Sign in

Daniel Gordon

@validhorizon.bsky.social
3.4K followers 218 following 880 posts

Thought Trailer, Cyber Threat Intel, DFIR. He/Him. Bucketing, sharing, and bacon-saving as a service. validhorizon.medium.com

PostsRepliesMedia
Reposted by Daniel Gordon
Wesley Shields @wxs.bsky.social · 14h
MSFT updated their blog on the captive portal shenanigans: www.microsoft.com/en-us/securi... This stuff has been continuing for a while now, and the tooling is evolving too. No new indicators I see in there (or that we are sharing, so not throwing shade) but be on the look out for this stuff!
microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...
141
Daniel Gordon @validhorizon.bsky.social · 18h
As of now workaround still considered a Denial of Sevice vulnerability. I wouldn’t be surprised if it becomes RCE later but for now folks Gossi is mistaken. support.citrix.com/support-home...
support.citrix.com
Loading...
000
Reposted by Daniel Gordon
Kate Starbird @katestarbird.bsky.social · 03/10/2026
It's Oct 3. The midterms are a month away, but early voting has already begun in some states. Mail-in ballots will start circulating soon. Some of the usual suspects are already pushing the same "rigged election" rumors we've all heard before. This year, you can play along at home. bingo.cip.uw.edu
bingo.cip.uw.edu
"Rigged Election" Bingo
Spot the tropes before they spread. Recognize the common story elements behind election rumors — can you get BINGO?
817083
Daniel Gordon @validhorizon.bsky.social · 03/10/2026
I can see exploitation going back to 21 August (not on my network, fortunately).
110
Daniel Gordon @validhorizon.bsky.social · 03/10/2026
A Bag of Cats
000
Daniel Gordon @validhorizon.bsky.social · 02/10/2026
Citrix: “I guess something bad is happening, check your logs 🤷‍♂️” community.citrix.com/techzone-blo...
community.citrix.com
Security Update: Guidance for NetScaler SAML Authentication Deployments
NetScaler engineering and support teams are tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. This post explains what customers should review, h...
100
Daniel Gordon @validhorizon.bsky.social · 02/10/2026
Apparently there’s a bypass for the Citrix patch for the vulnerability trainwreck last weekend, so everyone look get excited for another trainwreck. cyberplace.social/@GossiTheDog...
cyberplace.social
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 2 images It looks like we may have #PitScaler 2 on our hands. I can see my patched honeypots, 13.1 and 14.1, are crashing. Multiple source IPs. grep -Ei 'proc nsaaad.*(SIGNALED|EXITED)|ma...
151
Daniel Gordon @validhorizon.bsky.social · 02/10/2026
💀💀💀💀💀💀💀💀
010
Reposted by Daniel Gordon
Steve Syfuhs @syfuhs.net · 02/10/2026
I suppose I should explain. Credential Manager, aka CredMan, aka cmdkey, is this thing.
Windows Credential Manager UI in the old Control Panel dialog.
59519
Reposted by Daniel Gordon
Bob Lord @boblord.bsky.social · 01/10/2026
Human error is inevitable. Secure-by-design systems are built to account for that. When a security failure is blamed on "human error" the real question is: why did the system make the unsafe choice easy and the safe choice hard?
2122
Reposted by Daniel Gordon
Mark Kelly @mkyo.bsky.social · 01/10/2026
🚨 New @threatinsight.proofpoint.com blog covering a 🇨🇳- aligned threat actor targeting US AI policy circles in spear phishing campaigns in recent months: www.proofpoint.com/us/blog/thre...
proofpoint.com
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint US
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial
2106
Daniel Gordon @validhorizon.bsky.social · 30/09/2026
[Frantically builds a data center]
110
Daniel Gordon @validhorizon.bsky.social · 30/09/2026
blog.talosintelligence.com/china-nexus-...
blog.talosintelligence.com
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a pre...
020
Daniel Gordon @validhorizon.bsky.social · 30/09/2026
Wild that the Citrix trainwreck pushed the Kiteworks trainwreck to page 4 lol
010
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 30/09/2026
-Sanctions impact TLS certs in Iran, Russia -ShinyHunters member arrested in the Netherlands -Apple fixes iOS zero-day found by Meta -Citrix zero-days see mass exploitation within hours -Hackers exploit security product in Bitget hack P: risky.biz/RBNEWS617/ N: news.risky.biz/risky-bullet...
2113
Daniel Gordon @validhorizon.bsky.social · 28/09/2026
How am I incorrect?
000
Daniel Gordon @validhorizon.bsky.social · 28/09/2026
How am I incorrect?
100
Daniel Gordon @validhorizon.bsky.social · 28/09/2026
In case anyone is curious about who broke TLP, lied about it, and then blocked me, it’s this guy.
110
Daniel Gordon @validhorizon.bsky.social · 28/09/2026
While this particular situation was a total comm’s clusterfuck, publishing things publicly often helps the adversary as much as it helps defenders. The fact you broke TLP suggests you don’t understand why people restrict info but more importantly will hurt your org long term.
440
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Reposted by Daniel Gordon
Zack Whittaker @zackwhittaker.com · 25/09/2026
New: Kiteworks (formerly Accellion) is urging customers to shut down their servers amid a threat of "imminent" cyberattack as soon as this weekend. An email to customers warns of a possible zero-day bug. Kiteworks' CISO confirms email alert. Ad-block bypass: web.archive.org/web/20260925...
techcrunch.com
Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack | TechCrunch
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.
21610
Reposted by Daniel Gordon
lazarusholic @lazarusholic.bsky.social · 25/09/2026
"Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026" published by Elliptic. #Bitget www.elliptic.co/insights/bitget-att…
elliptic.co
Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026
011
Daniel Gordon @validhorizon.bsky.social · 25/09/2026
I’m just waiting for URLscan to get acquired by private equity. I’m halfway tempted to try out FOFA just because I see so many adversaries using it.
340
Reposted by Daniel Gordon
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Daniel Gordon @validhorizon.bsky.social · 24/09/2026
There have been a lot of blogs about North Korean IT workers but never one like this before. Absolutely mind blowing access spun into a great story. haydenmckenzie.com/research/dpr...
haydenmckenzie.com
The Women Behind North Korea's IT Worker Operations - Hayden McKenzie
An exclusive interview with a first-time female operative, and a day-by-day record of her first three weeks inside a North Korean IT worker cell. Her training, her assignments, and the American front ...
043
Daniel Gordon @validhorizon.bsky.social · 23/09/2026
I brought Varys into this investigation and she might be the most amazing web injects hunter I have ever crossed paths with. Just amazing work. medium.com/@ping.from.d...
medium.com
One inject, fifty shops: how we hunted a Magecart-style VM kit by its packer, not its C2
Varys — info@b4c2.net
053
Reposted by Daniel Gordon
Saher @saffronsec.bsky.social · 23/09/2026
Excited to share I'm presenting a last-minute talk @virusbtn.bsky.social! Come watch me hype @greg-l.bsky.social's research on Russia-aligned TA488's operational evolution, complete with half-click XSS exploits, zero-days, webmail stealers, & browser implants www.virusbulletin.com/conference/v...
092
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 23/09/2026
-A network of 10,000 AI servers masks Chinese malicious activity -Ukrainian hackers leak Russia's naval secrets -ShinyHunters hack the FBI -Tech firms disrupt EvilTokens PhaaS -BigCommerce notifies merchants of security breach P: risky.biz/RBNEWS614/ N: news.risky.biz/risky-bullet...
2297
Daniel Gordon @validhorizon.bsky.social · 22/09/2026
Do you call them true positives? Something else?
100
Reposted by Daniel Gordon
Greg @jamyang.net · 22/09/2026
Team Cymru says it found 10,000+ “transfer stations” masking Chinese access to Western frontier #AI models, bypassing regional blocks, & potentially enabling #distillation. Striking look at China's shadow AI infrastructure. teamcymru-01.webflow.io/post/llm-gat...
teamcymru-01.webflow.io
LLM Gateways: How They Enable Frontier Model Abuse
Team Cymru uncovered 10,800+ self-hosted LLM gateways relaying pooled credentials to frontier models like Claude, enabling model distillation and abuse.
1108
Daniel Gordon @validhorizon.bsky.social · 22/09/2026
I’m glossing over some details but the hacker basically tasked an AI with “hack everything” and it did 🤦‍♂️
010
Daniel Gordon @validhorizon.bsky.social · 22/09/2026
The AI future is here (derogatory) gambit.security/blog-posts/a...
gambit.security
AI Agents Are Hacking Online Retailers for $25 a Company
Gambit Threat Intelligence reconstructed an ongoing campaign in which open source AI agents compromised online retailers for about $25 each.
101
Reposted by Daniel Gordon
Volexity @volexity.com · 21/09/2026
Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.
volexity.com
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2...
155
Daniel Gordon @validhorizon.bsky.social · 22/09/2026
TraderTraitor has very publicly targeted things outside of crypto since 2022 but also this research is not about TraderTraitor. This is a new DPRK threat actor that looks absolutely nothing like TraderTraitor. I am so tired.
010
Reposted by Daniel Gordon
Colin @colin-fraser.net · 21/09/2026
Alright. Let me resolve this once and for all. The simple fact is that there are a few different things that can be reasonably meant by “thinking” and mixing them up is what’s making everyone mad.
3359
Daniel Gordon @validhorizon.bsky.social · 22/09/2026
I mean it’s both lol
000
Reposted by Daniel Gordon
Kate Starbird @katestarbird.bsky.social · 21/09/2026
The infrastructure for addressing informational attacks on election administration isn’t what it once was, but there are still great orgs out there fighting the good fight, including VoteBeat, Protect Democracy, and our Election Rumor Research team at UW: uwcip.substack.com/p/our-electi...
uwcip.substack.com
Our election rumor research work is ramping up for the 2026 U.S. midterms
Subscribe to our Election Rumor Rundowns, get in touch, and collaborate
0309
Daniel Gordon @validhorizon.bsky.social · 21/09/2026
Glad to see Atlassian piling on to this threat actor. www.atlassian.com/blog/how-we-...
atlassian.com
From fake interviews to malicious repositories: Disrupting Contagious Interview - Inside Atlassian
Software developers and IT professionals are increasingly being targeted through fraudulent recruitment processes that exploit their trust in established development platforms. Candidates are invited ...
000
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 20/09/2026
The Rust team warns of a social engineering campaign targeting core members and owners of popular packages blog.rust-lang.org/2026/09/17/t...
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
1147
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
Honestly people underestimate how vulnerable everything is at any given moment. A lot of the hacking I see from AIs isnt sexy. It tends to be “realize that a public POC applies” or “recognize that a credential or service is exposed and important” or “notice that something is misconfigured”.
010
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
This does help what you describe does make AI better at vulnerability identification and exploitation but there are lots of other parts of hacking that don’t directly use those skills. Like the events here. www.livemint.com/technology/g...
livemint.com
Google’s Gemini breaks out of test environment to hack three external firms: Report | Mint
Google’s Gemini hacked three companies in the first known breakout, after the model accessed the internet and breached external systems during an evaluation of its cybersecurity capabilities.
100
Reposted by Daniel Gordon
Catalin Cimpanu @campuscodi.risky.biz · 19/09/2026
The UN says North Korea has an overseas labor force estimated at around 100,000, with most based in China and Russia It generated between $450m and $800m for the regime, with its "remote IT workers" allegedly accounting for the "majority of these funds" msmt.info/Publications...
msmt.info
MSMT App
Multilateral Sanctions Monitoring Team
1114
Reposted by Daniel Gordon
Eli D @eli.pizza · 19/09/2026
Also a lot of hacking is boring and repetitive. LLMs are pretty good at automating stuff that requires flexibility and fuzzy logic.
071
Reposted by Daniel Gordon
Pwnallthethings @pwnallthethings.bsky.social · 19/09/2026
This is a good question, and the answer which is honestly a little bit disturbing is the reason why LLMs are good at hacking is mostly *not* because there is hacking data in the pretrain, but because there is so much code generally in the pretrain bsky.app/profile/josh...
1327028
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
This is a great analogy: current AI is completely revolutionary, there is a shocking amount of reckless incompetence and greed, the core product has some fundamental problems, and energy issues may wreck a lot of things.
031
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
This is a mental health/stress framework for cybersecurity. I’ve always kinda poopoo’d this because my job is so cushy compared to folks I know in first responder fields but there are a LOT of lessons for infosec folks here, especially those working CSAM cases. github.com/SoShinySoChr...
github.com
GitHub - SoShinySoChrome/human-incident-response-framework: A practitioner wellbeing framework for cybersecurity operations. Four injuries, four zones, and what to do about them.
A practitioner wellbeing framework for cybersecurity operations. Four injuries, four zones, and what to do about them. - SoShinySoChrome/human-incident-response-framework
041
Reposted by Daniel Gordon
Protect Democracy @protectdemocracy.org · 19/09/2026
Staying informed through trusted, nonpartisan sources is one of the most effective ways to combat election disinfo. For reliable, election-specific coverage, two nonprofit newsrooms stand out - @votebeat.org and @boltsmag.org. Check out ways you can be part of the solution ⬇️ protdem.org/4yCiN88
An image with a banner titled "WHAT YOU CAN DO WEEK OF SEPT 14" at the top. Below, a phone displays a news app. The main section reads "Get election news you can trust." Additional text indicates "Time needed: Few minutes" and "Action type: Learn." A website is provided: "protdem.org/actions.
24018
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
God I hate this so much. This is extremely not TraderTraitor. And now everyone is going to call this TraderTraitor forever.
011
Reposted by Daniel Gordon
Kevin Collier @kevincollier.bsky.social · 17/09/2026
AI CEOs are in awe that their models can, given few constraints, hack autonomously. They're also wracked with a vague fear that their products will soon hack the entire internet. I reported on how it's very curious that they seem utterly disinterested in working with cybersecurity experts on this.
nbcnews.com
Cybersecurity experts say AI giants are shutting them out of safety plans
Cybersecurity experts told NBC News they were concerned that fundamental issues of cybersecurity weren’t being addressed.
1120576
Reposted by Daniel Gordon
ESET Research @esetresearch.bsky.social · 17/09/2026
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
177