Microsoft has released new comprehensive security updates for all supported versions of SharePoint Server (Subscription Edition, 2019, and 2016) that protect customers against these new vulnerabilities. msft.it/6045sE1ux
Matthew Kennedy
@matthewkennedy.bsky.social
Manager at Microsoft Threat Intelligence Center (MSTIC). Adjunct Faculty at Georgetown University. Penn State Alum. Tweets are my own.
Microsoft is moving antivirus providers out of the Windows kernel
Microsoft is moving antivirus providers out of the Windows kernel
Microsoft wants to avoid another CrowdStrike incident.
buff.ly
Excellent work by Mandiant and crew! Great blog!
🔥 new blog detailing 0day exploitation of Ivanti appliances as well as some newly observed malware families tracked as PHASEJAM and DRYHOOK. We also detail activity related to the previously observed SPAWN* malware ecosystem tied to China-nexus cluster UNC5337. cloud.google.com/blog/topics/...
MSTIC is hiring in the UK and EU for entry level and senior analyst roles! jobs.careers.microsoft.com/global/en/jo... jobs.careers.microsoft.com/global/en/jo...
Be sure to check out part 2! Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine www.microsoft.com/en-us/securi...
Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine | Microsoft Security Blog
Since January 2024, Microsoft has observed Secret Blizzard using the tools or infrastructure of other threat groups to attack targets in Ukraine and download its custom backdoors Tavdig and KazuarV2.
microsoft.com
MSTIC is hiring! Current roles in US and AU. The Microsoft Threat Intelligence Center (MSTIC) is recruiting experienced nation-state threat hunters with highly honed threat intel analysis skills. MSTIC is responsible for delivering timely threat intelligence across our product & services teams.
Excellent work by the team! Another fascinating example of Secret Blizzard using “the tools/infrastructure of at least six other threat actors during the past seven years”
www.microsoft.com/en-us/securi... Based on both Microsoft Threat Intel findings and governments and other sec vendors, we assess that the Russian nation-state actor tracked as Secret Blizzard has used the tools and infrastructure of at least six other threat actors during the past seven years.
New, by me: Security researchers say North Korean hackers, posing as VCs, recruiters, and remote IT workers, have infiltrated "hundreds of organizations" and stolen billions of crypto in recent years to fund the regime's nuke program. My dispatch from Cyberwarcon: techcrunch.com/2024/11/28/n...
North Korean hackers have stolen billions in crypto by posing as VCs, recruiters and IT workers | TechCrunch
Security researchers say North Korean hackers have infiltrated hundreds of organizations with the goal of taking money and stealing data to further the regime's nuclear weapons program.
techcrunch.com
Every holiday season I do a “security tune up” across all my accounts to ensure I’m making use of the best new security features. What features / tech should I prioritize this year?
We are generally way too overconfident in understanding adversary intent. Activity is straightforward, attribution is tricky and intent is often opaque and relies on organizational politics and bureacracy inside organizations.
One of my favorite aspects about @cyberwarcon.bsky.social is how it’s a yearly homecoming for a group of people with the primary focus of making a positive impact in the digital domain. Regardless of healthy business competition, there’s a shared camaraderie being in the fight together.
Can’t forget to shout out these three GOATs who presented on Storm-2077 today!
Don’t miss Microsoft’s deep dive into Storm-2077, a China-based threat actor targeting U.S. agencies, NGOs, and industries like defense and telecom. Join Ned Moran, Judy Ng, and Mark Parsons to explore their tactics, from app exploits to spear-phishing. 🔗 www.cyberwarcon.com/registration
James crushing it as always. But what’s even better is getting to work alongside of him each day. An amazing teammate and friend!
James Elliott's DPRK cybercrime talk is a great way to end the day. i love this stuff. nomnomnom. #cyberwarcon #cybercrime #sleuthcon
James Elliott absolutely crushing the last talk of the day at #CYBERWARCON.
Doppelgänger insight from Meta: Professional/contracted IO has two audiences: the target of the campaign and those who hired them (Kremlin)
Made a list of accounts at @cyberwarcon.bsky.social to make it easier to follow along: bsky.app/profile/did:...
As always, great insights from Josh and Pratik at Google TAG on IRGC operations. #cyberwarcon
Find out more on what MSTIC plans to present at CyberWarCon today! www.microsoft.com/en-us/securi...
Microsoft shares latest intelligence on North Korean and Chinese threat actors at CYBERWARCON | Microsoft Security Blog
At CYBERWARCON 2024, Microsoft Threat Intelligence analysts will share research and insights on North Korean and Chinese threat actors representing years of threat actor tracking, infrastructure monit...
microsoft.com
The DPRK IT Worker apparatus is a well oiled machine. Few grasp the depth of how many pieces enable these operations.
🚨 New Research Drop: 🇰🇵 DPRK IT Workers | A Network of Active Front Companies and Their Links to China Summary: ⚪ Newly Disrupted Front Companies by USG ⚪ Impersonating US based software and tech orgs ⚪ Links to still-active front orgs, CN association Report: www.sentinelone.com/labs/dprk-it...
My two favorite Gregs talking my favorite topic. Check it out! thecyberwire.com/podcasts/mic...
Between Two Gregs: An Update on the North Korean Threat Landscape
In this episode of the Microsoft Threat Intelligence Podcast host Sherrod DeGrippo is joined by Proofpoint’s Greg Lesnewich and Microsoft’s Greg Schloemer to share the unique threat posed by North Korea’s (DPRK) state-sponsored cyber activities. The Gregs discuss their years of experience tracking North Korean cyber actors and the distinct tactics that set DPRK apart from other nation-sponsored threats. The conversation also explores North Korea’s high stakes, as DPRK threat actors operate under intense pressure from government handlers, adding a layer of urgency and fear to their operations. They share insights into North Korea’s aggressive use of stolen cryptocurrency to fund the regime’s initiatives, like ballistic missile tests, and discuss the broader geopolitical impact.
thecyberwire.com
There's been a lot of attention on the Salt Typhoon intrusions. Don't forget the Volt Typhoon prepositioning is still a major problem as well! www.tenable.com/blog/volt-ty...
Volt Typhoon: What State and Local Government Officials Need to Know
Increased activity from the state-sponsored threat group Volt Typhoon raises concerns about the cybersecurity of U.S. critical infrastructure. Here’s how you can identify potential exposures and attac...
tenable.com
Excited to support my teammates as they share fascinating insights into threat actors from North Korea and China. Don’t miss these!
www.cyberwarcon.com/agenda-2024 truly incredible agenda. Great mix of OGs and up-and-comers
One of the most fascinating aspects of following DPRK threat actors is observing leading indicators from numerous intrusion sets target the same technology months before an announcement.
North Korean leader Kim Jong Un called for the mass production of attack drones after Pyongyang accused Seoul of flying unmanned aerial vehicles in the airspace over its capital in what it called a “war provocation.”
MSTIC is hiring! Come join our team focused on tracking and disrupting threats to Microsoft and our customers! jobs.careers.microsoft.com/global/en/sh...
Senior Security Researcher in Redmond, Washington, United States | Security Engineering at Microsoft
Apply for Senior Security Researcher in Redmond, Washington, United States | Security Engineering at Microsoft
jobs.careers.microsoft.com