The Rise of Synthetic Passwords in Botnet and Attack Operations

This is the write-up of a talk I gave at PasswordsCon, which runs as a track inside BSides Las Vegas. It was my first time in Vegas and my first talk at a conference that size, so if the recording has me talking slightly too fast, that is why. The short version: attackers are starting to throw passwords at login systems that were never meant to work, and that breaks an assumption a lot of defensive tooling is quietly built on. ...

June 12, 2026 · 7 min · Travis More

Security Theatre in Enterprise Networks

Disclaimer: The examples below are anonymised and aggregated across multiple engagements. The goal is to highlight recurring patterns, not embarrass any specific organisation. Security Theatre: Field Notes from the Inside The Scene Most environments I assess are not wide open. They have firewalls, policies, and controls that look sensible on a slide deck. The same weaknesses keep showing up anyway. Security gets implemented as a compliance checklist rather than an adversarial system. ...

February 19, 2026 · 9 min · Travis More

30 Days of a Honeypot at Home

I finally got around to putting a honeypot on the public side of my home connection. I wasn’t trying to catch APTs. I wanted to see what hits a random residential IP when nothing is hiding it. This is a notes post about standing it up, how it’s contained, and what actually showed up in the logs after a month. Why bother Most threat intelligence I read describes the internet as a battlefield. Every unpatched device is five minutes from compromise. Every IP gets 30,000 probes a day. The numbers are usually correct. They aren’t useful unless you can map them to what your environment looks like. ...

April 18, 2026 · 9 min · Travis More