@thsottiaux 1) Add pro model for architecture/design decisions
2) Add remote control (leave codex running, use the phone to continue the work remotely)
3) Mobile app for the above would be nice
4) Keep up the good work :)
4/ x-loading[.]com does not look X-owned. The issue is that X resolves whatever is in url= for the link card, giving attackers full control over what domain users see before clicking.
1/ The token-supabase[.]com phishing going around today looks interesting. It was posted from a compromised account: Tyler Shukert's (dshukertjr). That's why it looked credible.
3/ Same redirector, same trick, two more cases today. An impersonator account "Liquid[.]af" (TradeOnLiquid) pushing liquid-af[.]com, and a separate chain targeting ONINO sending users to oninofoundation[.]com. All three destination domains registered in the last 48h.
@flpsnd@threepointone@supabase@kiwicopple Redirect infra used: x-loading[.]com/index[.]php?url=hxxps://www[.]supabase[.]com&redirect=hxxps://token-supabase[.]com. X appears to show the decoy url= host instead of the real redirect= target. Same pattern hit (on X) oninofoundation[.]com and liquid[.]af too. Ongoing campaign
@Cyb3r_D4ddy @UK_Daniel_Card https://t.co/QfCPkvoExq
That same app can be used to provide Warp and zero trust services to team/enterprise users, that’s why it says that on the playstore (as it should).
@solostalking Intelligence analysis - Robert Clark
Psychology of intelligence analysis - Richard’s Jeuer
Structured analytic techniques - Jeuer & Randolph
Intelligence driven incident response - Rebekah & Scott
Top tier reading 👍
Microsoft has partnered with others across industry and international law enforcement and facilitated a disruption of Lumma infrastructure and the marketplaces in which the stealer malware was sold to other cybercriminals. https://t.co/KBvVTFm6QX