Liam Lynch :donor:

❤ Dogs | nice photos tagged as #LiamsSky
I'm based in Ireland, in a rural location in County Tipperary, close to Limerick City. I'm a cybers trainer and consultant for micro, small and medium businesses and charities. I feel strongly about helping to protect these folk, as they typically don't have the resources that larger orgs can leverage. So I show them, in very simple terms, how they can easily and cheaply protect themselves and their organisations from the evil doers. I live to the maxim #SecuritySimplified as that is how I deliver the training and support.

Liam Lynch :donor: boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2025-05-06

SANS Stormcast Tuesday, May 6th: Mirai Exploiting Samsung magicInfo 9; Kali Signing Key Lost;
isc.sans.edu/podcastdetail/9438

image of sans internet stormcenter logo with stormcast flair
Liam Lynch :donor: boosted:
2025-05-05

Defensive Security Podcast Episode 305

In this episode, we discuss the Google Mandiant 2025 M-Trends report.  The report is available here: Like what we’re doing and want to help support us? Donate here: 

defensivesecurity.org/defensiv

Liam Lynch :donor: boosted:
2025-05-05

For the past year I’ve been working on a committee to produce a consensus report on Cyber Hard Problems for the National Academies of Science, Engineering and Medicine. The report, commissioned by the White House, is finally going to be released on May 15th, and you can join this public webinar to hear about it: nationalacademies.org/event/45

There are too many people to thank, from the NASEM staff to the committee members, subject matter experts who presented to us, and the anonymous reviewers (you know who you are, and now so do I 😉).

Liam Lynch :donor: boosted:
2025-05-05

One of the points of exploitation of large orgs is they usually outsource their Service Desk to somewhere cheap offshore who don’t know the org staff, and when you call and say your name, they normally put big all caps bold red warning if the person is a VIP, eg C suite, so they get VIP service - ie anything goes.

Liam Lynch :donor: boosted:
2025-05-05

I’ve been using Recall for a few weeks now on my daily driver.

It scooped up my credit card statements after I logged into online banking - both screenshots (text indexed) of the PDFs, transaction history from the website, and my name, date of birth and security question reminders.

Sensitive filtering mode only kicked in when I viewed my cards CVV number.

Worth excluding bank websites from Recall’s options, if you see it enabled.

Liam Lynch :donor: boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2025-05-05

SANS Stormcast Monday, May 5th: Steganography Challenge; Microsoft Makes Passkeys Default and Moves Away from Authenticator as Password Manager; Magento Components Backdoored.
isc.sans.edu/podcastdetail/9436

image of sans internet stormcenter logo with stormcast flair
Liam Lynch :donor: boosted:
Zack Whittakerzackwhittaker
2025-05-04

If you're a fan of cyber news but don't know where to begin, my free newsletter ~ this week in security ~ is a weekly roundup of all the cyber news you need to know, plus the happy corner and a weekly featured cyber cat. No email open or link tracking.

Out Sundays. Sign up now to get this week's edition.

this.weekinsecurity.com/

Liam Lynch :donor: boosted:
2025-05-04

Attention Montréal! I’ll be tag-teaming with the amazing @hdm to bring you some fun talks to go with all the brilliant speakers making up @NorthSec this month. When I’m not at the conference, you’ll find me making a pilgrimage to St.-Viateur 🥯

nsec.io/schedule/

Liam Lynch :donor: boosted:
2025-05-04

A wrote a piece about paying ransoms does not equal quick restoration - in fact, quite often it makes things worse. doublepulsar.com/big-game-rans

Liam Lynch :donor: boosted:
2025-05-03
Liam Lynch :donor: boosted:
2025-05-03

I'm going to make this the new ongoing megathread for DragonForce Ransomware Cartel's attack on UK retailers as they're all connected.

Why it matters: these are some of the UK's largest retailers, think Target or some such in a US sense.

Prior threads

M&S: cyberplace.social/@GossiTheDog

Co-op: cyberplace.social/@GossiTheDog

Harrods:
cyberplace.social/@GossiTheDog

Liam Lynch :donor: boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2025-05-02

SANS Stormcast Thursday, May 1st: More Steganography; Malicious Python Packages GMail C2; BEC to Steal Rent Payments
isc.sans.edu/podcastdetail/9434

image of sans internet stormcenter logo with stormcast flair
Liam Lynch :donor: boosted:
2025-05-02

I would also draw UK cyber defenders attention to review this document and strengthen MFA and their service desks.

In particular, high street brands visible in Greater London area.

cisa.gov/sites/default/files/2

Liam Lynch :donor: boosted:
2025-05-02

Mastodon has taken the strategic decision not to accept venture capital investments for growth, but rather restructure to a European non-profit organisation. 👏

blog.joinmastodon.org/2025/05/

Liam Lynch :donor: boosted:
2025-05-01

Remembering Ayrton Senna da Silva 🇧🇷
21st March, 1960 – 1st May, 1994
#F1 #Formula1

A racing driver is seated in a car, wearing a yellow helmet with brand logos on it. The visor is slightly open, revealing the driver's eyes looking upwards and to their left.Black and white portrait of a racing driver (Ayrton Senna) with curly hair, gazing thoughtfully into the distance. The individual is wearing a Williams racing suit with a "Rothmans" logo on the collar.
Liam Lynch :donor: boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2025-05-01

SANS Stormcast Thursday, May 1st: Sonicwall Attacks; Cached Windows RDP Credentials
isc.sans.edu/podcastdetail/9432

image of sans internet stormcenter logo with stormcast flair
Liam Lynch :donor: boosted:
2025-04-30

Two things about that -

You might look at 2341 orgs and think 'wow, that's more victims than all ransomware a year! how have I never heard of this group?'.

Answer: most groups don't have portals and don't list victims. They just extort SMBs. Ransomware is massively under reported. Threat intelligence has become scraping ransomware group portals, but a vast majority of victims aren't on them.

You might also think 'aren't all ransomware groups Russian?'.

Answer: Nope.

Liam Lynch :donor:L2actual@infosec.exchange
2025-04-30

Thanks @faduda I was trying to place the tune.

Liam Lynch :donor: boosted:
Zack Whittakerzackwhittaker
2025-04-30

If there's one thing I've learned about covering cybersecurity over the past decade or so, is that the cybersecurity community (the fixers and breakers) and the cybersecurity industry (profits above all else) are two very, very different things.

Liam Lynch :donor: boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2025-04-30

SANS Stormcast Wednesday, April 30th: SMS Attacks; Apple Airplay Vulnerabilities
isc.sans.edu/podcastdetail/9430

image of sans internet stormcenter logo with stormcast flair

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst