Sign in

Audra Streetman

@audrastreetman.bsky.social
628 followers 1.2K following 99 posts

Threat Intel @ Target

PostsRepliesMedia
Audra Streetman @audrastreetman.bsky.social · 12/08/2026
Combined with the Hugging Face incident, I'd consider this an early signal of the tempo and scale we can expect as agentic AI becomes more integrated into offensive operations: www.dreamgroup.com/blog/inside-...
dreamgroup.com
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia | | Dream Security Blog
220
Audra Streetman @audrastreetman.bsky.social · 09/12/2025
Kroll is revealing a new AMOS infostealer delivery vector where malicious instructions appeared inside a legitimate ChatGPT session. Basically ClickFix-style malware delivery, but presented through a real LLM chat URL. www.kroll.com/en/publicati...
kroll.com
New AMOS Infection Vector Highlights Risks around AI Adoption
During a recent investigation into AMOS InfoStealer, Kroll Threat Intelligence has discovered a troubling new delivery vector that leverages the growing trust users place in AI tools. In this case, at...
142
Reposted by Audra Streetman
Andrew Morris @andrewmorr.is · 07/12/2025
React2Shell exploitation frequency in GreyNoise dec 5-dec 6
12611
Audra Streetman @audrastreetman.bsky.social · 05/12/2025
The amount of times today I've typed React2j or React4Shell....
a cartoon of a girl with the words internally screaming above her
091
Audra Streetman @audrastreetman.bsky.social · 05/12/2025
Censys identifies ~2.15M exposed web services running Next.js or other RSC-based frameworks, predominantly in the U.S. and China. Not all are vulnerable, but given the scale, “spray-and-prey” seems more accurate than "spray-and-pray." censys.com/advisory/cve...
censys.com
December 5 Advisory: Unauthenticated RCE Flaw in React Server Components [CVE-2025-55182]
CVE-2025-55182 is a critical unauthenticated RCE flaw in React Server Components with a CVSS score of 10.
011
Audra Streetman @audrastreetman.bsky.social · 25/11/2025
Comparing the IOCs released by Gainsight and Salesloft, there is one overlapping IP: 185.220.101[.]185 communities.gainsight.com/community-ne... trust.salesloft.com?uid=Drift%2F...
communities.gainsight.com
000
Audra Streetman @audrastreetman.bsky.social · 18/11/2025
Annoying as hell when a security vendor (and CNA) with a global PSIRT doesn't update its CSAF with a CVE once it's assigned. Like what is even the point.
000
Audra Streetman @audrastreetman.bsky.social · 16/11/2025
Some of the LLM skepticism in security looks more like backlash to hype than analysis. AlphaFold showed how experts can underestimate capability jumps. Dismissing early signals from Anthropic/Google assumes the future stays static, but AI capability and adoption curves may not behave that way.
111
Reposted by Audra Streetman
Eric Geller @ericjgeller.com · 13/11/2025
This is a popular tactic. Google recently said that Chinese hackers got vulnerability information from Gemini by posing as capture-the-flag participants. cloud.google.com/blog/topics/...
0177
Reposted by Audra Streetman
evacide @evacide.bsky.social · 22/09/2025
404 Media is suing ICE for documents relating to its $2 million contract with Paragon Solutions. These are the journalists you should be supporting with your subscription money because they are meeting the moment. www.404media.co/were-suing-i...
404media.co
We’re Suing ICE for Its $2 Million Spyware Contract
404 Media has filed a lawsuit against ICE for access to its contract with Paragon, a company that sells powerful spyware for breaking into phones and accessing encrypted messaging apps.
015046
Reposted by Audra Streetman
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/07/2025
The critical RCE Vulnerability in Microsoft #SharePoint was disclosed at #Pwn2Own in May. Because of Trend @thezdi.bsky.social, our customers have been protected since May. Stay up to date on the latest with this vulnerability here: https//www.trendmi...
trendmicro.com
Proactive Security for CVE-2025-53770 and CVE-2025-53771 SharePoint Attacks
CVE-2025-53770 and CVE-2025-53771 are vulnerabilities in on-premise Microsoft SharePoint Servers that evolved from previously patched flaws, allowing unauthenticated remote code execution through adva...
143
Reposted by Audra Streetman
Eric Geller @ericjgeller.com · 25/06/2025
Iran's APT42 (Charming Kitten) hacker team is now conducting targeted spearphishing attacks on high-profile Israeli national security journalists and cybersecurity researchers, according to Check Point. blog.checkpoint.com/security/edu...
0124
Reposted by Audra Streetman
Matt Kapko @mattkapko.com · 24/06/2025
Supposed experts and mainstream media have spent the past few days hyperventilating over reports of a colossal data breach that exposed more than 16 billion credentials. There’s just one inconvenient detail: evidence to support its sensational claim is lacking. cyberscoop.com/colossal-dat...
cyberscoop.com
The ‘16 billion password breach’ story is a farce
Experts told CyberScoop the research 'doesn’t pass a sniff test' and detracts from needed conversations around credential abuse and information stealers.
11913
Audra Streetman @audrastreetman.bsky.social · 22/06/2025
Iran has demonstrated its capability/intent to keep up cyber operations amid Israeli strikes. On Friday, an IRGC-linked group targeted Albania's capital in retaliation for the country hosting ~3k Iranian dissidents. The intrusion could disrupt services/expose data: www.politico.eu/article/iran...
politico.eu
Iranian hackers target Albania in retaliation for hosting dissidents
A group tied to Iran’s Revolutionary Guard targeted the capital of Tirana in retaliation for Albania hosting around 3,000 Iranian dissidents.
020
Reposted by Audra Streetman
Dustin Volz @dustinvolz.bsky.social · 15/06/2025
News: The Washington Post has suffered a cyber intrusion that compromised the emails of at least several reporters at the paper, including those on the national security and economic policy teams, according to people familiar with the matter.
27342142
Reposted by Audra Streetman
Eric Geller @ericjgeller.com · 13/06/2025
Google's @hultquist.bsky.social‬ says his threat intel team expects Iranian hackers to "rededicate themselves to attacks against Israeli targets" following Israel's bombing operation, though he says 🇮🇷-on🇮🇱 hacking "is already persistent and aggressive." US infrastructure could face more hacks too.
0139
Audra Streetman @audrastreetman.bsky.social · 10/06/2025
The cybercriminal group FIN6 (Skeleton Spider) is phishing recruiters by posing as job seekers on LinkedIn/Indeed and luring them to fake resume sites that deliver the "more_eggs" backdoor via AWS-hosted, CAPTCHA-protected pages. More from DomainTools: dti.domaintools.com/Skeleton-Spi...
dti.domaintools.com
Eggs in a Cloudy Basket: Skeleton Spider’s Trusted Cloud Malware Delivery - DomainTools Investigations | DTI
Discover how the FIN6 cybercrime group, also known as Skeleton Spider, leverages trusted cloud services like AWS to deliver stealthy malware through fake job applications and resume-themed phishing ca...
030
Audra Streetman @audrastreetman.bsky.social · 09/06/2025
"This research underscores the persistent threat Chinese cyberespionage actors pose to global industries and public sector organizations, while also highlighting a rarely discussed target they pursue: cybersecurity vendors." www.sentinelone.com/labs/follow-...
sentinelone.com
Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
This report uncovers a set of related threat clusters linked to PurpleHaze and ShadowPad operators targeting organizations, including cybersecurity vendors.
010
Reposted by Audra Streetman
Glenn @ntkramer.bsky.social · 15/05/2025
🥤& #threat-intel: CISA added Langflow Code Injection CVE-2025-3248 to the KEV on May 5. Recently, it has garnered considerable attention, with South Korea leading the pack. This vuln enables unauthenticated attackers to execute arbitrary code via /api/v1/validate/code viz.greynoise.io/tag...
042
Reposted by Audra Streetman
stephen fowler @stphnfwlr.com · 09/05/2025
@npr.org EXCLUSIVE: The Department of Agriculture is demanding states hand over personal data of food assistance recipients — including Social Security numbers, addresses and, in at least one state, citizenship status, according to emails shared with NPR.
npr.org
USDA, DOGE demand states hand over personal data about food stamp recipients
The Department of Agriculture is demanding sensitive data from states about more than 40 million food stamp recipients, as DOGE is amassing data for immigration enforcement.
51918661
Reposted by Audra Streetman
Stratosphere Laboratory @stratosphereips.bsky.social · 07/05/2025
Deploying realistic honeypots at scale is hard—DECEIVE makes it simple. Join David Bianco at #Honeynet2025 in Prague as he presents an AI-assisted SSH honeypot that enables high-fidelity deception with minimal effort. 📅 June 2–4, 2025 🔗 prague2025.honeynet.org #honeypots #llm #ai
144
Reposted by Audra Streetman
Kevin Collier @kevincollier.bsky.social · 07/05/2025
In December, leading EdTech company PowerSchool was hacked, exposing the private information of tens of millions of American kids. PowerSchool paid the ransom to keep the data private. That apparently didn't work: somebody started using that data today to extort public schools in North Carolina.
nbcnews.com
School districts hit with extortion attempts months after education tech data breach
The attempted extortion has so far targeted schools in Canada and North Carolina.
46438
Reposted by Audra Streetman
sydney @letswastetime.bsky.social · 01/05/2025
🔥 Dispatch Debrief: April 2025 is live 🔥 Explore star sign-inspired hunting techniques, organizing your hunt squad, and the value of finding "nothing." Discover this month's insights from @thorcollective.bsky.social Dispatch - dispatch.thorcollective.com/p/april-debr...
dispatch.thorcollective.com
Dispatch Debrief: April 2025
What We Hunted, Learned, and Loved This Month
144
Reposted by Audra Streetman
David DiMolfetta @ddimolfetta.bsky.social · 30/04/2025
Hm! He argues the CSRB has to evolve + be fully separated from CISA (it was dismantled at start of Trump 2.0), noting that, during the board's Salt Typhoon probe, some telcos got nervous and said they will not share information with the agency b/c CSRB is tied to the DHS office.
121
Reposted by Audra Streetman
Ryan Gallagher @rjgallagher.co.uk · 28/04/2025
Initial probe into cause of power outages in Spain & Portugal today suggests fault rather than cyberattack, according to the European Union Agency for Cybersecurity (ENISA). “For the moment the investigation seems to point out to a technical/cable issue,” a spokesperson for the agency tells me.
810055
Reposted by Audra Streetman
sydney @letswastetime.bsky.social · 17/04/2025
When incidents hit, how you communicate shapes the outcome. This week’s @thorcollective.bsky.social Dispatch features @audrastreetman.bsky.social, former journalist turned cyber intel analyst. dispatch.thorcollective.com/p/how-commun...
dispatch.thorcollective.com
How Communication Shapes the Outcome of Cybersecurity Incidents
Why the timing and transparency of messaging can make or break your incident response
143
Reposted by Audra Streetman
Dustin Volz @dustinvolz.bsky.social · 16/04/2025
News: @thekrebscycle.bsky.social, a target of Trump's wrath last week, is resigning from SentinelOne to focus fully on fighting back against against the White House's campaign to punish dissent. www.wsj.com/politics/pol...
wsj.com
Exclusive | Former Trump Official Targeted With Government Probe Vows to Fight
Chris Krebs, the cybersecurity official from the first Trump administration who was fired after saying the 2020 election wasn’t stolen, vowed to fight back against a White House investigation.
17555151
Reposted by Audra Streetman
David J. Bianco @davidjbianco.bsky.social · 15/04/2025
If this contract ends, the damage will be immense. To be clear, that's immense damage to the US' ability to protect its computer systems, both in the commercial and in the public sectors. And yes, this includes critical infrastructure such as power, water, and transportation.
185
Reposted by Audra Streetman
Tib3rius @tib3rius.bsky.social · 15/04/2025
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
35672409
Reposted by Audra Streetman
evacide @evacide.bsky.social · 11/04/2025
Infosec must not remain silent while Trump goes after Chris Krebs: www.eff.org/deeplinks/20...
eff.org
Cybersecurity Community Must Not Remain Silent On Executive Order Attacking Former CISA Director
Cybersecurity professionals and the infosec community have essential roles to play in protecting our democracy, securing our elections, and building, testing, and safeguarding government infrastructur...
3340160
Reposted by Audra Streetman
Raphael Satter @raphae.li · 11/04/2025
THREAD: When @thekrebscycle.bsky.social and his workplace, @sentinelone.com, were singled out by Donald Trump on Wednesday, I thought it was an opportunity to weigh the cybersecurity industry's rhetoric against their real world actions.
512871
Audra Streetman @audrastreetman.bsky.social · 11/04/2025
“When you see important societal actors — be it university presidents, media outlets, C.E.O.s, mayors, governors — changing their behavior in order to avoid the wrath of the government, that’s a sign that we’ve crossed the line into some form of authoritarianism..” www.nytimes.com/2025/03/06/u...
nytimes.com
‘People Are Going Silent’: Fearing Retribution, Trump Critics Muzzle Themselves (Gift Article)
People say they are intimidated by online attacks from the president, concerned about harm to their businesses or worried about the safety of their families.
030
Reposted by Audra Streetman
evacide @evacide.bsky.social · 10/04/2025
Big Law has failed to stand up to Trump and now infosec is following suit.
7396118
Audra Streetman @audrastreetman.bsky.social · 11/04/2025
“Reuters contacted 33 of the largest U.S. cybersecurity companies… for comment on Trump's action against SentinelOne. Only one offered comment on Trump's action. The rest declined, did not respond or did not answer questions.” www.reuters.com/world/us/cyb...
reuters.com
Cybersecurity industry falls silent as Trump turns ire on SentinelOne
The cybersecurity industry has gone mostly quiet after President Donald Trump took action against one of its prominent members.
020
Audra Streetman @audrastreetman.bsky.social · 10/04/2025
"The Chinese official’s remarks at the December meeting were indirect and somewhat ambiguous, but most of the American delegation in the room interpreted it as a tacit admission and a warning to the U.S. about Taiwan, a former U.S. official familiar with the meeting said" www.wsj.com/politics/nat...
wsj.com
Exclusive | In Secret Meeting, China Acknowledged Role in U.S. Infrastructure Hacks
A senior Chinese official linked intrusions to escalating U.S. support for Taiwan.
020
Reposted by Audra Streetman
Joe Slowik @pylos.co · 09/04/2025
So I stuck up for Sean Plankey as future CISA, now time to stick up for Chris Krebs, past CISA - this shit is bonkers and should give pause to anyone even considering federal employment if this kind of shit is what you get for doing your job: www.whitehouse.gov/fact-sheets/...
whitehouse.gov
Fact Sheet: President Donald J. Trump Addresses Risks from Chris Krebs and Government Censorship
RESTORING TRUST IN GOVERNMENT: Today, President Donald J. Trump signed a Presidential Memorandum revoking any active security clearance held by Chris
26720
Reposted by Audra Streetman
Raphael Satter @raphae.li · 09/04/2025
The Trump administration is now going after its first cybersecurity company, stripping @sentinelone.com of "any active security clearance." Will the infosec industry do any better than the legal industry in showing solidarity? www.whitehouse.gov/fact-sheets/...
The Order directs the head of every federal agency to immediately revoke any active security clearance held by Krebs.
The Order also suspends any active security clearance held by individuals at entities associated with Krebs, including SentinelOne, pending a review of whether such clearances are consistent with the national interest.
1215267
Audra Streetman @audrastreetman.bsky.social · 03/04/2025
New from WSJ: North Korea commands 8,000+ hackers who "can wait months or years to exploit a single slip in a company’s digital security." Over the past decade, regime has stolen more than $6 billion in cryptocurrency: www.wsj.com/world/asia/n...
1328
Audra Streetman @audrastreetman.bsky.social · 01/04/2025
The actor behind the alleged Oracle breach shared a class action complaint filed yesterday that claims #Oracle became aware of a ransomware attack on or around Jan. 22 and failed to report the data breach to customers as outlined in its privacy policies. www.pacermonitor.com/public/filin...
010
Audra Streetman @audrastreetman.bsky.social · 31/03/2025
Sekoia found DPRK targeting of job seekers in the cryptocurrency sector has evolved to include the "ClickFix" tactic of displaying a fake error message in a browser to deceive users into executing malicious PowerShell to deploy the GolangGhost backdoor on Windows/macOS blog.sekoia.io/clickfix-tac...
blog.sekoia.io
ClickFix tactic: The Phantom Meet
Analyse the ClickFix tactic and related campaigns. Uncover a ClickFix campaign impersonating Google Meet and cybercrime infrastructure.
010
Audra Streetman @audrastreetman.bsky.social · 31/03/2025
The Cisco Talos 2024 Year in Review found that #ransomware actors are less likely to fully rebound from a law enforcement takedown if decryption tools are made publicly available. Compares the impact of the ALPHV takedown (key provided) vs LockBit (no key). blog.talosintelligence.com/content/file...
021
Reposted by Audra Streetman
Eric Geller @ericjgeller.com · 14/03/2025
The Multi-State Information & Analysis Center contacted member states Wed night to share which services it can keep providing (Albert, MDBR, EDR, NCSR, & SOC) and which it can't (IR, CTI, member engagement, VDP) after its host organization lost federal funding. www.documentcloud.org/documents/25...
31410
Audra Streetman @audrastreetman.bsky.social · 30/01/2025
“The Lazarus Group’s campaign targeted applications used in cryptocurrency and authentication systems, embedding malware into trusted software packages. Developers unknowingly included these compromised packages in their projects...” securityscorecard.com/blog/operati...
securityscorecard.com
Operation Phantom Circuit: North Korea's Global Data Exfiltration Campaign
STRIKE reveals Lazarus Group's new tactic: embedding malware in trusted apps for stealthy, widespread attacks and long-term access.
031
Audra Streetman @audrastreetman.bsky.social · 22/01/2025
Registration is open for the SANS New2Cyber Summit on March 13! The free virtual event is for anyone new to cybersecurity or looking to level up their skills. I'm presenting at 4:25pm ET about my career change from local TV news to cyber threat intelligence: www.sans.org/cyber-securi...
sans.org
New2Cyber Summit & Live Online Cybersecurity Training | SANS Institute
Cybersecurity is a fast-growing, dynamic field and SANS mission is to equip you with the skills you need to succeed in the industry. This free live-online event brings together leading experts prepare...
021
Reposted by Audra Streetman
Eric Geller @ericjgeller.com · 21/01/2025
DHS has terminated the memberships of everyone on its advisory committees. This includes several cyber committees, like CISA's advisory panel and the Cyber Safety Review Board, which was investigating Salt Typhoon. That review is "dead," person familiar says. www.documentcloud.org/documents/25...
501059595
Audra Streetman @audrastreetman.bsky.social · 16/12/2024
Congratulations @letswastetime.bsky.social, @davidjbianco.bsky.social, and Dr. Ryan Fetterman for being named the community winners in the “Innovation of the Year” category at the SANS Difference Makers Awards! So proud to work with you and see the impact of the PEAK Threat Hunting framework.
021
Reposted by Audra Streetman
Jim Donahue @jimdonahue-cyber.bsky.social · 09/12/2024
New on @darkreading.bsky.social: "The consequences of large-scale incidents, such as Log4j ..., have had lasting impacts on the cybersecurity world. However, cybersecurity defenders can learn from these experiences." By Audra Streetman @audrastreetman.bsky.social www.darkreading.com/vulnerabilit...
darkreading.com
The Art of Vulnerability Prioritization
We can anticipate a growing number of emerging vulnerabilities in the near future, emphasizing the need for an effective prioritization strategy.
021