Brian Clark
deepthoughts10@infosec.exchange
<p><a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="tag">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="tag">#<span>threatintel</span></a> and Politics. I try my best. <br />Also @deepthoughts10@twitter.com</p><p>Searchable</p>
Posts
-
View post
So glad I don’t have any Citrix Netscalers in my environment. SecOps hugs to those who do. 🤗
-
View post
RE: https://c.im/@nickrauchen/117304280530477897 🤯
-
View post
RE: https://mastodon.social/@zackwhittaker/117039173900529368 Maybe @wdormann@infosec.exchange was right about not using apps and only using websites #cybersecurity
-
View post
RE: https://infosec.exchange/@wdormann/117039138203111701 Many @defcon@defcon.social and @BSidesLV@infosec.exchange talks are recorded and eventually posted to YouTube. If you can’t make it, follow those accounts to get notified when they post the recordings.
-
View post
Happy to be at @BSidesLV@infosec.exchange #bsideslv
-
View post
RE: https://infosec.exchange/@SecureOwl/117032579489312068 FFS
-
View post
RE: https://mastodon.online/@streetartutopia/116999561247400940 Perfect timing! See my earlier posts on this topic #cybersecurity
-
View post
RE: https://infosec.exchange/@DarkWebInformer/116999813453991351 I’ve been waiting for this to be published …. #cybersecurity
-
View post
RE: https://infosec.exchange/@ESETresearch/116996496516280171 For defenders, take a look at the free https://loldrivers.io to build automatic detection capabilities for vulnerable driver use in your organization. To move to prevention, take a look at https://magicsword.io to help you create Windows Defender Application Control policies that prevent the execution of vulnerable drivers on your systems. #cybersecurity
-
View post
RE: https://infosec.exchange/@VirusBulletin/116996988073045096 This is exactly why you should block access to Telegram from business networks. It’s too risky. If you have users that want or need it, create a Wi-Fi network that only has access to the Internet (no internal network access) to which they can connect their smartphones. #cybersecurity
-
View post
RE: https://defcon.social/@defcon/116993849606697118 DEF CON doesn’t want you wearing Meta glasses to their events either. Please just don’t. #cybersecurity
-
View post
RE: https://mastodon.social/@zackwhittaker/116986783278293072 OMG the collapsing robot is spot on for this tech right now #cybersecurity
-
View post
Yuck #canadawildfires #smoke
-
View post
Think I can still use these? 😉 I played a lot of coin-operated video games in my youth. #ChuckECheese #MalibuFunCenter
-
View post
RE: https://infosec.exchange/@jaythvv/116858665927371933 Unbelievable game! #worldcup
-
View post
RE: https://infosec.exchange/@CDubbs/116847680945065797 Create a group called "Device Code Users" and a CA policy that blocks the use of the Device Code authentication flow except for those in the group. #cybersecurity #entraID
-
View post
Saturday #bloomscrolling in Lake Geneva, WI
-
View post
Saturday #bloomscrolling in Lake Geneva, WI
-
View post
Well-written article from Marlink on the Black Shrantac #ransomware group. I like that they have sections on “What defenders should watch for” and “How to reduce exposure” in addition to IOCs. https://marlink.com/resources/knowledge-hub/black-shrantac-inside-the-ransomware-group-weaponising-legitimate-tools-against-global-organisations/ #cybersecurity
-
View post
@scalzi sadly, I know nothing about any of these authors. I’m following this thread to find out what others like.
-
View post
What day is it? #piday
-
View post
New report from Palo Alto’s Unit42 on sophisticated attacks with long dwell times by one or more Chinese threat groups. There is a lot going on in this article and much of it likely doesn’t apply to my organization, but I try to learn from reports like this at least one thing that I can bring to my organization to improve our security posture. In this case I learned about DumpIt — a new-to-me free multiplatform forensics tool. I’m going to add that to an upcoming threat hunt and will build detec...
-
View post
RE: https://mastodon.social/@campuscodi/116194688591162933 Security firm Bitdefender has an in-depth report on the latest TTPs and #IOC ‘s used by an APT group, shared by Catalin below. You may not be targeted by this group, but they use the very common technique of Living off Trusted Services. One highlighted in this report is Discord. I strongly agree with Bitdefender’s advice of controlling or blocking access to Discord. Another service mentioned is the file-sharing service tmpfiles.org — li...
-
View post
Watched the movie Mickey 17 last night. I know it was not commercially successful, but I liked it. Good weird sci-fi movie with interesting characters. #movies #cinema https://www.rottentomatoes.com/m/mickey_17
-
View post
RE: https://infosec.exchange/@ScumBots/116195646833821026 Come ‘on now?!? Who still doesn’t have *.ngrok.io blocked? Ngrok themselves don’t even recommend using this domain any longer. #cybersecurity
-
View post
What are Out-of-band Application Security Testing (OAST) domains? Out-of-band application security testing (OAST) is a method for finding exploitable vulnerabilities in a web application by forcing a target to call back to a piece of infrastructure controlled by the tester. OAST domains (sub-domains most often) are often free and hosted by OAST tool providers like interact.sh. What happens when something is free on the Internet? It gets abused. Let’s make tOAST of the most commonly abused OAST...
-
View post
RE: https://infosec.exchange/@patrickcmiller/116210592807071943 Here are some controls to put in place to prevent this attack from happening to you: - Block ISO file extensions from being emailed to your users - Prevent downloads of ISO files from untrusted sites (such as consumer friendly file storage services) - Change your Windows File Explorer settings to associate the .ISO file extension with Notepad.exe so it won’t auto mount when double-clicked #cybersecurity
-
View post
RE: https://mastodon.social/@verge/116212236350531341 This shouldn’t baffle anyone. This is a transactional administration and clearly the right people were paid off. #uspol
-
View post
RE: https://infosec.exchange/@merill/116096226364016976 This should be handy for Microsoft SysAdmins. I ran into an issue with old modules recently and I’m going to try this out. Merill is a trusted source for this sort of stuff and happens to work for Microsoft. #powershell
-
View post
Geoshitties for the win! If you use @badsamurai ‘s blocklists you’d have already blocked *.vercel.app which is a key link in the kill chain for this attack described by Microsoft. My advice: block Vercel for everyone in your org except for those that have a business need. #cybersecurity https://www.microsoft.com/en-us/security/blog/2026/02/24/c2-developer-targeting-campaign/