A blog on some long running research @kristindelrosso and I worked on for a while. (shoutout @terminalrift):
Hornbill and SunBird are state-sponsored surveillanceware with roots in commercial stalkerware/spyware. https://t.co/2iJfSDIAZA
The mobile platform is perfect for surveillance, & actors are using various techniques to steal info from mobile devices. Learn more in this Microsoft Threat Intelligence podcast episode with @x71n3, @lauriewired, @abby_kcs, & host @sherrod_im https://t.co/nDXzK4uh3n
8/ Bonus from @Google TAG: super helpful chart of some key players.
Of course, familiar names like NSO Group, Intellexa & Quadream, but also signs of the smaller market players (a growing part of the problem).
Journalists, this is a fantastic list of companies to scrutinize.
I can’t believe some of you are out here browsing the internet without uBlock.
Now google is making changes that will disable it?!
This is a game changer in the browser user share wars.
🚨 @Google TAG's @maddiestone in close collaboration with our colleagues at @citizenlab burning more 🍏 and 🤖 0days used against targets in 🇪🇬 in an effort to install Predator
https://t.co/0U5G0ekeyS
🚨 Microsoft's warning: Phishing-as-a-Service is on the rise. Learn how AiTM techniques are used to bypass MFA protections.
Learn more: https://t.co/7C0maAuq8J
#cybersecurity#informationsecurity
🚨SCOOP: My new @Haaretzcom investigation reveals new Israeli cyber companies developed technology that exploits the heart of the online economy - ads - not just for mass surveillance, but also to hack phones 👇
https://t.co/TPfBO1SZHP
Canadian researchers discover spyware infecting iPhones without users ever clicking on anything https://t.co/5QNaF4pLYd via @torontostar@joshualdwchong reports 👇
North Korean actors 🇰🇵 are targeting security researchers again including use of at least one 0-day. IOCs in the blog ⬇️ If you've been in contact, please reach out
https://t.co/SiMq2tsNuY
Genuinely every Windows user should look through all the random capabilities PowerToys has. It can do TONS of stuff like window management. Really it's worth clicking and being aware of what you can do with it. It's a tools suite that's constantly updated.
https://t.co/G8j32OrrEd
Great story, with visuals showing near misses. US has shortage of air traffic controllers, which officials believe may be “leading to close calls, in which planes nearly crash. There were at least 46 near misses involving commercial airlines last month” https://t.co/h0OOEGGyl3
THC RELEASE: How to bounce via Cloudflare when the attacker and the victim are both behind NAT (and how to extract WireGuard Secrets from WARP+). https://t.co/2FkpYeew8o #cloudflare#hacking#exfil
#DYK you can forward it to 7726 (SPAM)? Doing so will help mobile service providers identify smishing messages which can help keep Canadians safe! You can also register your number to the national #DoNotCallList :
https://t.co/fjLJxje4u5
If you think you’ve received a smishing attempt, delete the message and block the number. Do not reply, even if the text tells you to text “STOP” or “NO”.
From the @Volexity#threatintel team: this blog post details #CharmingKitten's POWERSTAR malware, now with an InterPlanetary twist... Read more: https://t.co/vA6WZjRenO #dfir
The slides of our talk at Recon 2023 "Dissecting the Modern Android Data Encryption Scheme" are now available online.
Thanks @reconmtl for organizing this great event.
https://t.co/vv2Z5zcTNQ