Sign in

Chi En (Ashley) Shen

@ashl3y-shen.bsky.social
216 followers 210 following 42 posts

Security researcher @ Cisco Talos. / Ex-Google TAG / Black Hat & HITCON review board / Organiser of Rhacklette.

PostsRepliesMedia
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 05/02/2026
🔥 NEW research published: We uncover #DKnife, a China-nexus gateway-monitoring framework that intercepts network traffic, monitors user activity, and delivers malware #Shadowpad & #DarkNimbus via routers and edge devices. blog.talosintelligence.com/knife-cuttin...
blog.talosintelligence.com
Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework
Cisco Talos uncovered “DKnife,” a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants.
132
Reposted by Chi En (Ashley) Shen
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/12/2025
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
recordedfuture.com
Intellexa’s Global Corporate Web
22618
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 13/11/2025
So excited that I’m going to present my latest research at @districtcon.bsky.social in January! The last round of tickets are going on sale on this Sunday (Nov 16th @12pm EST). Looking forward to see you in DC!
041
Reposted by Chi En (Ashley) Shen
Saher @saffronsec.bsky.social · 05/11/2025
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...
proofpoint.com
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.  Key findings  Between June and August 2025,
21812
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 27/10/2025
Gonna be in Belgium for the first time after living in Europe for 7 years. Come catch me if you are at @what-is-sos.bsky.social tomorrow!!!
010
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 23/10/2025
Great work and thanks for referencing our research on redefining IAB! The four-tier classification framework is insightful for identifying collaborative campaigns!
040
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 15/10/2025
Great investigation from Trend Micro with the contributions from Joey Chen! Threat actor are actively targeting the SNMP protocol on routers for exploitation. www.trendmicro.com/en_us/resear...
trendmicro.com
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts obse...
151
Reposted by Chi En (Ashley) Shen
StrikeReady Labs @strikereadylabs.com · 03/10/2025
Quite a bit of CN APT activity in europe in the past week strikeready.com/blog/cn-apt-... As always, if you're interested in tuning your skills, download the samples here github.com/StrikeReady-...
strikeready.com
CN APT targets Serbian Government
Mustang Panda continues targeting European governments
096
Reposted by Chi En (Ashley) Shen
State of Statecraft Conference @what-is-sos.bsky.social · 14/10/2025
There's was a mad dash on SOS tickets over the weekend. SOS is two weeks away, if you've been putting off getting a ticket... your time is now. stateofstatecraft.com/register
032
Reposted by Chi En (Ashley) Shen
Catalin Cimpanu @campuscodi.risky.biz · 14/10/2025
Another major surveillance provider exposed: First Wap Its product was used to track some very high-profile figures www.lighthousereports.com/investigatio...
text that reads: In Italy, investigative journalist Gianluigi Nuzzi was tracked days after publishing a dramatic exposé of corruption in the Vatican, as police closed in on his source. In California, Anne Wojcicki, founder of DNA startup 23andMe and then married to Google’s Sergey Brin, was tracked more than a thousand times as she moved across Silicon Valley. And in South Africa, associates of Rwandan opposition leader Patrick Karegeya were tracked before his assassination in a Johannesburg hotel room.
1107
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 15/09/2025
👾 Had a great time at the DC4131 Padawan CTF with the Swiss @defcon.bsky.social community! Back to CTFs after a while teamed up with J & M and knocked out a few challenges. Go, pwnrpuffgirls girl power! 💪 Big thanks to the organizing team. Looking forward to the next one! #CTF
0111
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 09/08/2025
Caught a Pokémon at @defcon.bsky.social 😍 Big fan of @lauriewired.bsky.social. It was so interesting to discuss about reverse engineering with her. Please can we all have a card like this?
0171
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 08/08/2025
At @defcon.bsky.social today. Come find me!
020
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 31/07/2025
Heading to Hacker Summer Camp next week? 🌵If you’re curious about the journeys behind the hacks, the challenges and the stories that shaped us, come join our panel: "Hacking the Status Quo”. With Valentina Palmiotti (Chompie), Natalie Silvanovich, and Vandana Verma. #BHUSA #blackhatusa
000
Reposted by Chi En (Ashley) Shen
State of Statecraft Conference @what-is-sos.bsky.social · 28/07/2025
The SOS conference is officially THREE months away! On October 28, we gather to discuss the latest developments in nation-state operations with leading experts! ⏰ CFP Ends September 1st! 🐧 Early Bird Tickets almost sold out! 🕵️ Come talk espionage, sabotage, ORBATs, and more! stateofstatecraft.com
141
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 18/07/2025
Excited to see another threat intel focused conference taking place in Europe, and it’s organized by threat analyst in the field! The CFP is opened until Sept 1st. Looking forward to see your amazing research! #What_is_SOS #StateOfStatecraft www.stateofstatecraft.com
stateofstatecraft.com
State of Statecraft
A new conversation for a new era.
041
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 10/07/2025
Had a great time on the @malspace.bsky.social podcast with Julien talking about my PIVOTcon presentation from tracking compartmentalized attacks to thoughts on attribution. Fun convo (and I loved the theme song at the end!). 🎶 Thanks for having me! malspace.com/episodes/mul...
malspace.com
Malspace | Multiple Actors, One Breach - Rethinking Threat Models in 2025
In this episode, Julien sits down with Chi En (Ashley) Shen, a distinguished threat researcher at Cisco Talos. Ashley shares her fascinating journey from hacking forums in Taiwan to leading threat ...
043
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 10/06/2025
I'm excited to return to Black Hat USA this year and have the opportunity to give away one briefings pass to the conference. If you're a student or someone who could use a little support to attend, I'd love to hear from you. DM me if you're interested! #BHUSA
020
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 20/05/2025
Looking forward to my week at @botconf.infosec.exchange.ap.brid.gy ! Please come say hi if you are around! #Botconf2025
010
Reposted by Chi En (Ashley) Shen
Catalin Cimpanu @campuscodi.risky.biz · 20/05/2025
Talks from the OffensiveCon 2025 security conference, which took place last week, are now available on YouTube www.youtube.com/playlist?lis...
youtube.com
OffensiveCon25 - YouTube
OffensiveCon 2025 Talks
0127
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 13/05/2025
📡 New blogs out: Compartmentalized attacks are no longer limited to financially motivated actors, state-sponsored groups are adopting them too. We propose a new taxonomy for initial access groups to reflect broader motivations and affiliations. (1/3)
163
Reposted by Chi En (Ashley) Shen
Saher @saffronsec.bsky.social · 13/05/2025
@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...
proofpoint.com
TA406 Pivots to the Front | Proofpoint US
What happened  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these
11513
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 12/05/2025
Had an amazing time speaking at @pivotcon.bsky.social last week! Grateful for the chance to share insights and connect with the brilliant minds. PIVOTcon remains my favorite threat intel event in Europe. Huge thanks to the organizers for creating this community and the memorable experience.
082
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 09/05/2025
A lot of you have been asking, YES! HITCON 2025 CFP is open! The conference will be host on August 15 - August 16. Submit your talk before June 8th. Looking forward to your submissions! #HITCON #HITCON2025 CFP: cfp2025.hitcon.org/en/
cfp2025.hitcon.org
HITCON 2025 CFP
HITCON 2025 CFP
011
Reposted by Chi En (Ashley) Shen
The Citizen Lab @citizenlab.ca · 06/05/2025
Come work with us! We are looking for a creative and self-motivated communications professional to join our team this summer in the role of Digital Communications Specialist. This is a FT, hybrid position based at @uoft.bsky.social in downtown Toronto. Learn more: citizenlab.ca/2025/05/job-...
199
Reposted by Chi En (Ashley) Shen
John Scott-Railton @jsrailton.bsky.social · 06/05/2025
BREAKING: jury awards massive $167 million in punitive damages against spyware company NSO Group. Precedent-setting win against notorious #Pegasus spyware maker. Very consequential for victims to see this. Congratulations to #WhatsApp on sticking this case through since 2019. Some thoughts 1/
19760283
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 24/04/2025
We just published our investigation into a Cactus ransomware campaign, uncovering TOYMAKER, an IAB group using a custom backdoor LAGTOY. It’s still challenging to identify compartmentalized attacks. We’ll share our approach and solutions at @pivotcon.bsky.social in 2 weeks! #toymaker
084
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 14/04/2025
New blog from TeamT5 warns a China-nexus APT is exploiting a vulnerability in #Ivanti Connect Secure VPN appliances to target victims in EMEA and the US. Today Shadowserver's CVE-2025-22457 tracker shows 4,098 unpatched instances remain, mostly in Asia and the US. pse.is/7esf4n
pse.is
China-nexus APT exploits Ivanti Connect Secure VPN vulnerability to infiltrate multiple entities - TeamT5
In late March, TeamT5 detected that the China-nexus APT group exploited the critical vulnerability in Ivanti Connect Secure VPN appliances to infiltrate multiple entities around the globe. The victims...
063
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 08/04/2025
Wrapped up 2 panels at Black Hat Asia 🥳 ! Had such a great time meeting everyone. Thank you to all who stopped by the Community Lounge! I truly enjoyed the discussions and hope our answers were helpful. See you next year! #BHASIA
010
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 03/04/2025
Lego of Black Hat Operations Center 😍😍 Love the Bricks & Picks zone at Black Hat Asia this year! #BHASIA
020
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 01/04/2025
After nearly 9 years on the Black Hat Asia review board (ufff time flies!), I’m honored to take on more responsibility and join the Black Hat USA review board this year. The CFP closes in 2 days—get your brilliant research in! #BlackHat #BHUSA 💻Submit CFP: usa-briefings-cfp.blackhat.com
040
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 24/03/2025
Come join us at the Ask A Security Expert session at Black Hat Asia on April 4th! I'll be there with Orange Tsai, Ryan Flores, and Dr. Marina Krotofil answering your cybersecurity questions. Submit your topics in advance using the form on the event page. Looking forward to seeing you there!
132
Reposted by Chi En (Ashley) Shen
b4n1shed @b4n1shed.bsky.social · 17/03/2025
Introducing: abuse.ch Hunting Platform abuse.ch/blog/introdu...
abuse.ch
abuse.ch - Figthing malware and botnets
abuse.ch is providing community driven threat intelligence on cyber threats
042
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 17/03/2025
I had an amazing time at the Devcore conference last weekend! It was an honor to share my thoughts on exploit hunting there. Super impressed by the quality of talks and really enjoyed meeting so many great people. Huge thanks to the Devcore team for the wonderful experience!
030
Reposted by Chi En (Ashley) Shen
Catalin Cimpanu @campuscodi.risky.biz · 16/03/2025
It looks like Microsoft has been quietly updating its 2023 new APT naming table with new entries The table used to have 20-30 entries... it's now gigantic! Bookmark it: learn.microsoft.com/en-gb/unifie...
1208
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 15/03/2025
Love the swags from @devco.re.web.brid.gy conference 2025 😍
010
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 15/03/2025
Here we go!!
040
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 12/03/2025
✈️  Heading to Taiwan this week for @devco.re.web.brid.gy Conference 2025! I’ll give an intro on exploit hunting and its challenges. Excited to speak in Taiwan again and looking forward to the great talks and meeting everyone there! conf.devco.re/2025/agenda/
050
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 07/03/2025
Honored and excited to be speaking at @pivotcon.bsky.social again this year! 🎉 Huge shoutout to the co-authors @_vventura, @b4n1shed.bsky.social and @asheermalhotra —couldn’t have done this research without you! Looking forward to seeing everyone in Málaga. This year I must join the Karaoke!😆
162
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 21/02/2025
📣 @talosintelligence.com investigated #SaltTyphoon and discovered a custom-built tool called JumbledPath, used for packet capturing. While no new exploits were observed, their tactics remain a significant threat to targeted organizations. blog.talosintelligence.com/salt-typhoon...
blog.talosintelligence.com
Weathering the storm: In the midst of a Typhoon
Cisco Talos has been closely monitoring reports of widespread intrusion activity against several major U.S. telecommunications companies, by a threat actor dubbed Salt Typhoon. This blog highlights ou...
010
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 09/01/2025
I have the honor of giving away two passes to the Black Hat Asia 2025 conference! Priority goes to students and anyone who needs support to attend. Please DM me if interested. #BHASIA
000
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 17/12/2024
Had a 0day at the hacker bar in Taipei today. This is where you meet real hackers in the wild in Taiwan 😂
030
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 12/12/2024
Had a good time attending #ThreatAnalystSummit organised by TeamT5 today. Good to be back and see some old and new faces!! I enjoyed the talks and discussions during the conference. Thanks for having me!
000
Reposted by Chi En (Ashley) Shen
Natto Thoughts @nattothoughts.bsky.social · 11/12/2024
Natto Thoughts is honored to have guest contributor Eugenio Benincasa discussing China’s pubic opinion analysis systems and how Bluesky should outsmart them. @euben.bsky.social nattothoughts.substack.com/p/bluesky-sh...
nattothoughts.substack.com
Bluesky Should Outsmart China's Public Opinion Monitoring Tools to Safeguard Public Discourse
The Chinese government has leveraged public opinion analysis systems to target U.S. social media platforms to tamper with public discourse in the past. Will Bluesky be included? most likely yes.
031
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 06/12/2024
New research from @jspchc and @thehellu.bsky.social uncovers a campaign leveraging the Moonshine framework to deliver Chrome Nday exploits targeting Android devices. Thanks for giving the credit to my research!
020
Reposted by Chi En (Ashley) Shen
Gynvael Coldwind @gynvael.bsky.social · 05/12/2024
bughunters.google.com/blog/6355265... This is my favorite ethical hacking exercise that a company can run – the "Leaving Tradition" at Google. This spawned so many amazing hacking stories over the years and let to mitigating so many complex exploitation paths!
bughunters.google.com
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!)
The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...
1181
Reposted by Chi En (Ashley) Shen
Maijin @maijin.infosec.exchange.ap.brid.gy · 03/12/2024
To all folks moving to Bsky - It'd be very helpful if you follow bsky.app/profile/ap.brid.gy. This automatically enable folks in Mastodon to follow you back automatically via a Bridged Account! If you however, decided, to stay on Mastodon, you can follow @bsky.brid.gy - This will do […]
infosec.exchange
Original post on infosec.exchange
024
Reposted by Chi En (Ashley) Shen
Lea Kissner @leak.bsky.social · 01/12/2024
In the absolutely hands-down worst meeting I've ever been in (thanks, Elon) I had to explain repeatedly that the security engineers didn't check in much code because they were: a) doing their jobs of helping everyone else do their job without getting us hacked b) yes security engineers are technical
29413
Chi En (Ashley) Shen @ashl3y-shen.bsky.social · 29/11/2024
Pretty bad at managing my socials. But hello world Bluesky!
060