Ben (@polygonben) 's Twitter Profile
Ben

@polygonben

SOC analyst @ Accenture | GCFA | Views are my own

ID: 1594877186607140866

linkhttps://polygonben.github.io/ calendar_today22-11-2022 02:15:54

185 Tweet

440 Followers

762 Following

Alfie Champion (@ajpc500) 's Twitter Profile Photo

Turns out the same ClickFix mitigation of ‘disabling’ the Win+R shortcut (HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer - NoRun DWORD 1) also prevents exploitation of the address bar FileFix technique💡

Turns out the same ClickFix mitigation of ‘disabling’ the Win+R shortcut (HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer - NoRun DWORD 1) also prevents exploitation of the address bar FileFix technique💡
0xBurgers (@0xburgers) 's Twitter Profile Photo

Always learned about these but never seen ITW myself until yesterday. WebDAV abuse in phishing kits isn’t dead. file:// UNC paths + Cloudflare Tunnels = modern twist on an old trick. 🔥

Always learned about these but never seen ITW myself until yesterday.

WebDAV abuse in phishing kits isn’t dead. file:// UNC paths + Cloudflare Tunnels = modern twist on an old trick. 🔥
Rem (@sudo_rem) 's Twitter Profile Photo

I've started the rather tedious project of labeling every Cloudflared account ID that is observed on multiple, unrelated organizations. A shocking number of Cloudflared tunnels draw lineage to benign software applications such as pharmacy software, municipal government

I've started the rather tedious project of labeling every Cloudflared account ID that is observed on multiple, unrelated organizations. A shocking number of Cloudflared tunnels draw lineage to benign software applications such as pharmacy software, municipal government
EncapsulateJay (@encapsulatej) 's Twitter Profile Photo

If your organisation uses a third-party managed IT provider, and said IT provider says you have a shiny VPN with logging enabled. Please challenge the provider to prove that the VPN logs are configured correctly. A trusted IT partner will be happy to do this.

BSides Cheltenham (@bsideschelt) 's Twitter Profile Photo

It's the week of BSides Cheltenham, and we're looking for some final prize donations for our Charity Raffle. We're supporting The Ollie Foundation - a suicide prevention and wellbeing charity on an important mission. Any prizes, virtual or physical, are welcome. Get in touch!

It's the week of BSides Cheltenham, and we're looking for some final prize donations for our Charity Raffle. 

We're supporting The Ollie Foundation - a suicide prevention and wellbeing charity on an important mission.

Any prizes, virtual or physical, are welcome. Get in touch!
Virus Bulletin (@virusbtn) 's Twitter Profile Photo

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a PHP variant of Interlock RAT (aka NodeSnake) distributed via KongTuke FileFix. thedfirreport.com/2025/07/14/kon…

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a PHP variant of Interlock RAT (aka NodeSnake) distributed via KongTuke FileFix.  thedfirreport.com/2025/07/14/kon…
Huntress (@huntresslabs) 's Twitter Profile Photo

Congratulations to RussianPanda 🐼 🇺🇦 & Ben for having talks accepted at #defcon33! Follow these folks and if you're headed to DEF CON put it on you to-do list to be in attendance!

Congratulations to <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> &amp; <a href="/polygonben/">Ben</a> for having talks accepted at #defcon33! 

Follow these folks and if you're headed to <a href="/defcon/">DEF CON</a> put it on you to-do list to be in attendance!
Jamie Levy🦉 (@gleeda) 's Twitter Profile Photo

We’ve started seeing Crux ransomware, which seems to be related to / affiliated with BlackByte ransomware (maybe?). Since we haven’t really seen anything about them, we wrote up a bit of info: huntress.com/blog/crux-rans…

Will (@bushidotoken) 's Twitter Profile Photo

I am very pleased to announce I will be speaking at Adversary Village at @DEFCON 33! My first time in Las Vegas 🇺🇸🎰 Come to Creator Stage 3 (Room 231) on 10 August at 11am to catch my talk! adversaryvillage.org/adversary-even…

I am very pleased to announce I will be speaking at <a href="/AdversaryVillag/">Adversary Village</a> at @DEFCON 33! My first time in Las Vegas 🇺🇸🎰 

Come to Creator Stage 3 (Room 231) on 10 August at 11am to catch my talk!

adversaryvillage.org/adversary-even…
alden (@birchb0y) 's Twitter Profile Photo

im so pumped to be talking through some fun north korean malware with Stuart Ashenbrenner 🇺🇸 🇨🇦 at #OBTS v8 🤠 it's truly a goated lineup and i'm very humbled to be speaking along side so many sick researchers (also dw i will be dressed up in a blues clues onesie for the talk)

Europol (@europol) 's Twitter Profile Photo

🚨 Suspected admin of xss.is, a top Russian-speaking cybercrime forum, was arrested in Ukraine. The suspect, active for nearly 20 years, allegedly made €7M facilitating cybercrime. 🇫🇷🇺🇦🇪🇺 Operation led by France with Europol support. europol.europa.eu/media-press/ne…

🚨 Suspected admin of xss.is, a top Russian-speaking cybercrime forum, was arrested in Ukraine.

The suspect, active for nearly 20 years, allegedly made €7M facilitating cybercrime.

🇫🇷🇺🇦🇪🇺 Operation led by France with Europol support.

europol.europa.eu/media-press/ne…