Well this is concerning.
I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.
Thanks to IFTAS SW-ISAC for noting and reporting the bots.
abeorch
in reply to Chief TWiT :twit: • •like this
Elyse M Grasso and seanpm2001 🇺🇦️🇬🇱 like this.
Viss
in reply to Chief TWiT :twit: • • •AntiComposite
in reply to Viss • • •RE: mastodon.iftas.org/@iftas/1164…
@Viss @leo the current tactic seems to be getting a legit-looking account through review, then using invites (which bypass review) to create the spam accounts.
IFTAS
2026-04-18 17:48:27