's Avatar

@mesiagh.bsky.social

54 Followers  |  106 Following  |  9 Posts  |  Joined: 13.11.2024  |  2.2038

Latest posts by mesiagh.bsky.social on Bluesky

How SnortML Uses Machine Learning to Stop Zero-Day Attacks
YouTube video by Cisco Talos Intelligence Group How SnortML Uses Machine Learning to Stop Zero-Day Attacks

SnortML, Cisco’s machine learning-powered detection engine, identifies patterns of exploit attempts β€” even those it hasn't seen before β€” without relying on static rules. Stop by the Cisco booth at Black Hat to learn more: www.youtube.com/watch?v=jkxn...

24.07.2025 14:34 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Jaeson, a qhite man with a moustache and beard, smiles at the camera.

Jaeson, a qhite man with a moustache and beard, smiles at the camera.

Don’t miss Part 2 of last week's TTP! Talos' Jaeson Schultz breaks down how attackers are using large language models (LLMs) to usher in the next phase of cyber threats by manipulating the data these models rely on: http://cs.co/633204Cuoo

16.07.2025 18:09 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Jaeson, a white man with a moustache and beard, smiles at the camera. The "TTP" logo is on a black background on the right half of the screen.

Jaeson, a white man with a moustache and beard, smiles at the camera. The "TTP" logo is on a black background on the right half of the screen.

Don't miss the newest TTP! Jaeson Schultz joins Hazel to explore the wild world of cybercriminals scamming each other with fake AI tools, inventing new ways to jailbreak large language models, and so much more: http://cs.co/633204IoEG

11.07.2025 15:15 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

UNC6040 used voice-phishing to steal data from companies' Salesforce systems

cloud.google.com/blog/topics/...

04.06.2025 17:51 β€” πŸ‘ 6    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

While important to have, MFA isn’t an invincible shield. Ready to see how cybercriminals are bypassing MFA β€” and what it means for your security? Read our newest blog: blog.talosintelligence.com/state-of-the...

01.05.2025 13:30 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

In 2024, the education sector faced the brunt of ransomware attacks. πŸ“š Explore our latest summary for more insights, including the methods ransomware actors are using to slip past defenses with minimal noise: blog.talosintelligence.com/year-in-revi...

15.04.2025 17:49 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Banner reading: "Threat Source newsletter: All the security news you need to know - hitting your inbox every Thursday."

Banner reading: "Threat Source newsletter: All the security news you need to know - hitting your inbox every Thursday."

In this week's Threat Source newsletter, Martin shares strategies to strengthen defenses against evolving email lures and frequently targeted vulnerabilities, even when budgets are tight. Read it here: http://cs.co/63325FLEAf

10.04.2025 18:05 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

Part 2 of the latest Talos Threat Perspective is out now! This year's report authors dive into most prolific ransomware groups and what is contributing to their success. Watch the full video here: youtu.be/YFwMSxYd-Kk?...

04.04.2025 14:26 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

Cisco Talos’ 2024 Year in Review is available now! With visibility into more than 886 billion security events per day, the report features our key insights. Read the full report here: http://cs.co/63320FzuMG

31.03.2025 12:05 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1
Video thumbnail

πŸ’‘phisherman: A real fake social engineering app

Link: github.com/jfmaes/phish...

12.03.2025 17:30 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

2025-02-25 (Tuesday): #VenomRAT from #malspam uses zip attachment containing a VHD file containing a VBS file. Calls Pastebin link for C2 server information. Details at github.com/malware-traf...

25.02.2025 20:22 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Nothing to see here. Just casually dropping a comprehensive list of banned books

docs.house.gov/meetings/GO/...

24.02.2025 14:04 β€” πŸ‘ 962    πŸ” 349    πŸ’¬ 67    πŸ“Œ 42

The Witcher 3: Wild Hunt

24.02.2025 16:51 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cisco Talos Threat Source Newsletter logo

Cisco Talos Threat Source Newsletter logo

This week's newsletter is fresh in your inbox. William dives into security and efficiency, and the latest Talos research: http://cs.co/63329IhpJ3

20.02.2025 19:18 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

2025-02-05 (Wednesday): #ClearFake / #ClickFix style fake CAPTCHA leads to possible #Vidar.

Vidar C2 using eteherealpath[.]top behind Cloudflare.

Details at github.com/malware-traf...

06.02.2025 01:03 β€” πŸ‘ 6    πŸ” 7    πŸ’¬ 1    πŸ“Œ 0
Screenshot of my blog post with analysis of the XLoader infection.

Screenshot of my blog post with analysis of the XLoader infection.

XLoader distributed as a RAR attachment to an email.  The malware is a Windows executable file within that RAR archive.

XLoader distributed as a RAR attachment to an email. The malware is a Windows executable file within that RAR archive.

Traffic from the XLoader infection filtered in Wireshark.

Traffic from the XLoader infection filtered in Wireshark.

XLoader persistent on the infected Windows host through a Windows registry update.

XLoader persistent on the infected Windows host through a Windows registry update.

2025-01-30 (Thursday): #XLoader infection. Unlike my previous XLoader infections, this one didn't run in my VM, so I used a physical host. A #pcap of the infection traffic, the associated malware samples, and more info is available at malware-traffic-analysis.net/2025/01/30/i...

30.01.2025 18:32 β€” πŸ‘ 10    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

2025-01-28 (Tues): A case of web injects--malicious script injected in pages of legit websites. In this example, a site has two instances of injected script, #KongTuke and #SocGholish. A #pcap of the resulting infection, malware samples & more info at www.malware-traffic-analysis.net/2025/01/28/i...

29.01.2025 05:40 β€” πŸ‘ 8    πŸ” 6    πŸ’¬ 1    πŸ“Œ 0
Preview
New TorNet backdoor seen in widespread campaign Cisco Talos discovered an ongoing malicious campaign operated by a financially motivated threat actor targeting users, predominantly in Poland and Germany.

We've discovered an ongoing malicious campaign operated by a financially motivated threat actor targeting users, predominantly in Poland and Germany. Read the blog on the new TorNet backdoor here:
blog.talosintelligence.com/new-tornet-b...

28.01.2025 19:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Configuration_extractors/LummaC2 at main Β· RussianPanda95/Configuration_extractors Configuration Extractors for Malware. Contribute to RussianPanda95/Configuration_extractors development by creating an account on GitHub.

Recent changes in #LummaStealer - using ChaCha20 for C2 encryption, the new config extractor in C/C++. Courtesy of @russianpanda.bsky.social
github.com/RussianPanda...

27.01.2025 19:38 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Seasoning email threats with hidden text salting Hidden text salting is a simple yet effective technique for bypassing email parsers, confusing spam filters, and evading detection engines that rely on keywords. Cisco Talos has observed an increase i...

We observed an increase in the number of email threats leveraging hidden text salting, also known as "poisoning", in the second half of 2024. Read our latest blog to learn more: blog.talosintelligence.com/seasoning-em...

24.01.2025 15:43 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Machine Learning Security -- Sam Bowne

I'm teaching Machine Learning Security as an online class, free for anyone to attend (as all my classes are):
https://samsclass.info/ML/ML_S25.shtml

20.01.2025 20:45 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
3 takeaways from red teaming 100 generative AI products | Microsoft Security Blog The growing sophistication of AI systems and Microsoft’s increasing investment in AI have made red teaming more important than ever. Learn more.

The Microsoft AI Red Team recently released both a blog and an in-depth whitepaper after red teaming 100+ different GenAI products.

Read the blog here - microsoft.com/en-us/securi...

And download the whitepaper here - airedteamwhitepapers.blob.core.windows.net/lessonswhite...

14.01.2025 19:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I wish more managers hear that.

04.12.2024 16:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Deepfake YouTube Ads of Celebrities Promise to Get You β€˜Rock Hard’ Deepfakes of Arnold Schwarzenegger, Sylvester Stallone, Mike Tyson, and Terry Crews are selling erectile dysfunction supplements on YouTube.

New: YouTube is running hundreds of ads featuring deepfaked celebrities like Arnold Schwarzenegger, Sylvester Stallone, and Mike Tyson promising to get customers 'rock hard' (they're selling sketchy erectile dysfunction treatments)

www.404media.co/deepfake-you...

04.12.2024 14:17 β€” πŸ‘ 59    πŸ” 15    πŸ’¬ 3    πŸ“Œ 7

Sorry to hear that, injury?

02.12.2024 23:26 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday All the deals for InfoSec related software/tools this Black Friday - 0x90n/InfoSec-Black-Friday

Cyber Blackfriday tips is already ongoing on GitHub (via Thomas Roccia, fr0gger_)

github.com/0x90n/InfoSe...

20.11.2024 08:32 β€” πŸ‘ 9    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Malicious QR Codes: How big of a problem is it, really? QR codes are disproportionately effective at bypassing most anti-spam filters. Talos discovered two effective methods for defanging malicious QR codes, a necessary step to make them safe for consumpti...

QR codes are disproportionately effective at bypassing most anti-spam filters. We discovered two effective methods for defanging malicious QR codes, a necessary step to make them safe for consumption. Find out how prevalent this attack is in our blog #QR #phishing cs.co/6012sxBa4

20.11.2024 19:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
New PXA Stealer targets government and education sectors for sensitive information Cisco Talos discovered a new information stealing campaign operated by a Vietnamese-speaking threat actor targeting government and education entities in Europe and Asia.

We've recently published a blog on a new information stealing campaign, PXA Stealer, targeting government and education sectors. #malware #stealer #cybersecurity Read the blog here: cs.co/6019sqbWX

19.11.2024 19:39 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@mesiagh is following 19 prominent accounts