-Hacker breaches Hungary's State Treasury -Russia to mandate 40 apps on all smartphones next year -Hackers hits Liechtenstein's business database -AI hallucinates 55 vulnerability reports -Pass-ta-key attack recovers passkeys from Chrome N: news.risky.biz/risky-bullet... P: risky.biz/RBNEWS596/
Daniel Gordon
@validhorizon.bsky.social
Thought Trailer, Cyber Threat Intel, DFIR. He/Him. Bucketing, sharing, and bacon-saving as a service. https://validhorizon.medium.com/
👊 🇰🇵 🔥 Friends and Foes, Comrades and Competitors, Allies and IT Workers, today we put out the call for original research to be presented at BSides Pyongyang 2026. Fill out the form and see if you have the Juche: https://forms.gle/x2LKBWYSddnmKNbu9
Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers. msft.it/63328aBnhE
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
msft.it
This DPRK subgroup doing watering holes and also ransomware would definitely be a new development.
"Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)" published by Ahnlab. #Phishing, #Ransomware, #Wateringhole, #Gunra, #Copperhedge, #DoubleBarrel https://asec.ahnlab.com/en/94696
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. 1/6
This is an under discussed part of how LLMs enhance TA tradecraft
aws.amazon.com/blogs/securi...
Amazon identifies North Korean hacker group behind open-source supply chain attacks | Amazon Web Services
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companie...
aws.amazon.com
People ask me why I don’t go to summer camp. I like doing outdoor stuff and this is crazy pants even if there are no locusts or sandstorms or flooding this year.
Looking forward to living in a hair dryer next week
The excitement continues. @greg-l.bsky.social discovered Russia-aligned actor TA488 using another half-click exploit - this time in Outlook- leading to a new (very cool) browser-based implant, OWAReaper. Check out TA488 upping its game @threatinsight.proofpoint.com www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
proofpoint.com
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. 1/5
Who did you piss off now @activemeasures.bsky.social en.mehrnews.com/news/246525/...
Wisconsin-based communications infrastructure hacked: Handala
TEHRAN, Jul. 25 (MNA) – The cyber group “Handala” has announced a successful cyberattack targeting the network infrastructure of SupraNet Communications, a major internet service provider based in Mad...
en.mehrnews.com
Updating blogs based on new information is normal and all naming schemes are bad in different ways; some are just less-bad.
This is interesting but I have to push back and ask for your thoughts. If I have a blog post pinned to the top of my CTI firm's blog saying definitively that BORSCHT = Russia, can I actually keep that name in my work products if the attribution changes? In that case, the name is the attribution
Periodic reminder that if you are being asked by a captcha to type any kind of combinations of keys & especially if they look like shortcut key stroke combinations it is an attack called ClickFix. Basically the prompt is to fool you into downloading & installing malicious software. Stay vigilant!
This is new and completely wierd. To proof that I am not an AI, cloudflare now wants me to enter something in the terminal, of unknown origin. Sorry, no way.
Read Reuters coverage from @raphae.li on Proofpoint and NSA's reporting of half-click exploits used by Russian actors to target Zimbra, Roundcube, and other mailservers to steal emails www.reuters.com/legal/govern...
US and allies say Russian hackers stole emails without social engineering
The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of the Zimbra email program without having to fool them into opening an attachmen...
reuters.com
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
proofpoint.com
I hope you are correct but a lot of intrusions are not from vulnerabilities per se (social eng, structural reasons, legacy, competing incentives, SMB resourcing etc.) and I’ve seen a shed load of AI-enabled intrusions. I consider AI a net-negative for security and I don’t expect that to improve.
Hard to predict, but my working theory is it's going to be a really rough couple of years IMO, followed by computer systems and internal networks rapidly becoming dramatically very substantially more secure.
A great explanation of what happened and why though not completely sure I agree with the very last post in the thread.
OpenAI takes credit for the Hugging Face breach last week The company says that some of its models, including a pre-release one, escaped their testing sandboxes during a test evaluation and then... just hacked Hugging Face's package repo 🤣 openai.com/index/huggin...
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
openai.com
dtex.ai/blog/dprk-it... dtex.ai/org_hierarch... dtex.ai/payment_brea... dtex.ai/geography_ma... Used this as a jumping off point because ZachXBT drop on it didn't get as much attention as it should've. In between the crypto info, were the operators/managers self identifying and filling in...
From Payroll to Pyongyang: The DPRK IT Worker Money Trail
Follow the DPRK IT worker money trail. Our research reveals how payments are processed and funds flow through the regime.
dtex.ai
This has been confirmed exploited in the wild. Updated with IoCS.
Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge.
Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintel
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil...
volexity.com
HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models. Another aspect for your IR plans. huggingface.co/blog/securit...
Talk spotlight: tracking a cluster of activity aimed at North Korean IT workers — the pivots, the TTPs, and an attribution assessment that doesn't land where you'd expect. Watch: https://youtu.be/x4a24slACeU #BSidesPyongyang #ThreatIntel
Hey! Cybersecurity guy here. We really don't want to create a norm where it's cool to attack critical infrastructure, civic infrastructure or private companies.
Oh boy, back to Trump threatening moar warcrimes by threatening to Big Attack Iran power plants & bridges. Presumably, he will once again invent a reason to "delay". or not. hellish, self-defeating cycle that could end w/him actually doing it & BAD long-term global consequences thereof.
No idea! 🤠 Whatever it is, it's concentrated in the eastern Great Lakes. The outbreak started in New York, now most of the cases are in Michigan. MN is somehow untouched. (And it's not bc Minnesota's just missing their cases. Minnesota does not miss cases.) www.indystar.com/story/graphi...
Map tracks spread of 'explosive' diarrhea outbreak. How to prevent infection
Hundreds of cyclosporiasis cases have been reported across the US. Here's where they're occurring and tips to help reduce your risk of infection.
indystar.com
So do you think it's one farm that is widely distributing something like lettuce or just a breakdown of hygiene and coming from several places?
a political fraudster decided to start an infosec company and he's going to get eaten alive krebsonsecurity.com/2026/07/felo... his tweet about the krebs article is very funny x.com/c2iris/statu...
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most...
krebsonsecurity.com
Proofpoint's threat research team is tracking a password-spraying campaign against the U.S. education sector, using a spoofed user agent so outdated it may predate some of the accounts it targeted. Read more below. 👇🏼🧵
New research from @greg-l.bsky.social and @mkyo.bsky.social on a China-aligned actor exploiting n-day vulns in Roundcube to pop mailservers of North American universities. So reminder to protect & patch your mailserver, the edge device you forgot was an edge device www.proofpoint.com/us/blog/thre...
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. Key
proofpoint.com