after 15+ years, friday was my last day at @Google. really proud of what we accomplished and the impact we had protecting users everywhere. thank you to everyone that was part of the journey ❤️
really excited about what’s up next!
NEW: foreign mercenary spyware is coming to the US.
ICE just quietly unsuspended contract with spyware maker #Paragon.
Remember them?
Caught earlier this year being used to hack journalists.
Bad move for Americans rights, national security & counterintelligence 1/
Get ready! We are excited to announce that RooCon is planned to be a two-day conference this year, on 5-6 November 2025, packed with an amazing agenda of CTI content. 🦘
⏲️📅 Guest registration will open next week at 0930 AEST on 2 Sep 2025
🧵
#RooCon#RooCon25#CTI
New GTIG blog just dropped! 🥸🇨🇳🌐💼 ”Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats"! We're analyzing an operation that has it all; AitM, social engineering, signed malware, and more! Get the full breakdown here:
https://t.co/nud9mj1ddY
🚨 Heads up! 🚨 APT41 is getting creative, using Google Calendar 🗓️ as their latest C2 trick. Google Threat Intelligence Group just pulled back the curtain 🎭 on the TOUGHPROGRESS malware campaign and how we shut it down 💪. Dive into the details here: 🚀https://t.co/x9CeAPmpX0
🆕 research from @Google Threat Intelligence Group and friends in @GoogleDeepMind on adversary misuse of gen AI. productivity gainz 💪, but no 🚫 new novel capabilities observed yet. really great work from many across the team!
https://t.co/EgjpB1vC6Z
🆕🚨 analysis from @Google on APT42 activity against 🇺🇸 and 🇮🇱. A ton of work from folks over the past few months dedicated to protecting users disrupting campaigns, and making life hard for the actors. More to come!
https://t.co/rFocbBqXXv
🚨 #RooCon24 Guest Registration is Open! 🦘
Register to attend at https://t.co/aYQdrTDLxg
Get in quick before the seats fill up! We will be approving registrations starting next week.
Stay tuned for further conference details, including keynote speakers.
🪲And the 2023 Year in Review of Zero-Days Exploited In-the-Wild is out!
This year I teamed up with @JaredSemrau & James from Mandiant to write a joint report combining our expertise and providing a more holistic view on in-the-wild 0-days in 2023 🔥🧐
https://t.co/6INizgzKwg
So proud of the team here and being able to put together a glimpse into the work we're doing day in and day out in TAG analyzing these threats and doing what we can to disrupt and crush these attackers 💪
🆕report from @Google TAG and @Mandiant 🤝 on cyber activity related to IL-Hamas war and the actors involved.
blog: https://t.co/pmuApkjdNR
report pdf: https://t.co/FRv7ZXZpn5
iocs: https://t.co/8H5DBwhgwg
We're naming names 🔥 because the harm is not hypothetical.
Today we share "Buying Spying", our new report diving into the commercial surveillance/spyware industry. We dive into the players, the campaigns, the spyware, & the harm it perpetuates.
https://t.co/D8Lx4wRrw6
Wow @Zurich_Marriott is a class act in customer service!! I forgot my watch, they said they'd mail it to me in Sydney. Comes a week later beautifully packaged along with a little box of chocolates 😍
Proud of the work done by @Google TAG's @Katz29 in the new blog post detailing how government-backed attacker groups are leveraging the WinRAR vuln CVE-2023-38831 https://t.co/GUyiCwEtku