If you’re trying to build a more proactive security program, I think you’ll find it useful.
👉 Read it here: feedly.com/ti-essential...
If you’re trying to build a more proactive security program, I think you’ll find it useful.
👉 Read it here: feedly.com/ti-essential...
We sat down with Rebecca Taylor from Sophos and @bushidotoken.net from @teamcymrus2.bsky.social to discuss 2025’s highs and lows in cyber and make educated guesses on what to look for in 2026.
feeds.soundcloud.com/users/soundc...
We sat down with Rebecca Taylor from Sophos and @bushidotoken.net from @teamcymrus2.bsky.social to discuss 2025’s highs and lows in cyber and make educated guesses on what to look for in 2026.
feeds.soundcloud.com/users/soundc...
This blog discusses the topic of cybercrime counterintelligence to highlight the growing threat toward the cyber threat intelligence (CTI) and law enforcement (LE) communities ⚠️
🔗 www.sans.org/blog/for589-...
This blog discusses the topic of cybercrime counterintelligence to highlight the growing threat toward the cyber threat intelligence (CTI) and law enforcement (LE) communities ⚠️
🔗 www.sans.org/blog/for589-...
When a company that manages data for millions of UK citizens falls victim to ransomware, the whole industry should pay attention to it. 📝
blog.bushidotoken.net/2025/10/less...
When a company that manages data for millions of UK citizens falls victim to ransomware, the whole industry should pay attention to it. 📝
blog.bushidotoken.net/2025/10/less...
In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub.
🔗 www.sans.org/blog/evoluti...
In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub.
🔗 www.sans.org/blog/evoluti...
After the last few large breaches, I discuss several cases in which the customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have been extorted by adversaries from the English-speaking #cybercrime communities.
🔗 www.sans.org/blog/hunting...
After the last few large breaches, I discuss several cases in which the customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have been extorted by adversaries from the English-speaking #cybercrime communities.
🔗 www.sans.org/blog/hunting...
“Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry” 🇰🇵 🔍
www.team-cymru.com/post/uncover...
“Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry” 🇰🇵 🔍
www.team-cymru.com/post/uncover...
How did Law Enforcement Deanonymize IntelBroker? 🔍
TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰
www.justice.gov/usao-sdny/me...
How did Law Enforcement Deanonymize IntelBroker? 🔍
TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰
www.justice.gov/usao-sdny/me...
1.94.184[.]17:8000
Huawei Cloud AS55990
.jsp Godzilla Web Shell
6d403c3fc246d6d493a6f4acc18c1c292f710db6ad9c3ea2ff065595c5ad3c5b
/poc.xml contents
wqtzskzmtp[.]zaza[.]eu[.]org
101.33.34[.]170
Tencent AS132203
1.94.184[.]17:8000
Huawei Cloud AS55990
.jsp Godzilla Web Shell
6d403c3fc246d6d493a6f4acc18c1c292f710db6ad9c3ea2ff065595c5ad3c5b
/poc.xml contents
wqtzskzmtp[.]zaza[.]eu[.]org
101.33.34[.]170
Tencent AS132203
All 762 indicators 💥⤵️
www.validin.com/blog/not_rea...
All 762 indicators 💥⤵️
www.validin.com/blog/not_rea...
blog.bushidotoken.net/2025/04/trac...
blog.bushidotoken.net/2025/04/trac...
To help make life easier for some, I’ve manually mapped their TTPs to ATT&CK: github.com/BushidoUK/MI...
To help make life easier for some, I’ve manually mapped their TTPs to ATT&CK: github.com/BushidoUK/MI...
1. Send phish to an <org_name>@service-now[.]com inbox
2. A ticket is then auto-created in the platform using servicenow_notification@<org_domain>
3. A link is put in the body of the SNOW ticket that can lead to malware or fake login page
1. Send phish to an <org_name>@service-now[.]com inbox
2. A ticket is then auto-created in the platform using servicenow_notification@<org_domain>
3. A link is put in the body of the SNOW ticket that can lead to malware or fake login page
Link: x.com/BushidoToken...
Newsletter: risky.biz/risky-bullet...
-FBI warns of online file converters that distribute malware
-China backdoors Juniper routers
-Ransomware wave hits Taiwan
-North Korean spyware slips onto the Play Store
-Senators call for US cyber offensive against China
Link: x.com/BushidoToken...
— This is a step-by-step extraction and translation of the leaked conversation between the BlackBasta members during the Ascension Health attack
🔗 blog.bushidotoken.net/2025/02/blac...
— This is a step-by-step extraction and translation of the leaked conversation between the BlackBasta members during the Ascension Health attack
🔗 blog.bushidotoken.net/2025/02/blac...
h/t to @drb_ra for lending me some of their C2 data! Made my life a lot easier 🫡
🔗 blog.bushidotoken.net/2025/02/inve...
Podcast version: www.youtube.com/watch?v=xX25...
h/t to @drb_ra for lending me some of their C2 data! Made my life a lot easier 🫡
🔗 blog.bushidotoken.net/2025/02/inve...
Podcast version: www.youtube.com/watch?v=xX25...
ZSERVERS BPH sanctioned by the UK for enabling LockBit attacks
www.gov.uk/government/n...
Phobos & 8BASE arrests by international partners
www.europol.europa.eu/media-press/...
ZSERVERS BPH sanctioned by the UK for enabling LockBit attacks
www.gov.uk/government/n...
Phobos & 8BASE arrests by international partners
www.europol.europa.eu/media-press/...
blog.bushidotoken.net/2025/01/trac...
blog.bushidotoken.net/2025/01/trac...