Unsophisticated attackers are gleefully called "skids". The defenders you hired that have no idea what they are doing are called "scarecrows". The glee goes both ways.
Hacky Easter 2026 takes place from April 3 to May 15! Online Capture-The-Flag #ctf ✋🚩 event for everyone! ⌨️ 🐰 🥚 #hackyeaster
Teaser challenge online: https://t.co/Kz1lYzSKVP
I am excited to share my latest research project I have dubbed the "Intel Outside" project. Last fall I discovered many critical vulnerabilities in Intel's web infrastructure that allowed me to exfiltrate sensitive information about 270k Intel employees/workers, and more.
Hi!
We will never sell courses. All of our courses will always remain fully publicly accessible, and free!
Our courses have sponsors to help support the cost of creating the course.
You can see our courses here: https://t.co/oZsoGlMgZR
🚨 Teams Malware via Browser’s Cache Smuggling!!
Attack Details : https://t.co/d733tr9KZk
A novel attack vector combining browser cache exploitation and DLL proxying has emerged as a significant threat to organizations using Microsoft Teams and OneDrive.
Dubbed Browser Cache Smuggling, this technique allows attackers to bypass traditional security defenses by leveraging browsers’ caching mechanisms to deliver malware disguised as benign files.
Modern browsers cache static files (e.g., images, JavaScript) to improve performance. Attackers exploit this by hosting malicious DLL files on a webpage, disguised as innocuous content like images.
#cybersecurity #teams
Quinlan’s post hits the nail on the head - most SOC analysts are stuck doing monotonous work that’s far below their true potential. Watching endless alerts is mind-numbing; let’s be honest, a machine should do that.
I totally agree with her point about the value of giving analysts the freedom to hunt. The real value of human analysts isn’t spotting a red dot in a sea of green - it’s taking those interesting highlights provided by algorithms and pivoting, exploring, and connecting the dots. That’s what humans are made for - curiosity, exploration, the thrill of the hunt (just like our ancestors chasing deer).
In my view, SOCs of the future should leave repetitive, tedious monitoring tasks to automation and AI. Let’s let humans focus on the detective work, the creative stuff, the things that actually make the job exciting and meaningful.
Great post. Totally resonated with me.
https://t.co/TX3u8noHvt
We're doing giveaways in a little over 24 hours (December 5th, 2024). If you want free stuff please read this post.
IMPORTANT: We apologize in advance for the insane giveaway spam some of you are going to see. Unfortunately, the next ... 20 days-ish will be dedicated to giving people stuff. Sorry! Please don't hate us:(
1. All giveaways will take place on Twitter.
2. All giveaways work worldwide EXCEPT countries sanctioned by the United States government (Cuba, Iran, North Korea, Russia, Syria)
3. All winners will be listed publicly (Twitter handle, not your real name).
4. Some prizes require PII-disclosure. If you win a prize then complain you don't want to share your address, you will be disqualified. How the hell are we gonna mail you something if you won't give us an address?
Gifts this Holiday season:
Physical goods:
- $2,200 (divided between 11 people, each person gets $200 of computer-related stuff)
- $7,500 (divided between 30 people, each person gets $250 of computer related stuff)
- $10,000 (divided between 20 people, each person gets $500 of computer related stuff)
- $100 of vx-underground merch
- 5 copies of Black Mass Volume I (1 per person)
- 5 copies of Black Mass Volume II (1 per person)
- 75 cybersecurity stickers (5 per person)
Courses:
- Certified Red Team Professional (x3)
- Certified Red Team Expert (x3)
- Certified Azure Red Team Professional (x3)
- Zero2Automated (x10)
- C5W Certified Malware Analyst (x10)
- Evilginx Mastery (x12)
- Malcore Lifetime Reverse Engineer Plan (x10)
- MalDevAcademy Lifetime Access Plan (x3)
- MalDevAcademy Database Access Plan (x3)
... more coming as we finalize some details with others. Expect more courses, some VPNs, and cool stuff!
tl;dr spooky malware ppl who spam cats r cool sometimes
BTW, the reason we are releasing a new version of ShellcodePack that soon is that since a few weeks Defender has launched a crackdown on most AMSI bypass methods available in opensource tools. Including Donut, Sliver, etc.
We are thus releasing our own custom method that is not detected by Defender so you can continue to weaponize your .NET assemblies peacefully :)
12 years ago my life was saved by Hurricane Sandy when I was supposed to be in a building performing incident response that got blown up.
There are not many public stories of physically targeted incidents directly related to cybersecurity but they exist.
This is the story
I once responded to a refinery that had been infiltrated by Iranian Revolutionary Guard Corps (IRGC) threat actors. It was chilling to realize they’d begun pivoting into the operational technology (OT) network, gaining potential control over critical refinery processes. They were in a position to alter valve settings, introducing volatile chemicals into the flow at just the right points—actions that could have led to catastrophic explosions, flattening an entire town.
Had they triggered those changes, my infant son might have grown up without a father, and my wife would have become a widow.
As we worked to secure the systems, we found they were able to watch us the whole time, from cameras that still had their default credentials intact.