Gi7w0rm(@Gi7w0rm) 's Twitter Profileg
Gi7w0rm

@Gi7w0rm

Threat Intelligence and #URINT Analyst |
See my Linktree for other socials |
In case I post false intel, contact me!
Support me: https://t.co/5WgDqr0K8p

ID:1058319953739333632

linkhttps://linktr.ee/gi7w0rm calendar_today02-11-2018 11:28:34

7,1K Tweets

14,3K Followers

678 Following

Validin(@ValidinLLC) 's Twitter Profile Photo

The threat actor initially reported by Infoblox in February has used CNAME records for their TDS in over 2,000 domains (and at least 80,000 FQDNs). Validin's PDNS database makes this detection trivial.

2,143 domains here:
pastebin.com/pza2BkRF

The #SavvySeahorse threat actor initially reported by @Infoblox in February has used CNAME records for their TDS in over 2,000 domains (and at least 80,000 FQDNs). Validin's PDNS database makes this detection trivial. 2,143 domains here: pastebin.com/pza2BkRF
account_circle
John Scott-Railton(@jsrailton) 's Twitter Profile Photo

OPEN SECRET: the same legislators & officials calling on companies to weaken encryption...

...are avid Signal users.

So are the staffers that write their bills.

Because, despite what they say, they can't do their jobs without the privacy protections of strong encryption.

account_circle
Gi7w0rm(@Gi7w0rm) 's Twitter Profile Photo

Seems Sekoia.io sinkholed a C2 and observed around 100.000 devices from 127 countries connecting.
Good job on this investigation 👍
blog.sekoia.io/unplugging-plu…

account_circle
Spamhaus(@spamhaus) 's Twitter Profile Photo

❗ Researchers at Spamhaus have identified an abuse problem for Internet Backbone and Colocation Provider, Hurricane Electric (Hurricane Electric) relating to AS394711, allocated to New Hampshire-based Limenet LLC.

Spamhaus currently assesses that Limenet is a bulletproof hosting operation;

account_circle
Will(@BushidoToken) 's Twitter Profile Photo

⚠️ Cisco ASA & FTD Zero Day Vulnerabilities are now tracked as CVE-2024-20353 and CVE-2024-20359

sec.cloudapps.cisco.com/security/cente…

account_circle
Validin(@ValidinLLC) 's Twitter Profile Photo

We expand a single domain reported by the FBI as part of a recent toll road smishing campaign into hundreds of phishing campaigns, including dozens related to 'unpaid toll' smishing scams.

Check out our latest blog post here:
validin.com/blog/hunting-f…

account_circle
vx-underground(@vxunderground) 's Twitter Profile Photo

The United States FTC has banned non-compete agreements. We look forward to all of you creating a cyber security startup

ftc.gov/news-events/ne…

account_circle
Gi7w0rm(@Gi7w0rm) 's Twitter Profile Photo

Maybe useful to some out here. No passwords shown, but domains of victim login data given.

Example search: .gov

Maybe useful to some out here. No passwords shown, but domains of victim login data given. Example search: .gov
account_circle
vx-underground(@vxunderground) 's Twitter Profile Photo

Today Avast unveiled 'GuptiMiner'.

tl;dr eScan AV, out of India, used HTTP for AV updates, not HTTPS, North Korea man-in-the-middle'd updates to large networks to deliver malware

We give this APT campaign an A+ because it's absurdly well executed

decoded.avast.io/janrubin/gupti…

account_circle