Sign in

Christopher Glyer

@cglyer.bsky.social
4K followers 63 following 12 posts

Microsoft Threat Intelligence Center - Former Incident Responder & Chief Security Architect @Mandiant

PostsRepliesMedia
Reposted by Christopher Glyer
PIVOTcon @pivotcon.bsky.social · 14/12/2023
Are you ready to pivot?! Come to Malaga on May 8-10, 2024! #PIVOTcon24 is crafted to bring together professionals from diverse backgrounds – private sector, government, law enforcement, military, academics, and investigative journalists. #ThreatIntel #CTI
197
Christopher Glyer @cglyer.bsky.social · 03/11/2023
Sneak preview of my #cyberwarcon slides 👀
050
Christopher Glyer @cglyer.bsky.social · 06/10/2023
"You compile me. You had me at RomCom" - When cybercrime met espionage" Get ready for a #CYBERWARCON talk full of romantic comedy memes! www.cyberwarcon.com/you-compile-...
031
Christopher Glyer @cglyer.bsky.social · 14/07/2023
Here are technical details on Storm-0558 www.microsoft.com/en-us/security/bl…
microsoft.com
Analysis of Storm-0558 techniques for unauthorized email access | Microsoft Security Blog
Analysis of the techniques used by the threat actor tracked as Storm-0558 for obtaining unauthorized access to email data, tools, and unique infrastructure characteristics.
062
Christopher Glyer @cglyer.bsky.social · 06/07/2023
IMO: Storm-0875 (overlaps UNC3944/Scattered Spider) is the most dangerous financial threat actor right now Some recent developments: 1. Now deploying ransomware (had been extorting orgs before) 2. In last few months targeting large/well known enterprises (not just telcos/help desk/crypto orgs)
185
Reposted by Christopher Glyer
Horkos @wylienewmark.bsky.social · 16/06/2023
if i was a FVEY CI officer, my first thought on a RU-based company publishing on FSB ops wouldn’t be “look at the analytic freedom!” — it would be “why is the FSB comfortable with the world knowing about this now? did they figure out we were onto it in some way?”
122
Christopher Glyer @cglyer.bsky.social · 15/06/2023
I’ve been in touch w/different victims of MOVEit exploitation by Lace Tempest. One thing orgs should be prepared for is initial $ demand that is (in some cases) order of magnitude or more than a typical org would pay (relative to size of payment in other ransom/extortion cases)
000
Christopher Glyer @cglyer.bsky.social · 15/06/2023
Attribution update from MSTIC on MOVEit Transfer 0-day exploitation by Lace Tempest. Victims w/ data theft are likely to be extorted via the cl0p leak site in coming weeks We’ve shared intel on dozens of exfil IP addresses used in attacks w/customers & industry partners
010