The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
Analysis of a threat actor campaign targeting Solidity developers via three malicious VS Code extensions
π¨ The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions!
Deep dive analysis in this obfuscated campaign including (PowerShell & VBS scripts, PE malware, Malicious browser extensions even stegomalware)
Enjoy reading securitylabs.datadoghq.com/articles/mut...
21.05.2025 12:10 β π 3 π 2 π¬ 0 π 0
Leaving SF right in time before all the AI diarrhea. Thank you Hack The Bay and Pacific Hackers for having me, Iβll be back next year.
29.04.2025 03:19 β π 0 π 0 π¬ 0 π 0
Catch me speaking intelligence collection at scale today at HackTheBay #PHACK
28.04.2025 20:07 β π 0 π 0 π¬ 0 π 0
Diagram showing an overview of the OUTLAW infection chain.
Elastic Security Labs researchers report on Outlaw, a persistent yet unsophisticated auto-propagating Linux coinminer. Despite lacking stealth and advanced evasion techniques, it remains active and effective by leveraging simple but impactful tactics. www.elastic.co/security-lab...
02.04.2025 12:18 β π 2 π 1 π¬ 0 π 0
How to Enter the US With Your Digital Privacy Intact
Crossing into the United States has become increasingly dangerous for digital privacy. Here are a few steps you can take to minimize the risk of Customs and Border Patrol accessing your data.
Green card holders detained. A French researcher denied entry for anti-Trump messages. A new travel ban on 40+ countries coming.
Given all these encroachments on travelers' civil liberties, we've updated our guide to digital privacy while crossing US borders. www.wired.com/2017/02/guid...
24.03.2025 18:29 β π 994 π 508 π¬ 27 π 43
Graphic showing relations between Moonstone Sleet and other subgroups
JPCERT/CC's δ½γ
ζ¨ εδΊΊ (Hayato Sasaki) looks into the practical challenges of attribution in the case of Lazarusβs subgroup. blogs.jpcert.or.jp/en/2025/03/c...
25.03.2025 13:58 β π 2 π 1 π¬ 0 π 0
Both Wiz and Palo Alto Networks have found evidence that the compromise of the Changed-Files GitHub Action might have been a complex multi-tier supply chain attack targeting tools used by Coinbase developers
www.wiz.io/blog/new-git...
unit42.paloaltonetworks.com/github-actio...
23.03.2025 12:27 β π 23 π 5 π¬ 0 π 1
GitHub - Zouuup/landrun: Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel.
Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel. - Zouuup/landrun
AI and blockchain software expert Armin Ranjbar released Landrun, a lightweight, secure sandbox for running Linux processes
github.com/Zouuup/landrun
23.03.2025 14:00 β π 13 π 5 π¬ 1 π 0
β οΈπ§΅ RL researchers have found 2 malicious #VSCode extensions, "ahban.shiba" & "ahban.cychelloworld," that deliver #ransomware in development to it's users. #Dev #SoftwareSupplyChainSecurity
19.03.2025 13:46 β π 8 π 9 π¬ 1 π 0
Just over 600 GitHub repos were impacted by Changed-Files supply chain attack
www.endorlabs.com/learn/blast-...
20.03.2025 00:04 β π 7 π 3 π¬ 0 π 1
Podcast: risky.biz/RBNEWS400/ (400, woohoo! π)
Newsletter: risky.biz/risky-bullet...
-China says Taiwan's military is behind PoisonIvy APT
-Google buys Wiz for $32 billion
-11 APTs abuse a Windows zero-day
-Judge tells CISA to reinstate fired workers
-Supply-chain attack hits car dealership sites
19.03.2025 09:23 β π 21 π 9 π¬ 3 π 0
EFF Border Search Pocket Guide
border-pocket-guide-2.pdf
If you're critical of the US government and you are planning to cross the US border any time soon, today is a good day to review EFF's border search pocket guide: www.eff.org/document/eff...
19.03.2025 19:46 β π 2384 π 1466 π¬ 68 π 74
-43% of WP vulns last year didn't require authentication to exploit
-96% of WP vulns impacted plugins
-22 new WP vulns published daily
-over 500k WP websites hacked last year
patchstack.com/whitepaper/s...
17.03.2025 23:43 β π 12 π 10 π¬ 3 π 1
An inside look at NSA (Equation Group) TTPs from Chinaβs lense
Xintra founder Lina Lau has published a report that untangles and puts more clarity on how Chinese authorities claim the Equation Group (US NSA) hacked the Xi'an Northwestern Polytechnical University
www.inversecos.com/2025/02/an-i...
19.02.2025 21:25 β π 12 π 8 π¬ 0 π 1
Sun Security Con
SunSecCon
Agenda for SunSecCon is up www.sunseccon.org
05.02.2025 22:39 β π 0 π 0 π¬ 0 π 0
Elastic Security Labs' Remco Sprooten & Ruben Groenewoud analyse PUMAKIT, a loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with command-and-control servers. www.elastic.co/security-lab...
20.01.2025 10:31 β π 0 π 1 π¬ 0 π 0
Link? If you can.
08.01.2025 02:10 β π 0 π 0 π¬ 1 π 0
Overview of the attack flow
Overview of how a large number of credentials were leaked
Clusters of fake GitHub profiles
Phishing e-mail
New research: We've been monitoring a threat actor publishing dozens of trojanized GitHub repositories targeting threat actors, leaking hundreds of thousands of credentials along the way
securitylabs.datadoghq.com/articles/mut...
16.12.2024 13:08 β π 22 π 13 π¬ 0 π 0
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages | Datadog Security Labs
Release of Supply-Chain Firewall, an open source tool for preventing the installation of malicious PyPI and npm packages
We are happy to introduce our latest tool "Supply Chain Firewall" π by @ikretz.bsky.social
The tool detects & prevents installation of malicious packages in local development environment.
Read more
securitylabs.datadoghq.com/articles/int...
And give it a try github.com/DataDog/supp...
06.12.2024 12:19 β π 11 π 7 π¬ 0 π 0
Mistakes happen to everyone!
β€οΈ @binaryninja.bsky.social
06.12.2024 03:57 β π 0 π 0 π¬ 0 π 0
Exclusive: The backdoor inserted in v1.95.7 adds an "addToQueue" function which exfiltrates the private key through seemingly-legitimate CloudFlare headers.
Calls to this function are then inserted in various places that (legitimately) access the private key.
03.12.2024 23:47 β π 50 π 32 π¬ 3 π 2
Supply Chain Attack Detected in @solana/web3.js Library - So...
A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library.
π¨ A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular #Solana web3.js library. The injected code captures private keys and transmits them to a hardcoded address. This is a developing story. socket.dev/blog/supply-... #crypto #cybersecurity
03.12.2024 22:10 β π 14 π 8 π¬ 1 π 3
Sun Security Con
SunSecCon
PHACK, some friends and I are creating a Security track in the famous SCALE in LA (Pasadena). CFP is open and early birds tickets are for sale!
If your in LA come check us out! www.sunseccon.org www.phack.org www.socallinuxexpo.org/scale/22x
@socallinuxexpo.bsky.social #infosec
02.12.2024 17:53 β π 1 π 0 π¬ 0 π 0
Sites that donβt let you copy/paste in the password field.
Let me try to type this 24 char (because the site doesnβt allow longer) randomly generated string.
Fail.
Reset password.
Letβs trying againβ¦
27.11.2024 22:01 β π 1 π 0 π¬ 0 π 0
MUT-8694: An NPM and PyPI Malicious Campaign Targeting Windows Users | Datadog Security Labs
This post includes an analysis of an infostealer supply chain attack targeting Windows users
Great analysis by my colleagues on a Windows stealer that's being distributed through a large number of malicious npm and PyPI packages: securitylabs.datadoghq.com/articles/mut...
Ends up dropping an infostealer (Blank Grabber/Skuld Stealer) which exfiltrates browser cookies (amongst others)
22.11.2024 23:03 β π 10 π 2 π¬ 0 π 1
Want to keep up to date with Datadogβs Cloud Security Research? Weβve got a starter pack for that. All of our researchers in one feed.
go.bsky.app/8XpcFm5
18.11.2024 13:21 β π 38 π 15 π¬ 0 π 3
Cyber Threat Intelligence at Microsoft | Former Yahoo & Secret Squirrel | Thoughts my own
https://strikeready.com/blog.html
Download live malware samples mentioned here: https://github.com/StrikeReady-Inc/samples
If you prefer marketing (our product is great!) subscribe to our main page @strikeready.com
Threat Intelligence Team Leader @ WΓΌrth Group, CPENT/CEH/CND/CSA/ECSA, owner of SATAYO CTI platform & deepdarkCTI project - member of
@Curatedintel
We build software for cyber #threatintelligence analysts.
https://www.dogesec.com/
π» Senior Staff Researcher @Lookout. δΈζε¦δΉ . China-Focused Threat Intelligence. Malware, Geopolitics, Human Rights. Opinions my own.
Principal Adversary Hunter @dragosinc, Army Veteran,
Cocktail Scientist, APT Researcher | #FSD
https://infosec.exchange/web/@DrunkBinary
https://twitter.com/DrunkBinary
China-Focused Consultant @SentinelOne | Nonresident Fellow @ACGlobalChina | Adjunct @Georgetown | Unprofessional Cook | β€οΈππ
https://linktr.ee/dakotaindc
Independent investigative journalist. Covers cybercrime, security, privacy. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter [β¦]
[bridged from https://infosec.exchange/@briankrebs on the fediverse by https://fed.brid.gy/ ]
Writer. Contact me here: https://raphae.li
Open source privacy and security focused mobile OS with Android app compatibility.
https://grapheneos.org/
A programming language empowering everyone to build reliable and efficient software.
Website: https://rust-lang.org/
Blog: https://blog.rust-lang.org/
Mastodon: https://social.rust-lang.org/@rust
Breaking news in Russia, investigative reports, interviews, and opinions. In English. Youβre welcome. https://meduza.io/en
Russia watcher supreme. @meduza.io English-language managing editor. Ugly American based in Portland, Oregon. Signal: @KevinRothrock.01 / Find all my junk here: https://linktr.ee/kevinrothrock
Intego is the leader in Apple security, protecting macOS and Windows users from malware and cybersecurity threats since 1997.
π° Headlines: https://blog.intego.com
π§ Podcast: https://podcast.intego.com
π§ Newsletter: https://blog.intego.com/newsletter
Yet an other Ransomware gang tracker - Opensource project: https://github.com/RansomLook/RansomLook - Website: https://www.ransomlook.io
Ransomware.live tracks & monitors ransomware groups' victims and their activity. It was created by @JMousqueton.bsky.social, a security researcher. The website provides information on Ransomware groups, victims, negotiations, payment demands and much more.
Security @ MORSE, v0.1.0 security tools on GitHub π³οΈβπ
@novafacing@haunted.computer
Reverse engineering dragon VTuber ππ
I stream malware analysis and RE on Twitch!
https://vgen.co/c/cyberkaida/cyberkaida-2-0
Twitch - https://twitch.tv/cyberkaida
GitHub - https://github.com/cyberkaida
Author of the worldβs most popular Reverse Engineering Tutorial