TJ Nel

@idr0p.net

Insikt Group @ Recorded Future Malware, AI, data, and coffee.

x.com/RnaudBertran... Interesting pivot; this tells me... Open-weight sovereign deployment stack is a real product category. Nvidia (compute), edge inference vendors, open model labs, and integration middleware players all benefit, regardless of who wins the model-quality race.

Arnaud Bertrand (@RnaudBertrand) on X

After reflection, this new narrative by Palantir is probably much more consequential than people may assume. Palantir is basically being the canary in the coal mine announcing the death of two major ...

x.com

Working on #malware analysis #AI #agents reminds me of playing with a #Tamagotchi 😆. Repetitive, sometimes frustrating, but you love to see it evolve! 🤩. Pro Tip: If you are just pointing Claude/Codex/OpenCode at a bunch of analysis tool MCPs... you are doing it wrong and expensively.

A malware tamagotchi prototype dancing on AI paperwork.

Wow! SMCI dropped 33% on this news. That reaction is telling. The market understood immediately that export controls on AI compute are serious business, not theater. The AI race has a resource constraint, and everyone's been watching how aggressively it gets enforced. lowendbox.com/blog/supermi...

SuperMicro Founder Indicted on Charges of Smuggling Nvidia GPUs to China

Yih-Shyan “Wally” Liaw, one of the founders of server manufacturer SuperMicro, has been indicted on charges of smuggling billions of dollars' worth of high-end Nvidia GPUs to China.

lowendbox.com

October infostealer 🗝️. March extortion emails 📧. 5 months of dwell time. This is what undetected credential compromise looks like in practice. And with AI tools lowering the automation barrier, expect that timeline to speed up fast 🏃. www.bleepingcomputer.com/news/securit...

Hacker mass-mails HungerRush extortion emails to restaurant patrons

Customers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data coul...

bleepingcomputer.com

We all spent the last year vibe coding the shit out of web apps in React without knowing a single thing about JavaScript. Then enters #CVE-2025-55182 #React2Shell... poetry. “The spirits that I summoned I now cannot rid myself of again.”

Bild

Big report from our team at Recorded Future around #ThreatActivityEnablers (all of the hostings and services that power malicious infrastructure). Great Research on #StarkIndustries!

Lawrence S.@lawrencesec.bsky.social · 11mo ago

1/ Today, we published “One Step Ahead: Stark Industries Solutions Preempts EU Sanctions,” revealing how hosting provider #StarkIndustries executed a multi-phase restructuring of its operations, beginning up to a month before #EU sanctions.

1/ We just released a new report on TAG-144 (also known as Blind Eagle), where we identified five distinct activity clusters that have been active throughout 2024 and 2025, primarily targeting the Colombian government at multiple levels. Link to the report: www.recordedfuture.com/research/tag...

TAG-144’s Persistent Grip on South American Organizations

Persistent cyber operations by TAG-144 (Blind Eagle) continue to target South American, primarily Colombian, government entities through advanced spearphishing and RAT-based malware campaigns. Explore...

recordedfuture.com

"By 2025, 96% of companies are expected to use public cloud services, and 84% will adopt private cloud services. Additionally, 92% of organizations are projected to implement a multicloud strategy, reflecting the growing trend of cloud adoption across various industries." - Nextwork

Bild

#Remcos #malware is now at v7.0. No significant changes to the payload side, but improvements to enhance reliability and address bugs based on operator experience added. Samples: tria.ge/250709-3vxwa... tria.ge/250710-vba87... Looks to be distributed via email campaigns from reboundue[.]com emails

remcos | e24d9afbc2ed01e348ef6946672ef5f310940dd57a5216d0f1edbe31c919374b | Triage

Check this remcos report malware sample e24d9afbc2ed01e348ef6946672ef5f310940dd57a5216d0f1edbe31c919374b, with a score of 10 out of 10.

tria.ge