We identified a malvertising campaign targeting users searching for legitimate software, leading to the download of a trojanized WinSCP installer that deployed Broomstick/OysterLoader.
All files involved in the initial access phase were signed with valid certificates.
NGL, that one was tough, I had just 2 minutes to spare at the end
So, if you have a Cyber Incident that needs some Leadership, find someone else, I’m going to the pub
Many thanks to @Nebulator for his patience a few months ago!
#SANS#GIAC#GCIL
Hot cybersecurity tip of the day: AI security is a pressing concern for *some* organizations.
But real talk: most of the people asking me about AI security already have horrific third party risk and vulnerability management programs. Fix your foundations first.
@santanderukhelp You've obviously never worked with charity trustees before - herding them into a room 4 times a year in the village is hard enough - trying to get them an hour away for a 'business' appointment ain't going to happen. Looks like we won't becoming customers #failedtomodernise
@santanderuk If you are going to close your branches you should adjust your processes - requiring charities to get ALL their trustees to drive an hour just to open an account is stupid!
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
https://t.co/e2EwvUMgqw
Sad how advert ridden the @MacRumors website is on an iPhone.
It’s a mess - you can’t tell what’s an article screenshot and what’s an advert e.g.
https://t.co/TJxuGrH1MT
Over commercialised - got bored counting past 23 adverts on only 1/3 of above link.
Always disappointed that the UK Olympic team uses the brand @TeamGB when basic geography should have told them that N Ireland is not in GB, it’s part of the UK.
Not very inclusive 😒
@britishairways your “free messaging for Executive Members” on board Wi-Fi is a poor advert for the paid for service.
Nine attempts to send a single sentence message in iMessage and 6hours of failed attempts to download a 413KB image #fail
@British_Airways Oh it’s available but I’ll sick of trying to guess what random field on the form you’re rejecting.
You have a woeful UI; either your developers can’t code or your don’t care, as the Advanced passenger form is a parsing and #UX disaster.
Everytime I have to use the online @British_Airways website I remember why I hate it and I regret my booking with BA decision.
Having to plan to check in at the airport is the ultimate signature of a failed website. #useless#disaster
🚨 How do you engage law enforcement and legal teams during an incident? Don't wait to find out!
Join 'Cyber Wars: The Legal Force Awakens' TOMORROW with @Nebulator and learn how to act swiftly in a crisis.
➡️ https://t.co/hHZcdtNE5Y
#SecLeadership#IncidentManagement
Hello! I’m going to close the “Go to DEF CON” award from the @offby1security YouTube channel on July 1st. Click on the image below to expand the details and requirements to enter. Visit and join https://t.co/pOHgFpAb7r for more details!
Knowing how to contact legal resources during an incident is crucial.
'Cyber Wars: The Legal Force Awakens' with @Nebulator will teach you strategies to engage with law enforcement and external counsel.
➡️ https://t.co/hHZcdtNE5Y
#SecLeadership#IncidentManagement
As an industry we tell people to adopt zero trust… whilst at the same time saying don’t use ‘public’ WiFi…..
It’s ridiculous….
We tell people to use a vpn…. The number of shady VPNs is massive.
We tell people to not use WiFi at Starbucks whilst our hospitals are running server 2008 r2 ….
Great watching @HackingDave on TV, I was telling Trevor yesterday how much I love Dave’s clarity, articulation and sneaking in of challenge words and references 😝
Here's my interview today from @CNBC talking about Microsoft Recall and Apple's AI announcement and partnership with OpenAI.
My challenge word was "Tautological".
https://t.co/q0NaSIrrXv
#BinaryDefense#TrustedSec
Here's my interview today from @CNBC talking about Microsoft Recall and Apple's AI announcement and partnership with OpenAI.
My challenge word was "Tautological".
https://t.co/q0NaSIrrXv
#BinaryDefense#TrustedSec