Intellexaβs Global Corporate Web
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
04.12.2025 04:17 β π 26 π 21 π¬ 2 π 4
So excited that Iβm going to present my latest research at @districtcon.bsky.social in January! The last round of tickets are going on sale on this Sunday (Nov 16th @12pm EST). Looking forward to see you in DC!
13.11.2025 13:06 β π 3 π 0 π¬ 0 π 0
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.Β Key findingsΒ Between June and August 2025,
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...
05.11.2025 13:37 β π 18 π 12 π¬ 2 π 0
Gonna be in Belgium for the first time after living in Europe for 7 years. Come catch me if you are at @what-is-sos.bsky.social tomorrow!!!
27.10.2025 11:18 β π 1 π 0 π¬ 0 π 0
Great work and thanks for referencing our research on redefining IAB! The four-tier classification framework is insightful for identifying collaborative campaigns!
23.10.2025 10:59 β π 4 π 0 π¬ 0 π 0
I donβt have enough data to speak confidently on that. In my own observations I havenβt seen much SNMP exploitation, though Iβve come across a few cases of suspected tunnelling traffic.
15.10.2025 14:38 β π 1 π 0 π¬ 1 π 0
CN APT targets Serbian Government
Mustang Panda continues targeting European governments
Quite a bit of CN APT activity in europe in the past week
strikeready.com/blog/cn-apt-...
As always, if you're interested in tuning your skills, download the samples here github.com/StrikeReady-...
03.10.2025 14:30 β π 9 π 7 π¬ 0 π 2
There's was a mad dash on SOS tickets over the weekend.
SOS is two weeks away, if you've been putting off getting a ticket... your time is now.
stateofstatecraft.com/register
14.10.2025 03:48 β π 3 π 2 π¬ 0 π 0
text that reads: In Italy, investigative journalist Gianluigi Nuzzi was tracked days after publishing a dramatic exposΓ© of corruption in the Vatican, as police closed in on his source. In California, Anne Wojcicki, founder of DNA startup 23andMe and then married to Googleβs Sergey Brin, was tracked more than a thousand times as she moved across Silicon Valley. And in South Africa, associates of Rwandan opposition leader Patrick Karegeya were tracked before his assassination in a Johannesburg hotel room.
Another major surveillance provider exposed: First Wap
Its product was used to track some very high-profile figures
www.lighthousereports.com/investigatio...
14.10.2025 20:15 β π 11 π 8 π¬ 1 π 0
πΎ Had a great time at the DC4131 Padawan CTF with the Swiss @defcon.bsky.social community! Back to CTFs after a while teamed up with J & M and knocked out a few challenges. Go, pwnrpuffgirls girl power! πͺ Big thanks to the organizing team. Looking forward to the next one! #CTF
15.09.2025 11:55 β π 11 π 1 π¬ 0 π 0
Caught a PokΓ©mon at @defcon.bsky.social π Big fan of @lauriewired.bsky.social. It was so interesting to discuss about reverse engineering with her. Please can we all have a card like this?
09.08.2025 17:17 β π 18 π 1 π¬ 0 π 0
At @defcon.bsky.social today. Come find me!
08.08.2025 19:41 β π 2 π 0 π¬ 0 π 0
Heading to Hacker Summer Camp next week? π΅If youβre curious about the journeys behind the hacks, the challenges and the stories that shaped us, come join our panel: "Hacking the Status Quoβ. With Valentina Palmiotti (Chompie), Natalie Silvanovich, and Vandana Verma. #BHUSA #blackhatusa
31.07.2025 15:30 β π 0 π 0 π¬ 0 π 0
The SOS conference is officially THREE months away! On October 28, we gather to discuss the latest developments in nation-state operations with leading experts!
β° CFP Ends September 1st!
π§ Early Bird Tickets almost sold out!
π΅οΈ Come talk espionage, sabotage, ORBATs, and more!
stateofstatecraft.com
28.07.2025 04:52 β π 4 π 1 π¬ 1 π 1
State of Statecraft
A new conversation for a new era.
Excited to see another threat intel focused conference taking place in Europe, and itβs organized by threat analyst in the field! The CFP is opened until Sept 1st. Looking forward to see your amazing research!
#What_is_SOS #StateOfStatecraft
www.stateofstatecraft.com
18.07.2025 07:44 β π 4 π 1 π¬ 0 π 1
Malspace | Multiple Actors, One Breach - Rethinking Threat Models in 2025
In this episode, Julien sits down with Chi En (Ashley) Shen, a distinguished threat researcher at Cisco Talos. Ashley shares her fascinating journey from hacking forums in Taiwan to leading threat ...
Had a great time on the @malspace.bsky.social podcast with Julien talking about my PIVOTcon presentation from tracking compartmentalized attacks to thoughts on attribution. Fun convo (and I loved the theme song at the end!). πΆ Thanks for having me!
malspace.com/episodes/mul...
10.07.2025 13:05 β π 4 π 3 π¬ 0 π 0
I'm excited to return to Black Hat USA this year and have the opportunity to give away one briefings pass to the conference. If you're a student or someone who could use a little support to attend, I'd love to hear from you. DM me if you're interested!
#BHUSA
10.06.2025 10:03 β π 2 π 0 π¬ 0 π 0
Looking forward to my week at @botconf.infosec.exchange.ap.brid.gy ! Please come say hi if you are around! #Botconf2025
20.05.2025 10:38 β π 1 π 0 π¬ 0 π 0
OffensiveCon25 - YouTube
OffensiveCon 2025 Talks
Talks from the OffensiveCon 2025 security conference, which took place last week, are now available on YouTube
www.youtube.com/playlist?lis...
20.05.2025 09:09 β π 12 π 7 π¬ 0 π 0
Huge thanks to @vertexproject.bsky.social for updating Synapse to support the new "relationship" context.
Weβre excited to see this research foster collaboration and push real change across the threat intelligence community. (3/3)
13.05.2025 13:02 β π 3 π 3 π¬ 1 π 0
π‘ New blogs out: Compartmentalized attacks are no longer limited to financially motivated actors, state-sponsored groups are adopting them too. We propose a new taxonomy for initial access groups to reflect broader motivations and affiliations. (1/3)
13.05.2025 13:02 β π 6 π 3 π¬ 1 π 0
Had an amazing time speaking at @pivotcon.bsky.social last week! Grateful for the chance to share insights and connect with the brilliant minds. PIVOTcon remains my favorite threat intel event in Europe. Huge thanks to the organizers for creating this community and the memorable experience.
12.05.2025 14:16 β π 8 π 2 π¬ 0 π 0
HITCON 2025 CFP
HITCON 2025 CFP
A lot of you have been asking, YES! HITCON 2025 CFP is open! The conference will be host on August 15 - August 16. Submit your talk before June 8th. Looking forward to your submissions! #HITCON #HITCON2025
CFP: cfp2025.hitcon.org/en/
09.05.2025 12:09 β π 1 π 1 π¬ 0 π 0
Come work with us! We are looking for a creative and self-motivated communications professional to join our team this summer in the role of Digital Communications Specialist. This is a FT, hybrid position based at @uoft.bsky.social in downtown Toronto.
Learn more: citizenlab.ca/2025/05/job-...
06.05.2025 21:03 β π 9 π 9 π¬ 1 π 1
BREAKING: jury awards massive $167 million in punitive damages against spyware company NSO Group.
Precedent-setting win against notorious #Pegasus spyware maker.
Very consequential for victims to see this.
Congratulations to #WhatsApp on sticking this case through since 2019. Some thoughts 1/
06.05.2025 21:30 β π 768 π 289 π¬ 19 π 20
We just published our investigation into a Cactus ransomware campaign, uncovering TOYMAKER, an IAB group using a custom backdoor LAGTOY. Itβs still challenging to identify compartmentalized attacks. Weβll share our approach and solutions at @pivotcon.bsky.social in 2 weeks! #toymaker
24.04.2025 13:26 β π 8 π 4 π¬ 0 π 0
sr detection engineer @ huntress β’ malware enjoyer β’ macOS security
https://alden.io
threaty threats -- helping build research workflows into a soc product, but I don't speak for them on this acct. pretty good at bash scripts and strings. disclosures on my linkedin below
https://www.linkedin.com/in/alexlanstein/
@DistrictCon Founder. Harvard & Georgetown MPP/JD candidate. @CyberStatecraft / @BelferCenter fellow, ex-Google threat research. Dog mom. Opinions=my own π©π»βπ»
Threat researcher @ Proofpoint. Formerly IBM X-Force, CMU, US Government, US Navy. Views are my own.
π¦
ο£Ώ mach-o enthusiast
loves dogs, sports, memes. she/her. podcaster. "bluesky's humblest resident nailfluencer π
" - Jerry
my heart is in the west π΅π views mine.
threat research @ proofpoint
macOS security researcher espousing no one's opinions but my own. Dogged follower of #lufc, at least until the world stops going round (IYKYK).
philastokes.com
Senior Threat Researcher @Proofpoint. The threat actor's threat actor. All things BEC, fraud, and scams. Love making pig butchers squeal. π·πͺπ½οΈ
#threatintel @PwC UK
Reverse engineering, threat intelligence, YARA. Amateur jazz pianist. All posts are my own. He/him.
Principal Adversary Hunter @dragosinc, Army Veteran,
Cocktail Scientist, APT Researcher | #FSD
https://infosec.exchange/web/@DrunkBinary
https://twitter.com/DrunkBinary
π³ founder of @greynoise.io. computers, networks, technology enthusiast. big goober.
cyber threat intelligence, OSINT, and corgi hair. Thoughts are my own, RT/Like != Endorsement. (He/Him)
Blog: intelcorgi.com
Security research and breaking news straight from ESET Research Labs.
welivesecurity.com/research/
it security & cyber guy, research @ http://vulnerability.ch, friendly, swiss | Opinions are my own
Security Researcher @Meta. Writer. Would-be musician. Maintainer of Manalyze and Gepetto. Trolling on a purely personal capacity.
Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.
hacker, poster, weird machine mechanic
https://chompie.rip