allan

Allan Liska, CSIRT at Recorded Future, Author, Certified Sommelier and Struggling Photographer

2024-06-30

Congratulations to @zackwhittaker for 6 years of incredible newsletters! Absolutely one of my must reads every Sunday (except next Sunday)!

allan boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2024-03-19

Decreasing #ransomware attacks: two strategies to consider:

databreaches.net/decreasing-ra

See what you think.

N.B. My site continues to be under attempted massive #DDoS attacks. This post probably won't help me, but screw it. :)

@brett @allan @GossiTheDog @euroinfosec @campuscodi

allan boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2024-03-05

So now there's a seizure notice on the newer AlphV leak site onion. But is it real or did AlphV just copy/paste the first one to the new site as part of an exit scam?

There has been no press release from DOJ. For now, I'm thinking this is a fake. Prove me wrong.

Updated: Some proof has been provided that it's fake:
mastodon.social/@campuscodi/11

@brett @briankrebs @allan
#Alphv #Exit #ransomware

allan boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2024-02-27

#AlphV #BlackCat has confirmed to me that they are responsible for the Change Healthcare #databreach that is having major impact on pharmacies and hospitals throughout the country.

databreaches.net/yes-change-he

#infosec #healthsec #ransomware

@brett @allan @BleepingComputer @carlypage @Reuters

2024-01-10

@potatogunkelly @howelloneill I also use Protonmail for everything. I like the privacy aspect, and the interface is really nice (or, I am just really used to it).

2024-01-10

@spiegelmama thank you for sharing and appreciate the support!

allan boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2024-01-10

If the purpose of a substitute notice under #HIPAA is to reach people the covered entity may not have sufficient or current contact information for, then burying the notice on the very bottom of the homepage and calling it a “privacy update” as if it is an update to the privacy policy is misleading at best.

Yesterday, I reported on a data breach disclosure by HMG Healthcare. You can read more here:

databreaches.net/hmg-healthcar

#databreach #HealthSec #cybersecurity #infosec #transparency #disclosure

@brett @allan

2023-08-01

@brett @PogoWasRight no, it hasn’t shown up anywhere I follow.

allan boosted:
Zack Whittakerzackwhittaker
2023-06-04

A new ~this week in security~ is now out:

• FTC says Ring snooped on customer videos
• Kaspersky staff hacked with unknown iOS malware
• Gigabyte motherboard sold with firmware backdoors
• Hackers exploiting MOVEit transfer tool zero-day
• Toyota apologizes for a new customer data leak
• Two huge healthcare data breaches
• A brand new cyber cat

Sign up: this.weekinsecurity.com/

Read online: mailchi.mp/zackwhittaker/this-

2023-04-13

@PogoWasRight @akmartinez @brett @briankrebs @lawrenceabrams @campuscodi
And, just because you paid for the decryptor doesn’t mean those other costs go away. You still have to do forensic analysis and the restore costs are still expensive. So, you have the original costs plus the cost of the ransom.

2023-04-04

@PogoWasRight @brett @Checkpoint @swidup

The Cl0p numbers throw things off a bit, because those leaks were really fast, but I think in general you are correct.

2022-12-14

Like to see this proactive work on the part of the US government to combat ransowmare.

therecord.media/us-finds-its-c

2022-12-12

@jerry wow, that is beautiful!

allan boosted:
Zack Whittakerzackwhittaker
2022-12-12

New, by me: Meet Xnspy, a little-known stalkerware app that has compromised tens of thousands of iPhones and Android devices worldwide. Xnspy's developers kept a low profile, but data seen by TechCrunch links the stalkerware to a Lahore-based startup called Konext.

More: techcrunch.com/2022/12/12/xnsp

a blurred and redacted screenshot of Xnspy's website, which advertises its spyware as a way to spy on a spouse or domestic partner.
2022-12-12

While numbers on extortion sites are down, that doesn’t mean that ransomware attacks are down. But, still an interesting trend to watch.

therecord.media/ransomware-tra

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst