless1der.com and I are really excited to run this @myosint.training 2-day, affordable OSINT training in Boston right before the conference. Details and registration link are www.myosint.training/courses/2025.... It'll be highly hands-on and cover a wide range of #OSINT topics!

I ❤️ shmoocon

Graduation day is almost here - just one more sleep until the final ShmooCon! 🎓 Check out the events schedule, amazing talks, and health policies (masks required) at https://shmoocon.org. See you soon!

I can’t wrap my head around the industry obsession with phishing portmanteaus. FOH with that “tishing” and “quishing” nonsense, what is wrong with just calling them Teams and QR code phishing 😭

For those heading to #ShmooCon or #ShmooLobbyCon You can find a much more filled out Hiring list here: lobbycon.org and if you wanna connect, a Shmoo slack is here: join.slack.com/t/shmoocon/s...

NEW: Automated license plate recognition systems used by police across the US are leaking the real-time video feeds and vehicle data collection to the open internet. @mattburgess1.bsky.social and @dmehro.bsky.social report: www.wired.com/story/licens...

Well, I observed the first hostile QR code in public today. And when I say "hostile" I mean it was the local Girl Scout troop that had set up a QR code for ordering cookies. If this had been a phishing test I would failed.

The Call for Presentations (CFP) is now open for the Layer 8 Conference. We solely focus on OSINT and Social Engineering topics. Conference is in Boston, June 14. CFP Info: layer8conference.com/call-for-spe... You can do it!

Welcome to 2025! If your new years resolution is to learn a new skill why don't you have a look at some of our guides on open source research? www.bellingcat.com/category/res... Want help? We have a community of people eager to learn alongside you and collaborate. discord.com/invite/belli...

I write to computers using a snake language, to give humans things they think they want.

Attention @shmoocon.bsky.social, you are hereby registered for #ShmooFAQ, the Final Exam! Please report Saturday night at 9pm, with a team of up to 5 people. Don’t forget your #2 pencils, as all answers will be graded live by optical reader, the Mog-tron 9000. Don’t be late, and #DFIU!

The 2024 #OSINT quiz is ready for you to explore! But this year, I had a special guest, @sector035.bsky.social, who also made some of the tasks. So, the adventure got more spicy! 😀 The quiz is here: github.com/seintpl/osin... Have fun!

Custom sprite injection over WIFI using RCE on a legit copy of Pokémon pearl :)

Friends, FBI has responded to my FOIA request for Kevin Mitnick's files, and have made them available to everyone via the FBI public portal here: vault.fbi.gov/kevin-mitnic...

“still punk as fuck,” i whisper as i place the heating pad against my back and the ice pack on my shoulder

OK, I am adding blogs to my #OSINT feeds on the knowledge base. this is a work in progress, so stay tuned. I will also provided an organized OPML file shoon. knowledgebase.plessas.net/OSINT-Feeds-...

Ever wondered why ~ represents the home directory on unix systems? It’s an artifact of a very particular keyboard. The Lear-Siegler ADM-3A terminal was quite popular in the 1970s, and happens to have a HOME key that is also a tilde. Notice anything else?

How would I hack YOU during the holidays? By messaging you about the packages, deals & giveaways you care about! Share these scam types with your fam so they know exactly which emails, texts, calls, and posts to be wary of this December. Stay politely paranoid, folks! www.youtube.com/watch?v=6Ewt...

The CFP for the very first hacker con I submitted to and spoke at is open. I’m also on their CFP board! Submit to Thotcon’s CFP by January 1, 2025! If you make submitting to a con in 2025 your New Year’s resolution, you’ll accomplish it on day 1 if you submit on Jan 1. www.thotcon.org/cfp.html

We created a Starter Pack of Social Engineers. Know of others? Let us know and we'd love to add them! #SocialEngineering bsky.app/starter-pack... #phishing #vishing #smishing #socialengineer

This festive season I’m sharing a video every day for the next 24 days showing useful OSINT tools & techniques. Creating this OSINT Advent Series has been a lot of fun and I hope it’s helpful for the ever-growing OSINT community! 🎄👇

Today would have been the 89th birthday of Joy Lim Arthur. Born in Manila, she came to the US to earn her engineering degree, then went on to serve as a senior research engineer for the US Army from 1958 to 2005, developing counter-measures for electronic attacks. #WomeninSTEM #Engineering 🧪

It's barely Monday and I've already been cybered

The Layer 8 Conference is back! Saturday, June 14 in Boston! More info here: layer8conference.com Hope to see you there! #OSINT #SocialEngineering

A novel phishing attack abuses Microsoft's Word file recovery feature by sending corrupted Word documents as email attachments, allowing them to bypass security software due to their damaged state but still be recoverable by the application. www.bleepingcomputer.com/news/securit...

treyarch remade og nuketown in black ops 6 because “probably a large percentage of [their] players never experienced the original one” 💀💀💀 wow thanks i don’t feel ancient at all youtu.be/DUeKKzUYp2U

The season of exploring, sharing, and learning is upon us! I compiled a small list with the best OSINT & cybersecurity advent calendars with prizes, team competitions, CTFs, live streams, and compelling storylines! Check them out on my new blog post 👇 gralhix.com/2024/11/30/t...

A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials. www.bleepingcomputer.com/news/securit...

Buffer overflow today. Butter overflow tomorrow.

The #OSINT community is incredible on here. It's a little harder to find #SocialEngineers. Are you one who does #phishing, #CovertEntry or any of the other types of #SE jobs? Happy to add you to this starter pack. go.bsky.app/ScRhm6z

for the mechanical keyboard enjoyers: found a home for the metal artisan keycap i got from boardsource.xyz at defcon 32! adjusting to the colemak layout has been something else 🥴 ErgoDox Wireless Pro by SliceMK > KAM Superuser keycaps > Zeal Zilent V2 67g silent tactile switches

Daniel Grzelak has released Awseye, a so-called Shodan for AWS, an OSINT and reconnaissance service that tracks and analyzes publicly accessible AWS data awseye.com

We've been working hard to put together something special for the #cybersecurity community for the holidays. Join us, Charlotte ISSA, and Phish Club at the Booth Playhouse for #Charlotte Winter Cyber Talks on December 12th in Charlotte, NC. Tickets: reduced.to/298z9 Discounts in the reply.

Women in Cyber Scholarships and Mentor from FS-ISAC. For post-secondary and graduate students with at least a year left to their studies. fsisac.submit.com

DualCore and I spoke at the Red Team Village this year. Here are the slides. QR code with link to gist with all the reference links on last page. Unfortunately it wasn't recorded. docs.google.com/presentation... #redteam #purpleteam #redteamvillage

bro, so to run a program, i "execute" it, but to stop it i "kill" it? computers are barbaric, bro