
Christopher Glyer
@cglyer
Followers
24K
Following
917
Media
518
Statuses
4K
Microsoft Threat Intelligence Center - Former Incident Responder & Chief Security Architect @Mandiant
Joined July 2009
MSTIC blog on Sharepoint exploitation . At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7:.Linen Typhoon.Violet Typhoon.Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown).
microsoft.com
Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting vulnerabilities targeting internet-facing SharePoint servers. In addition, we have observed...
0
8
6
RT @MsftSecIntel: Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint a….
0
162
0
RT @HackingLZ: Speakeasy is still one of my favorite tools. I needed a quick way to validate keying techniques on some C payloads and wha….
github.com
Windows kernel and user mode emulation. Contribute to mandiant/speakeasy development by creating an account on GitHub.
0
34
0
RT @reprise_99: New in the Defender XDR advanced hunting platform, GraphApiAuditEvents - any blue team, threat hunter or those working on d….
0
33
0
RT @RGB_Lights: Wow. Spain is putting salt typhoon out of business. They are just going to hand it all to them: Huawei contracted to man….
therecord.media
Huawei will manage and store judicially authorized wiretaps in Spain, under a contract that bucks the trend of Western governments restricting use of the Chinese tech company's products and services.
0
89
0
RT @Sysinternals: We've released Procmon for Linux, Sysmon for Linux, and SysinternalsEBPF with Azure Linux 3.0 support!. Get the tools at….
techcommunity.microsoft.com
Procmon 2.1 for Linux Sysmon 1.4 for Linux SysinternalsEBPF 1.5 This release includes Azure Linux 3.0 support across Procmon for Linux, Sysmon for Linux and...
0
123
0
RT @JohnLaTwC: Creating on-the-fly graphs with #Kusto is nice via make-graph, but what if Kusto could natively handle graphs as a data sour….
azure.microsoft.com
Subscribe to Microsoft Azure today for service updates, all in one place. Check out the new Cloud Platform roadmap to see our latest product plans.
0
10
0
I think CitrixBleed vuln is being exploited at a higher rate than I’ve seen discussed publicly. B/c it leaks data from memory it’s harder to directly tie exploitation to follow on activity. Reminder: I documented first session replay impact of Heartbleed.
cloud.google.com
Mandiant investigates where a threat actor leveraged the Heartbleed vulnerability in a SSL VPN concentrator to remotely access a client's environment.
3
11
85