Scarlet Shark Security

347 posts

Scarlet Shark Security banner
Scarlet Shark Security

Scarlet Shark Security

@ScarletSharkSec

Digital Security Intelligence

Washington D.C. Katılım Ocak 2020
1.8K Takip Edilen642 Takipçiler
Scarlet Shark Security
Scarlet Shark Security@ScarletSharkSec·
@MatrixGlitch1 @dcuthbert Most browsers use DNS over HTTPS by default these days. And it's difficult to obtain a valid alternative cert for a website / domain you don't control.
English
2
0
1
22
Matrix_Glitch
Matrix_Glitch@MatrixGlitch1·
@dcuthbert In 2016 only 40% of sites were HTTPS compared to about 85% today. That as well as HSTS & certificate pinning has changed the landscape a bit. Only need one site or app to use plain HTTP to silently inject your own stuff. Redirecting via DNS + different SSL certificate works
English
1
0
0
57
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
I too am over the "dont use public wifi" brigade. Often the advice is from tests done over a decade so, so it's good to see someone actually testing what modern devices behave like when interception is happening.
mRr3b00t@UK_Daniel_Card

Can anyone tell me why the public WiFi with an attacker in it is unsafe? I can read all the targets traffic metadata but I can’t read their traffic. Anybody? The ASD say it’s not safe but I’m not really sure why….. If you can show me an attack that will do something let me know I’ll run it here now!

English
26
24
234
77.9K
Scarlet Shark Security
Scarlet Shark Security@ScarletSharkSec·
DHL delivery failure themed #phishing hXXps://accomplish-delivery.change-server.info Threat actors are using email addresses from a NameCheep data breach after August 2022.
English
0
1
1
664
Samson
Samson@samson2655·
Interesting document #maldoc 313a743ed5558caa203fd873c22a178d6e4fed8c3ca75d40f827eeedccf31c37 PE: 180510ab8cde8a3828aa81289895458f IoCs: hxxp://""hxxp://asenal.medianewsonline.com/good/luck/flavor/list.php?query=1"" @InQuest @James_inthe_box @Ledtech3
Samson tweet media
English
1
2
9
0
Łukasz
Łukasz@maldr0id·
"Madware is short for mobile adware" Can we stop with coming up with new names for malware just so that we can sell more stuff?
Łukasz tweet media
English
10
3
59
0
Scarlet Shark Security
Scarlet Shark Security@ScarletSharkSec·
Quick correction there was a LNK in the ISO disk image as well.
English
0
0
1
0