Kim Zetter
@kimzetter.bsky.social
19K followers 660 following 700 posts
Journalist - cyber/natn'l security. Speaker. Georgetown adjunct prof. Author - COUNTDOWN TO ZERO DAY: Stuxnet and the Launch of the World's First Digital Weapon Signal: KimZ.42 https://www.zetter-zeroday.com
Posts Media Videos Starter Packs
Pinned
kimzetter.bsky.social
Have tips? Story ideas? Something you think I should know about?

Reach me on Signal at KimZ.42

I cover cybersecurity and national security, writing about nation-state hacking, espionage, cyber warfare, cybercrime, and policy. I don't write about companies - unless they've done something wrong.
Reposted by Kim Zetter
lorenzofb.bsky.social
NEW: ICE purchased custom-made vans from a company called TechOps Specialty Vehicles (TOSV) that are equipped with fake cellphone towers designed to spy on phones.

TOSV president said the company integrates the cell-site simulators into their vans, but does not manufacture the surveillance tool.
ICE bought vehicles equipped with fake cell towers to spy on phones  | TechCrunch
The federal contract shows ICE spent $825,000 on vans equipped with “cell-site simulators” which allow the real-world location tracking of nearby phones and their owners.
techcrunch.com
kimzetter.bsky.social
"This is your legacy, Attorney General Bondi. In eight short months you have fundamentally transformed the Justice Department and left an enormous stain on American history. It will take decades to recover."
atrupar.com
Durbin: "What has taken place since January 20, 2025, would make even President Nixon recoil. This is your legacy, AG Bondi."
Reposted by Kim Zetter
qjurecic.bsky.social
just noticed this little detail in Illinois's complaint
UNITED STATES DISTRICT COURT NORTHERN DISTRICT OF ILLINOIS
EASTERN DIVISION
STATE OF ILLINOIS, a sovereign state;
CITY OF CHICAGO, an Illinois municipal corporation,
kimzetter.bsky.social
It seems like an unusual number of "influencers" die young. Can't figure out if it's because everyone calla themselves an "influencer" these days making influencer death stats artificially inflated; or if influencers really do die more often, thus making "influencer" the most dangerous profession
Reposted by Kim Zetter
atrupar.com
Sean Duffy says the safety of the air traffic control system will start being impacted next Sunday if the shutdown continues
Reposted by Kim Zetter
thetriibe.com
NEW — Today, Illinois and Chicago jointly filed a federal lawsuit, asking a judge to block Trump’s efforts to federalize and deploy troops to Illinois, and to declare the actions unlawful.

The lawsuit includes a history of Trump’s “animus” toward a Chicago, as well.

thetriibe.com/2025/10/live...
LIVE: Illinois, Chicago sues Trump to block National Guard deployment; Pritzker and Johnson to speak at presser today • The TRiiBE
The plaintiffs are asking a judge to block Trump’s efforts to federalize and deploy troops to Illinois, and to declare the actions unlawful.
thetriibe.com
kimzetter.bsky.social
What? Do you have a photo of that?
kimzetter.bsky.social
Challenge coin that FBI Director Kash Patel gives to US and foreign dignitaries he meets.
kimzetter.bsky.social
Since the Cybersecurity Information Sharing Act expired due to a lack of renewal before the gov shut down last week, the private sector is now less likely to share info with law enforcement about cyber threats/breaches they experience. The law had provided them legal protection for sharing info
Government flying partially blind to threats after key cyber law expires
The law offered legal protections for groups to share cyber threat intel with the federal government.
www.politico.com
kimzetter.bsky.social
"Encouraged by a manosphere that’s made patriarchal bullying seem cool and a White House that houses a cabinet made up of men who have degraded women and rolled back decades of protections for us in the workplace, men have never felt more emboldened to attack us both on and offline"
kimzetter.bsky.social
"If you need more evidence that our culture is becoming more misogynistic...just look at Rory McIlroy’s wife’s Ryder Cup experience. While some [media] have been referring to the fans’ behavior..as 'raucous' or 'unruly' the behavior was pure misogynistic abuse, and it’s a growing movement" in the US
The Misogynistic Abuse Directed at Rory McIlroy’s Wife at the Ryder Cup Is Deeper Than Golf
It shows a cultural shift, one in which men feel emboldened to attack women in public without shame or consequence.
www.glamour.com
kimzetter.bsky.social
Both Google and Samsung also have tags, and there are a few other companies as well.
Reposted by Kim Zetter
mikespecter.com
Today, my research group @ Georgia Tech released a paper on vulnerabilities in Tile --- the second largest device finding network after Apple's AirTags.

You can read about it in Wired, reporting by @kimzetter.bsky.social!
www.wired.com/story/tile-t...
kimzetter.bsky.social
Tile stores location info about user's tags on its servers, allowing company to track all users all the time, contrary to company claim that only tag users can see location of their tags. Tile's terms say it can share this information with law enforcement at its discretion, with or without subpoena
kimzetter.bsky.social
Tile location-finding tags, unlike Apple/Google tags, broadcast MAC address/unique ID unencrypted, letting stalkers, Tile or LE track people/items. Anti-theft feature also undoes anti-stalking feature - any tag in anti-theft mode is invisible to scans looking for stalkers. My story for @wired.com
Tile Tracking Tags Can Be Exploited by Tech-Savvy Stalkers, Researchers Say
A team of researchers found that, by not encrypting the data broadcast by Tile tags, users could be vulnerable to having their location information exposed to malicious actors.
www.wired.com
Reposted by Kim Zetter
klonick.bsky.social
Last time he randomly attacked a CEO of a private company it was Intel and three days later they announced they were giving the US govt 10% of the company
kimzetter.bsky.social
Interesting article about how judges increasingly require data breach victims to show exactly how they were harmed by a breach and specify the breach that caused harm. Seems like an unfair/unrealistic demand - stolen data gets sold/re-sold and direct knowledge of harm might not come until yrs later
‘No Harm, No Foul:’ Courts Take Tougher Line on Data-Breach Suits
Plaintiffs are facing a higher bar on what constitutes ‘harm’ when their personal data is exposed, lawyers say.
www.wsj.com
Reposted by Kim Zetter
ericjgeller.com
Don't get too excited about AI's ability to find software vulnerabilities, @rgblights.bsky.social said today — we'll never be able to keep up w/ the patching, esp. for unsupported & poorly maintained software. My report from Google's Cyber Defense Summit: www.cybersecuritydive.com/news/ai-vuln...
kimzetter.bsky.social
UK arrested man suspected of conducting cyberattack that affected European airports last wk. Collins Aerospace, maker of software impacted by hack, "appears to be rebuilding the system...after trying to relaunch it on Monday" and told airlines to expect "at least another week" without the program
Man arrested in connection with cyber-attack on airports
The National Crime Agency (NCA) said a man in his forties was arrested in West Sussex.
www.bbc.com
kimzetter.bsky.social
The servers were seized in August
kimzetter.bsky.social
Only a decade behind the rest of the tech world
campuscodi.risky.biz
GitHub will require a FIDO-based two-factor authentication method to publish updates to npm packages.

The company will also deprecate legacy long-lived npm tokens and roll out new ones that last only seven days.

github.blog/security/sup...
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
github.blog
kimzetter.bsky.social
This is best story by far about the SIM farm uncovered in New York by Secret Service. The intent of the farm is not, as suggested by other stories, to disrupt Secret Service protection of dignitaries attending the UN or taking out mobile service for all NY but about managing criminal enterprises
Secret Service traced swatting threats against officials. They found 300 servers capable of crippling New York’s cell system | CNN
A Secret Service unit set out to unmask the layers of burner phones, changing phone numbers and SIM cards that were swatting American officials. It ended with the largest seizure of SIM servers and ca...
www.cnn.com
Reposted by Kim Zetter
atrupar.com
Pritzker: "One of the reasons Trump wants to send troops into cities is bc he wants to be able to take control of the 2026 elections...if they've got troops in cities, & it becomes a kind of norm for people, then it won't be abnormal for them when they're going to vote having troops at ballot boxes"
kimzetter.bsky.social
Everyone on the list they sent it to is a journalist, so if he's no longer calling himself a journalist, they don't seem to be aware of that. And his email back to them describes his web site as a "journalistic platform." So it seems like he's being intentionally vague.