Superfluous Sec
superfluoussec.bsky.social
Superfluous Sec
@superfluoussec.bsky.social
Hacker, Infosec Nerd, Cyber Security
Reposted by Superfluous Sec
It looks like Microsoft has been quietly updating its 2023 new APT naming table with new entries

The table used to have 20-30 entries... it's now gigantic!

Bookmark it: learn.microsoft.com/en-gb/unifie...
March 16, 2025 at 6:44 PM
Reposted by Superfluous Sec
Happy Birthday to ME,!!
March 17, 2025 at 2:41 AM
Reposted by Superfluous Sec
Microsoft wouldn't look at a bug report without a video. Researcher maliciously complied
Researcher trolls Microsoft over bug disclosure annoyance
: Maddening techno loop, Zoolander reference, and 14 minutes of time wasted
www.theregister.com
March 17, 2025 at 9:50 AM
Reposted by Superfluous Sec
"Over 100 auto dealerships were being abused compliments of a supply chain attack of a shared video service unique to dealerships. When active, the attack presented dealership visitors with a ClickFix webpage which led to a SectopRAT malware."

rmceoin.github.io/malware-anal...
March 17, 2025 at 6:15 PM
Reposted by Superfluous Sec
Amazon boots local Alexa processing: All your voice requests shipped to the cloud
Amazon kills off on-device Alexa processing for Echo owners
: Web souk says Echo hardware doesn't have the oomph for next-gen AI anyway
www.theregister.com
March 17, 2025 at 9:31 PM
Reposted by Superfluous Sec
Cloud security firm Permiso has open-sourced RansomWhen, a tool to enumerate cloud identities that can lock S3 buckets, resulting in possible ransomware attacks

permiso.io/blog/ransomw...

github.com/Permiso-io-t...
RansomWhen - An open-source tool to help defenders counter KMS-based ransomware
RansomWhen is a customizable Python-based tool designed to aid defenders in countering KMS-based ransomware scenarios. Detect potential ransomware attempts for a specific account based on evidence in ...
permiso.io
February 6, 2025 at 4:17 PM
Reposted by Superfluous Sec
Smashing Security podcast episode 403 with special guest Geoff White!

Coinbase crypto heists, QR codes, and ransomware in the classroom.

Find it in all good podcast apps, or at
Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom
In episode 403 of “Smashing Security” we dive into the mystery of $65 million vanishing from Coinbase users faster than J-Lo slipped into Graham’s DMs, Geoff gives a poor grade for PowerSchool’s…
grahamcluley.com
February 6, 2025 at 5:39 PM
Reposted by Superfluous Sec
Zero-day (CVE-2025-0994) patched in Trimble CityWorks, a platform used for remote asset management in water utility networks

learn.assetlifecycle.trimble.com/i/1532182-ci...
February 6, 2025 at 6:07 PM
Reposted by Superfluous Sec
Agencies Sound Alarm on Patient Monitors With Hardcoded Backdoor
Agencies Sound Alarm on Patient Monitors With Backdoor
www.darkreading.com
February 6, 2025 at 9:37 PM
Reposted by Superfluous Sec
EU prosecutors have launched an investigation into French IT and cybersecurity group Atos for using its Russian staff to build the EU's new electronic border system 🤦‍♂️🤦‍♀️🤦‍♂️🤦‍♀️🤦‍♂️🤦‍♀️

archive.ph/iD5LQ
February 6, 2025 at 12:44 PM
Reposted by Superfluous Sec
the end of an era
February 5, 2025 at 3:55 AM
Reposted by Superfluous Sec
Microsoft script updates bootable media for BlackLotus bootkit fixes
Microsoft script updates bootable media for BlackLotus bootkit fixes
Microsoft has released a PowerShell script to help Windows users and admins update bootable media so it utilizes the new "Windows UEFI CA 2023" certificate before the mitigations of the BlackLotus UEFI bootkit are enforced later this year.
www.bleepingcomputer.com
February 5, 2025 at 11:31 PM
Reposted by Superfluous Sec
International Civil Aviation Organization (ICAO) and ACAO Breached: Cyberespionage Groups Targeting Aviation Safety Specialists
International Civil Aviation Organization (ICAO)
The International Civil Aviation Organization (ICAO), a specialized agency of the United Nations, is investigating a significant data breach
securityaffairs.com
February 5, 2025 at 9:09 AM
Reposted by Superfluous Sec
Podcast: risky.biz/RBNEWS385/
Newsletter: risky.biz/risky-bullet...

-Crypto-stealer makes it on the iOS App Store for the first time
-GrubHub discloses security breach
-Russia hacked Keir Starmer's personal email
-Google patches Android zero-day
-Thailand to cut power to scam center regions
February 5, 2025 at 10:40 AM
Reposted by Superfluous Sec
New Process Hollowing Attack Vectors Uncovered in Windows 11 (24H2)
New Process Hollowing Attack Vectors Uncovered in Windows 11 (24H2)
cybersecuritynews.com
February 3, 2025 at 2:33 AM
Reposted by Superfluous Sec
WhatsApp disrupted a hacking campaign targeting journalists with Paragon spyware
WhatsApp disrupted a hacking campaign targeting journalists with Paragon spyware
Meta announced the disruption of a malware campaign via WhatsApp that targeted journalists with the Paragon spyware.
securityaffairs.com
February 2, 2025 at 2:58 PM
Reposted by Superfluous Sec
NSSFOCUS has some details on that week-long DDoS attack that targeted DeepSeek

"The attacker shows great pertinence and high tactical literacy"

nsfocusglobal.com/the-undercur...
February 2, 2025 at 2:52 PM
Reposted by Superfluous Sec
More than 1,000 GitHub repositories at risk: how to detect RepoJacking vulnerabilities
More than 1,000 GitHub repositories at risk: how to detect RepoJacking vulnerabilities
In 2024, GitLab developers discovered two critical vulnerabilities in their system. Due to verification errors, attackers could hijack user…
infosecwriteups.com
February 2, 2025 at 10:08 AM
Reposted by Superfluous Sec
Multiple high-profile accounts have been hacked over the past week to promote various memecoins.

Known victims so far:

Snopes
TIME Magazine
NASDAQ
Tor Project
former Brazilian president Jair Bolsonaro
Twitch streamer Asmongold
Breaking Bad actor Dean Norris
Various crypto-bros
February 2, 2025 at 5:42 PM
Reposted by Superfluous Sec
tl;dr WhatsApp fixed the vuln on the back end, so you don't need to do anything to your phone, up to and including enabling Lockdown mode. Paragon Solutions sucks and you should be mad at them for enabling spying on civil society.

www.theguardian.com/technology/2...
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware
www.theguardian.com
January 31, 2025 at 11:17 PM
Reposted by Superfluous Sec
Silent Push has discovered a Chinese CDN that rents IPs from major could providers and makes them available to various cybercrime operations.

FUNNULL has hosted phishing portals, online romance scams, and gambling sites linked to money laundering operations.

www.silentpush.com/blog/infrast...
Infrastructure Laundering: Silent Push Exposes Cloudy Behavior Around FUNNULL CDN Renting IPs from Big Tech
Infrastructure Laundering is a criminal practice of intermediaries enabling threat actors to hide infrastructure with major cloud providers.
www.silentpush.com
February 1, 2025 at 9:28 PM
Reposted by Superfluous Sec
Hackers have breached and leaked the code of Texas-based healthcare software provider Apex Custom Software

databreaches.net/2025/01/30/e...
February 1, 2025 at 10:54 PM
Reposted by Superfluous Sec
A group of security researchers have found a LAN-exploitable RCE in Marvel Rivals, one of today's most popular FPS games.

shalzuth.com/Blog/IFoundA...
February 1, 2025 at 11:28 PM
Reposted by Superfluous Sec
HPE is investigating IntelBroker’s claims of the company hack
HPE is investigating IntelBroker's claims of the company hack
HPE is probing claims by the threat actor IntelBroker who is offering to sell alleged stolen source code and data from the company.
securityaffairs.com
January 21, 2025 at 12:07 AM