Greg @Sophos ⚛️🧪 Infosec geek, GNU/Linux lunatic, blue teamer, and strategist for the Technology Office and MDR. Opinions my own (no one else wanted them)
@NISTcyber@NIST Is there any update on the NVD API? It's been returning 503 errors for days now and there hasn't been an update on https://t.co/ExGStV1mOa since the 15th. It's totally understandable that issues happen, but an update on the status would be deeply appreciated.
@joshua_saxe@EITS I remember picking up this album at a independent record store in Oxford when I was 13 along with Sigur Rós ( ) and Mogwai Happy Songs.
That was one life changing weekend!
Look up “mouse on the keys” if you haven’t already. Post-rock jazz from Japan.
Microsoft this week released its June Patch Tuesday collection – 69 patches for 10 project families, plus documentation for 25 (!) patches from Autodesk, GitHub, and Chrome.
We have made another update to our blog on the 3CX situation: https://t.co/AO3Re97w1H
Adding:
- new analysis of an emergent line of inquiry concerning a timestamp mechanism in the malicious code
- information on analysis of other Electron-built apps using ffmpeg.dll
1/7
NEW: Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
Attacker targets bugs in a popular web application graphical interface development tool...
1/16
I've become convinced that in the medium-term, very large models-as-a-service are going to become an important tool within defensive cybersecurity, and this is what Younghoo Lee and I will be talking about at Blackhat USA this year https://t.co/DyqSYQq6Rm
The experience of reading unreliable news about events one can't change affecting people one can't help. I hope there's some value to just bearing witness.
It strikes me that far worse than ML's branding as 'AI' is the branding of the search to unify quantum physics and relativity as a search for 'a theory of everything', when that theory wouldn't begin to explain the behavior of an amoeba
Ransomware Adversary Mishap #2:
The Maze ransomware attackers who exfiltrated a stack of victim files only to discover they were unreadable because they’d been encrypted by DoppelPaymer ransomware a week earlier.
More ransomware adversary mishaps: https://t.co/1SjcGGBHvx
NEW: Fake pirated software sites serve up malware droppers as a service 🏴☠️
During our recent investigation into an ongoing Raccoon Stealer campaign, we found the malware was being distributed by a network of websites acting as a “dropper as a service,”... 1/00
⚠️ Have questions about ProxyShell? Join @MatGangwer, head of the Sophos Managed Threat Response (MTR) team, to learn:
✔️ How attackers are exploiting the vulnerabilities
✔️ How to determine if you are impacted
✔️ Recommendations on how to respond
RSVP: https://t.co/y0psKpWRUo