Sign in

Jaeson Schultz

@jaesons.bsky.social
57 followers 230 following 24 posts
PostsRepliesMedia
Jaeson Schultz @jaesons.bsky.social · 20/11/2024
Malicious QR Codes: How big of a problem is it, really? blog.talosintelligence.com/malicious_qr...
blog.talosintelligence.com
Malicious QR Codes: How big of a problem is it, really?
QR codes are disproportionately effective at bypassing most anti-spam filters. Talos discovered two effective methods for defanging malicious QR codes, a necessary step to make them safe for consumpti...
020
Reposted by Jaeson Schultz
Richard @renuvian.bsky.social · 28/02/2024
In order to save democracy, Biden needs to threaten to assassinate all 6 conservatives on the Supreme Court as an official act of his presidency. It’s what FDR would have done.
0324
Jaeson Schultz @jaesons.bsky.social · 08/02/2024
McAfee products are so shitty they need to fake finding viruses on your computer to generate sales
000
Reposted by Jaeson Schultz
Brendel @brendelbored.bsky.social · 17/01/2024
Headline: Kentucky Republican introduces bill to legalize sex with first cousins: report and then I put in a picture of the guy who founded Shelbyville that was really horny for his cousins because they are so attractive
720218
Reposted by Jaeson Schultz
Ryan North @ryannorth.ca · 08/01/2024
This is a lie, and it's always been a lie. Something like ChatGPT needs a TON of text in the language you're targeting to train the model. You get it by licensing it, or you by paying people to write it for you, or by stealing it. What they're saying is it's impossible to create CHEAPLY.
492781964
Jaeson Schultz @jaesons.bsky.social · 04/12/2023
At Talos, we fight the good fight every day to protect others. Read an account of how Talos worked with several other Cisco teams to help the Ukrainian people, who are struggling to maintain civilization in an invaded country, and keep the lights on. blog.talosintelligence.com/project-powe...
blog.talosintelligence.com
Project PowerUp – Helping to keep the lights on in Ukraine in the face of electronic warfare
Project PowerUp is the story of how Cisco Talos worked with a multi-national, multi-company coalition of volunteers and experts to help “keep the lights on” in Ukraine, by injecting a measure of s...
010
Jaeson Schultz @jaesons.bsky.social · 30/11/2023
SugarGh0st RAT is a new customized variant of Gh0st RAT, an infamous trojan that’s been active for more than a decade blog.talosintelligence.com/new-sugargh0...
blog.talosintelligence.com
New SugarGh0st RAT targets Uzbekistan government and South Korea
Cisco Talos recently discovered a malicious campaign that likely started as early as August 2023, delivering a new remote access trojan (RAT) we dubbed “SugarGh0st.”
000
Jaeson Schultz @jaesons.bsky.social · 28/11/2023
Many organizations are curious about the idea of threat hunting, but what does this really entail? In this video, we try to address the many answers to the question, "What is threat hunting?" blog.talosintelligence.com/what-is-thre...
blog.talosintelligence.com
What is threat hunting?
Many organizations are curious about the idea of threat hunting, but what does this really entail? In this video, four experienced security professionals from across Cisco recently sat down to discus...
000
Jaeson Schultz @jaesons.bsky.social · 21/11/2023
Learn how a team of experts from Talos and others at Cisco are helping to protect #Ukraine's power grid with a line of specially crafted devices. www.cnn.com/2023/11/21/p...
cnn.com
Exclusive: This pizza box-sized equipment could be key to Ukraine keeping the lights on this winter ...
Staring down another frigid winter and desperate to keep the lights on, Ukraine’s power grid operator has surreptitiously imported custom-built equipment designed to withstand Russian electronic w...
011
Jaeson Schultz @jaesons.bsky.social · 31/10/2023
A threat actor known as #AridViper (likely operating out of #Gaza) has been targeting users in the #MiddleEast with #spyware disguised as dating apps, dating back to November 2022. blog.talosintelligence.com/arid-viper-m...
blog.talosintelligence.com
Arid Viper disguising mobile spyware as updates for non-malicious Android applications
Since April 2022, Cisco Talos has been tracking a malicious campaign operated by the espionage-motivated Arid Viper advanced persistent threat (APT) group targeting Arabic-speaking Android users.
011
Jaeson Schultz @jaesons.bsky.social · 24/10/2023
Attacks on web applications spike in third quarter, new Talos IR data shows blog.talosintelligence.com/talos-ir-tre...
blog.talosintelligence.com
Attacks on web applications spike in third quarter, new Talos IR data shows
We observed the BlackByte ransomware group’s new variant, BlackByte NT, for the first time in addition to the previously seen LockBit ransomware, which continues to be the top observed ransomware fa...
000
Jaeson Schultz @jaesons.bsky.social · 03/10/2023
"ShroudedSnooper" is actively targeting telecommunications companies in the Middle East using a previously undiscovered #malware family. More details on this threat and how users can stay protected. blog.talosintelligence.com/introducing-...
blog.talosintelligence.com
New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implants
Cisco Talos has discovered a new intrusion set we're calling "ShroudedSnooper" consisting of two new implants "HTTPSnoop" and "PipeSnoop" targeting telecommunications firms in the middle-east.
000
Jaeson Schultz @jaesons.bsky.social · 29/08/2023
Not all Top Level Domains are created equal. Some TLDs do some pretty strange things in DNS. blog.talosintelligence.com/whats-in-a-n...
blog.talosintelligence.com
What's in a name? Strange behaviors at top-level domains creates uncertainty in DNS
Google introduced the new “.zip” Top Level Domain (TLD) on May 3, 2023, igniting a firestorm of controversy as security organizations warned against the confusion that was certain to occur. When ...
042
Jaeson Schultz @jaesons.bsky.social · 24/08/2023
Lazarus Group is using a new remote access trojan called “CollectionRAT.” CollectionRAT appears to be connected to Jupiter/EarlyRAT, another malware family Kaspersky recently wrote about and attributed to Andariel, a subgroup within the Lazarus Group. blog.talosintelligence.com/lazarus-coll...
blog.talosintelligence.com
Lazarus Group's infrastructure reuse leads to discovery of new malware
Lazarus Group appears to be changing its tactics, increasingly relying on open-source tools and frameworks in the initial access phase of their attacks, as opposed to strictly employing them in the po...
000
Jaeson Schultz @jaesons.bsky.social · 24/08/2023
Cisco Talos discovered the North Korean state-sponsored actor Lazarus Group targeting internet backbone infrastructure and healthcare entities in Europe and the United States. blog.talosintelligence.com/lazarus-quit...
blog.talosintelligence.com
Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT
This is the third documented campaign attributed to this actor in less than a year, with the actor reusing the same infrastructure throughout these operations.
010
Jaeson Schultz @jaesons.bsky.social · 23/08/2023
On the latest Security Stories podcast, we cover how Cisco Talos Incident Response helped one healthcare customer avoid the worst with retainer services. www.cisco.com/c/en/us/prod...
000
Reposted by Jaeson Schultz
William Largent @securitywill.bsky.social · 22/08/2023
Holger wrote an amazing blog over on hexrays - digging in to generating signatures for Nim and other non-C programming languages.
hex-rays.com
Plugin focus: Generating signatures for Nim and other non-C programming languages – Hex Rays
001
Jaeson Schultz @jaesons.bsky.social · 15/08/2023
The rise of AI-powered criminals blog.talosintelligence.com/the-rise…
blog.talosintelligence.com
The rise of AI-powered criminals: Identifying threats and opportunities
A major area of impact of AI tools in cybercrime is the reduced need for human involvement in certain aspects of cybercriminal organizations.
000
Jaeson Schultz @jaesons.bsky.social · 08/08/2023
There have been multiple leaks of ransomware source code and builders, giving unsophisticated attackers the ability to easily generate their own ransomware with little effort or knowledge. blog.talosintelligence.com/code-lea…
blog.talosintelligence.com
Code leaks are causing an influx of new ransomware actors
Cisco Talos is seeing an increasing number of ransomware variants emerge, since 2021, leading to more frequent attacks and new challenges for cybersecurity professionals, particularly regarding actor...
000
Jaeson Schultz @jaesons.bsky.social · 03/08/2023
Between new ransomware groups, a growing mercenary space, espionage campaigns, supply chain attacks, and new “as a service” tools popping up, there's a lot to talk about already in the first half of 2023.
blog.talosintelligence.com
Half-Year in Review: Recapping the top threats and security trends so far in 2023
We've seen threat actors utilize every chance they get to steal sensitive data, to be used in future attacks and/or to manipulate victims into paying up before their data ends up on the dark web.
000
Jaeson Schultz @jaesons.bsky.social · 02/08/2023
The many vulnerabilities Talos discovered in SOHO and industrial wireless routers post-VPNFilter blog.talosintelligence.com/router-r…
blog.talosintelligence.com
The many vulnerabilities Talos discovered in SOHO and industrial wireless routers post-VPNFilter
Given the privileged position these devices occupy on the networks they serve, they are prime targets for attackers, so their security posture is of paramount importance.
010
Jaeson Schultz @jaesons.bsky.social · 31/07/2023
Data theft extortion rose as the threat Talos Incident Response saw the most last quarter. Want to learn more about what we're seeing in the wild, and what you can learn from it? Read our latest Quarterly Report. blog.talosintelligence.com/talos-ir…
blog.talosintelligence.com
Incident Response trends Q2 2023: Data theft extortion rises, while healthcare is still most-targete...
Ransomware was the second most-observed threat this quarter, accounting for 17 percent of engagements, a slight increase from last quarter’s 10 percent.
000
Jaeson Schultz @jaesons.bsky.social · 25/07/2023
As the internet starts to pivot away from passwords as a primary login method, what might future #phishing attacks look like? We address this future in our latest post blog.talosintelligence.com/what-mig…
010
Jaeson Schultz @jaesons.bsky.social · 12/07/2023
Cisco Talos recently saw threat actors exploiting a #Windows policy loophole that allows the signing and loading of cross-signed kernel-mode drivers with older signature timestamps. #Microsoft just released an advisory on this activity, but more on our blog here: cs.co/6011PzaVd
cs.co
Old certificate, new signature: Open-source tools forge signature timestamps on Windows drivers
Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates.
010
Jaeson Schultz @jaesons.bsky.social · 06/07/2023
#Spyware and the "mercenary" groups that make these tools aren't going anywhere. Here's what makes these groups so dangerous and what other steps the #cybersecurity community should still be taking. blog.talosintelligence.com/the-grow…
010
Jaeson Schultz @jaesons.bsky.social · 28/06/2023
Talos Threat Hunters are the front lines of #cybersecurity. They actively keep businesses, countries, and the whole internet safer. 💻🌎🔐 Discover how Talos identifies new and evolving threats in the wild, and how their intel helps organizations build strong defenses.
cisco.com
Cisco Talos—Threat Intelligence Research Team
Cisco Talos, a proven threat intelligence team of researchers, analysts, and incident responders, provides leading security research and response globally.
021
Jaeson Schultz @jaesons.bsky.social · 22/06/2023
Did you know Talos has 27 #opensource tools for anyone to use? These range from our world-class IPS #Snort, to free #ransomware decryptors. Learn more with this video blog.talosintelligence.com/how-talo…
blog.talosintelligence.com
Video: How Talos’ open-source tools can assist anyone looking to improve their security resilience
A rundown of Talos open-source software tools, which anyone in the security community can download for free, and use for research, skills, training, or integration into existing security infrastructur...
020