Talk about helping to build a better Internet ->Β har-sanitizer.pages.dev
Thanks @cloudflare.social π₯
@shellcromancer.io.bsky.social
Building something new! Used to be a security engineer @ Brex & Cloudflare. Hobbyist reverse engineer of π and π§ thingsβ¦ dogs are better than humans.
Talk about helping to build a better Internet ->Β har-sanitizer.pages.dev
Thanks @cloudflare.social π₯
Customer: Are we safe?
Okta: Give me a HAR and weβll let you know when we find out from other customers.
Helpful context: www.beyondtrust.com/blog/entry/o...
Much less helpful context response: sec.okta.com/harfiles
I really believe that if your infrastructure canβt survive a user clicking a link, you are doomed. Iβm the director of cybersecurity at NSA and you can definitely craft an email link I will clickβ¦
r.mtdv.me/TrustThis
My team is hiring for a new member of our D&R team based in π¨π¦ www.brex.com/careers/6952...
I'm very biased but I think we're a great team in the D&R space across a production & corporate environment. Big fans of open sourcing projects, managing components via source control where possible
Some new π₯ reporting on everyones least favorite threat actor by Permiso: 0ktapus, Scattered Spider, UNC3944, and STORM-0875 and now LUCR-3 π
permiso.io/blog/lucr-3-...
All these security vendors are trying to define XDR (eXtended Detection & Response) but Apple has been using XDR screens for years and improving it in iPhone 15 π§
12.09.2023 17:43 β π 1 π 0 π¬ 0 π 0Friday afternoons are a great time for releasing and deploying new software! π₯π
Substation v0.9.2 is here: github.com/brexhq/substation/dβ¦
In addition to a new bitmath inspector I wrote, this release brings some QoL improvements, let us know if you find use-cases for these additions. XDR onwards!
π₯ an at cost registrar, with WebAuthN support adding more domains to help migrate off of Google/Squarespace π
01.08.2023 23:13 β π 1 π 0 π¬ 0 π 0One of my biggest pet peeves within infosec is how people still refer to "knowing your network". In the era of cloud networks that really aren't yours, SaaS networks that definitely aren't yours... let's rebrand to "knowing your environment" which consists of: endpoints, SaaS, servers, and cloud.
29.07.2023 03:01 β π 0 π 0 π¬ 0 π 0Great reporting @philofishal.bsky.social on the many variants π https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/
25.07.2023 22:28 β π 2 π 1 π¬ 0 π 0More macOS stealers π
A simple detection for command lines w/ βsecurity find-generic-password <chromium>β catches most π
https://iamdeadlyz.gitbook.io/malware-research/july-2023/fake-blockchain-games-deliver-redline-stealer-and-realst-stealer-a-new-macos-infostealer-malware#realst-stealer-macos
Iβm clearly a fan of them getting caught because it gives us a glimpse of some of the only nation state macOS targeting with a pretty high cadence recently (and weβll Iβm a defender so suck it hackers). Are other macOS attacks undetected or is π°π΅ the only targeting entity?
24.07.2023 13:09 β π 0 π 0 π¬ 0 π 0π°π΅ operators seem brutally effective at getting to target environments directly (crypto scams, backdoored apps) and now more supply chain targeting (3CX, and JumpCloud)β¦ do they not care about stealth if they accomplish their goals? π€
24.07.2023 13:07 β π 0 π 0 π¬ 1 π 0Latest hacking from the DPRK with macOS payload details π Great reporting from the Mandiant team!
https://www.mandiant.com/resources/blog/north-korea-supply-chain
Not sure how a UPXβd executable got a function named βsetupsomethingβ through their agile code review π€£
13.07.2023 15:03 β π 2 π 0 π¬ 1 π 0I had a great time in 2020 at OBTS v3.0 and hope to make the next one π€
13.07.2023 14:27 β π 1 π 0 π¬ 1 π 0The evolution through 8 versions and adding support for GCP & Azure is my favorite part of this series.
Inclusion of YARA based malware detection is great but would have loved CloudTrail and equivalent log based detection that defenders could use π€
βοΈ intel blogs coming in from Permiso & SentinelOne today π
- https://permiso.io/blog/s/agile-approach-to-mass-cloud-cred-harvesting-and-cryptomining/
- https://www.sentinelone.com/labs/cloudy-with-a-chance-of-credentials-aws-targeting-cred-stealer-expands-to-azure-gcp/
Besides using it regularly to load and interrogate data - the Vertex blog is a great way to learn Storm recently π₯
12.07.2023 14:22 β π 2 π 2 π¬ 0 π 0π₯ lineup coming for the Objective-by-the-Sea v6 conference all on macOS & iOS security: https://objectivebythesea.org/v6/talks.html
- 2 talks on DPRK malware analysis
- 1 talk from Kaspersky on Triangulation (π¦
)
- ... and more on bug hunting across the OS and user applications!
2nd ever Apple Rapid Security Response update out for a WebKit bug (CVE-2023-37450):
iOS: https://support.apple.com/en-us/HT213823
macOS: https://support.apple.com/en-us/HT213825
Biggest question: how can I get a scaled down version for my home βcloudβ?
03.07.2023 00:36 β π 1 π 0 π¬ 0 π 0I would test this and see what detection opportunities exist with the Jira/Confluence audit logs but I already know there is not enough info logged to find token theft. Defenders have to rely on EDR logging for the token theft and hope users only access from work machines π
02.07.2023 15:08 β π 0 π 0 π¬ 0 π 0Iβm not hoping to start an big anti-OST flame war but itβs sad that the place that hosts a whole podcast drops offensive Atlassian tooling without a section on detection :(
https://posts.specterops.io/sowing-chaos-and-reaping-rewards-in-confluence-and-jira-7a90ba33bf62
Woo, my addition to the LOOBins project got released today! https://github.com/infosecB/LOOBins/releases/tag/v1.1.0
I added the mdls command used by common adware like Genio
I doubt they'll fix things, I've only seen one vendor make effort since https://audit-logs.tax went up... On the other hand it's really satisfying to publish and worth it.
23.06.2023 16:20 β π 1 π 0 π¬ 0 π 0Seems like the answer to this was to some extent: yes, 0-day was used.
New *OS releases (see https://support.apple.com/en-us/HT213814) from today include a mention of the Kaspersky team for CVE-2023-32434 so it seems like there was some level of 0-day with the Triangulation attack
More macOS threats to be detected π
https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/
Iconic way for @killedbygoogle.com to enter this new platform.
15.06.2023 22:19 β π 1 π 0 π¬ 0 π 0@jshlbrd.bsky.social is live at Fwd:cloudsec talking about
the design and use of https://substation.readme.io
at Brex! π₯
https://www.youtube.com/watch?v=ZvdYgL6b9xE