A suspected state-aligned threat actor targeted a global market research firm using LOTL techniques to evade AV/EDR.
Our SOC caught the activity mid-intrusion. Blog has full TTPs + Sigma rules.
https://t.co/pn8P5ssZXj
Is the era of the “named actor” done?
As the OG adversary sets diverge, get promoted, or move on
actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground)
AND the CTI models maturing…
APTs ⬇️⬇️
UNCs ⬆️⬆️
I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below.
https://t.co/NWkYfZEjVe
The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
Seeing lots of malicious Google ads being served to people trying to find their 401k. I suspect it's #Danabot being served from the domain usdepttreasury[.]org. Today the stage 2 downloader is various subdomains fo jacksoninternationalairport[.]org.
After years of cooking & cutting up my autistic sons fish fingers how he likes them so he is able to eat & enjoy them, I passed him his plate today and he said “you’re a good mummy to me, thank you.” My heart 🥰
Hot take: people dropping "autism/autistic" in a negative connotation as a replacement for the cancelled R word is technically a slur
It doesn't bother me, but I think it's an example of unfair double standards
💟 Love DFIR?
🛑 Love stoping lots of attacks?
⬅️ Live on the West Coast or in MST?
Huntress has a Principal Analyst role open. Drop me a DM if interested!