Isaac Dunham

343 posts

Isaac Dunham

Isaac Dunham

@DunhamSec

Senior Detection Engineer

Katılım Haziran 2023
655 Takip Edilen88 Takipçiler
Isaac Dunham retweetledi
Austin Larsen
Austin Larsen@AustinLarsen_·
The #axios maintainer just confirmed #UNC1069 🇰🇵 used the same playbook we documented in February. Cloned a founder's identity. Built a convincing Slack workspace. Scheduled a call. Fake "update" deployed WAVESHAPER.V2. npm creds stolen. Trojanized axios update pushed.
Austin Larsen tweet mediaAustin Larsen tweet media
English
5
62
333
26.8K
Isaac Dunham retweetledi
flavio
flavio@flaviocopes·
How Axios was compromised 🤯
flavio tweet media
English
147
857
6.9K
1.5M
Isaac Dunham retweetledi
Applied Network Defense
Applied Network Defense@NetworkDefense·
New Skills Vault Lesson!: Dan Marr shows how attackers use ICMP tunneling for covert data transmission and how you can detect and investigate it.
Applied Network Defense tweet media
English
1
2
6
249
Isaac Dunham retweetledi
The DFIR Report
The DFIR Report@TheDFIRReport·
We’re seeing a “Missing Font” ClickFix chain in the wild. Flow: 1️⃣ Fake “Missing Font” prompt 2️⃣ Leads to a BSOD-style recovery screen 3️⃣ Prompts users to open Terminal/PowerShell directly (skipping the Run dialog) and execute commands #infosec #DFIR #threatintel
The DFIR Report tweet media
English
1
43
148
8.7K
Isaac Dunham retweetledi
Mark Cecchini, CFP®
Mark Cecchini, CFP®@markcecchini·
COMMANDER: We’re fighting for freedom. And part of that freedom… is the freedom to retire with dignity. So we’re going to start accounts called 401(k)s. SOLDIER 1: What’s a 401(k)? COMMANDER: It’s a retirement account. You put money in, it grows tax-free, you take it out when you’re old. SOLDIER 2: So I don’t pay taxes on it? COMMANDER: Well, you pay taxes later. When you withdraw. SOLDIER 2: So it’s not tax-free. COMMANDER: It’s…tax-deferred. SOLDIER 2: What’s the difference? COMMANDER: You pay taxes later instead of now. SOLDIER 1: What if I want to pay taxes now? COMMANDER: Then you do a Roth 401(k). SOLDIER 3: What’s a Roth? COMMANDER: You pay taxes now, and it grows tax-free. SOLDIER 2: That’s what I thought the first one was. COMMANDER: No, the first one you pay taxes later. SOLDIER 1: Which one’s better? COMMANDER: Depends on your tax bracket in retirement. SOLDIER 1: …How would I…know that? COMMANDER: You don’t. You just guess. ⸻ SOLDIER 4: What if I don’t have a 401(k) through my employer? COMMANDER: Then you open an IRA. SOLDIER 4: What’s the difference? COMMANDER: One’s through your job, one’s on your own. SOLDIER 4: Can I have both? COMMANDER: Yes. SOLDIER 4: Should I? COMMANDER: Maybe. SOLDIER 3: Can I do a Roth IRA? COMMANDER: Only if you make under a certain amount. SOLDIER 3: What’s the limit? COMMANDER: Changes every year. SOLDIER 2: What if I make too much? COMMANDER: Then you do a backdoor Roth by putting it in a Traditonal first. SOLDIER 2: …Is that legal? COMMANDER: Surprisingly, yes. SOLDIER 1: What’s a backdoor Roth? COMMANDER: You contribute to a traditional IRA, then convert it to a Roth…but watch out for “pro rata”. SOLDIER 1: Why wouldn’t I just contribute to the Roth directly? COMMANDER: Because you make too much money. SOLDIER 1: But this way I can? COMMANDER: Yes. SOLDIER 1: That feels like a loophole. COMMANDER: It is. But the IRS is cool with it. ⸻ SOLDIER 5: I just changed battalions. What do I do with my old 401(k)? COMMANDER: You roll it over. SOLDIER 5: Into what? COMMANDER: An IRA. Or your new 401(k). Depends. SOLDIER 5: On what? COMMANDER: The funds. The fees. Whether your new plan accepts rollovers. SOLDIER 5: What if I just take the money out? COMMANDER: You’ll pay taxes plus a 10% penalty. SOLDIER 5: What if I’m 59? COMMANDER: Penalty. SOLDIER 5: 59 and a half? COMMANDER: No penalty. SOLDIER 5: …The half matters? COMMANDER: The half matters. ⸻ SOLDIER 3: What’s a mega backdoor Roth? COMMANDER: Okay. So. Your 401(k) has a limit of how much you can contribute. SOLDIER 3: Right. COMMANDER: But the total limit including employer contributions is higher. SOLDIER 3: Okay… COMMANDER: So if your plan allows ~after-tax~ contributions, you can put in more, then convert that to Roth. SOLDIER 3: Does my plan allow that? COMMANDER: I don’t know. You have to ask Betsy. SOLDIER 3: Will Betsy know? COMMANDER: Probably not. ⸻ SOLDIER 2: Can I deduct my IRA contribution on my taxes? COMMANDER: Are you covered by a retirement plan at work? SOLDIER 2: Yes. COMMANDER: Then only if you make under a certain amount per year. SOLDIER 2: What’s the amount? COMMANDER: Depends if you’re married. SOLDIER 2: What if my wife has a plan but I don’t? COMMANDER: Different limit. SOLDIER 2: What if neither of us has a plan? COMMANDER: Full deduction. SOLDIER 2: So it’s better to not have a 401(k)? COMMANDER: No… ⸻ SOLDIER 1: Can I just keep my money in a sock? COMMANDER: You could. But inflation will slowly destroy it. SOLDIER 1: What’s inflation? COMMANDER: (sighs)…
Mark Cecchini, CFP® tweet media
English
404
2.4K
23.9K
1.6M
Isaac Dunham
Isaac Dunham@DunhamSec·
@lillybilly299 Something that's always made me sad is that I, as a civilian not contracted by the government, am forbidden from enrolling here. dliflc.edu
English
0
0
0
43
Lilly
Lilly@lillybilly299·
The funny thing about Duolingo and highschool Spanish, etc is that language learning is a solved problem. The military can get people conversational in a new language in like a couple months. We just mostly don't teach languages that way because fuck it I guess
Lilly tweet media
Jay Alto@theJayAlto

there's an epidemic of fake learning. duolingo, tiktok, youtube. it's all entertainment cleverly disguised as education. real learning is hard. it's uncomfortable. if it feels 'fun', you probably aren't learning anything.

English
299
1K
27.7K
3.6M
Isaac Dunham retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
New research shows Credential Guard can still leak creds By abusing Remote Credential Guard, attackers can request NTLMv1 challenge responses and recover NT hashes - even on fully patched Windows 11 with VBS and PPL - Microsoft confirmed and marked it “won’t fix.” - PoC called DumpGuard Full write-up by @SpecterOps specterops.io/blog/2025/10/2…
Florian Roth ⚡️ tweet media
English
5
79
270
49.4K
Isaac Dunham
Isaac Dunham@DunhamSec·
I wrote a blog post about dealing with "The Modern Phish" - an email from a legitimate email address, passing all SPF/DKIM/DMARC checks, returning no results from URL scanners, and generally originating from a compromised business email address. isaacdunham.github.io/posts/the-mode…
English
0
0
0
48
Isaac Dunham retweetledi
Nagli
Nagli@galnagli·
We found a way to access Max Verstappen's passport, driver's license, and personal information. Along with every other @Formula1 driver's sensitive data. It took us 10 minutes using one simple security flaw 🧵
Nagli tweet media
English
126
613
5.9K
2.9M
Isaac Dunham retweetledi
Karsten Hahn
Karsten Hahn@struppigel·
Good news, the intermediate malware analysis course is almost finished. I have currently a test student working through the course to get rid of mistakes that I do not notice.
English
3
3
84
4.5K
Isaac Dunham retweetledi
Squiblydoo
Squiblydoo@SquiblydooBlog·
Fake DBeaver signed by "LLC Vtorsintez" 🇷🇺 MD5: 4fa9f678df14a33e2e5480d63604f811 (Too big for MalwareBazaar) https://tria[.]ge/250711-n4tsnst1fs/behavioral1 Anti-analysis: wmic memorychip get Capacity -> exits h/t @g0njxa @JAMESWT_WT
Squiblydoo tweet media
English
2
8
19
2.1K
Isaac Dunham
Isaac Dunham@DunhamSec·
@SamErde We had monitoring based on this: learn.microsoft.com/en-us/azure/az… KQL starting point: Usage | where TimeGenerated > ago(30d) | where IsBillable == true | summarize BillableDataGB = sum(Quantity) / 1000 by bin(StartTime, 1d), DataType | render columnchart
English
0
0
7
262
Sam Erde
Sam Erde@SamErde·
Question for #Azure, #Sentinel, and maybe #KQL friends: is there any way to drill my Microsoft Sentinel monthly costs to determine which data sources (or tables) are contributing the most to the accumulated cost? #MicrosoftSentinel
Sam Erde tweet media
English
11
3
42
7K