GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Synnovis aka Synlab, a key NHS frontline service supplier, has been hit by ransomware. #threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

You’re going to see some incredible media bias with the Synnovis ransomware incident as it impacts southern hospitals - whereas NHS Dumfries and Galloway are several months into their ongoing ransomware incident and barely any coverage. #threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar
GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

On 10th May 2024, Keytronic filed an 8-K with the SEC for a data breach.

Turns out it was ransomware, Black Basta say they have 530gb of data. Keytronic haven’t informed customers. #threatintel

dubbel, to python
@dubbel@mstdn.io avatar

Reported 5 malicious packages to : numberpy, tqmmd, pandans, openpyexl, reqwestss all by the same user leemay1782.

All with the same "functionality", getting commands via a socket from dzgi0h7on1jhzdg0vknw9pp9309rxjl8.oastify[.]com and executing it.
I don't think I saw the setup.py entry_points being used as a trigger mechanism before?

benjaoming,
@benjaoming@social.data.coop avatar

@dubbel maybe it's connected to some kind of "StackOverflow attack", where the attacker tells the user to install a package and run a command?

neurovagrant, to infosec
@neurovagrant@masto.deoan.org avatar

we just out here findin' stuff on a wednesday, don't mind us.

https://infosec.exchange/@securitysnacks/112526234384153881

neurovagrant, to random
@neurovagrant@masto.deoan.org avatar

Anyone have a good IOC IP list for RaspberryRobin?

(Starting to search now, but worth asking. External request from a pal, not an internal investigation)

#threatintel

nopatience, to Cybersecurity
@nopatience@swecyb.com avatar

MITRE Intrusion-Sets and ATT&CK Techniques mapped in an Obsidian Markdown node-network.

With inspiration from @screaminggoat and @mttaggart I have put together a first iteration of this.

https://publish.obsidian.md/nopatience/MITRE+-+Intrusion+Sets

Have a look, see what you think. How could I make it more useful to you?

It's generated using a custom-made graph-network abstraction layer I wrote in Python and then pulling some publicly available JSON-files for the Intrusion Sets and Techniques.

#ThreatIntel #CyberSecurity

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Some ‘free Palestine’ hacktivist style group called Handala have been defacing websites and claim to exfiltrate data. https://handala.to/ #threatintel

23 orgs hit so far.

christopherkunz, to random
@christopherkunz@chaos.social avatar

A couple of days ago, LockBit had published an entry on their leaksite titled "telekom.com". I asked the Telekom press corps and they denied any incident.

Yesterday, LB also published the data allegedy from Telekom. I had a look at the files. So far, it seems that nothing in the 1.2GByte directory on their file share has anything to do with Deutsche Telekom. It seems that in fact, they breached a client PC owned by a non-profit in Hamburg.

#lockbit #threatintel

secana, to random
@secana@mastodon.social avatar

A lot of booking.com phishing is going on today. Did I miss something? #threatintel #itsec

AngryAnt,
@AngryAnt@mastodon.gamedev.place avatar

@secana Seasonal? Opportunity to run a campaign centered on late cancellation opportunistic travel?

neurovagrant, to Cybersecurity
@neurovagrant@masto.deoan.org avatar

Whole lot of IDN Homoglyph Attack registrations via GoDaddy and hosted on Amazon the past few days. Examples from yesterday and today:

xn--fcbook-pta36b[.]com (fácębook[.]com)

xn--xnt-rmal15isb[.]com (xƭínïtƴ[.]com)

xn--xnt-vmag15isb[.]com (xƭînïtƴ[.]com)

xn--goole-b3b[.]com (gooǵle[.]com)

#cybersecurity #infosec #threatintel

neurovagrant,
@neurovagrant@masto.deoan.org avatar

Also seeing a cluster of Namesilo registrations of okta-company or company-okta domains and similar.

okta-keap[.]com and keap-okta[.]com (small biz CRM)

okta-plaid[.]com and plaid-okta[.]com (payments)

astranis-okta[.]app (satcom)

bizzabo-okta[.]com (event mgmt)

adasupport-okta[.]com and okta-adasupport[.]com (cust service platform)

okta-verified[.]com

#threatintel

neurovagrant,
@neurovagrant@masto.deoan.org avatar

Gotta go do SecOps stuff now. Lots and lots of badness out there, y'all be careful!

(And as always, hit up @DomainTools if you're looking to see what's out there or protect your brand.)

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

BrandyWine have filed an 8-K with the SEC for a “third party deploying encryption” which is a unique way of saying ransomware

https://www.sec.gov/Archives/edgar/data/1060386/000119312524133132/d824906d8k.htm

#threatintel #ransomware

joy,
@joy@mastodon.social avatar

@GossiTheDog It’s Brandywine Reality Trust, for us colonials. It’s a big East Coast commercial reality firm based in Philly.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

DocGo have filed an 8-K with the SEC for a security breach. Medical records related to ambulances in the US.

https://www.sec.gov/Archives/edgar/data/1822359/000182235924000037/dcgo-20240507.htm

#threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

LockBit are claiming they have hit Deutsche Telekom #threatintel #ransomware

lukas,
@lukas@social.lukas-schieren.de avatar
cccfr,

@GossiTheDog Telekom: "ich hatte die Fragen schon unter Gossis Beitrag im Fediverse gesehen. Die Situation war anfangs etwas unübersichtlich, weil offenbar Trittbrettfahrer auf das Thema eingestiegen sind. Jetzt kann ich dazu sagen:

Auf einer Website, die von einer Gruppierung mit dem Namen LockBit as-a-Service betrieben wird, sind die Namen von 40 Unternehmen veröffentlicht worden, denen Daten gestohlen worden sein sollen. "
1/2

nopatience, to random
@nopatience@swecyb.com avatar

NoName are going bananas with DDoS-attacks against Finland since a few days ago.

Sup?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • tester
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • ethstaker
  • cisconetworking
  • rosin
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • Durango
  • DreamBathrooms
  • megavids
  • ngwrru68w68
  • normalnudes
  • modclub
  • Leos
  • love
  • osvaldo12
  • tacticalgear
  • mdbf
  • anitta
  • provamag3
  • cubers
  • GTA5RPClips
  • JUstTest
  • All magazines