Sign in

The Banshee Queen 👑

@cyberoverdrive.bsky.social
966 followers 285 following 143 posts

#threatintel @Recorded Future | Formerly @PwC GTI | Malware & infrastructure analysis with a side of cyberpunk. 🌃🌌 She/her, support 🏳️‍🌈🏳️‍⚧️✨

PostsRepliesMedia
Reposted by The Banshee Queen 👑
Karen Attiah @karenattiah.bsky.social · 7h
Today, 8 years ago, my friend, Saudi Journalist and Washington Post columnist Jamal Khashoggi was murdered.
11446201458
Reposted by The Banshee Queen 👑
Mark Kelly @mkyo.bsky.social · 01/10/2026
🚨 New @threatinsight.proofpoint.com blog covering a 🇨🇳- aligned threat actor targeting US AI policy circles in spear phishing campaigns in recent months: www.proofpoint.com/us/blog/thre...
proofpoint.com
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint US
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial
2106
Reposted by The Banshee Queen 👑
Peter Geoghegan @petergeoghegan.bsky.social · 30/09/2026
Here's the full story that the Tony Blair Institute doesn't want to answer questions about, on Democracy for Sale
democracyforsale.substack.com
Tony’s minor tantrum: how Blair’s institute responded to fresh “cash for access” questions
We asked TBI about allegations of £500,000 corporate memberships and a logo that vanished at Labour conference. They said they’re not talking to us anymore
7339144
Reposted by The Banshee Queen 👑
Katie Drummond @katie-drummond.bsky.social · 30/09/2026
Today, @wired.com is publishing Choke Points, an 18-month investigation into how Israel’s network of checkpoints, gates, and roadblocks is reshaping daily life for Palestinians in the occupied West Bank. A thread on the reporting, and what we found:
113665
Reposted by The Banshee Queen 👑
singular locus sarah @scgriffith.bsky.social · 30/09/2026
with this and the microsoft exec calling ai the largest of theft of human labor in history, we've got some evidence that people in power understand the various reasons you might hate ai, and they think those reasons rule
06727
Reposted by The Banshee Queen 👑
c0nc0rdance @c0nc0rdance.bsky.social · 30/09/2026
Omigod, this is the most heartwarming story possible! Backpack (bear 89) is the son of the 2019 winner of Fat Bear Week, Holly (bear 435). In 2007, he injured his foot & a practice of riding on momma's Holly's back had a new meaning: he was mobility-restricted while it healed. So Holly moved him.
From DISCVR blog's Facebook page, a momma bear & a yearling cub on her back in the shallow water.  I think the background has been swapped out, and I can't rule out some AI use there?  God, Facebook has become the social media for AI slop : (

The title of the article, which I link below, is "How Bear 89 earned the name Backpack"
2847451595
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 30/09/2026
I miss old-days CTI Twitter (and just old-days Twitter) so much. It was so good. There was so much shitposting and so much whimsy. So many memes. Lots of IOCs. Big sad :C
081
Reposted by The Banshee Queen 👑
Kenn White @kennwhite.bsky.social · 29/09/2026
So proud of this: real-time highly scalable distributed generalized database search on fully encrypted data, what we call Queryable Encryption is now out of beta. Culmination of 25+ years of academic work and 7 years of R&D engineering leadership under @senykamara.com and Tarik Moataz... (1/2)
1127
Reposted by The Banshee Queen 👑
Ian Campbell @neurovagrant.bsky.social · 29/09/2026
Had to dig it up for a Signal group so I'll drop it here too. If you haven't read the Reddit thread about the sysadmin who discovered the entire prod system ran out of a 500TB Dropbox that everyone had read/write access to, block off some time in your calendar: www.reddit.com/r/sysadmin/c...
reddit.com
From the sysadmin community on Reddit
Explore this post and more from the sysadmin community
4114
Reposted by The Banshee Queen 👑
Active Measures, LLC @activemeasures.bsky.social · 29/09/2026
before hype another programmer with psychosis from not touching grass comes forward consider
1318
Reposted by The Banshee Queen 👑
Raphael Satter @raphae.li · 29/09/2026
FBI official to ShinyHunters: Call us. www.reuters.com/world/us/fbi...
reuters.com
FBI official tells hackers to get in touch, says 'we know how to find you'
A senior FBI official has made an unusually public ‌request to the hacking group ShinyHunters, telling the cybercriminals on Tuesday they should get in touch following a wide-ranging breach of the bur...
294
Reposted by The Banshee Queen 👑
BleepingComputer @bleepingcomputer.com · 28/09/2026
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
bleepingcomputer.com
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
034
Reposted by The Banshee Queen 👑
Ulrike Franke @rikefranke.eu · 29/09/2026
“Estonian authorities have confirmed that the 15 August arson attack against the Estonian defence company Milrem Robotics in Tallinn was an act of sabotage ordered by Russian security services.” www.theguardian.com/world/live/2...
theguardian.com
Estonia says arson attack on ‘consistent with other acts of sabotage carried out in Europe on behalf of Russia’ - Europe live
Foreign minister summons Russia’s chargé d’affaires over attack on Milrem Robotics as security agency says incident was ‘deliberate and pre-planned’
518571
Reposted by The Banshee Queen 👑
David DiMolfetta @ddimolfetta.bsky.social · 28/09/2026
"GPT-6 Astra often asked for permission to perform unsanctioned actions on out-of-scope targets." From UK's AI Security Institute report out today: www.aisi.gov.uk/blog/gpt-6-a...
033
Reposted by The Banshee Queen 👑
Eric Geller @ericjgeller.com · 28/09/2026
Heads up for Citrix customers: CISA is amplifying the vendor's urgent warnings about a series of vulnerabilities in NetScaler security products. www.cisa.gov/news-events/... CISA says it has intelligence showing that "threat actors are actively exploiting these vulnerabilities globally."
cisa.gov
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway | CISA
084
Reposted by The Banshee Queen 👑
IFIN @ifin-intel.org · 27/09/2026
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story. ifin.network/t/citri... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Citrix Advises Shutdown Due to New, Undisclosed Netscaler 0-Days
Last Updated: 2026-09-26T23:22:28Z (UTC) What’s Happening On 2026-09-26T07:00:00Z (UTC), a Reddit posts in the Citrix community indicated that the presence of two 0-day vulnerabilities in Citrix Netscaler devices. The poster was apparently advised to shut down external devices. Research firm WatchTowr corroborated the report, as did researcher Kevin Beaumont. Both Beaumont and WatchTowr doubled down on the claim later in the day. WatchTowr, while unable to confirm sourcing, stated t...
11911
Reposted by The Banshee Queen 👑
Catalin Cimpanu @campuscodi.risky.biz · 27/09/2026
JADEPUFFEr, the AI-powered ransomware group, is destroying Azure environments as part of its extortion campaigns, most likely to put pressure on victims www.microsoft.com/en-us/securi...
microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and prov...
1108
Reposted by The Banshee Queen 👑
JP @jpbrammer.bsky.social · 19/09/2026
Slavoj Žižek has my dream job. I watched him speak in front of a crowd for 45 minutes uninterrupted about whatever he felt like while the host watched helplessly. when he finally finished she said "wise words" and he said "I HATE WISDOM" then started talking again
504056634
Reposted by The Banshee Queen 👑
Steve YARA Synapse Miller @stvemillertime.bsky.social · 22/11/2024
*downselection of activity not to scale
22313
Reposted by The Banshee Queen 👑
Horkos @wylienewmark.bsky.social · 24/09/2026
like @greatdismal.bsky.social said “it, not he”
051
Reposted by The Banshee Queen 👑
ponder @ponder.ooo · 24/09/2026
calling this "misalignment" instead of "negligence" is an accountability dodge. we already have laws about cyber crimes and there's no scale of ML model you can incorporate into your code that makes you not responsible for running it
In a statement, an OpenAI spokesperson said the company was "conducting an extensive review of misaligned model activity" during training, and notifying third parties when there was a potential impact on their systems.

"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation," they said.

"In the course of that, our models took actions we did not intend.
161065230
Reposted by The Banshee Queen 👑
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Reposted by The Banshee Queen 👑
The Serfs (youtube.com/theserfstv) @theserfstv.bsky.social · 24/09/2026
X-Men never "became woke" you just grew up to be a bad person.
10713155
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 24/09/2026
First they came for PassiveTotal. Then for Censys V2. 😭 I'M JUST A GIRL! I JUST WANT TO DO INFRASTRUCTURE RESEARCH! (You can pry DomainTools from my cold, dead hands.)
250
Reposted by The Banshee Queen 👑
The Citizen Lab @citizenlab.ca · 17/09/2026
1/ 🚨 NEW RESEARCH: We identified a training program provided to government employees in Angola by the Israeli influence-for-hire company BlackCore. Read the brief: citizenlab.ca/research/bla...
citizenlab.ca
Research Note: BlackCore’s Influence Operations for Hire - The Citizen Lab
In this research note, we examine the digital infrastructure of BlackCore, an Israeli influence-for-hire company. We describe how we identified a BlackCore campaign consisting of a training program pr...
12914
Reposted by The Banshee Queen 👑
Techmeme @techmeme.com · 17/09/2026
AWS says it can't restore some data stored exclusively in data centers across Bahrain and one UAE availability zone after Iranian drone strikes in the spring (Omar Abdel-Baqui/Wall Street Journal) Main Link | Techmeme Permalink
01210
Reposted by The Banshee Queen 👑
Adam @adam35.bsky.social · 16/09/2026
Everything Is Counterintelligence
0296
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 13/09/2026
How do I teleport myself directly inside this VNC’s screensaver
040
Reposted by The Banshee Queen 👑
Daniel Gordon @validhorizon.bsky.social · 13/09/2026
Eyal is exactly right. It has long been the case that threat actors would adopt the tools of pentesters. Now adversaries using LLMs are telling them that this is an authorized pentest and the LLM will often leave traces of that.
You can detect some AI-enabled attacks by searching for explicit indications of penetration testing. This happens because threat actors tell their LLMs they are performing authorized engagements even when using open weight models, or use pentesting harnesses like cyberstrikeAI, PentAGO, Hexstrike.
01613
Reposted by The Banshee Queen 👑
Alexis Rapin @alexis-rapin.bsky.social · 11/09/2026
Undersea cables are the definition of a strategic headache: super important, super hard to defend, super easy to damage. The logical response should be to aim for greater resilience. Well, guess what? There’s currently a grand total of 22 repair ships in service globally… 🫠
033
Reposted by The Banshee Queen 👑
Ben Read @benread.bsky.social · 11/09/2026
This report from Anthropic is really good and comes with a level of detail on atribution that is impressive. www.anthropic.com/threat-intel...
anthropic.com
Countering misuse of AI: September 2026 / Anthropic
Case studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse.
021
Reposted by The Banshee Queen 👑
PM2.5 Kills ~9 Million People Each Year Worldwide @tkovach.bsky.social · 08/09/2026
"It is estimated that for every $1 invested in integrated climate change and air pollution action about $15 is generated in economic benefits... In contrast, every year of delayed action would forgo more than $1.5tn annually — 0.5 per cent of GDP."
ft.com
Strong economic case for tackling pollution and climate change together, UN finds
Combined action could lift global growth by 2.8% by 2035, report estimates
03012
Reposted by The Banshee Queen 👑
Ron Deibert @rondeibert.bsky.social · 03/09/2026
NEW @citizenlab.ca report, in collaboration with The Share Foundation, finds iPhone of Serbian student protestor hacked with NSO Group's Pegasus spyware This is the first documented Pegasus infection of 2026 citizenlab.ca/research/peg...
citizenlab.ca
Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist - The Citizen Lab
In collaboration with the SHARE Foundation, the Citizen Lab confirmed that the iPhone of a member of Serbia’s student protest movement was infected with Pegasus spyware.
13521
Reposted by The Banshee Queen 👑
Electronic Frontier Foundation @eff.org · 31/08/2026
“They are going after the messenger,” EFF's @jillian.bsky.social told @theintercept.com. “I don’t think that the members of the group would necessarily condone the actions of the people that they hosted. What they do condone is the freedom to host, the ability to be anonymous, ... to be private.”
theintercept.com
Trump Goes After Anonymous Email Provider in Italy. The Real Target Is Free Speech in the U.S.
Trump designated a collective that provides anonymous email services as a foreign “terrorist” group. It could curtail free speech in the U.S.
213366
Reposted by The Banshee Queen 👑
evacide @evacide.bsky.social · 31/08/2026
Organizers and activists who oppose the Trump administration's policies should absolutely be paying close attention to this story: theintercept.com/2026/08/28/t...
theintercept.com
Trump Goes After Anonymous Email Provider in Italy. The Real Target Is Free Speech in the U.S.
Trump designated a collective that provides anonymous email services as a foreign “terrorist” group. It could curtail free speech in the U.S.
617792
Reposted by The Banshee Queen 👑
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 31/08/2026
Looking forward to presenting at LABScon next month. Can’t wait for the event and catching up with everyone again: www.labscon.io/speakers/jul...
labscon.io
Julian Ferdinand Vögele | LABScon
Join us September 16-19th for LABScon, an intimate, invite-only event for the top cybersecurity minds to gather, share cutting-edge research.
041
Reposted by The Banshee Queen 👑
Zack Whittaker @zackwhittaker.com · 31/08/2026
Also, ICYMI: Last week I published a 3,200-word deep-dive explainer on a major threat to your home and office: Residential proxy networks allow hackers to use your internet connection for crime and cyberattacks. Find out why resproxies are a threat, how they work, and what *you* can do about them. 🤖
this.weekinsecurity.com
How residential proxy networks are hiding hackers in your home
Security researchers say residential proxy networks present a major threat by allowing hackers to commandeer home and office networks for cybercrime.
13310
Reposted by The Banshee Queen 👑
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 27/08/2026
Today Insikt Group released new research on BlueDelta’s initial access campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye, using diplomatic-themed docs to deliver the backdoor HOOKEDGE. Check out the report here: www.recordedfuture.com/research/blu...
recordedfuture.com
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
072
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 28/08/2026
If we take goose = the worker(s), and egg = output of their labour, we can read Masayoshi Son’s surrealist egg slide as a Marxist parable of the power of the goose 🪿🥚🥚🥚
The excellent surrealist GOOSE slide from a presentation by Softbank’s Masayoshi Son. The slide says: 
“Shareholder Value = 3 eggs”
“Goose value 0?”
“Goose was not valued”
The slide was a response to investors valuing Softbank lower than some of the companies (eggs) that Softbank (goose)’s incubator had financed, invested in, and grown.The Pepe Silvia meme. A dishevelled man who clearly has not slept is holding a lit cigarette and pointing wildly at some kind of investigative map with red thread connecting the dots.
010
Reposted by The Banshee Queen 👑
Virus Bulletin @virusbtn.bsky.social · 28/08/2026
Insikt Group has identified a series of BlueDelta (APT28/Fancy Bear/Forest Blizzard) initial access campaigns targeting government & diplomatic organizations in Romania, Spain & Turkey. The campaigns deliver the HOOKEDGE backdoor using diplomatic-themed lures. www.recordedfuture.com/research/blu...
083
Reposted by The Banshee Queen 👑
lazarusholic @lazarusholic.bsky.social · 27/08/2026
"Insights into Suspected DPRK Workers: Red Flags to Look Out For" published by Huntress. #ITWorker, #FamousChollima, #PiKVM, #Guermok www.huntress.com/blog/huntress-dprk…
huntress.com
Insights into Suspected DPRK Workers: Red Flags to Look Out For
023
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 26/08/2026
040
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 26/08/2026
The temptation to run an alt account to meme / complain / hot take in peace about the absolute s t a t e of the cybersecurity industry is real
040
Reposted by The Banshee Queen 👑
TarZangief @tarzangief.bsky.social · 26/08/2026
"Neutral in the culture war"
111155785321
Reposted by The Banshee Queen 👑
Daniel Gordon @validhorizon.bsky.social · 25/08/2026
That is a lot of Chinese companies. Will be interesting to see how this will play out. home.treasury.gov/news/press-r...
home.treasury.gov
Treasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-Day
Initiates Operation Economic Outcast **WASHINGTON**—Today, at President Trump’s direction, the U.S. Department of the Treasury has begun Operation Economic Outcast: an unprecedented, whole-of-government, economic campaign against the Islamic Republic of Iran and its enablers. “In the Second World …
021
Reposted by The Banshee Queen 👑
Eric Geller @ericjgeller.com · 25/08/2026
CISA's red teams tried to break into two unnamed volunteer targets (a government agency and a water utility), with very different results based on how the organizations operated. CISA's new report explains the takeaways: www.cisa.gov/news-events/...
0135
Reposted by The Banshee Queen 👑
Chance the Lawyer @chancethelawyer.bsky.social · 21/08/2026
say what you will about the myriad valid concerns with current LLMs but I personally will never get over the fact that Aaron Swartz was prosecuted to his literal death for downloading JSTOR and then a decade later, they downloaded & ingested the entire world and our IP laws just went ¯\_(ツ)_/¯
4645491569
Reposted by The Banshee Queen 👑
Wesley Shields @wxs.bsky.social · 21/08/2026
This stuff is the same as UNC5976 (and yes, i had to go look that up because we dont use the UNC designation internally on my team) discussed in our post yesterday: cloud.google.com/blog/topics/...
cloud.google.com
Distinct Clusters Target Individuals of Interest to Russia | Google Cloud Blog
Distinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account com...
064
Reposted by The Banshee Queen 👑
Ciaran Martin @ciaranm.bsky.social · 20/08/2026
Sometimes, and especially right now, the field of cyber security feels like a bandwagon of doom that never reaches its destination.
6202
Reposted by The Banshee Queen 👑
Ian Campbell @neurovagrant.bsky.social · 22/08/2026
Residential proxies are probably in the top 3 active threats to global cybersecurity, so Zack's work here is important:
0206