SentinelLABS

@sentinellabs.bsky.social

We are the Threat Intelligence and Malware Analysis team of @sentinelone.com https://sentinellabs.com https://labscon.io

🔥 👀 New research from @morecoffeeplz.bsky.social and @silascutler.bsky.social on the "silent" AI network, a massive, unmanaged layer of open-source AI infrastructure operating in the shadows.

SentinelOne@sentinelone.com · 6mo ago

🧵 175,000+ exposed AI hosts. Zero guardrails. New research from @sentinellabs.bsky.social and @censys.bsky.social reveals a massive, unmanaged layer of open-source AI infrastructure operating in the shadows. s1.ai/si-llama Here is what you need to know about the "silent" AI network. ⤵️

Reddit AMA with our very own @dakotaindc.bsky.social—ask him anything here: www.reddit.com/r/geopolitic...

From the geopolitics community on Reddit

Explore this post and more from the geopolitics community

reddit.com

SentinelOne@sentinelone.com · 11mo ago

🚨 Reddit AMA 🚨 @dakotaindc.bsky.social tracks how China builds its hacker pipeline—from campus and classrooms to command line. Ask him anything! 🗓 Sept 16 (ET) Set a reminder and join here: www.reddit.com/r/geopolitic...

🚨New research drop: Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms It was a pleasure collaborating with Sreekar Madabushi and @kennethkinion.bsky.social from Validin! Read our blog post: s1.ai/nk-ops

Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms

DPRK-aligned threat actors abuse CTI platforms to detect infrastructure exposure and scout for new assets.

s1.ai

The Cyber Patents China Didn’t Want Us to Find: @dakotaindc.bsky.social and @sentinellabs.bsky.social uncovered 10+ patents for highly intrusive forensics and data collection tools—filed by companies named in U.S. gov't. indictments for working with the Chinese Hafnium (aka Silk Typhoon) APT group.

China’s Covert Capabilities | Silk Spun From Hafnium

China-linked hackers used patented spyware tech from front companies tied to Hafnium, exposing gaps in cyber threat attribution.

s1.ai

👀 Apple: “macOS is secure by design.” 💻 Meanwhile, in /Users/Shared: 🕵️‍♂️ Persistent Malware masquerading as Apple “agent” >> Khepri beacon in /tmp 📦 Ad-hoc signed payloads 🌍 Targeting Chinese diaspora Deep dive from Dinesh Devadoss and me 👉 s1.ai/zuru #icymi #macOS #malware #APT #infosec

macOS.ZuRu Resurfaces | Modified Khepri C2 Hides Inside Doctored Termius App

ZuRu malware continues to prey on macOS users seeking legitimate business tools, adapting its loader and C2 techniques to backdoor its targets.

s1.ai

We just released our findings on long-term activity clusters attributed to China-nexus actors. We discuss a relatively underreported, yet critical, aspect of the threat landscape: the targeting of cybersecurity vendors. Big shout out to Lumen's Black Lotus Labs for their support! [1/2]

Love when we can talk about hoy dynamic the threat landscape actually is. The scope and scale of the DPRK IT workers effort alone surprised me as we worked it. Also love @sentinelone.com let us discuss this openly and viewed it as important to do so. www.sentinelone.com/labs/top-tie...

Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today's Adversaries

This report highlights a rarely-discussed but crucially important attack surface: security vendors themselves.

sentinelone.com