Travis Smith
@MrTrav
Followers
1K
Following
287
Media
59
Statuses
545
ML Threat Ops @HiddenLayerSec, Beer Geek, Family Man. Mastadon: @[email protected]
Portland, OR
Joined August 2008
HiddenLayer is now a CVE Numbering Authority (CNA) assigning CVE IDs all @hiddenlayersec systems, services, & products + vulnerabilities it discovers not in another CNA’s scope https://t.co/dtCisnu2lD
#CVE #CNA #VulnerabilityManagement #Vulnerability #Cybersecurity @CVEnew
0
4
5
A second vulnerability in MOVEit Transfer is announced, no evidence of exploitation yet, but orgs should patch quickly to reduce the risk. Remediation is as easy as replacing 3 DLLs or installing the latest version.
0
1
2
The MOVEit Transfer CVE is one of the more risky vulns in recent memory due to the quickness of threat actors to leverage it and extort their victims. We put together a few insights and how organizations can respond accordingly to this developing threat:
blog.qualys.com
On June 2nd, CVE-2023-34362 was published against the Progress MOVEit Transfer product and was quickly added to CISA’s Known Exploited Vulnerabilities Catalog. MOVEit Transfer is a managed file…
0
0
1
Really excited to share the 2023 @Qualys TruRisk Threat Research Report. Tremendous work by the Threat Research Unit to put together our view of the threat landscape.
qualys.com
Download the 2023 TruRisk Threat Research Report to better understand your organization's cybersecurity needs.
0
1
3
Lots of valuable information in here to understand the true risk of this developing vulnerability
#Qualys Threat Protection - Microsoft Exchange Server Zero-day Vulnerabilities (CVE-2022-41040 and CVE-2022-41082) https://t.co/9PA7lGpAH4
#vulnerability
0
1
1
Great discovery from the Qualys Vulnerability Research Team. More details are available in our blog going over the vulnerability, how to find out if you are impacted, and how to detect exploitation. #PwnKit
The #Qualys Research Team has discovered an easily exploitable memory corruption vulnerability (#Pwnkit) in polkit a SUID-root program that allows any unprivileged local user to gain root privileges on all major linux systems in its default configuration: https://t.co/hz74iWU7mz
0
0
2
Excellent analysis of the REvil ransomware from the @qualys Malware Threat Research Team.
How the REvil #ransomware supply chain attack works and mitigation steps you can take to lower your risk
1
0
0
Joke’s on you hackers, 15% of my password isn’t even one character.
0
0
2
Today marks my last day @TripwireInc . It's been an exciting 6.5 years building out the security content and research capabilities. While I am sad to leave behind lifelong friends, I am excited for the next chapter.
2
0
5
I updated @MITREattack TEACH to now map to v7.0, which now includes sub-techniques.
github.com
Contribute to TravisFSmith/mitre_attack development by creating an account on GitHub.
0
1
4
The ATT&CK Evaluations Team just released the APT29 Evaluation results, DIY Eval profile, and a Joystick update on https://t.co/39fEmIMIUG. Check out https://t.co/Mr2Lyo0S1O to learn more about the evaluation process.
medium.com
In late 2019, the ATT&CK Evaluations team evaluated 21 endpoint security vendors using an evaluation methodology based on APT29.
2
161
255
We're in full swing producing shields and other PPE. Yesterday we donated 50+ to medical professionals in OR and CA, and a team at PSU is evaluating a new laser cut model. If your org needs face shields or other PPE, please contact us through our web site. https://t.co/Kwisdvoxbg
2
24
81
Full sell out crowd of 96. Had a great time, thanks for everyone who made it out!
0
0
7
Environment spun up, @Elastic stack started, @MITREattack CALDERA running, and @redcanaryco Atomic Red Team loaded. I'm ready to teach some things here at #RSAC. Room 314 in the south hall if you'd like to get on the wait-list.
2
2
10
Headed to #RSAC and found out my learning lab is now sold out. This should be a fun conference!
rsaconference.com
0
3
11
So is one supposed to only wear this on job interviews, or is it supposed to be worn daily at work? Asking for a friend.
5
1
0
Juice jacking is as simple as plugging your phone into a public USB port or changing station. 📱 https://t.co/55Xb4DXTAi
1
4
1
Yesterday I climbed Mt St Helens to a summit of 8400 ft. Breathtaking views give you a whole new perspective of our planet.
1
0
2