Gotta hand it to General Motors for their absolute dedication to defensively registering domains based on threat intel....as I page through all the domains they registered to match ShinyHunters phishing patterns.
Sean Gallagher
🐀 
Security Research Engineer @Cisco Talos. Past: Natsec/Infosec Editor Emeritus @ Ars Technica. Ex Navy officer and actual battleship sailor. Verified cat furniture. Bird paparazzo. Still mostly s***posting as @thepacketrat@twitter.com. Also federating @thepacketrat@mastodon.social and @thepacketrat@mastodon.sdf.org
The Clickfix-in-browser scammers have switched to a new target site for their fake exploit lure to draw in crypto-hungry skids: https://docs.google.com/document/d/1Cz5fHkwyaApTWwqfgBBtpvConU8Lo_qJ9xtn7RazWpk/edit?tab=t.0
I wrote a thing about some weird stuff. https://blog.talosintelligence.com/clickfix-moves-into-the-browser/
Ten years ago this month, the DNC got hacked and emails were leaked by Russian intelligence ("Fancy Bear" and "Cozy Bear", as per CrowdStrike).
Why does it feel like it's been twice as long as that?
So you know how the mobile companies said they were shutting down their SMS-to-email gateways?
Not so much.

