Zach Corum
@infrasecalliance.org
65 followers
390 following
51 posts
IT | OT | Cybersecurity | GICSP | Whisk(e)y | Bonsai
Open to Work
Infrasec Aliance: A non-profit dedicated to securing critical infrastructure
https://infrasecalliance.org
https://blog.infrasecalliance.org
https://bio.site/zachcorum
Posts
Media
Videos
Starter Packs
Zach Corum
@infrasecalliance.org
· Apr 6
There's a ransomware group named DragonForce going around hacking its rivals.
After Mamona and BlackLock, the group has now hacked RansomHub—a major RaaS platform and one of the most active groups today.
After Mamona and BlackLock, the group has now hacked RansomHub—a major RaaS platform and one of the most active groups today.
Reposted by Zach Corum
Reposted by Zach Corum
The Record
@therecordmedia.bsky.social
· Mar 20
Major web services go dark in Russia amid reported Cloudflare block
Website outages were observed across Russia this week, with regulators attributing them to issues with foreign servers. Observers said the problems might be tied to Russian government moves to block the Cloudflare service.
therecord.media
Zach Corum
@infrasecalliance.org
· Mar 20
Zach Corum
@infrasecalliance.org
· Mar 20
Zach Corum
@infrasecalliance.org
· Mar 20
Zach Corum
@infrasecalliance.org
· Mar 20
Zach Corum
@infrasecalliance.org
· Mar 20
Reposted by Zach Corum
Catalin Cimpanu
@campuscodi.risky.biz
· Feb 20
Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Unit 42 details the just-discovered connection between threat group Stately Taurus (aka Mustang Panda) and the malware Bookworm, found during analysis of the group's infrastructure. Unit 42 details th...
unit42.paloaltonetworks.com
Reposted by Zach Corum
Zach Corum
@infrasecalliance.org
· Dec 6
And you thought your business had a lot of unpatched edge devices that enable long-dwell persistence!
I love how so many problems in cybersecurity are basic and ubiquitous — like common networking appliances having code riddled with vulnerabilities — but people wanna invest in AI or whatever…
I love how so many problems in cybersecurity are basic and ubiquitous — like common networking appliances having code riddled with vulnerabilities — but people wanna invest in AI or whatever…
There's a reason why it's going to take U.S. telcos a pretty long time to toss Beijing out of their networks: They have so much equipment they need to map out, patch and update.
But until each device is secured, Beijing is likely going to keep finding new ways in.
www.axios.com/2024/12/06/t...
But until each device is secured, Beijing is likely going to keep finding new ways in.
www.axios.com/2024/12/06/t...
Zach Corum
@infrasecalliance.org
· Dec 4
From now on, every time there is a new proposal to backdoor e2ee apps, we're just going to point to this, right?
www.nbcnews.com/tech/securit...
www.nbcnews.com/tech/securit...
U.S. officials urge Americans to use encrypted apps amid cyberattack that exposed live phone calls
Officials from the FBI and CISA said it was impossible to predict when the telecommunications companies would be fully safe from interlopers.
www.nbcnews.com
Reposted by Zach Corum
Troy Hunt
@troyhunt.com
· Dec 4
Introducing “Have I been pwned?” – aggregating accounts across website breaches
I often write up analyses of the passwords disclosed in website breaches. For
example, there was A brief Sony password analysis
[https://www.troyhunt.com/2011/06/brief-sony-password-analysis.html] bac...
www.troyhunt.com
Zach Corum
@infrasecalliance.org
· Dec 3
Zach Corum
@infrasecalliance.org
· Dec 2
Zach Corum
@infrasecalliance.org
· Nov 27
Justice Department Seizes Cybercrime Website and Charges Its Administrators
The Justice Department today announced the seizure of PopeyeTools, an illicit website and marketplace dedicated to selling stolen credit cards and other tools for carrying out cybercrime and fraud, an...
www.justice.gov
Zach Corum
@infrasecalliance.org
· Nov 22
Putin’s Assassination Targets Revealed in Declassified Memo
The Office of the Director of National Intelligence has released a long-classified memorandum shedding light on the targeted killings of Vladimir Putin’s political adversaries, following nearly eight ...
www.bloomberg.com
Zach Corum
@infrasecalliance.org
· Nov 22
Zach Corum
@infrasecalliance.org
· Nov 20
The Justice Department unsealed charges against five men accused of running prolific phishing campaigns that allowed them to steal employee credentials, gain access to sensitive data and pilfer millions.
By @jgreig.bsky.social on @therecordmedia.bsky.social
therecord.media/five-scatter...
By @jgreig.bsky.social on @therecordmedia.bsky.social
therecord.media/five-scatter...
Five members of Scattered Spider cybercrime group charged for breaches, theft of $11 million
Court documents say the five — who live in the U.S. and U.K. — are accused of stealing $11 million worth of cryptocurrency from at least 29 victims in addition to taking troves of corporate documents ...
therecord.media