Sign in

Saher

@saffronsec.bsky.social
208 followers 107 following 32 posts

Espionage Threat Research @ Proofpoint. Guest lecturer @warstudieskcl.bsky.social Former @virtualroutes.bsky.social fellow. She/her

PostsRepliesMedia
Reposted by Saher
Binding Hook @bindinghook.bsky.social · 29/09/2026
‘Despite widespread expectations of retaliation, Iranian cyber activity following the February strikes was consistent with Iran’s established peacetime playbook, rather than the predicted coordinated retaliatory wave.’ Read @saffronsec.bsky.social's latest: bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
041
Reposted by Saher
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/09/2026
“Restraint itself can be a signal.” Read more from the brilliant @saffronsec.bsky.social in @bindinghook.bsky.social on the relationship between cyber and kinetic conflict as observed in the Iran war
143
Reposted by Saher
Binding Hook @bindinghook.bsky.social · 25/09/2026
‘The doomsday predictions of wipers against US infrastructure at scale, hack-and-leak operations against defence and political targets, and coordinated destructive campaigns of the sort deployed in Ukraine never materialised.’ Read more @saffronsec.bsky.social: bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
043
Reposted by Saher
Horkos @wylienewmark.bsky.social · 25/09/2026
Absolutely mandatory reading. The single best analysis I’ve seen on Iranian CNA trends post-2/28, in terms of both accuracy and assessment.
2186
Reposted by Saher
Binding Hook @bindinghook.bsky.social · 24/09/2026
'The damage was likely negligible; the effect was psychological, not operational.’ Read more from @saffronsec.bsky.social on Iran’s wartime cyber operations: bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
074
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Saher @saffronsec.bsky.social · 23/09/2026
We're one month out from @what-is-sos.bsky.social in Brussels with a packed and stacked agenda on all things intel, espionage, sabotage, physical ops, and attribution - get your tickets asap!! www.stateofstatecraft.com/agenda
stateofstatecraft.com
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
033
Saher @saffronsec.bsky.social · 23/09/2026
Excited to share I'm presenting a last-minute talk @virusbtn.bsky.social! Come watch me hype @greg-l.bsky.social's research on Russia-aligned TA488's operational evolution, complete with half-click XSS exploits, zero-days, webmail stealers, & browser implants www.virusbulletin.com/conference/v...
092
Saher @saffronsec.bsky.social · 14/09/2026
Back by popular demand, it's time for Volume II of State of Statecraft @what-is-sos.bsky.social! Come check out the latest in state-sponsored operations across espionage, cyber/physical sabotage, disruption, attribution, and all the -INTs you could dream of - Oct 22 www.stateofstatecraft.com/agenda
stateofstatecraft.com
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
0125
Reposted by Saher
State of Statecraft Conference @what-is-sos.bsky.social · 11/09/2026
BEHOLD: the 🆘 AGENDA is OUT! VOLUME II features numerous discussions on developments in state-sponsored operations covering digital espionage, cyber/physical sabotage, economic tradecraft, disruption, attribution and dare we say, more? Agenda 👉 stateofstatecraft.com/agenda 🧵
143
Reposted by Saher
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026
New research from Proofpoint: BlueMoon, a Chrome-to-Windows exploit kit, has been used by at least four state-sponsored threat actors since late August. www.proofpoint.com/us/blog/thre...
proofpoint.com
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
164
Reposted by Saher
Mark Kelly @mkyo.bsky.social · 09/09/2026
🚨🌙 Today we are releasing a new @threatinsight blog on BlueMoon, an exploit kit that chained “patch-gap” Chrome zero-days with a Windows zero-day and had indicators of AI-assisted development. It was used by at least four espionage-motivated threat actors since late August.
175
Saher @saffronsec.bsky.social · 09/09/2026
Absolutely excellent work from @mkyo.bsky.social in discovery and investigation with help from TREE @greg-l.bsky.social @konstantinklinger.bsky.social and ope friends Julia/Dave/Stu in a huge @threatinsight.proofpoint.com cross-team collab!
0103
Saher @saffronsec.bsky.social · 09/09/2026
Exploits, zero-days, robots, oh my! New research from @threatinsight.proofpoint.com on multiple China-aligned actors using an exploit chain with Chrome (patch-gap) and Windows zero-days and indicators of AI-assisted development. Meet BlueMoon exploit kit: www.proofpoint.com/us/blog/thre...
proofpoint.com
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
185
Reposted by Saher
Raphael Satter @raphae.li · 29/07/2026
Looks like Void Blizzard — alleged to be the Russian cyber firm Yutek-NN — may also have been deploying an Outlook no-click (or half-click) zero day. Neat research here from @greg-l.bsky.social & the @proofpoint.com team:
073
Reposted by Saher
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22414
Saher @saffronsec.bsky.social · 29/07/2026
The excitement continues. @greg-l.bsky.social discovered Russia-aligned actor TA488 using another half-click exploit - this time in Outlook- leading to a new (very cool) browser-based implant, OWAReaper. Check out TA488 upping its game @threatinsight.proofpoint.com www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
072
Saher @saffronsec.bsky.social · 24/07/2026
@snlyngaas.bsky.social covers Proofpoint and NSA reporting on Russian actors' exploitation of Zimbra, Roundcube, and other mailservers, to target government, defense, and high science organizations for intelligence collection www.cnn.com/2026/07/23/p...
cnn.com
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | CNN Politics
A group of Russian hackers has spent the last year targeting nuclear scientists, defense contractors, and government employees in a cyber-espionage campaign, according to private-sector researchers an...
061
Saher @saffronsec.bsky.social · 24/07/2026
Read Reuters coverage from @raphae.li on Proofpoint and NSA's reporting of half-click exploits used by Russian actors to target Zimbra, Roundcube, and other mailservers to steal emails www.reuters.com/legal/govern...
reuters.com
US and allies say Russian hackers stole emails without social engineering
The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of ​the Zimbra email program without having to fool them into opening ‌an attachmen...
042
Reposted by Saher
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre...
265
Saher @saffronsec.bsky.social · 23/07/2026
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
proofpoint.com
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
21815
Saher @saffronsec.bsky.social · 09/07/2026
Thanks to @virtualroutes.bsky.social for hosting this fascinating and insightful workshop on commercial cyber proliferation! A revealing discussion with a walk through some of the darkest timelines
121
Reposted by Saher
Michael @matonis.bsky.social · 07/07/2026
ICYMI: the State of Statecraft conference (@what-is-sos) returns to Brussels for Volume II on October 22, 2026. Registration is open & the CFP runs until Aug. 14 SOS is an event focused on state-sponsored operations: stateofstatecraft.com 🧵👇
163
Saher @saffronsec.bsky.social · 07/07/2026
New research from @greg-l.bsky.social and @mkyo.bsky.social on a China-aligned actor exploiting n-day vulns in Roundcube to pop mailservers of North American universities. So reminder to protect & patch your mailserver, the edge device you forgot was an edge device www.proofpoint.com/us/blog/thre...
proofpoint.com
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. Key
097
Reposted by Saher
ThreatInsight @threatinsight.proofpoint.com · 07/07/2026
🚨 New research: Proofpoint has identified a suspected China-aligned espionage cluster, UNK_MassTraction, exploiting multiple Roundcube n-day vulnerabilities to compromise mail servers at U.S. and Canadian universities. Analysis, infection chain & IOCs: www.proofpoint.com/us/blog/thre....
UNK_MassTraction infection chain.
157
Saher @saffronsec.bsky.social · 01/07/2026
Thank you to @monicakello.bsky.social and @haguetix.bsky.social for an amazing Hague TIX conference - it’s always one of my favorites and I love coming back year after year!
051
Reposted by Saher
State of Statecraft Conference @what-is-sos.bsky.social · 18/06/2026
Registration and CFP for 🆘VOLUME II is officially OPEN! On October 22, 2026, we return to Brussels to showcase a day of community and discussions on the latest developments in state-sponsored operations and the actors & institutions that champion them.
2117
Reposted by Saher
ThreatInsight @threatinsight.proofpoint.com · 09/06/2026
🚨 New threat research: Proofpoint identified a likely North Korea-aligned threat cluster, UNK_DeadDrop, targeting software developers through trusted development platforms and workflows. Read the blog: www.proofpoint.com/us/blog/thre....
proofpoint.com
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor
168
Saher @saffronsec.bsky.social · 08/06/2026
New from @threatinsight.proofpoint.com! North Korean actor UNK_DeadDrop (possibly overlapping with Contagious Interview) conducts a high volume phishing campaign targeting developers with a new technique abusing VSIX extensions and new open source payload Overlord www.proofpoint.com/us/blog/thre...
proofpoint.com
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor
055
Saher @saffronsec.bsky.social · 05/11/2025
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...
proofpoint.com
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.  Key findings  Between June and August 2025,
21812
Saher @saffronsec.bsky.social · 28/07/2025
Check out the newest intel conference to discover the latest insights into all kinds of statecraft!
010
Saher @saffronsec.bsky.social · 17/07/2025
Bonus: great coverage of our research in an exclusive from one of my fave reporters @ajvicens.bsky.social www.reuters.com/sustainabili...
reuters.com
Exclusive: China-linked hackers target Taiwan's chip industry with increasing attacks, researchers say
Chinese-linked hackers are targeting the Taiwanese semiconductor industry and investment analysts as part of a string of cyber espionage campaigns, researchers said on Wednesday.
042
Saher @saffronsec.bsky.social · 17/07/2025
New from the one and only pun-king @mkyo.bsky.social on the increased and ongoing Chinese targeting of semiconductor-related organisations in Taiwan. Edge device exploitation may be the TTP of the moment, but Chinese groups still go phishing when the chips are down www.proofpoint.com/us/blog/thre...
proofpoint.com
Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting  | Proofpoint US
Key findings  Between March and June 2025, Proofpoint Threat Research observed three Chinese state-sponsored threat actors conduct targeted phishing campaigns against the Taiwanese
085
Saher @saffronsec.bsky.social · 01/07/2025
New DISCARDED podcast drop! Join @greg-l.bsky.social and me as we talk about our fave North Korean groups, DPRK as the neglected child, TA406 and the Russian connection, and finally, the dreaded but pervasive IT worker problem podcasts.apple.com/us/podcast/c... open.spotify.com/episode/01d1...
podcasts.apple.com
Comic Sans and Cybercrime: Inside North Korea’s Global Cyber Playbook
Podcast Episode · DISCARDED: Tales From the Threat Research Trenches · 07/01/2025 · 53m
184
Reposted by Saher
Greg Lesnewich @greg-l.bsky.social · 30/06/2025
Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals @selenalarson.bsky.social it’s got it all: 🛰️ Popped routers for sending phish 📊 ACH on attribution 👾 custom protocols 👽 cool malware 🕵️ crime 🎯 espionage ❔many unanswered questions www.proofpoint.com/us/blog/thre...
proofpoint.com
10 Things I Hate About Attribution: RomCom vs. TransferLoader | Proofpoint US
Threat Research would like to acknowledge and thank the Paranoids, Spur, and Pim Trouerbach for their collaboration to identify, track, and disrupt this activity.  Key takeaways
01712
Saher @saffronsec.bsky.social · 04/06/2025
From phishes to hands-on-keyboard commands 🔥 new @proofpoint.bsky.social research from @nickattfield.bsky.social and @konstantinklinger.bsky.social on Indian state-sponsored actor TA397 (Bitter) with a great story on the steps to technical and political attribution www.proofpoint.com/us/blog/thre...
proofpoint.com
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here.  Analyst note: Throughout
0102
Saher @saffronsec.bsky.social · 15/05/2025
Check out the new DISCARDED episode! Had too much fun recording my first podcast with @selenalarson.bsky.social and Sarah on my ClickFix crossover blog!! Podcast: podcasts.apple.com/us/podcast/d... Blog: www.proofpoint.com/us/blog/thre...
podcasts.apple.com
The ClickFix Convergence: How Threat Actors Blur the Lines
Podcast Episode · DISCARDED: Tales From the Threat Research Trenches · 05/14/2025 · 36m
182
Saher @saffronsec.bsky.social · 13/05/2025
@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...
proofpoint.com
TA406 Pivots to the Front | Proofpoint US
What happened  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these
11513
Saher @saffronsec.bsky.social · 18/04/2025
Thanks to my favorite team buddies for their collab and indulging my slight obsession 💜 @greg-l.bsky.social @mkyo.bsky.social and Josh
191
Reposted by Saher
Digital Monet @artaggi.bsky.social · 17/04/2025
You love to see it! Talented super friends beating up on the bad guys
031
Saher @saffronsec.bsky.social · 17/04/2025
My first blog with Proofpoint is live! And we love a good crossover. State-sponsored actors try their hand at ClickFix - the hottest thing in cybercrime. Meet the North Koreans, Iranians, and Russians who are upping their social engineering game www.proofpoint.com/us/blog/thre...
proofpoint.com
Around the World in 90 Days: State-Sponsored Actors Try ClickFix | Proofpoint US
Key Findings While primarily a technique affiliated with cybercriminal actors, Proofpoint researchers discovered state-sponsored actors in multiple campaigns using the ClickFix social
14219