<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Well this is concerning.]]></title><description><![CDATA[<p>Well this is concerning.</p><p>I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.</p><p>Thanks to IFTAS SW-ISAC for noting and reporting the bots.</p>]]></description><link>https://forum.fedi.dk/topic/735ee172-f71a-4bb5-81b2-25e80d1a1e38/well-this-is-concerning.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 14:18:06 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/735ee172-f71a-4bb5-81b2-25e80d1a1e38.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 02 May 2026 17:22:00 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 06:23:41 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> thanks for keeping vigilant, Leo!</p>]]></description><link>https://forum.fedi.dk/post/https://cosocial.ca/users/evan/statuses/116509207483483049</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://cosocial.ca/users/evan/statuses/116509207483483049</guid><dc:creator><![CDATA[evan@cosocial.ca]]></dc:creator><pubDate>Sun, 03 May 2026 06:23:41 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 06:17:57 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> aren't traditional capchas kind of a solved problem in machine learning?</p>]]></description><link>https://forum.fedi.dk/post/https://layer8.space/users/nihilistic_capybara/statuses/116509184957075492</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://layer8.space/users/nihilistic_capybara/statuses/116509184957075492</guid><dc:creator><![CDATA[nihilistic_capybara@layer8.space]]></dc:creator><pubDate>Sun, 03 May 2026 06:17:57 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 05:44:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/curiously%40mastodon.au">@<span>curiously</span></a></span> <span><a href="https://twit.social/@leo">@<span>leo</span></a></span> Yes, thanks a million. It is really appreciated.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.nz/ap/users/115828656027457735/statuses/116509052757903077</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.nz/ap/users/115828656027457735/statuses/116509052757903077</guid><dc:creator><![CDATA[iveyline@mastodon.nz]]></dc:creator><pubDate>Sun, 03 May 2026 05:44:19 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 03:34:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/ariarhythmic%40ohai.social" rel="nofollow noreferrer noopener">@<span>ariarhythmic</span></a></span> <span><a href="https://twit.social/@leo" rel="nofollow noreferrer noopener">@<span>leo</span></a></span> This is <a href="https://about.iftas.org/2025/10/05/coordinated-pro-russian-propaganda-network-targeting-activitypub-and-atproto-services/" rel="nofollow noreferrer noopener">how it's being done</a> by the 'Portal Kombat' crew. They use existing accounts and use server invites to bypass registration checks.</p>]]></description><link>https://forum.fedi.dk/post/https://olifant.social/users/oli/statuses/01KQNYDMR29QX21E67SKET4KHF</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://olifant.social/users/oli/statuses/01KQNYDMR29QX21E67SKET4KHF</guid><dc:creator><![CDATA[oli@olifant.social]]></dc:creator><pubDate>Sun, 03 May 2026 03:34:26 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 03:33:38 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> ims i had to give a reason to join</p>]]></description><link>https://forum.fedi.dk/post/https://twit.social/users/BeeT1123/statuses/116508538838903558</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://twit.social/users/BeeT1123/statuses/116508538838903558</guid><dc:creator><![CDATA[beet1123@twit.social]]></dc:creator><pubDate>Sun, 03 May 2026 03:33:38 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 02:10:59 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> thanks for putting in the effort to keep this instance clean!</p>]]></description><link>https://forum.fedi.dk/post/https://twit.social/users/roryh/statuses/116508213868989412</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://twit.social/users/roryh/statuses/116508213868989412</guid><dc:creator><![CDATA[roryh@twit.social]]></dc:creator><pubDate>Sun, 03 May 2026 02:10:59 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 00:32:17 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> thanks for keeping this server safe. <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title="👍" alt="👍" /></p>]]></description><link>https://forum.fedi.dk/post/https://twit.social/users/brothercasas/statuses/116507825737089629</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://twit.social/users/brothercasas/statuses/116507825737089629</guid><dc:creator><![CDATA[brothercasas@twit.social]]></dc:creator><pubDate>Sun, 03 May 2026 00:32:17 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sun, 03 May 2026 00:01:46 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> yeah, there was a wave of bots that joined my instance. Enabling Captcha didn’t slow them down at all. The only thing that helped was requiring new accounts to write a reason to join. Haven’t seen a bot since.</p>]]></description><link>https://forum.fedi.dk/post/https://retro-gaiden.com/users/Oregon_Pacifist/statuses/116507705795494673</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://retro-gaiden.com/users/Oregon_Pacifist/statuses/116507705795494673</guid><dc:creator><![CDATA[oregon_pacifist@retro-gaiden.com]]></dc:creator><pubDate>Sun, 03 May 2026 00:01:46 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 22:33:35 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> hey thanks for your work in finding and removing these bots. Much appreciated the horde of admins across the Fediverse do an awesome job keeping this a safe place that's people first. Thank you.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.au/users/curiously/statuses/116507359032432691</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.au/users/curiously/statuses/116507359032432691</guid><dc:creator><![CDATA[curiously@mastodon.au]]></dc:creator><pubDate>Sat, 02 May 2026 22:33:35 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 22:00:06 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> looking at the account in modtools should say the inviter name, just ban them too</p>]]></description><link>https://forum.fedi.dk/post/https://jorts.horse/users/scattapilla/statuses/116507227382975541</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://jorts.horse/users/scattapilla/statuses/116507227382975541</guid><dc:creator><![CDATA[scattapilla@jorts.horse]]></dc:creator><pubDate>Sat, 02 May 2026 22:00:06 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 21:23:26 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span><span> Can I confirm - this is on Mastodon's server software?</span></p>]]></description><link>https://forum.fedi.dk/post/https://mewblog.thepolarbear.co.uk/notes/alsexmosp15eleb7</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mewblog.thepolarbear.co.uk/notes/alsexmosp15eleb7</guid><dc:creator><![CDATA[hamishtpb@mewblog.thepolarbear.co.uk]]></dc:creator><pubDate>Sat, 02 May 2026 21:23:26 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 20:25:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/leo%40twit.social">@<span>leo</span></a></span> concerning is an understatement here, Leo.</p>]]></description><link>https://forum.fedi.dk/post/https://tlv.cool/users/god/statuses/116506856555314960</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://tlv.cool/users/god/statuses/116506856555314960</guid><dc:creator><![CDATA[god@tlv.cool]]></dc:creator><pubDate>Sat, 02 May 2026 20:25:48 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 19:03:47 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> </p><p>How did they circumvent your manual process?</p>]]></description><link>https://forum.fedi.dk/post/https://babka.social/users/serge/statuses/116506534077597511</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://babka.social/users/serge/statuses/116506534077597511</guid><dc:creator><![CDATA[serge@babka.social]]></dc:creator><pubDate>Sat, 02 May 2026 19:03:47 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 18:14:38 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> Are existing members allowed to create invites that bypass review?</p>]]></description><link>https://forum.fedi.dk/post/https://ohai.social/ap/users/115628614496668967/statuses/116506340817739389</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://ohai.social/ap/users/115628614496668967/statuses/116506340817739389</guid><dc:creator><![CDATA[ariarhythmic@ohai.social]]></dc:creator><pubDate>Sat, 02 May 2026 18:14:38 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 17:30:24 GMT]]></title><description><![CDATA[<p><span><a href="https://wikis.world/@anticomposite">@<span>anticomposite</span></a></span> <span><a href="https://twit.social/@leo">@<span>leo</span></a></span>  oh interesting - you think there are approved accounts already in there that are farming invites out to the bots?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/Viss/statuses/116506166867475390</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/Viss/statuses/116506166867475390</guid><dc:creator><![CDATA[viss@mastodon.social]]></dc:creator><pubDate>Sat, 02 May 2026 17:30:24 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 17:29:12 GMT]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://mastodon.iftas.org/@iftas/116426965511875330" rel="nofollow noopener"><span>https://</span><span>mastodon.iftas.org/@iftas/1164</span><span>26965511875330</span></a></p><p><span><a href="/user/viss%40mastodon.social">@<span>Viss</span></a></span> <span><a href="https://twit.social/@leo">@<span>leo</span></a></span> the current tactic seems to be getting a legit-looking account through review, then using invites (which bypass review) to create the spam accounts.</p>]]></description><link>https://forum.fedi.dk/post/https://wikis.world/users/anticomposite/statuses/116506162144551985</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://wikis.world/users/anticomposite/statuses/116506162144551985</guid><dc:creator><![CDATA[anticomposite@wikis.world]]></dc:creator><pubDate>Sat, 02 May 2026 17:29:12 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 17:29:06 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> is that perhaps the period where your subscription had expired?</p>]]></description><link>https://forum.fedi.dk/post/https://twit.social/users/andrewh/statuses/116506161750200552</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://twit.social/users/andrewh/statuses/116506161750200552</guid><dc:creator><![CDATA[andrewh@twit.social]]></dc:creator><pubDate>Sat, 02 May 2026 17:29:06 GMT</pubDate></item><item><title><![CDATA[Reply to Well this is concerning. on Sat, 02 May 2026 17:24:19 GMT]]></title><description><![CDATA[<p><span><a href="https://twit.social/@leo">@<span>leo</span></a></span> this is a pretty big deal. if youre running the stock mastodon code and not something like glitchsoc, this is worth submitting an issue to github about</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/Viss/statuses/116506142946399517</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/Viss/statuses/116506142946399517</guid><dc:creator><![CDATA[viss@mastodon.social]]></dc:creator><pubDate>Sat, 02 May 2026 17:24:19 GMT</pubDate></item></channel></rss>