International Maritime Organization appears to have recovered swiftly
Novel attacker uses Demonbot variant of Mirai malware to attack port 60001
La méthode n’est pas nouvelle, mais nous observons une recrudescence de TPE et PME victimes de cette arnaque, qui peut leur faire perdre plusieurs dizaines de milliers d’euros !
L’objet de cet article n’est pas de stigmatiser les victimes, mais d’illustrer [...] Lire la suite
Charges brought after illegal takeover of NFL and NBA players’ social media accounts
US Treasury issues advisory on potential sanctions risks for facilitating ransomware payments
Techniques to enumerate the account ID associated with an AWS access key.
Former Australian Prime Minister Talks ICS, Huawei and awareness
ESET claims group has remained undetected since 2011
P1: Critical - Discovering and Foiling a Threat Actor Disclaimers, Credits: Thank you to everyone who helped validate any part of the project. It took a lot of work to figure out the extent of who was/is affected. I appreciate all of the help that we have received, with a special thank you to those...
Calls for government regulation and “right to disconnect”
Report claims little progress has been made as vulnerabilities mount
This was also presented at BSides Singapore 2020. The slides are here and YouTube link is here.
The origins of the Shadowbunny A few years ago, around 2016, I went on a relaxing two weeklong vacation. It was great to disconnect from work. I traveled to Austria, enjoying hiking in the mountains, and...
Regular conversations are needed for a company-wide approach to security
German arm of Swedish fashion giant given massive fine as company announces closure of 250 stores
This year one of my goals was to learn about machine learning and artificial intelligence.
I wrote about my journey before - including what classes I took and books I read, the models and systems I built and operationalized, threat modeling it to learn about practical attacks and defenses. My goal i...
FBI warns online journals may be used to spread disinformation about the US election
US imprisons cyber-thief who stole millions of user records from Dropbox and LinkedIn
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts.
Overview: How Husky AI was built, threat modeled and operationalized Attacks: The attacks I want to investigate, learn about, and try out Mitigations: Ways to preve...
Cost, storage, user behavior and migration time cited as reasons to not do passwordless authentication
The ISF details six characteristics CISOs must exhibit in today's world