ServicesWorkAboutPricingBlog Get in Touch
Sep 24, 2026 SecurityPhishing

Getting an authorized phishing simulation past Google was harder than writing it

I built a phishing simulation for my own company. Chrome blocked my domain before I sent anything, and Gmail's documented allowlist does not work for this — messages with SPF, DKIM and DMARC all passing still went to spam. Here is what actually delivers, and why every vendor guide only half-explains it.

Sep 24, 2026 SecurityThreat Research

The phish passed DMARC because Moodle sent it

A MetaMask seed-phrase phish that passed SPF, DKIM and DMARC. The attacker never spoofed anything: they stood up a MoodleCloud site, enrolled the targets, and let Moodle's own mail pipeline send the lure. Then a kit that ships your recovery phrase to the operator as you type it.

Sep 21, 2026 SecurityManaged IT

SMBv1, in production, on a paid MSP's watch — twice

I run security and IT for small businesses, and onboarding a new client usually means cleaning up after their former MSP. Twice in a few months I found the protocol behind WannaCry still switched on in production, one of them a healthcare environment whose backups had also quietly died.

Sep 20, 2026 SecurityIncident Response

The backdoor was an app password and four filters

A small business's fraud case turned out to have a quiet half: a mailbox backdoor built so the owner's own security settings would look pristine. An app password that survives a password reset, and four auto-delete filters that make the fraud alerts disappear before anyone reads them.

Aug 21, 2026 SecurityThreat Intelligence

The phishing kit with no URL to block

A real, authenticated email led to a Browser-in-the-Middle kit that streams a live Google login from the attacker's own machine — no cookie to steal, no page to classify. Here's how I recovered its source, config, and command-and-control by replaying its own encrypted API, without ever opening it in a browser.

Aug 7, 2026 SecurityIncident Response

I got called about a popup. What was underneath it had been there six months.

Six months of malware hunting a client's QuickBooks and banking logins — then nagging them to pair their phone so it could read their 2FA codes. Cisco Talos documents that technique.

Jul 13, 2026 Data EngineeringPersonal Projects

I keep my whole life in a SQLite file

My bank knows what I spend. Apple knows how I slept. Google has years of my email. Each hands me its own dashboard behind its own login, and none will tell me how it all moves together — so I pulled it into one two-megabyte file I own.

Jul 11, 2026 AI AgentsEngineering

How I built Mercury, my personal AI assistant

A personal AI agent that lives on a Raspberry Pi in my living room — it texts me a daily briefing, watches my biometrics, buys things on a budgeted card, and can ship code fixes over SSH while I'm at the gym.

Jul 2, 2026 AIEssays

There is something archaic about the way we are doing AI that we'll look back on and laugh at

Neural networks are the pinnacle of human engineering — and woefully inefficient. A hot take on why the real frontier isn't bigger models, but doing far more with far less.

Mar 28, 2026 AIPhilosophy

On AI Sentience and the Alignment Problem

If the only way to solve AI alignment is to give a machine real emotional experience — and any being with emotional experience deserves autonomy — can we ever build an AI that is both perfectly aligned and fully under our command?