Isaac Gozzo Rinkevicius 

16 Followers
80 Following
17 Posts

๐Ÿ‡ฑ๐Ÿ‡น๐Ÿ‡ป๐Ÿ‡ช Living in ๐Ÿ‡จ๐Ÿ‡ฑ

All the things #Cyber #Cybersecurity #BreachNotice #ThreatIntelligence #IncidentResponse #SecOps #OWASP #MITRE

โš ๏ธAll comments and opinions are my own, and do not reflect in any way my current, previous or future employer's views, opinions or strategies.โš ๏ธ

โœ… Cybersecurity Consultant 

Pronounshe/him
Keybasehttps://igozzo.keybase.pub/mastodon_keybase.html
LinkedInhttps://www.linkedin.com/in/igozzo
All My Linkshttps://links.igozzo.cl
Gravatarhttps://gravatar.com/igozzo

#Lockbit operations were disrupted by Law Enforcement Agencies from 11 countries, including #UK and #USA in "Operation Cronos."

While the #Ransomware operator #LockBitSupp changed their status in the #Tox messaging service to "FBI f****d up servers via PHP, backup servers without PHP can't be touched,"

#FBI #Hackback #lawenforcement #cyberwarfare #cybercrime #cyberdefense

https://www.bleepingcomputer.com/news/security/lockbit-ransomware-disrupted-by-global-police-operation/

LockBit ransomware disrupted by global police operation

Law enforcement agencies from 11 countries have disrupted the notorious LockBit ransomware operation in a joint operation known as ''Operation Cronos."

BleepingComputer
A while back @mintynet had his car stolen in a keyless theft. He called me in as a #canbus guru to help work out how exactly the car was stolen, and now we know exactly how they did it and also how to stop them. We call it "CAN Injection ๐Ÿš˜๐Ÿ’‰" and I've written the whole story up in a blog post: https://kentindell.github.io/2023/04/03/can-injection/
CAN Injection: keyless car theft

This is a detective story about how a car was stolen - and how it uncovered an epidemic of high-tech car theft. It begins with a tweet. In April 2022, my friend Ian Tabor tweeted that vandals had been at his car, pulling apart the headlight and unplugging the cables.

Ken Tindellโ€™s blog
@techc0w you are doing a great job!! Keep at it!

Hello @Ashear based on the information provided by #LastPass and my understanding you do not need to be that worried. They are very open and forward with their security incidents, and most of the time they've kept the information safe.

I would recommend to follow good security practices:
1. Change your Master Password in LastPass
2. Enable #MFA in all your accounts, if possible (LastPass Included)
3. Change only the password for sensitive/confidential accounts. Example: email, work accounts, bank, payment method, payment platforms, cloud storage, encrypted storage.

Hope this clears your worries.

@adminkirsty @SheHacksPurple You would be mind blown as to how many developers and businesses bypass security concerns and recommendations.

I've worked on Application Security and many PMOs, Developers and Executives were more concerned with the date of deployment than with the security, even arguing that our recommendations would "delay the project" and the fixes could be "patched on a later date", "no harm" they said.

#BreachNotice On November 30th, 2022, the CEO of #LastPass , Karim Toubba, announced that they are in an ongoing investigation regarding a recent Security Incident.

They have identified that a third party gained access to their systems, specially where they have customer's information, by using obtained information from the August 2022 Breach.

#SecurityIncident #Breach #investigation #cybersecurity #KarimToubba #incident #IncidentResponse

@chadloder @maddler thanks for the clarification!

@hacks4pancakes well this is very accurate ... I believe I'm in the tertiary and quaternary stages.

"The bar idea is looking good"๐Ÿค”