New Monday Brief is live.
This week the attacker's R&D budget shrank while your attack surface grew. Tricked AI bots, automated EDR evasion, a Claude Code repo takeover, and fake recruiters. No zero-days needed.
Plus a first for us: our debut guest perspective, featuring the great Vicente Diaz @trompi
Douglas McKee (@fulmetalpackets) thinks 🔴
Ismael Valenzuela (@aboutsecurity) 🔵
Vicente Diaz (@trompi) adds the threat intel lens 🔍
https://t.co/RN8kOJ9sHt
#ThinkRedActBlue #TheMondayBrief
📢 Yes. It’s here. Absolutely mind blowing. The highlights of the #PIVOTcon24#agenda.
You have goosebumps all over your bodies? Drrrrrrrrumrrrrrrrroll.. 🥁🥁🥁 Go ahead and check them out! We still have some tickets😉
#ThreatIntel#CTI 🧵1/15
https://t.co/UhOtuCn6bL
1/4 While our PC is reviewing all submissions, we decided to tell you a bit more about pivotal people who are standing behind #PIVOTcon24.
#ThreatIntel#CTI
We are not here to judge! We want to carefully pick the most interesting content for @pivot_con. Welcome our Program Committee and don’t forget to submit your paper https://t.co/isaRCq36TH
#PIVOTcon24#ThreatIntel#CTI#PIVOTconCFP
PIVOTcon is finally out! This has been a nice project in the making, and we are just starting: join me + @secman_pl in Malaga, 8-10 May 2024 for a #threatintel conference, in a trusted environment (vetted attendees only) where we can push the #cti bar a little further #PIVOTcon24
Seeing some qs on what Gemini *is* (beyond the zodiac :). Best way to understand Gemini’s underlying amazing capabilities is to see them in action, take a look ⬇️
New VT Academy training for SOC and IR analysts, led by @digihash! Learn how to efficiently and successfully investigate and contextualize any malicious activity. Watch now: https://t.co/3uJhz7tEAy
Results of Major Technical Investigations for Storm-0558 Key Acquisition: crash dump contains crypto key, dump moved to debug env (not air gapped) for analysis, attackers sit there, use key to access gov corp mail as api accepts consumer key in corp env https://t.co/QgGXz0n3k2
Join us next August 30th 17:00 CEST for a new Threat Hunting live session with a focus on VT's new YARA Netloc capabilities, by @leximagination: https://t.co/7q2la2fIOP
We keep adding more security partners to our Crowdsourced AI effort. We are thrilled to welcome NICS Lab and their AI analysis engine for Powershell scripts, learn more about it at https://t.co/2HRPiRsZOH, by @bquintero
@VirusTotal's new YARA Netloc feature is insanely helpful for infrastructure tracking. If you are not using it already, you should fix that.
Fresh blog with ideas on getting started. Includes highlights of some DPRK #kimsuky fun. 👇
https://t.co/ai3r5qLwvy
Our new VirusTotal Malware Trends Report: "Emerging formats and delivery techniques" is out! by @gerardofn, @alexey_firsh, @entdark_ https://t.co/lw7T1UfjPy
Today we announce YARA Netloc, a new feature extending YARA's supported entities from traditional files to network infra, including domains, URLs and IPs. This opens endless possibilities for hunting and monitoring. All details here, by @leximagination: https://t.co/YsUqfElXyj
Today we launch VirusTotal's Crowdsourced AI, our open initiative for the security community to explore AI's capabilities to improve threat detection and response: https://t.co/QmrrnerfsK by @bquintero
Syntax highlighting, auto-complete, templates, testing capabilities ... Our new YARA editor couldn't look better! Check out all the details here, by @leximagination: https://t.co/CiVO4lNIOs
We've been working with @Mandiant's @JWilsonSecurity
to add Permhash to VirusTotal, a new way to unearth adversary's infrastructure and toolkits by leveraging permissions similarity. Details here, by @zenitrame: https://t.co/n3ueqSHYrJ