Daniel Gordon's Avatar

Daniel Gordon

@validhorizon.bsky.social

Thought Trailer, Cyber Threat Intel, DFIR. He/Him. Bucketing, sharing, and bacon-saving as a service. https://validhorizon.medium.com/

3,227 Followers  |  201 Following  |  639 Posts  |  Joined: 24.07.2023  |  3.0625

Latest posts by validhorizon.bsky.social on Bluesky

25% off all courses, promo code ALLYALL and sale ends at midnight ET on 12/2

25% off all courses, promo code ALLYALL and sale ends at midnight ET on 12/2

LIFTOFF! All my courses on networkdefense.io are 25% off until Tuesday, 12/2, at midnight ET πŸš€

This is the only sitewide sale we do all year, and the cheapest you'll see these courses.

This event is for all y'all, so to get the discount, use code ALLYALL at checkout.

28.11.2025 14:15 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Post image

For software developers: there's currently a highly sophisticated hacking group targeting developers with backdoored coding skills tests. They typically take the form of large source codes specific to your skillset. Please email any suspicious code to me on: suspicious-skill-tests@protonmail.com
1/2

27.11.2025 18:19 β€” πŸ‘ 121    πŸ” 74    πŸ’¬ 2    πŸ“Œ 1

On the plus side, if you had to decided to go into law or politics this would have just been a normal Tuesday.

27.11.2025 03:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Honestly just being able to summarize the scale and current state of the issue in 25 minutes is a pretty significant achievement.

24.11.2025 21:15 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

"A Pain in the Mist: Navigating Operation DreamJob’s arsenal" published by OrangeCyberdefense. #DreamJob, #MISTPEN, #UNC2970, #DPRK, #CTI https://www.orangecyberdefense.com/global/blog/cert-news/a-pain-in-the-mist-navigating-operation-dreamjobs-arsenal

21.11.2025 13:30 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Even ignoring all the practical challenges: marketing, researchers, customers/defenders and policy makers use threat group names differently. Standardization can’t really account for these different use cases very well.

20.11.2025 14:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Standards

The keynote from @dmitri.silverado.org was both a heartfelt apology but also basically this xkcd.com/927/ haha

20.11.2025 13:54 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This is a pretty wild evolution. Both the integration of cyber and kinetic and the fact IRGC and that MOIS might actually be working effectively together.

20.11.2025 11:48 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It was a pleasure to be a part of this event along with quite the cast of characters, including some folks who I’ve worked with over the years. Thank you to the organizers and their truly amazing promotional themes! See folks tomorrow at @cyberwarcon.bsky.social

19.11.2025 00:10 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
BSides Pyongyang πŸ‡°πŸ‡΅ #BSidesPyongyang2025 :A free community cyber conference on Nov 18 2025 (Missile Industry Day) @ Lazarus HQ Pyongyang Roblox | 30th anniversary πŸŽ‚

Bsides Pyongyang starts in 15 minutes if the Cloudflare gods cooperate.
youtube.com/@bsidespyong...
m.twitch.tv/bsidespyongy...

18.11.2025 15:14 β€” πŸ‘ 5    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

At the end of the day in incident response, you may get accolades if you catch the attacker, but you will have the most impact if you have met the victim's needs. #infosec #dfir

17.11.2025 21:36 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

I really enjoy when my research on unusual suspected state sponsored hacking groups is useful. *monkey paw curls*

17.11.2025 11:45 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Tax dollars?

16.11.2025 08:29 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Over the course of my career I’ve found and accomplished some pretty wild stuff. Next week I will be talking, for the first time, about one of the wildest things I ever found. The talk will be geared to analysts and practitioners but pretty sure this will be fascinating for everyone.

14.11.2025 02:57 β€” πŸ‘ 9    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

They dropped this in August which was better than I expected from an AI company. www.anthropic.com/news/detecti...

They’ve hired some established names in CTI.

I honestly don’t consider this recent report to be that extraordinary given the number of people trying to figure how to AI everything.

13.11.2025 21:36 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

They’re sharper and more careful than I am though maybe I’m a low bar to clear

13.11.2025 21:01 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Lots of orgs redact IOCs, which I hate, but when you have only one method of detection, you don’t broadcast it for the adversary.

I believe you know security folks but you don’t know the CTI team or you wouldn’t be posting.

Why would they call a 3rd party about platform abuse? Also Bishop Fox wtf?

13.11.2025 20:50 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Cannot believe I’m defending an AI company but no 1,4,5 are not legit. Like not even slightly legit.

13.11.2025 20:35 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
An org chart with R at the top, I’s and B’s at the second level and G’s and B’s on the third.

An org chart with R at the top, I’s and B’s at the second level and G’s and B’s on the third.

AI will do it for us!

13.11.2025 15:50 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Fixed πŸ™‚

11.11.2025 21:11 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Something is broken in YARA for VirusTotal right now, signatures matching on things for no apparent reason.🫑 to any folks who have to clean up

11.11.2025 16:14 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Doesn’t look like DPRK to me, should probably give them your social security number

10.11.2025 14:15 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I don’t know. Not a lot of public info on that. In the current environment, I suspect they write a love letter, do a photo op, and build a hotel and get him back for free but πŸ€·β€β™‚οΈ

10.11.2025 00:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If you defect, your family goes to a prison camp or worse.

09.11.2025 23:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

*Screams incoherently at five different things about this that make no sense*

09.11.2025 18:36 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

bsky.app/profile/vali...

08.11.2025 16:17 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

A lot of β€œinfrastructure geolocates to X, therefore state sponsored by X”. A lot of β€œmajor ransomware attack was to distract from an [unrelated] major espionage intrusion” and a lot of β€œI heard about something a couple times therefore growing trend”.

08.11.2025 13:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

With that said I’ve certainly seen this kind of thing from western intel folks as well and spent way more time than I would like debunking grand conspiracy theories and wild unsupported attribution statements.

08.11.2025 13:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I know dunking on this is fun and all but if you watch the clip Christo is laughing and mocking this conspiracy theory he heard from Russian intel. I’ve heard stories about the terrible quality of Russian intel but this is bad.

08.11.2025 13:43 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 1    πŸ“Œ 1

Also I should note Christo is relaying Russian intel RUMINT rather than things he actually believes.

07.11.2025 00:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@validhorizon is following 20 prominent accounts