Aiden Mitchell

375 posts

Aiden Mitchell banner
Aiden Mitchell

Aiden Mitchell

@amitchell516

Moved to https://t.co/NibbrE5Ia2

Canada Katılım Aralık 2021
1.1K Takip Edilen88 Takipçiler
Aiden Mitchell retweetledi
Hayden
Hayden@the_transit_guy·
Can someone add me to the US DOT group chat? I just want to talk about trains.
Hayden tweet media
English
9
74
1.9K
43.7K
Aiden Mitchell retweetledi
Sublime Security
Sublime Security@sublime_sec·
Scammers are using distribution lists to hide their tracks while blasting a wide range of targets in this new variant of Living Off the Land (LOTL) + callback phishing attacks. We’ve seen it with trusted brands like Microsoft, Venmo, and PayPal. Learn how the scam works: sublime.security/blog/callback-…
Sublime Security tweet media
English
0
3
8
1.3K
Aiden Mitchell
Aiden Mitchell@amitchell516·
New @sublime_sec rule out for this, utilizing our ability to run YARA rules on attachments: sublime.security/feeds/core/det… Looking back, we've seen this technique in use for some time. FWIW, Office does warn you that the document is corrupted, and only to click "yes" if you trust it.
ANY.RUN@anyrun_app

🚨ALERT: Potential ZERO-DAY, Attackers Use Corrupted Files to Evade Detection 🧵 (1/3) ⚠️ The ongoing attack evades #antivirus software, prevents uploads to sandboxes, and bypasses Outlook's spam filters, allowing the malicious emails to reach your inbox The #ANYRUN team discovered that as part of this #zeroday attack, threat actors attempt to conceal the file type by deliberately corrupting it, making it difficult for certain security tools to detect 📌 Our sandbox solves this problem thanks to interactivity. It launches these broken files in their corresponding programs, which allows it to identify #malicious behavior See example: app.any.run/tasks/6839e806… 🚫 Although these files operate successfully within the OS, they remain undetected by most security solutions due to the failure to apply proper procedures for their file types They were uploaded to VirusTotal, but all antivirus solutions returned "clean" or “Item Not Found” as they couldn't analyze the file properly

English
2
9
12
1.5K
Aiden Mitchell retweetledi
Josh Kamdjou
Josh Kamdjou@jkamdjou·
EML attachments are a clever way to bypass traditional analysis because they automatically get rendered and embedded in the original message, without user interaction, by most mail clients: sublime.security/blog/hidden-cr… h/t @amitchell516
English
0
20
58
5.3K
Aiden Mitchell retweetledi
Polling Canada
Polling Canada@CanadianPolling·
Canada 🤝 United States Pick New Speakers
English
5
21
226
15K
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
In high school I port-scanned the entire district network internally and sent direct prints to district HQ printers complaining about their lack of segmentation.
Dodge This Security@shotgunner101

@malwrhunterteam You'd be surprised how people learned Infosec before degrees, certifications, and things like virtual machine software existed and were common place. Many k-12 schools got to experience kids cyber pranks. Obviously without authorization.

English
58
42
903
168.6K
Aiden Mitchell
Aiden Mitchell@amitchell516·
why make employees suffer with these useless assessments, when you could invest in better email security punishing employees for failing phishing tests is not the answer...
Cybergibbons 🚲🚲🚲@cybergibbons

Recently had to do @KnowBe4's "Security Awareness Proficiency Assessment", and I've got to say, I think it's actively harmful to improving security. Let's look at the questions

English
0
0
3
110
Aiden Mitchell retweetledi
Aiden Mitchell retweetledi
Frank McGovern - INACTIVE
Frank McGovern - INACTIVE@FrankMcG·
Average age of last reboot time on core switches.
Frank McGovern - INACTIVE tweet media
English
9
10
90
9.6K
Aiden Mitchell retweetledi
Amtrak
Amtrak@Amtrak·
Amtrak tweet media
ZXX
144
1.6K
8.3K
631.6K
Aiden Mitchell retweetledi
Josh Kamdjou
Josh Kamdjou@jkamdjou·
This is so sick. Email -> Attached EML -> Embedded image -> OCR -> NLU to identify a financial request. Outlook/many clients will render an attached EML in the *original* message, making this an effective evasion technique. We've seen this in the wild recently. h/t @amitchell516
Josh Kamdjou tweet media
English
1
10
32
1.6K
Aiden Mitchell
Aiden Mitchell@amitchell516·
@TransLink Turn backs have now been cancelled, end-to-end service restored. Expect delays, as there is still single tracking in place.
English
0
0
0
46
Aiden Mitchell
Aiden Mitchell@amitchell516·
@TransLink Passengers, use the 119 bus at Metrotown and Edmonds to bridge the gap.
English
1
0
0
314
TransLink BC
TransLink BC@TransLink·
#SkyTrain Expo Line service between Edmonds Stn and Metrotown Stn is suspended beginning at 8:30 AM due to technical issue. Trains will be running between Waterfront & Metrotown Stn, and between Edmonds to Production-Way and King George Stn. M-line and Canada Line Unaffected. ^SM
English
4
0
5
7.5K