Aiden Mitchell retweeted
Can someone add me to the US DOT group chat? I just want to talk about trains.
9
69
1,878
43,681
Park in FSD doesn't work at all, lol
Tesla now has one thing left to do on this list
2
54
Aiden Mitchell retweeted
Scammers are using distribution lists to hide their tracks while blasting a wide range of targets in this new variant of Living Off the Land (LOTL) + callback phishing attacks. We’ve seen it with trusted brands like Microsoft, Venmo, and PayPal. Learn how the scam works: sublime.security/blog/callba…
3
8
1,321
New @sublime_sec rule out for this, utilizing our ability to run YARA rules on attachments: sublime.security/feeds/core/… Looking back, we've seen this technique in use for some time. FWIW, Office does warn you that the document is corrupted, and only to click "yes" if you trust it.
🚨ALERT: Potential ZERO-DAY, Attackers Use Corrupted Files to Evade Detection 🧵 (1/3) ⚠️ The ongoing attack evades #antivirus software, prevents uploads to sandboxes, and bypasses Outlook's spam filters, allowing the malicious emails to reach your inbox The #ANYRUN team discovered that as part of this #zeroday attack, threat actors attempt to conceal the file type by deliberately corrupting it, making it difficult for certain security tools to detect 📌 Our sandbox solves this problem thanks to interactivity. It launches these broken files in their corresponding programs, which allows it to identify #malicious behavior See example: app.any.run/tasks/6839e806-5… 🚫 Although these files operate successfully within the OS, they remain undetected by most security solutions due to the failure to apply proper procedures for their file types They were uploaded to VirusTotal, but all antivirus solutions returned "clean" or “Item Not Found” as they couldn't analyze the file properly
2
9
11
1,472
Aiden Mitchell retweeted
EML attachments are a clever way to bypass traditional analysis because they automatically get rendered and embedded in the original message, without user interaction, by most mail clients: sublime.security/blog/hidden… h/t @amitchell516
20
58
5,359
Please, everyone, use an ad blocker.
The way that Google handles accepting and displaying search advertising is the opposite of "Secure by Design". arstechnica.com/security/202…
5
71
Yeah, I won’t believe it until I see it, what with Google’s history of killing things at random.
Am I the only one who thinks 7 years of OS updates is just completely unnecessary? It feels like it’s just for marketing. That would be like the original Pixel running Android 14. Completely impractical, and a terrible experience.
3
115
Aiden Mitchell retweeted
Canada 🤝 United States Pick New Speakers
5
21
222
15,016
why make employees suffer with these useless assessments, when you could invest in better email security punishing employees for failing phishing tests is not the answer...
Recently had to do @KnowBe4's "Security Awareness Proficiency Assessment", and I've got to say, I think it's actively harmful to improving security. Let's look at the questions
3
110
Aiden Mitchell retweeted
If you're running @sublime_sec, you can prevent this at your email perimeter. @delivr_to put out a detection for the WinRAR vuln when the CVE initially dropped: share.sublime.security/feeds…
North Korean hackers exploits WinRAR vulnerability (CVE-2023-38831) to attack the digital currency industry. wallet_Screenshot_2023_09_06_Qbao_Network.zip virustotal.com/gui/file/40d1… report: paper.seebug.org/3032/
7
15
4,330
Average age of last reboot time on core switches.
9
10
89
9,612
Can confirm, it just works. Now it looks like I have a FortiGate at home :p maybe tomorrow it'll look like I have a Sophos firewall
someone in GN Sensors Early Access just asked if their beefy 16gb ram server would be enough to run a GreyNoise sensor👀 512mb ram to run literally anything from lighttpd to Microsoft Exchange and beyond. if it can run wireguard and iptables, itll run. docs.greynoise.io/docs/senso…
1
5
1,693
Aiden Mitchell retweeted
141
1,581
8,101
631,772
Aiden Mitchell retweeted
This is so sick. Email -> Attached EML -> Embedded image -> OCR -> NLU to identify a financial request. Outlook/many clients will render an attached EML in the *original* message, making this an effective evasion technique. We've seen this in the wild recently. h/t @amitchell516
1
10
32
1,627
#SkyTrain update: Expo Line trains from Waterfront will turnback at Metrotown. All trains from King George & Production Way will turnback at Edmonds outbound. No service between Edmonds & Metrotown. @TransLink
1
216
Passengers, use the 119 buses at Metrotown and Edmonds to bridge the gap.
78
Aiden Mitchell retweeted
Sublime has observed an increase in QR code credential phishing attacks over the past several weeks. We've enabled a new scanner to decode QR codes embedded in message bodies or attachments, and pushed new coverage to prevent these attacks: github.com/sublime-security/…
4
24
69
88,149