Arda Büyükkaya

3.7K posts

Arda Büyükkaya banner
Arda Büyükkaya

Arda Büyükkaya

@WhichbufferArda

Cyber Threat Intelligence Analyst at Rabobank | Threat Hunter | Malware Analyst |. (All opinions expressed here are mine only). 🇳🇱

The Netherlands شامل ہوئے Nisan 2022
1.4K فالونگ4.9K فالوورز
Arda Büyükkaya
Arda Büyükkaya@WhichbufferArda·
This week I presented at BSides Den Haag 🇳🇱, one of the rare cybersecurity events that brings together industry veterans and new talent under one roof. If you're starting your journey in cybersecurity, the networking here is unmatched.
Arda Büyükkaya tweet mediaArda Büyükkaya tweet media
English
0
1
8
370
Arda Büyükkaya ری ٹویٹ کیا
Polymarket
Polymarket@Polymarket·
BREAKING: Cyberattack against American breathalyzer test company locks out drivers across 45 states.
English
896
2.7K
23.7K
6.8M
Arda Büyükkaya ری ٹویٹ کیا
FBI Director Kash Patel
FBI Director Kash Patel@FBIDirectorKash·
The @FBI has identified cyber actors associated with Russian Intelligence Services targeting users of commercial messaging applications, including Signal. The campaign targets individuals of high intelligence value, including current and former U.S. government officials, military personnel, political figures, and journalists.   Globally, this effort has resulted in unauthorized access to thousands of individual accounts. After gaining access, the actors can view messages and contact lists, send messages as the victim, and conduct additional phishing from a trusted identity. It's important for you to be aware and take action - this vulnerability is not with the application - but you as the end user.   The FBI and CISA have released a joint PSA to help you identify this activity and protect your accounts: ic3.gov/PSA/2026/PSA26…
English
2.6K
4.1K
14.3K
1.9M
Arda Büyükkaya ری ٹویٹ کیا
Who said what?
Who said what?@g0njxa·
Malware trends in 2026: Using bot accounts in @virustotal to boost the community score 60171e71774630b9f5c824e2a4ee4742aff1461e0c1910395430ba1592c469cd C2: foxkids[.]us It won't work, makes it even more suspicious and your EV signature will be revoked anyways! Try harder ;)
Who said what? tweet mediaWho said what? tweet media
English
7
18
96
8.5K
Arda Büyükkaya ری ٹویٹ کیا
SecurityWeek
SecurityWeek@SecurityWeek·
The US has for the first time officially linked the Handala hacker group to the Iranian government. The announcement came amid the takedown of several websites used by Handala. securityweek.com/us-confirms-ha…
English
0
4
8
1.3K
Arda Büyükkaya ری ٹویٹ کیا
Feross
Feross@feross·
🚨 Breaking: Trivy GitHub Actions supply chain attack – 75 out of 76 version tags compromised. If your CI/CD pipelines reference “aquasecurity/trivy-action” by version tag, you’re likely running malware right now. At Socket, we identified that an attacker force-pushed nearly every version tag in the official aquasecurity/trivy-action repository. That’s @​0.0.1 all the way through @​0.34.2. Over 10,000 GitHub workflow files reference this action. The malicious payload runs silently before the legitimate Trivy scan, so nothing looks broken. Meanwhile it’s: - Dumping runner process memory to extract secrets - Harvesting SSH keys - Exfiltrating AWS, GCP, and Azure credentials - Stealing Kubernetes service account tokens The only unaffected tag right now appears to be @​0.35.0. Socket independently detected this at 19:15 UTC and generated 182 threat feed entries tied to this campaign – all correctly classified as Backdoor, Infostealer, or Reconnaissance malware. This is the second Trivy compromise this month. Earlier in March, attackers injected code into the Aqua Trivy VS Code extension on OpenVSX to abuse local AI coding agents. The compromised tags are still active. Pin to @​0.35.0 or use a SHA reference until this is fully remediated. Full write-up: socket.dev/blog/trivy-und…
English
12
112
375
211.5K
Arda Büyükkaya ری ٹویٹ کیا
Forbes
Forbes@Forbes·
Iran's cyber espionage groups have been intermittently active since the war with the U.S. and Israel began, with one notable breach of a U.S. company. Read more: forbes.com/sites/the-wire… (Illustration: Getty Images)
Forbes tweet media
English
3
13
43
13.2K
Arda Büyükkaya ری ٹویٹ کیا
watchTowr
watchTowr@watchtowrcyber·
What's new is old, and what's old is new - as is relentlessly proven. Join us in our analysis of CVE-2026-32746, the recent pre-auth RCE in inteutils' Telnetd Speak soon. labs.watchtowr.com/a-32-year-old-…
English
1
38
111
11.3K
Arda Büyükkaya ری ٹویٹ کیا
Andy Greenberg (@agreenberg at the other places)
This tool has already been used in distinct hacking campaigns against Ukrainians, Malaysians, Saudi and Turkish victims. If other hackers needed any more encouragement to adopt it, too, the Russian spies who used it left it fully unobfuscated with helpful code comments legible.
Andy Greenberg (@agreenberg at the other places)@a_greenberg

A second iOS exploit has been spotted in use by Russian spies to infect websites and hack visitors' iPhones. This one works on iOS 18, and appeared in a very reusable form, so will likely proliferate. If you haven't updated your iPhone, now's the time. wired.com/story/hundreds…

English
0
49
203
27.8K
Arda Büyükkaya ری ٹویٹ کیا
Bloomberg
Bloomberg@business·
The US government is warning businesses to secure their corporate accounts within a popular Microsoft management tool, following a cyberattack on Stryker last week bloomberg.com/news/articles/…
English
3
6
33
16.7K
Arda Büyükkaya ری ٹویٹ کیا
Will
Will@BushidoToken·
New Blog! The Beast Returns: Analysis of a Beast Ransomware Server 👹 In March 2026, @TeamCymru detected a Beast operator’s server that enabled us to understand the flow of their attacks from start, to middle, to the end, including ransomware binaries. team-cymru.com/post/beast-ran…
English
1
21
61
6K
Arda Büyükkaya ری ٹویٹ کیا
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
People who laugh and comment “who still uses telnet” have no idea how this industry actually works - or how power plants, warships, factories, baggage handling systems and other control and logistics systems are planned, built and expected to last for decades
The Hacker News@TheHackersNews

⚠️ WARNING - An unpatched critical telnetd bug (CVE-2026-32746) lets attackers gain full system access with no credentials. One connection to port 23 is enough to trigger memory corruption and execute code as root. No patch yet. Prior telnet flaw is already exploited in the wild. 🔗Read → thehackernews.com/2026/03/critic…

English
28
49
385
30.1K
Arda Büyükkaya ری ٹویٹ کیا
OSINTdefender
OSINTdefender@sentdefender·
Joe Kent is a heavily decorated combat veteran who served with the 75th Ranger Regiment and U.S. Special Forces. He served eleven combat tours, primarily in Iraq, and retired in 2018, becoming a paramilitary officer with the Central Intelligence Agency (CIA). His wife, Senior Chief Shannon M. Kent, was killed by a suicide bomber in Syria in 2019. I very much doubt that he was leaking anything, and I think it’s disgusting that members of the Trump Administration would attempt to circulate something like that without providing any kind of evidence, all because he decided to resign in protest of yet another war - which he has seen plenty of - in the Middle East.
OSINTdefender@sentdefender

Senior officials in the Trump Administration tell Fox News that Joe Kent was “a known leaker” - and was cut out of intelligence briefings with President Trump months ago. Adding that he had not been part of any Iran planning discussions or briefings at all. An official says the White House also told the Director of National Intelligence Tulsi Gabbard that she should fire Kent for suspected leaks, but she never had him removed as Director of the National Counterterrorism Center (NCTC).

English
788
1.9K
14.7K
1.4M