Stephan - ObiWan666 - Gerling

27.3K posts

Stephan - ObiWan666 - Gerling banner
Stephan - ObiWan666 - Gerling

Stephan - ObiWan666 - Gerling

@obiwan666

Bluesky @ObiWan666, Yacht Security, Firefighter, Security Evangelist, Speaker, IT & ICS Security, "Geraffel", IoT Hacker, Lingen (Ems)

Deutschland Katılım Mart 2012
777 Takip Edilen2.1K Takipçiler
Stephan - ObiWan666 - Gerling retweetledi
Boris Larin
Boris Larin@oct0xor·
We analyzed the Coruna exploit kit and found intriguing code overlaps with Operation Triangulation. Full analysis on our blog: link below.
Boris Larin tweet media
English
3
90
429
35.2K
Stephan - ObiWan666 - Gerling retweetledi
blackorbird
blackorbird@blackorbird·
#Sandworm Targeted RDP Backdoor Campaign (2024-2026) The group has fully evolved its operational strategy from high-impact instantaneous system destruction to intelligence-driven, long-term stealthy persistence. The campaign leverages a highly modular, iterated attack framework (Tambur/Sumbur/Kalambur/DemiMur) targeting global defense industry, critical infrastructure, and government entities. mp.weixin.qq.com/s/QWe2m4qdp45u…
blackorbird tweet mediablackorbird tweet media
English
0
35
121
10.1K
Stephan - ObiWan666 - Gerling retweetledi
Hunt.io
Hunt.io@Huntio·
📌 Looking Back: Iranian APT Infrastructure in Focus hunt.io/blog/iranian-a… Two weeks ago, we analyzed infrastructure linked to several Iranian-aligned threat groups. Pivoting across IPs, hashes, ASNs, and TLS certificates revealed clusters tied to actors like MuddyWater and APT35. In one case, a single IP exposed attacker tooling, additional servers in the same hosting network, and a short-lived Sliver C2 instance. Infrastructure patterns like these often appear weeks before campaigns become widely reported. #ThreatIntelligence #ThreatHunting #CyberSecurity
English
0
15
63
4.4K
Stephan - ObiWan666 - Gerling retweetledi
Ryan Naraine
Ryan Naraine@ryanaraine·
Two full iOS exploit kits in one month, deployed via watering holes on public websites, potentially affecting hundreds of millions of devices. Will Apple acknowledge that this no longer fits the "very small number of highly targeted individuals" narrative?
Ryan Naraine tweet media
English
14
138
716
111.9K
Stephan - ObiWan666 - Gerling retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
❗️Meet Hellcat ransomware group operator 'Pryx' — responsible for high-profile hacks like Jaguar Land Rover, Telefonica, Schneider Electric and many more. He started doing cybercrime as a kid. He got 4 people killed and 27 injured after starting a fire by hacking into the SCADA network of Telecom Egypt. An OSINT researcher just revealed who he is and how he tracked him down.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
32
203
1.8K
465.3K
Stephan - ObiWan666 - Gerling retweetledi
Alex. Turing
Alex. Turing@TuringAlex·
🚨An interesting #ELF sample da2e396baf23de1881d06dd3377f84a6 on VT, packed by modified upx, appears to be a #PLC program for traffic light control, but why does it contain an embedded XOR code to establish a reverse shell to 173.180.247[.]200🤔? #IOC Happy hunting 🍷@Xlab_qax
Alex. Turing tweet mediaAlex. Turing tweet media
English
2
20
97
6.8K
Stephan - ObiWan666 - Gerling retweetledi
VECERT Analyzer
VECERT Analyzer@VECERTRadar·
🚨 ALERT: Alleged Escalation in the Israel-Iran Cyberwar 🇮🇱🇮🇷 A series of alleged high-impact cyber intrusions against critical Israeli infrastructure have been reported, attributed to hacktivist groups claiming ties to Russian entities. These operations are part of the growing conflict of cyber espionage and cyberattacks affecting the region. Dimona Nuclear Power Plant: The group "Cardinal" has published evidence of an alleged intrusion into the systems of the Israeli nuclear power plant, explicitly declaring its affiliation with Russia. Intelligence and Emergencies: The actor "cardinalhackers" claims to have compromised Mossad documents and operating systems of the National Emergency Management Authority (RAHEL). It is important to note that these incidents are alleged and remain under technical investigation. The apparent involvement of actors with likely Russian origins suggests a growing complexity and escalation of the digital theater of operations in the regional conflict. Monitor: analyzer.vecert.io #CyberSecurity #ThreatIntel #CyberWar #Israel #Iran #Dimona #InfoSec #CyberAlert
VECERT Analyzer tweet media
English
1
13
30
2.2K
Stephan - ObiWan666 - Gerling retweetledi
John Scott-Railton
John Scott-Railton@jsrailton·
BREAKING: powerful iPhone hacking tools used by Chinese criminals originated from US defense giant L3 Harris. The $LHX zero-click exploits went to Russian spies too. Unbelievable harm to our collective security. Scoop by @lorenzofb, here's why this matters 1/
John Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
34
883
2.4K
268K
Stephan - ObiWan666 - Gerling retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
After 5 months of development, I'm releasing EvilWAF v2.4 - a MITM proxy that makes ANY tool bypass WAFs github.com/matrixleons/ev…
English
18
314
1.5K
130.1K
Stephan - ObiWan666 - Gerling retweetledi
Oleg Shakirov
Oleg Shakirov@shakirov2036·
Kaspersky recently produced a podcast on Operation Triangulation, basically a story of the investigation Things that I haven't seen mentioned elsewhere: — Triangulation malware existed for >10 years — Some technical details similar to the Equation Group youtube.com/watch?v=j4pCKh…
YouTube video
YouTube
Oleg Shakirov tweet media
English
3
31
135
31.2K
Stephan - ObiWan666 - Gerling retweetledi
Boris Larin
Boris Larin@oct0xor·
Amazing find by Google and iVerify, but a vulnerability isn’t a component. An exploit or implant may be a component, not the vulnerability itself. Both CVEs now have public implementations. I see no evidence of code reuse in the technical reports to support that attribution.
Boris Larin tweet media
English
3
5
77
8K
Stephan - ObiWan666 - Gerling retweetledi
joernchen
joernchen@joernchen·
Lands of Packets TTL exceeded. I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de. If anyone would like to contribute, please contact me. Mail: joernchen@phenoelit.de Signal: jrn.07
English
1
26
39
6.1K
Stephan - ObiWan666 - Gerling retweetledi
The Figen
The Figen@TheFigen_·
Cartoons are real.
English
367
1.8K
12K
446.4K
Stephan - ObiWan666 - Gerling retweetledi
blackorbird
blackorbird@blackorbird·
In the renewable energy sector, an attack targeted at least 30 wind and solar farms in Poland. The attack resulted in a loss of communication between the facilities and distribution system operators (DSOs), but it did not affect ongo‑ing electricity generation. #IOCs #APT #Wiper CERT Polska Energy Sector Incident Report 2025 github.com/blackorbird/AP… #Sandworm DynoWiper update: Technical analysis and attribution welivesecurity.com/en/eset-resear… dragos 2025 poland attack report github.com/blackorbird/AP…
blackorbird tweet mediablackorbird tweet mediablackorbird tweet mediablackorbird tweet media
English
0
6
22
7.8K
Stephan - ObiWan666 - Gerling retweetledi
Georgy Kucherin
Georgy Kucherin@kucher1n·
Imagine your #antivirus starts deploying malware after an update. This is exactly what happened with the eScan solution last week - the supply chain attack was discovered by @morphisec. We have analyzed the #malware used in this attack - and found lots of cool stuff! [1/7]
Georgy Kucherin tweet media
English
5
49
201
23.8K
Stephan - ObiWan666 - Gerling retweetledi
non aesthetic things
non aesthetic things@PicturesFoIder·
Beer distribution system
English
106
195
8K
1.7M