Matthew Kennedy

@matthewkennedy.bsky.social

Manager at Microsoft Threat Intelligence Center (MSTIC). Adjunct Faculty at Georgetown University. Penn State Alum. Tweets are my own.

MSTIC is hiring! Current roles in US and AU. The Microsoft Threat Intelligence Center (MSTIC) is recruiting experienced nation-state threat hunters with highly honed threat intel analysis skills. MSTIC is responsible for delivering timely threat intelligence across our product & services teams.

Excellent work by the team! Another fascinating example of Secret Blizzard using “the tools/infrastructure of at least six other threat actors during the past seven years”

Ann Johnson@ajohnsocyber.bsky.social · 2y ago

www.microsoft.com/en-us/securi... Based on both Microsoft Threat Intel findings and governments and other sec vendors, we assess that the Russian nation-state actor tracked as Secret Blizzard has used the tools and infrastructure of at least six other threat actors during the past seven years.

New, by me: Security researchers say North Korean hackers, posing as VCs, recruiters, and remote IT workers, have infiltrated "hundreds of organizations" and stolen billions of crypto in recent years to fund the regime's nuke program. My dispatch from Cyberwarcon: techcrunch.com/2024/11/28/n...

North Korean hackers have stolen billions in crypto by posing as VCs, recruiters and IT workers | TechCrunch

Security researchers say North Korean hackers have infiltrated hundreds of organizations with the goal of taking money and stealing data to further the regime's nuclear weapons program.

techcrunch.com

We are generally way too overconfident in understanding adversary intent. Activity is straightforward, attribution is tricky and intent is often opaque and relies on organizational politics and bureacracy inside organizations.