Turns out giving third-party packages broad access to your files, credentials, and APIs makes for an attractive attack vector. Shocking, I know. https://t.co/rBzxC75tf4
While this sort of action is an unalloyed good, these ecosystems are empowered by a constellation of issues around special economic zones, cryptocurrency enforcement, ignoring regional conflict, and a milieu of scamming or gambling normalization.
Looks like a second round of US sanctions against the Prince Group just popped off. The Prince Group is a significant player in the Southeast Asian scam compound ecosystem. https://t.co/lviXbUTzgp
The controversial facial recognition practices of Madison Square Garden have been known for years. Now, it seems they've made a dossier on people who are critical of them for it.
https://t.co/CgfF1D2YYe
Coming out of hiatus for a quick Threat Actor Drop. This one for FulcrumSec, who allegedly breached Novo Nordisk (of Ozempic fame) last week. https://t.co/WfS8WTT7Ka
"…the alerts included the word 'misanthropy' and were issued at the system's highest emergency level, causing phones to emit loud alarm sounds even when set to silent mode."
https://t.co/HEusGprZJy
"International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group."
https://t.co/DI7dL5kA21
‼️ Just in: FortiBleed attackers rented 36 enterprise GPUs from an AI cloud provider to crack stolen FortiGate configuration hashes at industrial scale.
Cheap, on-demand GPU compute has quietly made mass password cracking easy, while tens of thousands of organisations still run VPN firewalls with no MFA. The threat is now less likely a nation-state and more like a financially motivated crew with a credit card and rented hardware in the cloud.
A write-up by Kevin Beaumont shines a light on the campaign that cracked credentials for tens of thousands of Fortinet firewalls.
He disputes Fortinet's public line that the data is just old breaches and bruteforcing, noting it contains freshly cracked passwords and that every organisation he helped had its config exported in the past month. In those cases the attacker went well beyond collecting credentials, adding admin accounts, opening SSH and RDP firewall rules, and logging into IPsec tunnels, with CloudSEK assessing around a thousand organisations breached internally and the attacker reaching internal Active Directory at a number of telcos and managed service providers.
As much as I like to credit the EU with having less egregious privacy violations than the US or UK, but this piece by Access Now is as awesome as it is sobering: https://t.co/ACLP39kblR
"'The recent reduction in personnel has limited CISA’s ability to fully support national security imperatives and administration priorities,' acting CISA director Madhu Gottumukkala said."
https://t.co/my7chgQf2o
Great video demonstrating Flock's products' embarrassing attack surfaces and facepalm-inspiring practices. For all the talk of "adversaries" surveilling us, we sure have no problem putting these super vulnerable devices everywhere. What a joke.
https://t.co/LubsfEcVo5?...
A report by Anthropic about yet another "AI-powered" cyberattack (powered by their models, of course) is making the rounds. Looks like more fear-mongering. I have instead decided to share this blog post by Kevin Beaumont: https://t.co/Cm4x6UlpNT...
https://t.co/d6YEtA8Zq7 "Three former employees of cybersecurity incident response companies DigitalMint and Sygnia have been indicted for allegedly hacking the networks of five U.S. co...
https://t.co/qB8RoTd9N3 Anduril trials its fighter drone. One of the biggest "winners" in this new era of Silicon Valley defense contractors, it was founded by Palmer Luckey, and has connections to David Sacks, Peter Thiel, and Do...
Three stories (two more below) over the past few days related to the US' telecom infrastructure remaining vulnerable to nationstate infiltration, now almost two years post Salt Typhoon's discovery.
https://t.co/DChmH91Hwj...
https://t.co/kLCqUBKKOX "These media outlets, which operate under direct government control and receive state funding, regularly run smear campaigns against independent media and journalists."
Friends at Decoherence Media published a third article investigating the exposed web server for the neo-Nazi magazine, Rope Culture. It exposes a Canadian Nazi podcaster-turned-Orthodox priest, a Danish metal musician, and a notorious American pedophile. https://decoherence....
https://t.co/Rmjzl9sWQY "According to the document, ICE envisions 254 transport hubs statewide—one for each Texas county—each staffed continuously by two armed contractor personnel."