Manuel Urueña

8.4K posts

Manuel Urueña

Manuel Urueña

@muruenya

Security Architect at @RedeiaCorp. Entropy fighter. @[email protected] @muruenya.bsky.social

Katılım Mart 2011
1.2K Takip Edilen336 Takipçiler
Manuel Urueña retweetledi
Sean Lyngaas
Sean Lyngaas@snlyngaas·
US charges and extradites 33-year-old Ukrainian woman for her alleged role in pro-Russia hacking group that caused spillage at a Texas water plant and an ammonia leak at a meat processing plant in LA. cnn.com/2025/12/10/pol…
English
0
9
17
3.6K
Manuel Urueña retweetledi
John Hultquist
John Hultquist@JohnHultquist·
DOJ confirms our earlier assessment of ties between hacktivist front Cyber Army of Russia Reborn (CARR) and Russia’s military intelligence service, the GRU. CARR carried out cyberattacks on US and European critical infrastructure but hid behind this false persona. justice.gov/opa/pr/justice…
English
3
68
161
23.3K
Manuel Urueña retweetledi
ClearSky Cyber Security
ClearSky Cyber Security@ClearskySec·
A new wiper attack has been identified by ClearSky Cyber Security affecting Ukraine. We named this wiper "GamaWiper" (VBS-based wiper). The intrusion chain begins with the exploitation of a vulnerable WinRAR version (CVE-2025-80880). We assess with moderate confidence that this activity is linked to the Gamaredon APT group. This marks the first observed instance of Gamaredon conducting destructive operations rather than its traditional espionage activities. Related IoCs: 95262c4094a9a5e589a218e354ef54b3800aa0abc3b6a343bbcfdcbf021fc04f – initial ZIP with vulnerability CVE-2025-80880 68e21d7599d20444232415a7e74214ce50d7b4643215d83b8320e74c95a9dfd3 – downloaded VBA aafa4c206495163a5e408aa5c296139fe9f330a9f819a226c6934921493de9c6 – downloaded (padded+base64) wiper d4ce4776bdad9b741a1e8345b41737245b80f4cf8d361ebb1ae5415c7a4fe1eb – base64 encrypted wiper 9a39423ec90dc06a3058279cd744c08d83252d1c7096633b9853e435cc205755 – deobfuscated wiper Network: dears[.]serveirc[.]com whitesalad[.]zzrak08526[.]workers[.]dev
ClearSky Cyber Security tweet media
English
6
47
118
312.9K
Manuel Urueña retweetledi
sapir federovsky
sapir federovsky@sapirxfed·
This is simply an amazing talk. Except the subject itself and the REALLY GOOD explanations, Some really interesting research and detection methods hide in this post. BTW, I used the same methods in some of my researches lately, and found similar insights. knowing I'm in the "right" research mindset makes me so proud. It was worth the wait! @WEareTROOPERS @fabian_bader @_dirkjan youtube.com/watch?v=yYQBeD…
YouTube video
YouTube
English
0
7
60
9.5K
Manuel Urueña retweetledi
Christo Grozev
Christo Grozev@christogrozev·
GRU's Spy Airbnb: check out our latest video investigation into Unit 29155, and the "Czech" spy couple they used to help them plant explosives in weapons depots. youtu.be/tRqcJV0Z55c?si…
YouTube video
YouTube
English
14
192
620
101.2K
Manuel Urueña retweetledi
Print3M
Print3M@Print3M_·
Let me explain where this incredible vulnerability in Notepad++ comes from... my blog post from 3w ago. The problem is there's no vuln. I described this as sneaky init access. You might as well do binary patching of any PE file in the world. #infosec print3m.github.io/blog/dll-sidel…
English
4
49
190
21K
Manuel Urueña retweetledi
thaddeus e. grugq
thaddeus e. grugq@thegrugq·
The vast majority of hacking is just credentials. There are four basic ways to get creds: STAB Steal: using malware, etc. Try: brute force, guessing, etc. Ask: social engineering, etc. Buy: infostealer logs, etc. Steal. Try. Ask. Buy. A collab with @UK_Daniel_Card
English
27
142
792
58.9K
Manuel Urueña retweetledi
Flipper Devices
Flipper Devices@flipper_net·
Right now, the media is hyping up a story that a SECRET HACKER FIRMWARE FOR FLIPPER ZERO HAS APPEARED ON THE DARKNET THAT CAN HACK ANY CAR!!!11 WE’RE ALL IN DANGER. Let’s break it down and see if that’s actually true (spoiler: it’s not): blog.flipper.net/can-flipper-ze…
Flipper Devices tweet media
English
28
274
1.9K
248.4K
Manuel Urueña retweetledi
Kim Zetter
Kim Zetter@KimZetter·
Two yrs ago when researchers found backdoor in encryption algo used to secure radio comms for police/military/intel agencies, the org behind algo told users to deploy end-to-end encryption on top of it. Now researchers found security prob with the E2E too wired.com/story/encrypti…
English
1
33
59
11.6K
Manuel Urueña retweetledi
Mandiant (part of Google Cloud)
Mandiant has observed an increasing number of attacks targeting VMware vSphere in recent years, notably for deploying ransomware. Dive deep into what specifically is fueling this trend and get actionable guidance to defend your VMware vSphere estate in our latest blog posts. 👇
Mandiant (part of Google Cloud) tweet media
English
1
49
134
13K
Manuel Urueña retweetledi
Dwyer
Dwyer@_Dwyer_·
Dudes... please enable Detailed File Share auditing in your environment. All these attackers who switched over to the Impacket suite still run the default configs and it takes like 2 seconds to find them.
Dwyer tweet media
English
5
60
332
56.1K
Manuel Urueña retweetledi
John Scott-Railton
John Scott-Railton@jsrailton·
🚨NEW REPORT: exposing a new hacking tactic. 🇷🇺Russian state-backed hackers used an App-Specific Password attack against prominent Russia expert @KeirGiles & others. It's like they know what we all expect from them...and then did the opposite 1/ By us @citizenlab & @google's GTIG
John Scott-Railton tweet mediaJohn Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
9
155
472
104.9K
Manuel Urueña retweetledi
Hamid Kashfi
Hamid Kashfi@hkashfi·
1.CodeBreakers emerges, hacking Sepah bank. 2.They demand $42M for ransom, 3. Release the most valuable chunks of records for free, while hardly pushing sponsored PR! 4.They disappear and the tg. group is gone 5.Predatory Sparrows drops in and nuke the Sepah bank. 2+2=3.14?
English
0
8
27
5.8K
Manuel Urueña retweetledi