gab 🇺🇦🇵🇸
@gabagool.ing
fka @gabbyroncone on twitter. mission tech lead for RU & Eastern European APT ops @Google. views expressed here are mine, not my employer’s. she/her.
Reposted by gab 🇺🇦🇵🇸
NEW: A WIRED investigation of 911 calls placed from ICE detention sites across the US show a system inundated by life-threatening crises, delayed treatment, and overcrowding.
By me & @dmehro.bsky.social. Free to read:
By me & @dmehro.bsky.social. Free to read:
'They're Not Breathing': Inside the Chaos of ICE Detention Center 911 Calls
Records of hundreds of emergency calls from ICE detention centers obtained by WIRED—including audio recordings—show a system inundated by life-threatening incidents, delayed treatment, and overcrowdin...
www.wired.com
June 25, 2025 at 9:22 PM
NEW: A WIRED investigation of 911 calls placed from ICE detention sites across the US show a system inundated by life-threatening crises, delayed treatment, and overcrowding.
By me & @dmehro.bsky.social. Free to read:
By me & @dmehro.bsky.social. Free to read:
some other highlights:
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit
We (@gabagool.ing - AKA gabbot) and I updated this with some more recent tomfoolery from this group.
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
July 10, 2025 at 8:52 PM
some other highlights:
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit
Reposted by gab 🇺🇦🇵🇸
We (@gabagool.ing - AKA gabbot) and I updated this with some more recent tomfoolery from this group.
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog
A Russia-sponsored threat actor is impersonating the U.S. Department of State, and using phishing to gain access to email accounts.
cloud.google.com
July 10, 2025 at 6:28 PM
We (@gabagool.ing - AKA gabbot) and I updated this with some more recent tomfoolery from this group.
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
Reposted by gab 🇺🇦🇵🇸
“So ensuring [privacy] in a world where the authority to know us has been ceded to private actors who may or may not cooperate with one or another regime, who may choose to use that data to manipulate or to harm us or to exclude us from access to resources, is existentially important.”
A big humble thank you to @time.com and @billyperrigo.bsky.social for featuring Signal and me in your roundup of 2025’s most influential companies. An honor to serve alongside an incredible group of people backed by a rad movement ❤️
time.com/collections/...
time.com/collections/...
How Signal President Meredith Whittaker Took on Signal-Gate
Whittaker was forced to respond to a political firestorm after a White House blunder turned private chats into a national crisis
time.com
June 30, 2025 at 1:38 PM
“So ensuring [privacy] in a world where the authority to know us has been ceded to private actors who may or may not cooperate with one or another regime, who may choose to use that data to manipulate or to harm us or to exclude us from access to resources, is existentially important.”
Reposted by gab 🇺🇦🇵🇸
Suspected Russian hackers used new tactic against UK researcher reut.rs/44uUqw3
Suspected Russian hackers used new tactic against UK researcher
Suspected Russian hackers have deployed a new tactic to trick even wary targets into compromising their own accounts, a victim of the spy campaign and researchers said on Wednesday.
reut.rs
June 18, 2025 at 5:15 PM
Suspected Russian hackers used new tactic against UK researcher reut.rs/44uUqw3
more from me, @wxs.bsky.social (wxsbot), & @jsrailton.bsky.social about the ASP phishing attempts in this great piece by @timstarks.bsky.social. & kudos to @keirgiles.bsky.social for bringing attention to this, especially since it is targeting individuals vs orgs!
NEW: @citizenlab.ca and Google have details on a "sophisticated" and "novel" attempt by APT 29 to target a British expert who focuses on the Russian military by posing at the US State Department. @timstarks.bsky.social has the scoop cyberscoop.com/russian-hack...
Unusually patient suspected Russian hackers pose as State Department in ‘sophisticated’ attacks on researchers
A report out Wednesday from the University of Toronto’s Citizen Lab calls out a “novel method” Russian hackers used to bypass one of the most well-regarded cyber defense tools, multi-factor authentica...
cyberscoop.com
June 18, 2025 at 5:22 PM
more from me, @wxs.bsky.social (wxsbot), & @jsrailton.bsky.social about the ASP phishing attempts in this great piece by @timstarks.bsky.social. & kudos to @keirgiles.bsky.social for bringing attention to this, especially since it is targeting individuals vs orgs!
Reposted by gab 🇺🇦🇵🇸
NEW: @citizenlab.ca and Google have details on a "sophisticated" and "novel" attempt by APT 29 to target a British expert who focuses on the Russian military by posing at the US State Department. @timstarks.bsky.social has the scoop cyberscoop.com/russian-hack...
Unusually patient suspected Russian hackers pose as State Department in ‘sophisticated’ attacks on researchers
A report out Wednesday from the University of Toronto’s Citizen Lab calls out a “novel method” Russian hackers used to bypass one of the most well-regarded cyber defense tools, multi-factor authentica...
cyberscoop.com
June 18, 2025 at 5:06 PM
NEW: @citizenlab.ca and Google have details on a "sophisticated" and "novel" attempt by APT 29 to target a British expert who focuses on the Russian military by posing at the US State Department. @timstarks.bsky.social has the scoop cyberscoop.com/russian-hack...
Reposted by gab 🇺🇦🇵🇸
So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog
A Russia-sponsored threat actor is impersonating the U.S. Department of State, and using phishing to gain access to email accounts.
cloud.google.com
June 18, 2025 at 5:05 PM
So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
Reposted by gab 🇺🇦🇵🇸
Use Signal. We promise, no AI clutter, and no surveillance ads, whatever the rest of the industry does. <3
June 16, 2025 at 3:30 PM
Use Signal. We promise, no AI clutter, and no surveillance ads, whatever the rest of the industry does. <3
Reposted by gab 🇺🇦🇵🇸
folks I've been tear gassed something like 200 times and maced at least fifty or so times. once i was soaked in mace to my underwear. ignore any neat scientific tricks people give you for beating this stuff
-Water for tear gas
-sudecon wipes for mace
-if no sudecon, wash mace with water
-Water for tear gas
-sudecon wipes for mace
-if no sudecon, wash mace with water
Los Angeles: if you get tear gas or see other people who have been and someone calling themselves a medic tries to use milk to wash their eyes out SLAP THAT MILK JUG OUT THEIR FUCKING HAND. MILK DOES NOT WASH OUT TEAR GAS.
Just use bottled water please.
Just use bottled water please.
Timely reminder that the treatment for chemical weapons like tear gas and pepper spray is:
1) remove from active contamination (get them out of the cloud of teargas, remove outer layers of clothing if possible)
2) flush eyes with ONLY clean water. Wash skin and hair with water and soap.
1) remove from active contamination (get them out of the cloud of teargas, remove outer layers of clothing if possible)
2) flush eyes with ONLY clean water. Wash skin and hair with water and soap.
June 7, 2025 at 9:55 PM
folks I've been tear gassed something like 200 times and maced at least fifty or so times. once i was soaked in mace to my underwear. ignore any neat scientific tricks people give you for beating this stuff
-Water for tear gas
-sudecon wipes for mace
-if no sudecon, wash mace with water
-Water for tear gas
-sudecon wipes for mace
-if no sudecon, wash mace with water
Reposted by gab 🇺🇦🇵🇸
Russian forces have been building military infrastructure near the Finnish border, according to recent satellite imagery, in moves that could reveal their strategy for what happens after the Ukraine war.
Russia Beefs Up Bases Near Finland’s Border
www.nytimes.com
May 19, 2025 at 11:43 AM
Russian forces have been building military infrastructure near the Finnish border, according to recent satellite imagery, in moves that could reveal their strategy for what happens after the Ukraine war.
Reposted by gab 🇺🇦🇵🇸
Like I wrote yesterday, it's never been clearer that US aid for the Israeli military is morally indefensible, and there’s never going to be a better time than right now to stop defending it.
That's true today, too.
That's true today, too.
May 18, 2025 at 6:04 PM
Like I wrote yesterday, it's never been clearer that US aid for the Israeli military is morally indefensible, and there’s never going to be a better time than right now to stop defending it.
That's true today, too.
That's true today, too.
Reposted by gab 🇺🇦🇵🇸
“Project Esther aims to go further, equating actions such as participating in pro-Palestinian campus protests with providing “material support” for terrorism, a broad legal construct that can lead to prison time, deportations, civil penalties” www.nytimes.com/2025/05/18/u...
The Group Behind Project 2025 Has a Plan to Crush the Pro-Palestinian Movement
www.nytimes.com
May 18, 2025 at 3:08 PM
“Project Esther aims to go further, equating actions such as participating in pro-Palestinian campus protests with providing “material support” for terrorism, a broad legal construct that can lead to prison time, deportations, civil penalties” www.nytimes.com/2025/05/18/u...
Reposted by gab 🇺🇦🇵🇸
Lithuania files case against Belarus at the International Court of Justice reut.rs/4mnzyi8
Lithuania files case against Belarus at the International Court of Justice
Lithuania's foreign ministry said on Monday it has filed a case against Belarus at the International Court of Justice, accusing its neighbour of orchestrating a migrant crisis.
reut.rs
May 19, 2025 at 12:25 PM
Lithuania files case against Belarus at the International Court of Justice reut.rs/4mnzyi8
Reposted by gab 🇺🇦🇵🇸
welcome to the age of Weird Terrorism
Apparently the IVF terrorist self-identified as an anti-procreation, pro-death vegan
Online manifesto threatened clinic attack; FBI probes Palm Springs bomb suspect’s motive
The suspect in the bombing of a Palm Springs fertility clinic was tentatively identified by the FBI as Guy Edwards Bartkus, 25.
www.latimes.com
May 18, 2025 at 11:16 PM
welcome to the age of Weird Terrorism
some flowers I’ve seen while walking my dog this week
May 19, 2025 at 12:39 AM
some flowers I’ve seen while walking my dog this week
thanks to my lil roof garden we will not be getting scurvy anytime soon
May 19, 2025 at 12:37 AM
thanks to my lil roof garden we will not be getting scurvy anytime soon
harvested some kale and mustard greens for dinner, cut back some shiso to dry for tea, plucked some chive blossoms to make chive blossom vinegar…chat am I dangerously close to trad-wifery or dangerously close to witchery
May 7, 2025 at 11:51 PM
harvested some kale and mustard greens for dinner, cut back some shiso to dry for tea, plucked some chive blossoms to make chive blossom vinegar…chat am I dangerously close to trad-wifery or dangerously close to witchery
check out some really interesting analysis from @wxs.bsky.social on a very persistent russian apt targeting mostly personal accounts vs corp/gov 👀
I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it.
cloud.google.com/blog/topics/...
cloud.google.com/blog/topics/...
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog
Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.
cloud.google.com
May 7, 2025 at 6:58 PM
check out some really interesting analysis from @wxs.bsky.social on a very persistent russian apt targeting mostly personal accounts vs corp/gov 👀
shout out to this newly flowering geranium in my garden for single-handedly curing my depression
April 28, 2025 at 3:32 PM
shout out to this newly flowering geranium in my garden for single-handedly curing my depression
Reposted by gab 🇺🇦🇵🇸
In an interview with CBS, Russian Foreign Minister Sergey Lavrov says Moscow won't turn over control of the Zaporizhzhia nuclear power plant. Washington apparently hasn't formally suggested it, either. www.cbsnews.com/news/sergey-...
April 27, 2025 at 4:19 PM
In an interview with CBS, Russian Foreign Minister Sergey Lavrov says Moscow won't turn over control of the Zaporizhzhia nuclear power plant. Washington apparently hasn't formally suggested it, either. www.cbsnews.com/news/sergey-...
big s/o to @unauthorized.computer for the new handle find
April 27, 2025 at 3:57 PM
big s/o to @unauthorized.computer for the new handle find
Reposted by gab 🇺🇦🇵🇸
one of the bravest people of this century so far. RIP. hope you find peace somewhere.
R.I.P., Virginia Giuffre
www.theguardian.com/us-news/2025...
www.theguardian.com/us-news/2025...
Virginia Giuffre, a survivor of Jeffrey Epstein’s sexual abuse, has died aged 41
Giuffre’s family issued a statement confirming she took her own life at her farm in Western Australia, where she had lived for several years
www.theguardian.com
April 26, 2025 at 3:31 AM
one of the bravest people of this century so far. RIP. hope you find peace somewhere.
my bf is watching the movie “heat” in the other room & the only noises I have heard emanating from the room for the last 30 min are explosions, sounds of gunfire, and random grunts. seems cool
April 25, 2025 at 1:13 AM
my bf is watching the movie “heat” in the other room & the only noises I have heard emanating from the room for the last 30 min are explosions, sounds of gunfire, and random grunts. seems cool