Julian-Ferdinand Vögele

Julian-Ferdinand Vögele

@julianferdinand.bsky.social

Threat Research @ Recorded Future. Previously @ Security Research Labs. He/Him. 🏳️‍🌈

1,293 Followers 197 Following 209 Posts Joined Oct 2023
5 hours ago

Catch the lastest episode of the Three Buddy Problem on Spotify 👇
open.spotify.com/episode/2M5w...

3 2 0 1
1 day ago
Preview
Lost in translation: How Russia’s new elite hit squad was compromised by an idiotic lapse in tradecraft Center 795, which emerged after the start of Russia's full-scale war in Ukraine and comprises elite units from the GRU and FSB, was established as a top-secret and fully autonomous entity designed to ...

Bravo, @michaeldweiss.bsky.social, Christo Grozev and others who did this

40 15 0 2
1 day ago
Preview
Intellexa Founder Tal Dilian Indicates State Authorities Used Predator in Greece - Dnews Israeli tech entrepreneur Tal Dilian appeared to hint that Greece’s state authorities were behind the use of the controversial Predator spyware. Israeli businessman Tal Dilian, founder of the surveill...

“Tal Dilian, founder of the surveillance technology company Intellexa, has made what observers describe as an indirect admission that the controversial Predator #spyware used in 🇬🇷Greece was operated by state authorities.”

www.dnews.gr/eidhseis/new...

0 4 0 0
2 days ago

Europäische Geheimdienst-Einschätzungen deuten ähnliches an. Darin hieß es vergangene Woche bereits: #Iran habe vermeintliche Enthauptungsschläge einkalkuliert, Befehlsebenen seien früh auf 3. u 4. Reihe des Militärs verlagert worden. Man richte sich auf lange Konfrontation ein.

14 7 1 0
3 days ago
Preview
Cork Stryker plants hit by suspected global Iranian-linked cyberattack Stryker operations worldwide jammed by hackers

Medical device maker Stryker reportedly hit with cyberattack from Iranian hacktivist group. So far only Irish news reporting, not here in US. "many employees have had their device data wiped and cannot access their accounts" Stryker makes surgical equipment, defibrillators, imaging equipment

179 124 10 20
3 days ago
Post image

-Gen. Joshua Rudd confirmed as next CyberCom and NSA head
-US to establish new inter-agency cyber cell
-UK to launch Online Crime Centre in April
-Coruna exploit kit traced back to L3Harris
-New Salesforce hacking campaign

Newsletter: news.risky.biz/risky-bullet...
Podcast: risky.biz/RBNEWS536/

12 6 1 0
3 days ago
Preview
Deutscher "Migrantenschreck"-Betreiber liefert jetzt Fake-News aus Moskau Der frühere Betreiber des Online-Waffenhandels "Migrantenschreck" Mario Rönsch inszeniert sich als Exil-Journalist in Moskau. Spuren führen bis zum russischen Geheimdienst

Migrantenschreck-Betreiber Mario Rönsch ist zurück. Dieses Mal als Chefredakteur der Fake News-Seite Anonymous News in Moskau. Welche Verbindungen es zum FSB gibt, lest Ihr in der neuen @papertrailmedia.de Recherche für @spiegel.de, @derstandard.at & @tagesanzeiger.bsky.social: tinyurl.com/57wbfnbc

13 7 0 2
4 days ago
Preview
The mystery of a globetrotting iPhone-hacking toolkit Tools used in a series of hacking campaigns by hackers in Russia, Ukraine, and China may have originated inside U.S. government contractor L3Harris, TechCrunch has learned.

SCOOP: The iPhone mass hacking toolkit used by Russian spies was developed at U.S. military contractor L3Harris, former employees said.

The Coruna toolkit was used against Ukrainians and by Chinese cybercriminals, according to Google. But the toolkit was initially developed for Western governments.

219 123 7 14
4 days ago

Finland's intelligence service has released its yearly national security overview report. On the cyber side of things, SUPO warns startups that foreign espionage can rob them of their future.

supo.fi/en/espionage...

11 4 0 0
4 days ago
Post image

📣 #PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's edition!
2⃣ days and 19 talks from leading #ThreatResearch experts.
The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵
#CTI #ThreatIntel
1/15

15 10 1 1
4 days ago
Preview
Edition 11 – One mistake ties together more than 100 domains Hey there, Hakan here. This week's edition is going to be a short one about mistakes. Without those, it'd be a whole lot harder to do my job. When trying to...

Short newsletter item about one mistake from disinfo operations #Doppelgänger that makes it possible to tie together >100 domains

buttondown.com/readwrite/ar...

17 11 1 1
4 days ago
Post image Post image

BREAKING: powerful iPhone hacking tools used by Chinese criminals originated from US defense giant L3 Harris.

Their zero-click exploits went to Russian spies too.

Unbelievable harm to our collective security.

Scoop: @lorenzofb.bsky.social, here's why it matters 1/
techcrunch.com/2026/03/09/a...

488 246 5 21
6 days ago
Preview
From a Sophisticated Browser-Extension Supply-Chain Compromise to a VibeCoded Twist: A Chrome Extension as the Initial Access Vector for a Broader Malware Chain Independent technical analysis of a Chrome extension compromise, fake update chain, and Windows-stage malware activity.

"A formerly legitimate Featured Chrome extension (ShotBird) was turned into a remote-controlled malware channel after an apparent ownership transfer"

Curious if this is another case of an extension being sold on ExtensionHub again? A place to watch...

monxresearch-sec.github.io/shotbird-ext...

20 16 0 0
5 days ago
YouTube
Bird names in Coruna iOS exploit framework YouTube video by Three Buddy Problem

What's with the bird names in a .gov iOS exploit framework? @craiu.bsky.social @jags.bsky.social www.youtube.com/watch?v=-QNf...

2 2 1 1
5 days ago

We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously. 1/7

1,894 989 26 114
5 days ago
Post image

𝗜𝗿𝗮𝗻 𝗮𝗻𝗱 𝘁𝗵𝗲 𝗰𝘆𝗯𝗲𝗿 𝗱𝗼𝗺𝗮𝗶𝗻: our selected analysis providing useful context on the different ways cyber tools have been used in and around #Iran. (1/5)

3 3 1 0
5 days ago
Post image

(5/5) Ransomware, espionage, & sabotage.
A. Milenkoski, J. Minier, @julianferdinand.bsky.social, M. Smeets, and @tgrossman.bsky.social examine state uses of ransomware, including Iran’s capacity for disruptive & politically motivated cyber operations.
🔗 Read article: bindinghook.com/state-backed...

1 1 0 0
5 days ago
Post image

-Mammoth trojan comes to MAX
-Phishing campaign targets Armenian civil society leaders ahead of elections
-Coruna technical analysis
-LuaJIT malware on GitHub
-Red Alert malware in Israel
-DPRK (ab)uses AI for everything
-New CL-UNK-1068 APT
-APT36 adopts vibeware
-Claude found 22 Firefox bugs

9 4 1 1
5 days ago
Post image

-White House releases new Cyber Strategy
-New Trump EO prioritizes fight against scams and cybercrime
-Chinese hackers breach FBI wiretap network
-Romania's largest meat exporter enters insolvency after ransomware attack

Podcast: risky.biz/RBNEWS535/
Newsletter: news.risky.biz/risky-bullet...

15 5 1 1
5 days ago
Video thumbnail

Along with our open call for talks, we have also opened registration for Hague TIX 2026!

The ticket link and everything practical you need to know about #HagueTIX2026 is right here: www.thehagueprogram.nl/the-hague-ti...

@thehagueprogram.bsky.social @fggaleiden.bsky.social @monicakello.bsky.social

3 3 0 0
6 days ago
Video thumbnail

New video footage shows a US Tomahawk missile hitting an IRGC facility in Minab, Iran, on Feb 28, showing for the first time that the US struck the area. The footage also shows smoke already rising from the vicinity of the girls’ school, where 175 people were reportedly killed, including children.

3,278 1,700 89 191
5 days ago
Post image

Huntress researchers Jamie Levy & Harlan Carvey have identified and detailed the full timeline of an intrusion in a customer environment that aligns with what others have identified as MuddyWater. www.huntress.com/blog/muddywa...

2 4 0 0
5 days ago
Post image

The #DefCon #Singapore March Chill Out will be happening March 27th at Georges in Tai Seng. Everyone is welcome!

Come meet the local InfoSec, Hacker, and Researcher communities working to make the DEF CON Singapore conference a reality at the end April […]

[Original post on defcon.social]

3 4 0 0
5 days ago
Preview
Kremlin hackers attempting to compromise Signal, WhatsApp accounts globally Russian state hackers are carrying out a global campaign to compromise Signal and WhatsApp accounts belonging to government officials and military personnel, Dutch intelligence warned Monday.

Russian state hackers are carrying out a global campaign to compromise Signal and WhatsApp accounts belonging to government officials and military personnel, Dutch intelligence warned Monday.

123 64 5 4
1 week ago
Preview
A beginner's guide to analyzing the network traffic of apps and websites In 2025, journalist Zack Whittaker found three popular apps were leaking sensitive user data. This is how he uses network analysis tools like Burp Suite to understand how apps and websites work and sh...

In this how-to for beginners, I explain how to get started with Burp and similar browser tools, we'll explore API basics, how to understand network requests, and getting started. I'll also walk you through some examples of how I found security bugs and data leaks, which I wrote up for TechCrunch.

19 8 0 0
1 week ago
Post image

🧨 🚨 NEW POD UP! (presented by @thinkstcanary.canary.tools) - The Coruna iOS exploit kit, the connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use @craiu.bsky.social @jags.bsky.social

LISTEN everwhere 👇
pod.link/1414525622

6 4 1 0
1 week ago
Preview
The Iran war has entered a new phase Both sides have changed their tactics, our data analysis finds

Terrific data deep dive with animated maps, showing how US/Israeli targeting shows a shift over the course of the war’s first week: from targeting army and drone/missile sites to targeting police and regime security, to enable an uprising.
economist.com/interactive/...

59 20 2 2
1 week ago
Preview
Iran war shows data centers emerging as critical targets From Amazon sites in the Gulf to reported strikes on Tehran data centers, digital infrastructure is increasingly becoming a casualty of war - Anadolu Ajansı

My comment for Anadolu Agency (turkish press agency) on data centres as targets in the Iran war. The strikes on Amazon facilities in the UAE and Bahrain are the first time commercial cloud infrastructure has taken physical damage from a drone or missile attack. www.aa.com.tr/en/middle-ea...

13 5 1 0
1 week ago
Post image

Kaspersky recently produced a podcast on Operation Triangulation, basically a story of the investigation

Things that I haven't seen mentioned elsewhere:
— Triangulation malware existed for >10 years
— Some technical details similar to the Equation Group

www.youtube.com/watch?v=j4pC...

9 2 0 0
1 week ago
Preview
United States • Florida-based spyware company tied to ex-NSA head closes its doors Defense Prime Inc, also known as Palm Beach Networks, has been staffed by veterans of Israeli spyware firm NSO Group, as well as a former NSA boss. The low profile firm recently dissolved its Florida

“The Florida-based cyber firm Defense Prime—which has also done business as Palm Beach Networks—& been staffed mostly by former employees of NSO Group, has dissolved its Florida operations. Its executives have moved their business operations to 🇪🇸Barcelona.”
www.intelligenceonline.com/americas/202...

3 1 1 0