Gabby Roncone đŸ€ 

284 Followers
68 Following
28 Posts
technical analyst hunting RU malware on cyber espionage at Mandiant/Google Cloud. views expressed here are mine, not my employer’s.

Parasites exploiting a weakness in another organism to feed. Every vulnerability is a niche for survival.

https://www.wired.com/story/russia-turla-fsb-usb-infection/

Turla, a Russian Espionage Group, Piggybacked on Other Hackers' USB Infections

The infamous, FSB-connected Turla group took over other hackers' servers, exploiting their USB drive malware for targeted espionage.

WIRED
After that little footnote, citing KL is — more than ever — a flag for what I like to call “clown shoes”

RT @[email protected]

Belarus đŸ§” We're seeing new developments in Belarus, which could have major repercussions for Belarus and Ukraine. Today, Sergei Shoigu arrived in Belarus. The visit was reportedly unannounced. Straight after landing at Machulishchy Air Base, he met his Belarusian counterpart...

🐩🔗: https://twitter.com/konrad_muzyka/status/1599169936961568768

Konrad Muzyka - Rochan Consulting on Twitter

“Belarus đŸ§” We're seeing new developments in Belarus, which could have major repercussions for Belarus and Ukraine. Today, Sergei Shoigu arrived in Belarus. The visit was reportedly unannounced. Straight after landing at Machulishchy Air Base, he met his Belarusian counterpart...”

Twitter
@Big_Bad_Wolf @ty also I make an out of left field prediction about future cyber operations from Russia 👀 so listen & get ready to roast me
@Big_Bad_Wolf @ty I refuse to listen to my own voice but others have said the content is good so would recommend
y’all check out this cool podcast me and @Big_Bad_Wolf and @ty were on! we talk about our reflections on (mostly GRUwU) cyber operations in ukraine during the beginning of the war. https://open.spotify.com/episode/2AWdJNdk267DyIcqzQ1seF?si=oPRnudMJROavySimPjaGbA
Threat Trends: Reflections on Russian Cyber Threat Activity During the War in Ukraine

Listen to this episode from The Defender's Advantage Podcast on Spotify. This week’s episode of The Defender’s Advantage Podcast features Mandiant analysts Gabby Roncone, John Wolfram and Tyler McLellan who joined Threat Trends host Luke McNamara for a discussion on Russian cyber operations over the last year.The group discusses the Russia linked threat groups and activity Mandiant has been tracking related to the conflict in Ukraine, including UNC2589 and APT29. They also share their perspectives on the targeting trends they’ve observed over the last year and the activity we might expect to see moving forward, such as an increase in economic espionage and continued diplomatic targeting by APT29. Follow Gabby Roncone at @gabby_roncone, John Wolfram at @Big_Bad_W0lf_ and Tyler McLellan at @tylabs. Don’t forget to rate, review and subscribe to The Defender’s Advantage Podcast where you listen to podcasts. Additional Resources Listen to the episode, Threat Trends: Russian Invasion of Ukraine Information Operations featuring Sam Riddell and Alden Wahlstrom: https://mndt.info/3wGse9uListen to the episode, Threat Trends: Stolen Emails, Hacked Cameras and the Mysterious UNC3524 featuring Doug Bienstock and Josh Madeley: https://mndt.info/3vMne2RRead the blog post, Trello From the Other Side: Tracking APT29 Phishing Campaigns: https://mndt.info/3UU9HjPRead the blog post, They See Me Roaming: Following APT29 by Taking a Deeper Look at Windows Credential Roaming: https://mndt.info/3FZp7Pk

Spotify
today in my botany class I learned that an apple is a false fruit and I genuinely do not know what to do with this information now
The Black Hat USA talks are all online today. Terrific research and next-gen exploits!
https://www.youtube.com/user/BlackHatOfficialYT
Had a lovely conversation with a student today about my experience as a woman working at the intersection between national security and cybersecurity. It gave me the space to reflect on how much my experience has evolved over the years and for the better. I feel so incredibly fortunate to have found my people (so to speak) and to be so welcomed by them. Conferences like #LABScon and #CYBERWARCON and organizations like the Cyber Conflict Studies Association (CCSA) and the @alperovitch Institute at Johns Hopkins SAIS are wonderful examples of this. Deeply innovative and world class folks who see embracing and actively building a diverse community as central to their missions. Is it perfect? No. Do I still face challenges ranging from the blatant to subtle? Sadly, yes. Can and should we continue to do better? Absolutely, and please. But I am increasingly hopeful that we are heading in the right direction and that’s largely because leaders in this field have made it a priority. Let’s keep the momentum going! One day in the near future I want to find myself in a ridiculously long queue for the women’s restroom at every cybersecurity conference I attend.