Ján Trenčanský

@j91321@infosec.exchange
135 Followers
261 Following
615 Posts
EDR R&D team lead at ESET. Opinions are my own.
I regret to inform you that Cyber Satan is in play.
Githubhttps://github.com/j91321
Blueskyhttps://bsky.app/profile/j91321.bsky.social

Google’s M-Trends 2025 report is out - data from Mandiant’s incident response engagements. Direct PDF link to avoid the sales pitch wall:

https://services.google.com/fh/files/misc/m-trends-2025-en.pdf

Thread about my main observations:

- Firstly, no mention of generative AI or GenAI again. This is in common with Sophos incident response, ESET, etc etc etc. You’ll see why as we get into the data.

The Finals
If your company sells a product with limited visibility into the underlying systems ( network appliances, etc. ) and you have not yet published an advisory or doc stating whether or not your products are impacted by the Erlang / OTP perfect 10 CVE-2025-32433, then you are not my friend and I hope you step on a lego in the middle of the night.
I've got a Game Theory about Talos Principle Reawakened, which is that it is an in-universe recreation of Talos Principle 1, created by the robot people in Talos Principle 2 as a retelling of their creation myth.
Stop the Steal!
Model M that is settling dust and dirt in the admin building since probably 94.
Distillation column and some rusted tanks in an abandoned Italian distillery. This place was an endless parade of cylindrical shaped objects, pipes and barrels.
#urbex
He is risen
#StarTrek
It is a good Friday when chocolate eggs and bunnies are involved, and I don't have to work.

Career tip:

If you work for a company that allows you to write up a blog post about a "UAC bypass" that REQUIRES ADMIN CREDENTIALS, and this same company follows through with publishing it...

Consider finding a new employer that respects you.