Sign in

Arda Büyükkaya

@whichbufferarda.bsky.social
150 followers 340 following 43 posts

Cyber Threat Intelligence Analyst at Rabobank. (All opinions expressed here are mine only). #cybersecurity

PostsRepliesMedia
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 27/03/2026
-Russia to use custom crypto in 5G network -Orban government accused of using Candiru spyware -Coruna tied to Triangulation -Malware found on thousands of Luxembourg government phones -More advanced BPFdoor versions spotted Podcast: risky.biz/RBNEWS543/ Newsletter: news.risky.biz/risky-bullet...
1208
Reposted by Arda Büyükkaya
GreyNoise @greynoise.io · 10/02/2026
83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list. The IPs that are? VPN exits with zero Ivanti activity. We broke down who's actually doing this ⬇️ #Ivanti #ThreatIntel #CVE20261281 #InfoSec
greynoise.io
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
The GreyNoise Global Observation Grid observed active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, and 83% of that exploitation traces to a single IP address on bulletp...
063
Reposted by Arda Büyükkaya
Ollie Whitehouse @ollieatnowhere.bsky.social · 07/02/2026
Weekly summary is out.. ctoatncsc.substack.com/p/cto-at-ncs...
ctoatncsc.substack.com
CTO at NCSC Summary: week ending February 8th
Nation-state threat actors exploit end-of-support (EOS) edge devices -ncluding, but not limited to, load balancers, firewalls, routers, and virtual private network (VPN) gateways
033
Reposted by Arda Büyükkaya
The Shadowserver Foundation @shadowserver.bsky.social · 07/02/2026
We have started to report webshells (or other artifacts) found on Ivanti EPMM devices, likely compromised via CVE-2026-1281. 56 IPs found on 2026-02-06 Data in shadowserver.org/what-we-do/n... Tree Map view: dashboard.shadowserver.org/statistics/c... Thank you to the KSA NCA for the heads up!
2288
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 13/11/2025
This has been confirmed today: operation-endgame.com Europol took down servers for the Rhadamanthys infostealer, the VenomRAT, and the Elysium botnet
1276
Reposted by Arda Büyükkaya
FIRST.org @first.org · 12/11/2025
Que "The Final Countdown" by Europe 🎶 and lock in 💻-- it's time for final submissions for #FIRSTCTI26 #lastcall #timesup 🔗 go.first.org/EHUnv
go.first.org
FIRST — Forum of Incident Response and Security Teams
022
Arda Büyükkaya @whichbufferarda.bsky.social · 17/09/2025
🚨 New research: ShinyHunters teamed up with Scattered Spider for vishing attacks on cloud application users, bribed employees for insider access, and targeted engineering users to compromise CI/CD tools. blog.eclecticiq.com/shinyhunters... @likethecoins.bsky.social @campuscodi.risky.biz #CTI
blog.eclecticiq.com
ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications
EclecticIQ analysts assess with high confidence that ShinyHunters is expanding its operations by combining AI-enabled voice phishing, supply chain compromises, and leveraging malicious insiders.
024
Reposted by Arda Büyükkaya
Josh Junon @bad-at-computer.bsky.social · 08/09/2025
Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.
1518657
Reposted by Arda Büyükkaya
Zack Whittaker @zackwhittaker.com · 30/07/2025
New, by me: The hackers who breached Allianz Life earlier this month and stole the personal information belonging to the "majority" of its 1.4 million customers, also took Social Security numbers during the breach, per new filings with U.S. states.
techcrunch.com
Hackers stole Social Security numbers during Allianz Life cyberattack | TechCrunch
The U.S. insurance giant tells state regulators that Social Security numbers were among the personal information stolen in its mid-July cyberattack.
0165
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 31/07/2025
LOL... someone scrapped celebrity Spotify accounts/playlists and leaked their music preferences The *chef's kiss* here is the name of the site: Panama Playlists 😆 panamaplaylists.com
33211
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 22/07/2025
This is by far the coolest part in the UK's proposed ransomware ban and mandatory reporting proposal www.gov.uk/government/n...
Screenshot of text that reads: "Mandatory reporting is also being developed, which would equip law enforcement with essential intelligence to hunt down perpetrators and disrupt their activities, allowing for better support for victims. Consultation responses showed strong support for a new mandatory reporting regime to better protect British organisations and industry."
1101
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 09/07/2025
"This report presents the first detailed study of China’s cyber militia system since 2015. It draws from an analysis of 136 individual militia units, as well as authoritative Chinese-language military writings and mobilization documents." margin.re/mobilizing-c...
0178
Reposted by Arda Büyükkaya
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 05/06/2025
Ohhh…I smell a takedown coming! Via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
FBI: Play ransomware gang has attacked 600 organizations since 2023
Law enforcement officials said initial access brokers with ties to Play ransomware operators continue to exploit multiple vulnerabilities in remote monitoring and management tool SimpleHelp.
122
Reposted by Arda Büyükkaya
GreyNoise @greynoise.io · 20/05/2025
GreyNoise observed a major spike in scanning against Ivanti products weeks before two zero-days were disclosed in Ivanti EPMM. Full update: www.greynoise.io/blog/surge-i... #Ivanti #GreyNoise #Cybersecurity #ZeroDays
086
Reposted by Arda Büyükkaya
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 29/05/2025
Victoria’s Secret website down as company investigates security incident via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
Victoria’s Secret website down as company investigates security incident
The retailer's domain now features a brief message to customers explaining that it has “identified and are taking steps to address a security incident.”
112
Reposted by Arda Büyükkaya
Microsoft Threat Intelligence @threatintel.microsoft.com · 27/05/2025
Microsoft has discovered a cluster of worldwide cloud abuse activity by new Russia-affiliated threat actor Void Blizzard (LAUNDRY BEAR), whose cyberespionage activity targets gov't, defense, transportation, media, NGO, and healthcare in Europe and North America. msft.it/63324S9Jkp
msft.it
New Russia-affiliated actor Void Blizzard targets critical sectors for espionage | Microsoft Security Blog
Microsoft Threat Intelligence has discovered a cluster of worldwide cloud abuse activity conducted by a threat actor we track as Void Blizzard, who we assess with high confidence is Russia-affiliated and has been active since at least April 2024. Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to Russia, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America.
13223
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 27/05/2025
Dutch intelligence discover a new Russian APT—LAUNDRY BEAR www.aivd.nl/documenten/p... Microsoft calls it Void Blizzard. Their report is here: www.microsoft.com/en-us/securi...
12112
Reposted by Arda Büyükkaya
The Register @theregister.com · 14/05/2025
Ivanti patches two zero-days under active attack as intel agency warns customers
dlvr.it
Ivanti patches two zero-days under active attack as intel agency warns customers
Vendor says vulns are linked with 2 mystery open source libraries integrated into EPMM product Australia's intelligence agency is warning organizations about several new Ivanti zero-days chained for remote code execution (RCE) attacks. The vendor itself has said the vulns are linked to two mystery open source libraries which it declined to name.…
073
Reposted by Arda Büyükkaya
Cynthia Brumfield @metacurity.com · 22/05/2025
Never a dull day in cybersecurity. Check out today's Metacurity for the critical infosec developments you need to know. www.metacurity.com/russias-apt2...
metacurity.com
Russia's APT28 accused of infiltrating Western logistics, technology firms
Int'l partners destroy Lumma Stealer infrastructure, IT contractor breach led to M&S attack, Interlock stole data from West Lothian, 70K Coinbase customers exposed, EU sanctions GRU for disinformation...
084
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 22/05/2025
"A global law enforcement operation coordinated by Europol has struck a major blow to the criminal underground, with 270 arrests of dark web vendors and buyers across ten countries" www.europol.europa.eu/media-press/...
1113
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 22/05/2025
A Chinese APT (UNC5221) is behind recent attacks exploiting an Ivanti zero-day (CVE-2025-4427) This is a known Chinese APT group that seems to be specialized in Ivanti and other Western enterprise products... they have a long list of past zero-days in their name blog.eclecticiq.com/china-nexus-...
blog.eclecticiq.com
China-Nexus Threat Actor Actively Exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) Vulnerability
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier.
072
Arda Büyükkaya @whichbufferarda.bsky.social · 22/05/2025
cc @likethecoins.bsky.social
000
Arda Büyükkaya @whichbufferarda.bsky.social · 22/05/2025
🇨🇳 UNC5221 China-Nexus Threat Actor Actively Exploiting Ivanti EPMM (CVE-2025-4428).Targets critical networks like US airports and Telecommunications companies in EU. Exfiltrating sensitive data from managed mobile devices. #cyber Here is the full report: blog.eclecticiq.com/china-nexus-...
141
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 16/05/2025
-Ransomware IAB spreads trojanized KeePass installer -APT28 targets email servers with XSS attacks -Good report on DPRK cyber and IT worker schemes -Russia uses USAID shutdown in info-op targeting Moldova -RU disinfo group Storm-1516 is behind the Macron coke memes
161
Arda Büyükkaya @whichbufferarda.bsky.social · 16/05/2025
Storm-1516, a pro-Kremlin 🇷🇺 disinformation group, launched an AI-driven influence operation to discredit European leaders. 🇪🇺 blog.eclecticiq.com/storm-1516-d... @hatr.bsky.social
blog.eclecticiq.com
Storm-1516 Deploys AI-Generated Media to Spread Disinformation: Targets European Leaders and Influences Istanbul Peace Talks
EclecticIQ analysts assess with high confidence that on May 11, 2025, pro-Kremlin disinformation group Storm-1516 amplified a fabricated story on X, falsely claiming European leaders used drugs while ...
010
Arda Büyükkaya @whichbufferarda.bsky.social · 02/05/2025
🎉 Happy to share that my talk has been accepted at Virus Bulletin! I’ll be presenting in 🇩🇪 Berlin on Friday, September 26 at VB2025: Details: www.virusbulletin.com/conference/v... See you there! #vbconference #VB2025
052
Reposted by Arda Büyükkaya
David DiMolfetta @ddimolfetta.bsky.social · 01/05/2025
The FBI is awaiting signals from telecom victims that Salt Typhoon is fully excised from their systems. My Q&A with Deputy Assistant Director for Cyber Operations Brett Leatherman about Salt Typhoon and other topics at #RSAC2025 below: www.nextgov.com/cybersecurit...
nextgov.com
FBI awaits signal that Salt Typhoon is fully excised from telecom firms, official says
FBI Deputy Director for Cyber Operations Brett Leatherman said that "there’s a lot of work focused on containment" when it comes to the Salt Typhoon hacks.
052
Arda Büyükkaya @whichbufferarda.bsky.social · 01/05/2025
Microsoft Teams appears to have been used as part of the cyber kill chain in the Co-Op hack. I've recently seen similar tactics, where threat actors employed voice phishing via Teams calls. It’s a threat worth watching.
000
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 30/04/2025
Podcast: risky.biz/RBNEWS418/ Newsletter: news.risky.biz/risky-bullet... -French government grows a spine and calls out Russia's hacks -Marks & Spencer sends staff home after ransomware attack -China accuses US of hacking cryptography provider -AirBorne vulnerabilities impact Apple's AirPlay
1296
Reposted by Arda Büyükkaya
Cynthia Brumfield @metacurity.com · 30/04/2025
As RSA 2025 gets into full swing, stay ahead of the curve by checking out today's Metacurity for the most critical infosec developments you should know. www.metacurity.com/france-accus...
metacurity.com
France accuses Russia's APT28 of a string of serious cyberattacks going back to 2021
Kristi Noem urges "back-to-basics" for CISA, WhatsApp to roll out private processing for new AI features, Indian court blocks Proton Mail, Nova Scotia Power copes with a cyber breach, Israeli hacker-f...
031
Arda Büyükkaya @whichbufferarda.bsky.social · 25/04/2025
🚨 Erlang SSH RCE (CVE-2025-32433) is a significant supply chain risks to ICS and OT devices, particularly critical networking equipment like routers, switches, and smart sensors. The public availability of a POC makes this vulnerability especially concerning, as it is straightforward to exploit.
011
Arda Büyükkaya @whichbufferarda.bsky.social · 23/04/2025
Since April 15, 2025, BreachForums 2 was offline. Admin “Normal” confirmed its return at breached[.]fi, with no prior data restored. The new site faces skepticism, with some calling it a potential honeypot, likely pushing threat actors toward other platforms.
033
Arda Büyükkaya @whichbufferarda.bsky.social · 23/04/2025
BreachForums has reportedly resumed operations under a new domain, breached[.]fi
010
Arda Büyükkaya @whichbufferarda.bsky.social · 23/04/2025
Sri Lanka’s Foreign Ministry hit by phishing email posing as peacekeeper notice sent from Pakistan’s Naval Uni (likely breached) “pro-rector.admin@bahria.edu.pk.” Malicious link led to fake Gmail login via Railway-hosted page "gs23-production.up.railway[.]app", stealing user credentials and OTPs.
000
Arda Büyükkaya @whichbufferarda.bsky.social · 18/04/2025
Telephone-oriented attack delivery (TOAD) should be part of your threat model. We're seeing a rise in phishing where real human voices trick IT admins or helpdesks. Threat actors even run affiliate programs, paying people to guide victims into RMM installs or password reset.
054
Reposted by Arda Büyükkaya
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 12/04/2025
I’m speaking up in support of @thekrebscycle.bsky.social & @sentinelone.com Cybersecurity should be a non-partisan issue that unites us in our shared mission to defend our country. National security can’t afford the chilling effect on both public & private sector www.lutasecurity.com/post/in-supp...
lutasecurity.com
In Support of Chris Krebs and SentinelOne
Chris Krebs and his current employer are under investigation. If the infosec community unites to speak up for our friends and colleagues and leaves politics out of it, we can help strengthen our share...
530298
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 13/04/2025
Rakesh Krishnan has published an in-depth report on the evolution of the HelloKitty ransomware, analyzing samples going as far back as the group's inception back in 2020. The group doesn't have a leak site active, but new samples are still in the wild. theravenfile.com/2025/04/10/h...
theravenfile.com
HELLOKITTY RANSOMWARE — RESURFACED?
NOTE: This is a year-long Research project in which I have spent a lot of time spotting and analyzing various samples of HelloKitty Ransomware since its inception.You will get a 360-View on HelloKi…
071
Arda Büyükkaya @whichbufferarda.bsky.social · 13/04/2025
Ransomware brands come and go, but affiliates stay active, favoring repeatable/high-ROI tradecrafts. Many work with multiple RaaS crews at once. Their playbooks aren’t static, affiliates adapt to tech shifts like cloud adoption. Focus on affiliate behavior and hunt the tradecraft. #Ransomware
021
Reposted by Arda Büyükkaya
David DiMolfetta @ddimolfetta.bsky.social · 05/04/2025
Confirming other reports: CISA is expected to initiate efforts to significantly reduce its workforce in the coming days, including vast cuts to its industry contracting teams, according to four people familiar with the moves. w/ @notamazonalexa.bsky.social www.nextgov.com/people/2025/...
nextgov.com
CISA to make comprehensive staff cuts in coming days, people familiar say
The nation’s premier cybersecurity agency, which sits in the Department of Homeland Security, has been in the Trump administration’s crosshairs for some time.
074
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 25/03/2025
Cloudflare has open-sourced OPKSSH (OpenPubkey SSH), a tool to support single sign-on (SSO) for SSH blog.cloudflare.com/open-sourcin...
blog.cloudflare.com
Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH
OPKSSH (OpenPubkey SSH) is now open-sourced as part of the OpenPubkey project. This enables users and organizations to configure SSH to work with single sign-on technologies like OpenID Connect, remov...
0278
Arda Büyükkaya @whichbufferarda.bsky.social · 25/03/2025
Thank you very much :) ❤️
010
Reposted by Arda Büyükkaya
fwd:cloudsec @fwdcloudsec.org · 24/03/2025
We’re thrilled to announce that the second edition of fwd:cloudsec Europe will take place on September 15-16 in Berlin! fwdcloudsec.org/conference/e...
fwdcloudsec.org
fwd:cloudsec Europe 2024 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
276
Reposted by Arda Büyükkaya
Virus Bulletin @virusbtn.bsky.social · 12/02/2025
EclecticIQ's Arda Büyükkaya looks into an espionage campaign by Sandworm (APT44, UAC-0145) against Ukrainian Windows users, likely ongoing since late 2023. Pirated Microsoft KMS activators & fake Windows updates are leveraged to deliver a new version of BACKORDER. blog.eclecticiq.com/sandworm-apt...
021
Reposted by Arda Büyükkaya
Catalin Cimpanu @campuscodi.risky.biz · 23/03/2025
The Cloak ransomware gang has taken credit for breaching the Virginia Attorney General's Office last week www.securityweek.com/ransomware-g...
042
Arda Büyükkaya @whichbufferarda.bsky.social · 20/03/2025
🚨Only 5 days left! Don't miss our FREE webinar on how Sandworm (APT44) is targeting the critical infrastructure. - Actionable intelligence on nation-state tactics Register now! 👉 hubs.ly/Q03b4ZTG0 #Cybersecurity #ThreatIntel #Cyber #Webinar
hubs.ly
Sandworm’s Cyber Espionage: Russia’s GRU-Linked APT Uses Pirated Software in Ukraine
Are your security defenses ready to counter the latest nation-state attack techniques? Since late 2023, Russia's elite Sandworm (APT44) team has been executing a sophisticated cyber espionage campaig...
100
Arda Büyükkaya @whichbufferarda.bsky.social · 15/03/2025
Thank you very much for sharing 🥳
010
Reposted by Arda Büyükkaya
Happygeek @happygeek.bsky.social · 15/03/2025
Afternoon, my fellow Saturday cyber-sloggers. By me @forbes.com: Automated brute-force VPN and firewall ransomware attack framework revealed. #kudos @whichbufferarda.bsky.social #infosec www.forbes.com/sites/daveyw...
forbes.com
Now Ransomware Attackers Can Brute Force Your VPNs And Firewalls
Hackers now have the tools to automate brute force attacks of your VPNs and firewalls during ransomware campaigns.
143
Arda Büyükkaya @whichbufferarda.bsky.social · 13/03/2025
CC @campuscodi.risky.biz
000
Arda Büyükkaya @whichbufferarda.bsky.social · 13/03/2025
🚨 Leaked Black Basta chat logs have helped EclecticIQ analysts uncover BRUTED, a previously undocumented automated brute-forcing framework used to compromise Edge Network devices. blog.eclecticiq.com/inside-brute... #CyberSecurity @likethecoins.bsky.social @GossiTheDog.cyberplace.social.ap.brid.gy
blog.eclecticiq.com
Inside BRUTED: Black Basta (RaaS) Members Used Automated Brute Forcing Framework to Target Edge Network Devices
Arda Buyukkaya reveals how the Black Basta Ransomware-as-a-Service (RaaS) group used an automated brute forcing framework to target edge network devices of its victims.
110