๐Ÿ“ข๐Ÿ”” Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
CFPTime - Cybersecurity Conference Calls for Papers

๐Ÿ“ข๐Ÿ”” Just 2 more weeks to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
CFPTime - Cybersecurity Conference Calls for Papers

5/5 Lateral Movement Assessment

Using valid administrator credentials, the attacker leveraged remote execution utilities to access additional internal hosts.

Observed Attack Chain:

PHPStudy Exploitation
โ†’ Discovery
โ†’ Payload Deployment
โ†’ C2 Establishment
โ†’ Persistence
โ†’ Credential Access
โ†’ Network Discovery
โ†’ Lateral Movement

This intrusion demonstrates how a single vulnerable web application can rapidly evolve into broader internal compromise.

#ThreatIntel #CTI #MITREATTACK

1/5 Threat Activity Analysis

Source: Attack simulation telemetry analysis.

Initial access was achieved through exploitation of a vulnerable PHPStudy deployment. The attacker executed reconnaissance commands to identify the current user context, network configuration, ARP cache, and external connectivity.

Assessment: The activity indicates validation of code execution capabilities prior to payload deployment.

ATT&CK: T1190, T1082, T1016

#ThreatIntel #CyberSecurity #MITREATTACK

๐Ÿ“ข๐Ÿ”” Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
CFPTime - Cybersecurity Conference Calls for Papers

โšก Fresh Talk Alert for BSides Luxembourg 2026!

๐—ฌ๐—ข๐—จ๐—ฅ ๐—–๐—ง๐—œ ๐—ฅ๐—˜๐—ฃ๐—ข๐—ฅ๐—ง๐—ฆ ๐—”๐—ฅ๐—˜ ๐—จ๐—ฆ๐—˜๐—Ÿ๐—˜๐—ฆ๐—ฆ ๐—ช๐—œ๐—ง๐—›๐—ข๐—จ๐—ง ๐—ฆ๐—ง๐—ฅ๐—จ๐—–๐—ง๐—จ๐—ฅ๐—˜: ๐—™๐—ฅ๐—ข๐—  ๐—จ๐—ก๐—ฆ๐—ง๐—ฅ๐—จ๐—–๐—ง๐—จ๐—ฅ๐—˜๐—— ๐—ง๐—›๐—ฅ๐—˜๐—”๐—ง ๐—œ๐—ก๐—ง๐—˜๐—Ÿ ๐—ง๐—ข ๐—ฆ๐—ง๐—œ๐—ซ ๐—ž๐—ก๐—ข๐—ช๐—Ÿ๐—˜๐——๐—š๐—˜ ๐—š๐—ฅ๐—”๐—ฃ๐—›๐—ฆ ๐—ช๐—œ๐—ง๐—› ๐—Ÿ๐—Ÿ๐— ๐—ฆ ๐—”๐—ก๐—— ๐— ๐—–๐—ฃ ๐—ฆ๐—˜๐—ฅ๐—ฉ๐—˜๐—ฅ โ€“ Antonio Formato

Turn unstructured threat intelligence into actionable, machine-readable defense logic in this deep dive from the Actionable CTI & Detection Engineering Village. Every week, critical threat reports are published in PDFs and blog posts โ€” rich in insight but unusable for SIEMs, SOARs, or AI agents. This talk shows how to bridge that gap using a hybrid architecture that combines deterministic extraction and LLM-based semantic inference to generate STIX 2.1 knowledge graphs.

Youโ€™ll explore how threat reports can be transformed into structured intelligence objects, mapped to MITRE ATT&CK, and visualized as interactive knowledge graphs. The session also introduces TI Mindmap HUB, an independent research platform that converts real-world reports into multi-layered CTI views including ATT&CK heatmaps, Diamond Model structures, and CVE prioritization.

A key focus is the Model Context Protocol (MCP), which exposes structured CTI as tool calls for AI agentsโ€”making intelligence directly usable in automated workflows, SOC tooling, and AI copilots. The talk concludes with emerging research into LLM-inferred threat intelligence knowledge graphs and cross-report correlation at scale.

Antonio Formato is a Senior Cybersecurity Solution Engineer at Microsoft and an independent researcher focused on Generative AI for Cyber Threat Intelligence. He is the creator of TI Mindmap HUB and co-author of academic research on automated STIX 2.1 generation currently under peer review.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #CTI #ThreatIntelligence #STIX #MITREATTACK #AISecurity #DetectionEngineering

๐ŸŽฎ The Return of Malware & Monsters: Collaborative IR Gaming (2h Workshop) on May 6th!

๐—š๐—ข๐—ง๐—ง๐—” ๐—–๐—ข๐—ก๐—ง๐—”๐—œ๐—ก '๐—˜๐—  ๐—”๐—Ÿ๐—Ÿ: ๐—–๐—ข๐—Ÿ๐—Ÿ๐—”๐—•๐—ข๐—ฅ๐—”๐—ง๐—œ๐—ฉ๐—˜ ๐—œ๐—ก๐—–๐—œ๐——๐—˜๐—ก๐—ง ๐—ฅ๐—˜๐—ฆ๐—ฃ๐—ข๐—ก๐—ฆ๐—˜ ๐—ง๐—ฅ๐—”๐—œ๐—ก๐—œ๐—ก๐—š ๐—ง๐—›๐—ฅ๐—ข๐—จ๐—š๐—› ๐—š๐—”๐— ๐—œ๐—ก๐—š with Klaus Agnoletti (@klausagnoletti) & ๐—š๐—Ÿ๐—˜๐—ก ๐—ฆ๐—ข๐—ฅ๐—˜๐—ก๐—ฆ๐—˜๐—ก - 6 May, 9AM - 11AM

Back by popular demand after last year's hit! Ditch dull tabletops for Malware & Monsters โ€“ tabletop RPG meets creature-collecting where teams hunt/contain digital threats in story-driven scenarios with MITRE ATT&CK-mapped malware "malmons." Experience real IR chaos: coordination under pressure, incomplete intel, stakeholder drama. Take roles like Hunter, Analyst, Forensicator, Communicator to see how teams actually collaborate. Learn mechanics, build custom scenarios from real malware history, run live sims with "type effectiveness" for defenses and evolution for escalating attacks. Walk away with free, ready-to-use materials for fun, effective IR training.

Led by Klaus Agnoletti https://pretalx.com/orga/event/bsidesluxembourg-2026/speakers/SQVVHK/ (infosec pro since 2004, BSides Kรธbenhavn co-founder, storytelling cyber advisor, neurodiversity advocate) & Glen Sorensen https://pretalx.com/orga/event/bsidesluxembourg-2026/speakers/J3PRCC/ (Recovering CISO, DeleteMe Solutions Engineer, OSINT/AI expert, HackBack Gaming Incident Master).

๐Ÿ“… Conference dates and time: 6โ€“8 May 2026 | 9AM - 6PM
๐Ÿ“ Venue: 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/

Game your way to better IR skills โ€“ popular return engagement! ๐ŸŽฒ

#BSidesLuxembourg2026 #IncidentResponse #CyberSecurityTraining #BlueTeam #GameBasedLearning #MITREATTACK #BSides #DnD #DFIR

If the Kardashians launched their own framework it would be Kommand and Kontrol (K2).

The Momager (Kris.exe or Kris.sh): The primary C2 listener.
The Glow Up: Privesc
Keeping Up: Lateral movement

#C2Framework #RedTeaming #PostExploitation #MalwareDevelopment #Infosec #CyberSecurity #EDRBypass #ActiveDirectory #PenTesting #ThreatHunting #MITREATTACK #APTHunting #Shellcode #ZeroDay #Persistence #Exfiltration #BlueTeam #PurpleTeaming #kardashians

Why the MITRE ATT&CK Framework Actually Works

The alert goes off at 2:17 p.m.

Medium

Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.

Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/

#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux

Cron Persistence: Why Your Linux Malware Keeps Coming Back (Complete Guide 2025) - OSTechNix

Cron persistence is a common Linux malware technique. Learn how it works, how to detect it, and how to remove malicious cron jobs safely.

OSTechNix