#SilverFox

2026-01-10

Mate says "how can you walk around in full leather and never get any comments?"

Me "cos I look like a nasty piece of work who could really mess you up"

Fedi - if you ever see me in the street, please chat - I'm actually very friendly. Remember looks are very deceiving.

#leather #piercings #baldguysaresexy #baldy #baldguy #silverfox #scarylooking

A selfie. I'm on a bus and wearing full leather. I'm a 52 year old male with tattoos, piercings and a bald head. My demeanor is quite scary but I'm actually really friendly.
2025-12-30

Alright team, it's been a pretty packed 24 hours in the cyber world! We've got a mix of significant breaches, an actively exploited vulnerability making waves, new insights into nation-state and cybercrime tradecraft, and some interesting discussions around AI security and regulation. Let's dive in:

Recent Cyber Attacks and Breaches ⚠️

Coinbase Insider Threat & Fraud 💸
- An ex-Coinbase customer service agent in India has been arrested for allegedly selling customer data to criminals, leading to social engineering scams and an attempted $20 million extortion against Coinbase.
- The stolen data included names, addresses, phone numbers, emails, IDs, and bank info for nearly 70,000 customers, though no 2FA codes or private keys were compromised.
- This highlights the critical risk of insider threats, especially in outsourced customer service operations, and the ongoing challenge of social engineering attacks targeting crypto users.
🕵🏼 The Register | go.theregister.com/feed/www.th

Coupang Data Breach & Compensation 🛍️
- South Korean retail giant Coupang is set to distribute $1.17 billion in compensation to 33.7 million customers affected by a data breach discovered in November.
- The breach, one of South Korea's largest, was traced to a 43-year-old Chinese former IT employee who retained system access after leaving the company, accessing 33 million accounts and retaining data from about 3,000.
- While the company claims the data was not transferred or further misused, the incident underscores the severe financial and reputational costs of insider threats and poor identity and access management.
🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Korean Telco Femtocell Security Failure 📞
- Korea Telecom (KT) deployed thousands of femtocells with critical security flaws, including shared certificates, no root passwords, plaintext keys, and enabled SSH, leading to micropayment fraud and potential customer communication snooping.
- Attackers cloned femtocells, enabling them to read SMS messages and call logs, with one fake femtocell used for ten months, and a large gang involved in "war-driving" to find more phones.
- This incident exposes severe vulnerabilities in critical infrastructure, suggesting that the $169,000 in micropayment fraud might be a smokescreen for larger-scale surveillance, with one key even linked to a military base.
🕵🏼 The Register | go.theregister.com/feed/www.th

Cybersecurity Experts Plead Guilty to BlackCat Ransomware Attacks 🚨
- Two former cybersecurity incident response professionals, Ryan Goldberg (Sygnia) and Kevin Martin (DigitalMint), have pleaded guilty to conspiring to obstruct commerce by extortion using BlackCat (ALPHV) ransomware.
- They leveraged their expertise to breach multiple US organisations, demanding ransoms up to $10 million and receiving $1.27 million from one victim, with 20% going to ALPHV administrators.
- This shocking case highlights the severe risk of insider threats within the cybersecurity industry itself and the importance of due diligence when engaging third-party incident response firms.
🤖 Bleeping Computer | bleepingcomputer.com/news/secu
🗞️ The Record | therecord.media/ransomware-res

European Space Agency Confirms External Server Breach 🛰️
- The European Space Agency (ESA) has confirmed a breach of "external servers" containing unclassified information related to collaborative engineering activities, following claims by a threat actor on BreachForums.
- The attackers claim to have stolen over 200GB of data, including source code, CI/CD pipelines, API tokens, and hardcoded credentials, after accessing ESA's JIRA and Bitbucket servers for a week.
- While ESA states the impact is limited to a "very small number of external servers" and unclassified data, the nature of the stolen data (source code, API tokens) suggests potential for further compromise or intellectual property theft.
🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Vulnerabilities Under Active Exploitation 🛡️

MongoBleed (CVE-2025-14847) Under Active Exploitation ⚠️
- A high-severity information-disclosure vulnerability, CVE-2025-14847 (dubbed "MongoBleed"), affecting many default MongoDB versions, is now under active exploitation in the wild.
- The flaw, stemming from mismatched length fields in zlib-compressed protocol headers, allows unauthenticated attackers to leak server memory, potentially exposing sensitive data like credentials, API keys, and PII.
- CISA has added MongoBleed to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to patch by January 19, 2026, with estimates of 74,000 to 87,000 internet-exposed vulnerable instances globally. If immediate patching isn't possible, disabling zlib compression is advised.
🤫 CyberScoop | cyberscoop.com/mongobleed-vuln
🗞️ The Record | therecord.media/us-australia-b
🤖 Bleeping Computer | bleepingcomputer.com/news/secu
🕵🏼 The Register | go.theregister.com/feed/www.th

New Threat Research and Tradecraft 🔬

Mustang Panda Uses Kernel-Mode Rootkit for ToneShell Backdoor 🐼
- The Chinese state-sponsored group Mustang Panda (aka HoneyMyte or Bronze President) is deploying a new variant of its ToneShell backdoor using a previously undocumented kernel-mode rootkit driver.
- This rootkit, signed with a stolen or leaked certificate, registers as a mini-filter driver to evade user-mode monitoring, protect its files and processes, and interfere with Microsoft Defender, giving it high stealth and persistence.
- The evolved TTPs, including dynamic API resolution and network traffic obfuscation, highlight Mustang Panda's increasing sophistication in targeting government organisations in Southeast and East Asia, making memory forensics crucial for detection.
🤖 Bleeping Computer | bleepingcomputer.com/news/secu
📰 The Hacker News | thehackernews.com/2025/12/must

Silver Fox Targets India with ValleyRAT Malware 🦊
- The Chinese cybercrime group Silver Fox (aka SwimSnake) is now targeting Indian users with tax-themed phishing emails to distribute its modular ValleyRAT (Winos 4.0) remote access trojan.
- The sophisticated kill chain involves DLL hijacking via a legitimate executable (Thunder) and a Donut loader, performing anti-analysis checks before injecting ValleyRAT into explorer.exe.
- Silver Fox also uses SEO poisoning and fake application sites (e.g., Microsoft Teams, Signal) to spread ValleyRAT globally, demonstrating a multi-pronged approach for espionage, financial gain, and intelligence collection.
📰 The Hacker News | thehackernews.com/2025/12/silv

Zoom Stealer Browser Extensions Harvest Corporate Meeting Intelligence 🕵️‍♀️
- A campaign dubbed "Zoom Stealer," attributed to the China-linked threat actor DarkSpectre, is affecting 2.2 million Chrome, Firefox, and Edge users through 18 malicious browser extensions.
- These extensions, some functional as video downloaders or recorders, covertly collect sensitive meeting-related data (URLs, IDs, topics, embedded passwords, speaker info) from 28 video-conferencing platforms.
- The exfiltrated data, streamed in real-time, is likely used for corporate espionage, sales intelligence, and large-scale social engineering or impersonation operations, underscoring the need for careful extension permission review.
🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Threat Landscape Commentary 🗣️

OpenAI: Prompt Injection May Never Be 'Solved' for Browser Agents 🤖
- OpenAI warns that prompt injection is a central security risk for AI browser agents like ChatGPT Atlas, which operate within a web browser and can carry out tasks for users.
- Internal red-teaming uncovered new complex prompt-injection attacks, leading to a security update with an adversarially trained model and strengthened safeguards.
- The company acknowledges that prompt injection may never be fully mitigated, advising a focus on risk reduction and limiting impact, as content designed to persuade humans can now command AI agents.
🤫 CyberScoop | cyberscoop.com/openai-chatgpt-

Regulatory Issues 🏛️

Fragmented AI Regulation Poses Challenges ⚖️
- The rapid, uncoordinated expansion of state-level AI regulations in the US is creating a "patchwork regulatory landscape" that hinders responsible AI development and security.
- Conflicting definitions, compliance, and enforcement approaches across states disproportionately burden small and midsize companies, stifling innovation and allowing larger firms to gravitate towards less stringent rules.
- A unified federal framework is urgently needed to establish clear expectations for transparency, accountability, and responsible innovation, ensuring consistent safeguards and a more secure AI ecosystem.
🤫 CyberScoop | cyberscoop.com/ai-regulation-u

Sponsored Content 📈

Integrating AI into Modern SOC Workflows 📊
- Many SOCs struggle to operationalise AI, often treating it as a shortcut or applying it to ill-defined problems, with 40% using AI/ML tools informally and 42% without customisation.
- AI can reliably enhance SOC capabilities in detection engineering (for narrow, well-defined tasks), threat hunting (for exploration and pattern comparison), code development (for scaffolding), automation (for workflow drafting), and reporting (for standardisation and clarity).
- Successful AI adoption requires clear expectations, ongoing validation, and human accountability, with teams acting as "takers," "shapers," or "makers" to integrate AI effectively into existing workflows.
📰 The Hacker News | thehackernews.com/2025/12/how-

#CyberSecurity #ThreatIntelligence #Ransomware #NationState #APT #ZeroDay #Vulnerability #MongoBleed #AI #DataPrivacy #InfoSec #CyberAttack #Malware #IncidentResponse #MustangPanda #SilverFox #DarkSpectre

2025-12-30
2025-12-18

It's just me.

I was an odd looking fella until my mid 40's and then the silver fox happened and I started stretching out and adding to my piercings.

It's a very different look, but I certainly get remembered well for it!

The leather trousers? Yeah that's just a me thing. The missus loves me in them.

#piercings #whitebeard #whitehair #silverfox #pierced #leather #leatherpants

Me; a 52 year old man with multiple piercings, a white beard, bald head, and leather trousers on.
2025-12-08

Trimmed my beard. Feeling tidy.

Yes I am wearing The Nightmare Before Christmas pyjamas.

#beard #freshtrim #beards #silverfox #saltandpepper

A bald 50 year old man with a white beard.
2025-12-05

New analysis reveals a Silver Fox operation using a fake Microsoft Teams installer to deploy ValleyRAT in attacks targeting China-based users.

The campaign mixes SEO poisoning, Cyrillic false-flag elements, DLL injection, and BYOVD techniques - making detection and attribution more challenging.

Researchers also note a secondary chain using a trojanized Telegram installer.

What’s your perspective on increased abuse of trusted-app installers in malware campaigns?

Source: thehackernews.com/2025/12/silv

💬 Join the discussion
👍 Boost & follow for more threat intelligence

#CyberSecurity #ThreatIntel #ValleyRAT #SilverFox #InfoSec #MalwareResearch #SecurityOps #CyberThreats

Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
2025-11-10

#Gingitsune (aka #SilverFox) isn’t a great show but it is charming. By the nature of the premise (true successors to a shrine can interact with the Shrine Heralds but only after the death of the previous successor), the two MCs have lost at least one parent. So tvtropes.org/pmwiki/pmwiki.php is definitely a factor, but Makoto-chan’s father Tatsuo is definitely (and positively) present so that’s a plus.

2025-11-07
Old man alert 🚨🌵 #oldmancactus #silverfox #cactilover
Christian Drolet 📷𝐇𝐨𝐛𝐛𝐲cdrolet24@qlub.social
2025-11-02

Renard argenté
— Rare et fascinant, ce renard arbore une robe sombre aux reflets métalliques, résultat d’une mutation génétique appelée mélanisme. Bien qu’il s’agisse d’une forme du renard roux, son apparence énigmatique lui vaut souvent le surnom de « fantôme des bois ».

#photographies #passetemps #renardargente #automne #faune
#photography #nature #silverfox #quebec #canada

Renard argenté 
— Rare et fascinant, ce renard arbore une robe sombre aux reflets métalliques, résultat d’une mutation génétique appelée mélanisme. Bien qu’il s’agisse d’une forme du renard roux, son apparence énigmatique lui vaut souvent le surnom de « fantôme des bois ».
2025-11-01

Злоумышленники перенимают опыт коллег: что общего между SilverFox и APT41. Разбор атаки

Привет, Хабр! На связи Евгения Устинова, старший аналитик сетевой безопасности группы компаний «Гарда» . В статье хочу рассказать, как нам удалось связать инструментарий двух группировок через особенности реализации сетевых протоколов. Отследить эволюцию инструментов группировки SilverFox – например, ПО Winos – по отпечатку процедуры сетевой коммуникации оказалось довольно сложной задачей, поэтому я решила поделиться кейсом. Подключайтесь к расследованию

habr.com/ru/companies/garda/ar

#разбор_атаки #Winos #Silverfox #вредоносы #фишинг #ValleyRAT #apt41 #winnti

2025-10-18

during the first lockdown, 2020, Vinyl Fanatiks put out a free album. Hardcore Lockdown.

whole album is worth a listen, like a snapshot of expression in those dark days. don't think it's free anymore though.

this is probably my favourite track from it:

Silver Fox - Gunman

just sick, so good. hard breakbeats, filthy synths, pure raving energy.

youtube.com/watch?v=Kv2Sk0FzXr0

#SilverFox #VinylFanatiks #Hardcore #Music

2025-09-13

Solar work finished, but I also got to peek in on foxes today.

#fox #RedFox #SilverFox #foxen

An orange red fox crouched in a plastic drainage pipe, looking toward the viewer. The pipe is on a bed of wood chips within an enclosure, and behind the pipe is a plastic igloo shelter like you would get for a dog.A picture looking into an enclosed area outside, with walls of metal mesh. Inside the ground is covered in wood chips, then two red foxes can be seen, both with orange fur. One on the left side is standing with her head down to sniff something on the ground, while the other one to the right is crouched in a plastic drain pipe, looking toward the one on the left.A black and gray fox, technically a red fox, although known as a silver Fox, seen through the metal mesh of a dog crate, which he is crouched down behind. He is looking toward the camera, so you can see his eyes and ears and part of his back.
2025-09-02
2025-09-02

⚠️ The #SilverFox APT is exploiting a Microsoft‑signed but vulnerable driver to disable Windows security on Win 10/11 and install #ValleyRAT malware.

Details: hackread.com/silver-fox-apt-ex

#CyberSecurity #Malware #China #InfoSec #Windows

2025-08-07
#FotoVorschlag: Salz und Pfeffer // Salt and pepper

Da fallen mir als erstes Haare ein. Aber ich fotografiere ungern Menschen, darum muss ein richtiger #Silberfuchs im #WolfcenterDörverden herhalten. // 'Hair' was my first thought. But I rarely take photos of people, so here's a literal #silverFox at Wolfcenter #Dörverden.

😏


#fox #Fuchs #foxes #Füchse #foxesOfMastodon #foxOfTheDay #FuchsFreitag #Fuchsliebe #WildlifeWednesday
A silver fox, a melanistic variant of the red fox, is pictured sitting on a bed of small grey and brown stones. The fox has a thick coat of fur, which is a mix of black and white hairs, giving it a shimmering, silvery appearance. Its ears are pointy and black, and its snout is also dark. The fox is facing to the right of the frame, with its body curled slightly. One of its hind legs is raised, as if it is about to scratch itself. Its large, bushy tail is a mix of the same black and white fur, with a distinctive fluffy white tip. The background is slightly out of focus, showing green grass and other plants, with some fallen leaves and dirt visible.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst