GitHub - NCSC-NL/citrix-2025
Contribute to NCSC-NL/citrix-2025 development by creating an account on GitHub.
The Dutch cybersecurity agency has released a script to detect webshells typically installed by attackers exploiting the CitrixBleed2 vulnerability in Citrix NetScaler appliances
github.com/NCSC-NL/citr...
27.07.2025 14:18 β π 24 π 11 π¬ 1 π 0
Confluence Exploit Leads to LockBit Ransomware
Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.β¦
It took just 3 hours:
RCE β Metasploit C2 β Anydesk for remote GUI-access β LockBit ransomware
Interestingly, we observed the threat actor using PDQ Deploy, a patch management tool.
Read the report here:
24.02.2025 15:25 β π 9 π 3 π¬ 1 π 0
1/ Among one of the techniques to detect infections as laid out in my presentation and additional blog post "N-IOCs to Rule Them All" [1], is tracking lookups to Dynamic DNS (DynDNS) domains and providers.
28.02.2025 07:27 β π 1 π 2 π¬ 1 π 0
Google SecOps Detection Rule Wiki
Comprehensive collection of Google SecOps YARA-L detection rules for security operations.
secops.wiki is live, it let's you search and filter community detection rules for Google SecOps (formerly known as Google Chronicle). Also has a Yara-L rule builder & some additional resources. Work in progress.
28.02.2025 21:43 β π 0 π 0 π¬ 0 π 0
Very much appreciate @techy.detectionengineering.net mentioning the 2 part series π
28.02.2025 21:25 β π 2 π 0 π¬ 0 π 0
How to create a Detection Engineering LabβββPart 1
Setting up a Lab lets you mimic real-world TTPs in a safe environment, making it easy to test, build and fine-tune detection logic.
Rather recently, I finally found time to start writing security-focused blogs. Iβll try sharing content regularly, letβs start with my two part series on creating a Detection engineering testing environment:
1. medium.com/@bastradamus...
2. medium.com/@bastradamus...
28.02.2025 21:14 β π 1 π 0 π¬ 1 π 0
π‘οΈ CTO CyberSecurity @ Computacenter π«π· β¨π Lecturer @ Ecole2600 π΄ββ οΈ
π£οΈ π«π· & π¬π§
π΄ββ οΈπ° Owner of https://ransomware.live
Ransomware.live tracks & monitors ransomware groups' victims and their activity. It was created by @JMousqueton.bsky.social, a security researcher. The website provides information on Ransomware groups, victims, negotiations, payment demands and much more.
Building https://wut.dev (a better AWS console). Cloud Security EM @Stripe. Ex-Founder @CloudSploit_, acquired by @AquaSecTeam. Ex-Adobe.
β Cybersecurity reporter
β
Newsletters at Risky Business
#infosec #cybersecurity
https://risky.biz
π€ Researcher in cyber security / π LGBTQIA+ / πΎ Gaming / πΊπ¦ Ukrain / π€ part-time bot
Interested in Infosec, languages, AI, general IT news, travel, retro computing, and ways of connecting that don't involve Meta or Elon Musk.
Author, composer, keyboards. Author of the THE HIDDEN FACE
https://www.thriftbooks.com/w/the-hidden-face_m-i-verras/39420061/#edition=67723160&idiq=59042592
https://bookshop.org/p/books/the-hidden-face-m-i-verras/219927e81d5af327?ean=9798822921320&next=t
@mttaggart@infosec.exchange. Displaced Philly boy. Threat hunter. Educator. Dad. General in the AI Resistance.
taggartinstitute.org
wtfbins.wtf
linktr.ee/mttaggart
Mirrors r/netsec, "a community-curated link aggregator of technical information security content." Unofficial. Operated by @tweedge.net, open source @ https://github.com/tweedge/xpost-reddit-to-fediverse
Cyber Security | Staff Security Engineer @Ripple (fintech/crypto) | Specialised in Detection & Response π¦ Ex @PwC
The largest collection of malware source code, samples, and papers on the internet.
Password: infected
(unofficial, this is a bot! Maintained by @yjb.bsky.social, the bot can't handle retweets, video, and maybe a few other things)
Staff Security Researcher @datadoghq | DEF CON/Black Hat USA main stage speaker | he/him | OSCP OSWE | I turned hacking AWS into a career | Tweets are my own | Created https://hackingthe.cloud
threat intelligence @google
writing & sharing on adversary tradecraft, malware, threat detection, ics/ot + cyber physical intel, and of course all things #yara
Principal Threat Analyst - Google Threat Intelligence Group
Head of Threat Informed Defense @Google
Cybercrime Specialist
Adjunct Professor at Johns Hopkins School of Advanced International Studies Alperovitch Institute
Meme Fiend
Aka βBLoveβ
Senior cyber threat intelligence leader. @CitizenLab.ca Research Fellow. Former federal agent. Fan of space, books, technology, and Mother NatureπͺοΈ. Personal account. πΊπΈ πΊπ¦ πΉπΌ #ThreatIntel
Storm chasing: https://bsky.app/profile/wxdox.com
Head of Investigations at InfoGuard AG - dfir.ch