SimoKohonen Profile Banner
Simo Profile
Simo

@SimoKohonen

Followers
2K
Following
8K
Media
962
Statuses
4K

chief honeypot @defusedcyber

☠ πŸ’» πŸ”‘ πŸ›‘ cyberspace
Joined February 2016
Don't wanna be here? Send us removal request.
@SimoKohonen
Simo
2 days
Friends, we are live! πŸ₯³ Defused TF, our first paid plan, now available πŸ‘‡ Super happy to finally get this out the door but so much more to come!
@DefusedCyber
Defused
2 days
DEFUSED TF [”ThreatFlix”] is LIVE! πŸ₯³πŸ₯³ Pricing details: https://t.co/YN0ubeqgMT Subscribe: https://t.co/vJlRQ5KmoN Plans starting at $29 USD / month!
6
5
23
@SimoKohonen
Simo
2 days
Friends, we are live! πŸ₯³ Defused TF, our first paid plan, now available πŸ‘‡ Super happy to finally get this out the door but so much more to come!
@DefusedCyber
Defused
2 days
DEFUSED TF [”ThreatFlix”] is LIVE! πŸ₯³πŸ₯³ Pricing details: https://t.co/YN0ubeqgMT Subscribe: https://t.co/vJlRQ5KmoN Plans starting at $29 USD / month!
6
5
23
@SimoKohonen
Simo
14 hours
🍯🍯🍯
@DefusedCyber
Defused
14 hours
New Free Stream on Defused TF ["ThreatFlix"] 🍯 We have added Oracle E-Business into the free streams Sign up now to take advantage of free Oracle E-Business threat intelligence: https://t.co/GXFaqghsXI
1
0
6
@SimoKohonen
Simo
1 day
> launch a product > immediately get hit by a ddos The internet is such a friendly place πŸ˜‚
5
1
15
@SimoKohonen
Simo
1 day
πŸ™πŸ™πŸ™πŸ™πŸ™πŸ™
@techspence
spencer
1 day
This platform @SimoKohonen has built @DefusedCyber is really cool. I've seen first hand how hard he's been working to bring this to you all. Countless hours of troubleshooting, and tons and tons of feedback to hone in on what would be the most useful and valuable. Couldn't be
0
0
8
@kmkz_security
kmkz
1 day
@SimoKohonen @techspence Cannot agree more dude
1
1
4
@Kostastsale
Kostas
1 day
Translating noise into signals one honeypot at a time πŸ™‚ Checkout @DefusedCyber y’all, a great way to stay ahead of the game!
@SimoKohonen
Simo
2 days
Friends, we are live! πŸ₯³ Defused TF, our first paid plan, now available πŸ‘‡ Super happy to finally get this out the door but so much more to come!
0
2
18
@M_haggis
The Haagβ„’
1 day
This is a steal - perfect price point for quick honeypot deployments. @DefusedCyber keeps these up to date and cutting edge. Buy this instead of a bag of coffee for a month and it'll pay dividends!
@SimoKohonen
Simo
2 days
Friends, we are live! πŸ₯³ Defused TF, our first paid plan, now available πŸ‘‡ Super happy to finally get this out the door but so much more to come!
1
1
11
@SimoKohonen
Simo
1 day
πŸ₯°πŸ₯°πŸ₯°
@SimoKohonen
Simo
2 days
Friends, we are live! πŸ₯³ Defused TF, our first paid plan, now available πŸ‘‡ Super happy to finally get this out the door but so much more to come!
2
1
23
@techspence
spencer
1 day
I’m totally biased here, but I really think CTI folks and threat researches will get a lot of value from this platform πŸ™ŒπŸ€˜πŸ’ͺ
@SimoKohonen
Simo
2 days
Friends, we are live! πŸ₯³ Defused TF, our first paid plan, now available πŸ‘‡ Super happy to finally get this out the door but so much more to come!
1
2
15
@techspence
spencer
2 days
Seriously awesome stuff from @SimoKohonen!!! Why manage your own honeypots anymore?! πŸ™ŒπŸ€˜πŸ’ͺ🐝🍯 Highly recommend checking this out if you’re in threat intel/security research.
@DefusedCyber
Defused
2 days
DEFUSED TF [”ThreatFlix”] Available 10th Nov 12pm EST Sign up now: https://t.co/GXFaqggV8a
0
2
15
@SimoKohonen
Simo
2 days
Every launch needs an over-the-top hype vid Wear headphones for max experience Tomorrow 12pm EST - LFGgggg
@DefusedCyber
Defused
2 days
DEFUSED TF [”ThreatFlix”] Available 10th Nov 12pm EST Sign up now: https://t.co/GXFaqggV8a
4
1
19
@Lawrence_Sec
Lawrence_Sec
2 days
AΓ©za International (#AS210644 ) via, you guessed it.... @aurologiccom (#AS30823) πŸ‡©πŸ‡ͺ
@DefusedCyber
Defused
2 days
⚠ Exploitation of the unknown Fortinet exploit (FortiWeb path traversal / API exploit) continues from 89.169.55.168 πŸ‡©πŸ‡ͺ (unbiaseddeer.ptr . network) 0/95 on VirusTotal - but IP has been observed exploiting an Oracle vulnerability and domain widely used in exploit activity
0
5
6
@SimoKohonen
Simo
2 days
πŸ‘€πŸ‘€
@DefusedCyber
Defused
2 days
⚠ Exploitation of the unknown Fortinet exploit (FortiWeb path traversal / API exploit) continues from 89.169.55.168 πŸ‡©πŸ‡ͺ (unbiaseddeer.ptr . network) 0/95 on VirusTotal - but IP has been observed exploiting an Oracle vulnerability and domain widely used in exploit activity
0
0
18
@SimoKohonen
Simo
5 days
you know its serious when the hacker is using leetspeak in their exploits
@DefusedCyber
Defused
5 days
⚠ Multiple IPs mass exploiting unknown Fortinet exploit (FortiWeb path traversal / API exploitation) The exploit aims at creating a user with the user-password combination Testpoint:AFT3$tH4ckmet0d4yaga!n πŸ” IPs involved in this exploit: 185.192.70.39 185.192.70.55
0
0
7
@SimoKohonen
Simo
5 days
Some heightened activity on WSUS / CVE-2025-59287 during the last few days, put one of the payloads into a gist if someone is interested: https://t.co/ttzcTuh9V4
0
19
57
@SimoKohonen
Simo
5 days
πŸ‘€πŸ‘€
@DefusedCyber
Defused
5 days
⚠️Actor mass exploiting unknown Fortinet exploit (FortiWeb path traversal / API exploitation) from 107.152.41.19 πŸ‡ΊπŸ‡Έ ( TZULO ) VirusTotal Detections 0/95 🟒 After the exploit, the actor attempted to login using the newly created username-credential pair πŸ”
0
0
10
@SimoKohonen
Simo
7 days
Interesting exploits hitting multiple Cisco ASA honeypots Notably in the payload: <svg/onload=alert('PTSwarm')> PTSwarm is the offensive arm of Positive Technologies, a Russian company that "..supports RU Intelligence in carrying out malicious cyber activities against the US"
1
5
12
@SimoKohonen
Simo
8 days
always patch! πŸ’€
@DefusedCyber
Defused
8 days
Patching Motivation of the Day πŸ‘‡ Actor repeatedly hammering the CVE-2025-25257 exploit onto our Fortiweb honeypots with a DROP TABLE payload 213.209.143.41 just wants to watch the world burn! πŸ”₯
0
1
16