💻Last week I presented at @ComfyConAU about code graphology and how it can be used for exploit hunting! Here is a thread on what was discussed and how you can apply code graphology in your research! #infosec#threatintel#exploit#yara🧵👇
We (@Iglocska) with @CERT_Polska_en / @NASK_pl are presenting the MeliCERTes project and how the toolset supporting the cooperation of EU CSIRTS have been developed at #FIRSTCON22 .
The project is funded by @EU_Commission (under Connecting Europe Facility (CEF)-telecoms).
Leaked in 2016, #Mirai source code still powers most of the IoT botnets tracked by #ESETresearch. Although a living corpse, #Mozi was the biggest of them, attacking 5.6 million times and compromising 500,000 unique IPs in T1 2022. 1/4
North Korea government sponsored hacking group SectorA05 targeted Spear Phishing attack against NGO activists for assisted North Korean defectors, they also disguise as NGO activists for attack #APT#Phishing#threatintel#threathunting#threatintelligence
@KorbenD_Intel@_CERT_UA Hypothesis: CERT_UA fight for their country when intel vendors fight to look more impressive that their competitors ? Remind me this @mljanderson's tweet :)
https://t.co/yqrxtRjNKc
Tell me how @_CERT_UA can say more in one short google-translated paragraph than most intel vendors do in five? They are under fire and still exemplifying excellence!
There is a little secret about a three letter company selling a SIEM for a significant pricing and then you have many customers asking for integration with a well-known open source TIP. And obviously to who they ask to do it for free? the open source volunteers…
Our #CatalanGate report reveals the largest number of confirmed spyware victims and targets in a single case, including *every Catalan president since 2010*
https://t.co/yuyxVpvx5w
#ResourcesRot : What would happen if the www[.]google-analytics[.]com domain present on billions of sites expired and was not renewed? Two #OffensiveSecurity Specialists explore the exploitation opportunity brought by Broken Hypertext Link. #vulnerability
https://t.co/QgBvWEWBqA
How are there 2 winners? Mitre: "MITRE Engenuity does not assign scores, rankings, or ratings. The evaluation results are available to the public, so other organizations may provide their own analysis and interpretation - these are not endorsed or validated by MITRE Engenuity."