Sign in

Dan Black

@danwblack.bsky.social
4.6K followers 238 following 153 posts

Previously Google, NATO, 🇨🇦 Government. Views mine and mine only.

PostsRepliesMedia
Reposted by Dan Black
Microsoft Threat Intelligence @threatintel.microsoft.com · 31/07/2026
Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers. msft.it/63328aBnhE
msft.it
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
2108
Reposted by Dan Black
State of Statecraft Conference @what-is-sos.bsky.social · 08/07/2025
State of Statecraft (SOS) is a new security and intelligence conference that brings together experts on espionage, sabotage, influence, and other unique forms of covert statecraft to share their work with a community hyper-focused on tackling state-sponsored operations.
1175
Dan Black @danwblack.bsky.social · 18/07/2025
APT28 🤝 war crimes
081
Dan Black @danwblack.bsky.social · 21/06/2025
Extending the veneer of grassroots activism «by default» to an entire category of threat activity routinely orchestrated (if not carried out directly) by intelligence agencies is just flat out irresponsible at this point. I beg of you: stop using the label "hacktivism".
140
Reposted by Dan Black
SwiftOnSecurity @swiftonsecurity.com · 13/06/2025
... maybe Teams isn't so bad
930736
Reposted by Dan Black
Ankit Panda @nktpnd.bsky.social · 10/05/2025
Short thread (hopefully in plain English) on the nuclear deterrence dynamics in the India-Pakistan relationship and where this goes if escalation continues. <1>
251335547
Reposted by Dan Black
Ollie Whitehouse @ollieatnowhere.bsky.social · 03/05/2025
Weekly summary is out.. ctoatncsc.substack.com/p/cto-at-ncs...
ctoatncsc.substack.com
CTO at NCSC Summary: week ending May 4th
The age of advanced cryptography techniques edges ever closer..
053
Dan Black @danwblack.bsky.social · 29/04/2025
Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service? www.diplomatie.gouv.fr/fr/dossiers-...
diplomatie.gouv.fr
Russie – Attribution de cyberattaques contre la France au service de renseignement militaire russe (APT28) (29.04.25)
La France condamne avec la plus grande fermeté le recours par le service de renseignement militaire russe (GRU) au mode opératoire d'attaque APT28, (…)
3167
Dan Black @danwblack.bsky.social · 15/04/2025
Credibility of claims aside, the slow creep toward direct mirroring of US public attribution has reached its final stop: www.reuters.com/technology/c...
reuters.com
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents
Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) of launching "advanced" cyberattacks during the Asian Winter Games in February, targeting essential industries.
0102
Dan Black @danwblack.bsky.social · 26/03/2025
Incredibly important piece here, bravo @lhn.bsky.social and @agreenberg.bsky.social www.wired.com/story/signal...
wired.com
SignalGate Isn’t About Signal
The Trump cabinet’s shocking leak of its plans to bomb Yemen raises myriad confidentiality and legal issues. The security of the encrypted messaging app Signal is not one of them.
0219
Reposted by Dan Black
Signal @signal.org · 25/03/2025
In order to help protect people from falling victim to sophisticated phishing attacks, Signal introduced new user flows and in-app warnings. This work has been completed for some time and is unrelated to any current events. 5/
278354
Reposted by Dan Black
Signal @signal.org · 25/03/2025
The memo used the term ‘vulnerability’ in relation to Signal—but it had nothing to do with Signal’s core tech. It was warning against phishing scams targeting Signal users. 3/
21009102
Reposted by Dan Black
Signal @signal.org · 25/03/2025
One piece of misinfo we need to address is the claim that there are ‘vulnerabilities’ in Signal. This isn’t accurate. Reporting on a Pentagon advisory memo appears to be at the heart of the misunderstanding: npr.org/2025/03/25/n.... 2/
121072146
Reposted by Dan Black
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/03/2025
It's never a bad time to take a look at your online accounts and see if you spot a weird device or login. We have a comprehensive guide on how to check if your Gmail, Apple ID, Facebook, IG, WhatsApp, Telegram, Discord, etc have been hacked. techcrunch.com/2025/03/25/h...
techcrunch.com
How to tell if your online accounts have been hacked | TechCrunch
This is a guide on how to check whether someone compromised your online accounts.
514977
Dan Black @danwblack.bsky.social · 25/03/2025
Russia's intelligence services have spent time and resources to develop Signal-specific tradecraft because it is best-in-class for secure communications. It is Signal's lack of vulnerability that makes the app the high priority target that it is.
43614
Reposted by Dan Black
Kevin Collier @kevincollier.bsky.social · 25/03/2025
It's really crucial to understand how badly framed this is. There is no Signal vulnerability. The Pentagon email did a bad job explaining a Google report from a month ago and NPR repeated it. This is like saying because you got a phishing email at your Gmail address, there's a Google vulnerability.
14481147
Reposted by Dan Black
James Sullivan @mrjamessullivan.bsky.social · 23/03/2025
We are looking for a motivated Research Analyst to join our cyber and tech team at @rusi.bsky.social. You need to be able to work in London. Full job spec below 👇 royalunitedservicesinstitute.peoplehr.net/Pages/JobBoa...
royalunitedservicesinstitute.peoplehr.net
Research Analyst
This position sits in RUSI’s Cyber and Tech Research group, which seeks to shine a light on UK and international cyber and technology issues. We take what can sometimes be complex and technical subjec...
03625
Dan Black @danwblack.bsky.social · 25/03/2025
Developing low visibility, low signature forms of compromise for signal accounts is a clear area of investment for Russia's services as well. Generally speaking if you use the app for sensitive comms: audit your linked devices. Do it now. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
0156
Reposted by Dan Black
Matthew Green @matthewdgreen.bsky.social · 25/03/2025
Right now a single technical organization is being asked to defend (at least) one side in a major regional war, the political communications of the entire US administration, the communications of anyone opposed to that administration, big piles of NGOs, and millions of “ordinary” folks to boot.
2334
Reposted by Dan Black
Ben Read @benread.bsky.social · 24/03/2025
For no reason at all, re-upping this blog from @danwblack.bsky.social, which shows the high interest that Russian APTs have in getting access to Signal messages. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
22010
Reposted by Dan Black
John Scott-Railton @jsrailton.bsky.social · 19/03/2025
🚨NEW REPORT: first forensic confirmation of #Paragon mercenary spyware infections in #Italy... Known targets: Activists & journalists. We also found deployments around the world. Including ... #Canada? And a lot more... Thread on our @citizenlab.ca investigation 1/ citizenlab.ca/2025/03/a-fi...
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations
By Bill Marczak, John Scott-Railton, Kate Robertson, Astrid Perry, Rebekah Brown, Bahr Abdul Razzak, Siena Anstis, and Ron Deibert March 19, 2025 
Clicca qui per leggere un riassunto del report in italiano.

Key Findings
Introducing Paragon Solutions. Paragon Solutions was founded in Israel in 2019 and sells spyware called Graphite. The company differentiates itself by claiming it has safeguards to prevent the kinds of spyware abuses that NSO Group and other vendors are notorious for.
Infrastructure Analysis of Paragon Spyware. Based on a tip from a collaborator, we mapped out server infrastructure that we attribute to Paragon’s Graphite spyware tool. We identified a subset of suspected Paragon deployments, including in Australia, Canada, Cyprus, Denmark, Israel, and Singapore. 
Identifying a Possible Canadian Paragon Customer. Our investigation surfaced potential links between Paragon Solutions and the Canadian Ontario Provincial Police, and found evidence of a growing ecosystem of spyware capability among Ontario-based police services.
Helping WhatsApp Catch a Zero-Click. We shared our analysis of Paragon’s infrastructure with Meta, who told us that the details were pivotal to their ongoing investigation into Paragon. WhatsApp discovered and mitigated an active Paragon zero-click exploit, and later notified over 90 individuals who it believed were targeted, including civil society members in Italy.

Please drop me a reply or note letting me know if this alt text helps you.Android Forensic Analysis: Italian Cluster. We forensically analyzed multiple Android phones belonging to Paragon targets in Italy (an acknowledged Paragon user) who were notified by WhatsApp. We found clear indications that spyware had been loaded into WhatsApp, as well as other apps on their devices. 
A Related Case of iPhone Spyware in Italy. We analyzed the iPhone of an individual who worked closely with confirmed Android Paragon targets. This person received an Apple threat notification in November 2024, but no WhatsApp notification. Our analysis showed an attempt to infect the device with novel spyware in June 2024. We shared details with Apple, who confirmed they had patched the attack in iOS 18.
Other Surveillance Tech Deployed Against The Same Italian Cluster. We also note 2024 warnings sent by Meta to several individuals in the same organizational cluster, including a Paragon victim, suggesting the need for further scrutiny into other surveillance technology deployed against these individuals.

Please drop me a note /reply letting me know if this alt text helps you.
4182109
Reposted by Dan Black
Nate Schenkkan @nateschenkkan.bsky.social · 15/03/2025
Gorbachev believed the Soviet Union had to reform or die. But his reforms were so incoherent and inconsistent, yet persistent, he wound up destroying the USSR-something practically no one when he started thought was a possible outcome.
3246
Dan Black @danwblack.bsky.social · 08/03/2025
One of things I miss the most now that I'm fully remote is the old in-office nerding out about what was in the news. This podcast has really helped to fill that void. Highly recommend.
1162
Reposted by Dan Black
The Kyiv Independent @kyivindependent.com · 23/02/2025
⚡️Russia launches largest drone attack since start of full-scale invasion. Ukraine’s air defense shot down 138 drones while 119 decoy drones were lost out of a total of 267 drones launched by Russia, the Ukrainian Air Force said.
kyivindependent.com
Russia launches largest drone attack since start of full-scale invasion
Ukraine’s air defense shot down 138 drones while 119 decoy drones were lost.
16500143
Reposted by Dan Black
Max Smeets @maxwsmeets.bsky.social · 20/02/2025
Ransom War: How Cyber Crime Became a Threat to National Security is officially out in Europe today! Thanks to everyone who helped make this possible. It has been a fascinating research journey. www.amazon.co.uk/Ransom-War-B...
amazon.co.uk
Ransom War: How Cyber Crime Became a Threat to National Security
Buy Ransom War: How Cyber Crime Became a Threat to National Security by Smeets, Max (ISBN: 9781911723912) from Amazon's Book Store. Everyday low prices and free delivery on eligible orders.
0268
Dan Black @danwblack.bsky.social · 20/02/2025
Regarding the anatomy of what is now a highly consequential disinformation narrative: has anyone sourced where the claim that Zelenskyy has four percent approval ratings originates from?
4171
Reposted by Dan Black
Kevin Collier @kevincollier.bsky.social · 19/02/2025
I feel like that point has maybe been underappreciated about this historic era we're living through. Governance not just by the historically wealthy, but by people consumed by mass, often shared delusions. People have always been wrong on some facts, but not sure it's ever been quite like this.
3519
Reposted by Dan Black
Andrew @athomashemlock.bsky.social · 19/02/2025
Really important to point out that part of the reason Russia is gunning for Signal in such an ass-backwards way is that all the normal ways they have to break into communications haven't worked on Signal.
39833
Reposted by Dan Black
Mark Karayan @markkarayan.bsky.social · 19/02/2025
"This activity is yet another example of the lengths threat actors will go through to find novel methods to compromise sensitive, encrypted communications." - @danwblack.bsky.social Update your Signal app folks cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
161
Dan Black @danwblack.bsky.social · 19/02/2025
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
3165115
Dan Black @danwblack.bsky.social · 18/02/2025
Intelligence from the US and close allies shows that Putin still wants to control all of Ukraine, according to four Western intelligence officials and two US congressional officials. “We have zero intelligence that Putin is interested in a real peace deal right now" www.nbcnews.com/politics/nat...
nbcnews.com
As U.S. and Putin negotiate, intel shows he's not interested 'in a real peace deal,' sources say
Intelligence suggests Russian President Vladimir Putin is going through the motions and still thinks he can eventually control all of Ukraine, the sources told NBC News.
55717
Dan Black @danwblack.bsky.social · 18/02/2025
A deeply disturbing third bullet point there
9234
Dan Black @danwblack.bsky.social · 17/02/2025
"An offer of Nato membership conditional on a Russian ceasefire breach has been promoted by some US senators and now has the backing of senior European leaders, including Alexander Stubb, the Finnish president" www.theguardian.com/world/2025/f...
theguardian.com
Macron convenes European leaders for Ukraine summit amid tension with US
Paris meeting aims to devise action plan for Ukraine’s future as US and Russian delegates prepare to meet
2319
Dan Black @danwblack.bsky.social · 16/02/2025
Upcoming discussions in Riyadh will almost certainly upend a lot of immediate collection priorities across Europe. Ripple effects likely to be seen in the mobile threat landscape with long-term proliferation consequences.
0193
Reposted by Dan Black
Oana Lungescu @oanalungescu.bsky.social · 15/02/2025
Not a great idea to do this individually - force sensing & prudent planning should be done through NATO.
5227
Dan Black @danwblack.bsky.social · 15/02/2025
www.wsj.com/world/europe... "The SSD has brought together various elements of Russia’s intelligence services. It has taken over some powers from the FSB, the country’s largest intelligence service, and absorbed Unit 29155"
wsj.com
Exclusive | A New Spy Unit Is Leading Russia’s Shadow War Against the West
The Department of Special Tasks has brought together veterans of the Kremlin’s most daring clandestine operations to carry out assassination attempts and sabotage overseas.
13421
Reposted by Dan Black
Ben Read @benread.bsky.social · 12/02/2025
Sharing the project I've been working on for the last month. Here's GTIG's paper on the severe threat to national security posed by cyber crime.
cloud.google.com
Cybercrime: A Multifaceted National Security Threat | Google Cloud Blog
Google Threat Intelligence Group discusses the current state of cybercrime, and why it must be considered a national security threat.
0175
Dan Black @danwblack.bsky.social · 12/02/2025
Fantastic work here from the MSTIC folks re: 74455. So many threads to pull. www.microsoft.com/en-us/securi...
microsoft.com
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
02311
Reposted by Dan Black
Monica @jolemamels.bsky.social · 10/02/2025
Swoop, Phanatic and Gritty photoshopped on NWO members
5618210
Dan Black @danwblack.bsky.social · 08/02/2025
Explosive-Laden Goggles Sent To Russian FPV Drone Operators www.twz.com/news-feature...
twz.com
Explosive-Laden Goggles Sent To Russian FPV Drone Operators
Russia is searching for the perpetrators of a scheme designed to blow up the heads of FPV drones operators, or at least induce fear of their kit.
1321
Reposted by Dan Black
Max Smeets @maxwsmeets.bsky.social · 30/01/2025
We created the Ransomware Countermeasures Tracker: virtual-routes.org/ransomware-c...
virtual-routes.org
Ransomware Countermeasures Tracker
This tracker identifies trends in government actions against ransomware, highlights areas where we see more or less activity, and establishes a baseline of awareness that can support future analyses o...
2105
Reposted by Dan Black
Mark MacKinnon @markmackinnon.bsky.social · 25/01/2025
With Trump in the White House "it is now clear that the starting assumption for economic and defence decisions in the future can no longer be that the U.S. will always be there for Canada. We must stand on our own." Today's @theglobeandmail.com editorial... www.theglobeandmail.com/opinion/edit...
theglobeandmail.com
Globe editorial: It’s time for Canada to finally grow up
Ottawa and the provinces need to accept that the United States can no longer be counted on
24711
Dan Black @danwblack.bsky.social · 23/01/2025
Exhibit B: united24media.com/latest-news/...
united24media.com
Russian Deputy Proposes Renaming Black Sea to ‘Russian Sea’
The Saratov Duma deputy proposes renaming the Black Sea to the 'Russian Sea,' after US President Trump renamed the Mexican Gulf to the American Gulf.
1123
Dan Black @danwblack.bsky.social · 19/01/2025
"Ruptures of undersea cables that have rattled European security officials in recent months were likely the result of maritime accidents rather than Russian sabotage, according to several U.S. and European intelligence officials." www.washingtonpost.com/world/2025/0...
washingtonpost.com
Accidents, not Russian sabotage, behind undersea cable damage, officials say
An emerging consensus among U.S. and European security services holds that accidents were the cause of damage to Baltic seabed energy and communications lines.
12110
Dan Black @danwblack.bsky.social · 19/01/2025
While the exact number is likely classified, the head of the US government’s dedicated counterintelligence organization said that by now “nearly 100” nations have purchased advanced spyware designed to crack into cellphones, “and they’re using it.” breakingdefense.com/2025/01/near...
breakingdefense.com
Nearly 100 countries have acquired cellphone spyware ‘and they’re using it’: Official
Michael Casey, director of the National Counterintelligence and Security Center, warned about the vulnerability of mobile devices.
36440
Dan Black @danwblack.bsky.social · 19/01/2025
"Some Chinese RedNote users have also posted reminders for their American counterparts on navigating the censorship system. For example, some have openly called on the newbies to accept China’s sovereignty over Taiwan" edition.cnn.com/2025/01/16/t...
edition.cnn.com
As US TikTok users move to RedNote, some are encountering Chinese-style censorship for the first time | CNN Business
Chinese social media platform Xiaohongshu, also known as RedNote, has been hiring for a surprising position in recent days: English-language content moderators.
1121