//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...








Loading...
LMAO www.proofpoint.com/us/blog/thre...
New from @threatinsight.proofpoint.com! North Korean actor UNK_DeadDrop (possibly overlapping with Contagious Interview) conducts a high volume phishing campaign targeting developers with a new technique abusing VSIX extensions and new open source payload Overlord www.proofpoint.com/us/blog/thre...
5d
5d
This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing. The generated test files rely on real threat actor infrastructure to download or exfiltrate. hxxps://github.com/DataDog/guarddog/blob/main/tests
@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. [1/4]
I only know of this one, maybe that's the one? lolrmm.io
1d
8d
2d
Daniel Gordon
Saher
Volexity
My name is Daniel Gordon and I am writing to let you know that you have a serious problem. Next week I will be speaking at FirstCon about The Art of Notification. Distilled lessons learned from hundreds of victim notifications I’ve done over the years. www.first.org/conference/2...
1d
Karsten Hahn
38th Annual FIRST Conference: DENVER (US), June 14-19, 2026
38th Annual FIRST Conference - Denver (US), June 14-19, 2026.
www.first.org
Such an interesting report from Poland's CERT. Looks like Ghostwriter is now targeting the personal Gmail accounts of high-profile Polish citizens. Some of the attacks are random, with them trying to guess the victim's Gmail, ending up phishing random people cert.pl/en/posts/202...
3h
Daniel Gordon
Our new @threatinsight report is a comprehensive overview of TA4922, a newly designated Chinese-speaking, financially motivated threat actor that largely targets East Asia. It currently conducts more unique campaigns than any other cybercriminal we track. www.proofpoint.com/us/blog/thre...
10d
lolrmm.io
Dltd
Catalin Cimpanu
Npm will block all auto-running installation scripts starting next month with the release of version 12.0. The change is meant to counter the rising number of supply-chain attacks taking place on the platform github.blog/changelog/20...
By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor
www.proofpoint.com
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
2d
Recently, we have been observing attacks by the UNC1151/Ghostwriter group targeting Gmail accounts. This group has been regularly attacking the mailboxes of Polish citizens for several years, although...
cert.pl
UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
ThreatInsight
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The...
www.volexity.com
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available behind warnings in npm today on 11.16.0 or newer, so you can…
github.blog
Upcoming breaking changes for npm v12 - GitHub Changelog
Catalin Cimpanu
Key Findings: TA4922 is a highly sophisticated threat actor demonstrating a rapid operational tempo and continually evolving malware arsenal. The group has been
TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US
www.proofpoint.com