Ido Naor ๐ฎ๐ฑ
@IdoNaor1
Followers
7K
Following
12K
Media
2K
Statuses
11K
Not here most of the time
Israel ๐ฎ๐ฑ
Joined November 2011
It's been a busy week so I almost missed this interesting unfolding story. The newly created GitHub repository "KittenBusters/CharmingKitten" appears to be part of an exposure campaign against the Iranian Advanced Persistent Threat (APT) group Charming Kitten, aka APT35. The
github.com
Exposing CharmingKitten's malicious activity for IRGC-IO Counterintelligence division (1500) - KittenBusters/CharmingKitten
2
25
88
Iโm guessing no one briefed him about who Netanyahu is for both sidesโฆ
0
0
0
Itโs interesting how a person who had nothing to do with the middle east conflict became the โenemyโ of both sides just bcz of a selfie and a couple of naive sentences.
1
0
0
We have reasons to believe that there might be a connection to Hidden Cobra and the trigger isnโt a False Positive. Still checking similarity to recent #LazarOps we released earlier last month.
An open-source YARA rule from @SEKOIA_IO triggered on the sample โ and itโs part of their public repo. The attribution in the rule name is probably misleading though, given this kind of obfuscation comes from public tools. The rule has been included in the YARA Forge set for a
0
0
1
๐จ New Blogpost is Out!! Over 50 GitHub accounts, and several LinkedIn accounts as well, were involved in a massive Lazarus fake hiring attack, dubbed as "LazarOps" by the security joes incident response team. Read the full blog at - https://t.co/FODjNuPnix
0
3
4
XBOW has become the top hacker in the US on @Hacker0x01, outperforming every human participant. Alongside this milestone, we are announcing our $75M Series B with @apoorv03 of @altcap. As bad actors get more advanced and use AI to become more powerful, @XBOW is our answer. XBOW
10
23
177
the most crowded flight in history (!) 1,088 people on a single Boeing airplane. Why?! How?! Thatโs 1 minute, see you tomorrow for Day 56!
297
1K
6K
Meet Marlene Engelhorn, one of the major organizers of anti-Israel protests in Europe ๐ Fun fact: Her wealth comes from her great-grandfather Friedrich Engelhorn, who made his fortune from producing Zyklon B, the gas used by the Nazis to murder Jews during the Holocaust.
4K
18K
53K
Our system has detected a hack into @CoinDCX centralized exchange 20 hours ago. Here's what we know: - The hacker stole around $44.2M in USDC/USDT from one of the exchange's operational wallets on Solana. - The hacker funded the hack with 1 ETH from Tornado Cash. - Part of the
9
37
108
Nothing too exciting by APT41 ๐จ๐ณ here IMO, using Impacket, CobaltStrike, Mimikatz, Pillager, RawCopy, Neo-reGeorg Using a compromised SharePoint server for C2 is interesting I guess, especially with this new ToolShell exploit for SharePoint servers https://t.co/IT3vowLIEr
securelist.com
Kaspersky experts analyze an incident that saw APT41 launch a targeted attack on government IT services in Africa.
1
92
286
Border agents copy entire phone contents in seconds using Cellebrite devices. Full disk encryption only protects powered-off devices.
66
210
1K
๐ฅ CERT-UA published a report on a malware powered by an LLM. The malware uses Qwen 2.5-Coder-32B-Instruct via the HuggingFace API to generate and execute commands on infected systems. It is a Python script that embeds prompts to dynamically craft Windows reconnaissance
11
88
272
FINALLY MY PROJECT IS OUT โ
CloudCastle v.2 release: - Free CSPM scanner - No SaaS - report is HTML - MITRE translations for every issue - Categorized, multi-account scans - Jump between accounts in a single page - Top 10, Top Vulnerable, Scoring & more and more ๐
๐๏ธ Following our live podcast launchโฆ ๐ CloudCastle is now officially live on GitHub! ๐ To everyone who joined us live โ thank you! ๐ Let us know how youโre using CloudCastle. #CloudCastle #SecurityJoes #AWSIR #ThreatHunting #OpenSource #CybersecurityTools
0
1
10
ืืื ืฉืขืจ ืจืืง ืืืืฆืช ืืช ืื ๐ ืืฉืืืฉืจืืื ืืืฆื ืื ืืคืืืงืกื ืืื ืืืืช
Podcast Behind The Scenes - Take 2๐ฌ๐ Join us, July 15 2025 at 18 PM Israel Time. (Not July 16!!) Register here: https://t.co/zr85NDjxRX #ืฉืขืจ_ืจืืง #its_the_15 #AI #security_joes #incident_response
0
0
2
Itโs believed that the only known Java applet used in SRM is AuctionGUI, historically living under the /sap/bc/bid_ehp4/auct/ path. #CVE202530012 #SAPSRM
0
0
0
Took the challenge of building an end-2-end solution during weekends. It took 3 months, but the first release is here. July 15, 2025. Join us live.
Join us as we release CloudCastle - CSPM for everyone, for free. In this podcast- 1. Why CloudCastle 2. Code overview 3. DIY tips 4. AMA session with our CEO @IdoNaor1, who coded the tool single-handedly Host: Sr. IR, Eilay Y. #XJOES
https://t.co/cN3JEIusTW
1
0
5