✨ Cas ✨
banner
cat5xmbi.bsky.social
✨ Cas ✨
@cat5xmbi.bsky.social
Hmmm. How could one describe me? Well…
IT Leadership Lab this morning! Having a conversation about tough conversations. Love it.
November 19, 2024 at 5:04 PM
Executed on two 52 week lows over the weekend. Fingers crossed we see some positive movement today 🤞
November 18, 2024 at 3:46 PM
At this point in my life having too much time to think outside of work or momming is just not good.
October 29, 2024 at 12:27 AM
Mondays, am I right?
October 28, 2024 at 11:54 PM
Gonna read this later
October 27, 2024 at 4:04 PM
Good morning ☀️ it’s Sunday. Today’s goal: put up them dang Halloween decorations! 🎃👻
October 27, 2024 at 3:47 PM
Reposted by ✨ Cas ✨
in retrospect it was dumb to build a house on top of quicksand but i’ve adapted, gotten stronger, become more powerful
October 27, 2024 at 3:40 PM
Reposted by ✨ Cas ✨
Watercolor and colored pencil studies inspired by ktscanvases
#mixedmedia
October 27, 2024 at 10:34 AM
Something with a little color.
October 27, 2024 at 7:40 AM
The Poltergeist is one of the best horror films ever created no cap “YOU ONLY MOVED THE HEADSTONES!!!” 💀 🪦
October 27, 2024 at 7:07 AM
Okay my feed is literally inspiring me to share some of my art. What is this feeling
October 27, 2024 at 5:26 AM
This 🖤
God I can't even begin to describe the euphoria of drawing being a thing that I not only seek out again but have started to absent minded chisel at when I'm at my computer.

I'll just be like "Tee hee, I shall make this little critter just for me." and then do that
October 27, 2024 at 5:25 AM
So I just found out that this is a thing. Here’s my #promosky

21+
Stephen King
William Shakespeare
Masters of Horror
Creepshow
Evil Dead
Resident Evil
2007’s Emo
Movies/TV
Animals
Art & Design
Technology
Neopets
Furby
Gremlins
Batman

Do your thing algorithm!
Looking for Mutuals ☠️✨
October 27, 2024 at 5:01 AM
Reposted by ✨ Cas ✨
I am done having anxiety I just decided. Thank you for tuning in for my new no anxiety journey
October 27, 2024 at 12:09 AM
Reposted by ✨ Cas ✨
Light Mode ☀️ Flash Bang

#art #toasttheraccoon #raccoon #animal
October 27, 2024 at 1:15 AM
Reposted by ✨ Cas ✨
I love when i feel motivated to write, i'm so excited
October 26, 2024 at 11:09 PM
Reposted by ✨ Cas ✨
Unpopular motivation hack for drawing:

Start drawing immediately, even if it feels impossible.

After 15 minutes, your brain will recognize the difficult task and create dopamine to help you keep going.

Agonizing endlessly before the drawing doesn't help your creative process.
October 26, 2024 at 12:56 PM
Reposted by ✨ Cas ✨
People with conflicting names...

Gary Numan vs Gary Oldman
Britney Spears vs Brooke Shields
Marvin Gaye vs George Strait
Diane Farr vs Glenn Close
Amber Heard vs Mos Def
Emily Blunt vs Pat Sharp
MC Hammer vs Jimmy Nail
Ruby Wax vs John Wayne
Orlando Bloom vs Jane Withers
Steve Swallow vs Mark Spitz
October 26, 2024 at 2:38 PM
Reposted by ✨ Cas ✨
The Good, the Bad and the Ugly in Cybersecurity – Week 41
The Good, the Bad and the Ugly in Cybersecurity – Week 41
The Good | Raccoon Infostealer Admin Pleads Guilty & Police Seize Two Extensive Dark Marketplaces This week marks two wins for global law enforcement groups, leading to the takedown of Raccoon Infostealer’s operator, Mark Sokolovsky, and two alleged administrators of the Bohemia dark market and its sister market, Cannabia. According to the DoJ , Sokolovsky, a Ukrainian national, pleaded guilty to running the Raccoon Infostealer , linked to the theft of sensitive data such as personally identifiable information (PII), bank account details, and cryptocurrency information . Sold as malware-as-a-service (MaaS), Raccoon Infostealer affected millions of users worldwide before it was dismantled by the FBI and international partners in 2022 . Although operators attempted a comeback in 2023 , Sokolovsky’s arrest and extradition to the U.S. in 2024 dealt a significant blow to the operation. In total, law enforcement recovered more than 50 million stolen credentials since the malware was seized. In another success, the alleged administrators of Bohemia and Cannabia, two leading dark marketplaces , were arrested after attempting to carry out an exit scam . Dutch police uncovered the extent of the marketplaces’ involvement in illegal drug sales and distributed-denial-of-service (DDoS) tools, which came out to an average of 67,000 transactions per month, generating a staggering €12 million in turnover by September 2023. Bohemia dark market seizure notice (Source: DarkWebInformer) The administrators’ attempt to shut down the sites and escape with funds was thwarted by authorities in the Netherlands, Ireland, the U.K., and the U.S. These arrests send a clear message: the dark web is not as anonymous as criminals think, and international collaboration is key to disrupting longstanding and complex criminal infrastructure. The Bad | GoldenJackal Deploys New Toolsets Against Government Air-Gapped Systems Two advanced toolsets used by little-known threat actor, GoldenJackal, have been identified in a string of cyberattacks on embassies and government organizations . These attacks, all focused on infiltrating air-gapped systems, share a common goal of stealing sensitive data that has been deliberately isolated from external connections like the internet. Air-gapping as a security practice is most typically seen for uber-sensitive networks or devices, such as those used for voting, manufacturing , and critical industrial services. Initial compromise of an air-gapped system (Source: ESET Research) GoldenJackal has been active since at least 2019 but gained widespread attention in May 2020 when it was linked to a cluster of attacks on diplomatic entities across South Asia and the Middle East. This week, cyber researchers offered insight into GoldenJackal’s completely revamped toolset within just five years, made apparent during its targeting of E.U. government organizations between 2022 and 2024. The new air-gapped infiltration techniques include malware families GoldenDealer, to infect USB drives and deliver malware to isolated systems, GoldenHowl, a backdoor that steals data and establishes remote access, and GoldenRobo, for exfiltrating data and files. GoldenJackel’s latest toolset (comprised of GoldenUsbCopy, GoldenUsbGo, GoldenAce, GoldenBlacklist, GoldenMailer, and GoldenDrive) is written in Go and engineered to drive malware propagation, perform data collection, and leverage machine servers to stage and distribute payloads to other hosts. While its initial compromise methods remain unclear, other researchers suspect that trojanized Skype installers and malicious Word documents are serving as entry points. GoldenJackal remains highly sophisticated and resourceful, creating and managing two bespoke toolsets to breach air-gapped networks in only five years . For now, the group’s advanced capabilities, especially in targeting segmented networks, highlight the growing threat to high-profile government and diplomatic systems. The Ugly | Mamba 2FA Phishing Kit Targets Corporate & Consumer Microsoft 365 Accounts An emerging predator in the adversary-in-the-middle (AiTM) phishing ecosystem has been targeting Microsoft 365 accounts through convincing login pages and various security evasion techniques. ‘ Mamba 2FA ’, a phishing-as-a-service (PhaaS) platform, is relatively new having first been documented in spring of this year. It enables threat actors to bypass multi-factor authentication (MFA) by capturing authentication tokens from victims . Sold for a considerably low cost of $250 per month, Mamba 2FA has quickly become one of the most attractive phishing platforms in the current market . Screenshots of four known Mamba 2FA phishing pages (Source: Sekoia) The Mamba 2FA kit is used to primarily target Microsoft 365 users, including corporate and consumer accounts, and offers advanced phishing templates for services like OneDrive, SharePoint, and Microsoft login pages. It enables attackers to customize phishing pages and reflect the branding of targeted organizations, adding credibility to the phishing attempt. Stolen MFA codes, credentials , and cookies are then sent to the attackers via Telegram bots, which allow them to hijack user sessions immediately. Most recently, Mamba 2FA has improved its stealth tactics by using proxy servers from a commercial provider called ‘IPRoyal’ to hide relay server IPs, rotate phishing link domains weekly, and embed malicious JavaScript in benign-looking HTML attachments. These capabilities make it difficult for organizations to detect unusual logins. Another key feature of Mamba 2FA is its use of sandbox detection to redirect analysis attempts to Google 404 pages instead to throw security teams off its scent . Phishing continues to top the ways attackers steal sensitive data and deploy malware. Given Mamba 2FA’s accessibility to non-technical and low-skilled cybercriminals, the kit has become a potent threat. To defend against sophisticated AiTM phishing tactics, organizations can implement hardware security keys, certificate-based authentication, geo-blocking, IP and device allowlisting, and limit token lifespans.
www.sentinelone.com
October 26, 2024 at 9:17 PM
Sleepy day today with the familia. Loving this blessing 🙏🏽
October 27, 2024 at 1:02 AM
Reposted by ✨ Cas ✨
We can make it if we try
October 26, 2024 at 2:21 AM
Today I resolved an org-wide issue we've been tackling since May. my brain is potatoes & senior engineer is currently spending EOB mansplaining why the fix was wrong while also not understanding what exactly the fix was👍CLOCKING OUT NOW :) Happy Friday Y'all!
a man in a suit is saying for that reason i 'm out .
ALT: a man in a suit is saying for that reason i 'm out .
media.tenor.com
October 25, 2024 at 11:36 PM
IT is doing some good work today. Soaring past those KPI’s, pushing boundaries, and doing all of the hard things….loving these vibes!
October 25, 2024 at 9:14 PM
I did the thing! 🥇
October 25, 2024 at 5:35 PM