A shoutout to all of the unsung heroes right now triaging MGM, restoring systems, analyzing, and helping the businesses recover. Also to the security team there that undoubtedly has been fighting to secure the place and in an immensely stressful time.
This storm shall pass.
🔫 #CornerShot is seamlessly integrated into #TrustMeter, enabling 2nd order scanning.
What is it?
It goes beyond just "seeing" network access from the source scanner to include the access of another host —no special privileges are required!
https://t.co/ufrooE7hnm
Someone has purchased https://t.co/KKUXhs0PWP.
The domain tries to trick users into downloading malware and/or into calling a phony tech support phone number.
Unusual decision considering our userbase is people whose entire lives revolve around malware....
⚠️ SECURITY ALERT
🗒️ 0-CLICK Microsoft Word RCE exploit
Microsoft identifies this exploit as critical. It is important to avoid .rtf files at all costs!
Another day, another #OneNote maldoc! 📄
We're seeing growing OneNote #maldoc usage lately: crooks leverage different lures, such as #Office365 and blurred documents.
Check a fresh "Legal Notice" maldoc with #Redline as the payload 👇
https://t.co/WEa3njqw6x
LastPass breach gets worse and worse.
First: We were breached but no customer data was accessed
Next: Okay some customer data was accessed, but not password vaults.
Now: Customer password vaults were copied by the attacker but don't worry, it will be hard to crack your vault.
LastPass update: The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data as well as fully-encrypted sensitive fields.
https://t.co/TqMQRcHS0w
New BloodHound version 4.2 means new BloodHound[.]py version 😀 BloodHound python v1.4.0 is now live, compatible with the latest BloodHound version. It includes the research from my last blog as a new edge "WriteAccountRestrictions", which also got added to SharpHound ❤️
Thank you all who showed me love/support on the Bloomberg article that alleged I acted unethically. Here's my side of the story: https://t.co/yIYIFAJQoF
Regardless of your opinions please realize the amazing work of the electric utilities to protect this country.
SCOOP: China launched a massive cyber attack on #Ukraine on the eve of Russia’s invasion. Beijing knew about it all along - and helped.
https://t.co/sqAqN5LA03
I’ve previously warned about the potential that Russia could conduct malicious cyber activity against the U.S. Today, I’m reiterating those warnings based on evolving intelligence that the Russian Government is exploring options for potential cyberattacks. https://t.co/wO2jJgg5SJ
I can't count how many hours were spent on this blog but you will walk away with insight into the #Conti#Ransomware group like never before:
Conti Org Chart
Conti Figure Heads
Conti Inner Workings
Conti Blockchain Project
Conti Tools
#ContiLeaks
https://t.co/AKbdrXvWe4