If I did one of those Ancestry DNA tests right now, a significantly high proportion would come back as Stilton Cheese
Toby Lewis
@tobaslouis.co.uk
Global Head of Threat Analysis at @Darktrace.com All things Cyber Security Ops, Threat Hunting, Threat Intel and Incident Mgmt.
Details of the cyber attack at Harrods (as they are with Co-op & M&S) are still low and we shouldn’t rule out that the three incidents impacting the retailers are simply coincidence. .... 1/2
Luxury store Harrods is latest retail victim of cyber attackers
Harrods has "restricted internet access" after an attempt to gain access to its systems left some customers struggling to pay for purchases, Sky News can reveal.
news.sky.com
Why is @microsoft.com "Teams" plural, when "Word" is not? Surely a singular Team feels more homely... maybe. Conversely, a singular "Word", feels like about as much effort as I put in my school coursework.
Cooking top tip: quarter-pounders are not the same size as quarter-kilo’ers #ImadeBigBurgers
New blog post from @darktrace.com, looking at the detection of an Insider Threat in a SaaS application, with the customer supported by our amazing Analyst SOC
Bytesize Security: Insider Threats in Google Workspace | Darktrace Blog
Insider threats pose significant risks due to access to internal systems. Darktrace detected a former employee attempting to steal data from the customer’s Google Workspace platform. Learn about this ...
darktrace.com
In my first Executive Order, I will be renaming France as "Cheese-land" #GulfOfMexico
A cautionary tale: not everything suspicious is malicious. (although, I'd argue everything malicious was indeed suspicious at one point)
So, Is Someone Getting Fired, Or…?
Two weeks before Christmas, exactly that happened. It was pandemonium in security. Someone apparently tried really hard to break into our high-sec company by sending out a "gift certificate" to every ...
notalwaysright.com
A new blog post from analysts at @darktrace.com: The use of phishing kits as part of an AitM attack, increasing an attackers ability and proficiency in stealing legitimate credentials. ... and then simply just logging on.
Detecting and mitigating adversary-in-the-middle phishing attacks with Darktrace Services | Darktrace Blog
Threat actors often use advanced phishing toolkits and Adversary-in-the-Middle (AitM) attacks in Business Email Compromise (BEC) campaigns, Discover how Darktrace detected and mitigated a sophisticate...
darktrace.com
Ok Brain Trust: Prove me wrong. There is no application of cyber attack, where the intended outcome can't be achieved by non-cyber means.
One of my 2025 resolutions is to write more, including reinvigorating my cyber security focussed blog, which took a bit of a hiatus in the latter half of 2024. I've got a few ideas lined up already, but what would you like to see me write about?
Common Sense Security | Toby Lewis | Substack
Removing the FUD from Cyber Security. Click to read Common Sense Security, by Toby Lewis, a Substack publication. Launched 2 years ago.
tobylewis.substack.com
Interesting OpSec aspect with regards to the BeyondTrust compromise. (H/T to @GossiTheDog.cyberplace.social.ap.brid.gy for first spotting this) Having a search for some of the IOCs from the BeyondTrust blog, reveals that they appear in a file uploaded to VirusTotal on the 19th December
US Treasury announce network breach by “Chinese Actors” via cybersecurity vendor BeyondTrust. BeyondTrust specialise in Privileged Access Management. In other words, they have the power to access or generate one-time-use Admin credentials for their customer networks.
US Treasury says it was hacked by China in 'major incident'
A Chinese state-sponsored hacker broke into the US Treasury Department's systems in what is being called a "major incident".
bbc.com
New blog post by analysts from @darktrace.com: Detecting the exploitation of internet-facing File Transfer Servers, exploiting CVE-2024-50623
Cleo File Transfer Vulnerability: Patch Pitfalls and Darktrace’s Detection of Post-Exploitation Activities | Darktrace Blog
File transfer applications are prime targets for ransomware groups due to their critical role in business operations. Recent vulnerabilities in Cleo's MFT software, namely CVE-2024-50623 and CVE-2024-...
darktrace.com
New blog post by analysts from @darktrace.com - a review of recent exploit campaigns against Palo Alto firewalls which are then used as a launch point into customer networks.
Darktrace’s view on Operation Lunar Peek: Exploitation of Palo Alto firewall devices (CVE 2024-2012 and 2024-9474) | Darktrace Blog
Darktrace’s Threat Research team investigated a major campaign exploiting vulnerabilities in Palo Alto firewall devices (CVE 2024-2012 and 2024-9474). Learn about the spike in post-exploitation activi...
darktrace.com
New blog post by analysts @darktrace.bsky.social - detecting the use of AiTM Phishing Kits, including MFA bypass, by attackers.
A snake in the net: Defending against AiTM phishing threats and Mamba 2FA | Darktrace Blog
Phishing-as-a-Service (PhaaS) platforms have lowered entry barriers for cybercriminals, leading to sophisticated AiTM phishing attacks. Darktrace's AI-driven solutions, including Darktrace / EMAIL, ef...
darktrace.com
I can only read this in the voice of the guy who reads out the Football results.
‘Tis the season to… … be constantly picking up dropped pine needles off the floor
New blog post by analysts at @darktrace.bsky.social - detecting SaaS account compromise including the use of multiple VPN access points by threat actors.
Behind the veil: Darktrace's detection of VPN exploitation in SaaS environments | Darktrace Blog
A recent phishing attack compromised an internal email account, but Darktrace’s advanced AI quickly intervened. By identifying unusual activity across email and SaaS environments, Darktrace uncovered ...
darktrace.com
Nuances become lost when arguments are oversimplified. In this case, both attribution and motivation are reduced into its simplest form. With attribution, it’s worth considering we’re talking about threats from multiple groups originating, or in support of, Russia’s objectives.
Russia ready to wage cyber war on UK, minister to say - BBC News
Pat McFadden will tell a Nato conference that Russia could try to attack British businesses and power grids.
www-bbc-co-uk.cdn.ampproject.org
Only those of a certain age/persuasion will know what this means: FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8
A list of the most popular names for the daughters of drummers: 3. Anna One 2. Anna Two 1. Anna One Two Three Four
Sure, a snowy back garden sounds like fun, but for any dog owners out there, you now have your own dog 💩 minefield. One step and it could be catastrophe.
As we're in this rapid growth of @bsky.app, not only are we going to see accnts impersonating high profile individuals, but critically, impersonating high reputation news sources. All it would take is some imaginative "Breaking News" to hit public confidence. Can the real BBC News please stand up?
With reports of "fake" bsky accnts impersonating UK MPs, its important to note that accnt verification (akin to the pre-Musk Twitter "Blue tick") is left to the user, not @bsky.app. This is done using a method similar to how email spoofing is mitigated, with a special DNS record:
How to set your domain as your handle - Bluesky
Using a domain as your handle helps with account identity, verification, and portability. Here's how to set your domain as your handle.
bsky.social
New to @bsky.app? We’ve got some etiquette just for you! Turn on the little feature that reminds you to post alt text with your images. Alt text allows blind and partially sighted people to understand what's in your images using screen readers. Without alt text, it just says "image".