Do not dismiss geo blocking! It has loads of benefits and is a good capability to include in the toolkit, it's not a control but it can have a range of benefits! if someone dismisses this without looking at business suitability they probably sell SIEM solutions or firewalls based on traffic volume....
:P
Security through transparency: all chips have vulnerabilities, and most vendors' strategy is not to talk about them. In contrast, we aim to find and fix them.
Read the results of our RP2350 Hacking Challenge: https://t.co/g3ZOPw8Rqp
Weekly summary is out (attribution by other):
-100 orgs in 18 industries sold via initial access brokers in one forum
-0days using 🕸️ vulns in 📧 servers
-cred theft and DNS domain hijacking
- malvertising access campaigns
plus the off/def tradecraft...
https://t.co/ASUSI9sIK8
That's it - my commercial contracts concluded - thx to @DafyddStuttard and the team at @PortSwigger & @NerdKernel and the team at @InterruptLabs for the op to work with world class British companies.
Weekend before I start to help secure a country by joining @NCSC on Monday!
Chinese Cyber: Resources for Western Researchers
Here is a summary of the sources I have built over the last 5 years which are used to source content for the subreddit and Blue Purple pulse etc.
https://t.co/oicPPWAF6G
Weekly summary is out (attribution by others):
-❓ ops on🇷🇺 semiconductors
-🇰🇵 🤖 implant evolution
-🇨🇳 behind 0day ops on Confluence
-❓ ops in 🇹🇼
-🦹🏾 Android supply chain op gets 70k devices
-🦹🏾 skimmers using 404s
plus more inc def/off tradecraft...
https://t.co/ZBhbuLxUTU
Weekly analysis is out (attribution by others):
-🇰🇵 ops in 🇪🇸 on ✈️ coders
-🇰🇵 ops in 🇰🇷 on 🚢
-🇨🇳 ops on ASEAN members
-🇨🇳 ops in 🇬🇾 on Gov
-🇮🇷 ops in 🇸🇦
then
- Malvertising via hacked ad accts
-Smart contracts hosting payloads
Plus off/def tradecraft.
https://t.co/8ZElyuvtiZ
Weekly analysis is out (attribution by others):
-🇨🇳 router ops in 🇺🇸🇯🇵
-🇨🇳 📱 ops against 🇹🇼, Tibet & Uyghur
-🇨🇳 telco and gov ops in ME
-🇨🇳 ops in 🇹🇼🇳🇵🇰🇷
-🇮🇷 ops in 🇮🇱
-❓ telco ops in 🇫🇷
-🇦🇪 ops in 🇶🇦 & wider
plus the usual off/def tradecraft..
https://t.co/wodyNp0uD6
Weekly analysis went out Weds night (attribution by others).
-🇷🇺 ops in 🇺🇦 using Tor etc.
-🇰🇵 ops for ₿ continue at scale / Skype initial access
-🇨🇳 ops on Asian power grid
-🇮🇷 ops were opportunistic
-🦹🏾♀️ using Teams for initial access
+ tradecraft etc.
https://t.co/j4pitYKuDr
Weekly analysis is out (attribution by others).
-🇷🇺 ops in response to 🇺🇦 counter ops
-🇷🇺 info ops in 🌍
-🇰🇵 ops on infosec researchers
-🇰🇵 ops on 👩💼🎤📖
-🇨🇳 ops using SOHO IoT in 🇩🇪
- + more
& 📈 in AI research
+ usual offensive/defensive tradecraft
https://t.co/1ZdmSrit5K
Our IETF journey has resulted in RFC9424 - 'Indicators of Compromise (IoCs) and Their Role in Attack Defence'
The journey started in March 2020
https://t.co/GFDY0rehHZ
August 2023 it became a RFC:
https://t.co/gHdIQhLZhl
Weekly analysis is out (attribution by others).
-🇷🇺 ops using 🎣📱 etc. in 🇺🇦
-🇨🇳 ops far and wide
-🇰🇵 ops after ₿
-🦹🏼 malvertising
-🦹🏽 using 0day in WinRAR for some time
then:
- AI research go brr..
plus the usual offensive and defensive tradecraft.
https://t.co/kfVRDU4Agd
Weekly analysis is out
-🇨🇳 ops in 🇰🇷 using 🍟
-🇨🇳 ops in 🇭🇰 and SE Asia via supply chain
-🇰🇵 ops on ₿ get $2bil in 5 years
-🦹♀️ ops on 🍎 using signed code
-🦹🏻 ops deploying 📡 geo implants
-🦹🏽♂️ ops from 🇸🇾
- ☁️ backdoors
plus the usual tradecraft etc.
https://t.co/MS0wJKGyKT
Weekly analysis is out..
-🇧🇾 ops against diplo targets in 🇧🇾
-🇨🇳 ops in the 🎰 sector
-🇮🇷 ops in 🇩🇪
-🦹🏾 ops in southern African CNI
-🇮🇳 ops in 🇧🇩🇱🇰 using 📱🎣
and
-various crypt breaks
-0day in 🇨🇳 Office suite equiv
plus defensive/offensive tradecraft.
https://t.co/Yy4IgYVs8c
Weekly analysis is out:
-🇷🇺 ops in 🇺🇦 using battlefield endpoints
-🇰🇵 ops in 🇷🇺
-🇨🇳 ops in 🇦🇫🇧🇩🇰🇭🇨🇿🇧🇹🇭🇰🇮🇳🇱🇦🇲🇾����🇵🇵🇸🇵🇰🇵🇭🇹🇭🇹🇼🇺🇸🇻🇳
-🇮🇷 ops in 🇮🇱 via social media
-❓ ops against executives with MFA bypass 🎣
plus the usual offensive / defensive tradecraft.
https://t.co/RWCTmLHiaW
Weekly analysis is out
-🇺🇦 vigilante ops in 🇷🇺
-🇷🇺 diplo ops continue
-🇷🇺 🎣 ops via Teams from SMEs
-🇰🇵 🎣 ops going after ₿
-🇨🇳 ops against 🐧 using open source
-🇮🇷 hosting providers supporting ops for *
plus the usual tradecraft analysis..
https://t.co/h2QSvDvdsY
Weekly analysis is out:
-🇷🇺 ops on diplomats in 🇺🇦
-🇷🇺 ops on 📧 servers in 🇪🇸🇫🇷🇧🇷🇺🇦🇮🇩
-❓ ops in 🇷🇺
-🇰🇵 ops in supply chains
-🇨🇳 ops go brrrr..
-❓ ops on 70k routers
& ++ more ops..
plus the usual offensive/defensive tradecraft and policy analysis.
https://t.co/JyYWDiO4jg