RE: APEX / ALGS / EAC Remote Code Execution
👋 I wrote undectable cheats for online games for challenge and sport for many, many years. I know enough to know that no one has the answers, but I'd like to call out some things you may have glazed over, and put them in context. 🧵
A lot of organizations are getting hammered by QR-code based phishing. Many SOC teams seem to be struggling to find a good answer.
We've been seeing and stopping this since (before) July this year - using machine learning.
Real-life example & tech:
darktrace.com/blog/phishing-…
#EPSS & #KEV are great for #vulnerability management. What's usually still lacking is local organizational context though 🧐. Combining ML, graph theory & attack path modelling for vulnerability prioritization with local context 🙏: darktrace.com/blog/leveragin…
The famed Stanford Smallville is officially open-source!
25 AI agents inhabit a digital Westworld, unaware that they are living in a simulation. They go to work, gossip, organize socials, make new friends, and even fall in love. Each has unique personality and backstory.…
Do you often use ChatGPT for cybersecurity? If so, what do you use it for? Be it for writing queries, scripts, etc. I've spent just a couple of minutes so far and couldn't find a use case for myself and probably I'm missing something or just dumb.
My threat research colleagues have translated last week's internal leaks of the #yanluowang#ransomware gang and analysed them. Interesting to see what impact these leaks have on the broader ransomware landscape. darktrace.com/blog/inside-th…
Details of the OpenSSL vuln have now been released. Downgraded from Crit > High. No known exploit POC & no ITW exploitation.
A big factor is that it would need pre-existing compromise of the CA path to even reach the vuln code.
If that's happened, there are bigger problems.
This will be a thread discussing a real world breach involving a drone delivered exploit system that occurred this summer
Some details I am not able to discuss, however for the blue teams & red teams out there I hope this provides a good measure of capability.
🧵🚁 🎮🖥️🦠
Cyberattacks involving data manipulation could pose an even more severe threat than data theft or ransomware (at least in some cases). But they're not top of mind for most businesses protocol.com/enterprise/dat…
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
41K Followers 9K FollowingInformation security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
5K Followers 1K FollowingHead of Bundeswehr Cyber Innovation Hub @CIHBw / Leading innovation in defense / Capital Top 40 Under 40 / 🇩🇪🇹🇷🇪🇺 / private opinion only
15K Followers 6K FollowingADEO’nun ve BlueCortex AI'ın Kurucu Ortağı, Adli Bilişim Uzmanı, Beyaz Şapkalı Hacker, TOBB Üniversitesinde Öğretim Görevlisi, Adli Bilişim Derneği
353 Followers 4K Following🌐 I made this account to warn others and share my experience with a potential Trojan that auto-downloaded from the TikTok Seller website. 🆘
640 Followers 4K FollowingIT security vendor with HQ in UAE and offices in Lithuania and Singapore. We bring evolution to the #PKI, #IAM, #PrivillegedAccessManagement, #AccessManagement
15K Followers 5K FollowingSenior AI reporter @Verge. 5+ years covering the industry's power dynamics, societal implications & the AI arms race. Previously @CNBC.
Signal: haydenfield.11
6K Followers 3K Followingxss0r
Deploying an alert box in a web app is like having a tiny pop-up comedian shout 'Surprise!' whenever you least expect it!
#xss0r #ibrahimXSS #Blindxss0r
4 Followers 117 FollowingBramfitt Technology Labs leads in technical cyber security consulting focused on embedding a culture of security with its clients.
160 Followers 5K FollowingDevr is a new Internet protocol for the governance of decentralized privacy networks (DPN), powering a new era for data sharing economies
752 Followers 3K FollowingAdvocate for AI Ethics, training transparency and accountability. Empowering companies, organizations and individuals with a strong dedication to #AIEthics
262 Followers 198 FollowingExploring the frontiers of digital innovation and driving the future of #DigitalTransformation. Based @cardiffuni. Sign up to our newsletter - https://t.co/axTNW4Qvek
539K Followers 17K FollowingThe best from AI community | Ex-Microsoft, Rackspace, Fast Company | Wrote eight books about the future | Silicon Valley robots, holodecks, BCIs, and startups.
4K Followers 1K FollowingCriminal IP is a comprehensive web-based cyber threat intelligence search engine.
Search for Anything, Secure Your Everything.
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
209K Followers 195 FollowingDer Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen für Informationsfreiheit und Technikfolgenabschätzung.
@[email protected]
41K Followers 9K FollowingInformation security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
5K Followers 1K FollowingHead of Bundeswehr Cyber Innovation Hub @CIHBw / Leading innovation in defense / Capital Top 40 Under 40 / 🇩🇪🇹🇷🇪🇺 / private opinion only
15K Followers 5K FollowingSenior AI reporter @Verge. 5+ years covering the industry's power dynamics, societal implications & the AI arms race. Previously @CNBC.
Signal: haydenfield.11
204K Followers 624 FollowingFPS is my DNA. Game Director @RomeroGamesLtd | New FPS in the works | DOOM, DOOM II, Quake, Wolfenstein 3D, Heretic, Hexen, SIGIL, SIGIL II.
539K Followers 17K FollowingThe best from AI community | Ex-Microsoft, Rackspace, Fast Company | Wrote eight books about the future | Silicon Valley robots, holodecks, BCIs, and startups.
5K Followers 700 FollowingPrincipal analyst @Forrester bringing cyberattacks into the context of today's biggest global events
infosec, opinionated human - tweets = mine
13K Followers 10K FollowingMost companies only realise they are breached when informed by a 3rd party. This is a stupid problem! Thinkst Canary. Know. When it Matters.
1K Followers 1K FollowingMary 🌸 | she/her🌻🍵🍒 | drawing in a sunny fantasy dreamworld ☔️ | British-Chinese 🇨🇳🇬🇧 | human artist 🍰 Comms: https://t.co/u3hEmHW0AF 🍡
688 Followers 327 FollowingHaunted Hacker is a podcast we started this year. Its based on my experiences with manipulating systems, networks, websites etc. I have a background in SIGINT.
244 Followers 1K FollowingInfosec Guy, Blue Teamer, Threat Hunter & Malware Enthusiast. Infosec is in my blood and all my opinions are purely mine
#infosec #threathunting #malware #DFIR
153 Followers 408 FollowingThere’s a man who spoke wonders, though I’ve never met him He said, ‘We who seek find, and who knock will be let in’ (IBMer with my own thoughts)
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
310K Followers 7K Following#SophieFromRomania book out now! https://t.co/UPEvwIY2rx Movers and Shakers podcast Ruskin Park out in paperback https://t.co/Voo7uXA2IM
5K Followers 141 FollowingWe aim to make the digital world a safer place by reporting vulnerabilities we find in digital systems to the people who can fix them.
45K Followers 2K Following(Grumpy Old) Hacker. Co-founder @GDI_FDN. Co-founder @DIVDnl. Co-founder and CEO of https://t.co/Gfgrg51IjY. Unfiltered on https://t.co/6hPoWNR9jw.
37K Followers 2K Following20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.