Sign in

Cedric Pernet

@cedricpernet.bsky.social
1.7K followers 187 following 96 posts

Senior Threat Researcher @ Proofpoint. Cybercrime / Cyberespionage aficionado. Has worked in several CSIRTs/CERTs. Metal & Rock dude, never enough guitars. Motorcycles fan. Wrote a book in French language on cyberespionage. Ex-Law Enforcement Officer

PostsRepliesMedia
Reposted by Cedric Pernet
Matt Burgess (WIRED) @mattburgess1.bsky.social · 03/07/2026
NEW: A politician investigating Pegasus spyware… had their phone hacked with Pegasus multiple times. The compromises came days ahead of key meetings of the spyware inquiry Story with @lhn.bsky.social
wired.com
EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones
“It is a direct attack on the rule of law,” says one European Parliament member of the new findings from Citizen Lab.
6372173
Reposted by Cedric Pernet
Wesley Shields @wxs.bsky.social · 30/06/2026
Jordan doing good work deep diving into Turla related malware we’ve been tracking for a while now. If you’re into Turla this is a good read. cloud.google.com/blog/topics/...
cloud.google.com
The Latest Addition to Turla’s Intelligence Gathering Apparatus | Google Cloud Blog
Analysis of a backdoor, STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla.
1103
Reposted by Cedric Pernet
François Deruty @derutyf.bsky.social · 25/06/2026
Adint ⤵️ www.sekoia.com/blog/sold-to...
sekoia.com
Sold to the Highest Bidder: The Escalation of ADINT from Geolocation Tracking to Intrusion Vector
033
Cedric Pernet @cedricpernet.bsky.social · 11/06/2026
Strengthening Public-Private Collaboration in the Fight Against #Cybercrime : #Proofpoint Joins #Europol EC3’s Advisory Group on #InternetSecurity www.proofpoint.com/us/blog/corp...
100
Reposted by Cedric Pernet
François Deruty @derutyf.bsky.social · 11/06/2026
APT28 ⤵️ blog.sekoia.io/apt28-an-evo...
blog.sekoia.io
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and public...
011
Cedric Pernet @cedricpernet.bsky.social · 09/06/2026
Definitely worth a read : Don't Fear the Repo: UNK_DeadDrop #Phishing Campaign Targets #Developers to Steal #Cryptocurrency www.proofpoint.com/us/blog/thre... #proofpoint #cybercrime #datatheft #northkorea
070
Reposted by Cedric Pernet
Gurvan Kristanadjaja @gurvankris.bsky.social · 28/05/2026
Mon caissier est un esclave : 43 travailleurs nigérians sans-papiers ont été exploités sans rémunération dans des Franprix, Super U, G20 de Paris et de la région parisienne. Une enquête préliminaire pour traite d’êtres humains a été ouverte. Une info @liberation.fr www.liberation.fr/societe/des-...
liberation.fr
Des dizaines de Nigérians sans papiers exploités dans des supérettes parisiennes : «Il m’a dit qu’il allait me sortir de la rue et que j’aurais un CDI»
Contre la promesse d’un titre de séjour, des exilés vulnérables ont été recrutés par un prêcheur pentecôtiste pour effectuer des stages dans des magasins. En réalité, ils ont dû travailler autant voir...
2238225
Reposted by Cedric Pernet
Internet Archive @archive.org · 22/05/2026
Web history disappears when it can’t be preserved. Today, many publishers are blocking the Wayback Machine from archiving parts of the public web, putting decades of digital history at risk. Tell publishers: don’t block the #WaybackMachine Sign the petition ➡️ www.savethearchive.com/newsleaders/
savethearchive.com
Tell New York Times, The Atlantic, and USA Today to keep the crucial work of journalists in the Wayback Machine!
The news isn’t getting preserved in the Wayback Machine anymore because major media outlets are blocking it.
015261
Reposted by Cedric Pernet
Pixels | Le Monde @pixelsfr.bsky.social · 22/05/2026
Derrière les fuites de données, une cyberdélinquance française, jeune et en quête d’« affirmation de soi »
lemonde.fr
Derrière les fuites de données, une cyberdélinquance française, jeune et en quête d’« affirmation de soi »
« Données personnelles, la grande fuite » (8/9). Loin des dossiers cybercriminels aux ramifications internationales, les vols de données sont bien souvent le fait d’adolescents isolés cherchant une forme de reconnaissance. Des profils particuliers auxquels la justice tente aujourd’hui d’adapter sa réponse.
035
Reposted by Cedric Pernet
Zack Whittaker @zackwhittaker.com · 21/05/2026
New, by me: Scammers are abusing a legitimate internal Microsoft account, used for sending critical account alerts and MFA codes to users logging in, to send spam and scam emails. We first saw a flood of these emails last week, but anti-spam project Spamhaus says this has been going on for months.
techcrunch.com
Scammers are abusing an internal Microsoft account to send spam links | TechCrunch
The loophole allows spammers and scammers to send emails from a legitimate Microsoft email address typically used for sending genuine account alerts.
12813
Reposted by Cedric Pernet
Bellingcat @bellingcat.com · 21/05/2026
Since the beginning of 2026, at least four landslides are reported to have killed hundreds of people at the Rubaya mines in the Democratic Republic of Congo (DRC), a major global source of coltan. Coltan is widely used in smartphones, laptops and e-vehicles. www.youtube.com/shorts/RZ_PH...
youtube.com
How We Verified Deadly Landslides in DRC Mines
YouTube video by Bellingcat
516675
Reposted by Cedric Pernet
Alexander Martin @alexmartin.bsky.social · 07/05/2026
Poland’s domestic intelligence service said attackers breached water treatment facilities in five towns in 2025, in some cases gaining access to industrial control systems that could have disrupted water supplies.
therecord.media
Polish intelligence warns hackers attacked water treatment control systems
The agency did not publicly attribute the incidents to a specific group or country but said Poland faced intensified hostile cyber activity in 2024 and 2025, “with particular emphasis on the special s...
156
Cedric Pernet @cedricpernet.bsky.social · 08/05/2026
Just heard @cloudflare.social kicked 1100 people out. A 20% layoff. Fxxxk !
000
Reposted by Cedric Pernet
Catalin Cimpanu @campuscodi.risky.biz · 06/05/2026
All German .de domains went down on Tuesday due to a DNSSEC failure at the country's domain registrar status.denic.de/pages/incide...
0187
Cedric Pernet @cedricpernet.bsky.social · 05/05/2026
@crowdstrike.bsky.social extends Falcon OverWatch to @microsoft.com #Endpoint Customers - ittech-pulse.com/news/crowdst... #crowdstrike #microsoft #detection #DFIR
000
Reposted by Cedric Pernet
Graham Cluley @grahamcluley.com · 04/05/2026
If you're going to extort millions from major retailers, maybe don't pose for Snapchat in a diamond-encrusted "HACK THE PLANET" necklace. A 19-year-old accused of being part of the Scattered Spider cybercrime gang has been arrested at Helsinki Airport. He now faces extradition to the USA.
bitdefender.com
Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition
Here's a tip for you all.
3153
Reposted by Cedric Pernet
andy jabbour @andyjabbour.bsky.social · 04/05/2026
'What to do if your child is being sextorted: A therapist’s guide for parents' new on Bitdefender www.bitdefender.com/en-us/blog/h... #sextortion #cybersecurity #parenting @gate15.bsky.social
bitdefender.com
What to do if your child is being sextorted
Learn how sextortion affects children and how parents can respond calmly, support recovery, and protect their child from online abuse.
054
Cedric Pernet @cedricpernet.bsky.social · 30/04/2026
Such a good news ! Made my day ! #cybercrime #europol #bust #fraud #financialfraud #cryptocurrency #cryptocurrencies www.europol.europa.eu/media-press/...
011
Reposted by Cedric Pernet
Gabriel Thierry @gabrielthierry.eurosky.social · 08/04/2026
QAnthropic restreint le lancement de son dernier modèle d’IA pour prévenir les risques de cyberattaques www.lemonde.fr/pixels/artic...
lemonde.fr
Anthropic restreint le lancement de son dernier modèle d’IA pour prévenir les risques de cyberattaques
Une cinquantaine d’entreprises auront accès à Mythos, modèle avancé de l’entreprise d’intelligence artificielle, particulièrement performant pour identifier les failles logicielles. Les progrès fulgur...
112
Reposted by Cedric Pernet
Hash Miser ✊🇺🇦 @hash-miser.bsky.social · 02/02/2026
Notepad ++ hijacked by state sponsored group, updates mechanism hijacked to spread fake update to a very specific set of selected targets notepad-plus-plus.org/news/hijacke...
notepad-plus-plus.org
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++
02530
Reposted by Cedric Pernet
Andy Greenberg @agreenberg.bsky.social · 30/01/2026
For those who read our piece about crypto scam compound whistleblower Red Bull, I've verified that this is his real Bluesky account below. Thank for your incredible courage and all your work to achieve justice, @mohammadmuzahir02.bsky.social.
114041
Cedric Pernet @cedricpernet.bsky.social · 28/01/2026
Can’t stop, won’t stop: TA584 innovates initial access www.proofpoint.com/us/blog/thre... #ClickFix #cybercrime #TA584 #ThreatActor #SocialEngineering #EMail #Tsundere #IAB
000
Cedric Pernet @cedricpernet.bsky.social · 28/01/2026
Fell on this nice #malware analysis and noticed I did not know about "anti-termination signal handling", so super interesting for me - evilcel3ri.github.io/2026/01/16/s... #threatintel #CTI #cybercrime
010
Cedric Pernet @cedricpernet.bsky.social · 21/01/2026
Cet article est un must-read qui nous éclaire sur les problématiques liées à l' #AdInt
031
Reposted by Cedric Pernet
Wesley Shields @wxs.bsky.social · 09/01/2026
github.com/VirusTotal/y... - 1.11.0 is out! Lots of new features, modules and bug fixes. Read the release notes and congrats to Victor and the contributors!
github.com
Release v1.11.0 · VirusTotal/yara-x
Make the parser stricter (#502). Implement dex module (#458). Implement C api console log (#515). Implement permhash for the crx module (#510). Implement the imports() method for the Rules object i...
063
Reposted by Cedric Pernet
andy jabbour @andyjabbour.bsky.social · 09/01/2026
FBI FLASH: North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities www.ic3.gov/CSA/2026/260... #cybersecurity @gate15.bsky.social
043
Reposted by Cedric Pernet
404 Media @404media.co · 08/01/2026
404 Media has obtained material that explains how two surveillance systems ICE recently purchased, work. One can track phones without a warrant and follow their owners home or to their employer. @evystadium.bsky.social has more. Scoop by @josephcox.bsky.social: www.404media.co/inside-ices-...
34717427
Reposted by Cedric Pernet
Vas Panagiotopoulos @vaspanagiotopoulos.com · 06/01/2026
"Among the government bodies listed on documents seen by Intelligence Online are 🇵🇰Pakistan and its defence ministry, 🇮🇩Indonesia's State Intelligence Agency, the 🇲🇲Myanmar Police Force, 🇲🇽Mexico's army and navy and 🇻🇪Venezuela's defence ministry." www.intelligenceonline.com/americas/202...
072
Cedric Pernet @cedricpernet.bsky.social · 11/12/2025
Common mistake for some CTI people: flagging a web provider's parking IP addresses as malicious. Please check carefully. This can lead to total nonsense attribution/pivots when unverified. #fail #ThreatIntelligence
130
Reposted by Cedric Pernet
Zack Whittaker @zackwhittaker.com · 26/11/2025
Brian Krebs identified the real-world identity of Rey, a key administrator of Scattered Lapsus$ Hunters, a hacking group blamed for dozens of high profile hacks. The hacker, identified as a Jordanian teenager, agreed to be interviewed after Krebs tracked him down and contacted his father.
krebsonsecurity.com
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
A prolific cybercriminal group that calls itself "Scattered LAPSUS$ Hunters" made headlines regularly this year by stealing data from and publicly mass extorting dozens of major corporations. But the ...
2244
Reposted by Cedric Pernet
Matt Burgess (WIRED) @mattburgess1.bsky.social · 26/11/2025
NEW: Myanmar has made a big show of destroying the notorious KK Park scam compound—even publishing a video of a steamroller driving over thousands of phones But new images show buildings are only destroyed in one area. Hundreds are left untouched and experts say the crackdown is mostly propaganda
wired.com
The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been ‘Performative’
Myanmar’s military has been blowing up parts of the KK Park scam compound. Experts say the actions are likely for show.
410843
Reposted by Cedric Pernet
Pixels | Le Monde @pixelsfr.bsky.social · 26/11/2025
Le géant de l’informatique HP annonce la suppression de 4 000 à 6 000 emplois d’ici 2028 du fait de l’IA
lemonde.fr
Le géant de l’informatique HP annonce la suppression de 4 000 à 6 000 emplois d’ici 2028 du fait de l’IA
C’est l’une des premières fois qu’une entreprise de taille importante fait publiquement un lien direct entre des réductions de personnel et la mise en place d’outils IA.
032
Cedric Pernet @cedricpernet.bsky.social · 26/11/2025
Charming Kitten exposed: spy unit led Iran’s surveillance for deadly plots - content.iranintl.com/secret-spy-u...
021
Reposted by Cedric Pernet
Gabriel Thierry @gabrielthierry.eurosky.social · 05/11/2025
Incroyable histoire dévoilé par @theguardian.com : "Rise of the ‘porno-trolls’: how one porn platform made millions suing its viewers" www.theguardian.com/society/ng-i...
theguardian.com
Rise of the ‘porno-trolls’: how one porn platform made millions suing its viewers
A company called Strike 3, owner of Vixen and Tushy, has clogged US courts with lawsuits, mostly against porn watchers who feel shamed into settling privately
041
Cedric Pernet @cedricpernet.bsky.social · 05/11/2025
My thought of the day: all registrars should rethink their registration processes, so that automatic registration cannot be done that easily by cybercriminals. Some of them register hundreds of domains every day... #fightautomation #cybercrime
231
Cedric Pernet @cedricpernet.bsky.social · 05/11/2025
Well some people here asked me where the hell I have been. To make it short: lot of good work (not public), and getting separated from my wife. So, quite a hot-cold situation. Will try to come more often here and start spreading cybercrime/APT stuff again.
130
Cedric Pernet @cedricpernet.bsky.social · 27/07/2025
Infamous BreachForums Is Back Online With All Old Accounts and Posts Restored - cybersecuritynews.com/breachforums... #cybercrime
012
Reposted by Cedric Pernet
Andrew Couts @couts.bsky.social · 17/06/2025
NEW: Data broker sites were allegedly used by the Minnesota shooting suspect, authorities claim, highlighting the danger of an industry that freely sells your personal information. @lhn.bsky.social reports www.wired.com/story/minnes...
wired.com
Minnesota Shooting Suspect Allegedly Used Data Broker Sites to Find Targets' Addresses
The Minnesota shooter allegedly researched several “people search” sites in an attempt to target his victims, highlighting the potential dangers of widely available personal data.
11425179
Reposted by Cedric Pernet
ThreatInsight @threatinsight.proofpoint.com · 05/06/2025
We recently discovered an infostealer in our data that we originally dubbed "Aurotun," named for a misspelling of "autorun" in its strings. After collab w/ @intel471.bsky.social, @malwareindepth.com & others, we believe this malware is actually MonsterV2, a newer version of an existing infostealer.
242
Reposted by Cedric Pernet
Martin Untersinger @untersin.gr · 30/04/2025
Tu envoies des e-mails de phishing usurpant Le Monde ? @flrnd.bsky.social et @okami.bsky.social retrouvent ton adresse e-mail.
lemonde.fr
Qui organise les campagnes d’hameçonnage visant les abonnés du « Monde » et de « Télérama » ?
Des tentatives d’arnaques avec des messages piégés ont ciblé, ces dernières semaines, les abonnés de plusieurs grands journaux, dont « Le Figaro » ou « Le Monde ». La trace des pirates mène en France.
141
Cedric Pernet @cedricpernet.bsky.social · 30/04/2025
Very happy and proud that one of my "weekend research" has been exposed in an article from Le Monde. I had spent some time during my short unemployed period to dig into #Traffyque infrastructure. www.lemonde.fr/pixels/artic... #cybercrime #lemonde
081
Reposted by Cedric Pernet
Joseph Cox @josephcox.bsky.social · 28/04/2025
New from 404 Media: the age of realtime deepfake fraud is here. Scammers in Nigeria are using realtime deepfakes to change their race, facial hair, gender, more to appear as someone else on video calls. Results very realistic now. Also tricking verification systems www.404media.co/the-age-of-r...
404media.co
The Age of Realtime Deepfake Fraud Is Here
Fraudsters are able to change their race, facial hair, voice, and more during live video calls with very little effort. Scammers are already fooling the elderly and verification systems.
9282166
Reposted by Cedric Pernet
Alexander Martin @alexmartin.bsky.social · 09/04/2025
Spyware-infected apps are being used to target individuals and organizations worldwide who are tied to Uyghur, Tibetan and Taiwanese activities “considered by the Chinese state to pose a threat to its stability,” @suzannesmalley.bsky.social reports this morning.
therecord.media
NCSC shares technical details of spyware targeting Uyghur, Tibetan and Taiwanese groups
The U.K.’s National Cyber Security Centre and international cybersecurity and intelligence agencies on Wednesday said hackers are deploying two forms of previously identified spyware to snoop on Uyghu...
01514
Reposted by Cedric Pernet
Synacktiv @synacktiv.com · 09/04/2025
From firmware dumps to wireless exploration — check out our latest dive into DVB receiver analysis and the hidden attack surface it exposes! www.synacktiv.com/en/publicati...
synacktiv.com
Hack the channel: A Deep Dive into DVB Receiver Security
Introduction During a garage cleaning, we found a DVB receiver and thought it would be a great target for vulnerability research.
01211
Cedric Pernet @cedricpernet.bsky.social · 29/03/2025
Weaver Ant, the Web Shell Whisperer: Tracking a Live China-nexus Operation - www.sygnia.co/threat-repor... #APT #longpersistence
020
Reposted by Cedric Pernet
Catalin Cimpanu @campuscodi.risky.biz · 29/03/2025
The Grandoreiro malware operation is back up and running after some of its members were detained last year. Forcepoint has detected new large-scale phishing operations spreading the banking trojan to users in Europe and Latin America www.forcepoint.com/blog/x-labs/...
forcepoint.com
Grandoreiro Trojan Distributed via Contabo-Hosted Servers in Phishing Campaigns
Cybercriminals are spreading the Grandoreiro banking trojan in Mexico, Argentina and Spain through phishing emails impersonating a tax agency.
072
Cedric Pernet @cedricpernet.bsky.social · 29/03/2025
Pulling the Threads on the Phish of Troy Hunt - www.validin.com/blog/pulling... #cybercrime #phishing
000
Reposted by Cedric Pernet
Catalin Cimpanu @campuscodi.risky.biz · 29/03/2025
Zscaler has spotted a new malware loader named CoffeeLoader, used in the wild since September of last year. The malware was used together and appears to bear similarities with SmokeLoader. www.zscaler.com/blogs/securi...
zscaler.com
CoffeeLoader: A Brew of Stealthy Techniques | ThreatLabz
CoffeeLoader is a new malware loader that employs stealthy techniques including call stack spoofing, sleep obfuscation, and Windows fibers to evade detection.
0105
Cedric Pernet @cedricpernet.bsky.social · 10/03/2025
Following the discreet layoffs at Trend Micro at the end of last year, I am now incredibly proud to announce that I just joined the powerful forces of @proofpoint.com ! I feel very gifted and honored to start working with such an amazing team of researchers !
3102