Over 14,000 BIG-IP APM instances are exposed to ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability, according to Internet security watchdog Shadowserver.
https://t.co/yss3t1qv8V
I have created a website, where you can share your sample analysis (via links or posts) and search samples for training based on tags and difficulty.
If you write analysis blogs, you can share them there.
https://t.co/9jlkRxfYW5
I forgot there is a huge chunk of people who aren't in information security and missed the entire VXUG TMZ era where we met people from FBI Most Wanted, the Taliban, got electronics from North Korea, and got sent cat pictures from the FBI
2022 - 2023 VXUG was crazy
tl;dr of today
> @rastalandTV gets crypto drained
> he has stage 4 cancer
> hes targeted specifically for his cancer treatment money
> loses $32,000
> nerds band together
> @ZssBecker donates $30,000 to him
> malware nerds come together
> drainer infra found
> pull all victim data from infra
> victims will be notified
> all malware flagged
> osint nerds come together
> find drainers info from their telegram ids
> find info from their steam ids
tl;dr tl;dr stage 4 cancer bro gets fucked over, 50+ nerds band together to undo the damage
fuck cancer
Big drama today in the Tor community.
Conrad Rockenhaus, a Tor operator based out of Michigan, United States, was arrested in 2020 after refusing to cooperate with the United States Federal Bureau of Investigation
Rockenhaus, a disabled United States military veteran, ran the fastest Tor node in the United States. He was approached sometime in late 2019 when the FBI requested he allow them arbitrary access to his exit node and allow them to decrypt traffic. He denied their request.
Subsequently, in February, 2020 his home was raided. He was arrested for violating the CFAA (Computer Fraud and Abuse Act). It was alleged that he was a disgruntled ex-employee causing problems at his former place of employment.
Interestingly, to "help resolve the matter", law enforcement requested he decrypt his Tor exit node to prove his innocence (???). After he refused, he was held in a pre-trial detention cell for over 3 years. He was denied bail after law enforcement stated Mr. Rockenhaus used Linux to "access the dark web" and he was "not complying" and not allowing them access to this Tor exit node.
After Mr. Rockenhaus' wife filed an official complaint, and Mr. Rockenhaus was miraculously released, he was raided by the United States Marshal Fugitive Task Force TWO TIMES(???).
They took him out his home, threw him to the ground, beat him, smashed his windows, and threatened to murder his animals.
They are still requesting Mr. Rockenhaus allow them to access his Tor exit node. Mr. Rockenhaus still has not granted them that privilege.
All of this has been captured on home security camera footage. Additionally, his wife has released all court documents.
See subsequent post for more information.
Google confirmed that members of group known as Scattered Lapsus$ Hunters were able to gain access to Googles Law Enforcement Request System portal.
A Google spokesperson told Bleeping Computer, "We have identified that a fraudulent account was created in our system for law enforcement requests and have disabled the account".
No requests were made while the account was active
The Great Firewall of China (GFW) today experienced the largest internal document leak in its history. More than 500GB of source code, work logs, and internal communications have been exposed, revealing details about the development and operation of the GFW.
The leak originated from a core technical force — Geedge Networks (with chief scientist Fang Binxing) and the MESA Lab in the Institute of Information Engineering, Chinese Academy of Sciences.
The company not only provides services to local governments in Xinjiang, Jiangsu, and Fujian, but also exports censorship and surveillance technology to countries such as Myanmar, Pakistan, Ethiopia, and Kazakhstan under the “Belt and Road” framework.
Due to the massive volume of material, GFW Report will continue analyzing and updating on this page:
https://t.co/HgzRJbcTls
The FBI has released a FLASH alert on the targeting of Salesforce platforms by the cybercriminal groups UNC6040 and UNC6395, which are responsible for a surge in data theft and extortion attempts. Click for indicators of compromise (IOCs) and protect your organization: https://t.co/CNCBWbMzMj
Zscaler ThreatLabz has released a technical analysis of kkRAT, a new RAT deployed in malware campaigns targeting Chinese-speaking users. kkRAT’s capabilities include disabling antivirus and EDRs, capturing the victim’s screen, and proxying network traffic.
Read the full analysis here: https://t.co/NMxc1veQV0
Excited to share our latest research on APT37(a.k.a ScarCruft, Ruby Sleet, and Velvet Chollima)’s new infection chain and C2 operation:
1⃣ Initial Access: Leveraging LNK and CHM files to deliver Rust-based and PowerShell-based malware.
2⃣ Post-Recon: Deployment of FadeStealer via a Python loader using Process Doppelgänging, followed by hands-on-keyboard activity.
3⃣ C2: A simple yet highly effective C2 script orchestrating the entire operation
Please check this out: https://t.co/P9nUYObvz2
🚨 New malware alert: macOS backdoor CHILLYHELL and cross-platform RAT ZynorRAT discovered.
CHILLYHELL was Apple-notarized and linked to Ukrainian gov site attacks—Apple revoked its certs.
ZynorRAT hijacks Windows & Linux via Telegram, stealing files and taking screenshots.
Full details → https://t.co/CIyYP5H9Z1
A hacker clicked a Google ad.
They thought they were grabbing a tool to help their ops.
Instead, they installed Huntress on their own machine.
👀 And just like that—we got a front-row seat.
We published a wild blog yesterday about a threat actor who installed Huntress.
Some folks had questions.
Was it a privacy violation?
Was it ethical to investigate?
@_JohnHammond + @Laughing_Mantis dig into the story on #tradecrafttuesday
Blog: https://t.co/jjnKpTJCSQ