We offer a wide variety of services primarily relating to the digital realm, from custom software solutions to auditing and consulting. Let's work together.
Today we released fierce3, a modernized version of the fierce CLI tool. Functionality should be identical, just add the 3 to the end of all existing commands and look at it go!
https://t.co/N4rfnX7201
The U.S. Secret Service has announced that, following a monthlong investigation, it has carried out an operation which resulted in the dismantling of a network consisting of more than 300 SIM Servers and 100,000 SIM Cards at multiple sites across New York and New York City, all within a 35-mile radius of this week’s United Nations General Assembly.
According to officials, the network could interfere with emergency response services, conduct encrypted communication, jam cellular networks in New York, as well as disrupt official communication from and eavesdrop on the U.N. General Assembly, capable of sending over thirty-million text messages per minute, anonymously. The official said the agency had never before seen such an extensive operation.
The Secret Service believes that the scale of the equipment discovered suggests the network could be part of a nation’s surveillance operation, with initial analysis of the data on some of the SIM Cards having identified ties to at least one foreign nation, as well as links to criminals, including the members of Cartels, already known to be operating in the United States. Cybersecurity experts have stated that only a handful of countries could pull off such an operation, including Russia, China and Israel.
Why can AIs code for 1h but not 10h?
A simple explanation: if there's a 10% chance of error per 10min step (say), the success rate is:
1h: 53%
4h: 8%
10h: 0.002%
@tobyordoxford has tested this 'constant error rate' theory and shown it's a good fit for the data
chance of success declines exponentially
Just made a Medium post on setting up Security Onion in Proxmox, I had some difficulties the first time so I hope this can help others avoid the same hurdles:
https://t.co/PDD6bG6Xer
Following up on this, I found another instance of the campaign yesterday and tracked down the IOCs. There is a lot of overlap, so it is likely being run by the same actors.
https://t.co/PuVamBivwZ
Very interesting article in the #WSJ yesterday, it highlighted the work of "Metalplant" and their efforts to farm nickel using species of plants.
Super interesting mission, worth a look for anyone interested in sustainable mining:
https://t.co/jgFnCj3wfY
Today, @ajmeese7 breaks down a malicious redirection campaign, showing the tools and process used to connect to #ApateWeb, originally reported by @Unit42_Intel.
You can follow his process and review his findings with thousands of indicators here:
https://t.co/VzlFyvPPsR
Well, we actually did it. We digitized scent. A fresh summer plum was the first fruit and scent to be fully digitized and reprinted with no human intervention. It smells great.
Holy moly, I’m still processing the magnitude of what we’ve done. And yet, it feels like as we cross this finish line we are instantly at a new starting line. I’ll have more to share about what’s in store that we’re building on top of this.
A huge HUGE congrats to the entire team across scientific, engineering, operational, and creative disciplines. It takes a village named Osmo to do this.
I don’t know if this is embarrassing, but I carry the plum scent with me a lot of places and smell it constantly. It makes me smile.
I’m curious, if y’all want to smell it? If we made a limited release fragrance of the first teleported scent and dedicated the proceeds to science, would you want it?
Fantastic write-up by Microsoft on the creation and spread of Adversary in the Middle (AiTM) attacks, definitely recommend for anyone in an IT field:
https://t.co/Adm86QZ6Cr
We revamped an aria2 file parser during our participation in the NCL 2023 game, now it's much more user friendly and provides additional information on the file's contents! Check it out below:
https://t.co/8bB2pjySTf
We're going to start posting open source Yara rules whenever we come across malicious traffic on our servers that's able to be fingerprinted. Stay tuned, and let us know your thoughts!
I've reported on VirusTotal and will be adding to https://t.co/a7xn6DgBDr once I've been approved for the reporting privilege. You can use the following Yara rule to detect similar activity on your networks:
https://t.co/5DW5WMOuKh
Just published a blog post on hunting down vulnerable Parallels Plesk Panel instances, use it to check your own company's infrastructure or to look for possible bug bounty targets!
https://t.co/Bm8vIKKCpg
Developed this when I encountered a sophisticated sample using `%=exitcodeascii%` with subshells for obfuscation, and it works like a charm so far!
Give it a look and share any thoughts, I'm opening to adding any missing functionality.