x0rz

@x0rz.bsky.social

Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓

1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).

Bild

2/2 Russia at will. Although he claims to be apolitical, he denies responsibility for the crimes that are enabled by his platform. He loves to dish out advice to Western politicians, but hates paying taxes and prefers to live in a dictatorship. In short, he embodies the stereotypical Russian.

Telegram, the FSB, and the Man in the Middle

The technical infrastructure that underpins Telegram is controlled by a man whose companies have collaborated with Russian intelligence services. An investigation by IStories

istories.media

Following long practice of US gov indicting Chinese/Russian state hackers for breaching US systems, China has named and issued warrants for 3 NSA workers it says were behind hacks of China systems during Asian Winter Games. Also says University of California and Virginia Tech participated in attacks

China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents

Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) of launching "advanced" cyberattacks during the Asian Winter Games in February, targeting essential industries.

reuters.com

Extraordinary comment from Tory MP Graham Stuart: “We have to consider the possibility that President Trump is a Russian asset. If so, Trump's acquisition is the crowning achievement of Putin's FSB career.” (Narrator: It’s extraordinary because our own gd government didn’t say it first.)

Tweet by Graham Stuart, Tory MP @grahamstuart:
We have to consider the possibility that President Trump is a Russian asset.
If so, Trump's acquisition is the crowning achievement of Putin's FSB career - and Europe is on its own.

It shouldn’t take a panic over Chinese AI to remind people that most companies in the business set the terms for how they use your private data. And when you use their AI apps, you’re doing work for them, not the other way round.

incredibly detailed piece on Salt and Volt Typhoon (apparently named as if they're brothers) "a cybersecurity vendor notices the activity and flags it to the port's cybersecurity chief, who examines it and decides it's a false alarm. He heads to lunch at Whataburger." www.wsj.com/tech/cyberse...

How Chinese Hackers Graduated From Clumsy Corporate Thieves to Military Weapons

Massive “Typhoon” cyberattacks on U.S. infrastructure and telecoms sought to lay the groundwork for potential conflict with Beijing, as intruders gathered data and got in position to impede response a...

wsj.com

I don’t normally get worked up about the naming threat actors thing. But the Volt & Salt Typhoon is a disaster as it’s so hard for non-specialists to tell them apart: - Salt is Snowden style espionage by China against US - Volt is a direct 🇨🇳 military threat to degrade western infrastructure 1/2

"The networks are still compromised, and booting the hackers out could involve physically replacing “literally thousands and thousands and thousands of pieces of equipment across the country,” specifically outdated routers and switches" 🕵️‍♂️

Top senator calls Salt Typhoon ‘worst telecom hack in our nation’s history’

The severity of the Chinese breach highlights the need for more telecommunications regulation, lawmakers say.

washingtonpost.com