
Tim Kromphardt
@infosectimmy
Followers
318
Following
7K
Media
228
Statuses
1K
Senior Threat Researcher @ Proofpoint and Co-Host of the Discarded Podcast #bec #emailfraud #infosec #TOAD My tweets are my own.
A series of tubes
Joined June 2021
This blog was a lot of fun to work on. 😁
Threat researchers at @Proofpoint released new details on a widespread Request for Quote (RFQ) scam that involves leveraging common Net financing options to steal a variety of high value electronics and goods. Blog: https://t.co/VWYsj41Rva
#shipment #RFQ #finance #scam 🧵⤵️
1
1
7
A *spooky* Only Malware in the Building episode is here, featuring @threatinsight's Selena Larson. 👻 Listen for “ghost stories” from the cyber underworld and explore the impacts these legendary incidents and operations have left on the digital landscape.
thecyberwire.com
Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofp...
0
3
9
Researchers at @Proofpoint have uncovered a recent brute force campaign, tracked as UNK_CustomCloak, targeting the first-party app, Windows Live Custom Domains. Activity was observed from September 20th-30th, affecting nearly half a million users in over 4,000 tenants.
2
10
16
October is the month of pumpkin spice & #cybersecurityawareness. 🎃 On a new Discarded #podcast, the @threatinsight team recognizes the critical role humans play in the attack chain. Deep dive into why #socialengineering is at the 💙 of so many attacks. https://t.co/RQOcZeIt0Z
0
5
12
The Discord breach is another example of the risk of collecting IDs for age verification. If you’re going to collect sensitive data, you have to protect it. We’re not seeing it protected well so far.
NEW: breach of Discord age verification data. For some users this means their passports & drivers licenses. Discord has only run age verification for 6 months. Age verification is a badly implemented data grab wrapped in a moral panic. Mark my words, as age verification
45
419
2K
#OperationEndgame was a collaborative effort between global law enforcement and private sector partners, including Proofpoint @threatinsight. At #ProofpointProtect 2025, attendees got an exclusive play-by-play of exactly how the operation disrupted global ransomware networks.
0
4
8
Dawg, this Discord Zendesk compromise is crazy. The Threat Actor has so much fucking leverage Depending on what's in the data they could extort celebrities, crypto influencers, politicians, scammers and/or other Threat Actors, government officials The possibilities are endless
27
122
1K
This speech should terrify anyone who cares about our country. Declaring war on our nation’s cities and using our troops as political pawns is what dictators do. This man cares about nothing but his own ego and power.
Trump: You know, our inner cities, which we'll be talking about because it's a big part of war now, a big part of war.
8K
20K
92K
The @Proofpoint threat research team published new research identifying a new cyber-espionage campaign by #TA415 (#APT41), a China-aligned threat actor, exploiting growing uncertainty in U.S.-China economic relations. ⤵️
proofpoint.com
What happened Throughout July and August 2025, TA415 conducted spearphishing campaigns targeting United States government, think tank, and academic organizations utilizing U.S.-China
1
14
29
The Attorney Generals in DC and Iowa have filed lawsuits against Bitcoin ATM providers, Athena, CoinFlip, and Bitcoin Depot for knowingly facilitating fraud as they allow hundreds of elderly folks to stuff money into their machines to be sent to scammers around the world while
0
1
7
There really should be a standard for rejecting non-essential cookies instead of going through this sort of time wasting. What makes your 'Legitimate interest' mine? No 'Reject all' option of course. Cookie control RFC anyone?
95
109
1K
Hot sauce and hot takes: For the first time, the Only Malware in the Building team is together in-studio—and they’re turning up the heat. 🔥 Think you’ve seen them tackle malware mysteries before? Wait until you see them sweat. Stream now on YouTube!
0
2
3
Something #spicy is coming to the next Only Malware in the Building #podcast—dropping September 2nd. 🌶️ Bookmark the show page and reserve your seat 🪑 at the table alongside Selena Larson, Dave Bittner, and Keith Mularski. 🔥 You won't want to miss it! https://t.co/wDKwnjN5lT
0
1
2
You asked, we answered. AI tools are significantly lowering the barrier to entry for cybercriminals. We have observed threat actor campaigns leveraging the AI-generated website builder Lovable to create and host cred phishing, malware, and fraud websites. https://t.co/J1VjyEmGXO
1
7
15
THATS 👏WHY 👏WE👏SUPPORT👏THE👏EFF👏 FUCK👏THE👏GOVERNMENT👏SPYING👏 FUCK👏THE👏GOVERNMENT👏 SUPPORT👏INTERNET👏ANONYMITY👏
Age verification is here, and now UK Redditors can’t access their favorite LGBTQ+, political, or public health communities without destroying their anonymity. Help us fight to avoid this future. https://t.co/aXbQ6fJrzQ
28
867
4K
Threat researchers from @Proofpoint have found a way to sidestep FIDO-based #authentication, a discovery that could expose targets to credential phishing attacks, account takeover (#ATO), and adversary-in-the-middle (AiTM) threats. #FIDO #MFA
proofpoint.com
Key takeaways FIDO-based passkeys remain a highly recommended authentication method to protect against prevalent credential phishing and account takeover (ATO) threats.
3
23
48
Platforms where this kind of thing happens need to start stepping up.
0
0
0
New video is now live! https://t.co/HYcIkPQdTs The Job Scam....
11
43
200
New video on Sunday at 7pm BST (Patrons can already see it though!). Ever wonder about those "Review for $5" messages on WhatsApp or Telegram? I dig deep into a very fast-growing scam.
17
22
224
The Governor of Texas is threatening to remove democratically elected officials from office because they have refused to rig an election for Donald Trump. United States of America, 2025.
9K
16K
90K