Corsin's Avatar

Corsin

@cocaman.ch

it security & cyber guy, research @ https://ecrime.ch, friendly, swiss | Opinions are my own

236
Followers
236
Following
21
Posts
07.02.2024
Joined
Posts Following

Latest posts by Corsin @cocaman.ch

Post image

Thank you @ecrime.ch for being #PIVOTcon26 Silver SponsorπŸ₯³
Read more about: @ecrime.ch here: ecrime.ch

They detect extortion threats, stolen data, and brand exposure before attackers escalate - with verified intelligence.

Our sponsors: pivotcon.org/sponsors

24.02.2026 14:11 πŸ‘ 7 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0
screenshot of tweet saying "who the fuck is playing pokemon in antarctica" with a trade partner in antarctica

screenshot of tweet saying "who the fuck is playing pokemon in antarctica" with a trade partner in antarctica

photo of me in antarctica playing my switch. adelie penguins are in the background

photo of me in antarctica playing my switch. adelie penguins are in the background

photo of me in antarctica playing my switch, with pokemon legends z-a. adelie penguins are in the background.

photo of me in antarctica playing my switch, with pokemon legends z-a. adelie penguins are in the background.

I've waited 3 years to make this post

30.12.2025 15:14 πŸ‘ 22220 πŸ” 5697 πŸ’¬ 140 πŸ“Œ 88

#PIVOTcon2026 call for papers is open!

Remember, it's #PIVOTcon for a reason - your proposal should give insight into techniques and methodology, not just "what my favorite threat group did last summer". 😎

Bring on those proposals! #CFP

01.12.2025 15:57 πŸ‘ 7 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0

Our annual review is out covering technical highlights such as

- Engineering resilience against critical loss
- Passkeys
- The future of digital identity
- Post quantum crypt transition
- Our Initiate r&d program with industry
- Radical transparency in technology

.. and more

14.10.2025 06:23 πŸ‘ 6 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0
Post image

You know you want to speak at Disobey 2026. And now is your chance to do that!

Our CfP is open at: cfp.disobey.fi/disobey-2026/

Check the guidelines from the link and send your proposal by Sep 30th!

05.08.2025 14:52 πŸ‘ 11 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0

Tap in to the stream this week for some YARA fun, highlighting some crazy rules, how I think about learning yara (or anything) as a mid-career professional, and more!

21.07.2025 17:06 πŸ‘ 14 πŸ” 6 πŸ’¬ 3 πŸ“Œ 0

I don't think it is, but nobody will stop you...

15.07.2025 20:30 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Well, where else do you get fresh Yara rules?
cc @stvemillertime.bsky.social @greg-l.bsky.social

15.07.2025 17:34 πŸ‘ 6 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Screenshot of email showing a fake email quarantine summary. Used as a social engineering lure to trick recipients into clicking links and entering their credentials on a phishing site.

Screenshot of email showing a fake email quarantine summary. Used as a social engineering lure to trick recipients into clicking links and entering their credentials on a phishing site.

Finally a new template for a phishing email.

Sender IP: 45.138.48[.]158
Subject: Your email quarantine summary!!!

URLscan: urlscan.io/result/01980...

Phishing URL reported and blocked by Google Safe Browsing already.

14.07.2025 11:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

five times more

13.06.2025 21:00 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Which AI do you use for your messaging?

07.06.2025 21:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
TA406 Pivots to the Front | Proofpoint US What happenedΒ  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these

@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...

13.05.2025 09:53 πŸ‘ 15 πŸ” 13 πŸ’¬ 1 πŸ“Œ 1
Preview
Incidents impacting retailers – recommendations from the NCSC A joint blog post by the NCSC’s National Resilience Director, Jonathon Ellison, and Chief Technology Officer, Ollie Whitehouse.

Incidents impacting retailers – recommendations from the NCSC

www.ncsc.gov.uk/blog-post/in...

04.05.2025 18:20 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware North Korean state-sponsored group Slow Pisces (Jade Sleet) targeted crypto developers with a social engineering campaign that included malicious coding challenges. North Korean state-sponsored group ...

amazing work from Palo Alto and Wired today on TraderTraitor (aka SlowPisces, UNK_MachoMan, UNC something or other, Jade Sleet)

unit42.paloaltonetworks.com/slow-pisces-...

www.wired.com/story/trader...

and a minor line item, only one mention of the L word is a major success

14.04.2025 16:20 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Cybersecurity Community Must Not Remain Silent On Executive Order Attacking Former CISA Director Cybersecurity professionals and the infosec community have essential roles to play in protecting our democracy, securing our elections, and building, testing, and safeguarding government infrastructur...

Infosec must not remain silent while Trump goes after Chris Krebs: www.eff.org/deeplinks/20...

11.04.2025 20:03 πŸ‘ 346 πŸ” 164 πŸ’¬ 3 πŸ“Œ 6

Aaaaand we have just released the #PIVOTcon25 #agenda Again You will find there crΓ¨me de la crΓ¨me of #CTI #ThreatIntel #ThreatReserch Top researchers tracking both APTs and cybercriminals using very clever and effective PIVOTs 😎πŸ’ͺ Link and thank you ⬇️1/2

07.03.2025 15:12 πŸ‘ 5 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Month by month comparison of observed events on data leak sites.

Month by month comparison of observed events on data leak sites.

Overview for February 2025 on events, to countries, actors and sector.

Overview for February 2025 on events, to countries, actors and sector.

Top 10 actors and top 10 countries impacted by ransomware and data leaks.

Top 10 actors and top 10 countries impacted by ransomware and data leaks.

February 2025 was a high-volume month on data leak and ransomware sites. Our system picked up and enriched 705 events, the highest ever.

CL0p has been active posting victims from their December 2024 attack against vulnerable Cleo servers.

Get the full picture with our subscription at eCrime.ch

03.03.2025 08:50 πŸ‘ 5 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0

And now I need to figure out what is "Zone 1" in London :-D

19.02.2025 12:25 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I'll do the call without you and will repeatedly ask what you have to say 🀣

"Greg? Greg? Guess he is not on"

16.02.2025 13:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Screenshot showing logos of police organisations involved in taking down/seizing the dark web site

Screenshot showing logos of police organisations involved in taking down/seizing the dark web site

Great job by police organisations around the globe to seize domains and arrest #ransomware operators of Phobos/#8BASE.

www.khaosodenglish.com/news/2025/02...

10.02.2025 14:06 πŸ‘ 19 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
DOGE Teen Owns β€˜Tesla.Sexy LLC’ and Worked at Startup That Has Hired Convicted Hackers Experts question whether Edward Coristine, a DOGE staffer who has gone by β€œBig Balls” online, would pass the background check typically required for access to sensitive US government systems.

A teen DOGE staffer recently given access to government systems worked at a startup known for hiring convicted hackers. Someone using a Telegram handle associated with him also solicited a cyberattack-for-hire service in 2022. All raising questions about his vetting. www.wired.com/story/edward...

06.02.2025 07:43 πŸ‘ 19365 πŸ” 8344 πŸ’¬ 1222 πŸ“Œ 854

Subscribing to WIRED should be mandatory for anyone who is concerned about what's happening and wants in-depth coverage from journalists who have been reporting on privacy, security, feds, and national security for years. Plus my besties @dell.bsky.social and @couts.bsky.social work there.

04.02.2025 18:22 πŸ‘ 19 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
x.com

from the other site

x.com/abuse_ch/sta...

21.01.2025 21:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

auth is being worked on and new version should come next month

21.01.2025 20:37 πŸ‘ 5 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Interesting report from Twitter:
"Another certificate was acquired by this company and used to sign a malicious kernel driver. The driver injects an IIS module into w3wp.exe, embedding JS into webpages that redirects to a Chinese adult site, tricking users into downloading a spyware-like app."

18.01.2025 12:23 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Image generated by Apple "Image Playground" showing a cyclist in front of a mountain scenery.

Image generated by Apple "Image Playground" showing a cyclist in front of a mountain scenery.

Strange, dann bin ich einfach ein NachzΓΌgler :)

14.01.2025 12:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

keine Ahnung, hatte heute einfach eine Meldung und konnte es aktivieren. Habe schon immer Englisch eingestellt.

14.01.2025 09:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

@benkoe.com Apple Intelligence seit heute in der Schweiz verfΓΌgbar?

14.01.2025 09:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Wayback Machine capture of MTV News.

Wayback Machine capture of MTV News.

This year, we worked swiftly to save legacy media sites Vice.com and MTVNews before decades worth of valuable journalism could be erased. These sites are now searchable on the Wayback Machine!

Help us in saving these resources:: https://archive.org/donate/?origin=blsky-eoy2024

28.12.2024 16:00 πŸ‘ 8175 πŸ” 2172 πŸ’¬ 53 πŸ“Œ 107

hey, leave us out of that

25.12.2024 20:49 πŸ‘ 8 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0