x0rz's Avatar

x0rz

@x0rz.bsky.social

Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon ๐Ÿฅ“

1,440 Followers  |  211 Following  |  23 Posts  |  Joined: 18.11.2024  |  2.3205

Latest posts by x0rz.bsky.social on Bluesky

Post image

1/ Chinaโ€™s cyber capabilities didnโ€™t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped Chinaโ€™s cyber ecosystem, moving from online forums to industry leaders (link in thread).

21.07.2025 08:11 โ€” ๐Ÿ‘ 13    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Telegram, the FSB, and the Man in the Middle The technical infrastructure that underpins Telegram is controlled by a man whose companies have collaborated with Russian intelligence services. An investigation by IStories

2/2 Russia at will. Although he claims to be apolitical, he denies responsibility for the crimes that are enabled by his platform. He loves to dish out advice to Western politicians, but hates paying taxes and prefers to live in a dictatorship. In short, he embodies the stereotypical Russian.

20.06.2025 04:51 โ€” ๐Ÿ‘ 17    ๐Ÿ” 6    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) of launching "advanced" cyberattacks during the Asian Winter Games in February, targeting essential industries.

Following long practice of US gov indicting Chinese/Russian state hackers for breaching US systems, China has named and issued warrants for 3 NSA workers it says were behind hacks of China systems during Asian Winter Games. Also says University of California and Virginia Tech participated in attacks

15.04.2025 12:53 โ€” ๐Ÿ‘ 19    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Preview
You will always remember this as the day you finally caught FamousSparrow ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the groupโ€™s signature backdoor, SparrowDoor.

ESET disputes Microsoft's classification of the FamousSparrow APT as part of the Salt Typhoon group.

ESET believes the two APTs may be using a shared digital quartermaster (malware and tools developer).

www.welivesecurity.com/en/eset-rese...

27.03.2025 11:46 โ€” ๐Ÿ‘ 6    ๐Ÿ” 5    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

When the answer to "are you cheating on me?" is "who told you that?" and not "no"

21.03.2025 17:04 โ€” ๐Ÿ‘ 2220    ๐Ÿ” 396    ๐Ÿ’ฌ 67    ๐Ÿ“Œ 9
Post image

@hpiedcoq.bsky.social ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‘€

12.03.2025 20:59 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Tweet by Graham Stuart, Tory MP @grahamstuart:
We have to consider the possibility that President Trump is a Russian asset.
If so, Trump's acquisition is the crowning achievement of Putin's FSB career - and Europe is on its own.

Tweet by Graham Stuart, Tory MP @grahamstuart: We have to consider the possibility that President Trump is a Russian asset. If so, Trump's acquisition is the crowning achievement of Putin's FSB career - and Europe is on its own.

Extraordinary comment from Tory MP Graham Stuart:

โ€œWe have to consider the possibility that President Trump is a Russian asset.
If so, Trump's acquisition is the crowning achievement of Putin's FSB career.โ€

(Narrator: Itโ€™s extraordinary because our own gd government didnโ€™t say it first.)

04.03.2025 14:53 โ€” ๐Ÿ‘ 2674    ๐Ÿ” 985    ๐Ÿ’ฌ 127    ๐Ÿ“Œ 72

It shouldnโ€™t take a panic over Chinese AI to remind people that most companies in the business set the terms for how they use your private data.

And when you use their AI apps, youโ€™re doing work for them, not the other way round.

28.01.2025 04:25 โ€” ๐Ÿ‘ 77    ๐Ÿ” 19    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0

being able to walk away from the internet, even via laptops was nice

28.01.2025 04:19 โ€” ๐Ÿ‘ 8    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image Post image

Ah yes. We're at the 'pUt It On ThE bLoCkChAiN' stage.

25.01.2025 20:13 โ€” ๐Ÿ‘ 296    ๐Ÿ” 35    ๐Ÿ’ฌ 27    ๐Ÿ“Œ 13

It's like Ivanti. Every month is zero-day awareness month.

14.01.2025 21:35 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I can never fully know if I already read this "Fortinet 0day in the wild" article 3 weeks ago or if itโ€™s new. Ha, never mind! Itโ€™s new ๐Ÿฅฒ

14.01.2025 21:14 โ€” ๐Ÿ‘ 17    ๐Ÿ” 8    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
Preview
StravaLeaksย : des dates de patrouilles des sous-marins nuclรฉaires franรงais dรฉvoilรฉes par lโ€™imprudence de membres dโ€™รฉquipage Des membres dโ€™รฉquipage des sous-marins franรงais dotรฉs de lโ€™arme atomique partagent publiquement leurs activitรฉs sportives par le biais de lโ€™application Strava, divulguant ainsi, par inadvertance, des ...

LeMonde investigation finds that members of a French nuclear-armed submarine crew inadvertently shared sensitive information about the patrol schedule of the ship via the Strava workout app: www.lemonde.fr/videos/artic...

13.01.2025 18:01 โ€” ๐Ÿ‘ 26    ๐Ÿ” 17    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 5

We're witnessing the evolution of ransomware.

Yesterday someone informed us of the existence of the new TTP of AWS S3 extortion. More specifically, Threat Actors abusing the Amazon Key Management Service (KMS) to encrypt company AWS buckets (or any cloud provider).

08.01.2025 02:07 โ€” ๐Ÿ‘ 91    ๐Ÿ” 31    ๐Ÿ’ฌ 8    ๐Ÿ“Œ 4
Preview
How Chinese Hackers Graduated From Clumsy Corporate Thieves to Military Weapons Massive โ€œTyphoonโ€ cyberattacks on U.S. infrastructure and telecoms sought to lay the groundwork for potential conflict with Beijing, as intruders gathered data and got in position to impede response a...

incredibly detailed piece on Salt and Volt Typhoon (apparently named as if they're brothers)

"a cybersecurity vendor notices the activity and flags it to the port's cybersecurity chief, who examines it and decides it's a false alarm. He heads to lunch at Whataburger."

www.wsj.com/tech/cyberse...

05.01.2025 20:16 โ€” ๐Ÿ‘ 27    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Court order text. Link to follow

Court order text. Link to follow

Court order text. Link to follow

Court order text. Link to follow

Court order text. Link to follow

Court order text. Link to follow

Court order text. Link to follow

Court order text. Link to follow

BREAKING: court finds NSO Group liable for #Pegasus hacking of #WhatsApp users.

Big win for spyware victims.

Big loss for NSO.

Bad time to be a spyware company.

Landmark case. Huge implications. 1/ ๐Ÿงต

21.12.2024 01:37 โ€” ๐Ÿ‘ 659    ๐Ÿ” 322    ๐Ÿ’ฌ 12    ๐Ÿ“Œ 32
Post image

This aspect of restructuring authority between NSA and USCYBERCOM in light of a dual-hat split is one I hadnโ€™t considered before:

19.12.2024 06:49 โ€” ๐Ÿ‘ 9    ๐Ÿ” 5    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I donโ€™t normally get worked up about the naming threat actors thing.

But the Volt & Salt Typhoon is a disaster as itโ€™s so hard for non-specialists to tell them apart:

- Salt is Snowden style espionage by China against US

- Volt is a direct ๐Ÿ‡จ๐Ÿ‡ณ military threat to degrade western infrastructure 1/2

12.12.2024 20:47 โ€” ๐Ÿ‘ 133    ๐Ÿ” 39    ๐Ÿ’ฌ 7    ๐Ÿ“Œ 6

The US Treasury has sanctioned Sichuan Silence, the Chinese company that developed exploits against Sophos firewalls

home.treasury.gov/news/press-r...

10.12.2024 16:45 โ€” ๐Ÿ‘ 18    ๐Ÿ” 10    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

A simple experiment you can do is buy a server, set up a website with nothing on it, then look at the access logs. All day, every day, there are random systems just blasting vulnerabilities at every device on the internet. Analysts call it "background noise", executives call it "cyber attacks".

06.12.2024 02:15 โ€” ๐Ÿ‘ 6846    ๐Ÿ” 757    ๐Ÿ’ฌ 160    ๐Ÿ“Œ 48

Free backup service!

30.11.2024 11:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Why the f*ck does my Windows trying to reach browser.events.data.msn[.]cn

30.11.2024 09:45 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Top senator calls Salt Typhoon โ€˜worst telecom hack in our nationโ€™s historyโ€™ The severity of the Chinese breach highlights the need for more telecommunications regulation, lawmakers say.

"The networks are still compromised, and booting the hackers out could involve physically replacing โ€œliterally thousands and thousands and thousands of pieces of equipment across the country,โ€ specifically outdated routers and switches" ๐Ÿ•ต๏ธโ€โ™‚๏ธ

29.11.2024 18:35 โ€” ๐Ÿ‘ 45    ๐Ÿ” 37    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 3

More people should use QubesOS

28.11.2024 19:22 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
Preview
BND-Chef warnt vor Putins konventioneller und hybrider Kriegsfรผhrung Der Kreml wird versuchen, die Bundestagswahl zu beeinflussen. Davon geht BND-Chef Bruno Kahl aus. Und seine Agenten kommen zu dem Schluss: Russland wird wahrscheinlich Ende der Zwanzigerjahre in der L...

Seems kind of important that Bruno Kahl, head of german foreign intelligence, said that it's his assessment that Russia by the end of this decade will be in a position to initiate an attack against NATO

www.spiegel.de/politik/bnd-...

27.11.2024 21:25 โ€” ๐Ÿ‘ 34    ๐Ÿ” 15    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 0

Itโ€™s a matter of time, Chinese media/bots will eventually target this platform as well.

27.11.2024 07:00 โ€” ๐Ÿ‘ 12    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

Itโ€™s all about the message. Itโ€™s more convincing this way.

27.11.2024 06:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

CTI is the cause of my brainrot but I really cooked on this #salttyphoon #telecomhack

26.11.2024 22:18 โ€” ๐Ÿ‘ 51    ๐Ÿ” 18    ๐Ÿ’ฌ 5    ๐Ÿ“Œ 3
Preview
RomCom exploits Firefox and Windows zero days in the wild ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit.

Firefox, Thunderbird, Tor Browser RCE: www.welivesecurity.c...

27.11.2024 05:31 โ€” ๐Ÿ‘ 8    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@x0rz is following 20 prominent accounts