Sign in

John

@bigbadw0lf.bsky.social
1.5K followers 171 following 59 posts

Frontline Intelligence with #AdvancedPractices 🦅 @Google Threat Intel | views are my own

PostsRepliesMedia
Reposted by John
Tony Stark @tonystark.bsky.social · 18/07/2026
I loved it when the Cyclops said “Jesus Christ it’s Jason Bourne”
614022
John @bigbadw0lf.bsky.social · 09/07/2026
The Tourmalet looks absolutely brutal
010
John @bigbadw0lf.bsky.social · 26/06/2026
Bring back the PBY and put this thing on it.
010
John @bigbadw0lf.bsky.social · 22/12/2025
What’s the over / under on how many Renhai‘s will be put to sea before this is canceled.
110
John @bigbadw0lf.bsky.social · 16/10/2025
what are we without the sauce
162
Reposted by John
Greg Otto @gregotto.bsky.social · 24/09/2025
🚨🚨🚨 Google released a report on "Brickstorm" this morning — a next-level, suspected China-linked campaign targeting U.S. firms. Ultra-stealthy, 400+ day dwell times, focus on stealing IP, finding zero-days, and focused on long-term cyberespionage. cyberscoop.com/chinese-cybe...
cyberscoop.com
Brickstorm malware powering ‘next-level’ Chinese cyberespionage campaign
Mandiant and Google have identified “Brickstorm,” a sophisticated, suspected China-linked hacking campaign targeting U.S. tech firms, legal organizations, and BPOs. The operation often goes undetected...
86646
Reposted by John
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 20/05/2025
Not me losing my mind tracking ORBs lalalala I can't hear you over the sound of how many darned ORB networks there are 🫠
media.tenor.com
a close up of a woman 's face with a purple shirt on .
ALT: a close up of a woman 's face with a purple shirt on .
2164
Reposted by John
Wesley Shields @wxs.bsky.social · 07/05/2025
I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it. cloud.google.com/blog/topics/...
cloud.google.com
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog
Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.
11714
John @bigbadw0lf.bsky.social · 03/04/2025
Hot off the press is a new blog detailing our observations from in the wild exploitation of CVE-2025-22457 by UNC5221 including two newly observed malware families tracked as BRUSHFIRE and TRAILBLAZE. cloud.google.com/blog/topics/...
cloud.google.com
Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) | Google Cloud Blog
0167
John @bigbadw0lf.bsky.social · 12/03/2025
🔥 new blog covering recent UNC3886 ops. Massive S/O to all the authors for dropping such a great blog.
081
Reposted by John
Lasq @lasq.pl · 12/03/2025
Super happy this blog is finally released. Dive into the intricacies of backdoors targeting Juniper devices, veriexec bypass zero-day and other interesting TTPs, all with UNC3886, a China-nexus cyber espionage group as your guide! cloud.google.com/blog/topics/...
cloud.google.com
Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers | Google Cloud Blog
We discovered China-nexus threat actors deployed custom backdoors on Juniper Networks’ Junos OS routers.
064
John @bigbadw0lf.bsky.social · 08/03/2025
The universe doesn’t want me to get a pair of the Vaporfly 4s
010
John @bigbadw0lf.bsky.social · 07/03/2025
Friday playlist brought to you by all of @stonepwn3000.bsky.social’s favorite bands open.spotify.com/playlist/4B0...
open.spotify.com
You Think You Hate This But You Don't
Playlist · turkehbacon · 34 items · 2 saves
130
Reposted by John
Kori Schake @kschake.bsky.social · 28/02/2025
What I feel is ashamed.
511035108
John @bigbadw0lf.bsky.social · 22/02/2025
Submitted without comment
1385
Reposted by John
Dan Black @danwblack.bsky.social · 19/02/2025
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
3165115
Reposted by John
Dan Black @danwblack.bsky.social · 12/02/2025
Fantastic work here from the MSTIC folks re: 74455. So many threads to pull. www.microsoft.com/en-us/securi...
microsoft.com
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
02311
John @bigbadw0lf.bsky.social · 10/02/2025
Next generation hater and I’m here for it
170
John @bigbadw0lf.bsky.social · 10/01/2025
Starting the day with homemade bagels and affogato is the way.
1220
John @bigbadw0lf.bsky.social · 09/01/2025
Mfw I get to name some new malware
0100
Reposted by John
Matthew Kennedy @matthewkennedy.bsky.social · 09/01/2025
MSTIC is hiring in the UK and EU for entry level and senior analyst roles! jobs.careers.microsoft.com/global/en/jo... jobs.careers.microsoft.com/global/en/jo...
083
Reposted by John
Lasq @lasq.pl · 09/01/2025
New Year - New Ivanti Zero-Day. Almost exactly 1 year later, UNC5337 returns with their SPAWN malware family. Blog: cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
153
John @bigbadw0lf.bsky.social · 09/01/2025
🔥 new blog detailing 0day exploitation of Ivanti appliances as well as some newly observed malware families tracked as PHASEJAM and DRYHOOK. We also detail activity related to the previously observed SPAWN* malware ecosystem tied to China-nexus cluster UNC5337. cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
03322
John @bigbadw0lf.bsky.social · 08/01/2025
The Vaporfly 4 looks 🔥🔥🔥
010
Reposted by John
H I Sutton @covertshores.bsky.social · 05/01/2025
***BREAKING*** After loss of Tartus, Russia now has no submarines in the Mediterranean Russia’s struggle is symptomatic of wider issues. The Russian Navy is overstretched following the 2022 full-scale invasion of Ukraine and is suffering maintenance challenges. #OSINT
navalnews.com
After loss of Tartus, Russia now has no submarines in the Mediterranean - Naval News
The Russian Navy is significantly weakened in the Mediterranean. The only boat known to be there has just left, leaving no Russian submarines in the Mediterranean.
1846094
John @bigbadw0lf.bsky.social · 14/12/2024
This absolute banger is finally on Spotify, I invite you all to bask in its glory open.spotify.com/track/0oSjvM...
open.spotify.com
One Last Breath - Jojo Lorenzo Remix
Creed, Jojo Lorenzo · One Last Breath (Jojo Lorenzo Remix) · Song · 2024
120
John @bigbadw0lf.bsky.social · 13/12/2024
My backlog seeing me add more books my cart / wishlist
media.tenor.com
a woman is looking out a window and making a funny face .
ALT: a woman is looking out a window and making a funny face .
1103
John @bigbadw0lf.bsky.social · 11/12/2024
Mfw the post-injury VO2 max is back to the pre-injury VO2 max.
media.tenor.com
I Want You To Get The Word Out There That We Back Up The Wire GIF
ALT: I Want You To Get The Word Out There That We Back Up The Wire GIF
050
Reposted by John
Dan Black @danwblack.bsky.social · 09/12/2024
For those who who found interest in our presentations at @labscon.bsky.social and @cyberwarcon.bsky.social this year detailing Russia's espionage against frontline targets, CERT-UA has released details around one of the groups we spoke about (UNC4221) here: cert.gov.ua/article/6281...
cert.gov.ua
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
12612
Reposted by John
Mark MacKinnon @markmackinnon.bsky.social · 08/12/2024
Unconfirmed reports that the Kremlin has asked Viktor Yanukovych to get his guest room ready…
513015
John @bigbadw0lf.bsky.social · 08/12/2024
When you just drive straight to Damascus
050
John @bigbadw0lf.bsky.social · 08/12/2024
You moved your ships out of another strategic Naval base?
0563
Reposted by John
Matthew Kennedy @matthewkennedy.bsky.social · 05/12/2024
MSTIC is hiring! Current roles in US and AU. The Microsoft Threat Intelligence Center (MSTIC) is recruiting experienced nation-state threat hunters with highly honed threat intel analysis skills. MSTIC is responsible for delivering timely threat intelligence across our product & services teams.
411535
Reposted by John
Drunk Binary @drunkbinary.bsky.social · 29/11/2024
@bigbadw0lf.bsky.social www.instagram.com/share/reel/_...
instagram.com
Login • Instagram
Welcome back to Instagram. Sign in to check out what your friends, family & interests have been capturing & sharing around the world.
231
Reposted by John
Zach @thrustwr.bsky.social · 25/11/2024
What if you were a SAM operator waiting for an aircraft to enter your FOV so you could shoot it down? But the EA-6B said "In your face from outer space!" Then fired a salvo of HARMs at you from beyond your radar horizon.
513017
Reposted by John
Brian Kerg @briankerg.bsky.social · 24/11/2024
"Ukrainian victory will serve as the most effective deterrent to future aggression" - Tsai. The Taiwanese get it. To deter #PRC from attacking #TWN, help #UKR defeat #RUS. www.politico.com/news/2024/11...
politico.com
Taiwan’s former president says Ukraine needs US weapons more urgently than Taipei
Tsai Ing-wen’s comments come after a top U.S. military leader said supplying U.S. weapons to Kyiv was cutting into stockpiles that could be used in a war in Asia.
215136
John @bigbadw0lf.bsky.social · 23/11/2024
GNX is so damned good. Album on repeat all day.
071
John @bigbadw0lf.bsky.social · 23/11/2024
It’s simply too good
media.tenor.com
a cartoon of spongebob and patrick standing next to each other .
ALT: a cartoon of spongebob and patrick standing next to each other .
070
Reposted by John
Volexity @volexity.com · 22/11/2024
@volexity.com’s latest blog post describes in detail how a Russian APT used a new attack technique, the “Nearest Neighbor Attack”, to leverage Wi-Fi networks in close proximity to the intended target while the attacker was halfway around the world.    Read more here: www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
18040
John @bigbadw0lf.bsky.social · 22/11/2024
#cyberwarcon is the absolute best. Amazing talks and convos, massive shout out to @hultquist.bsky.social and the entire team for another unreal con.
0211
Reposted by John
Andy Greenberg @agreenberg.bsky.social · 22/11/2024
Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...
wired.com
Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack
In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street.
12573322
John @bigbadw0lf.bsky.social · 21/11/2024
Beautiful Crystal City, how I’ve missed your defense contractors and hotels
0110
Reposted by John
Sebastian Bae @sebastianbae.bsky.social · 21/11/2024
Exciting news from MicroProse on the digital version of my "Littoral Commander Indo-Pacific" #wargame. I am really excited to see the early access version in April 2025. #wargaming
714028
John @bigbadw0lf.bsky.social · 18/11/2024
media.tenor.com
a man with long white hair and a beard says to war
ALT: a man with long white hair and a beard says to war
040
Reposted by John
David Oxley @oxley.io · 09/11/2024
I’ve created a Starter Pack around cyber threat intelligence to make it easier to find that community here on Bluesky. Let me know of folks I missed, as I’m sure there are many! go.bsky.app/TxQYHap
3218370
John @bigbadw0lf.bsky.social · 17/11/2024
Super hype as always for CYBERWARCON. The talk lineup is 🔥🔥🔥
1101
John @bigbadw0lf.bsky.social · 17/11/2024
Full Send
050