Sign in

x0rz

@x0rz.bsky.social
1.6K followers 211 following 25 posts

Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓

PostsRepliesMedia
x0rz @x0rz.bsky.social · 31/03/2026
Is your iPhone secure? Verifium is a free open-source iOS auditor. It runs local checks against renowned security and privacy guidelines. Zero data leaves your device: verifium.app
verifium.app
Verifium - iOS Security & Privacy Auditor
An open-source iOS privacy and security auditor based on industry-standard best practices.
1119
Reposted by x0rz
Catalin Cimpanu @campuscodi.risky.biz · 27/11/2025
"A Russian citizen suspected of hacking IT systems of Polish companies was arrested in Krakow, Polish Interior Minister Marcin Kierwinski said on Thursday." www.reuters.com/world/poland...
reuters.com
Poland arrests Russian suspected of hacking Polish companies
A Russian citizen suspected of hacking IT systems of Polish companies was arrested in Krakow, Polish Interior Minister Marcin Kierwinski said on Thursday.
0124
Reposted by x0rz
Reuters @reuters.com · 21/10/2025
AI assistants make widespread errors about the news, new research shows reut.rs/4qkIfvx
reut.rs
AI assistants make widespread errors about the news, new research shows
Leading AI assistants misrepresent news content in nearly half their responses, according to new research published on Wednesday by the European Broadcasting Union (EBU) and the BBC.
32257121
Reposted by x0rz
Joseph Menn @joemenn.bsky.social · 26/09/2025
Taiwan having to defend itself against both China AND Russia would be a tall order. www.washingtonpost.com/world/2025/0...
washingtonpost.com
Russia is helping prepare China to attack Taiwan, documents suggest
Russia is using its battlefield experience to give Chinese airborne units the training and technical knowhow to carry out lightning-fast operations.
178
Reposted by x0rz
Taggart @taggart-tech.com · 25/09/2025
Dubai chocolate is a psyop
152
Reposted by x0rz
Eugenio Benincasa @euben.bsky.social · 21/07/2025
1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).
1158
Reposted by x0rz
Kristian Kiehling @kristiankiehling.bsky.social · 20/06/2025
2/2 Russia at will. Although he claims to be apolitical, he denies responsibility for the crimes that are enabled by his platform. He loves to dish out advice to Western politicians, but hates paying taxes and prefers to live in a dictatorship. In short, he embodies the stereotypical Russian.
istories.media
Telegram, the FSB, and the Man in the Middle
The technical infrastructure that underpins Telegram is controlled by a man whose companies have collaborated with Russian intelligence services. An investigation by IStories
1187
Reposted by x0rz
Kim Zetter @kimzetter.bsky.social · 15/04/2025
Following long practice of US gov indicting Chinese/Russian state hackers for breaching US systems, China has named and issued warrants for 3 NSA workers it says were behind hacks of China systems during Asian Winter Games. Also says University of California and Virginia Tech participated in attacks
reuters.com
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents
Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) of launching "advanced" cyberattacks during the Asian Winter Games in February, targeting essential industries.
1198
Reposted by x0rz
Catalin Cimpanu @campuscodi.risky.biz · 27/03/2025
ESET disputes Microsoft's classification of the FamousSparrow APT as part of the Salt Typhoon group. ESET believes the two APTs may be using a shared digital quartermaster (malware and tools developer). www.welivesecurity.com/en/eset-rese...
welivesecurity.com
You will always remember this as the day you finally caught FamousSparrow
ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor.
165
Reposted by x0rz
Coach Finstock @coachfinstock.bsky.social · 21/03/2025
When the answer to "are you cheating on me?" is "who told you that?" and not "no"
642177390
x0rz @x0rz.bsky.social · 12/03/2025
@hpiedcoq.bsky.social 🇷🇺👀
120
Reposted by x0rz
Lisa Reyna Loe @lisaloe.bsky.social · 04/03/2025
Extraordinary comment from Tory MP Graham Stuart: “We have to consider the possibility that President Trump is a Russian asset. If so, Trump's acquisition is the crowning achievement of Putin's FSB career.” (Narrator: It’s extraordinary because our own gd government didn’t say it first.)
Tweet by Graham Stuart, Tory MP @grahamstuart:
We have to consider the possibility that President Trump is a Russian asset.
If so, Trump's acquisition is the crowning achievement of Putin's FSB career - and Europe is on its own.
1262642969
Reposted by x0rz
John Scott-Railton @jsrailton.bsky.social · 28/01/2025
It shouldn’t take a panic over Chinese AI to remind people that most companies in the business set the terms for how they use your private data. And when you use their AI apps, you’re doing work for them, not the other way round.
37419
Reposted by x0rz
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 28/01/2025
being able to walk away from the internet, even via laptops was nice
082
Reposted by x0rz
Katie Martin @katie0martin.ft.com · 25/01/2025
Ah yes. We're at the 'pUt It On ThE bLoCkChAiN' stage.
2729135
Reposted by x0rz
The Register @theregister.com · 14/01/2025
It's like Ivanti. Every month is zero-day awareness month.
021
x0rz @x0rz.bsky.social · 14/01/2025
I can never fully know if I already read this "Fortinet 0day in the wild" article 3 weeks ago or if it’s new. Ha, never mind! It’s new 🥲
2168
Reposted by x0rz
Sean Lyngaas @snlyngaas.bsky.social · 13/01/2025
LeMonde investigation finds that members of a French nuclear-armed submarine crew inadvertently shared sensitive information about the patrol schedule of the ship via the Strava workout app: www.lemonde.fr/videos/artic...
lemonde.fr
StravaLeaks : des dates de patrouilles des sous-marins nucléaires français dévoilées par l’imprudence de membres d’équipage
Des membres d’équipage des sous-marins français dotés de l’arme atomique partagent publiquement leurs activités sportives par le biais de l’application Strava, divulguant ainsi, par inadvertance, des ...
22617
Reposted by x0rz
vx-underground (automated mirror) @vxundergroundre.bsky.social · 08/01/2025
We're witnessing the evolution of ransomware. Yesterday someone informed us of the existence of the new TTP of AWS S3 extortion. More specifically, Threat Actors abusing the Amazon Key Management Service (KMS) to encrypt company AWS buckets (or any cloud provider).
88730
Reposted by x0rz
hakan @hatr.bsky.social · 05/01/2025
incredibly detailed piece on Salt and Volt Typhoon (apparently named as if they're brothers) "a cybersecurity vendor notices the activity and flags it to the port's cybersecurity chief, who examines it and decides it's a false alarm. He heads to lunch at Whataburger." www.wsj.com/tech/cyberse...
wsj.com
How Chinese Hackers Graduated From Clumsy Corporate Thieves to Military Weapons
Massive “Typhoon” cyberattacks on U.S. infrastructure and telecoms sought to lay the groundwork for potential conflict with Beijing, as intruders gathered data and got in position to impede response a...
1278
Reposted by x0rz
John Scott-Railton @jsrailton.bsky.social · 21/12/2024
BREAKING: court finds NSO Group liable for #Pegasus hacking of #WhatsApp users. Big win for spyware victims. Big loss for NSO. Bad time to be a spyware company. Landmark case. Huge implications. 1/ 🧵
Court order text. Link to followCourt order text. Link to followCourt order text. Link to followCourt order text. Link to follow
12649317
Reposted by x0rz
Max Smeets @maxwsmeets.bsky.social · 19/12/2024
This aspect of restructuring authority between NSA and USCYBERCOM in light of a dual-hat split is one I hadn’t considered before:
194
Reposted by x0rz
Ciaran Martin @ciaranm.bsky.social · 12/12/2024
I don’t normally get worked up about the naming threat actors thing. But the Volt & Salt Typhoon is a disaster as it’s so hard for non-specialists to tell them apart: - Salt is Snowden style espionage by China against US - Volt is a direct 🇨🇳 military threat to degrade western infrastructure 1/2
712938
Reposted by x0rz
Catalin Cimpanu @campuscodi.risky.biz · 10/12/2024
The US Treasury has sanctioned Sichuan Silence, the Chinese company that developed exploits against Sophos firewalls home.treasury.gov/news/press-r...
11810
x0rz @x0rz.bsky.social · 30/11/2024
Why the f*ck does my Windows trying to reach browser.events.data.msn[.]cn
140
Reposted by x0rz
Nicolas Grégoire @agarri.fr · 29/11/2024
"The networks are still compromised, and booting the hackers out could involve physically replacing “literally thousands and thousands and thousands of pieces of equipment across the country,” specifically outdated routers and switches" 🕵️‍♂️
washingtonpost.com
Top senator calls Salt Typhoon ‘worst telecom hack in our nation’s history’
The severity of the Chinese breach highlights the need for more telecommunications regulation, lawmakers say.
14437
x0rz @x0rz.bsky.social · 28/11/2024
More people should use QubesOS
330
Reposted by x0rz
hakan @hatr.bsky.social · 27/11/2024
Seems kind of important that Bruno Kahl, head of german foreign intelligence, said that it's his assessment that Russia by the end of this decade will be in a position to initiate an attack against NATO www.spiegel.de/politik/bnd-...
spiegel.de
BND-Chef warnt vor Putins konventioneller und hybrider Kriegsführung
Der Kreml wird versuchen, die Bundestagswahl zu beeinflussen. Davon geht BND-Chef Bruno Kahl aus. Und seine Agenten kommen zu dem Schluss: Russland wird wahrscheinlich Ende der Zwanzigerjahre in der L...
33414
x0rz @x0rz.bsky.social · 27/11/2024
It’s a matter of time, Chinese media/bots will eventually target this platform as well.
0123
Reposted by x0rz
Winnona @winnona.bsky.social · 26/11/2024
CTI is the cause of my brainrot but I really cooked on this #salttyphoon #telecomhack
54817
Reposted by x0rz
Taggart @taggart-tech.com · 27/11/2024
Firefox, Thunderbird, Tor Browser RCE: www.welivesecurity.c...
welivesecurity.com
RomCom exploits Firefox and Windows zero days in the wild
ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit.
088
Reposted by x0rz
Gabriel Thierry @gabrielthierry.eurosky.social · 25/11/2024
Bonjour, Bienvenue dans ce live-skeet du procès de Florent Curtet, ce trentenaire poursuivi pour des extorsions numériques, jugé en cette fin de mois à Paris par le tribunal judiciaire.
65127
Reposted by x0rz
Sean Gallagher @thepacketrat.net · 25/11/2024
👏IF YOU HAVE A VPN APPLIANCE 👏ON YOUR NETWORK AND 👏YOU DON'T HAVE 2FA OR OTHER VERIFICATION 👏JUST USERNAME/PASSWORD CREDS 👏YOU HAVE AN OPEN DOOR TO YOUR NETWORK 👏YOU ARE GOING TO GET RANSOMWARED
69828
x0rz @x0rz.bsky.social · 24/11/2024
Just got a TLS certificate error on bsky.app for a while. Showing the cert for ism[.]bible. The fuck?
030
Reposted by x0rz
Horkos @wylienewmark.bsky.social · 23/11/2024
Nearest Neighbor? Espionage. www.wired.com/story/russia... Salt Typhoon? Espionage. wapo.st/3CHK3dQ GRU’s use of Moobot? Espionage. www.justice.gov/opa/pr/justi... MSS hack of MSFT? Espionage. www.cisa.gov/sites/defaul... SolarWinds? Espionage. www.lawfaremedia.org/article/sanc...
0237
x0rz @x0rz.bsky.social · 22/11/2024
Why is it *ALWAYS* UTC+8 👀🇨🇳
030
Reposted by x0rz
Taggart @taggart-tech.com · 22/11/2024
This is your reminder that DMs here are _not encrypted_. They're not even really part of ATProto. It's on the roadmap, but that's not the case now. DMs are centralized and unencrypted. Behave accordingly.
56127
Reposted by x0rz
Horkos @wylienewmark.bsky.social · 22/11/2024
Close access technical operations are never going away; there’ll always be at least edge cases requiring physical proximity to target. But given the risks involved, pursuing remote means to achieve “close”-style tactics is likely a trend that has been ongoing but only just now coming into the light.
1294
Reposted by x0rz
Andy Greenberg @agreenberg.bsky.social · 22/11/2024
Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...
wired.com
Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack
In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street.
12571320
Reposted by x0rz
Melissa K. Griffith @melissakgriffith.bsky.social · 07/11/2024
The “messy middle between war and peace is not the only grey zone that hackers are exploiting. They are also straddling the line between “crime and statecraft” and the distinction between “espionage and attacks”." Read my latest piece in Articles of War below.
lieber.westpoint.edu
Hybrid Threats and Grey Zone Conflict Symposium – Cyber Operations are Thriving in the Grey - Lieber Institute West Point
Cyber operations are thriving in a series of grey zones, widening the aperture of what is possible short of war.
132
x0rz @x0rz.bsky.social · 21/11/2024
Bluesky be like
050
Reposted by x0rz
Steve YARA Synapse Miller @stvemillertime.bsky.social · 18/11/2024
Much like the conservation of mass-energy, the "detection evasion paradox" suggests that detection surface area cannot be created nor destroyed, only transformed or transferred to another form. Every attempt to hide generates a new signal.
0153
Reposted by x0rz
DPRK CERT @dprkcert.bsky.social · 21/11/2024
We are excited to announce #Trump has nominated our very own Park Jin Hyok as director of the #FBI.
05916
x0rz @x0rz.bsky.social · 20/11/2024
The X social network is being weaponized by both its CEO and Russia. It’s more of a botnet now. Sad world.
060
x0rz @x0rz.bsky.social · 20/11/2024
Oopsec
040
Reposted by x0rz
Sam Sabin @samsabin.bsky.social · 19/11/2024
CrowdStrike has identified a new China hacking group that's been targeting telecom networks since at least 2020. The group has primarily targeted networks in SE Asia and Africa — but it also have the ability to use their access to breach other networks. www.axios.com/2024/11/19/c...
axios.com
Exclusive: CrowdStrike finds that yet another China-linked hacking group is targeting telecom networks
The discovery comes as the U.S. responds to a sprawling China hack of officials' phones.
22818
Reposted by x0rz
Intel Night OWL 🦉🇺🇸 @intelnightowl.bsky.social · 18/11/2024
The two submarine cables that are cut: #CLion1 - between #Finland and #Germany #BSC - between #Sweden and #Lithuania yle.fi/a/74-20125395 Thank you @henrikytonen.bsky.social for the correction of the second cable name!
yle.fi
Yritykset Ylelle: Liettuasta Ruotsiin menevään datakaapeliin kohdistunut fyysistä vahinkoa
Yle kertoo tuoreimmat tiedot aiheesta tässä artikkelissa.
49145