🌐 I didn't think it was possible but Lockbit is increasing the attack rate 🚨
Sixteen victims were added by Lockbit in the last 24 hours. most of the victims are from the United States 🇺🇸 two are from Netherlands 🇳🇱
#Lockbit
How do cyber criminals grow their organization? Vote for my panel at @sxsw to hear about the 5 essential factors of building a cyber-crime empire (and how to disrupt them). @TrellixLabs @Trellix
https://t.co/rToWBGHcIf
Our labs team at @Trellix is sharing insights into the recent #ransomware campaign targeting Ukraine, which is believed to be pseudo in nature. Read more here: https://t.co/EBf6gkekus
We received multiple requests asking if MISP is vulnerable to #Log4Shell . It's not vulnerable as we don't use Java and don't rely on log4j. At least, you can skip one software from your attack surface review.
One of the developers for Babuk ransomware group, a 17 year old person from Russia, has been diagnosed with Stage-4 Lung Cancer. He has decided to leaked the ENTIRE Babuk source code for Windows, ESXI, NAS.
You can download the Babuk source here: vx-underground[.]org/tmp/
"YAFRA is a semi-automated framework for analysing and representing reports about IT security incidents. Users can provide reports as PDF and YAFRA will extract IOCs (indicators of compromise)" A promising open source project with a nice MISP integration.
https://t.co/srxKSp2gY6
For years ATT&CK Navigator has enabled users to annotate and make ATT&CK their own. Today, the Center for Threat Informed Defense released another piece of the toolkit, which lets users create and share their own techniques. Check out ATT&CK Workbench at https://t.co/tnohtCSLLs
@Jisc enters partnership with organisations in US, Canada, Australia to share cyber threat intelligence on MISP platform https://t.co/8fhVS1plCR #CyberSecurity#highereducation
We're hiring again for ATR :) This is a unique position, as a technical liaison for industry researchers. Job details below - feel free to ask me any questions.
https://t.co/B0IZTSQnvg
We've just discovered 6970 exposed webshells which are publicly exposed and were placed by actors exploiting the Exchange vulnerability. These shells are being used to deploy ransomware. If you're signed up to Telltale (https://t.co/caXU7rqHaI) you can check you're not affected
Virustotal retrohunt results for the YARA rules published by FireEye
#FireEye#Hack#YARA
- post-processed with Munin for a better overview
https://t.co/7Gy1P8madk
How often do you get the opportunity to investigate an adversary's C2 server? We did and you can read our analysis of Operation NorthStar's C2 here: https://t.co/PtIyd7Q8Ah #DFIR#infosecurity@McAfee_Labs
.@RiskIQ has just released the entirety of its unique and expansive holdings relating to the Ryuk ransomware.
We are exposing all known infrastructure upon which the threat actors behind the attacks currently rely. https://t.co/b5Ar445m7T