Alexis Dorais-Joncas (@adorais.bsky.social) (@adorais) 's Twitter Profile
Alexis Dorais-Joncas (@adorais.bsky.social)

@adorais

Sr Manager, APT Threat Research @Proofpoint

ID: 25084905

calendar_today18-03-2009 14:54:32

971 Tweet

1,1K Takipçi

850 Takip Edilen

Threat Insight (@threatinsight) 's Twitter Profile Photo

Beginning on September 28, @Proofpoint began observing attempts to exploit CVE-2024-45519, a remote code execution vulnerability in Zimbra mail servers. The emails spoofing Gmail were sent to bogus addresses in the CC fields in an attempt for Zimbra servers to parse and execute

Beginning on September 28, @Proofpoint began observing attempts to exploit CVE-2024-45519, a remote code execution vulnerability in Zimbra mail servers.

The emails spoofing Gmail were sent to bogus addresses in the CC fields in an attempt for Zimbra servers to parse and execute
Karsten Hahn (@struppigel) 's Twitter Profile Photo

I have looked at 2024 malware research papers in academia and found that none of them used today's relevant malware. Families they used were old worms and viruses that had been relevant decades ago and nowadays only thrive on sandbox systems.

I have looked at 2024 malware research papers in academia and found that none of them used today's relevant malware. 

Families they used were old worms and viruses that had been relevant decades ago and nowadays only thrive on sandbox systems.
Threat Insight (@threatinsight) 's Twitter Profile Photo

New APT insight from @Proofpoint: This week, Threat Insight has observed Iraninan-aligned threat group #TA453 (AKA #CharmingKitten #APT42 #MintSandstorm) continue their phishing efforts despite the recent unsealing of indictments and sanctions by the U.S. government. #IRGC

Will (@bushidotoken) 's Twitter Profile Photo

Hey Cyble marketing team please clarify your blog and actually credit the author of the Ransomware Vulnerability Matrix… because that would be me 🙃 otherwise others may think you made it 🤦🏻‍♂️ hxxps://cyble[.]com/blog/ransomware-vulnerability-matrix-a-comprehensive/

Hey <a href="/cybleglobal/">Cyble</a> marketing team please clarify your blog and actually credit the author of the Ransomware Vulnerability Matrix… because that would be me 🙃 otherwise others may think you made it 🤦🏻‍♂️

hxxps://cyble[.]com/blog/ransomware-vulnerability-matrix-a-comprehensive/
mRr3b00t (@uk_daniel_card) 's Twitter Profile Photo

Public WiFi is so unsafe (it’s not it’s generally fine for personal/family use) that when I arp spoof and dns spoof not only do I get errors with TLS (this site doesn’t have hsts enabled) but my phone (android) literally warns me the network is acting in a suspicious manner….

Public WiFi is so unsafe (it’s not it’s generally fine for personal/family use) that when I arp spoof and dns spoof not only do I get errors with TLS (this site doesn’t have hsts enabled) but my phone (android) literally warns me the network is acting in a suspicious manner….
💻 Sherrod DeGrippo 🛸 (@sherrod_im) 's Twitter Profile Photo

Recoding a hot af podcast episode tomorrow with the Gregs all about 🇰🇵 DPRK. What threat intel questions do you have for the experts? #sleet #chollima

Greg Lesnewich (@greglesnewich) 's Twitter Profile Photo

Lots of good research this week on MacOS activity from Bluenoroff / TA444 / Sapphire Sleet New record: only one of them said Lazarus instead of Bluenoroff 😂

Alexis Rapin (@alexis_rapin) 's Twitter Profile Photo

Next monday, I'll have the privilege to chat with my colleagues Jean-Ian Boutin, Alexis Dorais-Joncas (@adorais.bsky.social) and Catherine Dupont-Gagnon (Cyber Citoyen) for a panel focused on “State-sponsored cyber attacks: current trends and impact on modern society” at #FPS2024. Join us ! 👉fps-2024.hec.ca

Next monday, I'll have the privilege to chat with my colleagues <a href="/jiboutin/">Jean-Ian Boutin</a>, <a href="/adorais/">Alexis Dorais-Joncas (@adorais.bsky.social)</a> and Catherine Dupont-Gagnon (<a href="/Cybercitoyen_/">Cyber Citoyen</a>) for a panel focused on “State-sponsored cyber attacks: current trends and impact on modern society” at #FPS2024. Join us ! 
👉fps-2024.hec.ca
Hash Miser (@h_miser) 's Twitter Profile Photo

Cette information pop à droite à Haude depuis qq jours et je pense qu’il manque beaucoup de contexte alors petit thread 👇

Alexis Dorais-Joncas (@adorais.bsky.social) (@adorais) 's Twitter Profile Photo

Developing story - attack against #BGP peers of a European telco. The malicious emails impersonated that same telco and included the ASN of each recipient in the subject line. The emails contained a password-protected RAR attachment with the malicious payload.

Alexis Dorais-Joncas (@adorais.bsky.social) (@adorais) 's Twitter Profile Photo

Vendors only have partial visibility on any campaign. What appears as highly targeted to one can be widespread to another. It is normal and expected - we all have visibility biases. Working together and combining our findings is the only way to get closer to the full picture 🤜🤛

Simon Kenin (@k3yp0d) 's Twitter Profile Photo

1/16 Recently I became aware of this The Jerusalem Post breaking "News" article, which turns out to be more like a paid content: jpost.com/middle-east/ir…