Vadim Gordas

153 posts

Vadim Gordas

Vadim Gordas

@VGordas

Head of InfoSec Risk, opinions are my own.

London, England Katılım Ekim 2014
884 Takip Edilen93 Takipçiler
Vadim Gordas retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
For most of 2025, I was skeptical that AI was already playing a major operational role in real intrusions. Most public examples seemed limited to phishing and supporting tasks. This report by my friend Eyal Eyal lines up with what I have been hearing elsewhere, too - in recent publications and in private conversations with people seeing this stuff up close. I think that phase is over. AI is moving into the operational core of attacks. With stronger models, open models, and jailbroken variants circulating, the economics have changed. Tailored tooling, exploit adaptation, and large-scale analysis get cheaper and faster. I expect AI to play a major role in future campaigns, and that means more variation, more fresh tooling, and less reliance by attackers on recycled code. All the more reason to focus on controls and detections that do not depend only on known samples. Worth reading.
Eyal Sela@eyalsela

Technical report released: The AI-Assisted Breach of Mexico’s Government Infrastructure gambit.security/blog-post/a-si…

English
10
56
289
50.2K
Vadim Gordas retweetledi
Matt Zorich
Matt Zorich@reprise_99·
One of our very smart Active Directory experts has been putting together a series of blog posts about hardening AD. Already into its 7th installment, it covers SMB hardening, disabling NTLMv1, least privilege and more. Check the series out - techcommunity.microsoft.com/tag/adhardening
English
4
254
878
50.6K
Vadim Gordas retweetledi
Sam Stepanyan
Sam Stepanyan@securestep9·
CISA releases a Secure Software Development Attestation Form that will help ensure the software producers who partner with the US federal government leverage minimum secure development techniques and toolsets: cisa.gov/resources-tool…
English
0
1
1
308
Vadim Gordas retweetledi
Mark Simos
Mark Simos@MarkSimos·
The long-awaited Microsoft Cybersecurity Reference Architectures (MCRA) update is now live! aka.ms/MCRA In addition to the latest products & names, this is the first MCRA version integrated into the Microsoft Security Adoption Framework (SAF). Share and Enjoy!
English
6
161
414
47K
Sam Stepanyan
Sam Stepanyan@securestep9·
Hundreds of millions of #Twitter users using SMS for 2FA will have their accounts suspended if they don't upgrade to paid Twitter by 19th March 2023. I wonder how long until @elonmusk starts charging Tesla drivers $8/hour for wearing seatbelts while driving 🤔
Sam Stepanyan tweet media
English
1
3
17
3K
Vadim Gordas retweetledi
Lesley Carhart
Lesley Carhart@hacks4pancakes·
Tech people on Twitter be like, "just buy and install a pi hole to make your $2000 smart TV not play constant ads and narc on your viewing habits"
English
124
239
2.4K
0
Vadim Gordas
Vadim Gordas@VGordas·
There is some truth in it:
Vadim Gordas tweet media
English
0
0
1
0
Vadim Gordas retweetledi
Sophos X-Ops
Sophos X-Ops@SophosXOps·
NEW: Conti affiliates use ProxyShell Exchange exploit in ransomware attacks ⚠️ In one of the ProxyShell-based attacks observed by Sophos, the Conti affiliates managed to gain access to the target’s network and set up a remote web shell in under a minute... 1/14
Sophos X-Ops tweet media
English
8
241
512
0
Vadim Gordas retweetledi
rik van duijn
rik van duijn@rikvduijn·
Wanted to do a quick blog on o365 audit logging and its quirks for a while now. Finally finished it. TLDR: enable it even if you dont monitor any of it. Atleast your incident responder will thank you. zolder.io/office-365-aud…
English
1
57
193
0
Vadim Gordas retweetledi
Forrest Brazeal
Forrest Brazeal@forrestbrazeal·
The recent "All the ways to run containers on AWS" threads have left me super confused so I made this flowchart to help. It's probably also wrong.
Forrest Brazeal tweet media
English
37
441
2.2K
0
Vadim Gordas retweetledi
Chris Wysopal
Chris Wysopal@WeldPond·
Syncing your phone to the car or having a built in GPS are privacy risks. Cars don’t have the data protection of a modern phone. jalopnik.com/the-feds-can-a…
English
14
131
304
0
Vadim Gordas retweetledi
Alex Ionescu
Alex Ionescu@aionescu·
What fresh hell is this?
Alex Ionescu tweet media
English
125
440
5.5K
0
Vadim Gordas retweetledi
Troy Hunt
Troy Hunt@troyhunt·
Just to add to this, look at ParkMobile’s password requirements then look at the cracked passwords and ask yourself: do those requirements help people make good passwords? No, of course not, that’s why we ditched that craziness years ago: troyhunt.com/passwords-evol…
Troy Hunt tweet media
English
5
13
100
0