Alan Neville

@abnev.bsky.social

Principal Intelligence Analyst @ Symantec. Views are my own etc. https://keybase.io/abnev

Mercenary spyware vendor Paragon claims it's "responsible", (unlike NSO Group) But our investigations @citizenlab.ca show Paragon's spyware was abused in Italy 🇮🇹 to target civil society @accessnow.org sent them a letter with questions, and I signed on 👇 www.accessnow.org/press-releas...

Access Now - Paragon must answer for spyware use against civil society and journalists

Access Now calls on Paragon to answer for the use of its spyware in Italy against journalists, and to address oversight failures.

accessnow.org

#ESETresearch has published its latest APT Activity Report, covering October 2024 to March 2025 (Q4 2024–Q1 2025). China-aligned groups like Mustang Panda and DigitalRecyclers continued their espionage campaigns targeting the EU government and maritime sectors. 1/2

Bild

Layoffs at CrowdStrike. I’m safe, but if you’re looking for IR consultants I know a bunch of fucking amazing ones that will be looking for jobs 🫠

I'm analyzing the TM SGNL source code and will publish findings tomorrow. But the for a sneak peak, here's how it seems TeleMessage's system works: There's E2EE between TM SGNL and Signal, but NOT between TM SGNL and archive destinations. TM's archive server can read the chat logs. Stay tuned.

Diagram that shows:
- E2EE chat logs between TM SGNL and Signal
- TM SGNL sends data to archive server using HTTPS API
- Archive server sends data to destinations using SMTP, SFTP, or Microsoft 365

Check Point published a write-up of CVE-2025-24054, an NTLM leak that Microsoft patched last month. The company says the vulnerability is now being exploited in the wild, with one campaign targeting government and private institutions in Poland and Romania. research.checkpoint.com/2025/cve-202...

CVE-2025-24054, NTLM Exploit in the Wild - Check Point Research

Key Points Introduction NTLM (New Technology LAN Manager) is a suite of authentication protocols developed by Microsoft to verify user identities and protect the integrity and confidentiality of netwo...

research.checkpoint.com

My first blog with Proofpoint is live! And we love a good crossover. State-sponsored actors try their hand at ClickFix - the hottest thing in cybercrime. Meet the North Koreans, Iranians, and Russians who are upping their social engineering game www.proofpoint.com/us/blog/thre...

Around the World in 90 Days: State-Sponsored Actors Try ClickFix | Proofpoint US

Key Findings While primarily a technique affiliated with cybercriminal actors, Proofpoint researchers discovered state-sponsored actors in multiple campaigns using the ClickFix social

proofpoint.com

NEW: In a hearing last week, an NSO Group lawyer said that Mexico, Saudi Arabia, and Uzbekistan were among the governments responsible for a 2019 hacking campaign against WhatsApp users. This is the first time representatives of the spyware maker admit who its customers are.

NSO lawyer names Mexico, Saudi Arabia, and Uzbekistan as spyware customers behind 2019 WhatsApp hacks | TechCrunch

This is the first time representatives for the spyware maker have publicly named its government customers.

techcrunch.com

SCOOP: sources tell me that the State Dept plans to eliminate its only office to counter foreign disinformation, as soon as today, delivering a win to foreign governments like Russia, Iran, and China—and the office's mostly conservative critics. www.technologyreview.com/2025/04/16/1...

US office that counters foreign disinformation is being eliminated, say officials

Conservative critics have long accused the department of helping to censor the American right.

technologyreview.com