
Andre Gironda
@andregironda
He/Him; Pre-/Post-breach Cyber Responder
ID: 327015253
30-06-2011 21:21:26
56,56K Tweet
2,2K Takipçi
6,6K Takip Edilen




Oh, you had me for this Executive Summary! Security Response Congrats Michael.Gorelik and team for the discovery.:) msrc.microsoft.com/update-guide/v…


Details published research.checkpoint.com/2025/stealth-f…. To summarize: the "WorkingDirectory" problem within .url files. Oh, .url files, my old friend (I previously discovered another .url/IE 0day itw last year).. My thoughts/opinion: no organization should allow any inbound .url files in




⚠️ New threat detected: @yoti-web-share/[email protected] ⚠️ The code is suspicious as it collects environment variables, compresses them, and sends them via DNS queries to a hardcoded server. This behavior indicates potential data exfiltration, ... socket.dev/npm/package/@y…



ConnectWise rotating code signing certificates over security concerns - Bill Toulas bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…


DanaBot malware operators exposed via C2 bug added in 2022 - Bill Toulas bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…




