Sunday, January 5, 2025

Threat Intelligence Hot Shots Part 3: Episodes 4-13 (Compilation)

 


This is Episode 4 of Threat Intelligence Hot Shots. Sr. Threat Intelligence Analyst, Alex Ryan, and Peter discuss the recent shutdown of breach forums by the FDI, the increasing pace of advanced techniques and target scope of Russian state-sponsored threat actors, and two new vulnerabilities for Dealing routers. They advise limiting access to these devices and keeping them up to date with patches and admin password changes. They also mention a competition to name a movie. This week we looked at: Russian state sponsored threat actors. Vulnerabilities in KEV and D-Link This is Episode 5 of Threat Intelligence Hot Shots, Senior threat intelligence analyst, Alex Ryan, discusses a critical vulnerability in Chromium that allows exploit codes to escape the isolation mechanism of the browser. The vulnerability can be exploited through a carefully crafted HTML page, which can be delivered through phishing links, search engine optimization, or ads on trusted platforms. Ryan provides tips on how to detect the attack and establish persistence. The focus for Episode 6 is on attacks on water utilities by Chinese and Russian state-sponsored actors, targeting PLC and HMI devices with weak passwords and known vulnerabilities. The threat is increasing, with advisories from government entities warning about the attacks. The threat actors are using living off the land techniques, such as power show commands and PS exec, and data exfiltration over unencrypted channels like FTP. The solution is to use a zero-trust architecture and isolate the systems. In this Episode 7 of Threat Intelligence Hot shots, featuring senior analyst Alex Ryan. They discuss the emergence of a new ransomware group called RansomHub, which has quickly become a major player in the ransomware landscape due to its veteran operators and fast expansion. The malware is highly obfuscated and difficult to detect, and its advanced features include rebooting devices into safe mode to avoid detection by host-based detections and EDRs. The best defense is to patch active directory servers and use browser isolation to prevent initial access. In Episode 8 of Threat Intelligence Hot Shots Weekly, featuring Senior Threat Intelligence Analyst Alex Ryan. This week's focus is on info stealers, which have become a major concern due to their ability to steal data and credentials. The impact of an info stealer is demonstrated through the recent Snowflake incident, where data was stolen and sold on breached forums. The summary provides insights on how info stealers work and how to protect against them. Episode 9, Alex Ryan discusses the idea of data consolidation and mining of breached data, which can be used by threat actors for social engineering and pretexting. The data can be used for credential theft, extortion, and malicious insider attacks. AI can be used to strip out usernames and passwords, and to create authentic emails to target individuals. Users are becoming more susceptible to social engineering, and it is important to remove automatic logins from profiles. Episode 10 we look at the top three ransomware players for the past week and the past couple of weeks are discussed, along with a new botnet named Zergeca that is made for denial of service attacks. Denial of service attacks are becoming more frequent and sophisticated, and are being used to target the financial sector and healthcare facilities associated with military support. The Olympics, World Cup, and political gatherings like NATO and G2 summit may also be targeted. Defenses against these attacks are discussed. Episode 11, we discuss the recent AT&T data breach, which exposed metadata about telephone calls and text messages for about 110 million people. The breach occurred on April 19th, but the FBI requested that the reporting be delayed to give people time to change their numbers. The breach could put people in danger, especially those in espionage, politics, or journalism. The summary also covers a critical vulnerability in the legacy authentication protocol, RADIUS, which could have a huge impact on network devices.

Threat Intelligence Hot Shots Part 2: Episodes 3-8 (Compilation)

 


Friday's with the Threat Intelligence Team as we take a look at some of the security announcements over the past week and the things that might impact you in the coming weeks. A couple little quick stories that, Alex and Threat Intelligence team came up with and we hope to give you a little insight into these. Maybe added to your weekend reading or to your Monday list of things to do if this impacts you directly.

Threat Intelligence Hot Shots Part 1: Episodes 1-2 Plus Quarterly Review (Compilation)

 


Friday's with the Threat Intelligence Team as we take a look at some of the security announcements over the past week and the things that might impact you in the coming weeks. A couple little quick stories that, Alex and Threat Intelligence team came up with and we hope to give you a little insight into these. Maybe added to your weekend reading or to your Monday list of things to do if this impacts you directly.

The Unemployed Chronicles: Wrapping Up 2024 with Gratitude

 


As we close out 2024, I'm smiling and reflecting on the year in Episode 8 of The Unemployed: My Laid Off Life. Despite one unforgettable "dumpster fire" day, this year has been pretty decent. I've learned so many new technologies and grown in ways I never expected—grateful for the lessons and for all of YOU who have engaged with my content. Being laid off (again) was one of those defining life moments that opened my eyes to new perspectives. It’s shaped my character and inspired what’s coming next: a special Reemployment Project I’ll unveil next week! I’m excited to share it with you and get your involvement. For now, as we head into the New Year, stay safe out there—no unnecessary risks! (Yes, I’m a security person at heart.) Thank you for your incredible support, encouragement, and engagement this year. And, If 2024 wasn’t your year, here’s to lighting the wick, flicking the match and walking away without a glance Bruckheimer style! Happy New Year! Aloha 🌟

The Unemployed Chronicles: Holiday Edition

Welcome to Episode 7 of The Unemployed: My Laid-Off Life! It's Christmas Eve, and if you're a job seeker, take a deep breath and let go of some of that stress and anxiety for the next few days. 🎁 Nothing major is likely to change this week, so focus on what keeps you going.

For me, I’ve been thinking about passions and ideas, and I’m starting to pursue something new. I’ll share more details with you right after the New Year—and I hope to get you involved if you're on the job hunt. It’s exciting, and I can’t wait to tell you about it! This holiday season, remember to be kind, generous, and helpful, and most importantly, have fun. 🌟 Let’s brighten the season together! Episode 7 is in the books, and I’ll see you next week—on New Year’s Eve. 🎉 Wishing you all a Merry Christmas and Happy Holidays! 🎄✨ Aloha. #TheUnemployed #LaidOffLife #JobSeekerSupport #MerryChristmas #HappyHolidays


The Unemployed Chronicles: Learn from My Mistakes

I had rehearsed a whole opening for Episode 6 of The Unemployed: My Laid-Off Life but alas, I did not get the gig. This week, I share how I came close to landing a role through an internal referral—only to face rejection. But it’s not all bad news! I received some helpful feedback that I’m passing on:

1️⃣ Match the Experience: They chose someone with deep partner/reseller experience, which made sense for the role. 2️⃣ Know Your Audience: Adjusting tone and formality for different regions and teams is crucial. 3️⃣ Keep It Concise: Stay focused on answering interview questions clearly and directly. While this one didn’t work out, I’m now on their "warm list" for future openings. That’s how I landed a great role in the past, so I’m staying optimistic! Resources to Help You: Howard Holton’s LinkedIn posts (resume tips and ChatGPT prompts). https://www.linkedin.com/posts/howardholton_in-my-life-ive-been-lucky-enough-to-hire-activity-7274525692598362113-Prgt/ https://www.linkedin.com/posts/howardholton_chatgpt-resume-feedback-wizard-activity-7274816349879635971-aZcM/ Podcasts and posts like Kingfisher’s for job openings and advice. https://kingfisher.substack.com/p/kingfisher-issue-6-curated-cybersecurity I’m also considering launching a project to help others—quick 3-5 minute video interviews for those laid off, highlighting their skills and goals. Interested? Drop me a DM or comment! Remember: visualize, believe, and show up to receive. It worked for Bruce Lee, and it can work for us too! See you next week. Aloha!


The Unemployed Chronicles: Interviews, Rejections, and Keeping Hope Alive

It’s Episode 5 of The Unemployed: My Laid-Off Life, and I’m keeping hope alive! Last week, I went through eight interviews, spanning early mornings to afternoon meetings with VPs. The process felt great, with positive chemistry all around. Meanwhile, I faced rejection for another role but was quickly contacted by a recruiter for a new, different opportunity. In job search news, remember: interviews mean companies are investing in you—time and resources matter so stay confident. Also, a fun business tip: if meeting costs exceed the budget you’re discussing, call it the "over-meeting rule!" Sending good vibes your way—keep smiling and stay hopeful! Aloha!

Episode 4: The Unemployed Chronicles: A Lesson from My Laid Off Life https://www.linkedin.com/posts/psilvas_the-unemployed-chronicles-a-lesson-from-activity-7269854916968407042-K6re/ Episode 3: Thanksgiving Gratitude & Job Hunt Updates for Episode 3 of, The Unemployed https://lnkd.in/grzZezCD Episode 2: Week Two of Unemployment'ville: Stay Positive & Patient https://lnkd.in/gBByea_E Episode 1: Axed from Ericsson? Taking Control of Your Post-Layoff Journey https://lnkd.in/ggKiW2wz