August 11, 2022
A really excellent look at the air war in Ukraine. The Ukrainians are developing a sort of guerrilla air warfare.
-
-
Ukraine is winning the propaganda war.
Unless they want an unpleasantly hot summer break, we advise our valued russian guests not to visit Ukrainian Crimea.
Because no amount of sunscreen will protect them from the hazardous effects of smoking in unauthorised areas.
🎶Bananarama
-
The Ministry of Defense of Ukraine would like to remind everyone that the presence of occupying troops on the territory of Ukrainian Crimea is not compatible with the high tourist season.
-
This.
We constantly hear "AV is useless" but my experience is the same. Nearly every incident I deal with has an overlooked AV alert early on.
It won't stop ninja APT but it nearly always sees them.
Florian Roth ⚡ @cyb3rops
-
BIRDWATCH program: Ghost in the Orlan: demystifying a military drone platform. Read the full report at subreption.com/press-releases… (code at github.com/subreption/bir…) First publicly documented exploit against a military drone platform! Technical unbiased research > Marketing op eds
-
-
I’ve been playing this “what would you do” type game with @BrianGurien from 1986 and WHAT was wrong with that decade
-
Great details on how Cisco got hacked.
1- Personal Google account of an employee gets compromised - it has password synced enabled.
2- Got all the employee's passwords, including their Cisco VPN credentials.
3- Phishing to accept 2FA
4- They are in
blog.talosintelligence.com/2022/08/recent…
Kudos to #Cisco for publishing details of their security breach by initial access broker (IAB) with ties to #UNC2447, #Lapsus$ and #Yanluowang. There are so many lessons to be drawn from this highlighted part about the initial access:
This was pretty prescient.
Seeing an increasing amount of abuse of MFA prompt "push" notifications. Attackers are simply spamming it until the users approve. Suggest disabling push in favor of pin, or something like @Yubico for simplicity. In the meantime, alert on volume of push attempts per account.
-
Today @USENIXSecurity (at 1.30PM EST), Alejandro Cuevas (CMU) and Fieke Miedema (TUD) will present our work entitled "Measurement by Proxy: On the Accuracy of Online Marketplace Measurements."
Joint work with @SoskaKyle @nc2y @RolfvanWegberg
Short 🧵below
-
-
SlowMist first half of 2022 blockchain security and anti-money laundering analysis report
SlowMist first half of 2022 report - this report is in Chinese, but gives an a fascinating insight: A total of 187 security incidents occurred in the first half of 2022, with a loss of US$1.976 billion - 74.6% of the money laundered in security incidents went to Tornado.
Via Ollie’s Pulsing Purple Substack.
-
-
Debugging is the art of slowly teaching yourself that your problems are a result of your own poor choices
-
Finally the curtain has been pulled for Chameleon Binaries (don't mind the marketing name: Arm64X). This is how most user-mode DLLs are build in Arm64 Windows and that is why they can be loaded both by Arm64 and Arm64EC(x64) processes.
-
My taxi driver apologized for breaking a traffic law. My man, what do you think our business arrangement was.
-
I'm no Sauron fan, but here's why forming a fellowship to raid Mount Doom and destroy the One Ring is going to enrage his base
-
-
Don't miss what's next. Subscribe to the grugq's newsletter: