Brian Clark
deepthoughts10@infosec.exchange
<p><a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="tag">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="tag">#<span>threatintel</span></a> and Politics. I try my best. <br />Also @deepthoughts10@twitter.com</p><p>Searchable</p>
Posts
-
Post #4385417
RE: https://mastodon.social/@zackwhittaker/117039173900529368 Maybe @wdormann@infosec.exchange was right about not using apps and only using websites #cybersecurity
-
Post #4382991
RE: https://infosec.exchange/@wdormann/117039138203111701 Many @defcon@defcon.social and @BSidesLV@infosec.exchange talks are recorded and eventually posted to YouTube. If you can’t make it, follow those accounts to get notified when they post the recordings.
-
Post #4360104
Happy to be at @BSidesLV@infosec.exchange #bsideslv
-
Post #4359930
RE: https://infosec.exchange/@SecureOwl/117032579489312068 FFS
-
Post #4175446
RE: https://mastodon.online/@streetartutopia/116999561247400940 Perfect timing! See my earlier posts on this topic #cybersecurity
-
Post #4175066
RE: https://infosec.exchange/@DarkWebInformer/116999813453991351 I’ve been waiting for this to be published …. #cybersecurity
-
Post #4164283
RE: https://infosec.exchange/@ESETresearch/116996496516280171 For defenders, take a look at the free https://loldrivers.io to build automatic detection capabilities for vulnerable driver use in your organization. To move to prevention, take a look at https://magicsword.io to help you create Windows Defender Application Control policies that prevent the execution of vulnerable drivers on your systems. #cybersecurity
-
Post #4164158
RE: https://infosec.exchange/@VirusBulletin/116996988073045096 This is exactly why you should block access to Telegram from business networks. It’s too risky. If you have users that want or need it, create a Wi-Fi network that only has access to the Internet (no internal network access) to which they can connect their smartphones. #cybersecurity
-
Post #4163976
RE: https://defcon.social/@defcon/116993849606697118 DEF CON doesn’t want you wearing Meta glasses to their events either. Please just don’t. #cybersecurity
-
Post #4115984
RE: https://mastodon.social/@zackwhittaker/116986783278293072 OMG the collapsing robot is spot on for this tech right now #cybersecurity
-
Post #3875488
Yuck #canadawildfires #smoke
-
Post #3614773
Think I can still use these? 😉 I played a lot of coin-operated video games in my youth. #ChuckECheese #MalibuFunCenter
-
Post #3568557
RE: https://infosec.exchange/@jaythvv/116858665927371933 Unbelievable game! #worldcup
-
Post #3524447
RE: https://infosec.exchange/@CDubbs/116847680945065797 Create a group called "Device Code Users" and a CA policy that blocks the use of the Device Code authentication flow except for those in the group. #cybersecurity #entraID
-
Post #3438723
Saturday #bloomscrolling in Lake Geneva, WI
-
Post #3438700
Saturday #bloomscrolling in Lake Geneva, WI
-
Post #1351234
Well-written article from Marlink on the Black Shrantac #ransomware group. I like that they have sections on “What defenders should watch for” and “How to reduce exposure” in addition to IOCs. https://marlink.com/resources/knowledge-hub/black-shrantac-inside-the-ransomware-group-weaponising-legitimate-tools-against-global-organisations/ #cybersecurity
-
Post #712864
What day is it? #piday
-
Post #642943
New report from Palo Alto’s Unit42 on sophisticated attacks with long dwell times by one or more Chinese threat groups. There is a lot going on in this article and much of it likely doesn’t apply to my organization, but I try to learn from reports like this at least one thing that I can bring to my organization to improve our security posture. In this case I learned about DumpIt — a new-to-me free multiplatform forensics tool. I’m going to add that to an upcoming threat hunt and will build detec...
-
Post #642941
RE: https://mastodon.social/@campuscodi/116194688591162933 Security firm Bitdefender has an in-depth report on the latest TTPs and #IOC ‘s used by an APT group, shared by Catalin below. You may not be targeted by this group, but they use the very common technique of Living off Trusted Services. One highlighted in this report is Discord. I strongly agree with Bitdefender’s advice of controlling or blocking access to Discord. Another service mentioned is the file-sharing service tmpfiles.org — li...
-
Post #642940
Watched the movie Mickey 17 last night. I know it was not commercially successful, but I liked it. Good weird sci-fi movie with interesting characters. #movies #cinema https://www.rottentomatoes.com/m/mickey_17
-
Post #642938
RE: https://infosec.exchange/@ScumBots/116195646833821026 Come ‘on now?!? Who still doesn’t have *.ngrok.io blocked? Ngrok themselves don’t even recommend using this domain any longer. #cybersecurity
-
Post #642937
What are Out-of-band Application Security Testing (OAST) domains? Out-of-band application security testing (OAST) is a method for finding exploitable vulnerabilities in a web application by forcing a target to call back to a piece of infrastructure controlled by the tester. OAST domains (sub-domains most often) are often free and hosted by OAST tool providers like interact.sh. What happens when something is free on the Internet? It gets abused. Let’s make tOAST of the most commonly abused OAST...
-
Post #642936
RE: https://infosec.exchange/@patrickcmiller/116210592807071943 Here are some controls to put in place to prevent this attack from happening to you: - Block ISO file extensions from being emailed to your users - Prevent downloads of ISO files from untrusted sites (such as consumer friendly file storage services) - Change your Windows File Explorer settings to associate the .ISO file extension with Notepad.exe so it won’t auto mount when double-clicked #cybersecurity
-
Post #642935
RE: https://mastodon.social/@verge/116212236350531341 This shouldn’t baffle anyone. This is a transactional administration and clearly the right people were paid off. #uspol
-
Post #493718
RE: https://infosec.exchange/@merill/116096226364016976 This should be handy for Microsoft SysAdmins. I ran into an issue with old modules recently and I’m going to try this out. Merill is a trusted source for this sort of stuff and happens to work for Microsoft. #powershell
-
Post #493716
Geoshitties for the win! If you use @badsamurai ‘s blocklists you’d have already blocked *.vercel.app which is a key link in the kill chain for this attack described by Microsoft. My advice: block Vercel for everyone in your org except for those that have a business need. #cybersecurity https://www.microsoft.com/en-us/security/blog/2026/02/24/c2-developer-targeting-campaign/
-
Post #493714
RE: https://swecyb.com/@orlysec/116144639827797601 Maybe you’ve noticed that I’ve repeatedly recommended that you should block access to *.vercel.app ? Well, here are 31 more reasons. Also, block pastebin.com too. #cybersecurity
-
Post #493713
RE: https://mastodon.social/@scalzi/116138157607069357 #catsofmastodon #caturday
-
Post #493712
A new-to-me #Porter: Tupac Shaporter from Ivanhoe Park Brewing Co. in Orlando, FL. #beersofmastodon #beer