Chi En (Ashley) Shen's Avatar

Chi En (Ashley) Shen

@ashl3y-shen.bsky.social

Security researcher @ Cisco Talos. / Ex-Google TAG / Black Hat & HITCON review board / Organiser of Rhacklette.

118 Followers  |  66 Following  |  29 Posts  |  Joined: 28.11.2024  |  1.974

Latest posts by ashl3y-shen.bsky.social on Bluesky

Post image

Heading to Hacker Summer Camp next week? ๐ŸŒตIf youโ€™re curious about the journeys behind the hacks, the challenges and the stories that shaped us, come join our panel: "Hacking the Status Quoโ€. With Valentina Palmiotti (Chompie), Natalie Silvanovich, and Vandana Verma. #BHUSA #blackhatusa

31.07.2025 15:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

The SOS conference is officially THREE months away! On October 28, we gather to discuss the latest developments in nation-state operations with leading experts!

โฐ CFP Ends September 1st!
๐Ÿง Early Bird Tickets almost sold out!
๐Ÿ•ต๏ธ Come talk espionage, sabotage, ORBATs, and more!

stateofstatecraft.com

28.07.2025 04:52 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Preview
State of Statecraft A new conversation for a new era.

Excited to see another threat intel focused conference taking place in Europe, and itโ€™s organized by threat analyst in the field! The CFP is opened until Sept 1st. Looking forward to see your amazing research!
#What_is_SOS #StateOfStatecraft

www.stateofstatecraft.com

18.07.2025 07:44 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Malspace | Multiple Actors, One Breach - Rethinking Threat Models in 2025 In this episode, Julien sits down with Chi En (Ashley) Shen, a distinguished threat researcher at Cisco Talos. Ashley shares her fascinating journey from hacking forums in Taiwan to leading threat ...

Had a great time on the @malspace.bsky.social podcast with Julien talking about my PIVOTcon presentation from tracking compartmentalized attacks to thoughts on attribution. Fun convo (and I loved the theme song at the end!). ๐ŸŽถ Thanks for having me!

malspace.com/episodes/mul...

10.07.2025 13:05 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I'm excited to return to Black Hat USA this year and have the opportunity to give away one briefings pass to the conference. If you're a student or someone who could use a little support to attend, I'd love to hear from you. DM me if you're interested!
#BHUSA

10.06.2025 10:03 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Looking forward to my week at @botconf.infosec.exchange.ap.brid.gy ! Please come say hi if you are around! #Botconf2025

20.05.2025 10:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
OffensiveCon25 - YouTube OffensiveCon 2025 Talks

Talks from the OffensiveCon 2025 security conference, which took place last week, are now available on YouTube

www.youtube.com/playlist?lis...

20.05.2025 09:09 โ€” ๐Ÿ‘ 12    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Huge thanks to @vertexproject.bsky.social for updating Synapse to support the new "relationship" context.
Weโ€™re excited to see this research foster collaboration and push real change across the threat intelligence community. (3/3)

13.05.2025 13:02 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Defining a new methodology for modeling and tracking compartmentalized threats How do you profile actors and defend your systems when multiple threat actors are working together? In Part 2, Cisco Talos proposes an extended Diamond Model to analyze complex relationships between a...

In blog 2, we dive into the challenges of investigating compartmentalized campaigns. We share our approach to identifying them and propose an extended Diamond Model with a new "relationship" layer to close the analytical gaps. (2/3)
blog.talosintelligence.com/compartmenta...

13.05.2025 13:02 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐Ÿ“ก New blogs out: Compartmentalized attacks are no longer limited to financially motivated actors, state-sponsored groups are adopting them too. We propose a new taxonomy for initial access groups to reflect broader motivations and affiliations. (1/3)

13.05.2025 13:02 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
TA406 Pivots to the Front | Proofpoint US What happenedย  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these

@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...

13.05.2025 09:53 โ€” ๐Ÿ‘ 15    ๐Ÿ” 13    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Post image Post image

Had an amazing time speaking at @pivotcon.bsky.social last week! Grateful for the chance to share insights and connect with the brilliant minds. PIVOTcon remains my favorite threat intel event in Europe. Huge thanks to the organizers for creating this community and the memorable experience.

12.05.2025 14:16 โ€” ๐Ÿ‘ 8    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
HITCON 2025 CFP HITCON 2025 CFP

A lot of you have been asking, YES! HITCON 2025 CFP is open! The conference will be host on August 15 - August 16. Submit your talk before June 8th. Looking forward to your submissions! #HITCON #HITCON2025
CFP: cfp2025.hitcon.org/en/

09.05.2025 12:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Come work with us! We are looking for a creative and self-motivated communications professional to join our team this summer in the role of Digital Communications Specialist. This is a FT, hybrid position based at @uoft.bsky.social in downtown Toronto.

Learn more: citizenlab.ca/2025/05/job-...

06.05.2025 21:03 โ€” ๐Ÿ‘ 9    ๐Ÿ” 10    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

BREAKING: jury awards massive $167 million in punitive damages against spyware company NSO Group.

Precedent-setting win against notorious #Pegasus spyware maker.

Very consequential for victims to see this.

Congratulations to #WhatsApp on sticking this case through since 2019. Some thoughts 1/

06.05.2025 21:30 โ€” ๐Ÿ‘ 775    ๐Ÿ” 290    ๐Ÿ’ฌ 19    ๐Ÿ“Œ 20

We just published our investigation into a Cactus ransomware campaign, uncovering TOYMAKER, an IAB group using a custom backdoor LAGTOY. Itโ€™s still challenging to identify compartmentalized attacks. Weโ€™ll share our approach and solutions at @pivotcon.bsky.social in 2 weeks! #toymaker

24.04.2025 13:26 โ€” ๐Ÿ‘ 8    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
China-nexus APT exploits Ivanti Connect Secure VPN vulnerability to infiltrate multiple entities - TeamT5 In late March, TeamT5 detected that the China-nexus APT group exploited the critical vulnerability in Ivanti Connect Secure VPN appliances to infiltrate multiple entities around the globe. The victims...

New blog from TeamT5 warns a China-nexus APT is exploiting a vulnerability in #Ivanti Connect Secure VPN appliances to target victims in EMEA and the US. Today Shadowserver's CVE-2025-22457 tracker shows 4,098 unpatched instances remain, mostly in Asia and the US.

pse.is/7esf4n

14.04.2025 12:34 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image Post image Post image Post image

Wrapped up 2 panels at Black Hat Asia ๐Ÿฅณ ! Had such a great time meeting everyone. Thank you to all who stopped by the Community Lounge! I truly enjoyed the discussions and hope our answers were helpful. See you next year! #BHASIA

08.04.2025 13:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Lego of Black Hat Operations Center ๐Ÿ˜๐Ÿ˜ Love the Bricks & Picks zone at Black Hat Asia this year! #BHASIA

03.04.2025 05:45 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

After nearly 9 years on the Black Hat Asia review board (ufff time flies!), Iโ€™m honored to take on more responsibility and join the Black Hat USA review board this year. The CFP closes in 2 daysโ€”get your brilliant research in! #BlackHat #BHUSA
๐Ÿ’ปSubmit CFP: usa-briefings-cfp.blackhat.com

01.04.2025 13:42 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Black Hat Black Hat

Event page: www.blackhat.com/asia-25/feat...

24.03.2025 16:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Come join us at the Ask A Security Expert session at Black Hat Asia on April 4th! I'll be there with Orange Tsai, Ryan Flores, and Dr. Marina Krotofil answering your cybersecurity questions. Submit your topics in advance using the form on the event page. Looking forward to seeing you there!

24.03.2025 16:04 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
abuse.ch - Figthing malware and botnets abuse.ch is providing community driven threat intelligence on cyber threats

Introducing: abuse.ch Hunting Platform abuse.ch/blog/introdu...

17.03.2025 13:26 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

I had an amazing time at the Devcore conference last weekend! It was an honor to share my thoughts on exploit hunting there. Super impressed by the quality of talks and really enjoyed meeting so many great people. Huge thanks to the Devcore team for the wonderful experience!

17.03.2025 12:03 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It looks like Microsoft has been quietly updating its 2023 new APT naming table with new entries

The table used to have 20-30 entries... it's now gigantic!

Bookmark it: learn.microsoft.com/en-gb/unifie...

16.03.2025 18:44 โ€” ๐Ÿ‘ 21    ๐Ÿ” 9    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 2
Post image

Love the swags from @devco.re.web.brid.gy conference 2025 ๐Ÿ˜

15.03.2025 14:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Here we go!!

15.03.2025 00:36 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

โœˆ๏ธย  Heading to Taiwan this week for @devco.re.web.brid.gy Conference 2025! Iโ€™ll give an intro on exploit hunting and its challenges. Excited to speak in Taiwan again and looking forward to the great talks and meeting everyone there!

conf.devco.re/2025/agenda/

12.03.2025 13:44 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Honored and excited to be speaking at @pivotcon.bsky.social again this year! ๐ŸŽ‰ Huge shoutout to the co-authors @_vventura, @b4n1shed.bsky.social and @asheermalhotra โ€”couldnโ€™t have done this research without you! Looking forward to seeing everyone in Mรกlaga.

This year I must join the Karaoke!๐Ÿ˜†

07.03.2025 19:55 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Preview
Weathering the storm: In the midst of a Typhoon Cisco Talos has been closely monitoring reports of widespread intrusion activity against several major U.S. telecommunications companies, by a threat actor dubbed Salt Typhoon. This blog highlights ou...

๐Ÿ“ฃ @talosintelligence.com investigated #SaltTyphoon and discovered a custom-built tool called JumbledPath, used for packet capturing. While no new exploits were observed, their tactics remain a significant threat to targeted organizations. blog.talosintelligence.com/salt-typhoon...

21.02.2025 13:05 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@ashl3y-shen is following 20 prominent accounts