Florian Roth(@cyb3rops) 's Twitter Profileg
Florian Roth

@cyb3rops

Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇

ID:1538299243

linkhttps://linktr.ee/cyb3rops calendar_today22-06-2013 08:46:16

32,3K Tweets

179,8K Followers

2,3K Following

Squiblydoo(@SquiblydooBlog) 's Twitter Profile Photo

Beautiful.
One doesn't always get to see how revoking authenticode certs causes an impact, but RussianPanda 🐼 🇺🇦 has great example:
Disrupted malware service delivery.

More about cert abuse: squiblydoo.blog/2023/05/12/cer…

Want to report? github.com/Squiblydoo/cer… makes reporting easy

account_circle
Ax Sharma(@Ax_Sharma) 's Twitter Profile Photo

A GitHub flaw lets attackers upload executables that appear to be hosted on a company's official repo, such as Microsoft's—without the repo owner knowing anything about it.

The following URLs, for example, make it seem like these ZIPs are present on Microsoft's source code repo:

A GitHub flaw lets attackers upload executables that appear to be hosted on a company's official repo, such as Microsoft's—without the repo owner knowing anything about it. The following URLs, for example, make it seem like these ZIPs are present on Microsoft's source code repo:
account_circle
randy@infosec.exchange - Stand with 🇺🇦(@rpargman) 's Twitter Profile Photo

🤯 you can upload any file as an attachment in a draft comment on any public GitHub repo, delete the comment but the file download URL remains active, and the repo owner can’t do anything about it

account_circle
Justin Elze(@HackingLZ) 's Twitter Profile Photo

Looking at more than one PANOS support file for CVE-2024-3400 stuff? This might be a useful starting point but very hacky.

github.com/HackingLZ/panr…

Florian Roth already has a good solution using his thor lite scanner

twitter.com/cyb3rops/statu…

account_circle
Florian Roth(@cyb3rops) 's Twitter Profile Photo

TIL that TikTok's shell company developed a Rust based EDR agent ... at least that's what it looks like

... probably the last thing I'd like to find on a machine outside of China, but hey, it always depends on your risk profile, right?

TIL that TikTok's shell company developed a Rust based EDR agent ... at least that's what it looks like ... probably the last thing I'd like to find on a machine outside of China, but hey, it always depends on your risk profile, right?
account_circle
Florian Roth(@cyb3rops) 's Twitter Profile Photo

We decided to share our rules to scan for indicators of the exploitation of CVE-2024-3400 in 's PAN-OS with the community and included some of the generic rules (detect similar attacks)

Three Steps

1. Generate a Tech Support file and extract it

We decided to share our #YARA rules to scan for indicators of the exploitation of CVE-2024-3400 in #PaloAlto's PAN-OS with the community and included some of the generic rules (detect similar attacks) Three Steps 1. Generate a Tech Support file and extract it
account_circle
3xp0rt(@3xp0rtblog) 's Twitter Profile Photo

HelloKitty Ransomware released some decryption keys and rebranded into HelloGookie with a new blog. Gookie, who is the author of this ransomware, sends his regards to LockBit due to possible competition. He also regained access to his lost account on the Exploit forum.

HelloKitty Ransomware released some decryption keys and rebranded into HelloGookie with a new blog. Gookie, who is the author of this ransomware, sends his regards to LockBit due to possible competition. He also regained access to his lost account on the Exploit forum.
account_circle
Caitlin Condon(@catc0n) 's Twitter Profile Photo

Full Rapid7 analysis of PAN-OS CVE-2024-3400 now available from Stephen Fewer and our stellar new research teammate ryan emmons! Spoiler: It's a two-vuln exploit chain. attackerkb.com/topics/SSTk336…

account_circle
Jeff Woolsey (also on Threads as WSV_GUY) ☮️(@WSV_GUY) 's Twitter Profile Photo

PLEASE RT: IMPORTANT
Folks, we are making security changes in Windows Server 2025 such as in Active Directory, File Servers, SMB to name a few. We’ve been messaging these changes, but in case you missed them, this thread is for you.

account_circle
Ivan Kwiatkowski(@JusticeRage) 's Twitter Profile Photo

On March 25, the FBI released an indictment of APT31 hackers. We read it carefully to find new intel, and managed to connect a few dots (including about the RAWDOOR malware family).

Full article and IOCs: harfanglab.io/en/insidethela…

account_circle