home.social

#operationalsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #operationalsecurity, aggregated by home.social.

  1. Incident Response Readiness Exposes Operational Gaps

    Being incident response ready means more than just having a plan - it requires immediate visibility into identity and authentication access, including investigator-level read access to crucial systems. Without this visibility, teams are left making blind containment decisions and piecing together timelines with guesswork.

    osintsights.com/incident-respo

    #IncidentResponse #IdentityAndAccessManagement #Mfa #OperationalSecurity #EmergingThreats

  2. Threat Actors Formalize Operational Security Playbook

    Cybercrime players are now treating operational security as a sophisticated game-changer, and it's time for you to level up your security strategy beyond just using VPNs. A battle-tested three-tier infrastructure model has emerged, separating exposure, execution, and monetization to safeguard high-stakes operations.

    osintsights.com/threat-actors-

    #OperationalSecurity #CardingOperations #ThreatActors #Vpns #Cybercrime

  3. Managed Detection and Response Targets Gaps in Cyber Defenses

    State, local, tribal, and territorial organizations, along with their schools, are facing a perfect storm of rising cyber threats, limited staff, and tight budgets - making it tough to stay ahead of attacks. Managed Detection and Response can help bridge the gaps in their cyber defenses, providing the support…

    osintsights.com/managed-detect

    #ManagedDetectionResponse #EmergingThreats #OperationalSecurity #CyberDefenses #EducationSector

  4. New on The Sovereign Auditor.
    The FBI recovered deleted Signal messages from an iPhone -- not by breaking encryption, but from Apple's push notification database. Signal had been deleted. The notifications hadn't.
    The fix is one setting. But the lesson is bigger than that.
    open.substack.com/pub/sovereig
    #Signal #Privacy #OperationalSecurity #InfoSec #OPSEC

  5. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  6. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  7. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  8. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  9. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  10. 🔐 Secure Connectivity as Crisis Infrastructure
    Internews’ 2025 findings demonstrate a clear pattern: when VPN access declines, exposure to phishing, surveillance, and account compromise increases rapidly.

    With pro-bono Surfshark support:
    • 100 high-risk partners protected
    • 9 countries impacted
    • Field-based digital security training delivered
    • One-year VPN access deployed to journalists and activists

    In hostile environments, encrypted traffic and secure authentication workflows directly affect operational safety.

    Is the cybersecurity sector allocating sufficient resources toward safeguarding independent media?

    Source: internews.org/wp-content/uploa

    Share your insights below.
    Follow TechNadu for continued coverage on digital risk, cyber resilience, and global privacy developments.

    #InfoSec #CyberResilience #DigitalRights #VPNInfrastructure #OperationalSecurity #ThreatIntelligence #PressFreedom

  11. 🔐 Secure Connectivity as Crisis Infrastructure
    Internews’ 2025 findings demonstrate a clear pattern: when VPN access declines, exposure to phishing, surveillance, and account compromise increases rapidly.

    With pro-bono Surfshark support:
    • 100 high-risk partners protected
    • 9 countries impacted
    • Field-based digital security training delivered
    • One-year VPN access deployed to journalists and activists

    In hostile environments, encrypted traffic and secure authentication workflows directly affect operational safety.

    Is the cybersecurity sector allocating sufficient resources toward safeguarding independent media?

    Source: internews.org/wp-content/uploa

    Share your insights below.
    Follow TechNadu for continued coverage on digital risk, cyber resilience, and global privacy developments.

    #InfoSec #CyberResilience #DigitalRights #VPNInfrastructure #OperationalSecurity #ThreatIntelligence #PressFreedom

  12. 🔐 Secure Connectivity as Crisis Infrastructure
    Internews’ 2025 findings demonstrate a clear pattern: when VPN access declines, exposure to phishing, surveillance, and account compromise increases rapidly.

    With pro-bono Surfshark support:
    • 100 high-risk partners protected
    • 9 countries impacted
    • Field-based digital security training delivered
    • One-year VPN access deployed to journalists and activists

    In hostile environments, encrypted traffic and secure authentication workflows directly affect operational safety.

    Is the cybersecurity sector allocating sufficient resources toward safeguarding independent media?

    Source: internews.org/wp-content/uploa

    Share your insights below.
    Follow TechNadu for continued coverage on digital risk, cyber resilience, and global privacy developments.

    #InfoSec #CyberResilience #DigitalRights #VPNInfrastructure #OperationalSecurity #ThreatIntelligence #PressFreedom

  13. 🔐 Secure Connectivity as Crisis Infrastructure
    Internews’ 2025 findings demonstrate a clear pattern: when VPN access declines, exposure to phishing, surveillance, and account compromise increases rapidly.

    With pro-bono Surfshark support:
    • 100 high-risk partners protected
    • 9 countries impacted
    • Field-based digital security training delivered
    • One-year VPN access deployed to journalists and activists

    In hostile environments, encrypted traffic and secure authentication workflows directly affect operational safety.

    Is the cybersecurity sector allocating sufficient resources toward safeguarding independent media?

    Source: internews.org/wp-content/uploa

    Share your insights below.
    Follow TechNadu for continued coverage on digital risk, cyber resilience, and global privacy developments.

    #InfoSec #CyberResilience #DigitalRights #VPNInfrastructure #OperationalSecurity #ThreatIntelligence #PressFreedom

  14. POV: You want to find love but also take care of your #OPSEC.

    ✅ Here are 5️⃣ good habits to strengthen your #OPSEC (you probably don’t know the last one):

    1️⃣ Limit what you share on social media (workplace, family/friends, location) and set your personal accounts to private.

    2️⃣ Avoid using the same usernames across different platforms.

    3️⃣ Keep your operating system and apps up to date.

    4️⃣ Use long, unique passwords and a password manager.

    5️⃣ Turn on lockdown mode on your phone when attending events, conferences, or corporate gatherings.

    🔎 As a reminder, OPSEC stands for #OperationalSecurity. It refers to a set of methods and best practices designed to prevent an adversary from obtaining sensitive information about you by observing, collecting, or inferring details that may seem harmless.

    👉 Follow Epieos for more tips and tricks related to #OSINT.

  15. Cell Phone OPSEC for Border Crossings

    I have heard stories of more aggressive interrogation of electronic devices at US border crossings. I know a lot about securing computers, but very little about securing phones.
    Are there easy ways to delete data—files, photos, etc.&#... schneier.com/blog/archives/202

    #operationalsecurity #Uncategorized #cellphones #borders

  16. The news that snr ofcls in the #Trump admin discussed plans on #Signal, a commercial messaging app, for an impending attack angered & bewildered those who have taken to the air on behalf of the #US.

    The mistaken inclusion of the editor of #TheAtlantic in the chat & #Hegseth’s insistence that he did nothing wrong by disclosing the secret plans upend decades of #military doctrine about #OperationalSecurity, a dozen #AirForce & #Navy fighter pilots said.

    #law #NationalSecurity #SignalGate

  17. #MikeWaltz Left His #Venmo Friends List Public

    A WIRED review shows national #security adviser Mike Waltz, #WhiteHouse chief of staff #SusieWiles , and other top officials left sensitive information exposed via Venmo—until WIRED asked about it.

    > looks like these folks don’t understand the concept of basic operational #security

    #opsec #operationalsecurity #privacy

    wired.com/story/michael-waltz-

  18. Watch it here ➫ youtu.be/u349u65BJLg
    Two darknet markets, two outcomes: Atlas Market succeeded with competence and trust, while Vortex Market collapsed under admin mistakes. This is a clear lesson in why OPSEC and professionalism matter.
    #DarknetMarkets #AtlasMarket #VortexMarket #HiddenWeb #CyberSecurity #OperationalSecurity

  19. Watch it here ➫ youtu.be/u349u65BJLg
    Two darknet markets, two outcomes: Atlas Market succeeded with competence and trust, while Vortex Market collapsed under admin mistakes. This is a clear lesson in why OPSEC and professionalism matter.
    #DarknetMarkets #AtlasMarket #VortexMarket #HiddenWeb #CyberSecurity #OperationalSecurity

  20. Did you miss last week's podcast with @dragosinc's @hacks4pancakes? In this episode of the Breaking Badness Cybersecurity Podcast, Lesley joins @NotTheLinux and @danonsecurity to share insights on OT challenges, incident response, and bridging the gap between cyber and operations. Don’t miss out on this enlightening discussion! 🎙️

    🎧 Listen here: domaintools.com/resources/podc

    #cybersecurity #CyberPodcast #IncidentResponse #OperationalTechnology #OperationalSecurity

  21. "LockBit's Bold Return: A Threat Renewed 🚨 #CyberAlert"

    Despite recent crackdowns, the notorious LockBit ransomware gang has defiantly announced a comeback, threatening new cyber onslaughts on government sectors in the UK and USA. Leveraging a previously exploited PHP vulnerability, they've bounced back, boasting updated security measures and a new dark web haunt for victim listings. This follows a brief hiatus post-Operation Cronos, highlighting the resilient and adaptive nature of cyber threats today. LockBit's strategy now includes manual decryptor releases and rewards for vulnerability reports, underlining an intensified focus on operational security to thwart future law enforcement infiltrations. Stay vigilant, stay informed. #LockBit #CyberSecurity #RansomwareResurgence #ThreatIntelligence #DigitalDefense

    Source: HackRead

    Tags: #APT #CyberCrime #InfoSec #SecurityAwareness #CyberThreats #GovernmentSecurity #OperationalSecurity #PHPVulnerability 🌐🔒💡

  22. If your first instinct is to try and find blame when a security vulnerability is pointed out...

    ...you have already created an environment where everyone will hide issues from you.

    You currently live in a fake reality where you think everything is fine and you have no idea the rot that is underneath you.

    If you fire or punish a person every time a vulnerability is found, you will have no one left. Hell, fire yourself first to save us all the trouble.

    Vulnerabilities exist. The world changes. Software changes. Attacks change. Business needs change.

    Life is fucking impermanence.

    So create an environment where folks come to you quickly and tell you what needs to be fixed as they find it.

    How do you do that?! Reward vulnerability discovery. Reward mitigations. Reward patch management. Reward security improvement. Reward safety improvement.

    #informationsecurity #infosec #operationalsecurity #opsec #ics #ot