October 7, 2023
October 7, 2023
The #PredatorFiles investigation reveals the #Predator spyware attack interface for the first time, with invasive capabilities to steal photos, track the victims location and record their microphone pic.twitter.com/7mt8fx4cVD
โ Donncha ร Cearbhaill (@DonnchaC) October 6, 2023
Good morning. Do u have adhd?? food for thought pic.twitter.com/RiyhKaCAIP
โ Vinny Thomas (@vinn_ayy) October 6, 2023
This new Twitter link change is a killing field for malware operators.
โ John McFarland ๐ป ู (@BruSec_) October 5, 2023
Hard to envision a trained, well-funded foreign intelligence service not taking advantage of this personality trait. https://t.co/EOEip7huFX pic.twitter.com/Egrcg7Q7J3
โ Pete Strzok (@petestrzok) October 6, 2023
Employee: Iโm good at my job and deserve a raise
โ Adam Karpiak (@Adam_Karpiak) October 6, 2023
Company: pic.twitter.com/L98TsJXUN1
And weโre live! https://t.co/c6ztQwvR5f https://t.co/wPmPif9Fo5
โ cts๐ธ (@gf_256) October 7, 2023
23andMe user data was seemingly stolen in a credential stuffing campaign that targeted Ashkenazi Jews. Also maybe data from Mark Zuckerberg, Elon Musk and Sergey Brin is in the leak? 23andMe seems to be confirming the incident yet hasn't validated the data https://t.co/9Rq4DcqHnP
โ Lily Hay Newman (@lilyhnewman) October 6, 2023
Really cool project @meansec has started kicking off tracking the legality of #ransomware payments:https://t.co/f6XjAzDWZn
โ Silas // p1nk (@silascutler) October 7, 2023
cc: @IST_org #RansomwareTaskForce pic.twitter.com/Fq1jGYfNZs
One saving grace for US counterintelligence is that most of our traitors arenโt exactly geniuses. pic.twitter.com/UFLuZummgb
โ ๐ฐ๐๐๐ก ๐ฑ๐๐๐๐๐ ๐๐๐ (@alexrblackwell) October 6, 2023
"Individuals entrusted with national defense information have a continuing duty to protect that information beyond their government service and certainly beyond our borders".
โ Dr. Dan Lomas (@Sandbagger_01) October 6, 2023
https://t.co/Mu5q8fnPfL
Intel history nerds when they see the wooden seal https://t.co/dDm75fXk8H pic.twitter.com/L4XQnLclQc
โ Glitchy Michael ๐ป (@GlitchyMichael) October 5, 2023
It's not a bug, it's a feature!
โ Jonathan Jogenfors (@Jogenfors) October 6, 2023
Interesting reading on how to break bare metal firmware encryption (FortiGate firewalls) for security research.
โ 0xor0ne (@0xor0ne) October 6, 2023
Credits Jon Williams (@bishopfox)https://t.co/IezIyMddWF#Fortinet #embedded #infosec pic.twitter.com/0ajPeVzDY1
Did your your experience "running sources as a spy handler" teach you to handle them over Gmail? I'll bet it didn't. pic.twitter.com/mbuqszcC2w
โ Adam Rawnsley (@arawnsley) October 6, 2023
People, please. I cannot stress this enough: do *not* take espionage advice from Reddit. pic.twitter.com/YMNVwDaC5w
โ Adam Rawnsley (@arawnsley) October 6, 2023
Thatโs just what the espionage elite want you to think, this is gatekeeping
โ Dave (also @cursed.monster on bsky) (@6502_ftw) October 6, 2023
โ phishing 2fa 25 years ago โ
โ pad (@123456) October 6, 2023
two-factor authentication is revered as the end all be all of account security. it shouldn't be. it's been easy to phish 2fa since the 90s.
aol employees used physical "rsa securid" devices displaying 6 digits that changed once per minute.
iโฆ pic.twitter.com/gBxrUezeYd
Weekly analysis is out (attribution by others):
โ Ollie Whitehouse (@ollieatnowhere) October 7, 2023
-๐ฐ๐ต ops in ๐ช๐ธ on โ๏ธ coders
-๐ฐ๐ต ops in ๐ฐ๐ท on ๐ข
-๐จ๐ณ ops on ASEAN members
-๐จ๐ณ ops in ๐ฌ๐พ on Gov
-๐ฎ๐ท ops in ๐ธ๐ฆ
then
- Malvertising via hacked ad accts
-Smart contracts hosting payloads
Plus off/def tradecraft.https://t.co/8ZElyuvtiZ
Checkout @sublime_sec 's "quishing" ๐ฌ aka QR Code Phishing analysis and protection tech. Excellent overview:https://t.co/jlyBfNLTcY
โ Jason Haddix (@Jhaddix) October 6, 2023
Now do one's on LNK, CHM, MSI, MSIX, APPX, HTML Smugg, *ZIP, ISO, CPL, XLL, js, WSF's ... ! ๐
Looks like a good time for a thread on token theft :)
โ Nathan McNulty (@NathanMcNulty) October 6, 2023
Not all MFA is of the same quality, and anything using OTP (SMS, hardware/software tokens) or Push (MS Authenticator, Duo, etc.) is susceptible to AITM attacks
That doesn't mean it's useless, but it's becoming less useful https://t.co/YKIcsYVY7y
I hate that when something is difficult, people say "it's no picnic," as if picnics are just some walk in the park.
โ Dead Pan Nick (@Contwixt) June 2, 2018
The Herald-Journal, Logan, Utah, February 29, 1936 pic.twitter.com/AouYQddqBQ
โ Yesterday's Print (@yesterdaysprint) October 6, 2023
A Brief History of America is in Decline Like The Roman Empire
โ Paul Fairie (@paulisci) October 2, 2023
๐งต
Trying something that will probably not work:
"I usually donโt do this on the first date," I say, pushing two lobsters together and making sex noises
Add a comment: