News: I have quit VICE. Me and a small group of Motherboard writers have launched our own company: https://t.co/PF27rMNe22. We'll continue impactful journalism.
If you've ever wanted to support my work, this is the time. Please subscribe monthly/yearly https://t.co/PbZLcI5Ikp
Leaked Google document: “We Have No Moat, And Neither Does OpenAI”
The most interesting thing I've read recently about LLMs - a purportedly leaked document from a researcher at Google talking about the huge strategic impact open source models are having
https://t.co/q2lsjTHKGS
Fake "Monkey Drainer" leak on @github targets wannabe #Web3 Scammers with a Raccoon Stealer!
https://t.co/AQzwfo5ads
c2: 193.37.213.23
As crypto-drainers gain popularity, we see more and more backdoored or malicious codebases targeting would-be thieves.
Malvertisers love to abuse low-impact browser bugs. They're often slow to get patched and make a significant impact on the efficacy of their malicious campaigns.
https://t.co/JQmhrjHQIW
TAG Working Groups are back on THIS WEEK🎉 What have we got in store?
For the #AntiMalware working group, @WeAreConfiant's John Murphy has got a couple of ideas of how to move #antimalware programme forward ⏩⏩⏩
Details to register for the session are in TAG Member's inbox!
A new blog post from Taha Karim ( @lordx64 ) revealing a new method for Mac malware to conceal C2 configuration within the headers of Apple DMG files. This technique was observed in a Shlayer variant, we have dubbed it OSX/Shlayer.F.
https://t.co/dWGK2xUXc2
Thank you @trishlaostwal for chatting with me about the state of Twitter security after the brual downsizing, and the questions it raises for their risk exposure moving forward. Among many things, pressure to make more revenue with ads could lead to an increase in Malvertising ☠️
Scoop: A bug in Twitter’s system, which was rectified on Saturday, exposed sensitive information to the company’s advertising team. Names, addresses and credit card information of several advertisers were left exposed.
https://t.co/x9QIIWusW7 via @Adweek
Last year, while conducting audits on SDKs installed in mobile apps for @SafeTechLabs, a popular SDK installed in thousands of apps called “Pushwoosh” started to raise some odd questions, was it secretly Russian? Reuters has an explosive story out today: https://t.co/vqytktKKlW🧵
When Adtech meets National Security, publishers and app developers (and uh... governments!) need to know their vendors! Great investigation by Reuters' @pearswick and team. Thank you for working with @WeAreConfiant, @Kaileighrose and I on the research.
https://t.co/fuDsftEQAC
Malvertising attack matrix from @WeAreConfiant. Details entire chain, from initial access, execution, to browser exploitation, credential access & more. Helps communicate actionable threat intelligence to entities outside of the #adtech space. https://t.co/UETIBVSauu #infosec
Voldrakus! Cool interview of Confiant Privacy Engineer @Kaileighrose by @Digiday's @petersontee going over this concerning case of TCF consent string abuse:
https://t.co/TgSdSzqlEt
Original research at https://t.co/26E5vr336o