/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Dan Black

@danwblack
21 posts
2025-04-15
Credibility of claims aside, the slow creep toward direct mirroring of US public attribution has reached its final stop:  —  www.reuters.com/technology/c...
2025-04-15 View on X
Reuters

Chinese state media: police in Harbin accuse the NSA of launching “advanced” cyberattacks during the Asian Winter Games in February 2025 and name three agents

Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) …

2025-02-19
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. https://cloud.google.com/...
2025-02-19 View on X
Wired

Signal updates its app with phishing protections after Google warned Russia-linked hackers are using fake QR codes for group invites to trick Ukrainian soldiers

Google warns that hackers tied to Russia are tricking Ukrainian soldiers with fake QR codes for Signal group invites that let spies steal their messages.

We judge this emerging operational interest has likely been sparked by wartime demands to gain access to sensitive government and military communications, and is part of Russia's wider shift in focus to Ukraine's frontlines as the war turned attritional. https://www.rusi.org/...
2025-02-19 View on X
Wired

Signal updates its app with phishing protections after Google warned Russia-linked hackers are using fake QR codes for group invites to trick Ukrainian soldiers

Google warns that hackers tied to Russia are tricking Ukrainian soldiers with fake QR codes for Signal group invites that let spies steal their messages.

2024-10-23
The search for precise mass is also an apt way to explain Russia's approach to sustaining cyber effects in Ukraine (and it's wartime arsenal management strategy more generally). More effort needed to ground cyber conflict research within the “cheap, scalable, attritable” arc
2024-10-23 View on X
Foreign Affairs

How advances in AI and autonomous systems, new tech, and lower costs are shifting global wars towards “precise mass”, or the mass deployment of uncrewed systems

"Militaries are beginning to realize that they don't have to choose between precision and mass; they can have both." https://www.foreignaffairs.com/ ... Shashank Joshi / @shashj : ...

2024-09-07
An astute observation in Andy's piece that is often lost in the mirroring-imaging fueled rush to judgment common in analyses of Russia's cyber campaigns. “Success is measured differently in the Western world and Russia”
2024-09-07 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

There has been a lot of talk this week about Putin paying “useful idiots” to spread his propaganda. … X: @dojnatsec : Five Russian GRU Officers and One Civilian Charged for Conspir...

14 services in 10 countries. 🔥🔥🔥 Operation Toy Soldier is a remarkable feat of collective counterintelligence action, exposing an aggressive cyber campaign against Ukraine and NATO, now linked to one of the GRU's most brazen elements. #StrongerTogether
2024-09-07 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

There has been a lot of talk this week about Putin paying “useful idiots” to spread his propaganda. … X: @dojnatsec : Five Russian GRU Officers and One Civilian Charged for Conspir...

WhisperGate attack (rel Cadet Blizzard, UNC2589) linked to Unit 29155: “Five of the defendants were officers in Unit 29155 of the Russian Main Intelligence Directorate (GRU), a military intelligence agency of the General Staff of the Armed Forces.” https://www.justice.gov/...
2024-09-07 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

There has been a lot of talk this week about Putin paying “useful idiots” to spread his propaganda. … X: @dojnatsec : Five Russian GRU Officers and One Civilian Charged for Conspir...

2024-09-06
An astute observation in Andy's piece that is often lost in the mirroring-imaging fueled rush to judgment common in analyses of Russia's cyber campaigns. “Success is measured differently in the Western world and Russia”
2024-09-06 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

Unit 29155 of Russia's GRU military intelligence agency—a team responsible for coup attempts, assassinations, and bombings …

WhisperGate attack (rel Cadet Blizzard, UNC2589) linked to Unit 29155: “Five of the defendants were officers in Unit 29155 of the Russian Main Intelligence Directorate (GRU), a military intelligence agency of the General Staff of the Armed Forces.” https://www.justice.gov/...
2024-09-06 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

Unit 29155 of Russia's GRU military intelligence agency—a team responsible for coup attempts, assassinations, and bombings …

14 services in 10 countries. 🔥🔥🔥 Operation Toy Soldier is a remarkable feat of collective counterintelligence action, exposing an aggressive cyber campaign against Ukraine and NATO, now linked to one of the GRU's most brazen elements. #StrongerTogether
2024-09-06 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

Unit 29155 of Russia's GRU military intelligence agency—a team responsible for coup attempts, assassinations, and bombings …

2024-08-30
Important report highlighting the SVR's wider enablers: “In each iteration of the watering hole campaigns, [APT29] used exploits that were identical or strikingly similar to exploits previously used by commercial surveillance vendors Intellexa and NSO Group.”
2024-08-30 View on X
TechCrunch

Google says Russia-linked APT29 is using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group

«Russian government hackers found using #exploits made by spyware companies NSO and Intellexa: … Frederic Jacobs / @fj@mastodon.social : “Our latest n-day exploit reporting shows t...

2024-08-29
Important report highlighting the SVR's wider enablers: “In each iteration of the watering hole campaigns, [APT29] used exploits that were identical or strikingly similar to exploits previously used by commercial surveillance vendors Intellexa and NSO Group.”
2024-08-29 View on X
TechCrunch

Google says Russia-linked APT29 is using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group

Google says it has evidence that Russian government hackers are using exploits that are “identical or strikingly similar” …

2024-04-17
Also known commonly as the GRU's Main Centre for Special Technologies (GTsST) or Unit 74455 - APT44 has been at it for the better part of 15 years. Publicly available images of its anniversary insignia place the unit's formation in 2009. [image]
2024-04-17 View on X
Wired

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

Over a decade in the making: Sandworm is now APT44. Below is a thread with some major takeaways and insights from our new report: https://cloud.google.com/...
2024-04-17 View on X
Wired

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

2024-01-19
New blog from Google's TAG (@wxs) outing some elusive COLDRIVER (UNC4057) malware tracked as SPICA: “Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware” https://blog.google/...
2024-01-19 View on X
TechCrunch

Google's TAG says Russia-linked hacking group Cold River is ramping up its activity and using new tactics, like data-stealing malware, to cause more disruption

Carly Page / TechCrunch :

2023-12-09
Notable the US-UK trade leaks were confidently linked to COLDRIVER (and by extension, Center 18 of the FSB) in the briefing. Begs the question of whether the FSB is also responsible for Secondary Infektion (the series of forged letters that overlap tactically with the leaks)
2023-12-09 View on X
Wall Street Journal

The US and the UK accuse Russia's FSB of orchestrating a global hacking campaign since 2015 to interfere in UK elections and target US energy networks and spies

2023-12-08
Notable the US-UK trade leaks were confidently linked to COLDRIVER (and by extension, Center 18 of the FSB) in the briefing. Begs the question of whether the FSB is also responsible for Secondary Infektion (the series of forged letters that overlap tactically with the leaks)
2023-12-08 View on X
Wall Street Journal

The US and the UK accuse Russia's FSB of orchestrating a global hacking campaign since 2015 to interfere in UK elections and target US energy networks and spies

The cyberattacks also allegedly took aim at U.S. energy networks and American spies  —  LONDON—The U.S. and U.K. governments …

2023-12-07
Notable the US-UK trade leaks were confidently linked to COLDRIVER (and by extension, Center 18 of the FSB) in the briefing. Begs the question of whether the FSB is also responsible for Secondary Infektion (the series of forged letters that overlap tactically with the leaks)
2023-12-07 View on X
The Record

The UK accuses a unit of Russia's FSB of using cyberattacks in a “sustained but unsuccessful” campaign to undermine democratic institutions since 2015

The British government accused a unit of Russia's Federal Security Service (FSB) on Thursday of using cyberattacks in a …

2023-11-09
New today from @Mandiant detailing a new class of cyber physical attack from Sandworm to disrupt Ukraine's grid This attack departs from the group's history of using OT-specific malware, instead opting for a harder to detect living off the land approach https://www.mandiant.com/...
2023-11-09 View on X
Wired

Mandiant: Russia-tied Sandworm carried out a third successful attack on Ukraine's electric utility in October 2022, coinciding with a series of missile strikes

Russia's most notorious military hackers successfully sabotaged Ukraine's power grid for the third time last year.

2023-08-30
“In July, an attack that was disguised as a ransomware incident temporarily closed down the port of Nagoya. It has since been assessed by government cyber experts as part of a “persistent testing of Japan's infrastructural defences by China”.”
2023-08-30 View on X
Financial Times

Sources: Chinese-backed hackers breached Japanese cybersecurity agency NISC's email system; experts link the July 4 ransomware attack on Port of Nagoya to China

Infiltration comes as allies scrutinise Tokyo's defences against hacking  —  The organisation responsible for Japan's national defences …