惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
博客园 - 司徒正美
博客园 - 【当耐特】
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
宝玉的分享
宝玉的分享
V
V2EX
S
SegmentFault 最新的问题
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
L
LangChain Blog
D
Docker
腾讯CDC

DomainTools Investigations | SecuritySnacs

SecuritySnack - Account Farmers and Sellers Scarcity Scams SecuritySnack - Hijacking Corporate Sessions Cybersecurity Reading List - Week of 2026-06-01 Cybersecurity Reading List - Week of 2026-05-04 DPRK Contagious Interview: Developer Workflow Compromise The AI Frame Campaign Continues Cybersecurity Reading List - Week of 2026-04-06 SecuritySnack - OpenAI Anti-Ads Malware SecuritySnack - CloudFlare Anti-Security For Phishing Cybersecurity Reading List - Week of 2026-03-02 SecuritySnack - Idolized Crypto Scams Cybersecurity Reading List - Week of 2026-02-02 SecuritySnack: Phishing Interviews Pay to Lose: Dubious Online Gambling Games SecuritySnack: Repo The Repo - NPM Phishing Banker Trojan Targeting Indonesian and Vietnamese Android Users SecuritySnack: 18+E-Crime Cybersecurity Reading List - Week of 2026-01-05 Hunting for Malware Networks TrickBot the Unperturbed Silicon Valley Bank B2B2C Supply Chain Attack: Hotel’s Booking Accounts Compromised to Target Customers .GA Moves Away from FreeNom Cybersecurity Reading List - Week of 2025-03-04 Cybersecurity Reading List - Week of 2025-06-16 Cybersecurity Reading List - Week of 2025-05-19 "airdrop" Domain Bloom Cybersecurity Reading List - Week of 2025-04-21 Cybersecurity Reading List - Week of 2025-03-24
Cybersecurity Reading List - Week of 2026-08-17
DomainTools · 2026-08-18 · via DomainTools Investigations | SecuritySnacs

I’m tired of AI. 

I’m tired of hearing about it, of reading about it. I’m tired of otherwise-sensible people falling into foolish behavior around it. I’m tired of the banners and the claims and the manufactured inevitability.

Why yes, I was at BlackHat and DEF CON recently, why do you ask?

In all seriousness: what we are seeing with LLMs right now in security is less revolutionary than you might think. A few months ago I wrote about Thomas Kuhn’s “History of Scientific Revolutions” and the concept of mop-up operations, where science becomes concerned only with filling in the blank spots of the world we think we know. LLMs are excellent attackers in that respect: they are pointed straight at our ever-growing mountains of technical debt, and they can assess and exploit it much, much faster. It’s not creative, and it’s not imaginative. It’s predictive. This point is hard to catch for management folks removed from the actual work. And the answer is not more AI.

The answer - as it almost always is in security - is people. 

As mentioned above, I was lucky enough to attend BlackHat and DEF CON again this year. And while companies plastered AI offerings on every flat surface, what actually came out of the woodwork to provide dimensionality and expertise was humanity. 

Security professionals need to learn and know AI deeply for all sorts of reasons. Other technologists, hobbyists, or whatever reason you were in Vegas point to the same. That’s undeniable for now. But what creates form and function from start to finish is the people on any given side of our various work equations. 

I don’t care about enterprise deployments - so far in practice they’re all prone to hallucination and require expert guidance and handholding for everything but attack - but do I want to hear from the SOC analyst working on a project to tune a model and skills to their environment? Absolutely. 

Do I want to talk with the network engineer responsibly building an agentic workflow to measure and monitor baseline activity in their RFC 1918 space? Hell yes. 

And on, and on. 

It’s the people that matter; I want to quiz the users, I want to listen to the builders. Lessons learned, wins achieved, problems they’re beating their head against that someone may have solved one DEF CON village over. 

Hacker Summer Camp delivered in fine style on this front. My first instinct around AI may be curmudgeonly, but like any other technology, hackers are hacking, and that’s still where the magic happens. 

Keep on hacking. Then share.

Articles

Gambit Security Threat Intel - AI Across the Intrusion Lifecycle - One of the things I hear most from my blue teamer groups is the lack of technical data and indicators out there regarding AI-augmented attacks. Gambit uses access to attacker infrastructure here to provide a hefty amount of technical data. PDF download, but to their great credit, no email address needed. 

Worth reiterating: if you’ve got technical details to share, whatever you publish will get about ten times the traction via community sharing. Defenders are hungry for this. Help us defend.

Research Papers and Reports

Tools and Resources

  • Jarocki - Pivotglass - “Pivotglass is a local, AI-augmented workspace for cyber-threat investigation.”

SecuritySnack - Account Farmers and Sellers

Explore how account farmers exploit lax signup friction to inflate metrics and sell verified accounts. Discover key IOCs and mitigation strategies.

Scarcity Scams

Discover how scarcity scams exploit government service bottlenecks to commit wire fraud and identity theft. Learn the tactics behind fake fast-track portals.

Cybersecurity Reading List - Week of 2026-06-01

Commentary followed by links to cybersecurity articles and resources that caught our interest internally.