Sign in

Joe Roosen

@jroosen.bsky.social
2.1K followers 537 following 88 posts

SpyCloud - Director of Security Research, Cryptolaemus Coordinator, Emotet(Ivan)/QBot(Boris) Destroyer, gold prospector & former sysadmin.

PostsRepliesMedia
Reposted by Joe Roosen
Joseph Cox @josephcox.bsky.social · 28/09/2026
New from 404 Media: the group that hacked the FBI and stole data on "all FBI employees" says it won't publish the data. The group gave the FBI a one week countdown. Now says won't publish at all. Still represents a massive national security/counterintelligence risk www.404media.co/fbi-hackers-...
404media.co
FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data
ShinyHunters, the group that stole data on “all FBI employees” including addresses and details on their spouses, told 404 Media on Monday “Since the very beginning we had made our decision that we wou...
79531
Reposted by Joe Roosen
InfoWars @realinfowars.bsky.social · 10/07/2026
EXCLUSIVE: Proof that Alex Jones may be a clone! youtu.be/y9MTEhAWVmw
youtu.be
Emergency with Tim Heidecker - FAKE ALEX JONES REVEALED
Welcome to episode two of Emergency with Tim Heidecker. This week, we examined the evidence that clearly proves the current Alex Jones is a clone with audio expert Stan Bennett, Tim opened up about the custody battle for his horse Horace, Phil from Aust...
428836
Reposted by Joe Roosen
warrior cop @wyattprivilege.bsky.social · 05/06/2026
Lmfao whoops
1466154
Reposted by Joe Roosen
Rav BOO!dram 🎃👻 @rvbdrm.com · 04/06/2026
Autonomous robot clown roundhouse kicks a small child
2452653734
Reposted by Joe Roosen
Molly White @molly.wiki · 21/04/2026
“Fraudulent messages promising safe passage through the Strait of Hormuz in exchange for cryptocurrency have been sent to some shipping companies... [A]t least one ​of the vessels, ⁠which tried to exit the strait on Saturday and was hit by gunfire, was a victim of the fraud.”
reuters.com
Scam messages offering ships safe transit through Hormuz, security firm warns
Fraudulent messages promising safe passage through the Strait of Hormuz in exchange for cryptocurrency have been sent to some shipping companies whose ​vessels are stranded west of the waterway, Greek...
929494
Reposted by Joe Roosen
AFP News Agency @en.afp.com · 12/03/2026
Iran warns it could wage a prolonged war with the US and Israel that would "destroy" the world economy, even as Trump says it is near defeat. Iranian strikes have brought shipping through the Strait of Hormuz almost to a halt, forcing governments to scramble to contain the fallout u.afp.com/SLwq
Smoke rises from the site of an Israeli airstrike in BeirutA screen displays a portrait of Iran's new supreme leader Mojtaba Khamenei during the funerals of Revolutionary Guard members at Enghelab Square in Tehran A building targeted by an Israeli airstrike in the Lebanese city of Tyre Smoke rises from the Thai bulk carrier 'Mayuree Naree' near the Strait of Hormuz after an attack
35623
Reposted by Joe Roosen
Fared Al Mahlool | فريد المحلول @faredalmahlool.bsky.social · 12/03/2026
Bahrain’s Ministry of Interior is reporting that “Iranian aggression” has targeted fuel tanks at a facility in the Muharraq Governorate.
13620
Reposted by Joe Roosen
Fared Al Mahlool | فريد المحلول @faredalmahlool.bsky.social · 12/03/2026
Multiple large fires are continuing to spread throughout Oman’s MINA Petroleum Facility at the Port of Salalah, following Wednesday’s drone strikes against the port and nearby infrastructure by Iran.
15330
Reposted by Joe Roosen
Ed Zitron @edzitron.com · 13/02/2026
Here’s this week’s Better Offline monologue. I walk you through why Matt Shumer’s “Something Big Is Coming” is deceptive misinformation peddled by a grifter, and why everybody who boosted or republished it should be ashamed of themselves. podcasts.apple.com/us/podcast/b... Linktr.ee/betteroffline
podcasts.apple.com
Monologue: No, Something Big Isn't Coming
Podcast Episode · Better Offline · 02/13/2026 · Bonus · 7m
1732650
Reposted by Joe Roosen
The Associated Press @apnews.com · 06/02/2026
Bitcoin's price continues its decline, dropping another 11% to $67,000. It has lost nearly half its value since hitting a record high in October.
bit.ly
Bitcoin price falls below pre-Trump second term levels, now hovering below $67,000
Bitcoin's price continues its decline, dropping another 11% to $67,000. It has lost nearly half its value since hitting a record high in October.
2014642
Reposted by Joe Roosen
CyberScoop @cyberscoop.bsky.social · 15/01/2026
The botnet took an unusual path by abusing residential proxy networks, allowing it to control an untapped collection of unofficial Android TV devices. cyberscoop.com/kimwolf-aisu...
cyberscoop.com
Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers
The botnet took an unusual path by abusing residential proxy networks, allowing it to control an untapped collection of unofficial Android TV devices.
032
Reposted by Joe Roosen
hakan @hatr.bsky.social · 15/01/2026
About a year ago we published a story on Black Basta and the alleged leader of the gang, called Oleg N. He managed to escape after being presented to a judge Today, LEA agencies announced having searched two homes of Black Basta operators in Ukraine. For Oleg, there's a "Wanted" poster
166
Reposted by Joe Roosen
Catalin Cimpanu @campuscodi.risky.biz · 15/01/2026
Lumen has sinkholed over 550 command and control servers for the Kimwolf botnet www.linkedin.com/pulse/keepin...
linkedin.com
Keeping the Kimwolf at bay: putting a leash on a massive DDoS Botnet.
With the fall of RapperBot in August 2025, Aisuru quickly regained its position as the world’s most powerful DDoS botnet. By September, Aisuru had achieved record-breaking attacks, flooding targets wi...
2188
Reposted by Joe Roosen
AFP News Agency @en.afp.com · 10/01/2026
🇬🇱 🇺🇸 "We don't want to be Americans," Greenland's political parties said late on Friday as US President Donald Trump again suggested using force to seize the mineral-rich Danish autonomous territory, raising concern worldwide ➡️ u.afp.com/SXWX
File photo shows a tourist looking at a statue of Hans Egede (1686-1758), a Dano-Norwegian Lutheran missionary, in Nuuk, Greenland, on March 9, 2025US President Donald Trump speaks during a meeting with US oil companies executives in the East Room of the White House in Washington, DC on January 9, 2026
13217
Reposted by Joe Roosen
AZ Intel @azintel.bsky.social · 09/01/2026
Explosion and fire at alleged illegal fuel tap in city of Villagrán in Guanajuato, Mexico. - ADN
1154
Reposted by Joe Roosen
AZ Intel @azintel.bsky.social · 04/01/2026
BREAKING: Death toll from U.S. airstrikes on Venezuela rises to 80, number could rise.- NYT
02213
Reposted by Joe Roosen
ChrisO_wiki @chriso-wiki.bsky.social · 04/01/2026
1/ Vladimir Putin's heavy investment in the regime of Venezuelan former President Nicolás Maduro has been a costly and disastrous failure, according to Russian commentators. They admit that Russia is too weak to stop its allies from being picked off one by one by the West. ⬇️
17443116
Reposted by Joe Roosen
Ira @ira.bailey.nz · 01/01/2026
Tis the season for data breaches, as Neighbourly.co.nz joins ManageMyHealth. It’ll probably mean a quick death or sale of Neighbourly as it was slowly dying already. 150GB is probably a full DB dump as it doesn’t include images. dailydarkweb.net/neighbourly-...
dailydarkweb.net
Neighbourly Data Breach: 150GB of User Data and Messages Put for Sale - Daily Dark Web
Neighbourly Data Breach: 150GB of User Data and Messages Put for Sale Discover the latest security threats and database leaks, including unauthorized VPN access and email breaches, in the cyber underg...
22417
Reposted by Joe Roosen
Electronic Frontier Foundation @eff.org · 01/01/2026
Data breaches affect everyone, and in 2025 we saw plenty of them, ranging from the novel to the predictable. www.eff.org/deeplinks/2...
eff.org
The Breachies 2025: The Worst, Weirdest, Most Impactful Data Breaches
Another year has come and gone, and with it, thousands of data breaches that affect millions of people. The question these days is less, Is my information in a data breach this year? and more How
04519
Reposted by Joe Roosen
Undercode Testing @undercode.bsky.social · 16/10/2025
The F5 BIG-IP Breach: Your Blueprint for Defense Against the Incoming Zero-Day Storm Introduction: The confirmed theft of F5 BIG-IP source code by a nation-state actor represents a critical inflection point for enterprise and federal network security. This breach provides threat actors with an…
undercodetesting.com
The F5 BIG-IP Breach: Your Blueprint for Defense Against the Incoming Zero-Day Storm
Introduction: The confirmed theft of F5 BIG-IP source code by a nation-state actor represents a critical inflection point for enterprise and federal network security. This breach provides threat actors with an unprecedented roadmap to engineer novel zero-day exploits, turning widely used network appliances into potential entry points for systemic compromise. The immediate mitigation directives from CISA underscore the severity of the situation, demanding urgent and decisive action from all organizations reliant on F5 infrastructure.
011
Reposted by Joe Roosen
Nariman Gharib @nariman.bsky.social · 13/08/2025
Tonight, Iran International TV exposed the identity of a Handala hacking group admin—part of the Banished Kitten cyber unit I've previously reported on—and unmasked his handler in Iran's Ministry of Intelligence. - Morteza Aftabi-Far - Ali Bermoudeh
1143
Reposted by Joe Roosen
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2025
Thanks to a scan conducted by @leakix.bsky.social, we have shared SharePoint IPs confirmed vulnerable to CVE-2025-53770, CVE-2025-53771. 424 SharePoint IPs found on 2025-07-23. One-off data in www.shadowserver.org/what-we-do/n... Tree map overview: dashboard.shadowserver.org/statistics/c...
143
Reposted by Joe Roosen
Ukrainska Pravda 🇺🇦 @pravda.ua · 11/07/2025
🤡 Russia and Belarus plan to create AI model based on "traditional values"
pravda.com.ua
Russia and Belarus plan to create AI model based on “traditional values”
Russia and Belarus intend to develop their own artificial intelligence model built on “traditional values” that would be “understandable” to citizens of both countries.
15469
Reposted by Joe Roosen
AZ Intel @azintel.bsky.social · 02/07/2025
BREAKING: Massive explosion at fireworks factory in Yolo County, California.
1901174339
Reposted by Joe Roosen
UNITED24 Media @united24media.com · 27/06/2025
Why do Russians insist Crimea belongs to them? The answer isn’t just about strategy or borders but a deeply ingrained national myth.
united24media.com
Why Does Russia Want Crimea So Badly? Cambridge Professor Rory Finnin Unpacks the “Crimea Is Ours” Mindset
Russia seized Crimea in 2014, sparking global outrage. Why does this peninsula matter so much, and why is its liberation the only viable solution?
27312
Reposted by Joe Roosen
Jakub Janovsky @rebel44cz.bsky.social · 27/06/2025
321814
Reposted by Joe Roosen
John Hultquist @hultquist.bsky.social · 27/06/2025
Mandiant is now aware of multiple incidents in the airline sector that resemble Scattered Spider. The industry should button up its call centers where this actor has had a lot of success with social engineering. www.axios.com/2025/06/27/a...
axios.com
A prolific hacking group that's shutdown retailers and insurance companies turns to aviation
A cyberattack on WestJet last week is likely tied to the Scattered Spider gang, a source tells Axios.
02214
Reposted by Joe Roosen
NOELREPORTS @noelreports.com · 27/06/2025
The General Staff of Ukraine reports: a strike by long-range drones destroyed two Russian Su-34 fighter-bombers at the Marinovka airbase in Russia’s Volgograd region. Two more were damaged.
135632
Reposted by Joe Roosen
NOELREPORTS @noelreports.com · 27/06/2025
The General Staff of Ukraine reports: a strike by long-range drones destroyed two Russian Su-34 fighter-bombers at the Marinovka airbase in Russia’s Volgograd region. Two more were damaged.
529718
Reposted by Joe Roosen
CyberInsider @cyberinsider.bsky.social · 25/06/2025
Police Arrest BreachForums Admins, Including ShinyHunters and IntelBroker
cyberinsider.com
Police Arrest BreachForums Admins, Including ShinyHunters and IntelBroker
French authorities have arrested five alleged administrators of BreachForums, including prominent figures like ShinyHunters and IntelBroker.
011
Reposted by Joe Roosen
Dark Web Informer @darkwebinformer.com · 25/06/2025
"ShinyHunters", "Hollow", "Noct" and "Depressed" have allegedly been arrested by the Brigade for the Fight against Cybercrime (BL2C) of the Paris police headquarters on Monday. IntelBroker was allegedly arrested by French law enforcement in February 2025. Source: www.leparisien.fr/high-tech/la...
leparisien.fr
La police interpelle cinq hackers français de haut vol, derrière un célèbre forum de vol de données
Les cybercriminels administraient BreachForums, le plus grand site de revente de données piratées, selon nos informations.
031
Reposted by Joe Roosen
BleepingComputer @bleepingcomputer.com · 25/06/2025
The French police have reportedly arrested five operators of the BreachForum cybercrime forum, a website used by cybercriminals to leak and sell stolen data that exposed the sensitive information of millions.
bleepingcomputer.com
BreachForums hacking forum operators reportedly arrested in France
The French police have reportedly arrested five operators of the BreachForum cybercrime forum, a website used by cybercriminals to leak and sell stolen data that exposed the sensitive information of millions.
0125
Reposted by Joe Roosen
BleepingComputer @bleepingcomputer.com · 25/06/2025
A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed "CitrixBleed 2," after its similarity to an older exploited flaw that allowed unauthenticated attackers to hijack authentication session cookies from vulnerable devices.
bleepingcomputer.com
New ‘CitrixBleed 2’ NetScaler flaw let hackers hijack sessions
A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed "CitrixBleed 2," after its similarity to an older exploited flaw that allowed unauthenticated attackers to hijack authentication session cookies from vulnerable devices.
062
Joe Roosen @jroosen.bsky.social · 20/06/2025
Hierarchy of Credential Data Tiers 1. Infostealer Log 2. Stealer Log DBs 3. ULPs/Combolists 2 & 3 are very close to each other in adjacency to the source but 2 is above your average combolist(3). If your creds show in 2 or 3 there is 95%+ chance there is a 1 for that cred too.
010
Joe Roosen @jroosen.bsky.social · 20/06/2025
As you may have already heard, 16 billion credentials were leaked for popular sites. The fine print is this has been happening for years and is a result of the rise of Infostealer malware. These 30 different DBs mentioned in the original article are personalized collections. 1/5
170
Reposted by Joe Roosen
Patrick C Miller @patrickcmiller.bsky.social · 20/06/2025
No, the 16 billion credentials leak is not a new data breach vapt.me/16B
buff.ly
No, the 16 billion credentials leak is not a new data breach
News broke today of a "mother of all breaches," sparking wide media coverage filled with warnings and fear-mongering. However, it appears to be a compilation of previously leaked credentials stolen…
0248
Reposted by Joe Roosen
The Associated Press @apnews.com · 16/06/2025
Flash flooding caused by torrential rains has killed five people in northern West Virginia and rescue crews are out searching for three other people who are missing.
bit.ly
Flash flooding kills 5 in West Virginia, rescue teams searching for missing people
Flash flooding caused by torrential rains has killed five people in northern West Virginia and rescue crews are out searching for three other people who are missing.
812132
Reposted by Joe Roosen
AZ Intel @azintel.bsky.social · 14/06/2025
TASS: "Iranian television channel Press TV reported new explosions in the city of Tabriz in the northwest of the country."
032
Reposted by Joe Roosen
AZ Intel @azintel.bsky.social · 14/06/2025
BREAKING: New photos shows the destruction from Iranian missile attack on Rishon Lezion, Israel; at least 2 dead, dozens injured.
044
Reposted by Joe Roosen
WarTranslated (Dmitri) @wartranslated.bsky.social · 14/06/2025
Reports say Jordan closed its airspace to allow Israeli Air Force to intercept incoming Iranian Shahed-136 kamikaze drones. Video shows an Israeli AH-64A/D Apache chasing the drones.
324112
Reposted by Joe Roosen
Alexander Martin @alexmartin.bsky.social · 09/06/2025
NHS England issued a call on Monday for 1 million people to give blood this week as stocks remain low following a cyberattack last year. Just 2% of the population “is keeping the nation’s blood stocks afloat” said Monday’s announcement, and “there is now a pressing need to avoid a Red Alert.”
therecord.media
NHS calls for 1 million blood donors as UK stocks remain low following cyberattack
A cyberattack on London hospitals last year led to the depletion of stocks of crucial O-type blood, and the U.K.'s National Health Service is calling for a nationwide effort to shore up supplies.
184
Reposted by Joe Roosen
InfoSec @infosec.skyfleet.blue · 09/06/2025
FakeCaptcha Infrastructure HelloTDS Infects Millions of Devices With Malware
cybersecuritynews.com
FakeCaptcha Infrastructure HelloTDS Infects Millions of Devices With Malware
0112
Reposted by Joe Roosen
MAKS 26 👀🇺🇦 @maks23.bsky.social · 01/06/2025
🕸️🃏 "Zelensky has no cards…" they said
393162892892
Reposted by Joe Roosen
Matthew Vinge @mvinge.bsky.social · 31/05/2025
Oh boy. Huge flare on earth-facing disk of sun few mins ago. Exactly where we want to see it! This is what can produce insane aurora we all hope to see. Reminiscent of the huge stuff in Oct!!! 😮🙃 We might be in for treat in 48-72 hrs 🌎 NASA needs cpl hrs to model forecast but looks promising 🤞
614320
Reposted by Joe Roosen
disc horse bot @horsedisc.bsky.social · 28/05/2025
0213
Reposted by Joe Roosen
Joe Warminsky @jwarminsky.bsky.social · 27/05/2025
For those who are still getting coffee: therecord.media/laundry-bear...
therecord.media
Dutch intelligence unmasks previously unknown Russian hacking group 'Laundry Bear'
Recent attacks on institutions in the Netherlands were the work of a previously unknown Russian hacking group that Dutch intelligence agencies are labeling Laundry Bear. Microsoft also reported on the...
042
Reposted by Joe Roosen
70s Sci-Fi Art @70sscifiart.bsky.social · 26/05/2025
Me, logging on to work after the long weekend
A 1980s or '90s ad featuring a businessman recoiling in horror at the sight of an envelope zipping around his office in a shower of electric sparks to land on his desk. The text below this image simply reads: "What the heck is Electronic Mail?"
134007870
Reposted by Joe Roosen
John Hammond @johnhammond.bsky.social · 27/05/2025
Exploring a backdoored Github repository abusing .suo deserialization, so just opening a Visual Studio solution file runs malware- then a PowerShell script pulls further payloads from social media... and we stumble onto the actor actively preparing more!👀 youtu.be/pw0xSFEnowk
1185