Curated Intelligence

402 posts

Curated Intelligence banner
Curated Intelligence

Curated Intelligence

@CuratedIntel

Bringing together intelligence researchers and incident responders. #TrackThePlanet

Katılım Eylül 2020
106 Takip Edilen14.1K Takipçiler
Sabitlenmiş Tweet
Curated Intelligence
Curated Intelligence@CuratedIntel·
ICYMI: In October 2024, we released the CTI Research Guide. It aims to help practitioners learn more about how to effectively perform the collection, processing, analysis, and production stages of the CTI lifecycle. 🔗curatedintel.org/2024/10/the-ct…
Curated Intelligence tweet media
English
1
21
68
10.1K
Curated Intelligence
Curated Intelligence@CuratedIntel·
⚠️PSA: VPN & RDWeb password guessing attacks have been observed originating from IP addresses consistently across the following subnets: 85.239.59.0/24 85.239.58.0/24 85.239.57.0/24 85.239.56.0/24 ➡️ Check for low & slow password guessing attempts and successful logins.
English
2
3
17
2.7K
Curated Intelligence
Curated Intelligence@CuratedIntel·
⚠️PSA: Curated Intel members in DFIR have noticed a trend in exploitation of CVE-2024-57727 in the SimpleHelp RMM tool to deploy Medusa ransomware. ➡️ This tool is often used by IT Managed Service Providers (MSPs) to remotely control customer endpoints and have been impacted.
English
2
20
46
6.1K
Curated Intelligence retweetledi
Will
Will@BushidoToken·
Got a new project to share later this year which will be published via @CuratedIntel — a community of researchers that are awesome at providing great feedback and insights. Keep a look out for it in the next few months! 📝 Last time we did, we made this: curatedintel.org/2023/07/the-th…
English
0
4
30
5.7K
Curated Intelligence
Curated Intelligence@CuratedIntel·
⚠️PSA: Curated Intel DFIR has noticed a new trend among Akira Ransomware cases in Summer 2024. For a while, Akira has been exploiting Cisco ASA devices. ➡️ They are now targeting SonicWall SSL-VPNs for access with no MFA (!) and weak passwords (!). Other TTPs remain the same 🔍
English
0
26
51
9.8K
Curated Intelligence retweetledi
Will
Will@BushidoToken·
PSA from the @CuratedIntel Community to the CTI industry — watch out for cybercrime groups seeking access to your vendor platforms ⚠️
Will tweet media
English
0
28
77
21K
Marc
Marc@MHiemer22·
@CuratedIntel VPN access via legit creds and on mfa or are they attacking a Cisco ASA VPN vulnerability?
English
1
0
1
580
Curated Intelligence
Curated Intelligence@CuratedIntel·
⚠️PSA: Curated Intel DFIR teams noticed a severe uptick in Akira Ransomware cases in Jan 2024. Same repeated TTPs: - Dwell times of < 4 hours on average - Cisco ASA VPN for Access - WinSCP for exfil / WinRAR for compression - AnyDesk RMM for persistence - 'w.exe' Akira payload
English
5
62
180
62K
Curated Intelligence
Curated Intelligence@CuratedIntel·
🌐 Curated Intel is tracking hacktivist, cybercriminal, and regional APT groups surrounding the war in Israel. We describe the types of campaigns and attacks we've observed so far and have also provided recommendations for CTI analysts monitoring the war. curatedintel.org/2023/10/tracki…
Curated Intelligence tweet media
English
2
51
114
35.2K
Curated Intelligence retweetledi
Will
Will@BushidoToken·
We had some good convos in the @CuratedIntel community today based on this @thecyberwire interview Really interesting that @C_C_Krebs says the *most important skill* he looks for in a CTI analyst is their “ability to communicate risk to businesses” 🗣️⚠️ thecyberwire.com/podcasts/speci…
English
0
9
36
12.8K
Curated Intelligence retweetledi
Kostas
Kostas@Kostastsale·
A Day in the Life of a CISO
English
12
125
462
65.4K
Curated Intelligence retweetledi
Zach
Zach@svch0st·
@phillmoore and I posted a blog on a TTP observed in an #Akira Ransomware case. ➡️ Actor gains access to Hyper-V server (with EDR) and creates a fresh VM ➡️ Turns off server VMs and mounts Hyper-V data disk on new VM ➡️Starts encrypting vhdx files! cybercx.com.au/blog/akira-ran…
Zach tweet media
English
4
44
139
25K
Curated Intelligence retweetledi
Will
Will@BushidoToken·
TL;DR of ALPHV/BlackCat's essay on the MGM breach - The attack began ~8 Sept. - They stole data and gained admin on their Okta SSO & Azure cloud tenant - ~100 ESXi hypervisors were hit by ransomware on 11 September - No ransom was paid Read in full here: gist.githubusercontent.com/BushidoUK/20b8…
Will tweet media
English
21
144
448
152.1K
Curated Intelligence retweetledi
Will
Will@BushidoToken·
⚠️ Use Microsoft Teams? Watch out for TeamsPhisher! While it is not usually possible to send files to MS Teams users outside your org, by security researchers found a bypass by manipulating Teams web requests 🔥 github.com/Octoberfest7/T… Examples of MS Teams phish lures ⬇️ 1/3
Will tweet mediaWill tweet media
English
2
143
407
82.5K