Daniel Gordon

@validhorizon.bsky.social

Thought Trailer, Cyber Threat Intel, DFIR. He/Him. Bucketing, sharing, and bacon-saving as a service. https://validhorizon.medium.com/

Periodic reminder that if you are being asked by a captcha to type any kind of combinations of keys & especially if they look like shortcut key stroke combinations it is an attack called ClickFix. Basically the prompt is to fool you into downloading & installing malicious software. Stay vigilant!

Nicolai von Ondarza@nvondarza.bsky.social · 2w ago

This is new and completely wierd. To proof that I am not an AI, cloudflare now wants me to enter something in the terminal, of unknown origin. Sorry, no way.

Cloudflare trying to prompt me to enter stuff in the windows terminal to proof I am not a robot...

Read Reuters coverage from @raphae.li on Proofpoint and NSA's reporting of half-click exploits used by Russian actors to target Zimbra, Roundcube, and other mailservers to steal emails www.reuters.com/legal/govern...

US and allies say Russian hackers stole emails without social engineering

The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of ​the Zimbra email program without having to fool them into opening ‌an attachmen...

reuters.com

Saher@saffronsec.bsky.social · 2w ago

Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...

I hope you are correct but a lot of intrusions are not from vulnerabilities per se (social eng, structural reasons, legacy, competing incentives, SMB resourcing etc.) and I’ve seen a shed load of AI-enabled intrusions. I consider AI a net-negative for security and I don’t expect that to improve.

Pwnallthethings@pwnallthethings.bsky.social · 2w ago

Hard to predict, but my working theory is it's going to be a really rough couple of years IMO, followed by computer systems and internal networks rapidly becoming dramatically very substantially more secure.

OpenAI takes credit for the Hugging Face breach last week The company says that some of its models, including a pre-release one, escaped their testing sandboxes during a test evaluation and then... just hacked Hugging Face's package repo 🤣 openai.com/index/huggin...

OpenAI and Hugging Face partner to address security incident during model evaluation

OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.

openai.com

Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintel

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil...

volexity.com

Proofpoint's threat research team is tracking a password-spraying campaign against the U.S. education sector, using a spoofed user agent so outdated it may predate some of the accounts it targeted. Read more below. 👇🏼🧵