The critical '0-day' vulnerability you just heard about was likely a 'N-day' vulnerability to intelligence agencies for months, or even years, before public disclosure. #InfoSec
Much of the 'stolen' personal data you see for sale isn't stolen at all. It's legally purchased from data brokers and then repackaged for illicit dark web markets. #InfoSec
Many initial access brokers (IABs) don't break in themselves. They buy validated network access from lower-tier hackers, then resell it to ransomware gangs & nation-states. #InfoSec
Right now, UNC5537 is actively exfiltrating data from Snowflake customer environments. They're not breaking in; they're logging in with credentials stolen from info-stealing malware. Over 165 organizations are confirmed impacted. Your data is likely on their servers. #CyberSec...
Right now, APT groups are actively weaponizing Ivanti CVE-2024-21887, bypassing authentication on exposed Connect Secure VPNs. They're dropping custom backdoors and pivoting into internal networks. Systems without recent fixes are compromised. #CyberSecurity
9/ This week: A massive consumer data leak, high-profile ransomware, a huge botnet bust & a state-sponsored router campaign. The threat landscape never sleeps. Follow @zerodaypost for the latest intel.
#CyberSecurity#DataBreach
1/ ๐งต From the massive Ticketmaster breach affecting 560M to a global botnet takedown, it's been a wild week in cyber. Hereโs the essential intel on the biggest security events. ๐งต
8/ State-sponsored threat actor BlackTech (linked to China) was caught deploying custom malware on routers of international firms. The stealthy firmware backdoor allows them to pivot into corporate networks undetected.
A significant percentage of cloud breaches aren't due to provider flaws, but customer misconfigurations. Companies are often too busy pointing fingers to fix their own exposed S3 buckets and IAM policies. #InfoSec
Ransomware negotiation firms often advise clients to pay, sometimes even facilitating cryptocurrency, ensuring their own business continuity while normalizing extortion. #InfoSec
Right now, nation-state actors are actively exploiting Ivanti Connect Secure vulnerabilities. Thousands of government and critical infrastructure networks remain backdoored, mapping your connections. This isn't just data theft. #CyberSecurity
11/ The dark web thrives on easy targets. Don't be one. Stay vigilant, use a password manager, and turn on 2FA. For more cybersecurity tips, follow @zerodaypost.
#CyberSecurity#InfoSec
1/ Your email and password could be on sale for $2 on the dark web right now. But what *is* this hidden corner of the internet, and how does your data end up there? A deep dive. ๐งต
10/ The best defense is to make stolen passwords useless. 1) Use a password manager for unique, strong passwords on every site. 2) Enable two-factor authentication (2FA) on all important accounts.