X thread is series of posts by the same author connected with a line!
From any post in the thread, mention us with a keyword "unroll" @threadreaderapp unroll
Follow @ThreadReaderApp to mention us easily!
Practice here first or read more on our help page!

Recent

Mar 6
When in the Course of human events, it becomes necessary for one people to dissolve the political bands which have connected them with another, and to assume among the powers of the earth, the separate and equal station to which the Laws of Nature and of Nature's God entitle them
a decent respect to the opinions of mankind requires that they should declare the causes which impel them to the separation.

We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights,
that among these are Life, Liberty and the pursuit of Happiness.--That to secure these rights, Governments are instituted among Men, deriving their just powers from the consent of the governed,
Read 39 tweets
Mar 6
>"Iran's use of cluster munitions was a war cri--" Image
They deserve everything they're getting, and worse.
share.google/aimode/YtRt9un…Image
Read 3 tweets
Mar 6
BREAKING:

The Justice Department just posted online three FBI interviews that had been missing from the massive trove of Epstein files initially released.

They're related to unsubstantiated sexual assault allegations against Donald Trump.

DOC 1: justice.gov/epstein/files/…
Read 4 tweets
Mar 5
*HUGE* Win for President Trump in the challenge to Chicago's law enforcement surge. This is a stunning rebuke of the district court, explaining that the order is necessary to stop futute courts from following. The district judge is chastened by the appeals judges for overstepping Image
Image
Equally important is another court has joined in to explain the problems with district court judges entering so-called "putative" class actions. The Seventh Circuit recognizes the problems and orders courts to stop, under the Trump v. CASA decision. Image
Image
"Recall that the plaintiffs asked the district court for an order voluntarily dismissing the case with prejudice pursuant to Rules 23(e) and 41(a). That ruling would bind the whole class, which is why the district court held a hearing and had
the parties notify the class...
Read 8 tweets
Mar 5
LEGAL ALERT: The DC Court of Appeals (the highest local court in the district) has ruled that DC's ban on magazines over 10 rounds violates the Second Amendment. dccourts.gov/sites/default/…Image
Image
Image
"...we use that term rather than 'large capacity' magazines to avoid any misleading suggestion that they are outside the norm or larger than your average magazine." Image
"Most people would conclude that the non-voter’s right to read Harry Potter is protected under this first analogy, if only because they think that is an individual right regardless of the prefatory language." Image
Read 19 tweets
Mar 5
Microsoft Defender Experts identified a widespread ClickFix social engineering campaign in February 2026 leveraging Windows Terminal as the primary execution mechanism. Rather than the traditional Win + R → paste → execute technique, this campaign instructs targets to use the Windows + X → I shortcut to launch Windows Terminal (wt.exe) directly, guiding users into a privileged command execution environment that blends into legitimate administrative workflows and appears more trustworthy to users.

This approach bypasses detections specifically tuned to Run dialog abuse while exploiting the legitimacy and familiarity of Windows Terminal. Once the terminal is opened, targets are prompted to paste malicious PowerShell commands delivered through fake CAPTCHA pages, troubleshooting prompts, or verification-style lures designed to appear routine and benign.Screenshot of ClickFix lure using Windows Terminal
What makes this campaign notable are the post-compromise outcomes. The first attack path begins when a user pastes a hex-encoded, XOR-compressed command copied from the ClickFix lure into a Windows Terminal session. This action spawns additional Windows Terminal/PowerShell instances, ultimately launching another powershell.exe process responsible for decoding the embedded hex commands.

The decoded PowerShell script downloads a legitimate but renamed 7-Zip binary and saves it with a randomized file name, along with a ZIP payload. The renamed archive utility extracts and executes a multi-stage attack chain that includes retrieval of additional payloads, persistence through scheduled tasks, defense evasion through Microsoft Defender exclusions, and exfiltration of stolen machine and network data.

The final-stage payload, deployed to C:\ProgramData\app_config\ctjb, is found to be a Lumma Stealer component that performs QueueUserAPC()-based code injection into chrome.exe and msedge.exe processes. The stealer targets high-value browser artifacts, including Web Data and Login Data, harvesting stored credentials and exfiltrating them to attacker-controlled infrastructure.Screenshot of decoded ClickFix command
In the second attack path, when a user pastes a hex-encoded, XOR-compressed command into Windows Terminal, the command downloads a randomly named .bat file to AppData\Local that is invoked through cmd.exe to write a VBScript to %Temp%. The batch script is then executed via cmd.exe with the /launched command-line argument. The same batch script is then executed through MSBuild.exe, resulting in LOLBin abuse.

The script connects to Crypto Blockchain RPC endpoints, indicating etherhiding technique. It also performs QueueUserAPC()-based code injection into chrome.exe and msedge.exe processes to harvest Web Data and Login Data.Screenshot of decoded ClickFix command
Read 4 tweets
Mar 5
1. Hey Canada - whether you’re in Ontario, Quebec, or here in Alberta, and you think staying in 🇨🇦 is best—I get it.

But as an Albertan who’s seen the numbers and felt the effects, here are a few honest reasons why many of us are seriously asking, “what if we went our own way?”Image
2. It’s the money.
Albertans send $30-40B more to Ottawa every year than comes back. I know you might say “that’s how federation works,” but when it’s our taxes propping up other provinces while our hospitals wait + roads crumble… wouldn’t you want that cash? Image
3. Protecting our jobs.
I respect that climate goals matter to you, but Ottawa’s carbon tax, pipeline kills, and net-zero mandates hit our energy industry hard. As our own country, we’d green our way, on our own timeline, with full control. No more begging for approvals. Jobs 1st.Image
Read 11 tweets
Mar 5
Here is the basics on how to pray noted on Matthew 6 vs. 1-7. Image
Image
I am Acadian. We know the damage done by the Roman Catholic Episcopal Company who was anti Pope & Protestant. We know the abuse was systemic and coordinated by the New England Company inspired by Oliver Cromwell laws. The New England Company ran Canadian Residential Schools and churches that abused us.
The New England Company controlled the churches in Canada. They went after Indigenous, Black, Roman Catholics, Quakers, French and anyone who wasn’t a Protestant. We all survived. We all remember. Image
Image
Image
Image
Read 22 tweets
Mar 5
An Iranian ship at a joint Indian naval exercise, where all vessels were required to be unarmed, paraded its sailors along other participants, including the US. The US then withdrew at the last minute, torpedoed the Iranian vessel, and refused to rescue survivors. 87 sailors killed, 60 missing.Image
Torpedoing an unarmed ship, then leaving survivors to die, violates the Geneva Conventions, UNCLOS, the UN Charter, and the Rome Statute. All at once. The Trump regime claims no war exists, which makes this even more illegal. Calling it an 'operation' doesn't make it legal.
Sinking IRIS Dena under an undeclared conflict removes any combat necessity defense. Pure aggression under UN Charter Art. 2(4), GA Res. 3314, with UNCLOS and SOLAS violations for abandoning survivors.
Read 6 tweets
Mar 5
Australia's National Construction Code 2025 will let developers replace up to half of all single-sex toilets in schools, workplaces, shopping centres and sports venues with "all-gender" facilities.

States have until 1 May to stop it.

Here's what's at stake 🧵 Image
The Australian Building Codes Board released the NCC 2025 preview on 2 February.

Under clause F4D4(12), developers can swap out up to half of required male and female facilities for mixed-sex alternatives — voluntarily.

Voluntary for developers. Not for users.
Small buildings can replace both single-sex toilets with one mixed facility.

Larger buildings can convert up to half.

Each "all-gender" cubicle must be accessed from a shared circulation space and signed as "all gender".

That's the full protection on offer.
Read 11 tweets
Mar 5
WHOA: signs an @FBI wiretapping & surveillance network got hacked.

Extremely concerning. These systems have huge potential access to every citizens sensitive data.

Making them an incredibly juicy target for foreign hacking.

By @PaulaReidCNN @snlyngaas @evanperez & @kpolantzImage
2/America has a bad history with surveillance systems getting hacked by #China & other foreign operations.

When you build a #backdoor, or a mechanism for accessing communications outside the usual controls, hackers will come for it.
cnn.com/2026/03/05/pol…
3/ Insecure surveillance systems create secondary violations of your rights.

Even when used lawfully to the law.. if they aren't properly secured, people can still get harmed.

Poland having a reckoning over this lately with Pegasus spyware.👇
Read 3 tweets
Mar 5
1/🚨 BREAKING: Email Describes $100M/Year Proposal to Epstein Attributed to Bill Gates

In May 2013, Boris Nikolic — Bill Gates's science advisor — sent Jeffrey Epstein this message:

"Bill is anxiously awaiting your answer."

The offer on the table: $100 million per year. For 30% of Epstein's time.

This is in the documents. Here's what they show — and what they don't.🧵👇Image
2/ The full Nikolic email reads:

"He feels that 100 million per year for no more than 30 percent of your time is fair for the first three years. There will most likely be bonuses."

Nine figures. Annual. With performance bonuses.

This is not the language of social contact.

📎 EFTA00960138 justice.gov/epstein/files/…Image
3/ Then this line:

"The purchase of the algorithm for the foundation is another matter."

A separate transaction. The acquisition of something called "the algorithm." For the Gates Foundation.

📎 EFTA00960138 justice.gov/epstein/files/…Image
Read 11 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!