banner
kasstoner.bsky.social
@kasstoner.bsky.social
Reposted
For local roles, I am also a USCCA certified firearms instructor. With Christmas coming and kids waiting for Santa, referrals and introductions are deeply appreciated. Sharing this thread helps increase visibility during a very difficult time.
#Hiring #CyberJobs #JobHunt
December 8, 2025 at 5:23 PM
Reposted
I can support Sales and Sales Engineering teams as a subject matter expert when needed, providing technical depth and threat context without limiting my role as a practitioner. I also write white papers and blogs, create podcast content, and speak on security topics.
#InfoSec #Tech
December 8, 2025 at 5:23 PM
Reposted
I am urgently searching for work. My unemployment ends soon, my family is approaching eviction, and with Christmas coming I am trying to keep things steady for my kids. I have been interviewing since September and reached several final rounds but still have not secured a role.
#OpenToWork #JobSearch
December 8, 2025 at 5:23 PM
Reposted
I am sharing this because our situation has become urgent. I have been unemployed since late September despite active interviewing, my family is facing eviction. About $8,000 is needed to stop it due to rent & legal fees. Any help or shares are appreciated

gofund.me/699d76e84
#HelpNeeded #MutualAid
Donate to Urgent Help Needed to Avoid Eviction, organized by Billy Gray
Why I’m Asking for Help This is not something I ever imagined I would need to do, … Billy Gray needs your support for Urgent Help Needed to Avoid Eviction
gofund.me
December 13, 2025 at 6:18 PM
Reposted
Today, a new OSINT lesson with MJ landed in the inboxes of our paid subscribers. This one takes you on a journey to answer the question: Is the sex worth the OPSEC risk? Subscribe today and find out.

www.bullshithunting.com/p/a-free-osi...
A Free OSINT Lesson: How Your "Friend with Benefits" Became an Insider Threat
The sex is great though...
www.bullshithunting.com
July 30, 2025 at 6:24 PM
Reposted
God I mourn 2019 Twitter.
August 12, 2025 at 5:37 PM
Reposted
In all inboxes: The Trick to Cooperation. Systems may run on routine, but for those pulled into them, that routine can feel destabilizing and demeaning. Today, Kennedy reflects on what it means to navigate a case from the other side, from the witness stand.

www.bullshithunting.com/p/the-trick-...
The Trick to Cooperation
How clarity and compassion creates results
www.bullshithunting.com
September 24, 2025 at 3:19 PM
Reposted
🚨NEW!

From @kennedycatherine.bsky.social and arguably one of her best: open.substack.com/pub/bullshit...
The Trick to Cooperation
How clarity and compassion creates results
open.substack.com
September 24, 2025 at 3:21 PM
Reposted
🚨NEW! From yours truly and @kennedycatherine.bsky.social

A Fake Prince, a Game Show Contestant and the Devil

open.substack.com/pub/bullshit...
A Fake Prince, a Game Show Contestant and the Devil
How an intelligence officer's trivia show winnings were a gift to us all
open.substack.com
October 1, 2025 at 2:40 PM
Reposted
Going no-contact with my partner for a week (she left her phone in an Uber on the way to the airport , leaving me to negotiate over the phone with the driver I found on Instagram to get the phone back, a man who seemingly believed I could have psychic knowledge of a strangers phone)
October 25, 2025 at 6:04 PM
Reposted
👏 NEW! Witchgrass - a podcast from us pirates on the Permanent Record Research crew, featuring @kennedycatherine.bsky.social and @mjbanias.bsky.social.

A cold, Canadian story that will teach you how us maniacs do what we do.

Wherever you get your podcasts:

open.spotify.com/episode/4vWj...
Witchgrass: Episode One
open.spotify.com
October 30, 2025 at 4:53 PM
Reposted
deck.blue is the 3rd-party TweetDeck for Bluesky!

- Multi-column & multi-account
- Bookmark posts
- Chat/DM columns
- Disable reposts
- #hashtag columns
- Keyboard shortcuts
- Color themes
- Gallery/Grid Mode
- Filter notifications by type
- Inline translations
- Scheduling

Patreon | Ko-fi
deck.blue
Get the most out of Bluesky with a multi-column layout
deck.blue
December 23, 2024 at 6:58 PM
Reposted
Got an image from a conflict zone? Stop guessing the location. Use Maxar satellite imagery for context and LiDAR data to literally see through tree cover. That's the advanced geolocation OSINT tradecraft we get into this week. Theosintoutput.com

#podcast #geolocation #osint #imagery
The OSINT Output Hosted by Tim and Chris
Join Tim and Chris as they share the latest updates on open-source intelligence, new content, and opportunities for collaboration. Discover insights, connect with us, and gather fresh ideas for you…
Theosintoutput.com
November 10, 2025 at 7:32 PM
Reposted
The Human is the Most Obvious Vulnerability. (They literally just called and pretended to be IT.) The Scattered Lapis Hunters hack on Salesforce was pure social engineering genius. They stole a database of CEOs and government contacts. Listen now: theosintoutput.com

#podcast #socialengineering
The OSINT Output Hosted by Tim and Chris
Join Tim and Chris as they share the latest updates on open-source intelligence, new content, and opportunities for collaboration. Discover insights, connect with us, and gather fresh ideas for you…
theosintoutput.com
November 13, 2025 at 9:41 PM
Reposted
If you use WhatsApp, assume your number is already in someone's database.
Source: www.wired.com/story/a-simp...
November 18, 2025 at 4:48 PM
Reposted
What you can do NOW: Go to WhatsApp Settings > Privacy and set your profile photo, about info, and status to "My Contacts" or "Nobody." This won't hide your number, but it limits what strangers can see. This is recommended as well for platforms like Telegram & Signal.
November 18, 2025 at 4:48 PM
Reposted
Meta's response? They thanked the researchers and called it "basic publicly available information." They fixed rate limiting in October 2024, but provided no evidence they stopped malicious actors from doing the same scraping over the years...
November 18, 2025 at 4:48 PM
Reposted
Who's at risk? Scammers of course have a goldmine. But worse: researchers found 2.3M WhatsApp numbers in China & 1.6M in Myanmar...countries where the app is banned. Governments could hunt down users. People in China have been detained just for having WhatsApp installed.
November 18, 2025 at 4:48 PM
Reposted
Not only numbers were exposed. 57% of accounts had profile photos, 29% had public bio text. In India, 62% had exposed photos. In Brazil, 61% had photos exposed. Most users don't enable privacy settings (More on this soon...)
November 18, 2025 at 4:48 PM
Reposted
A researcher warned WhatsApp about this exact vulnerability in 2017. Meta dismissed it, saying privacy settings were "working as designed" Fast forward 8 years later, still vulnerable until October 2024 😅
November 18, 2025 at 4:48 PM
Reposted
Here's how simple it was: WhatsApp lets you check if a phone number is registered. Researchers automated this for every possible number combination at ~100 million checks per hour. Meta had ZERO effective rate limiting in place (because why would anyone want that?)
November 18, 2025 at 4:48 PM
Reposted
🚨 MASSIVE: Researchers scraped 3.5 BILLION WhatsApp phone numbers using the app's contact discovery feature, along with profile photos and bios for millions of people. This would be "the largest data leak in history" if it hadn't been done by researchers 🧵
November 18, 2025 at 4:48 PM
Reposted
The problem with that, too, is if there's a clear enough pattern of life with the phone, you can use the absence of its movement and identification at a second location as probative information.
September 17, 2025 at 3:51 PM
This. If people don't realize what kind of databases/websites are online. As someone in the #osint community there is SO much
People radically underestimate the sophistication of OSINT tools that aren't "looking at posts on the internet" and with a few pictures of your location and trajectory through an area, someone could connect you to your device in maybe an hour or so.
September 18, 2025 at 9:23 AM
Reposted
People radically underestimate the sophistication of OSINT tools that aren't "looking at posts on the internet" and with a few pictures of your location and trajectory through an area, someone could connect you to your device in maybe an hour or so.
September 17, 2025 at 3:49 PM