Diogo Fernandes 🤙🏼

@diogowski.bsky.social

🇵🇹 🇨🇭 #DFIR, #malware, #detectionengineering and #python! + 🚵🏼🤿🏂 https://github.com/diogo-fernan

Proofpoint's threat research team is tracking a password-spraying campaign against the U.S. education sector, using a spoofed user agent so outdated it may predate some of the accounts it targeted. Read more below. 👇🏼🧵

The cloud threat research team at Proofpoint has discovered an account takeover campaign targeting around 40,000 users. Malicious activity has been recorded as early as Feb. 2nd, with a surge on Feb. 10th and a peak on Feb. 12th.

Bild

There's a new Hindsight release! Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests. 🌐 Blog: dfir.blog/hindsight-pa... 🛠️ Tool download: hindsig.ht/release #DFIR #Chrome #Extensions

Hindsight v2025.03 Released!

Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests.

dfir.blog

You receive a laptop (powered off) in a high-stakes case. You are told the owner is extremely technical but given no useful technical details. The laptop is modern, with chassis intrusion features, and you must assume Secure Boot & BitLocker are in use. How do you proceed? #DFIR

Bild

YARA-X 0.13.0 is out: github.com/VirusTotal/y... As always, Victor and the contributors are cranking out quality improvements! In particular, check out the docs on how to use the formatter and linter and open issues (or tell me somehow) if you hit bugs or have things you want to see.

Release v0.13.0 · VirusTotal/yara-x

Implemented basic linting via the check command. Refactor the format of JSON output (#281). Parse Mach-O certificates (#276). Allow using previously defined variables in with statements (#287). BUG...

github.com

Just put out this research on MiTM PaaS kits labeled Rockstar and Flowerstorm over the past few months. While my name is on this I partnered with two researchers, Josh Rawles and Jordon Olness who did a bulk of the work alongside @thepacketrat.net, and Colin Cowie who are all individually brilliant!

Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces

A sudden disruption of a major phishing-as-a-service provider leads to the rise of another…that looks very familiar

news.sophos.com