GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Brian Clark (deepthoughts10@infosec.exchange)

  1. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Monday, 13-Jul-2026 19:28:15 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont

    @GossiTheDog I’m starting to see some companies log all AI prompts and review them to see what people are using AI to do. The ones I’ve seen do this are positioning it as a way to discover additional training opportunities for their staff — to train them that they gave other, better tools to compare PDFs, for example. It makes sense if you have the tools and resources to put together this kind of analysis.

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Sunday, 05-Jul-2026 04:24:49 JST Brian Clark Brian Clark

    Happy #caturday Ran across this cat sitting on top of a mailbox on a walk. It very much enjoyed the head scratching.

    #catsofmastodon #cat

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/862/740/544/742/635/original/51d893fa34d3354e.jpeg
  3. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Thursday, 12-Mar-2026 20:05:35 JST Brian Clark Brian Clark

    RE: https://infosec.exchange/@patrickcmiller/116210592807071943

    Here are some controls to put in place to prevent this attack from happening to you:
    - Block ISO file extensions from being emailed to your users
    - Prevent downloads of ISO files from untrusted sites (such as consumer friendly file storage services)
    - Change your Windows File Explorer settings to associate the .ISO file extension with Notepad.exe so it won’t auto mount when double-clicked
    #cybersecurity

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Patrick C Miller :donor: (@patrickcmiller@infosec.exchange)
      from Patrick C Miller :donor:
      Fake job applications pack malware that disables EDR https://www.theregister.com/2026/03/10/malware_targeting_hr/
  4. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Thursday, 08-Jan-2026 08:49:29 JST Brian Clark Brian Clark
    • B'ad Samurai :ifin:

    tl;dr Block these domains and you’ll have broken several links in this attack’s kill chain:

    Webhook[.]site
    My-board[.]org
    ngrok-free[.]app
    rf[.]gd

    If you followed @badsamurai ‘s advice and used his block lists, you’d have already blocked a couple of them.

    https://www.recordedfuture.com/research/gru-linked-bluedelta-evolves-credential-harvesting #cybersecurity

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.recordedfuture.com
      GRU-Linked BlueDelta Evolves Credential Harvesting
      from Insikt Group®
      Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
  5. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Wednesday, 26-Nov-2025 09:21:06 JST Brian Clark Brian Clark
    • Kevin Beaumont

    @GossiTheDog you sure they are not just blocking your scanner?

    In conversation about 10 months ago from infosec.exchange permalink
  6. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Tuesday, 25-Nov-2025 02:10:50 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont

    @GossiTheDog it doesn’t appear that the csv files themselves are accessible. Just the listing. Or at least that’s the behavior I’m seeing right now. You seeing anything different?

    In conversation about 10 months ago from infosec.exchange permalink
  7. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Friday, 14-Nov-2025 00:51:56 JST Brian Clark Brian Clark
    • Kevin Beaumont
    • Stuart Longland (VK4MSL)

    @stuartl @GossiTheDog you absolutely should block the execution of mshta.exe. It will only block some of the ClickFix attacks, but block some other techniques too. Mshta.exe is an attacker favorite.

    While you are at it, block cscript.exe and wscript.exe too.

    In conversation about 11 months ago from infosec.exchange permalink
  8. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Friday, 14-Nov-2025 00:51:54 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont
    • Stuart Longland (VK4MSL)
    • System Adminihater

    @systemadminihater @stuartl @GossiTheDog hasn’t had a significant impact in my environment. But I imagine it depends on how much old software you have hanging around.

    In conversation about 11 months ago from infosec.exchange permalink
  9. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Friday, 14-Nov-2025 00:51:53 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont
    • Stuart Longland (VK4MSL)
    • System Adminihater

    @systemadminihater @stuartl @GossiTheDog just apply the policy blocking those exe’s after initial deployment

    In conversation about 11 months ago from infosec.exchange permalink
  10. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Sunday, 28-Sep-2025 11:05:42 JST Brian Clark Brian Clark

    While watching TV I turned around and found that I had company
    #catsofmastodon #caturday #cats

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/279/317/638/314/977/original/62bd9e69b9c3694d.jpeg
  11. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Wednesday, 24-Sep-2025 07:29:12 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont

    @GossiTheDog Steven Lim has written a Microsoft KQL detection for EDR Freeze and made it available here:

    https://detections.ai/share/rule/cicyA1JW

    In conversation about a year ago from infosec.exchange permalink
  12. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Tuesday, 23-Sep-2025 07:25:52 JST Brian Clark Brian Clark

    Zensec has a good article on the Akira ransomware group's tactics taken directly from their DFIR experience on 16+ incidents. A few key take-aways:

    - Initial Access: Please, please please patch your Internet-facing VPN and firewall devices including your Sonicwall, Cisco ASA and Watchguard devices.
    - Patch our Veeam software. They used vulnerable Veeam installs to perform privilege escalation
    - Block access to Anydesk.com and remotedesktop.google.com if you don't use those services

    #cybersecurity #ransomware
    https://zensec.co.uk/blog/unmasking-akira-the-ransomware-tactics-you-cant-afford-to-ignore/

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Chrome Remote Desktop
    2. Domain not in remote thumbnail source whitelist: anydesk.com
      The Fast Remote Desktop Application – AnyDesk
      Discover AnyDesk, the secure and intuitive remote desktop app with innovative features, perfect for seamless remote desktop application across devices.
    3. Domain not in remote thumbnail source whitelist: zensec.co.uk
      Unmasking Akira: The ransomware tactics you can’t afford to ignore
      from Francesca Meyrick
      If you are reading this because you have experienced a ransomware incident and are unsure how to deal with it, contact Zensec immediately.
  13. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Wednesday, 20-Aug-2025 22:03:31 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont

    @GossiTheDog I’m worried that they got documentation on their customer network and router configurations. That could open up a lot of new attack paths.

    In conversation about a year ago from infosec.exchange permalink
  14. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Monday, 19-May-2025 08:05:01 JST Brian Clark Brian Clark
    in reply to
    • Tim Chambers
    • Analytodon

    @tchambers @analytodon thanks for sharing. I’m going to try this out too.

    In conversation Monday, 19-May-2025 08:05:01 JST from infosec.exchange permalink
  15. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Friday, 09-May-2025 13:13:53 JST Brian Clark Brian Clark
    in reply to
    • Will Dormann

    @wdormann I assume this doesn’t work if Tamper Protection is enabled?

    In conversation Friday, 09-May-2025 13:13:53 JST from infosec.exchange permalink
  16. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Tuesday, 29-Apr-2025 07:21:01 JST Brian Clark Brian Clark
    • Kevin Beaumont

    @GossiTheDog I’m just glad the feature is off by default on managed systems and you have to have an admin specifically allow it to be enabled by an end user.

    In conversation Tuesday, 29-Apr-2025 07:21:01 JST from infosec.exchange permalink
  17. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Friday, 18-Apr-2025 06:59:14 JST Brian Clark Brian Clark
    in reply to
    • Kevin Beaumont

    @GossiTheDog I didn’t realize this part. It won’t show up in MDE logs?

    In conversation Friday, 18-Apr-2025 06:59:14 JST from infosec.exchange permalink
  18. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Thursday, 17-Apr-2025 13:08:56 JST Brian Clark Brian Clark
    • Sophos X-Ops
    • Sean Gallagher :verified: 🐀 :donor:

    Security Firm @SophosXOps published another report, this one on incidents at small and medium-sized businesses by @thepacketrat and Anna Szalay. One of the things I always look for in these reports are easy #cybersecurity wins -- and this report has a bunch of them.

    First off - take a look at this chart: Top 15 dual-use tools. Imagine the pain you can cause threat actors by blocking the use of these tools and disrupting their playbooks!

    In conversation Thursday, 17-Apr-2025 13:08:56 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/350/603/475/705/098/original/35b29599747d242d.webp
  19. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Sunday, 16-Mar-2025 04:06:04 JST Brian Clark Brian Clark
    • ScumBots

    The free service from portmap.io is being abused to support malware C2 communications. If you don’t use it, I suggest blocking *.portmap.io via DNS, NGFW and/or web proxy.

    #cybersecurity #threatintel

    From: @ScumBots
    https://infosec.exchange/@ScumBots/114167879065509347

    In conversation Sunday, 16-Mar-2025 04:06:04 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: portmap.io
      Portmap.io - free port forwarding solution
      Expose your local PC to Internet from behind firewall and without real IP address
    2. No result found on File_thumbnail lookup.
      ScumBots (@ScumBots@infosec.exchange)
      from ScumBots
      #StagedC2 config observed at Sat Mar 15 18:09:04 2025 UTC, located at hXXps://pastebin[.]com/raw/a0epCKQK C2: xdeadlylez-30616[.]portmap[.]io:30616 (IP: 193.161.193.99)
  20. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Thursday, 13-Mar-2025 18:26:04 JST Brian Clark Brian Clark
    • Threat Insight

    I’ve never heard of the MSP-focused bluetrait.io but add it to the list of legitimate services that get abused. If you don’t use this RMM service, I suggest blocking it via DNS, NGFW or Web security proxy. #cybersecurity

    From: @threatinsight
    https://infosec.exchange/@threatinsight/114144688263847941

    In conversation Thursday, 13-Mar-2025 18:26:04 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: bluetrait.io
      Home - bluetrait.io
      The complete cloud-based MSP platform
    2. No result found on File_thumbnail lookup.
      Threat Insight (@threatinsight@infosec.exchange)
      from Threat Insight
      New cyber threat research from Proofpoint highlights how attackers are adapting to law enforcement disruptions, leveraging trusted software to evade detection and compromise systems. This blog details our team's findings: https://www.proofpoint.com/us/blog/threat-insight/remote-monitoring-and-management-rmm-tooling-increasingly-attackers-first-choice?campaign=2025&utm_medium=social_organic. #malware #ransomware #financialtheft #dataloss
  • Before

User actions

    Brian Clark

    Brian Clark

    InfoSec #Cybersecurity #threatintel and Politics. I try my best. Also @deepthoughts10@twitter.comSearchable

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          116759
          Member since
          4 May 2023
          Notices
          34
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.