neurovagrant Profile Banner
Ian Campbell Profile
Ian Campbell

@neurovagrant

Followers
2K
Following
16K
Media
2K
Statuses
53K

Security ops engineer and researcher for @DomainTools, writer, voracious reader. he/him. Opinions here mine only. Autistic/depressed/anxious/hungry.

Massachusetts
Joined January 2009
Don't wanna be here? Send us removal request.
@neurovagrant
Ian Campbell
14 days
RT @GelosSnake: The pattern is simple:.- Dev gives vague instruction.- AI has production access.- Literal interpretation.- Catastrophic dam….
0
1
0
@neurovagrant
Ian Campbell
14 days
RT @GelosSnake: Introducing a new attack vector: AI-Induced Destruction. After a shared volume of incident responses, we can confirm: AI co….
0
19
0
@neurovagrant
Ian Campbell
3 months
RT @DomainTools: Looking for smart reads & listens in cyber? .@Neurovagrant shares what’s buzzing on our team’s radar this week:. 🎧 @Malteg….
Tweet card summary image
dti.domaintools.com
Recommended cybersecurity podcasts, books, blog posts, reports, and essential tools from DomainTools Investigations
0
3
0
@neurovagrant
Ian Campbell
5 months
RT @SecuritySnacks: DTI reveals a phishing campaign targeting defense and aerospace firms linked to the Ukraine conflict. The infrastructur….
0
4
0
@neurovagrant
Ian Campbell
5 months
RT @SecuritySnacks: .@neurovagrant shares his top cybersecurity picks: podcasts, blogs, research papers, and more! . Starting with "To Catc….
0
4
0
@neurovagrant
Ian Campbell
5 months
I'm super proud of my employer @DomainTools and our DT Investigations team under @DanOnSecurity today. Consider this historical analysis piece on Russian disinfo actors the first of many disinformation-related pieces to come!.
@SecuritySnacks
SecuritySnacks
5 months
New research from DTI: Russian actors use low-cost, privacy-protected domains for #disinformation. Key points:.🔸Fake news portals.🔸Typosquatting.🔸Bulletproof hosting.🔸Preferred registrars.🔸Emerging trends.Stay informed & read more here:
Tweet media one
0
5
8
@neurovagrant
Ian Campbell
7 months
also, hello friends, i hope 2025 is treating you well.
0
0
4
@neurovagrant
Ian Campbell
7 months
stay frosty out there, friends. homebrew typosquat serving malware.
@neurovagrant
Ian Campbell
7 months
@JeroenGui @ryanchenkie assuming brewe[.]sh - . Created: 2024-12-22.Registrar: Dynadot.Host: Hostinger.NS: dyna-ns[.]net.IP: 46[.]202.159[.]95. I've got no other domain hits for that IP; DNS has it hitting hostinger's cloud. going back to 2024-12-01 I see brewi[.]sh and brewx[.]sh as well.
0
0
2
@neurovagrant
Ian Campbell
7 months
RT @ryanchenkie: ⚠️ Developers, please be careful when installing Homebrew. Google is serving sponsored links to a Homebrew site clone tha….
0
3K
0
@neurovagrant
Ian Campbell
1 year
(okay, commentary other than "no shit, sherlock").
0
0
1
@neurovagrant
Ian Campbell
1 year
RT @DomainTools: Proud to see our own @neurovagrant quoted in @helpnetsecurity regarding #cybersecurity career tips and guidance 👏.
0
2
0
@neurovagrant
Ian Campbell
1 year
Flash back to the Rio Olympics of 2016 - of course now I'm wondering if JD Vance was involved.
@pkelso
Paul Kelso
9 years
Hearing an Olympic kayaker may have capsized after hitting a submerged sofa. Story of day & possibly the week if true. #kayaksofa #Rio2016.
0
0
1
@neurovagrant
Ian Campbell
1 year
I hear Delta was offered compensation for their outage prior to filing suit but were unimpressed with the partial travel voucher and a bag of nuts.
0
1
2
@neurovagrant
Ian Campbell
1 year
VP Kamala Harris is absolutely up to the task of being elected. The dynamics will shift surprisingly fast. Be ready to help.
1
0
2
@neurovagrant
Ian Campbell
1 year
Just a reminder that I'm mostly at neurovagrant at masto dot deoan dot org these days. But some of y'all, I just can't quit.
0
1
3
@neurovagrant
Ian Campbell
1 year
Just a note for folks, we've added a second set of CSVs with human-readable timestamps instead of epochal in case folks are hunting manually rather than importing into a platform. They're located in a subfolder in the same place on Github.
0
1
1
@neurovagrant
Ian Campbell
1 year
Hey folks, we're seeing some real badness aimed at Web3 domains right now, along with many others. We've released passive DNS records from 2024-07-01 onward for sites highlighted by the community (not all necessarily compromised) to help investigators and blue teamers.
@DomainTools
DomainTools
1 year
.@cryptonews relayed widespread social media reports of Web3-related domain takeovers of Squarespace-held domains. Using @0xngmi’s list as a guidepost, passive DNS records can be found on CTI Grapevine here:
Tweet media one
Tweet media two
1
1
1
@neurovagrant
Ian Campbell
1 year
RT @DomainTools: .@cryptonews relayed widespread social media reports of Web3-related domain takeovers of Squarespace-held domains. Using @….
0
3
0
@neurovagrant
Ian Campbell
1 year
Tweet media one
0
26
0