Elektrine lite

← Feed

Brian Clark

deepthoughts10@infosec.exchange

<p><a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="tag">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="tag">#<span>threatintel</span></a> and Politics. I try my best. <br />Also @deepthoughts10@twitter.com</p><p>Searchable</p>

Posts

  • Post #4385417

    RE: https://mastodon.social/@zackwhittaker/117039173900529368 Maybe @wdormann@infosec.exchange was right about not using apps and only using websites #cybersecurity

  • Post #4382991

    RE: https://infosec.exchange/@wdormann/117039138203111701 Many @defcon@defcon.social and @BSidesLV@infosec.exchange talks are recorded and eventually posted to YouTube. If you can’t make it, follow those accounts to get notified when they post the recordings.

  • Post #4360104

    Happy to be at @BSidesLV@infosec.exchange #bsideslv

  • Post #4359930

    RE: https://infosec.exchange/@SecureOwl/117032579489312068 FFS

  • Post #4175446

    RE: https://mastodon.online/@streetartutopia/116999561247400940 Perfect timing! See my earlier posts on this topic #cybersecurity

  • Post #4175066

    RE: https://infosec.exchange/@DarkWebInformer/116999813453991351 I’ve been waiting for this to be published …. #cybersecurity

  • Post #4164283

    RE: https://infosec.exchange/@ESETresearch/116996496516280171 For defenders, take a look at the free https://loldrivers.io to build automatic detection capabilities for vulnerable driver use in your organization. To move to prevention, take a look at https://magicsword.io to help you create Windows Defender Application Control policies that prevent the execution of vulnerable drivers on your systems. #cybersecurity

  • Post #4164158

    RE: https://infosec.exchange/@VirusBulletin/116996988073045096 This is exactly why you should block access to Telegram from business networks. It’s too risky. If you have users that want or need it, create a Wi-Fi network that only has access to the Internet (no internal network access) to which they can connect their smartphones. #cybersecurity

  • Post #4163976

    RE: https://defcon.social/@defcon/116993849606697118 DEF CON doesn’t want you wearing Meta glasses to their events either. Please just don’t. #cybersecurity

  • Post #4115984

    RE: https://mastodon.social/@zackwhittaker/116986783278293072 OMG the collapsing robot is spot on for this tech right now #cybersecurity

  • Post #3875488

    Yuck #canadawildfires #smoke

  • Post #3614773

    Think I can still use these? 😉 I played a lot of coin-operated video games in my youth. #ChuckECheese #MalibuFunCenter

  • Post #3568557

    RE: https://infosec.exchange/@jaythvv/116858665927371933 Unbelievable game! #worldcup

  • Post #3524447

    RE: https://infosec.exchange/@CDubbs/116847680945065797 Create a group called &quot;Device Code Users&quot; and a CA policy that blocks the use of the Device Code authentication flow except for those in the group. #cybersecurity #entraID

  • Post #3438723

    Saturday #bloomscrolling in Lake Geneva, WI

  • Post #3438700

    Saturday #bloomscrolling in Lake Geneva, WI

  • Post #1351234

    Well-written article from Marlink on the Black Shrantac #ransomware group. I like that they have sections on “What defenders should watch for” and “How to reduce exposure” in addition to IOCs. https://marlink.com/resources/knowledge-hub/black-shrantac-inside-the-ransomware-group-weaponising-legitimate-tools-against-global-organisations/ #cybersecurity

  • Post #712864

    What day is it? #piday

  • Post #642943

    New report from Palo Alto’s Unit42 on sophisticated attacks with long dwell times by one or more Chinese threat groups. There is a lot going on in this article and much of it likely doesn’t apply to my organization, but I try to learn from reports like this at least one thing that I can bring to my organization to improve our security posture. In this case I learned about DumpIt — a new-to-me free multiplatform forensics tool. I’m going to add that to an upcoming threat hunt and will build detec...

  • Post #642941

    RE: https://mastodon.social/@campuscodi/116194688591162933 Security firm Bitdefender has an in-depth report on the latest TTPs and #IOC ‘s used by an APT group, shared by Catalin below. You may not be targeted by this group, but they use the very common technique of Living off Trusted Services. One highlighted in this report is Discord. I strongly agree with Bitdefender’s advice of controlling or blocking access to Discord. Another service mentioned is the file-sharing service tmpfiles.org — li...

  • Post #642940

    Watched the movie Mickey 17 last night. I know it was not commercially successful, but I liked it. Good weird sci-fi movie with interesting characters. #movies #cinema https://www.rottentomatoes.com/m/mickey_17

  • Post #642938

    RE: https://infosec.exchange/@ScumBots/116195646833821026 Come ‘on now?!? Who still doesn’t have *.ngrok.io blocked? Ngrok themselves don’t even recommend using this domain any longer. #cybersecurity

  • Post #642937

    What are Out-of-band Application Security Testing (OAST) domains? Out-of-band application security testing (OAST) is a method for finding exploitable vulnerabilities in a web application by forcing a target to call back to a piece of infrastructure controlled by the tester. OAST domains (sub-domains most often) are often free and hosted by OAST tool providers like interact.sh. What happens when something is free on the Internet? It gets abused. Let’s make tOAST of the most commonly abused OAST...

  • Post #642936

    RE: https://infosec.exchange/@patrickcmiller/116210592807071943 Here are some controls to put in place to prevent this attack from happening to you: - Block ISO file extensions from being emailed to your users - Prevent downloads of ISO files from untrusted sites (such as consumer friendly file storage services) - Change your Windows File Explorer settings to associate the .ISO file extension with Notepad.exe so it won’t auto mount when double-clicked #cybersecurity

  • Post #642935

    RE: https://mastodon.social/@verge/116212236350531341 This shouldn’t baffle anyone. This is a transactional administration and clearly the right people were paid off. #uspol

  • Post #493718

    RE: https://infosec.exchange/@merill/116096226364016976 This should be handy for Microsoft SysAdmins. I ran into an issue with old modules recently and I’m going to try this out. Merill is a trusted source for this sort of stuff and happens to work for Microsoft. #powershell

  • Post #493716

    Geoshitties for the win! If you use @badsamurai ‘s blocklists you’d have already blocked *.vercel.app which is a key link in the kill chain for this attack described by Microsoft. My advice: block Vercel for everyone in your org except for those that have a business need. #cybersecurity https://www.microsoft.com/en-us/security/blog/2026/02/24/c2-developer-targeting-campaign/

  • Post #493714

    RE: https://swecyb.com/@orlysec/116144639827797601 Maybe you’ve noticed that I’ve repeatedly recommended that you should block access to *.vercel.app ? Well, here are 31 more reasons. Also, block pastebin.com too. #cybersecurity

  • Post #493713

    RE: https://mastodon.social/@scalzi/116138157607069357 #catsofmastodon #caturday

  • Post #493712

    A new-to-me #Porter: Tupac Shaporter from Ivanhoe Park Brewing Co. in Orlando, FL. #beersofmastodon #beer