quad9dns, to security
quad9dns, to worldwithoutus

Read the latest Cyber Insights from Quad9's Director of #ThreatIntel on our partner AFRINIC's blog: https://blog.afrinic.net/cyber-insights-african-perspectives
#Africa #DNS #security #privacy

RedPacketSecurity, to OSINT
LeeArchinal, to Cybersecurity

Happy Wednesday everyone!

I am flattered that I have the opportunity to present my 2-day training "A Beginner's Guide To Threat Hunting: How to Shift Focus from IOCs to Behaviors and TTPs" again at Black Hat USA 2024 and that early bird registration is open and you have two opportunities to take the course!

Day 1 begins with a theory section where we discuss resources and models that can help aid our threat hunting from both an intel and communication perspective. We then move to a section that covers how to extract artifacts from an intel report and how to make those artifacts actionable. Then we create some hypotheses and test them against a set of data to see what we can find.

Day 2 will put all the theory and applications to the test where the students will break into teams, process another intel report, create hypotheses, and hunt again!

Last year was a lot of fun and we receive high ratings, so we hope you can join us again this year for the fun! I hope to see you there, but until then, Happy Hunting!

A BEGINNER'S GUIDE TO THREAT HUNTING: HOW TO SHIFT FOCUS FROM IOCS TO BEHAVIORS AND TTPS
https://www.blackhat.com/us-24/training/schedule/#a-beginners-guide-to-threat-hunting-how-to-shift-focus-from-iocs-to-behaviors-and-ttps-36528

#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Black Basta #ransomware group claim they have hit Siemens Manufacturing in the US, taken 800gb of data.

#threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

B. Riley Financial has filed an 8-K with the SEC. It’s for their company, Targus International, LLC.

Reads like ransomware.

https://www.sec.gov/Archives/edgar/data/1464790/000121390024031252/ea0203500-8k_briley.htm

#threatintel

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

Hmm. People are speculating on the nation state that’s behind the #xzbackdoor and seem to be taking a decidedly Western perspective on this. The suspected threat actors they’re naming are typically Russia, China, Iran, and North Korea.

Folks, I just want to point out that you shouldn’t exclude UK, Israel, France, USA, and many others who are more than capable of this as well. And yes, this could have also been some black hat or even a commercial spyware shop doing this to later sell to the highest bidder.

#infosec #xz #HackerLife #threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Trigona #ransomware group claim they hit Claro, a large telco.

Claro was one of the early LAPSUS$ victims a few years ago, with LAPSUS$ gaining access to their VMware vCenter clusters.

#threatintel

dubbel, to python
@dubbel@mstdn.io avatar

Reported 15 malicious #PyPI packages: asyncioo, asyyncio, asyincio, aasyncio, etc...

On install they decrypt Fernet encrypted code, which loads further code from https://funcaptcha[.]ru/paste2?package=asyncioo (replace the parameter with the package name).

I was blocked from accessing that code (am on mobile right now, so I don't have the means to investigate for real, Fernet decryption was already fun :abloblamp: ).

Anyone else able to access it?

#IOC #threatIntel #python

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

INC Ransomware claim they have 3tb of NHS Scotland data.

It may be related to the ongoing ransomware breach at NHS Dumfries and Galloway (“cyber attack”)

#threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

NHS Dumfries and Galloway finally confirm ransomware, say:

“We absolutely deplore the release of confidential patient data as part of this criminal act.

“This information has been released by hackers to evidence that this is in their possession.

“We are continuing to work with Police Scotland, the National Cyber Security Centre, the Scottish Government, and other agencies in response to this developing situation.”

#threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

INC Ransomware group should go on the shit list if they don’t delete the data and help decryption, it’s a shit target - it’s public healthcare. #threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Scottish government have confirmed the INC Ransomware “NHS Scotland” dump is actually just NHS Dumfries and Galloway.

https://www.bleepingcomputer.com/news/security/inc-ransom-threatens-to-leak-3tb-of-nhs-scotland-stolen-data/

#threatintel #ransomware

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

NHS Dumfries and Galloway have set up a website for victim questions: https://www.nhsdg.co.uk/cyber-attack-faq/

NHS D&G are saying a small number of patient info has been leaked but there is a lot of wordsmithing going on - they’re talking about just the INC portal posts, and they’re only contacting those patients.

I am hoping the Scottish government tells them not to pay the extortion.

#threatintel #ransomware

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

LockBit claim to have got into Lifeline, who do US federal government hosting. They’ve dumped a bunch of Active Directory data which appears authentic, and spans managed and SaaS customers, in an effort to get payment. Some of the domains have FedRAMP in them.

“Lifeline Data Centers Chosen to Supply FedRAMP Services to $50B EIS Federal Contract”

#threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Lifeline Data Centers also offer cybersecurity compliance services #threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

The Big Issue (a homeless magazine and social enterprise) has had a ransomware incident running for about a week, appears they haven’t disclosed it.

Pretty messed up target as homeless people sell the magazine, which makes next to no money in profit.

#threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Inc Ransom casually going after the Peru government - calls them a company. 😅

#threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

VNDirect Securities Corporation, a financial investment and assst management org, is rumoured to be dealing with a ransomware situation since yesterday: https://www.otofun.net/threads/bat-ngo-cong-ty-chung-khoan-vndirect-bi-danh-sap-he-thong.1897603/

#threatintel

RedPacketSecurity, to OSINT
GossiTheDog, (edited ) to random
@GossiTheDog@cyberplace.social avatar

Radiant Logistics have filed an 8-K with the SEC for a cybersecurity breach. Sounds like ransomware, recovery will take weeks. https://www.sec.gov/Archives/edgar/data/1171155/000095017024033954/rlgt-20240319.htm

This is not Randiant Logistics first 8-K - they had another one for ransomware in 2021 which resulted in data breach notifications in 2022.

#threatintel

GossiTheDog, (edited ) to random
@GossiTheDog@cyberplace.social avatar

Another Fujitsu security breach, unrelated to other one - they setup an open S3 bucket called fjbackup, including client data, email server backups, private AWS keys, LastPass vaults, plaintext credentials and more and left it exposed for over a year until security researchers pointed it out. This happened over a year ago, it looks like they didn't tell anybody.

(And no, I'm not a massive fan of the meme in that article).

https://www.thestack.technology/fujitsu-breach-cloud-buckets/

#threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

MarineMax filed an 8-K for a “cybersecurity incident” (their quotes 🤣) https://www.sec.gov/Archives/edgar/data/1057060/000095017024030041/hzo-20240310.htm

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Rhysida ransomware group just claimed MarineMax, who filed an 8-K last week for a “cybersecurity incident”. #threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

A few days ago, IT systems and services at Leicester City Council stopped working. Councillors were not told the cause. (Link: https://www.leicestermercury.co.uk/news/leicester-news/systems-outage-leicester-city-council-9151322)

At 7pm this Friday, they tweeted it is a "cyber incident". Services are still offline.

#threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Inc Ransomware group just claimed Leicester City Council, 3tb of data exfil. I’m told it is indeed Inc.

Inc are also trying to extort NHS Dumfries and Galloway.

Inc Ransomware group need to go on the National Cyber Force shitlist.

#ransomware #threatintel

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Huge US healthcare provider Change Healthcare has a “cybersecurity incident” going on for 15 hours and has shut down systems. https://techcrunch.com/2024/02/21/change-healthcare-cyberattack/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Ransomhub #ransomware group are claiming AlphV stole their money for Change Healthcare (this is believed to be true btw), and the operator has given them the data. So now they’re extorting Change Healthcare again. #threatintel

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • magazineikmin
  • ethstaker
  • InstantRegret
  • tacticalgear
  • rosin
  • love
  • Youngstown
  • slotface
  • ngwrru68w68
  • kavyap
  • cubers
  • DreamBathrooms
  • provamag3
  • mdbf
  • cisconetworking
  • GTA5RPClips
  • modclub
  • khanakhh
  • everett
  • Leos
  • osvaldo12
  • normalnudes
  • tester
  • Durango
  • anitta
  • JUstTest
  • All magazines