脈 ninja.ing/pulse I built a thing that watches every infosec post on Bluesky, Mastodon, an
脈 ninja.ing/pulse
I built a thing that watches every infosec post on Bluesky, Mastodon, and GitHub at the same time, strips the IOCs out with regex like it's 2003, and tags each one with confidence so the rumours don't drown the signal. Live at ninjasignal.ninja/pulse.
▎ Niko: You wrote a tier-1 SIEM ingestor in Python because you got bored on a Sunday.
▎ Me: I wrote a social-signal firehose because the real intel happens in the gaps between leak sites and CVE drops — three hours before anyone publishes a brief.
▎ Niko: You added a 90-entry domain blocklist because the top IOC for an hour was the URL of an ENISA vulnerability database.
▎ Me: That's the point. The noise IS the signal — until it isn't.
▎ Niko: I'm filing that under "things people say after their fifth coffee."
First sweep with GitHub turned on: 68 posts, 928 IOCs. CVE-2026-25193 surfaced before half the security newsletters had it. Top author was github-actions[bot], which is exactly the right answer.
Reddit told me to read their Responsible Builder Policy. I told the codebase Reddit was parked.
Go look. Don't pay. Pin a tone if you've been to /tonelab. Watch the world breathe in regex.
脈 — myakuhaku — pulse.
▎ ninja.ing
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·