Lawrence S.

@lawrencesec.bsky.social

🇬🇧 Threat Research @ Recorded Future. I Like Tracking ASNs and ISPs for some reason...

-Iran internet outage not caused by strikes -Russia expands internet blackout to Sankt Petersburg -Oracle out-of-band security update -Himmelblau vulnerability gives root -Claudy Day vulnerabilities -Leak in German uni campuses platform -Langflow attacks started within a day

Bild

1/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...

2025 Year in Review: Malicious, Infrastructure

Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.

recordedfuture.com

-Even more research on Twitter/X algorithm manipulation -Russia turns on Telegram -Texas sues TP-Link -West Virginia sues Apple -US does dumb things, part 332737232 -Spain arrests hotel hacker -Nigerian hacker sentenced to 8 years -651 cybercrime arrests in Africa -GrayCharlie profile

Bild

CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.

Julian-Ferdinand Vögele@julianferdinand.bsky.social · 8mo ago

1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...

🚨 - New report by Haaretz, Inside Story, Inside-IT and Amnesty International release the Intellexa Leaks. Which exposes Intellexa support staff had access through Teamviewer to customer deployments and confirms found IOC's in the past by civil society. 🧵👇

Bild

1/ [UPDATE] As of November 10, 2025, metaspinner net GmbH has provided substantial evidence confirming Insikt Group’s original assessment that their identity was unlawfully and fraudulently used in the registration of #AS209800.

Lawrence S.@lawrencesec.bsky.social · 9mo ago

1/ New report from myself and @whoisnt.bsky.social: “Malicious Infrastructure Finds Stability with aurologic GmbH.” We uncover how German ISP aurologic GmbH has become a central nexus for high-risk hosting networks, sustaining large concentrations of malicious infrastructure.