Sign in

Tom Padden

@tpad.bsky.social
113 followers 309 following 4 posts

Threat intelligence analyst. He/him

PostsRepliesMedia
Reposted by Tom Padden
PIVOTcon @pivotcon.bsky.social · 30/04/2026
Countdown is real ⌛️ Next week‼️ #ThreatResearch community gathers in Málaga 🇪🇸 Time to remind our PIVOTcon song: soundcloud.com/argonix/pivo... But watch out — it's a banger! #CTI #ThreatIntel #PIVOTcon26
media.tenor.com
a man in a white sweater is playing a keyboard with a vase of flowers in the background
ALT: a man in a white sweater is playing a keyboard with a vase of flowers in the background
098
Reposted by Tom Padden
State of Statecraft Conference @what-is-sos.bsky.social · 19/02/2026
SOS returns to Brussels on October 22, 2026! As the geopolitical landscape rifts, hybrid threats continue to adapt & evolve. We provide a forum for observers of state-aligned sabotage, espionage, and more to share research with an action-oriented community. Stay tuned for more announcements!
075
Reposted by Tom Padden
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 22/05/2025
New research from Insikt Group on a phishing campaign targeting Tajikistan attributed to TAG-110, a Russia-aligned threat actor, which overlaps with UAC-0063 and has been associated with APT28 (BlueDelta): www.recordedfuture.com/research/rus...
recordedfuture.com
TAG-110 Targets Tajikistan: New Macro Word Documents Phishing Tactics
Russia-aligned TAG-110 shifts to .dotm phishing lures in a 2025 campaign against Tajikistan’s public sector, advancing cyber-espionage in Central Asia.
052
Reposted by Tom Padden
Alexander Martin @alexmartin.bsky.social · 17/04/2025
011
Tom Padden @tpad.bsky.social · 17/04/2025
Slabhead
110
Reposted by Tom Padden
PIVOTcon @pivotcon.bsky.social · 07/03/2025
📣 Oops!... They did it again!!! 61 Talks submitted and so many too good that, once again, we had to increase a bit the number of accepted talks.🔥 #PIVOTcon25 Agenda is finally here, and the caliber is insane!!! Check it out➡️ pivotcon.org/agenda-2025/ #CTI #ThreatIntel Talks and presenters in🧵⬇️ 1/18
12014
Tom Padden @tpad.bsky.social · 06/03/2025
youtu.be
Heaven 17 - (We Don't Need This) Fascist Groove Thang
YouTube video by whynotandy
010
Reposted by Tom Padden
Dakota @dakotaindc.bsky.social · 03/03/2025
The number of companies providing vulnerabilities to China’s MSS has ballooned to 324, up from 151 in 2023! Most new companies are currently Tier 3. China’s ecosystem of vuln suppliers is frothy.
21711
Reposted by Tom Padden
Andy Greenberg @agreenberg.bsky.social · 12/02/2025
Microsoft finds a team within Sandworm has been carrying out widespread initial access operations on behalf of the GRU group and focused on US, UK, Canada and Australia networks over 2024, exploiting Connectwise ScreenConnect and Fortinet FortiClient EMS. www.wired.com/story/russia...
wired.com
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
26231
Reposted by Tom Padden
tlansec @tlansec.bsky.social · 09/01/2025
It's the most wonderful timeee of the year: cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
061
Reposted by Tom Padden
Bryan’s Gunn @bryansgunn.bsky.social · 30/11/2024
High octane stuff
571593288
Reposted by Tom Padden
StrikeReady Labs @strikereadylabs.com · 29/11/2024
What kind of actor would be interested in targeting eurozone gas storage, as well as Ukrainian electrical transmission infrastructure? strikeready.com/blog/ru-apt-...
strikeready.com
RU APT targeting Energy Infrastructure (Unknown unknowns, part 3)
Sandworm is considered one of the most advanced Russian APT groups, responsible for attacks on the Energy infrastructure of its neighbors. This blog will show a few techniques we use to track their p...
044
Reposted by Tom Padden
CYBERWARCON @cyberwarcon.bsky.social · 18/11/2024
🚨 Don’t miss Tom Padden at #CYBERWARCON as he unpacks edge device targeting via 0-day exploits. Learn how state-sponsored actors, especially from China, use covert 'ORB' networks to hide operations and target critical sectors. 🔗 www.cyberwarcon.com/registration
0101
Tom Padden @tpad.bsky.social · 19/11/2024
Bit going on with edge device exploitation at the moment labs.watchtowr.com/pots-and-pan...
labs.watchtowr.com
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
Note: Since this is 'breaking' news and more details are being released, we're updating this post as more details become available (and as we think of better memes). Mash that F5 key every so often fo...
032
Reposted by Tom Padden
David Oxley @oxley.io · 09/11/2024
I’ve created a Starter Pack around cyber threat intelligence to make it easier to find that community here on Bluesky. Let me know of folks I missed, as I’m sure there are many! go.bsky.app/TxQYHap
3218370
Reposted by Tom Padden
Volexity @volexity.com · 15/11/2024
@volexity.bsky.social has published a blog post detailing variants of LIGHTSPY & DEEPDATA malware discovered in the summer of 2024, including exploitation of a vulnerability in FortiClient to extract credentials from memory. Read more here: www.volexity.com/blog/2024/11...
volexity.com
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
In July 2024, Volexity identified exploitation of a zero-day credential disclosure vulnerability in Fortinet’s Windows VPN client that allowed credentials to be stolen from the memory of the client’s ...
03726
Reposted by Tom Padden
StrikeReady Labs @strikereadylabs.com · 14/11/2024
here's what today's russian apt phish campaign looked like, targeting ukraine tuyt8erti867i.synergize[.]co -> jkbfgkjdffghh.linkpc[.]net 44935484933a13fb6632e8db92229cf1c5777333fa5a3c0a374b37428add69fb
023
Tom Padden @tpad.bsky.social · 14/11/2024
blog.sekoia.io/a-three-beat...
blog.sekoia.io
A three beats waltz: The ecosystem behind Chinese state-sponsored cyber threats
Sekoia TDR analysts conduct an assessment of threats regarding the major elections that will occur in 2024.
010