Engineer | Investigator @meta, PhD in Applied Data Analytics x Criminology. #animalrights advocate. Founded @threatminer. Calisthenic hobbyist. Views are my own
Notable discovery from @DragosInc on a newly weaponized ICS capability referred to as "FrostyGoop" used in a real-world disruptive event leading to a power outage in Western Ukraine in January 2024. This finding is important for the global Energy sector relying on internet-accessible ENCO devices.
“The fact that it can interact with devices remotely means it doesn't necessarily need to be deployed to a target environment,” [Magpie] Graham says. “You may potentially never see it in the environment, only its effects.”
A remotely deployable capability in-the-wild combined with prevalent exposure of ENCO devices is likely to increases the risk profile of horizontal escalations in the event of cyber-misfires resulting from testing, refinement, mis-attribution of infrastructure, or misguided cyber attacks.
@malwareunicorn Have you tried chatgpt first? I find answers provided by General Practioners are not too different from a GenAI bot, in fact the bot might provide more interesting pointers because laziness isn’t a feature. Not saying one shouldn’t see a doc, but docs need to do better than a bot
ShodanHQ offers again a lifetime membership for one time 5 USD
(you have to login with a free account to see the offer) @shodanhq
https://t.co/jDO9DpzkU7
Financially motivated cybercriminal group Sangria Tempest (ELBRUS, FIN7) has come out of a long period of inactivity. The group was observed deploying the Clop ransomware in opportunistic attacks in April 2023, its first ransomware campaign since late 2021.
Orqa claims a 'greedy former contractor' secretly installed malicious code into the headset's firmware years ago. But the contractor claims it all boils down to a licensing dispute. https://t.co/PtGBsRJjBT
Introducing VirusTotal Code Insight: empowering threat analysis with generative AI. This tool is based on Sec-PaLM (LLM) and helps explaining behavior of suspicious scripts. Code Insight is available now for all our users! More details by @bquintero: https://t.co/TjPJxDWu6T
Today VirusTotal announced that each sample uploaded will be accompanied by "Code Insight". Code Insight uses Sec-PaLM, one of the generative AI models by Google, to explain what the malicious binary is doing.
Code Insight is available to all users.
tl;dr "they took my job"
@dcuthbert@ConradLongmore@UK_Daniel_Card Had the same debate with the wife and we as we have Three and Vodafone. We found it mainly depends on where you are. Sometimes I get reception where she doesn’t and vice versa.
A recent leak of sensitive US intelligence documents, including some marked “Top Secret”, has caught the attention of the US Justice Department and Pentagon. But where and how did these documents appear online? Bellingcat investigates: https://t.co/cKiZxLWGOn
In response to the #3CXpocalypse / #3CX, a group of us have put together a self-service site to look up if you were potentially impacted. If you're connecting from an IP address that was flagged, the header will turn red.
https://t.co/FsLaTsOxrS
#GPT4 saved my dog's life.
After my dog got diagnosed with a tick-borne disease, the vet started her on the proper treatment, and despite a serious anemia, her condition seemed to be improving relatively well.
After a few days however, things took a turn for the worse 1/
@jack 1) All media companies are regulated so regulation is nothing new. Transparency is key.
2) Bad actors will never remove content on their own accord.
3) Why? Algorithms can’t accurately understand context like human can