/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Robert M. Lee

@robertmlee
22 posts
2022-08-25
Hey @Twitter while y'all deal with the @dotMudge allegations resorting to a smear campaign against him is a really stupid idea. His character, skills, leadership, etc. are some of the most beloved and well documented in the community. Your response is telling. Focus on the facts.
2022-08-25 View on X
Washington Post

Peiter Zatko will testify before the Senate Judiciary Committee on September 13 to examine his allegations of widespread security failures at Twitter

Peiter Zatko will appear before the Senate Judiciary Committee next month pursuant to a subpoena  —  Twitter whistleblower Peiter Zatko …

2022-08-24
Hey @Twitter while y'all deal with the @dotMudge allegations resorting to a smear campaign against him is a really stupid idea. His character, skills, leadership, etc. are some of the most beloved and well documented in the community. Your response is telling. Focus on the facts.
2022-08-24 View on X
Washington Post

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

Hey @Twitter while y'all deal with the @dotMudge allegations resorting to a smear campaign against him is a really stupid idea. His character, skills, leadership, etc. are some of the most beloved and well documented in the community. Your response is telling. Focus on the facts.
2022-08-24 View on X
Washington Post

A profile of Peiter Zatko, aka Mudge, who worked at DARPA, Google, and Stripe before Twitter, and was a member of hacker groups L0pht and Cult of the Dead Cow

From the L0pht and Cult of the Dead Cow to DARPA and Google, Peiter ‘Mudge’ Zatko took unorthodox approaches to ‘make a dent in the universe’

2022-04-14
Today the US Government announced a new ICS malware that has been designed to disrupt industrial operations. CISA/FBI/NSA put out a great advisory; also I appreciate the callout/thanks to @DragosInc in the advisory - we call the malware PIPEDREAM https://www.cisa.gov/...
2022-04-14 View on X
The Record

US government agencies warn of new custom tools, created by several APT actors, that are capable of compromising IT equipment used in critical infrastructure

Several advanced persistent threat (APT) actors have created custom-made tools designed to breach IT equipment used … Source: CISA .

This is the first time, I'm aware of, that an industrial cyber capability has been found *prior* to its deployment for intended effects. This capability was designed to be disruptive/destructive in nature - and we're actually a step ahead of the adversary.
2022-04-14 View on X
The Record

US government agencies warn of new custom tools, created by several APT actors, that are capable of compromising IT equipment used in critical infrastructure

Several advanced persistent threat (APT) actors have created custom-made tools designed to breach IT equipment used … Source: CISA .

2022-03-26
I'm glad CISA is providing a companion document w/ the DOJ indictment of the Russian govt operators who targeted ICS. Lots of great info but please don't follow their mitigation advice for ICS. It's not practical & in some cases dangerous. A quick thread: https://us-cert.cisa.gov/...
2022-03-26 View on X
New York Times

The DOJ charges four Russian officials for alleged hacking campaigns from 2012 to 2018 on critical US infrastructure, including a Kansas nuclear power plant

Saturday, March 26, 2022 // (IG): BB //Weekly Sponsor: DiyGarage SoCal Gary Warner / CyberCrime & Doing Time : Russia's Invasion of Ukraine and CISA/FBI's New Era of Transparency C...

2022-03-25
I'm glad CISA is providing a companion document w/ the DOJ indictment of the Russian govt operators who targeted ICS. Lots of great info but please don't follow their mitigation advice for ICS. It's not practical & in some cases dangerous. A quick thread: https://us-cert.cisa.gov/...
2022-03-25 View on X
New York Times

The DOJ charges four Russian officials for alleged hacking campaigns from 2012 to 2018 on critical US infrastructure, including a Kansas nuclear power plant

The announcement covered hackings from 2012 to 2018, but served as yet another warning from the Biden administration of Russia's ability to conduct such operations.

2021-07-17
I've said it before but I've never once judged foreign intelligence agencies doing espionage. I try to stop them. My team your team. I get it. But hacker for hire groups...targeting of journalists and dissidents...my words here would be too coarse. I'd hope they all rot. https://twitter.com/...
2021-07-17 View on X
VICE

Microsoft and Citizen Lab say government hackers from several countries have used spyware from Israeli vendor Candiru that uses two 0-day exploits in Windows

2021-07-16
I've said it before but I've never once judged foreign intelligence agencies doing espionage. I try to stop them. My team your team. I get it. But hacker for hire groups...targeting of journalists and dissidents...my words here would be too coarse. I'd hope they all rot. https://twitter.com/...
2021-07-16 View on X
VICE

Microsoft and Citizen Lab say government hackers from several countries have used spyware from Israeli vendor Candiru that uses two 0-day exploits in Windows

Microsoft and Citizen Lab found a new kind of spyware made by the mysterious Israeli vendor Candiru, and targeting someone in Europe based on their political beliefs.

2021-07-04
Good thread on the Kaseya ransomware event. Also - thinking about all the security staff and incident responders who just had their weekend ruined, if we can't stop criminals it'd be nice to at least have some norms around weekends and holidays. https://twitter.com/...
2021-07-04 View on X
BleepingComputer

REvil is pushing ransomware via an update for Kaseya's IT management software, hitting hundreds of managed service providers with thousands of customers

A massive REvil ransomware attack affects multiple managed service providers and their clients through a reported Kaseya supply-chain attack.

2021-07-02
A very well done report and just mostly excited to see this level of transparency and public reporting out of NSA. They've wanted to be here for a long time, getting the internal approvals to do things are hard, but looks like they've made significant strides https://twitter.com/...
2021-07-02 View on X
The Record

NSA, FBI, and others say Russian hacking group Fancy Bear has been using Kubernetes to run brute force attacks on US and foreign organizations since mid-2019

essentially, trying different passwords until the attackers gained access — and then use other known software vulnerabilities to steal emails, compromise other accounts and collect...

2021-05-10
Good reporting by Ellen with quotes from me. The reality is ransomware is becoming more pervasive in both IT and OT networks, impacts in IT can impact operations as well. https://twitter.com/...
2021-05-10 View on X
Wall Street Journal

Colonial Pipeline, which carries 45% of fuel consumed on the US East Coast, says it halted operations due to a ransomware attack

Colonial Pipeline carries roughly 45% of gasoline and diesel fuel consumed on the East Coast  —  The main pipeline carrying gasoline and diesel fuel …

Good reporting by Ellen with quotes from me. The reality is ransomware is becoming more pervasive in both IT and OT networks, impacts in IT can impact operations as well. https://twitter.com/...
2021-05-10 View on X
Bloomberg

Sources: cybercrime gang DarkSide, which caused Colonial Pipeline to halt operations, stole and encrypted ~100GB of data on Thursday before demanding a ransom

> The hackers who caused Colonial Pipeline to shut down the biggest U.S. gas pipe on Friday began their blitz against the co. a day earlier, stealing a large amount of data before ...

2021-05-09
Good reporting by Ellen with quotes from me. The reality is ransomware is becoming more pervasive in both IT and OT networks, impacts in IT can impact operations as well. https://twitter.com/...
2021-05-09 View on X
Wall Street Journal

Colonial Pipeline, which carries 45% of fuel consumed on the US East Coast, says it halted operations due to a ransomware attack

Colonial Pipeline carries roughly 45% of gasoline and diesel fuel consumed on the East Coast  —  The main pipeline carrying gasoline and diesel fuel …

2021-04-13
Agree. Anne as NSC/White House cyber lead has already been amazing, if we're going to have an NCD having it be Chris Inglis is outstanding. Jen as CISA lead and grabbing Rob for Undersecretary - a very powerful, well informed, and passionate team with been there done that exp. https://twitter.com/...
2021-04-13 View on X
Washington Post

Biden administration announces the nominations of ex-NSA deputy director Chris Inglis as first national cyber director and Jen Easterly as CISA head

2021-04-12
Agree. Anne as NSC/White House cyber lead has already been amazing, if we're going to have an NCD having it be Chris Inglis is outstanding. Jen as CISA lead and grabbing Rob for Undersecretary - a very powerful, well informed, and passionate team with been there done that exp. https://twitter.com/...
2021-04-12 View on X
Washington Post

Biden administration announces the nominations of ex-NSA deputy director Chris Inglis as first national cyber director and Jen Easterly as CISA head

The Biden administration plans on Monday to name a former senior National Security Agency official as the first national cyber director …

2021-01-16
Apparently there's hope - congrats and thank you @RGB_Lights https://twitter.com/...
2021-01-16 View on X
CyberScoop

Rob Joyce will replace Anne Neuberger as the director of NSA's Cybersecurity Directorate; Neuberger will join the Biden admin as deputy adviser on the NSC

Shannon Vavra / CyberScoop :

2020-12-15
Fantastic report by FireEye on the SolarWinds supply chain compromise into organizations around the community including the FireEye intrusion: https://www.fireeye.com/... great insights for defenders to go burn the adversary's efforts to the ground
2020-12-15 View on X
Reuters

SolarWinds: under 18,000 customers were compromised between March and June via an update to its Orion software, leading to DHS, Treasury, Commerce Dept. hacks

LONDON/WASHINGTON (Reuters) - U.S. IT company SolarWinds said on Monday that up to 18,000 of its customers had downloaded …

2020-12-09
Going to be a lot of folks that dunk on FireEye for this but from my quick review they found it themselves and self disclosed. Everyone gets breached. Kudos to Kevin and the team for detecting and responding well. https://twitter.com/...
2020-12-09 View on X
Wall Street Journal

FireEye says some internal systems were hacked by nation state actors, compromising its Red Team tools, used to test the defenses of its thousands of customers

The cybersecurity company said the attack compromised its software tools used to test the defenses of its thousands of customers

2020-10-24
This style of sanctioning is significant and honestly entirely appropriate against those involved in the first ever cyber attack to intentionally try to kill people in civilian infrastructure. #TRISIS #TRITON https://home.treasury.gov/...
2020-10-24 View on X
ZDNet

US Treasury imposes sanctions against Russian research institute for its role in developing the Triton malware

US imposes sanctions against Russia's Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM).  —  The US Treasury Department announced sanctions today …