/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

@uuallan

@uuallan
23 posts
2024-08-28
As someone who has been inside telecom networks, going from “gathering intelligence” to shutting things down is just a matter of orders. Great reporting from ⁦@josephmenn⁩ https://www.washingtonpost.com/ ...
2024-08-28 View on X
Washington Post

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Joseph Menn / Washington Post :

2024-01-22
Love this! Government intervention is not the solution for everything ransomware, but early warning systems like this — WHEN HEEDED — can work. CISA's 1,200 pre-ransomware alerts saved organizations millions in damages https://www.cybersecuritydive.com/ ... via @CyberSecDive & @mattkapko
2024-01-22 View on X
Ciaran's Crispy Cogitations

British Library hack lessons for the UK: ransomware is a national security issue, a national response is required, policy mitigations are available, and more

Introduction, apology, caveat, and then another apology  —  The introduction: For nearly three months, the British Library …

2023-12-19
Love this! Giving victims options so they don't have to pay! Justice Department Disrupts Prolific ALPHV/Blackcat Ransomware Variant https://www.justice.gov/...
2023-12-19 View on X
TechCrunch

The FBI, the UK, Denmark, Germany, Spain, and Australia seize ransomware gang ALPHV's dark web leak website; the US also seized “several websites” run by ALPHV

An international group of law enforcement agencies have seized the dark web leak site of the notorious ransomware gang known as ALPHV, or BlackCat.

2023-08-13
Interesting, Netwalker used Lolek for hosting. I am pretty sure other ransomware groups use them as well. Nice reporting from @LawrenceAbrams https://www.bleepingcomputer.com/ ... [image]
2023-08-13 View on X
BleepingComputer

Poland arrests five people as Europol and the DOJ take down the Lolek “bulletproof” host for allegedly facilitating Netwalker ransomware and other attacks

Europol The Hacker News : Lolek Bulletproof Hosting Servers Seized, 5 Key Operators Arrested Habiba Rashid / HackRead : Feds Seize Bulletproof Hosting Service “Lolek Hosted” Jurgit...

2023-08-12
Interesting, Netwalker used Lolek for hosting. I am pretty sure other ransomware groups use them as well. Nice reporting from @LawrenceAbrams https://www.bleepingcomputer.com/ ... [image]
2023-08-12 View on X
BleepingComputer

Poland arrests five people as Europol and the DOJ take down the Lolek “bulletproof” host for allegedly facilitating Netwalker ransomware and other attacks

Update 8/11/23: Updated with information from DOJ about alleged Netwalker Ransomware involvement.

2023-04-05
Gotta love all those flags! Genesis Market, one of world's largest platforms for cyber fraud, seized by police https://therecord.media/... @TheRecord_Media & @AlexMartin https://twitter.com/...
2023-04-05 View on X
The Record

The FBI and over a dozen global partners seize Genesis Market, one of the top cyber fraud forums that sold stolen credentials and tools to weaponize that data

Genesis Market was seized on Tuesday in an FBI-led operation involving more than a dozen international partners …

2023-02-18
This is a really well-researched and in depth look into the life of John McAfee by @jamietarabay. Looking forward to future episodes! https://www.bloomberg.com/... via @BW & @jamietarabay
2023-02-18 View on X
Bloomberg

A look at the unraveling of John McAfee, a cybersecurity pioneer and cryptocurrency hawker who grew a conspiracy-minded fan base and built a fortune on paranoia

2023-01-27
As a number of people have reported, Hive has has their infrastructure seized by a truly impressive array of law enforcement. This also means another leader, in terms of postings to data leak sites (FWIW), has fallen and certain members of Conti are now 0-2. https://twitter.com/...
2023-01-27 View on X
TechCrunch

The FBI, US DOJ, Secret Service, Europol, and others seize ransomware gang Hive's site and decryption keys; the FBI had access to Hive's network since July 2022

using lawful means, we hacked the hackers.” Tonya Riley / @tonyajoriley : Since infiltrating the network the FBI in July it was able to help 1,300 victims with decryption keys, pre...

2022-05-21
As @campuscodi says, if it quacks like a ransomware attack it likely is. If so, this would seem like an escalation in ransomware victims along the lines of Costa Rica and Peru. These attacks are having a massive impact. https://twitter.com/...
2022-05-21 View on X
TechCrunch

Conti urges Costa Rican citizens to pressure their government to pay a ransom, now doubled to $20M, and says it is “determined to overthrow the government”

2022-05-20
🧵This has been a big concern of mine for a while with the proliferation of “new” ransomware groups over the last 6 months. Ransomware actors are taking a page from ISIS and adopting more of a “cell” model. https://www.bleepingcomputer.com/ ... via @LawrenceAbrams
2022-05-20 View on X
BleepingComputer

AdvIntel: the Conti ransomware group has taken its infrastructure offline and its leaders have partnered with other smaller ransomware groups to conduct attacks

The notorious Conti ransomware gang has officially shut down their operation, with infrastructure taken offline and team leaders told that the brand is no more.

2022-03-11
This is the only report of this I've seen, but it looks like Russia is attempting to mandate installation of a certificate authority. Which could be used for TLS MITM attacks. https://bugzilla.mozilla.org/ ...
2022-03-11 View on X
BleepingComputer

Russia has created its own trusted TLS certificate authority as sanctions prevent Russian sites from renewing existing TLS certificates

Yeah, RIGHT TechRadar : Russia creates its own TLS certificate authority to bypass sanctions Leigh Mc Gowran / Silicon Republic : Russia issues its own TLS certificates to get past...

2021-12-14
This Kronos /Telestaff ransomware attack is having a wide ranging impact. I've received several complaints from several companies that can't process payroll this morning. https://twitter.com/...
2021-12-14 View on X
Ars Technica

Kronos, one of the largest HR and workflow management companies, says a ransomware attack knocked its systems offline, possibly for the next several weeks

buckle up y'all. It is indeed #ransomware. “we strongly recommend that you evaluate and implement alternative business continuity protocols” https://twitter.com/... Catalin Cimpanu...

This Kronos /Telestaff ransomware attack is having a wide ranging impact. I've received several complaints from several companies that can't process payroll this morning. https://twitter.com/...
2021-12-14 View on X
CyberScoop

CISA Director Jen Easterly says the Log4j flaw likely affects hundreds of millions of devices and may be the most serious bug she has seen in her career

Cybersecurity and Infrastructure Security Agency Director Jen Easterly told industry leaders in a phone briefing Monday that a vulnerability …

2021-12-11
Happy Patch Friday. This is remotely executable and is being scanned for/presumably exploited in wild. You know the drill... https://twitter.com/...
2021-12-11 View on X
LunaSec Blog

A vulnerability in the Apache log4j Java logging library allows for remote code execution, impacting Steam, iCloud, Minecraft, and other services

A few hours ago, a -day exploit in the popular Java logging library, log4j, was tweeted along with a POC posted on GitHub that results …

2021-11-27
This is really good reporting from @OlaigbeUthman and it tracks with what @ddd1ms has said about Russian cybercriminals: a lot of smart, well-educated, trained, computer scientists with no job prospects so they turn to cybercrime. https://therecord.media/...
2021-11-27 View on X
The Record

How one Nigerian university student turned to cybercrime during the pandemic to pay his bills, driven by high unemployment, few well-paying jobs, and boredom

2021-11-26
This is really good reporting from @OlaigbeUthman and it tracks with what @ddd1ms has said about Russian cybercriminals: a lot of smart, well-educated, trained, computer scientists with no job prospects so they turn to cybercrime. https://therecord.media/...
2021-11-26 View on X
The Record

How one Nigerian university student turned to cybercrime during the pandemic to pay his bills, driven by high unemployment, few well-paying jobs, and boredom

so excited we published his first feature, a nearly year in the making, at @TheRecord_Media! https://therecord.media/... https://twitter.com/... @therecord_media : Since the start ...

2021-11-04
I am cautiously optimistic about this (with the awareness that the actors behind BlackMatter have had nine lives). Law enforcement action taken against ransomware groups in 2021 (10+) are having a legitimate deteriorative effect on ransomware operations. Let's keep it up! https://twitter.com/...
2021-11-04 View on X
The Record

The criminal group behind BlackMatter ransomware announces plans to shut down the operation, citing “pressure from the authorities”

Catalin Cimpanu / The Record :

2021-07-02
I explained to someone today that while Captain America can be very effective with planning and skill, so can the Hulk by just “smashing” everything. This is the latter. Excellent report by @NSACyber https://twitter.com/...
2021-07-02 View on X
The Record

NSA, FBI, and others say Russian hacking group Fancy Bear has been using Kubernetes to run brute force attacks on US and foreign organizations since mid-2019

essentially, trying different passwords until the attackers gained access — and then use other known software vulnerabilities to steal emails, compromise other accounts and collect...

2021-05-28
The vulnerabilities being exploited are tracked as CVE 2018-13379, CVE-2020-12812, and CVE-2019-5591. Note: none of these are new, but edge devices like this are often slow to be patched. via ⁦@campuscodi⁩ https://therecord.media/...
2021-05-28 View on X
The Record

FBI says a foreign nation-state hacking group breached a US municipal government via an unpatched Fortinet VPN appliance

Catalin Cimpanu / The Record :

2021-01-30
I am always impressed with the depth and breadth of @Graphika_NYC's research and this is no different. They uncovered a pro-Huawei influence campaign in Belgium. As these campaigns become more common this kind of research in the hands of leaders is more critical than ever. https://twitter.com/...
2021-01-30 View on X
New York Times

Graphika: Huawei officials retweeted messages from fake accounts on Twitter to spread a pro-5G influence campaign in Belgium; Huawei is investigating the claim

A covert online push to sway telecommunications policy in favor of the Chinese company may presage a new twist in social manipulation. Source: Graphika .