/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Ryan Naraine

@ryanaraine
73 posts
2025-10-16
We learn of a F5 Networks breach by “a highly sophisticated nation-state” from an SEC filing: https://www.sec.gov/...
2025-10-16 View on X
Bloomberg

Sources: F5 blames its breach on state-backed hackers from China who used the Brickstorm malware to infiltrate its network for 12+ months and steal source code

A potentially “catastrophic” breach of a major US-based cybersecurity provider has been blamed on state-backed hackers from China …

2025-09-10
Shoutout to Apple for shipping the most important things! https://security.apple.com/...
2025-09-10 View on X
The Verge

Apple says the iPhone 17 and iPhone Air have Memory Integrity Enforcement, “industry-first, always-on memory safety protection”, like Microsoft and Google offer

Memory Integrity Enforcement is always-on safety protection designed to make life harder for spyware developers.

2024-10-24
Another day, another Fortinet 0day exploited in the wild https://www.securityweek.com/ ...
2024-10-24 View on X
BleepingComputer

Fortinet discloses a critical FortiManager API flaw being exploited in 0-day attacks to steal sensitive files, after warning customers privately over a week ago

Fortinet publicly disclosed today a critical FortiManager API vulnerability, tracked as CVE-2024-47575, that was exploited …

2024-09-25
First question at CrowdStrike hearing: “Who pushed the update? Did AI do that?” ☠️
2024-09-25 View on X
CyberScoop

CrowdStrike SVP Adam Meyers apologizes before Congress over the company's faulty update that caused a global IT outage, to largely sympathetic House lawmakers

House lawmakers struck a sympathetic tone toward the company at a hearing where they nevertheless said nothing like that could happen again.

2024-09-14
Apple has abruptly withdrawn its lawsuit against NSO Group, citing increased risk that the legal battle might unintentionally reveal sensitive vulnerability data to the very adversaries involved in the legal dispute. https://www.securityweek.com/ ...
2024-09-14 View on X
Washington Post

Apple files to drop its NSO suit, citing Israeli government's alleged seizure of NSO files, and saying Apple's court disclosures may aid NSO and other hackers

Joseph Menn / Washington Post :

2024-08-28
Black Lotus Labs documentation is live https://blog.lumen.com/... @BlackLotusLabs YARA rule for hunting https://github.com/...
2024-08-28 View on X
Washington Post

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Joseph Menn / Washington Post :

“'Volt Typhoon' is actually a ransomware cybercriminal group who calls itself the ‘Dark Power’ and is not sponsored by any state or region,” said embassy spokesman Liu Pengyu. WaPo's @josephmenn with a banger of a quote! https://www.washingtonpost.com/ ...
2024-08-28 View on X
Washington Post

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Joseph Menn / Washington Post :

The high-risk vuln (CVE-2024-39717) was added to the CISA must-patch list over the weekend after Versa Networks confirmed zero-day exploitation @SecurityWeek Black Lotus Labs links exploitation to Volt Typhoon APT and says ISPs and MSPs are downstream targets 👇👇
2024-08-28 View on X
Washington Post

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Joseph Menn / Washington Post :

2024-08-27
Black Lotus Labs documentation is live https://blog.lumen.com/... @BlackLotusLabs YARA rule for hunting https://github.com/...
2024-08-27 View on X
Washington Post

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Beijing's hacking effort has “dramatically stepped up from where it used to be,” says former top U.S cybersecurity official.

The high-risk vuln (CVE-2024-39717) was added to the CISA must-patch list over the weekend after Versa Networks confirmed zero-day exploitation @SecurityWeek Black Lotus Labs links exploitation to Volt Typhoon APT and says ISPs and MSPs are downstream targets 👇👇
2024-08-27 View on X
Washington Post

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Beijing's hacking effort has “dramatically stepped up from where it used to be,” says former top U.S cybersecurity official.

2024-05-14
Note: RTKit is Apple's realtime embedded OS that runs on all devices and has been targeted/hit in previous 0day attacks See: https://support.apple.com/...
2024-05-14 View on X
MacRumors

Apple releases iOS 17.5 with cross-platform detection of unwanted tracking devices, EU app downloads from websites, News+ features like offline mode, and more

Apple today released iOS 17.5 and iPadOS 17.5, major updates to the iOS 17 and iPadOS 17 operating system updates that came out last September.

Apple documents at least 16 vulnerabilities on iPhones and iPads and called special attention to CVE-2024-23296, a memory corruption bug in RTKit that the company says “may have been exploited” prior to the availability of patches Story https://www.securityweek.com/ ...
2024-05-14 View on X
MacRumors

Apple releases iOS 17.5 with cross-platform detection of unwanted tracking devices, EU app downloads from websites, News+ features like offline mode, and more

Apple today released iOS 17.5 and iPadOS 17.5, major updates to the iOS 17 and iPadOS 17 operating system updates that came out last September.

2024-03-22
Great line from the DOJ complaint: “Apple users could use their iPod with a Windows computer, and Microsoft did not charge Apple a 30 percent fee for each song downloaded from Apple's iTunes store.”
2024-03-22 View on X
The Verge

In its lawsuit, the US DOJ alleges CarPlay lets Apple exert too much control over the auto industry; some analysts say the DOJ may be misunderstanding CarPlay

Buried in the 88-page antitrust lawsuit filed by the US Department of Justice against Apple is a reference to everyone's favorite phone-projection system, CarPlay.

Great line from the DOJ complaint: “Apple users could use their iPod with a Windows computer, and Microsoft did not charge Apple a 30 percent fee for each song downloaded from Apple's iTunes store.”
2024-03-22 View on X
TechCrunch

The US DOJ's Apple lawsuit has many parallels to its Microsoft lawsuit in the 1990s, but Apple's monopoly position is not nearly as clear-cut as Microsoft's was

“Apple inhibits third-party smartwatches from maintaining a reliable connection with the iPhone.”  —  To be fair, Apple does that to its own smartwatches too. X: Charles Arthur / @...

2023-12-08
Microsoft announces a major shakeup of its security hierarchy, removing the CISO and Deputy CISO and handing the reins to a recent hire who previously served as CTO and President at Bridgewater. Interesting times https://www.securityweek.com/ ...
2023-12-08 View on X
SiliconANGLE

Microsoft announces a major security leadership reshuffle as part of its Secure Future Initiative, replacing Bret Arsenault with Igor Tsyganskiy as Global CISO

2023-10-11
0days everywhere 👀 Cloudflare, Google and AWS on a new zero-day named ‘HTTP/2 Rapid Reset’ being exploited by malicious actors to launch “the largest distributed denial-of-service (DDoS) attacks in internet history” https://www.securityweek.com/ ... <- reporting by @EduardKovacs
2023-10-11 View on X
The Record

Amazon, Google, and Cloudflare say a DDoS attack hit 398M RPS in August 2023, ~8x larger than the prior record, due to a new flaw; Google mitigated the attack

Assigner: Mitre Published: 2023-10-10Updated: 2023-10-11 The HTTP/2 protocol allows … Bill Toulas / BleepingComputer : New ‘HTTP/2 Rapid Reset’ zero-day attack breaks DDoS records ...

2023-09-10
@wdormann agree. the decision to withhold the name of the software package is so odd.
2023-09-10 View on X
Ars Technica

Google says North Korea-backed hackers are again targeting security researchers via a zero-day exploit; this still unfixed flaw is in a popular software package

Google researchers say currently unfixed vulnerability affects a popular software package.  —  North Korea-backed hackers …

2023-09-09
@wdormann agree. the decision to withhold the name of the software package is so odd.
2023-09-09 View on X
Ars Technica

Google says North Korea-backed hackers are targeting security researchers with an exploit using a currently unfixed zero-day flaw in a popular software package

Google researchers say currently unfixed vulnerability affects a popular software package.  —  North Korea-backed hackers …

2023-08-26
Microsoft: “Because this activity relies on valid accounts and living-off-the-land binaries (LOLBins), detecting and mitigating this attack could be challenging. Compromised accounts must be closed or changed.” https://www.securityweek.com/ ...
2023-08-26 View on X
CyberScoop

Microsoft says Flax Typhoon, a hacking group active since mid-2021 with suspected Beijing ties, is targeting dozens of organizations in Taiwan, and elsewhere

AJ Vicens / CyberScoop :

2023-08-25
Microsoft: “Because this activity relies on valid accounts and living-off-the-land binaries (LOLBins), detecting and mitigating this attack could be challenging. Compromised accounts must be closed or changed.” https://www.securityweek.com/ ...
2023-08-25 View on X
CyberScoop

Microsoft researchers say Flax Typhoon, a hacking group with suspected links to the Chinese government, is actively targeting dozens of organizations in Taiwan

A group dubbed Flax Typhoon has targeted “dozens” of Taiwanese organizations, according to new research from Microsoft.