Tylermcl's Avatar

Tylermcl

@tylermcl

Advanced Practices at Google Cloud’s Mandiant

191
Followers
56
Following
7
Posts
01.06.2023
Joined
Posts Following

Latest posts by Tylermcl @tylermcl

Ivanti Community

Hot Zeroday Sunner continues with Ivanti Sentry CVE-2023-38035 affecting a limited number of users https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US

21.08.2023 14:44 👍 1 🔁 1 💬 0 📌 1

Citrix https://www.mandiant.com/resources/blog/citrix-zero-day-espionage

21.07.2023 21:18 👍 0 🔁 0 💬 0 📌 0
Post image

The takeaway: The GRU has followed the same five phase disruptive playbook throughout the war. Alternatives have existed, but the GRU has opted for the same tradecraft on repeat. We assess that these choices are calculated adaptations to a wartime operating environment.

12.07.2023 14:31 👍 4 🔁 1 💬 1 📌 0

GRU’s playbook on cyber disruption and infoops

12.07.2023 20:05 👍 3 🔁 0 💬 0 📌 0

Notable Storm-0875 tradecraft
1. Initial Access: Sms phishing + AITM or purchase infostealer logs (bypasses most defenses)
2. Privilege escalation via SIM swapping or call number forwarding global admin’s personal phone
3. Time from initial access to global admin often occurs within hours

06.07.2023 12:56 👍 4 🔁 1 💬 1 📌 0

If you haven’t turned on non sms/push 2FA and are a tech/bpo, retail, or telco org, they will find a weak spot and ruin your summer.

06.07.2023 23:53 👍 3 🔁 0 💬 0 📌 0

US holidays are perfect for tagging attribution on 25k events without getting any cpu usage complaints.

04.07.2023 23:35 👍 0 🔁 0 💬 0 📌 0
Post image

Happy Canada Day! 🇨🇦 Careful out there! 🌪️⛈️

01.07.2023 19:53 👍 2 🔁 0 💬 0 📌 0

Hello world!

01.07.2023 19:12 👍 2 🔁 0 💬 0 📌 0