We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort victims: https://t.co/gyaGA1iG1S
I have a hard time recognizing or appreciating Chinese innovation when I have spent my career responding to intrusions, particularly 🇨🇳 hacks of tech & data companies while at Mandiant. For so many in infosec, it’s impossible to differentiate breakthroughs from decades of cheating & theft.
Here are some memorable quotes from my time at Mandiant (2014-2020):
🗣️ "We probably have somewhere in the order of 2,000 active investigations that are just related to the Chinese government's effort to steal information." - Christopher Wray, FBI Director, at the U.S.-China Economic and Security Review Commission, 2020
🗣️ "The Chinese government is known for using their military's cyber capabilities to hack into private U.S. tech firms. They steal I.P. and then transfer the technology to state-run companies for profit off of its development." - Rep. Matt Gaetz, at a hearing on Chinese IP theft, 2017
🗣️ "The greatest transfer of wealth in history is from the U.S. to China through cyber theft, and it's happening every single day." - Mike Rogers, NSA Director, 2015
🗣️ "There are only two types of companies in the United States: those who have been hacked by the Chinese, and those who don't know they've been hacked by the Chinese." - Robert Mueller, FBI Director, 2014
This is awesome! Incredibly useful for IR and beats my handmade notes 😆
Thank you to the folks that made this guide public 🙏 🙏
Get the PDF directly from here 🔗 https://t.co/tXu3Y8oTSJ
Looking for a strong #dfir IR leader for a US east nightshift role. Happy to include even sending folks to Hawaii to make the time requirement easier. OK with remote or in office if preferred. DM me or apply:
https://t.co/yvciH4cg09
We have finished our investigation into last week's Mandiant X account takeover and determined it was likely a brute force password attack, limited to this single account.
Here’s an example of a common phone call scam hitting folks right now — the criminal uses AI to clone the voice of a loved one (often a child, nephew, grandson, etc) and call you. When you pick up they tell you they’re in trouble and need money for bail, etc.
Voice cloning only takes me 2 minutes and could trick folks out of thousands, make sure your loved ones and coworkers are aware.
Security tip: make sure you’ve enabled “number lock” for every phone line on your Verizon account
Account > Edit Profile & Settings > Number Lock
Coming back with a bang! Hope it was worth the wait...
#Venus captured from home under supremely good seeing conditions. Vast cloud structure is visible in the ultra-violet band, with the bright polar hoods also nicely resolved. False colour IR-UV image. #astrophotography
How does an organization even protect themselves against such an attack? For starters, using "phishing-resistant" forms of MFA, such as FIDO2, is an extremely effective measure against these social engineering attacks. 5/N https://t.co/Y3L529redj
Thank you for having me. Thanks to the organisers, volunteers and sponsors of @CrikeyCon. It's both an honour and a privilege to talk and share a topic that's near & dear to my heart.
@nnwakelam Hot water and lemon is great for that. Asp peppermint tea is a good cough depressant. Thanks for the update and hope you get well soon mate.