vulnu.com <- sign up for my weekly cybersecurity newsletter
He played along so we got a look inside their tactic here:
He played along so we got a look inside their tactic here:
Keys. Secrets. Deployment. All that jazz.
None of the tools help, if anything they make it super easy to do wrong.
Keys. Secrets. Deployment. All that jazz.
None of the tools help, if anything they make it super easy to do wrong.
@haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold”
Just great life advice in general. Will remember this quote forever.
Oh and @hdm.io and @andrewmorr.is are cool too.
@haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold”
Just great life advice in general. Will remember this quote forever.
Oh and @hdm.io and @andrewmorr.is are cool too.
They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public
They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public
Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
And now FileFix on top of it...
And now FileFix on top of it...
Artem Baranov did the dang math.
He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.
Artem Baranov did the dang math.
He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.
If you or your devs run macOS, keep scrolling.👇
If you or your devs run macOS, keep scrolling.👇
They also outline how they're using AI to level up. Here's some highlights:
They also outline how they're using AI to level up. Here's some highlights:
Whatever they want.
Then they do it with zero click 0days silently. Wild.
youtu.be/zqY2A112bAQ
Whatever they want.
Then they do it with zero click 0days silently. Wild.
youtu.be/zqY2A112bAQ
Safe to assume my routine is absolutely f’d.
I keep saying I’ll figure it out after I dig out of my massive backlog…
Safe to assume my routine is absolutely f’d.
I keep saying I’ll figure it out after I dig out of my massive backlog…
It allegedly contains code to extract data from the NLRB's case management system.
It allegedly contains code to extract data from the NLRB's case management system.
Critical systems offline since June 5. Significant supply chain disruptions ongoing.
Heres what we know. 🧵
Critical systems offline since June 5. Significant supply chain disruptions ongoing.
Heres what we know. 🧵
A) SSO with mandatory MFA (yubikey preferred)
B) Device health check on login. Don't let unpatched OS or browser even login.
Do this and you're in the 1%
A) SSO with mandatory MFA (yubikey preferred)
B) Device health check on login. Don't let unpatched OS or browser even login.
Do this and you're in the 1%