cyberresearch.bsky.social
@cyberresearch.bsky.social
Originally from Red Canary: Beyond the bomb: When adversaries bring their own virtual machine for persistence ( :-{ı▓ #threatintel #redcanary #cyberresearch
Beyond the bomb: When adversaries bring their own virtual machine for persistence
We peel back the layers on a threat involving an adversary who brought their own VM into an environment following aggressive spam bombing.
redcanary.com
December 10, 2025 at 11:40 AM
Originally from Unit 42: 01flip: Multi-Platform Ransomware Written in Rust ( :-{ı▓ #unit42 #threathunting #cyberresearch
01flip: Multi-Platform Ransomware Written in Rust
01flip is a new ransomware family fully written in Rust. Activity linked to 01flip points to alleged dark web data leaks. The post 01flip: Multi-Platform Ransomware Written in Rust appeared first on Unit 42.
unit42.paloaltonetworks.com
December 10, 2025 at 11:40 AM
Originally from TrustedSec: Holy Shuck! Weaponizing NTLM Hashes as a Wordlist ( :-{ı▓ #trustedsec #pentesting #cyberresearch
Holy Shuck! Weaponizing NTLM Hashes as a Wordlist
Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT teams recognize the risk, but longer passwords and password…
trustedsec.com
December 9, 2025 at 2:05 PM
Originally from PortSwigger: The Fragile Lock: Novel Bypasses For SAML Authentication ( :-{ı▓ #PortSwigger #Burpsuite #cyberresearch
The Fragile Lock: Novel Bypasses For SAML Authentication
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
portswigger.net
December 9, 2025 at 11:42 AM
Originally from Red Canary: Lost in the cloud: What Home Alone 2 teaches us about cloud security ( :-{ı▓ #threatintel #redcanary #cyberresearch
Lost in the cloud: What Home Alone 2 teaches us about cloud security
Home Alone 2 offers some some sage wisdom about cloud security. Here's what defenders can learn from Kevin McCallister.
redcanary.com
December 5, 2025 at 11:54 AM
Originally from DataDog: CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js ( :-{ı▓ #cloudsecurity #datadog #cyberresearch
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js
Learn more about the CVE-2025-55182 vulnerability affecting React Server Components and affecting Next.js.
securitylabs.datadoghq.com
December 5, 2025 at 11:53 AM
Originally from TrustedSec: What is a TrustedSec Program Maturity Assessment (PMA)? ( :-{ı▓ #trustedsec #pentesting #cyberresearch
What is a TrustedSec Program Maturity Assessment (PMA)?
The TrustedSec PMA is a tactical approach to evaluating the components, efficiency, and overall maturity of an organization’s Information Security program.Unlike a traditional compliance audit, the PMA is designed as a…
trustedsec.com
December 4, 2025 at 2:08 PM
Originally from Unit 42: The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen ( :-{ı▓ #unit42 #threathunting #cyberresearch
The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen
85% of daily work occurs in the browser. Unit 42 outlines key security controls and strategies to make sure yours is secure. The post The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen appeared first on Unit 42.
unit42.paloaltonetworks.com
December 3, 2025 at 12:00 PM
Originally from BHIS: Talkin' Bout [infosec] News 2025-12-01 #infosec #news ( :-{ı▓ #BlackHillsInfoSec #cybersecurity #cyberresearch
Talkin' Bout [infosec] News 2025-12-01 #infosec #news
Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. (https://blubrry.com/bhis/) We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat 🔗 Register for FREE webcasts, summits, and workshops - https://poweredbybhis.com 00:00 - PreShow Banter™ — WE need better superglue for Shecky. 03:39 - BHIS - Talkin' Bout [infosec] News 2025-12-01 04:28 - Story # 1: Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem) https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/ 12:29- Story # 2: Lawmakers Want to Ban VPNs—And They Have No Idea What They're Doing https://www.eff.org/deeplinks/2025/11/lawmakers-want-ban-vpns-and-they-have-no-idea-what-theyre-doing 22:04- Story # 3: Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update https://hackread.com/7-zip-vulnerability-public-exploit-manual-update/ 26:30 - Story # 4: 'Slop Evader' Lets You Surf the Web Like It’s 2022 https://www.404media.co/slop-evader-browser-extension-pre-generative-ai-search-filter/ 37:58- Story # 5: China’s Espionage in Europe is Deepening and More Sophisticated than Acknowledged, Expert Says https://www.kyivpost.com/post/64814 40:04- Story # 6: Apple Update Warning For All iPhone 17, 16 And 15 Users—Act Now https://www.forbes.com/sites/zakdoffman/2025/11/30/apple-update-warning-for-all-iphone-17-16-and-15-users-act-now/ 43:51- Story # 7: Meta is earning a fortune on a deluge of fraudulent ads, documents show https://www.reuters.com/investigations/meta-is-earning-fortune-deluge-fraudulent-ads-documents-show-2025-11-06/ 51:26- Story # 8: Meta had a 17-strike policy for sex trafficking, former safety leader claims https://www.theverge.com/news/827658/meta-17-strike-policy-sex-trafficking-testimony-lawsuit 53:55- Story # 9: Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison https://www.bleepingcomputer.com/news/security/man-behind-in-flight-evil-twin-wifi-attacks-gets-7-years-in-prison/ Brought to you by: 🔗 Black Hills Information Security https://www.blackhillsinfosec.com/ 🔗 Antisyphon Training https://www.antisyphontraining.com/ #livestream #infosec #news #BHIS #podcast #Cybersecurity #infosecnews
www.youtube.com
December 2, 2025 at 12:18 PM
Originally from Red Canary: Red Canary CFP tracker: December 2025 ( :-{ı▓ #threatintel #redcanary #cyberresearch
Red Canary CFP tracker: December 2025
Red Canary's monthly roundup of upcoming security conferences and calls for papers (CFP) submission deadlines
redcanary.com
December 2, 2025 at 12:03 PM
Originally from Unit 42: The Golden Scale: 'Tis the Season for Unwanted Gifts ( :-{ı▓ #unit42 #threathunting #cyberresearch
The Golden Scale: 'Tis the Season for Unwanted Gifts
Unit 42 shares further updates of cybercrime group Scattered LAPSUS$ Hunters. Secure your organization this holiday season. The post The Golden Scale: 'Tis the Season for Unwanted Gifts appeared first on Unit 42.
unit42.paloaltonetworks.com
November 26, 2025 at 12:22 PM