Since defending against ransomware begins with understanding what it is, we've created this flowchart that maps a typical attack from start to finish from an attacker's perspective.
Fun fact: “Buxgalter Tekshiruv Dasturi” is Uzbek for “Accounting Audit Software”.
Also, as of now, this IS detected and a "Deep CDR" sanitized version of the .jar is available at @OPSWAT's https://t.co/wmc1lY66SF.
A malware detection rate of up to 99.2% via @OPSWAT's MetaScan is incredible. Add MetaDefender Aether, an emulation-based sandbox, & its ability to detect & block zero days that slip past traditional anti-malware scanning & you've got a truly powerful cybersecurity platform.
The cyber attack on Stryker was attributed to the Handala persona of Iran's Storm-0842 group which often uses TTPs more similar to hacktivists than an APT. Shakespeare must've had cyber defense on his mind when he wrote "a rose by any other name...".
https://t.co/YQi3zYmosT
What I find interesting about Handala's attack on Stryker is how, within hrs, their employees started sharing details & tips on Reddit. Handala is a newish persona of Storm-0842 (aka Bannished Kitten) affiliated w/ Iran's MOIS.
More of my thoughts here:
https://t.co/FyUonq6X6J
This Mythbusters-styled pilot episode of "Into the Breach" has got to be the most entertaining way to introduce the concepts of firewalls and data diodes.
I stumbled upon 2 publicly traded companies that fell victim to ransomware but did NOT disclose it to the SEC. It inspired me to write this article about whether or not failing to disclose a ransomware attack is fair to shareholders.
https://t.co/WMnXhM0sRN
It seemed appropriate to use AI to help me develop some resources to pass @CompTIA's new SecAI+ cert (if they select me). I figured I'd share this (unofficial) practice quiz & study guide with the broader infosec community. Enjoy!
@CompTIA is launching a new AI security certification, SecAI+, & are seeking cybersecurity professionals to take the beta exam for FREE. To receive a FREE (unofficial) practice quiz & study guide we developed to help you pass, simply give us a follow & send a DM. Good luck!
Also, directed PT is part of the work day. How much less REAL work will get done so a bunch of cyber & Intel nerds can PT every day? We've already got military members finding excuses to work 6 hr work days as it is.
While I get his point about combat roles, the DoD is struggling to retain its best cyber warriors. Standards should reflect the unique needs & competitive job market of the role needed to be filled for the sake of national defense.
Secretary Hegseth: "Frankly, it's tiring to look out at combat formations or really any formation and see fat troops. Likewise, it's completely unacceptable to see fat generals and admirals in the halls of the Pentagon."
@Sophos Thank you for the clarification. Any insight into why y'all got $1M median ransomware payment but Verizon's DBIR got $115k? That's a BIG difference!
@ImposeCost Correct. I don't think many people want to employ or work around people that would celebrate or justify cold-blooded murder.
Firing those who do may be one of the best ways to mitigate workplace violence.
Fun fact about @TonySeruga. I think it was sometime after 2019 he started pretending being a CIA/NSA contractor after being an internet marketing guru in 2011 & then switching to commercial real estate financing around 2015. Weird dude. My guess is he's in his 70's.
Here's an updated image I created illustrating the real-world harm done by folks like @TonySeruga & anonymous 4Chan users LARP'ing as intel analysts or detectives. The popularity of misinformation & absurd conspiracy theories indicates a SEVERE lack of critical thinking.
It's not a "newer higher resolution" image of Charlie Kirk's alleged shooter, as some are claiming; it's an AI bastardization that is more likely to hinder the man-hunt than help it. This is yet another example of the misuse of AI by folks who don't understand its limitation.
It's not a "newer higher resolution" image of Charlie Kirk's alleged shooter, as some are claiming; it's an AI bastardization that is more likely to hinder the man-hunt than help it. This is yet another example of the misuse of AI by folks who don't understand its limitation.
@ImposeCost There's always going to be radicals & extremists at the fringes. But I'm afraid what we're seeing is an ideology inspiring a significant portion to have murder in their heart. WAY too many people celebrating & justifying Brian Thompson's & now Charlie Kirk's murder.
@Snakesan@ImposeCost You think Charlie Kirk "asked for this" so you can't find sympathy for him? But "reserving sympathy" makes you seem less violent & radical than outright defending those celebrating Kirk's murder bc everyone gets to the point where they can no longer "take it on the chin".
@BreakingDefense I bet that handsome cyber warrior can hack and defend all the things using that sweet "pew pew" map! Fun fact, we were encouraged to find something cool looking (& unclassied!) to have on our screens for this photo. I believe I had something like this on my other screen.