Sign in

Daniel Gordon

@validhorizon.bsky.social
3.4K followers 218 following 874 posts

Thought Trailer, Cyber Threat Intel, DFIR. He/Him. Bucketing, sharing, and bacon-saving as a service. validhorizon.medium.com

PostsRepliesMedia
Daniel Gordon @validhorizon.bsky.social · 9h
blog.talosintelligence.com/china-nexus-...
blog.talosintelligence.com
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a pre...
020
Daniel Gordon @validhorizon.bsky.social · 11h
Wild that the Citrix trainwreck pushed the Kiteworks trainwreck to page 4 lol
010
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 12h
-Sanctions impact TLS certs in Iran, Russia -ShinyHunters member arrested in the Netherlands -Apple fixes iOS zero-day found by Meta -Citrix zero-days see mass exploitation within hours -Hackers exploit security product in Bitget hack P: risky.biz/RBNEWS617/ N: news.risky.biz/risky-bullet...
2103
Daniel Gordon @validhorizon.bsky.social · 28/09/2026
While this particular situation was a total comm’s clusterfuck, publishing things publicly often helps the adversary as much as it helps defenders. The fact you broke TLP suggests you don’t understand why people restrict info but more importantly will hurt your org long term.
440
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Reposted by Daniel Gordon
Zack Whittaker @zackwhittaker.com · 25/09/2026
New: Kiteworks (formerly Accellion) is urging customers to shut down their servers amid a threat of "imminent" cyberattack as soon as this weekend. An email to customers warns of a possible zero-day bug. Kiteworks' CISO confirms email alert. Ad-block bypass: web.archive.org/web/20260925...
techcrunch.com
Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack | TechCrunch
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.
21610
Reposted by Daniel Gordon
lazarusholic @lazarusholic.bsky.social · 25/09/2026
"Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026" published by Elliptic. #Bitget www.elliptic.co/insights/bitget-att…
elliptic.co
Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026
011
Reposted by Daniel Gordon
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Daniel Gordon @validhorizon.bsky.social · 24/09/2026
There have been a lot of blogs about North Korean IT workers but never one like this before. Absolutely mind blowing access spun into a great story. haydenmckenzie.com/research/dpr...
haydenmckenzie.com
The Women Behind North Korea's IT Worker Operations - Hayden McKenzie
An exclusive interview with a first-time female operative, and a day-by-day record of her first three weeks inside a North Korean IT worker cell. Her training, her assignments, and the American front ...
043
Daniel Gordon @validhorizon.bsky.social · 23/09/2026
I brought Varys into this investigation and she might be the most amazing web injects hunter I have ever crossed paths with. Just amazing work. medium.com/@ping.from.d...
medium.com
One inject, fifty shops: how we hunted a Magecart-style VM kit by its packer, not its C2
Varys — info@b4c2.net
053
Reposted by Daniel Gordon
Saher @saffronsec.bsky.social · 23/09/2026
Excited to share I'm presenting a last-minute talk @virusbtn.bsky.social! Come watch me hype @greg-l.bsky.social's research on Russia-aligned TA488's operational evolution, complete with half-click XSS exploits, zero-days, webmail stealers, & browser implants www.virusbulletin.com/conference/v...
092
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 23/09/2026
-A network of 10,000 AI servers masks Chinese malicious activity -Ukrainian hackers leak Russia's naval secrets -ShinyHunters hack the FBI -Tech firms disrupt EvilTokens PhaaS -BigCommerce notifies merchants of security breach P: risky.biz/RBNEWS614/ N: news.risky.biz/risky-bullet...
2297
Reposted by Daniel Gordon
Greg @jamyang.net · 22/09/2026
Team Cymru says it found 10,000+ “transfer stations” masking Chinese access to Western frontier #AI models, bypassing regional blocks, & potentially enabling #distillation. Striking look at China's shadow AI infrastructure. teamcymru-01.webflow.io/post/llm-gat...
teamcymru-01.webflow.io
LLM Gateways: How They Enable Frontier Model Abuse
Team Cymru uncovered 10,800+ self-hosted LLM gateways relaying pooled credentials to frontier models like Claude, enabling model distillation and abuse.
1108
Daniel Gordon @validhorizon.bsky.social · 22/09/2026
The AI future is here (derogatory) gambit.security/blog-posts/a...
gambit.security
AI Agents Are Hacking Online Retailers for $25 a Company
Gambit Threat Intelligence reconstructed an ongoing campaign in which open source AI agents compromised online retailers for about $25 each.
101
Reposted by Daniel Gordon
Volexity @volexity.com · 21/09/2026
Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.
volexity.com
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2...
154
Reposted by Daniel Gordon
Colin @colin-fraser.net · 21/09/2026
Alright. Let me resolve this once and for all. The simple fact is that there are a few different things that can be reasonably meant by “thinking” and mixing them up is what’s making everyone mad.
3359
Reposted by Daniel Gordon
Kate Starbird @katestarbird.bsky.social · 21/09/2026
The infrastructure for addressing informational attacks on election administration isn’t what it once was, but there are still great orgs out there fighting the good fight, including VoteBeat, Protect Democracy, and our Election Rumor Research team at UW: uwcip.substack.com/p/our-electi...
uwcip.substack.com
Our election rumor research work is ramping up for the 2026 U.S. midterms
Subscribe to our Election Rumor Rundowns, get in touch, and collaborate
0309
Daniel Gordon @validhorizon.bsky.social · 21/09/2026
Glad to see Atlassian piling on to this threat actor. www.atlassian.com/blog/how-we-...
atlassian.com
From fake interviews to malicious repositories: Disrupting Contagious Interview - Inside Atlassian
Software developers and IT professionals are increasingly being targeted through fraudulent recruitment processes that exploit their trust in established development platforms. Candidates are invited ...
000
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 20/09/2026
The Rust team warns of a social engineering campaign targeting core members and owners of popular packages blog.rust-lang.org/2026/09/17/t...
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
1147
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 19/09/2026
The UN says North Korea has an overseas labor force estimated at around 100,000, with most based in China and Russia It generated between $450m and $800m for the regime, with its "remote IT workers" allegedly accounting for the "majority of these funds" msmt.info/Publications...
msmt.info
MSMT App
Multilateral Sanctions Monitoring Team
1114
Reposted by Daniel Gordon
Eli D @eli.pizza · 19/09/2026
Also a lot of hacking is boring and repetitive. LLMs are pretty good at automating stuff that requires flexibility and fuzzy logic.
071
Reposted by Daniel Gordon
Pwnallthethings @pwnallthethings.bsky.social · 19/09/2026
This is a good question, and the answer which is honestly a little bit disturbing is the reason why LLMs are good at hacking is mostly *not* because there is hacking data in the pretrain, but because there is so much code generally in the pretrain bsky.app/profile/josh...
1326328
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
This is a great analogy: current AI is completely revolutionary, there is a shocking amount of reckless incompetence and greed, the core product has some fundamental problems, and energy issues may wreck a lot of things.
031
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
This is a mental health/stress framework for cybersecurity. I’ve always kinda poopoo’d this because my job is so cushy compared to folks I know in first responder fields but there are a LOT of lessons for infosec folks here, especially those working CSAM cases. github.com/SoShinySoChr...
github.com
GitHub - SoShinySoChrome/human-incident-response-framework: A practitioner wellbeing framework for cybersecurity operations. Four injuries, four zones, and what to do about them.
A practitioner wellbeing framework for cybersecurity operations. Four injuries, four zones, and what to do about them. - SoShinySoChrome/human-incident-response-framework
041
Reposted by Daniel Gordon
Protect Democracy @protectdemocracy.org · 19/09/2026
Staying informed through trusted, nonpartisan sources is one of the most effective ways to combat election disinfo. For reliable, election-specific coverage, two nonprofit newsrooms stand out - @votebeat.org and @boltsmag.org. Check out ways you can be part of the solution ⬇️ protdem.org/4yCiN88
An image with a banner titled "WHAT YOU CAN DO WEEK OF SEPT 14" at the top. Below, a phone displays a news app. The main section reads "Get election news you can trust." Additional text indicates "Time needed: Few minutes" and "Action type: Learn." A website is provided: "protdem.org/actions.
24018
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
God I hate this so much. This is extremely not TraderTraitor. And now everyone is going to call this TraderTraitor forever.
011
Reposted by Daniel Gordon
Kevin Collier @kevincollier.bsky.social · 17/09/2026
AI CEOs are in awe that their models can, given few constraints, hack autonomously. They're also wracked with a vague fear that their products will soon hack the entire internet. I reported on how it's very curious that they seem utterly disinterested in working with cybersecurity experts on this.
nbcnews.com
Cybersecurity experts say AI giants are shutting them out of safety plans
Cybersecurity experts told NBC News they were concerned that fundamental issues of cybersecurity weren’t being addressed.
1120576
Reposted by Daniel Gordon
ESET Research @esetresearch.bsky.social · 17/09/2026
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
177
Daniel Gordon @validhorizon.bsky.social · 16/09/2026
Significant chance this was made up but hooboy this would have made for a wild turn of events. timesofindia.indiatimes.com/india/xi-suf...
timesofindia.indiatimes.com
Xi suffered stroke & fainted at Brics Summit, claims China Democracy Party chief; post gets community note
Wanjun Xie, chairman of the China Democratic Party, has claimed in a post on X that Chinese president Xi Jinping fainted during the Brics summit hosted by New Delhi and was taken back to China on a sp...
000
Reposted by Daniel Gordon
Rowdy @r0wdy.sk33t.expert · 16/09/2026
Remember when people said “I used to think Elon Musk was smart until he started talking about something I had subject matter expertise in”?
55511
Reposted by Daniel Gordon
Dr. Sarah Parcak @indyfromspace.bsky.social · 16/09/2026
I tell my students you cultivate "luck" with hard work and showing up for people ceaselessly and doing good work and kind deeds and if you are not lucky with a break... well. You are living a meaningful life and doing good aren't you.
0385
Reposted by Daniel Gordon
BSides Pyongyang @bsidespyongyang.bsky.social · 15/09/2026
Seven days remain to submit to BSides Pyongyang 2026. Abstracts may be up to 250 words. Submit: bsidespyongyang.com/cfp/2026
001
Daniel Gordon @validhorizon.bsky.social · 14/09/2026
John Hultquist did bribe me with socks to say this but it is a great conference and I’m bummed to be missing it for the first time ever this year.
081
Reposted by Daniel Gordon
Timnit Gebru @timnitgebru.blacksky.app · 14/09/2026
The only person in public service who has consistently made 100% sense on issues of "AI," which is why they hate her so much.
Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products. We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books — a point 
@FTC
 emphasized repeatedly during my tenure.

1. There is an extensive set of laws that govern dangerous and defective products. For example, releasing unvetted AI models or agents can violate consumer protection laws. Shipping flawed AI tools without implementing adequate measures to detect and stop rogue or defective AI agents can be an “unfair or deceptive” act or practice under the FTC Act (and analogous state laws). And some state AGs are already exploring holding AI firms and their CEOs criminally liable when their models participate in criminal activity.

2. Existing laws also prohibit “unfair methods of competition.” This covers instances where AI firms appropriate the competitively sensitive information of their customers, including through tracking their use of various tools. It can also cover instances where firms pursue dangerous behavior, aware that doing so may compel rivals to do the same.As the Supreme Court has noted: “A method of competition which casts upon one's competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal, was thought to involve the kind of unfairness at which the [unfair methods of competition] statute was aimed."

3. The highly concentrated and interconnected structure of these markets could be creating major risks and conflicts of interest. We had started investigating these partnerships and cross-investments across the stack (and released a preliminarily overview of some findings: https://ftc.gov/news-events/news/press-releases/2025/01/ftc-issues-staff-report-ai-partnerships-investments-study). 

Both federal and state enforcers should be scrutinizing these opaque relationships and inter-dependencies. We are already seeing how these relationships could undermine accountability. For example, OpenAI could face liability given the Hugging Face incident, but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this — given Nvidia’s strong incentive to see OpenAI continue full speed ahead.4. As AI tools dramatically change the landscape of cybersecurity risks and hacks, all businesses should be doubling down on having core security protections in place. Firms that fail to invest in adequate data security measures or fix known vulnerabilities can also be breaking the law. A recent analysis showed that around 1/3 of Fortune 100 companies do not even have a way to notify them about security issues. During my 
@FTC
 tenure, we sued firms for poor data security practices and held CEOs liable when they were personally responsible.

https://this.weekinsecurity.com/dozens-of-americas-largest-companies-have-no-simple-way-to-report-security-flaws/

https://ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million

5. As policymakers consider new legal regimes, we should be looking to lessons from prior efforts to govern major sectors, such as banking and other networks, platforms, and utilities. Tools like structural separations, nondiscrimination, and supervision could be key, and there’s a rich history of what works and what doesn’t. But we can and must pursue any new efforts alongside enforcing existing laws.
192029659
Daniel Gordon @validhorizon.bsky.social · 13/09/2026
Eyal is exactly right. It has long been the case that threat actors would adopt the tools of pentesters. Now adversaries using LLMs are telling them that this is an authorized pentest and the LLM will often leave traces of that.
You can detect some AI-enabled attacks by searching for explicit indications of penetration testing. This happens because threat actors tell their LLMs they are performing authorized engagements even when using open weight models, or use pentesting harnesses like cyberstrikeAI, PentAGO, Hexstrike.
0116
Daniel Gordon @validhorizon.bsky.social · 12/09/2026
This is exactly right. Note that Matt is careful to say in the near term. There are some other ways that AIs can cause widespread harm and I’m going to touch on them in an upcoming talk but I completely agree about that this accurately represents the current lack of risk of “AIs escaping”
000
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 12/09/2026
Back in May, I wrote about an attack on RubyGems, that most people suspected to be DRPK: news.risky.biz/risky-bullet... It was not. It was a rogue OpenAI model: www.rubyhack.ai
32712
Reposted by Daniel Gordon
Alexis Rapin @alexis-rapin.bsky.social · 11/09/2026
Undersea cables are the definition of a strategic headache: super important, super hard to defend, super easy to damage. The logical response should be to aim for greater resilience. Well, guess what? There’s currently a grand total of 22 repair ships in service globally… 🫠
033
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 11/09/2026
-OpenAI agents activity found on 10 more sites -Surfshark reports breach -New surveillance vendor leak at CyberGlobes -Ransomware cripples German energy provider -Deep-Live-Cam supply chain attack -US police warn officers of Meta glasses -Discord brings back age verification
155
Daniel Gordon @validhorizon.bsky.social · 11/09/2026
Damn that’s a good lineup. Would love to make it to this conference one day.
330
Daniel Gordon @validhorizon.bsky.social · 11/09/2026
Whoops-daisy they enabled both APT29 and ShinyHunters. What a real goof? 🤷‍♂️ Thanks for posting but I would throw everything I have ever done in a wood chipper rather than help them, even inadvertently. www.anthropic.com/threat-intel...
anthropic.com
Countering misuse of AI: September 2026 / Anthropic
Case studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse.
000
Daniel Gordon @validhorizon.bsky.social · 10/09/2026
Just submitted. Catch ya’ll on the stream (assuming I get accepted lol)
121
Daniel Gordon @validhorizon.bsky.social · 10/09/2026
www.nattothoughts.com/p/widening-t...
nattothoughts.com
Widening the Circle of Chinese Hacker Group QTFY: ELEX's Intelligence Client List and Lexbell's PLA Contracts
A new US advisory ties the group to companies including ELEX, which openly listed state and public security clients for years, and Lexbell, whose leadership and contract wins reveal deep PLA ties
010
Reposted by Daniel Gordon
Volexity @volexity.com · 09/09/2026
Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).   #DFIR #threatintel
volexity.com
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta...
1126
Reposted by Daniel Gordon
Saher @saffronsec.bsky.social · 09/09/2026
Absolutely excellent work from @mkyo.bsky.social in discovery and investigation with help from TREE @greg-l.bsky.social @konstantinklinger.bsky.social and ope friends Julia/Dave/Stu in a huge @threatinsight.proofpoint.com cross-team collab!
0103
Daniel Gordon @validhorizon.bsky.social · 08/09/2026
Surprising absolutely nobody, I have a lot of thoughts on this lol
111
Reposted by Daniel Gordon
Joe Uchill @joeuchill.bsky.social · 07/09/2026
Hey, cyberpeople. Help a PhD student out. Did you recently write or supervise a vendor's research report or release research on a blog? Maybe you dropped a vuln at a conference? In general, did you do something that, if we were in any other industry, would be an academic paper? Let me know.
92626
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 06/09/2026
Last week, MikroTik users were complaining about new "ops" admin accounts on their routers: www.reddit.com/r/mikrotik/c... CERT-LV warned of attacks: cert.gov.lv/lv/2026/09/u... And CERT-PL later confirmed two zero-days: cert.pl/en/posts/202... Patches are out now: mikrotik.com/supportsec/s...
1135
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 03/09/2026
Another one... FalconFlank in CrowdStrike github.com/MSNightmare/...
0138
Reposted by Daniel Gordon
Never stop poasting @persistentpoasting.bsky.social · 02/09/2026
Realizing that article may be behind a paywall, and in danish. So I'm posting the state broadcasters live blog of the same thing. Still in danish, just use Google translate, it's fine.
dr.dk
PET afslører konkrete planer for russisk sabotage i Danmark
Ruslands operationer i Danmark har nået et nyt niveau, siger PET.
2264