-
Tweets590
-
Followers2K
-
Following640
-
Likes293
For two years we told clients to wait on post-quantum migration. As of this month, we are telling them to start. Two recent papers cut the qubits needed to break P-256 by ~20x. Valsorda now puts CRQC at 2029. Inventory your crypto. Ship ML-KEM hybrid in TLS 1.3. profero.io/blog/quantum-c…
We added a detection rule for --allow-dangerously-skip-permissions in Claude Desktop. Then we found an attack chain nobody was talking about. "No shell, no impact" is the wrong mental model for AI agents. An agent running with that flag, even with Bash blocked, can still: • Read SSH private keys, .env files, AWS credentials, and browser session databases • Write to ~/.zshrc, .git/hooks/pre-commit, ~/.ssh/authorized_keys, or source files in your repo Execution is deferred. The next terminal you open, the next commit you push, the next CI run, runs the payload. It gets worse. Skills load as trusted context with no signatures, no checksums, and no version pinning. Inject once, persist in ~/.claude/skills/, and wait. The user invokes the skill days later in a fresh session, and the payload runs with full trust. No anomalous process, network, or permission signal to catch it. What defenders should do today: • Monitor ~/.claude/skills/ for unexpected modifications • Vet every MCP tool and skill before installation • Audit shell configs and git hooks after any agent session • Stop treating --allow-dangerously-skip-permissions as safe just because Bash is off Full breakdown by @barnhartguy : profero.io/blog/hiddenper… #AISecurity #IncidentResponse #ThreatIntelligence #ClaudeCode #RapidIR
The war between wars is being fought inside your controllers. Our IRT breaks down an IRGC front’s paired IT wiper and OT sabotage campaign, with GRAT IOCs and a YARA rules. profero.io/blog/war-betwe…
From the Profero team. Happy Shavuot! May your holiday be filled with peace, growth, and meaningful moments.
Our team just published research on a malware campaign that hit 25+ organizations, several in Israel. The attacker built it so badly that anyone who opened a sample got kill-switch access to the entire botnet. The malware: WindowsAudit. Runs as LocalSystem on compromised hosts. Discord as C2. The mistake: Discord bot token hardcoded in plaintext inside the binary. No XOR, no encryption, no obfuscation. Same token in every sample on every infected machine. What we did with it: • Authenticated to Discord with the token and pulled the full activity history •Extracted everything the attacker stole from victims: AD dumps, network maps, screenshots, file listings, usernames •Identified 25 distinct victims from the data •Tracked the attacker’s working hours and timezone in real time •Every time a new build got pushed, automation grabbed it, reversed it, and pulled fresh IOCs The architecture is worse: •Every infected host runs the same binary •That binary receives commands from the attacker AND can issue commands to other infected hosts •No command signing, no authentication. If you hold the token, you operate the botnet. •A single command could uninstall the malware from every victim. Accidental kill switch. We didn’t fire it. Any command we sent would surface in the attacker’s Discord and burn the monitoring op. Full IOCs in the writeup. Worth a look if you’re defending an Israeli environment. profero.io/blog/windowsau…
New research from Profero: a malware campaign affecting 25+ organizations, several in Israel, brought down by the attacker’s own operational security failure. The malware, WindowsAudit, runs as LocalSystem on compromised hosts and uses Discord for command and control. The Discord bot token was hardcoded in plaintext inside the binary, identical across every sample on every infected machine. Our research team used the exposed token to: •Authenticate to the attacker’s Discord and recover the full operation history •Recover all data the attacker had exfiltrated from victims, including AD dumps, network maps, screenshots, and file listings •Identify 25 distinct victim organizations •Profile the attacker’s working hours and timezone in real time •Automatically retrieve, analyze, and extract IOCs from every new build the attacker deployed A flaw in the malware’s design compounded the issue. Every infected host runs the same binary, capable of both receiving commands from the operator and issuing commands to other infected hosts. No signing, no authentication. Anyone holding the token could push a single command and uninstall the malware across the entire botnet. An accidental kill switch. We chose not to use it. Any command we sent would have appeared in the attacker’s own Discord and ended the monitoring operation. Full technical writeup and IOCs available at the link below. Particularly relevant for organizations operating in Israel. profero.io/blog/windowsau…
Full teardown, detections, and IOCs: profero.io/blog/windowsau…
Profero IRT pulled apart "WindowsAudit.exe", a 101MB .NET RAT running as LocalSystem that uses a Discord guild as its primary C2. Two channels inside one guild: one for tasking, one for results. Operators issue slash commands to target agents by hostname, Machine GUID, or broadcast to all. MQTT and Telegram sit as fallbacks. Inside the kit: LSASS dumps, DPAPI browser theft, full AD takeover toolkit, Hell's Gate syscalls, AMSI/ETW patches, EDR kill for 15+ vendors, WireGuard relay for pivoting. This isn't a script-kiddie RAT. Looks like a ransomware crew warming up.
Mythos is a real capability leap. The threat model that changes is narrower than the coverage implies, concentrated where it was always going to hurt most: incident response.
What happens when incident responders build their own platform? Rapid‑IR: Reforged brings four operational quadrants into one system, powered by Deep Breach Focus™ and designed as a continuous workflow where every feature was created to support real preparation and real response.
Read the full story: profero.io/blog/the-theat…
Russia's GRU built NotPetya. This week "Russian Legion" misspelled SharePoint in a fake nuclear breach screenshot. That gap is strategy, not decline. Full brief in next reply.
Deep Breach Focus™ is what makes Rapid‑IR: Reforged different. Built entirely in-house from real breach casework, it turns years of incident response experience into continuous scoring, prioritization, and intelligence-without relying on third-party AI. Your data never leaves the platform. Real incident knowledge. Applied where it matters.
Happy Easter! While you take time to recharge, Rapid‑IR: Reforged is here to keep readiness running-so when incident response matters most, you're already prepared.
Happy Passover to our customers, partners, and community. May your holiday be peaceful, and may Rapid‑IR bring even more confidence and readiness to your security journey.
Read the full blogpost: profero.io/blog/why-we-re…
When an incident hits at 2 AM, most organizations don't start with response-they start with chaos. PDFs, scattered tools, unclear priorities, and a clock that's already running. That's not rapid response. Years of real casework taught us something simple: the organizations that recover fastest aren't the ones with the biggest teams. They're the ones that were ready before the incident began. That's why we rebuilt Rapid-IR: Reforged, from the ground up-not as a feature update, but as a complete platform built around one conviction: the fastest response starts before the incident. Read the full blog in the first comment.
We don't know exactly how Handala got into Kash Patel's accounts-and we're not going to speculate. But after years tracking MOIS-linked intrusions, the answer is usually far less "zero-day" and far more credential dumps, stealer logs, and old breach data. Read the full breakdown on the blog: profero.io/blog/the-key-w…
Florian Roth ⚡️ @cyb3rops
221K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Omri Segev Moyal @GelosSnake
10K Followers 1K Following I used to take things apart, now I build them | CEO @proferosec | @forbes 30 under 30. Co-founder @minervalabs (Acquired by @rapid7)
Thomas Roccia 🤘 @fr0gger_
35K Followers 2K Following AI Security x Threat Intel · Threat Researcher · Creator of #Unprotect & #NOVA · Malware Warlock · Python 🧡 · Prev @Microsoft @McAfee_Labs
Inbar Raz @inbarraz
3K Followers 803 Following Hacker of Things. Research at @zenitysec. Co-organizer of Geekcon, @BSidesTLV, @dc9723. Opinions are mine.
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
עידוק @idokius
45K Followers 46K Following הכל בכל מקום בבת אחת #אדהד. מיזנתרופ של חתולים. מגיש-שותף @ohcybermycyber דברו איתי ☎️ [email protected]
Will @BushidoToken
38K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
SOS Intelligence @SOSIntel
20K Followers 2K Following Dark Web Intelligence. We find what's been stolen before it's weaponised. https://t.co/aQgEdlJVPl
Josh Grossman 👻 (t... @JoshCGrossman
2K Followers 2K Following Friendly AppSec Ghost 👻 @OWASP_IL | @OWASP_ASVS Mastodon 🐘: https://t.co/dHMXcjRkMH Blue Sky 🦋: https://t.co/LZHGv7q5HD
Ohad Zaidenberg @ohad_mz
2K Followers 925 Following Forbes 30 Under 30 @Forbes | Head of Intelligence @abinbev | Founder @ctileague | @SANSInstitute Difference Makers Award WIRED25 @wired | Opinions are mine
220v @__220v
22 Followers 1K Following
Itai @ItaiBoublil
3K Followers 632 Following Building my next chapter | Founder @finnx_ai | I tweet about my journey on this planet | 🔞
101010 @Dmitry123222
0 Followers 135 Following
Moshe S. @Moshe80hd
257 Followers 6K Following
Schiekadelic @cyberChad101
268 Followers 3K Following i defend 10% of the internet from all the things. (DFIR, vulns, cloudsec, Privacy) Views are my own. he/him/jawn. you do you
Jake Knowlton @j2k3k
1K Followers 2K Following cyber things @mandiant . natsec. prior USAF. opinions are my own. I’m back.
IceColdGlizzard @cold_ice34618
0 Followers 170 Following
AppSecLady @irislevari
174 Followers 816 Following Application security, IoT, Samsung SmartTV Bug Ex Bounty manager. 23 years of appsec. hacking for fun.
LonelyTesseract @typepunned
11 Followers 2K Following
Zed @ZShezzen
81 Followers 3K Following Man | Builder | Quant | Math | Investment-Advisor | $1B is my Goal.
Sebastiaan @Stekkz
1K Followers 5K Following Security Researcher | Wanderer/Traveler | People person | Lifting weights, gaming and helping people. My poison: #whiskey, #gin and #cider
isenhu @isenhu
33 Followers 3K Following
Ben Franklin @HoltzBen
109 Followers 1K Following Lover of Justice, Freedom, Counter-Terrorism, Pateks and my Xbox | Hater of radical islam #MAGA #counterterrorism #patek
Ari Ben Am @ari_ben_am
384 Followers 5K Following Open source investigation enthusiast. Co-founder of Telemetry Data Labs (https://t.co/rYsms4liSu). Writes at https://t.co/u4YBgXBf6L.
重莲 @lxghost1989
604 Followers 237 Following Focus on osint、intelligence、darkweb Services wechat 不会告诉你
Sreeharsha Kornu @sreeharshakornu
117 Followers 700 Following Cybersecurity analyst. Liverpool FAN since 2004. YNWA
Akshay @Akshyayyysocial
0 Followers 61 Following
Br*an @SecurityCollins
424 Followers 5K Following ☁️ security, general technology fan • opinions = mine
Pawan Joseph @Pawan_Joseph
228 Followers 3K Following Fintech business owner, Tech Leader, Passionate about family & work. Enjoy reading, Bollywood songs of the 80-90s.
Faruk SARI @faruksari
1 Followers 2K Following An IT pro, a Turk in Luxembourg, a human loves to learn.
JayTee427 @jephtanner
63 Followers 1K Following
UriShimron @UriShimron
258 Followers 5K Following Data Scientist. NL/ENG. Opinions are mine, but they can be yours too if you want! The book was better than the movie, btw
tjepl @tjepl
225 Followers 3K Following
nightsky4 @learn2tweetoneo
30 Followers 2K Following
Gwunjee @gwunjee
0 Followers 2K Following mission cures all. when market is clear I execute. we worked hard but had a good time
Ahad @Eddy2896
73 Followers 2K Following
Nitin Nayak @NitinNayak82
75 Followers 3K Following
terrence @tstank
460 Followers 4K Following Father, Runner, Linux Admin, TurboNerd, USMC Veteran, Aspiring Security Pro.
threathunterxx @threathuntxx
68 Followers 1K Following This account is for threat research purposes 😬 (not affiliated with any account) | For personal use
David Perez @anakinswal
304 Followers 2K Following |#CC |#CTIA |#ECIH |#eCTHP|#eCIR |Intel Ops Padawan |All systems are vulnerable (People2) |PurpleTeam addict👾 |Retrato atardeceres 🌅 |Destilo gin🍸|Cultivo 🍄
Alok Kumar @alokkumar1912
89 Followers 2K Following
Linux Networking @LNetworkin69385
218 Followers 4K Following
Madnight @Madnightea
1 Followers 101 Following
GNU Link @gnu_link
10 Followers 247 Following
Vinod More @vinodm41
71 Followers 2K Following Cybersecurity Professional | SOC Analyst | Security Engineer | Threat Hunter | Cloud Engineer | Cloud Security | AWS | Azure | AI-Enabled
Saeed Jaber @Saeedjabercyber
108 Followers 273 Following Cyber Security Researcher 💻 Do it with passion or not at all ❤️ https://t.co/y9DZDewonT
0xdfir-jutsu-mal @Jutsu0xdfir_mal
138 Followers 247 Following #ThreatHunting / #Cyber Threat Intelligence
lekiet @LQKiet19
3 Followers 273 Following
vx-underground @vxunderground
439K Followers 359 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Florian Roth ⚡️ @cyb3rops
221K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Ran Bar-Zik @barzik
60K Followers 117 Following Senior software architect at @PaloAltoNtwks. Tech journalist at @TheMarker. Lecturer at Ono Academic College, Haifa University, Author, Opinions are my own.
Omri Segev Moyal @GelosSnake
10K Followers 1K Following I used to take things apart, now I build them | CEO @proferosec | @forbes 30 under 30. Co-founder @minervalabs (Acquired by @rapid7)
Thomas Roccia 🤘 @fr0gger_
35K Followers 2K Following AI Security x Threat Intel · Threat Researcher · Creator of #Unprotect & #NOVA · Malware Warlock · Python 🧡 · Prev @Microsoft @McAfee_Labs
MalwareHunterTeam @malwrhunterteam
254K Followers 37 Following Official MHT Twitter account. Check out ID Ransomware (created by @demonslay335). More photos & gifs, less malware.
hasherezade @hasherezade
91K Followers 954 Following Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
Inbar Raz @inbarraz
3K Followers 803 Following Hacker of Things. Research at @zenitysec. Co-organizer of Geekcon, @BSidesTLV, @dc9723. Opinions are mine.
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Troy Hunt @troyhunt
249K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
MalwareTech @MalwareTechBlog
272K Followers 1 Following Not here anymore. Profiles: https://t.co/sFoOuGmYK2
BleepingComputer @BleepinComputer
254K Followers 205 Following Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
Florian Hansemann @CyberWarship
88K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
John Hammond @_JohnHammond
321K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyQtS && https://t.co/narO3sz7y6
Andrew Thompson @ImposeCost
41K Followers 2K Following Posts are attributable to me—not my employer. Leadership, Security, and Intelligence. Former Infantry, HUMINT, Counterintelligence, and Cyberspace Operations.
Josh Grossman 👻 (t... @JoshCGrossman
2K Followers 2K Following Friendly AppSec Ghost 👻 @OWASP_IL | @OWASP_ASVS Mastodon 🐘: https://t.co/dHMXcjRkMH Blue Sky 🦋: https://t.co/LZHGv7q5HD
Ohad Zaidenberg @ohad_mz
2K Followers 925 Following Forbes 30 Under 30 @Forbes | Head of Intelligence @abinbev | Founder @ctileague | @SANSInstitute Difference Makers Award WIRED25 @wired | Opinions are mine
Ismael Valenzuela @aboutsecurity
18K Followers 9K Following VP Labs, Threat Research & Intel @AWNetworks ▪️ SANS Author & Senior Instructor #GSE 132 ▪️ #SEC530 #ThinkRedActBlue @TheMondayBrief
Caitlin Condon @catc0n
4K Followers 3K Following Adventurer. Takes a lot of photos, calls many places home. Research VP @VulnCheckAI. Previous research director @Rapid7 / @metasploit. Opinions mine. She/her.
SysAid @sysaid
10K Followers 525 Following SysAid empowers IT to drive 100X more impact for organizations. ITSM run by AI—and you.
Alla Lenchn3r @Sweet_monkey
191 Followers 1K Following Interested in Computer Architecture, Security, Operating Systems
Petrus Vasenius @PetrusVasenius
397 Followers 937 Following Cloud Security leader 🛡️☁️ | Retweets/Likes ≠ Endorsements | #CyberSecurity #SecOps
shirasabo @shirasabo
27 Followers 271 Following
Cyber Outlook @CyberOutlook
9K Followers 7K Following Helping people explore and navigate #Cybersecurity. We share #InfoSec news, knowledge and resources from experts. Founded by an active CISO & CISSP.
Eric Petuch @EricPetuch
5 Followers 44 Following
Sam Goodman @asus__router
46 Followers 640 Following Here's some insider updates and 1st preview for the latest highlights of ASUS router. Stay tuned!
David Valles @davidvalles007
837 Followers 960 Following Passionate about Infosec! Tweets are my opinion and do not represent my employer's view.
Karthick Gopalakrishn... @ChennaiTechie
17 Followers 264 Following Cloud Security Engineer | Table Tennis Player | Astrology Enthusiasts Sleep - Eat - Make Money - Do Gaming
Ophir Bear @ophirbear
80 Followers 118 Following
XM Cyber @XMCyber_
3K Followers 816 Following Continuously discover, prioritize, and fix every validated exposure in YOUR environment, with a fraction of the effort. #FixWhatMatters
yetkinmiller @Yetkinmiller
309 Followers 980 Following * Chocolatier @joshuachocolate * Assistant Pastry Chef * AU / Culinary Arts - 2020 * Patron Saint of Rakı * IT Specialist
Esty Brandes @esty_brandes
4 Followers 68 Following
dwight @somasivan47
151 Followers 298 Following
Kimmo Rousku @kimmorousku
7K Followers 4K Following Keynote speaker, cyber & digital (security) @Tietoturva_ry. Author. (Bio)#hacker. | #AI painter | General Secretary (VAHTI-board) - Chief Special Expert @dvvfi
Oshry P. Alkeslasi / ... @OshryAlk
437 Followers 669 Following Tech Reporter @geektimecoil. Tech, Film, TV and Sports junkie. Got a tech Story? [email protected]
Skytalks @dcskytalks
7K Followers 147 Following A ‘sub-conference’ that gives a unique platform for researchers to share their research, for angry hackers to rant about issues in the industry off-the-record
AppSec Village™ @AppSec_Village
11K Followers 6K Following AppSec Village @DEFCON & @RSAConference A volunteer-run, non-profit focused on education, awareness, and community. Founded by @erezyalon and @tzionit411.
Johnny Heintz @Jorune00
144 Followers 652 Following 🇺🇸🌐 #NetworkEngineer CCS-EN, CCNA, #cybersecurity, #telephony, #technology, #python #DevOps #linux Other hobbies: #weatherenthusiast, #photography, and #cats
Paul Asadoorian @paul... @securityweekly
75K Followers 9K Following Founder of Security Weekly, Principal Security Evangelist at Eclypsium
SANS DFIR @sansforensics
111K Followers 104 Following The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
CyberScoop - @cybersc... @CyberScoopNews
23K Followers 1K Following CyberScoop, a @ScoopNewsGroup property, reports on news and events impacting technology and security.
Mark @MorrMarkJ
76 Followers 338 Following #CISSP | #CCSP | DevOps | Infosec | Tweets are my own and all that. #wvu
Gi7w0rm @Gi7w0rm
19K Followers 819 Following Threat Intelligence Analyst | Projects: https://t.co/azRpNg9NJQ & https://t.co/SyvUfXpbmI | If I post false intel, contact me! Support me: https://t.co/5WgDqr0K8p 🇪🇺🇩🇪🇺🇦🌈
Raouf | رؤوف @B1nary0wl
518 Followers 547 Following PhD | Independent Threat Researcher | Security Analyst
Tyler McLellan @tylabs
3K Followers 588 Following Intrusion aficionado. @Google/@Mandiant GTIG Advanced Practices
Arik Weiss אריק �... @arikweiss
11K Followers 1K Following מגיש ברשת 13 וגלצ Journalist & Anchorman @newsisrael13 retweet ≠ endorsement https://t.co/ZLHh3VrLDU
DevOps_Dad ☁️ @DevOps_Dad
423 Followers 949 Following DevOps/DevSecOps/SRE, husband, and dad. Awesome opinions are my own, bad opinions belong to my evil alter ego. | @NYIT | #DevOps | #Cloud |
Dana Baril @dana_baril
2K Followers 1K Following Security Leader | BlackHat USA Speaker | Forbes 30 Under 30 | Runner 🇺🇸🇮🇱
Or Katz @or_katz
393 Followers 219 Following Father, Husband, Security Researcher, Hunting phishing for fun, Former OWASP Israel chapter lead and big fan of white whales. Words are my own.
Alon Mantsur @AlonMantsur
20 Followers 94 Following
ElLicho @ElLicho007
88 Followers 149 Following
Jason Damron @JasonSDamron
1K Followers 1K Following Co-Founder @Sensilla_Inc - your security team when you don’t have one | Former NSA | 30 years defending networks
Expertise à l'Ouest @PoleAI
1K Followers 2K Following DSI, ex #Consultant Système et réseau #virtualisation, #messagerie, #vmware #microsoft #VDI #S2D #France #HCI Mastodon : @[email protected]

























