Sign in

Dan Black

@danwblack.bsky.social
4.6K followers 238 following 153 posts

Previously Google, NATO, 🇨🇦 Government. Views mine and mine only.

PostsRepliesMedia
Reposted by Dan Black
Microsoft Threat Intelligence @threatintel.microsoft.com · 31/07/2026
Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers. msft.it/63328aBnhE
msft.it
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
2108
Reposted by Dan Black
State of Statecraft Conference @what-is-sos.bsky.social · 08/07/2025
State of Statecraft (SOS) is a new security and intelligence conference that brings together experts on espionage, sabotage, influence, and other unique forms of covert statecraft to share their work with a community hyper-focused on tackling state-sponsored operations.
1175
Dan Black @danwblack.bsky.social · 18/07/2025
APT28 🤝 war crimes
081
Dan Black @danwblack.bsky.social · 21/06/2025
Extending the veneer of grassroots activism «by default» to an entire category of threat activity routinely orchestrated (if not carried out directly) by intelligence agencies is just flat out irresponsible at this point. I beg of you: stop using the label "hacktivism".
140
Reposted by Dan Black
SwiftOnSecurity @swiftonsecurity.com · 13/06/2025
... maybe Teams isn't so bad
930736
Reposted by Dan Black
Ankit Panda @nktpnd.bsky.social · 10/05/2025
Short thread (hopefully in plain English) on the nuclear deterrence dynamics in the India-Pakistan relationship and where this goes if escalation continues. <1>
251335547
Reposted by Dan Black
Ollie Whitehouse @ollieatnowhere.bsky.social · 03/05/2025
Weekly summary is out.. ctoatncsc.substack.com/p/cto-at-ncs...
ctoatncsc.substack.com
CTO at NCSC Summary: week ending May 4th
The age of advanced cryptography techniques edges ever closer..
053
Dan Black @danwblack.bsky.social · 29/04/2025
Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service? www.diplomatie.gouv.fr/fr/dossiers-...
diplomatie.gouv.fr
Russie – Attribution de cyberattaques contre la France au service de renseignement militaire russe (APT28) (29.04.25)
La France condamne avec la plus grande fermeté le recours par le service de renseignement militaire russe (GRU) au mode opératoire d'attaque APT28, (…)
3167
Dan Black @danwblack.bsky.social · 17/04/2025
Finally
130
Dan Black @danwblack.bsky.social · 15/04/2025
Credibility of claims aside, the slow creep toward direct mirroring of US public attribution has reached its final stop: www.reuters.com/technology/c...
reuters.com
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents
Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) of launching "advanced" cyberattacks during the Asian Winter Games in February, targeting essential industries.
0102
Dan Black @danwblack.bsky.social · 26/03/2025
Incredibly important piece here, bravo @lhn.bsky.social and @agreenberg.bsky.social www.wired.com/story/signal...
wired.com
SignalGate Isn’t About Signal
The Trump cabinet’s shocking leak of its plans to bomb Yemen raises myriad confidentiality and legal issues. The security of the encrypted messaging app Signal is not one of them.
0219
Reposted by Dan Black
Signal @signal.org · 25/03/2025
In order to help protect people from falling victim to sophisticated phishing attacks, Signal introduced new user flows and in-app warnings. This work has been completed for some time and is unrelated to any current events. 5/
278354
Reposted by Dan Black
Signal @signal.org · 25/03/2025
The memo used the term ‘vulnerability’ in relation to Signal—but it had nothing to do with Signal’s core tech. It was warning against phishing scams targeting Signal users. 3/
21009102
Reposted by Dan Black
Signal @signal.org · 25/03/2025
One piece of misinfo we need to address is the claim that there are ‘vulnerabilities’ in Signal. This isn’t accurate. Reporting on a Pentagon advisory memo appears to be at the heart of the misunderstanding: npr.org/2025/03/25/n.... 2/
121072146
Reposted by Dan Black
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/03/2025
It's never a bad time to take a look at your online accounts and see if you spot a weird device or login. We have a comprehensive guide on how to check if your Gmail, Apple ID, Facebook, IG, WhatsApp, Telegram, Discord, etc have been hacked. techcrunch.com/2025/03/25/h...
techcrunch.com
How to tell if your online accounts have been hacked | TechCrunch
This is a guide on how to check whether someone compromised your online accounts.
514977
Dan Black @danwblack.bsky.social · 25/03/2025
Russia's intelligence services have spent time and resources to develop Signal-specific tradecraft because it is best-in-class for secure communications. It is Signal's lack of vulnerability that makes the app the high priority target that it is.
43614
Reposted by Dan Black
Kevin Collier @kevincollier.bsky.social · 25/03/2025
It's really crucial to understand how badly framed this is. There is no Signal vulnerability. The Pentagon email did a bad job explaining a Google report from a month ago and NPR repeated it. This is like saying because you got a phishing email at your Gmail address, there's a Google vulnerability.
14481147
Reposted by Dan Black
James Sullivan @mrjamessullivan.bsky.social · 23/03/2025
We are looking for a motivated Research Analyst to join our cyber and tech team at @rusi.bsky.social. You need to be able to work in London. Full job spec below 👇 royalunitedservicesinstitute.peoplehr.net/Pages/JobBoa...
royalunitedservicesinstitute.peoplehr.net
Research Analyst
This position sits in RUSI’s Cyber and Tech Research group, which seeks to shine a light on UK and international cyber and technology issues. We take what can sometimes be complex and technical subjec...
03625
Dan Black @danwblack.bsky.social · 25/03/2025
Developing low visibility, low signature forms of compromise for signal accounts is a clear area of investment for Russia's services as well. Generally speaking if you use the app for sensitive comms: audit your linked devices. Do it now. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
0156
Reposted by Dan Black
Matthew Green @matthewdgreen.bsky.social · 25/03/2025
Right now a single technical organization is being asked to defend (at least) one side in a major regional war, the political communications of the entire US administration, the communications of anyone opposed to that administration, big piles of NGOs, and millions of “ordinary” folks to boot.
2334
Reposted by Dan Black
Ben Read @benread.bsky.social · 24/03/2025
For no reason at all, re-upping this blog from @danwblack.bsky.social, which shows the high interest that Russian APTs have in getting access to Signal messages. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
22010
Reposted by Dan Black
John Scott-Railton @jsrailton.bsky.social · 19/03/2025
🚨NEW REPORT: first forensic confirmation of #Paragon mercenary spyware infections in #Italy... Known targets: Activists & journalists. We also found deployments around the world. Including ... #Canada? And a lot more... Thread on our @citizenlab.ca investigation 1/ citizenlab.ca/2025/03/a-fi...
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations
By Bill Marczak, John Scott-Railton, Kate Robertson, Astrid Perry, Rebekah Brown, Bahr Abdul Razzak, Siena Anstis, and Ron Deibert March 19, 2025 
Clicca qui per leggere un riassunto del report in italiano.

Key Findings
Introducing Paragon Solutions. Paragon Solutions was founded in Israel in 2019 and sells spyware called Graphite. The company differentiates itself by claiming it has safeguards to prevent the kinds of spyware abuses that NSO Group and other vendors are notorious for.
Infrastructure Analysis of Paragon Spyware. Based on a tip from a collaborator, we mapped out server infrastructure that we attribute to Paragon’s Graphite spyware tool. We identified a subset of suspected Paragon deployments, including in Australia, Canada, Cyprus, Denmark, Israel, and Singapore. 
Identifying a Possible Canadian Paragon Customer. Our investigation surfaced potential links between Paragon Solutions and the Canadian Ontario Provincial Police, and found evidence of a growing ecosystem of spyware capability among Ontario-based police services.
Helping WhatsApp Catch a Zero-Click. We shared our analysis of Paragon’s infrastructure with Meta, who told us that the details were pivotal to their ongoing investigation into Paragon. WhatsApp discovered and mitigated an active Paragon zero-click exploit, and later notified over 90 individuals who it believed were targeted, including civil society members in Italy.

Please drop me a reply or note letting me know if this alt text helps you.Android Forensic Analysis: Italian Cluster. We forensically analyzed multiple Android phones belonging to Paragon targets in Italy (an acknowledged Paragon user) who were notified by WhatsApp. We found clear indications that spyware had been loaded into WhatsApp, as well as other apps on their devices. 
A Related Case of iPhone Spyware in Italy. We analyzed the iPhone of an individual who worked closely with confirmed Android Paragon targets. This person received an Apple threat notification in November 2024, but no WhatsApp notification. Our analysis showed an attempt to infect the device with novel spyware in June 2024. We shared details with Apple, who confirmed they had patched the attack in iOS 18.
Other Surveillance Tech Deployed Against The Same Italian Cluster. We also note 2024 warnings sent by Meta to several individuals in the same organizational cluster, including a Paragon victim, suggesting the need for further scrutiny into other surveillance technology deployed against these individuals.

Please drop me a note /reply letting me know if this alt text helps you.
4181108
Reposted by Dan Black
Nate Schenkkan @nateschenkkan.bsky.social · 15/03/2025
Gorbachev believed the Soviet Union had to reform or die. But his reforms were so incoherent and inconsistent, yet persistent, he wound up destroying the USSR-something practically no one when he started thought was a possible outcome.
3246
Dan Black @danwblack.bsky.social · 08/03/2025
One of things I miss the most now that I'm fully remote is the old in-office nerding out about what was in the news. This podcast has really helped to fill that void. Highly recommend.
1162
Reposted by Dan Black
The Kyiv Independent @kyivindependent.com · 23/02/2025
⚡️Russia launches largest drone attack since start of full-scale invasion. Ukraine’s air defense shot down 138 drones while 119 decoy drones were lost out of a total of 267 drones launched by Russia, the Ukrainian Air Force said.
kyivindependent.com
Russia launches largest drone attack since start of full-scale invasion
Ukraine’s air defense shot down 138 drones while 119 decoy drones were lost.
16500143
Reposted by Dan Black
Max Smeets @maxwsmeets.bsky.social · 20/02/2025
Ransom War: How Cyber Crime Became a Threat to National Security is officially out in Europe today! Thanks to everyone who helped make this possible. It has been a fascinating research journey. www.amazon.co.uk/Ransom-War-B...
amazon.co.uk
Ransom War: How Cyber Crime Became a Threat to National Security
Buy Ransom War: How Cyber Crime Became a Threat to National Security by Smeets, Max (ISBN: 9781911723912) from Amazon's Book Store. Everyday low prices and free delivery on eligible orders.
0268
Dan Black @danwblack.bsky.social · 20/02/2025
Regarding the anatomy of what is now a highly consequential disinformation narrative: has anyone sourced where the claim that Zelenskyy has four percent approval ratings originates from?
4171
Reposted by Dan Black
Kevin Collier @kevincollier.bsky.social · 19/02/2025
I feel like that point has maybe been underappreciated about this historic era we're living through. Governance not just by the historically wealthy, but by people consumed by mass, often shared delusions. People have always been wrong on some facts, but not sure it's ever been quite like this.
3519
Reposted by Dan Black
Andrew (🎃) @athomashemlock.bsky.social · 19/02/2025
Really important to point out that part of the reason Russia is gunning for Signal in such an ass-backwards way is that all the normal ways they have to break into communications haven't worked on Signal.
39833
Reposted by Dan Black
Mark Karayan @markkarayan.bsky.social · 19/02/2025
"This activity is yet another example of the lengths threat actors will go through to find novel methods to compromise sensitive, encrypted communications." - @danwblack.bsky.social Update your Signal app folks cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
161
Dan Black @danwblack.bsky.social · 19/02/2025
Last but not least: our extreme gratitude to Signal for helping to investigate this activity and introducing hardened features to protect users from similar phishing campaigns of a similar nature. Update to the latest version to enable these features. support.signal.org/hc/en-us/art...
support.signal.org
How do I ensure Signal is up to date?
Signal gets better with every update. Here's how to make sure you can get every one: Android iOS Desktop Android What is the latest version of Signal Android?Check Google Play for the latest ve...
0100
Dan Black @danwblack.bsky.social · 19/02/2025
Those at risk of targeting by Russian or other intelligence services should exercise caution in engaging with links on their mobile devices, and more generally, urgently consider whether the risk exposure from linked devices is appropriate for them.
160
Dan Black @danwblack.bsky.social · 19/02/2025
Or the excellent research from our colleagues at Microsoft covering Star Blizzard/ COLDRIVER’s attempts to compromise WhatsApp accounts using the same linked device phishing technique www.microsoft.com/en-us/securi...
microsoft.com
New Star Blizzard spear-phishing campaign targets WhatsApp accounts | Microsoft Security Blog
In mid-November 2024, Microsoft Threat Intelligence observed the Russian threat actor we track as Star Blizzard sending their typical targets spear-phishing messages, this time offering the supposed o...
140
Dan Black @danwblack.bsky.social · 19/02/2025
Importantly, this threat is not unique to Signal, and is already seeing wider use outside of Ukraine. See, for example, UNC5792’s effort to compromise the WhatsApp account of Christo Grozev using a fake invite to the World Economic Forum in Davos.
171
Dan Black @danwblack.bsky.social · 19/02/2025
We have also seen a range of Russia-aligned threat actors attempting to steal Signal database files from compromised Android or Windows systems. Multiple actors in play here, including APT44’s BadPilot subgroup, Turla, and Belarus-linked UNC1151. www.microsoft.com/en-us/securi...
microsoft.com
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
170
Dan Black @danwblack.bsky.social · 19/02/2025
Variations of this technique are in active use, including in remote phishing operations using fake group invites (UNC5792), fake military apps (UNC4221), and in close-access operations targeting captured devices on the battlefield (APT44) cloud.google.com/blog/topics/...
cloud.google.com
Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm | Google Cloud Blog
APT44 is a threat actor that is actively engaged in the full spectrum of espionage, attack, and influence operations.
150
Dan Black @danwblack.bsky.social · 19/02/2025
If successful, future messages are delivered synchronously to the threat actor in real-time, providing a persistent means to the victim's secure conversations without the need for full-device compromise.
160
Dan Black @danwblack.bsky.social · 19/02/2025
On the tradecraft front, the most novel and widely used technique has been Russia’s attempts to abuse the legitimate "linked devices" feature that enables Signal to be used on multiple devices concurrently. support.signal.org/hc/en-us/art...
support.signal.org
Linked Devices
You can link Signal Desktop or Signal iPad to your phone. All Signal communication on linked devices are private. Note: Your previous message history is not synchronized. Only new chats sent or re...
161
Dan Black @danwblack.bsky.social · 19/02/2025
Moscow itself will undoubtedly be tempted to employ these methods against Western participants in forthcoming Ukraine peace negotiations as well. Expect to see these tactics see wider play, and soon.
170
Dan Black @danwblack.bsky.social · 19/02/2025
Look no further than CISA guidance in the wake of Salt Typhoon for highly targeted individuals and senior officials to adopt encrypted messaging apps such as Signal to protect their mobile communications. The targeting incentives are clear as day. www.cisa.gov/resources-to...
cisa.gov
Mobile Communications Best Practice Guidance | CISA
170
Dan Black @danwblack.bsky.social · 19/02/2025
That said, we anticipate the tactics and methods used to target Signal are at risk for rapid proliferation outside of Ukraine. Signal’s widespread adoption among at-risk communities for surveillance and espionage makes it a high-value target for a range of different adversaries.
191
Dan Black @danwblack.bsky.social · 19/02/2025
We judge this emerging operational interest has likely been sparked by wartime demands to gain access to sensitive government and military communications, and is part of Russia’s wider shift in focus to Ukraine’s frontlines as the war turned attritional. www.rusi.org/explore-our-...
rusi.org
Russia’s Cyber Campaign Shifts to Ukraine’s Frontlines
Russian intelligence services have now adapted their thinking about how to optimally integrate cyber and conventional capabilities.
181
Dan Black @danwblack.bsky.social · 19/02/2025
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
3165115
Dan Black @danwblack.bsky.social · 18/02/2025
Intelligence from the US and close allies shows that Putin still wants to control all of Ukraine, according to four Western intelligence officials and two US congressional officials. “We have zero intelligence that Putin is interested in a real peace deal right now" www.nbcnews.com/politics/nat...
nbcnews.com
As U.S. and Putin negotiate, intel shows he's not interested 'in a real peace deal,' sources say
Intelligence suggests Russian President Vladimir Putin is going through the motions and still thinks he can eventually control all of Ukraine, the sources told NBC News.
55717
Dan Black @danwblack.bsky.social · 18/02/2025
A deeply disturbing third bullet point there
9234
Dan Black @danwblack.bsky.social · 17/02/2025
"An offer of Nato membership conditional on a Russian ceasefire breach has been promoted by some US senators and now has the backing of senior European leaders, including Alexander Stubb, the Finnish president" www.theguardian.com/world/2025/f...
theguardian.com
Macron convenes European leaders for Ukraine summit amid tension with US
Paris meeting aims to devise action plan for Ukraine’s future as US and Russian delegates prepare to meet
2319
Dan Black @danwblack.bsky.social · 16/02/2025
Upcoming discussions in Riyadh will almost certainly upend a lot of immediate collection priorities across Europe. Ripple effects likely to be seen in the mobile threat landscape with long-term proliferation consequences.
0193