106 Followers
114 Following
283 Posts
Senior Marketing Manager at The Vertex Project
Voted Most Likely To Subscribe To ZooBooks
Views are my own

The latest episode of Signals & Stories by the Vertex Project is here!

In this episode, the Vertex analysts discuss:

• How cyber reporting evolved beyond malware analysis

• Why attribution is more complicated than most people realize

• The tension between intelligence sharing and publicity

• How geopolitics now shapes cyber operations

• Why diverse perspectives improve intelligence analysis • The traits that separate strong analysts from the rest

Listen on:
Apple Podcasts: https://podcasts.apple.com/us/podcast/signals-stories/id1893656837?i=1000768498350

Spotify: https://open.spotify.com/episode/0smNRBAKqdB1zbn6hIlw91?si=2QYGk5nkSNWB2Yik_-xyIQ

YouTube: https://youtu.be/AqqjYu6618g?si=8_TGWWS56WKK4yFC

Show Notes: https://vertex.link/10-year-anniversary/episode02

#CTI #CyberThreatIntelligence

Episode 2: “It Depends”: Attribution, Analysis, and the Evolution of Cyber Reporting

Podcast Episode · Signals & Stories · May 19 · 42m

Apple Podcasts
Episode 1: There’s CTI and There’s Intelligence

Podcast Episode · Signals & Stories · May 5 · 44m

Apple Podcasts

I’m back podcasting!

The Vertex Project’s 10 year anniversary is next week and to mark the occasion, we’re kicking off something new.

We’re excited to share the trailer for our upcoming limited series podcast: Signals & Stories!

This series explores how security practitioners, analysts, and researchers turn signals into meaningful stories about adversaries, infrastructure, and the real-world impact of cyber operations.

We’ll be sharing conversations, field insights, and lessons learned from people working at the intersection of intelligence and action.

🎧 Watch the trailer and get a first look at what’s coming next.

Subscribe to the podcast on Apple, Spotify, and YouTube - episodes will be released bi-weekly.

Apple: https://podcasts.apple.com/us/podcast/signals-stories/id1893656837?i=1000761549007

Spotify: https://open.spotify.com/episode/2WnAdZbvETpv0GkL12s5L8?si=QIyzo5ISTNmcc7Akz06Zqw

YouTube: https://youtu.be/Ewc2o9Mhl8Y?si=HaC-ZtZ6QNICxDlJ

I’m really proud of designing these challenge coins for the upcoming Synapse Challenge Vertex is holding pre-CYBERWARCON. Get yours by taking the challenge - let us know if you’re coming here: https://vertex.link/events/cyberwarcon-2025

Join The Vertex Project the day before CYBERWARCON on Tuesday, November 18 between 5 and 8PM for the chance to use Synapse Enterprise to investigate a real-world scenario involving potential data theft and fraudulent access to protected information.

This challenge is made for everyone: if you haven’t used Synapse before - this is a great way to see what the buzz is all about. And if you have used Synapse, the challenge will cross multiple analysis specialties, making it a great opportunity to practice using it in scenarios you may not regularly encounter.

As with all good challenges, this one will offer both snacks and bragging rights.

We’re also issuing the first-ever custom Vertex Challenge Coin upon completion - there’s a limited supply, so be sure to attend!

Let us know if you’re coming!

https://vertex.link/events/cyberwarcon-2025

The Vertex Project

Making chainmail with roses in resin (and the roses are dried from my garden!)

If you’re in the northeast Ohio area, join women in cybersecurity for our 2nd annual hike!

Let us know if you're joining us - sign up here: https://mailchi.mp/929571e81a9f/julyhike

Where and When to Meet: 
🔹 Date: Sunday, July 13th 2025 (rain date: Saturday, July 26th, 2025)
🔹 Location: Brecksville Reservation
🔹 Meeting Spot: Chippewa Creek Gorge Scenic Overlook - 8263 Chippewa Rd, Brecksville, OH 44141. Park here and we'll start our hike from this spot
🔹 Cost of Hike: Free!

Bring water and comfy shoes!

Hike Details:
🔹 All participants will enjoy a trail suitable for all hiking levels (Wildflower Trail) and a break at the Harriet Keeler Picnic Area and Nature Center, offering water and restrooms.
🔹 If you’re a more advanced hiker, the Gorge Loop will be an optional, more challenging section of the hike that can be muddy and requires hiking shoes. Those who prefer to skip this can remain on the all-purpose trail.

Brunch After the Hike:
🔹 Join your fellow hikers for an optional brunch and additional networking at the Creekside Restaurant, which offers lovely views and delicious food. Brunch is at your own expense.

Cybercrime group FIN6 (aka Skeleton Spider) is leveraging trusted cloud services like AWS to deliver malware through fake job applications.

Our latest analysis breaks down:
🔹 How attackers use LinkedIn & Indeed to build trust
🔹 The use of resume-themed phishing lures
🔹 Cloud-hosted infrastructure that evades detection
🔹 The delivery of the More_eggs backdoor via .LNK files
🔹 Key defense strategies for recruiters and security teams

This campaign is a masterclass in low-complexity, high-evasion phishing

📖 Read the full breakdown: https://dti.domaintools.com/skeleton-spider-trusted-cloud-malware-delivery/?utm_source=Mastodon&utm_medium=Social&utm_campaign=Skeleton-Spider

#CyberSecurity #ThreatIntel #FIN6 #Phishing #CloudSecurity #MalwareAnalysis #InfoSec #SkeletonSpider

I had the opportunity to sit down with former DTer, Joe Slowik at #RSAC to talk about suspicious domains.

Here are some of the key takeaways from our conversation:

🔹 Joe shared how attackers are playing the long game—like in the SolarWinds attack, where a fake AWS domain sat dormant for nearly a decade.
🔹 From aged domains to hijacked home routers, adversaries are evolving. And groups like Volt Typhoon are targeting U.S. critical infrastructure with chilling precision.
🔹 It’s time to rethink defense—beyond tools, toward resilient architecture and even manual fallbacks.

Listen to the podcast here: https://podcasts.apple.com/us/podcast/breaking-badness/id1456143419?i=1000711183082

In this week's episode of the Breaking Badness Cybersecurity Podcast we delve into the critical role of domains in modern cyber attacks. From sophisticated
nation-state operations to AI-powered phishing kits and malicious browser extensions, domains are the foundational infrastructure for threat actors.

Host @NotTheLinux is joined by four leading cybersecurity experts Joe Slowik, Robert Duncan, John Fokker and Vivek Ramachandran to break down how domains are weaponized and what organizations can do to defend themselves on this ever-evolving frontline.

Listen wherever you get your podcasts:

Apple: https://podcasts.apple.com/us/podcast/beyond-the-perimeter-how-attackers-use-domains/id1456143419?i=1000711183082

Spotify: https://open.spotify.com/episode/0trcyZliGZuEj591IVnZCu

YouTube: https://www.youtube.com/watch?v=CpcJXpWwfQo

Web: https://www.domaintools.com/resources/podcasts/how-attackers-use-domains-phishing-ai-and-how-to-fight-back/?utm_source=Mastodon&utm_medium=Social&utm_campaign=RSAC-Domains