/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Pastebin adds two new features, Burn After Read and Password Protected Pastes, that experts say will make it easier to disguise malware operations

The two new features will make it easier to disguise malware operations.  —  Pastebin, the most popular website where users can share small snippets …

ZDNet Catalin Cimpanu

Context & Ripple Effects

The new Burn After Read and Password Protected Pastes features land five months after Pastebin quietly removed its scraping API, a change that already frustrated researchers using the site to hunt leaked breach data. Stacked together, the two moves push a long-open text-sharing service further out of the security community's sightline.

That matters because researchers have spent years documenting how legitimate developer infrastructure becomes malware plumbing — Trend Micro showed threat actors abusing GitHub Codespaces port forwarding for distribution, and Recorded Future later catalogued how criminals and APTs lean on GitHub's services for malware delivery. Pastebin's privacy upgrades add another such platform to that pattern.

First-order effects

  • Threat actors gain two built-in mechanisms — ephemeral pastes and paste-level passwords — that let them stage payloads or instructions without leaving an inspectable artifact.
  • Security researchers, already cut off by the scraping API's removal, lose even manual visibility into what is being shared on the platform.

Second-order effects

  • Pastebin inherits the same abuse-monitoring burden Recorded Future's GitHub reporting shows falls on platform operators: detect malicious use without the telemetry its own features now obscure.
  • Research teams tracking malware staging will shift effort toward platforms they can still observe, concentrating scrutiny on GitHub-style infrastructure where the abuse playbook is already mapped.

Third-order effects

  • If ephemeral-and-encrypted sharing becomes table stakes for paste and code-hosting sites, the industry drifts toward malware distribution running on consumer-grade platforms whose operators cannot see their own content — pushing detection back onto endpoints and network edges.
  • The scraping-API reversal plus these privacy features mark a broader redefinition of what counts as a 'public' paste site, forcing platforms to choose between openness researchers rely on and user-facing secrecy abusers exploit.

The trend: Text- and code-sharing platforms are steadily closing off researcher access while their infrastructure doubles as malware delivery channels, echoing the abuse patterns documented on GitHub.

Discussion

  • @pastebin @pastebin on x
    We're excited to announce 2 great new features for #Pastebin, we think you'll enjoy using them! In the interest of #security, the first is: Burn After Read, and the second is: Password Protected Pastes. Head on over to https://pastebin.com/ to check them out 🕵️ https://twitter.co…
  • @jcybersec_ Jake on x
    I can already see how this is going to be abused by threat actors. Going to make tracking these threats 100x harder. Who is pastebin working for? Security or threat actors? https://twitter.com/...
  • @core561 @core561 on x
    Making it more harder for security researcher to track threat actors while providing threat actors with extra layer of security https://twitter.com/...