RSSAmplifier

Blog

Disclosing.Observer

Research and analysis on vulnerability disclosure, cyber threat intelligence, and cybersecurity policy.

disclosing.observerRSS feed ↗10 posts

Latest posts

Opposites on the Same Host: Inside the 4vps.su Leak

A leaked dataset from 4vps[.]su shows a hosting environment where proxy networks, criminal infrastructure, and targeted attack activity coexist without requiring any shared political alignment. The post argues that these apparent contradictions only arise when applying a political model that the system itself does not support.

Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster

An analysis of administrative activity in the Media Land leak, showing how provider-level behaviour is concentrated, embedded in customer infrastructure, and observable on systems linked to ransomware operations.

After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes

A methodological analysis of how DNS sinkholes preserve abuse infrastructure at the moment of takedown, enabling post-hoc reconstruction using passive DNS data.

The Anatomy of a Bulletproof Hoster: A Data-Driven Reconstruction of Media Land

A data-driven reconstruction of the bulletproof hosting provider Media Land, using leaked internal records to analyze customer structure, address space allocation, and links to ransomware activity.

Virtue Before Permission: The Ethical Character of Vulnerability Disclosure

An argument for understanding vulnerability disclosure through virtue ethics, focusing on moral character rather than permission, rules, or outcomes alone.

Turla’s Pelmeni Wrapper: How Weak Crypto Exposed Kazuar’s Payload

A technical analysis of Turla’s Pelmeni wrapper showing how weak cryptographic design enabled payload recovery and created new threat intelligence opportunities.

Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells

An examination of how systems can remain compromised after patching, and how public-interest scanning can ethically uncover persistent backdoors.

Ready, Retain, Fire? The Quiet Fallout of U.S. Offensive Cyber Policy

An analysis of how U.S. zero-day retention and offensive cyber policy can create arms-race dynamics that undermine global cybersecurity and public defense.

What You Hide Will Hurt You: The Streisand Effect of Zero-Day Vulnerabilities

An analysis of how attempts to suppress zero-day vulnerability disclosure can backfire, increasing attention, risk, and harm through a Streisand effect.

The Ransomware Blame Game: Who Bears the Burden of Sanction Enforcement?

An analysis of how ransomware sanctions enforcement relies on fragile attribution signals, and how this shifts legal and financial risk onto victims rather than attackers.