WP
@wepIV
Followers
1K
Following
4K
Media
27
Statuses
3K
Currently @blackthornellc Entrepeneur, startup advisor, angel investor, CEO, CTO, red team / Frmly CEO @icebrgio before @Microsoft @DeptofDefense @dartmouth
Redmond, WA
Joined March 2009
WATCH: Whistleblower Rev. Robert Schenck describes how his decades-long influence campaign, aimed specifically at Supreme Court justices, successfully and intentionally exploited the high court’s lack of meaningful ethics and transparency rules.
125
1K
2K
Demonstrating CVE-2022-37958 RCE Vuln. Reachable via any Windows application protocol that authenticates. Yes, that means RDP, SMB and many more. Please patch this one, it's serious! https://t.co/ikOrTvQIJs
68
1K
4K
AI art isn’t theft? Pump some Disney and Nintendo in there. See what happens.
246
6K
70K
Kimsuky organization's APT attack sample on South Korea。 name:paypal.docx MD5:7b27586c4b332c5e87784c8d3e45a523 remote template http://k22012.c1[.]biz/paypal.dotm 历史攻击韩国报道 https://t.co/fkZPNFbTDD
https://t.co/G5wBUSXThU
@williamlong @malwrhunterteam @ShadowChasing1
2
18
43
Reminder for all the folks using YARA or regular expressions to find byte patterns in malware or other binaries - thou shalt use single line mode \0d\0a occurs way more than you would think (?s) at the start of your regex /s at the end of your YARA regex
1
7
22
@stvemillertime I like this analogy because it conveniently lets me rebrand my wild analysis distractibility intermixed with ADHD hyperfocus as “interval training”
1
2
14
@vxunderground Then go grab a free Windows VM and use 7zip to unzip it into a directory tree for easy testing on goodware https://t.co/cH8AYspcuF
Did you know that 7zip can "unzip" VMware VMDKs? Quickly build a ~"goodware" repo for testing your #100DaysofYARA rules w/ a free Windows 10 VM https://t.co/dzHhla9yIE Unzip and uze 7zz to extract the VMDK 7zz x ~/MSEdge-Win10-VMware/MSEdge-Win10-VMware-disk1.vmdk -oMSEdge-vm
0
4
8
Huh all I get now on Twitter is steady crypto bot spam. Where did infosec decide we were all gonna move to? Discord? Back to IRC?
2
0
2
Microsoft now offers the ability to link Azure Active Directory accounts to personal Microsoft accounts. It will be enabled by default, so Threat Actors can compromise both your business and your home life, essentially doubling the capabilities of Threat Actors. Very cool
27
311
1K
The activities in the report include illegal & legal attempts to steer US foreign policy by exploiting vulnerabilities in American governance, including its reliance on campaign contributions, susceptibility to powerful lobbying firms and lax enforcement of disclosure laws
29
282
948
BREAKING: FTX had a “backdoor” built into its accounting software by SBF, which he used to move billions without triggering alerts to other staff, auditors etc - Reuters
1K
8K
43K
.@redcanary if you're going to use a vx-underground meme to convey a message in your marketing advertisement, you should 200% donate to us.
4
14
179
Halo's Gate is (almost) dead, Long live ShellWasp! "Weaponizing Windows Syscalls": https://t.co/VU8KIsZNb9
3
79
221
Video games are a gateway drug to hacking, reverse engineering, and malware development
81
257
2K
On Windows, the new "raw-dylib" feature allows crates to import symbols from a DLL without making use of an import library (a .lib file). See the RFC for details: https://t.co/HfEsuIwhw0 9/10
1
8
141
@anton_chuvakin I had to search (because clearly I repeat myself) but it seems to be from my @BlackHatEvents keynote (where I was actually quoting my own tweet¹ ) 🙄 https://t.co/8C5p7305rJ __ ¹ https://t.co/1tAr4ipoRH
The honest question I have is: How can an industry that so prides itself on social engineering, also claim that "management don't get it" ?
0
3
13