/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Selena Larson

@selenalarson
40 posts
2025-06-03
lol, lmao www.crowdstrike.com/en-us/blog/ c...  (I actually think this is a good idea and have complained about actor naming for years but both these companies are #1 in “attribution is marketing” so it is very funny to see)
2025-06-03 View on X
Reuters

Microsoft, Google, CrowdStrike, and Palo Alto Networks plan to create a public glossary of state-sponsored hacking groups to ease unofficial alias confusion

Microsoft, CrowdStrike, Palo Alto (PANW.O) and Alphabet's (GOOGL.O) Google on Monday said they would create a public glossary …

2025-05-23
Also shoutout to ongoing Operation Endgame efforts, of which this was a part.  But also!  Qbot baddie aka Cortes!! www.justice.gov/opa/pr/leade...  Please watch the Endgame video for him: operation-endgame.com
2025-05-23 View on X
BleepingComputer

The US DOJ indicts a Russian national for allegedly leading the Qakbot malware operation that infected 700K+ computers and enabled ransomware attacks for years

The U.S. government has indicted Russian national Rustam Rafailevich Gallyamov, the leader of the Qakbot botnet malware operation …

2022-04-14
Now that is quite an assessment: “INCONTROLLER poses the greatest threat to Ukraine, NATO member states, and other states actively responding to Russia's invasion of Ukraine.” https://www.mandiant.com/...
2022-04-14 View on X
The Record

US government agencies warn of new custom tools, created by several APT actors, that are capable of compromising IT equipment used in critical infrastructure

Several advanced persistent threat (APT) actors have created custom-made tools designed to breach IT equipment used … Source: CISA .

2022-04-13
Very cool to see these ICS security firms coming together to advocate for the greater good. Personally I don't think much will change unless companies face penalties for not having robust cybersecurity. https://www.wsj.com/...
2022-04-13 View on X
Bloomberg

A group of cybersecurity companies specializing in securing US critical infrastructure form a coalition to work with the government and adopt uniform standards

A group of cybersecurity companies that specialize in securing critical infrastructure said Tuesday they've formed a lobbying group … Source: Yahoo Finance .

2022-01-22
something's rotten in the state of twitter https://twitter.com/...
2022-01-22 View on X
New York Times

Twitter terminated its head of security Peiter “Mudge” Zatko this week, and CISO Rinki Sethi will depart in the coming weeks; both execs joined Twitter in 2020

Market summary: 📊  —  Brutal week in the market finally ends. Steve Zurier / scmagazine.com : What's it mean? Making sense of Twitter's decision to oust ‘Mudge’ Zatko and Rinki Set...

2021-12-02
This predictive policing software (PredPol) has been in use for a decade, and The Markup/Gizmodo bombshell investigation found that the it was disproportionately predicting crimes in Black and Latino neighborhoods. https://themarkup.org/... https://twitter.com/... https://twitter.com/...
2021-12-02 View on X
The Markup

Investigation finds US predictive policing tool PredPol, used countrywide, often perpetuates biases, directing police to poor, Black, and Latino neighborhoods

Plainfield, N.J. Plainfield, N.J. Los Angeles  —  Orange County, Fla.

2021-11-09
This is awesome. Though half a million euros is less than some of the individual ransoms paid out to REvil. Hope they keep grabbing the affiliates to eventually take down the operators! https://twitter.com/...
2021-11-09 View on X
CNN

US charges a Ukrainian suspect, arrested in Poland last month, and a Russian citizen over REvil attacks, and says it seized $6M in ransom payments

(CNN)Law enforcement officials have seized an estimated $6 million in ransom payments, and the US Justice Department is expected to announce Monday …

This is awesome. Though half a million euros is less than some of the individual ransoms paid out to REvil. Hope they keep grabbing the affiliates to eventually take down the operators! https://twitter.com/...
2021-11-09 View on X
The Record

Europol has arrested seven people suspected of helping REvil and GandCrab with over 7,000 cyberattacks since early 2019, in a Romanian-led investigation

Catalin Cimpanu / The Record :

2021-11-04
I like to think of this as a warehouse full of unopened packages the government is sucking up and storing away until they can find the right box cutter to open them all https://www.technologyreview.com/ ...
2021-11-04 View on X
MIT Technology Review

How US agencies are preparing for “post-quantum cryptography” against attackers who harvest sensitive data now for decryption in the future

The US government is starting a generation-long battle against the threat next-generation computers pose to encryption. Tweets: @techreview , @techreview , @aarongrunwald , @statec...

2021-07-16
Incredible work here, and I appreciate the detailing of all the hunting and pivots that went into it https://citizenlab.ca/...
2021-07-16 View on X
VICE

Microsoft and Citizen Lab say government hackers from several countries have used spyware from Israeli vendor Candiru that uses two 0-day exploits in Windows

Microsoft and Citizen Lab found a new kind of spyware made by the mysterious Israeli vendor Candiru, and targeting someone in Europe based on their political beliefs.

2021-07-09
This piece has everything. Fun code names, criminal kingpins, Ukrainian corruption, vodka diplomacy, cybercrime connections to Russian intelligence, and the origin story of one of today's biggest cybercriminal operations. https://twitter.com/...
2021-07-09 View on X
MIT Technology Review

How a years-long cybercrime investigation by FBI, Russia, and Ukraine was undone by corruption, rivalry, and stonewalling, resulting in the hackers going free

2021-04-16
today's sanctions confirmed what many people suspected: fsb working with evil corp https://home.treasury.gov/... https://twitter.com/...
2021-04-16 View on X
MIT Technology Review

A look at Positive Technologies, a Russian cybersecurity firm sanctioned by the US, which sources say provides hacking tools and ops support for Russian spies

Washington has sanctioned Russian cybersecurity firm Positive Technologies.  US intelligence reports claim it provides hacking tools and runs operations for the Kremlin.

2021-02-05
It is absolutely unconscionable how Amazon treats its workers. https://twitter.com/...
2021-02-05 View on X
VICE

Amazon is quietly transitioning its US warehouse workers to 10-hour graveyard shifts; labor experts say the move is to cut costs and pay for fewer benefits

Lauren Kaori Gurley / VICE :

2021-01-21
The “SolarWinds actor” has been busy. And we've likely only seen a small fraction of its activities. Interesting similarities in using/exploiting MSFT cloud services for reconnaissance activities. Mimecast: https://www.reuters.com/... Malwarebytes:https://blog.malwarebytes. com/ ...
2021-01-21 View on X
ZDNet

Malwarebytes says it was hacked by group that breached SolarWinds, via Azure and Office 365 exploits, but attackers only accessed a subset of internal emails

Moar SolarWinds related malware. Really interesting to see how this is all unfolding in the weeks since the attack was first revealed. https://twitter.com/...
2021-01-21 View on X
ZDNet

Malwarebytes says it was hacked by group that breached SolarWinds, via Azure and Office 365 exploits, but attackers only accessed a subset of internal emails

2021-01-20
Moar SolarWinds related malware. Really interesting to see how this is all unfolding in the weeks since the attack was first revealed. https://twitter.com/...
2021-01-20 View on X
ZDNet

Malwarebytes says it was hacked by group that breached SolarWinds, via Azure and Office 365 exploits, but attackers only accessed a subset of internal emails

Malwarebytes becomes fourth major security firm targeted by attackers after Microsoft, FireEye, and CrowdStrike.

The “SolarWinds actor” has been busy. And we've likely only seen a small fraction of its activities. Interesting similarities in using/exploiting MSFT cloud services for reconnaissance activities. Mimecast: https://www.reuters.com/... Malwarebytes:https://blog.malwarebytes. com/ ...
2021-01-20 View on X
ZDNet

FireEye releases a free tool that audits networks to determine whether certain techniques, known to be employed by SolarWinds hackers, were used

Focusing on UNC2452 TTPs Lily Hay Newman / Wired : The SolarWinds Hackers Used Tactics Other Groups Will Copy Zeljka Zorz / Help Net Security : Malwarebytes was breached by the Sol...

2020-11-15
New blog from Microsoft details ongoing activity targeting COVID-19 researchers and vaccine development. Also goes hard on the need for international laws to protect healthcare facilities from cyberattacks. 👏https://blogs.microsoft.com/ ...
2020-11-15 View on X
ZDNet

Microsoft says it detected three APTs, from N. Korea and Russia, that launched attacks on at least seven companies developing a COVID-19 vaccine or treatments

The three state-sponsored hacker groups (APTs) are Russia's Strontium (Fancy Bear) and North Korea's Zinc (Lazarus Group) and Cerium.

2020-11-14
New blog from Microsoft details ongoing activity targeting COVID-19 researchers and vaccine development. Also goes hard on the need for international laws to protect healthcare facilities from cyberattacks. 👏https://blogs.microsoft.com/ ...
2020-11-14 View on X
ZDNet

Microsoft says it detected three APTs, from N. Korea and Russia, that launched attacks on at least seven companies developing a COVID-19 vaccine or treatments

The three state-sponsored hacker groups (APTs) are Russia's Strontium (Fancy Bear) and North Korea's Zinc (Lazarus Group) and Cerium.

2020-09-19
ah yes i see the u.s. is taking a measured, understandable approach to this whole thing https://twitter.com/...
2020-09-19 View on X
VICE

Banning TikTok from US app stores but allowing it to operate until Nov. 12 prevents TikTok from patching any security vulnerabilities found in the meantime

a move which is shortsighted, ridiculous, and likely unconstitutional. https://www.nytimes.com/... SIX / @sixiaotang : Tiktok will be fine; the no-compromise loss of WeChat access ...