Joe Roosen's Avatar

Joe Roosen

@jroosen

SpyCloud - Director of Security Research, Cryptolaemus Coordinator, Emotet(Ivan)/QBot(Boris) Destroyer, gold prospector & former sysadmin.

2,002
Followers
537
Following
88
Posts
13.05.2023
Joined
Posts Following

Latest posts by Joe Roosen @jroosen

Preview
Monologue: No, Something Big Isn't Coming Podcast Episode · Better Offline · 02/13/2026 · Bonus · 7m

Here’s this week’s Better Offline monologue. I walk you through why Matt Shumer’s “Something Big Is Coming” is deceptive misinformation peddled by a grifter, and why everybody who boosted or republished it should be ashamed of themselves.
podcasts.apple.com/us/podcast/b...
Linktr.ee/betteroffline

13.02.2026 05:40 👍 328 🔁 51 💬 17 📌 8
Preview
Bitcoin price falls below pre-Trump second term levels, now hovering below $67,000 Bitcoin's price continues its decline, dropping another 11% to $67,000. It has lost nearly half its value since hitting a record high in October.

Bitcoin's price continues its decline, dropping another 11% to $67,000. It has lost nearly half its value since hitting a record high in October.

06.02.2026 07:00 👍 147 🔁 42 💬 21 📌 5
Preview
Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers The botnet took an unusual path by abusing residential proxy networks, allowing it to control an untapped collection of unofficial Android TV devices.

The botnet took an unusual path by abusing residential proxy networks, allowing it to control an untapped collection of unofficial Android TV devices. cyberscoop.com/kimwolf-aisu...

15.01.2026 14:39 👍 3 🔁 2 💬 0 📌 0

About a year ago we published a story on Black Basta and the alleged leader of the gang, called Oleg N. He managed to escape after being presented to a judge

Today, LEA agencies announced having searched two homes of Black Basta operators in Ukraine. For Oleg, there's a "Wanted" poster

15.01.2026 13:52 👍 6 🔁 6 💬 1 📌 1
Preview
Keeping the Kimwolf at bay: putting a leash on a massive DDoS Botnet. With the fall of RapperBot in August 2025, Aisuru quickly regained its position as the world’s most powerful DDoS botnet. By September, Aisuru had achieved record-breaking attacks, flooding targets wi...

Lumen has sinkholed over 550 command and control servers for the Kimwolf botnet

www.linkedin.com/pulse/keepin...

15.01.2026 00:07 👍 19 🔁 8 💬 2 📌 1
File photo shows a tourist looking at a statue of Hans Egede (1686-1758), a Dano-Norwegian Lutheran missionary, in Nuuk, Greenland, on March 9, 2025

File photo shows a tourist looking at a statue of Hans Egede (1686-1758), a Dano-Norwegian Lutheran missionary, in Nuuk, Greenland, on March 9, 2025

US President Donald Trump speaks during a meeting with US oil companies executives in the East Room of the White House in Washington, DC on January 9, 2026

US President Donald Trump speaks during a meeting with US oil companies executives in the East Room of the White House in Washington, DC on January 9, 2026

🇬🇱 🇺🇸 "We don't want to be Americans," Greenland's political parties said late on Friday as US President Donald Trump again suggested using force to seize the mineral-rich Danish autonomous territory, raising concern worldwide ➡️ u.afp.com/SXWX

10.01.2026 09:32 👍 32 🔁 17 💬 1 📌 2
Video thumbnail

Explosion and fire at alleged illegal fuel tap in city of Villagrán in Guanajuato, Mexico. - ADN

09.01.2026 03:37 👍 15 🔁 4 💬 1 📌 2
Post image

BREAKING: Death toll from U.S. airstrikes on Venezuela rises to 80, number could rise.- NYT

04.01.2026 19:10 👍 23 🔁 14 💬 0 📌 0
Post image

1/ Vladimir Putin's heavy investment in the regime of Venezuelan former President Nicolás Maduro has been a costly and disastrous failure, according to Russian commentators. They admit that Russia is too weak to stop its allies from being picked off one by one by the West. ⬇️

04.01.2026 19:40 👍 446 🔁 118 💬 17 📌 16
Preview
Neighbourly Data Breach: 150GB of User Data and Messages Put for Sale - Daily Dark Web Neighbourly Data Breach: 150GB of User Data and Messages Put for Sale Discover the latest security threats and database leaks, including unauthorized VPN access and email breaches, in the cyber underg...

Tis the season for data breaches, as Neighbourly.co.nz joins ManageMyHealth.

It’ll probably mean a quick death or sale of Neighbourly as it was slowly dying already. 150GB is probably a full DB dump as it doesn’t include images.

dailydarkweb.net/neighbourly-...

01.01.2026 05:38 👍 26 🔁 19 💬 2 📌 3
Preview
The Breachies 2025: The Worst, Weirdest, Most Impactful Data Breaches Another year has come and gone, and with it, thousands of data breaches that affect millions of people. The question these days is less, Is my information in a data breach this year? and more How

Data breaches affect everyone, and in 2025 we saw plenty of them, ranging from the novel to the predictable. www.eff.org/deeplinks/2...

01.01.2026 17:59 👍 45 🔁 20 💬 0 📌 0
Preview
The F5 BIG-IP Breach: Your Blueprint for Defense Against the Incoming Zero-Day Storm Introduction: The confirmed theft of F5 BIG-IP source code by a nation-state actor represents a critical inflection point for enterprise and federal network security. This breach provides threat actors with an unprecedented roadmap to engineer novel zero-day exploits, turning widely used network appliances into potential entry points for systemic compromise. The immediate mitigation directives from CISA underscore the severity of the situation, demanding urgent and decisive action from all organizations reliant on F5 infrastructure.

The F5 BIG-IP Breach: Your Blueprint for Defense Against the Incoming Zero-Day Storm

Introduction: The confirmed theft of F5 BIG-IP source code by a nation-state actor represents a critical inflection point for enterprise and federal network security. This breach provides threat actors with an…

16.10.2025 05:17 👍 1 🔁 1 💬 0 📌 0
Post image Post image Post image

Tonight, Iran International TV exposed the identity of a Handala hacking group admin—part of the Banished Kitten cyber unit I've previously reported on—and unmasked his handler in Iran's Ministry of Intelligence.

- Morteza Aftabi-Far
- Ali Bermoudeh

13.08.2025 20:15 👍 15 🔁 5 💬 1 📌 2
Van Halen - Dreams (Blue Angels)
Van Halen - Dreams (Blue Angels) YouTube video by The Military Aviator

All you need now is Van Halen - Dreams playing for the audio backing track. youtu.be/mGpMUYmqHZM?...

06.08.2025 10:34 👍 0 🔁 0 💬 0 📌 0
Post image

Thanks to a scan conducted by @leakix.bsky.social, we have shared SharePoint IPs confirmed vulnerable to CVE-2025-53770, CVE-2025-53771.

424 SharePoint IPs found on 2025-07-23. One-off data in www.shadowserver.org/what-we-do/n...

Tree map overview: dashboard.shadowserver.org/statistics/c...

24.07.2025 07:05 👍 4 🔁 3 💬 1 📌 0
Preview
Russia and Belarus plan to create AI model based on “traditional values” Russia and Belarus intend to develop their own artificial intelligence model built on “traditional values” that would be “understandable” to citizens of both countries.

🤡 Russia and Belarus plan to create AI model based on "traditional values"

11.07.2025 21:29 👍 47 🔁 9 💬 16 📌 3
Video thumbnail

BREAKING: Massive explosion at fireworks factory in Yolo County, California.

02.07.2025 02:21 👍 1187 🔁 346 💬 191 📌 658
Preview
Why Does Russia Want Crimea So Badly? Cambridge Professor Rory Finnin Unpacks the “Crimea Is Ours” Mindset Russia seized Crimea in 2014, sparking global outrage. Why does this peninsula matter so much, and why is its liberation the only viable solution?

Why do Russians insist Crimea belongs to them?

The answer isn’t just about strategy or borders but a deeply ingrained national myth.

27.06.2025 18:08 👍 73 🔁 12 💬 2 📌 1
27.06.2025 18:13 👍 219 🔁 14 💬 3 📌 0
Preview
A prolific hacking group that's shutdown retailers and insurance companies turns to aviation A cyberattack on WestJet last week is likely tied to the Scattered Spider gang, a source tells Axios.

Mandiant is now aware of multiple incidents in the airline sector that resemble Scattered Spider. The industry should button up its call centers where this actor has had a lot of success with social engineering. www.axios.com/2025/06/27/a...

27.06.2025 17:28 👍 22 🔁 14 💬 0 📌 1
Post image

The General Staff of Ukraine reports: a strike by long-range drones destroyed two Russian Su-34 fighter-bombers at the Marinovka airbase in Russia’s Volgograd region. Two more were damaged.

27.06.2025 17:44 👍 357 🔁 32 💬 1 📌 1
Post image

The General Staff of Ukraine reports: a strike by long-range drones destroyed two Russian Su-34 fighter-bombers at the Marinovka airbase in Russia’s Volgograd region. Two more were damaged.

27.06.2025 17:37 👍 297 🔁 18 💬 5 📌 1
Preview
Police Arrest BreachForums Admins, Including ShinyHunters and IntelBroker French authorities have arrested five alleged administrators of BreachForums, including prominent figures like ShinyHunters and IntelBroker.

Police Arrest BreachForums Admins, Including ShinyHunters and IntelBroker

25.06.2025 13:26 👍 1 🔁 1 💬 0 📌 0
Preview
La police interpelle cinq hackers français de haut vol, derrière un célèbre forum de vol de données Les cybercriminels administraient BreachForums, le plus grand site de revente de données piratées, selon nos informations.

"ShinyHunters", "Hollow", "Noct" and "Depressed" have allegedly been arrested by the Brigade for the Fight against Cybercrime (BL2C) of the Paris police headquarters on Monday.

IntelBroker was allegedly arrested by French law enforcement in February 2025.

Source: www.leparisien.fr/high-tech/la...

25.06.2025 14:13 👍 3 🔁 1 💬 0 📌 0
Preview
BreachForums hacking forum operators reportedly arrested in France The French police have reportedly arrested five operators of the BreachForum cybercrime forum, a website used by cybercriminals to leak and sell stolen data that exposed the sensitive information of millions.

The French police have reportedly arrested five operators of the BreachForum cybercrime forum, a website used by cybercriminals to leak and sell stolen data that exposed the sensitive information of millions.

25.06.2025 10:26 👍 12 🔁 5 💬 0 📌 1
Preview
New ‘CitrixBleed 2’ NetScaler flaw let hackers hijack sessions A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed "CitrixBleed 2," after its similarity to an older exploited flaw that allowed unauthenticated attackers to hijack authentication session cookies from vulnerable devices.

A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed "CitrixBleed 2," after its similarity to an older exploited flaw that allowed unauthenticated attackers to hijack authentication session cookies from vulnerable devices.

25.06.2025 12:10 👍 6 🔁 2 💬 0 📌 0

Hierarchy of Credential Data Tiers

1. Infostealer Log
2. Stealer Log DBs
3. ULPs/Combolists

2 & 3 are very close to each other in adjacency to the source but 2 is above your average combolist(3). If your creds show in 2 or 3 there is 95%+ chance there is a 1 for that cred too.

20.06.2025 21:45 👍 1 🔁 0 💬 0 📌 0
Preview
📣 You’ve probably seen the headline that 16 billion Apple, Facebook, and Google passwords have been leaked, but let’s take a look at the full scope of the situation. | SpyCloud 📣 You’ve probably seen the headline that 16 billion Apple, Facebook, and Google passwords have been leaked, but let’s take a look at the full scope of the situation. ➡️ These 16 billion passwords ar...

For more info on this subject, see the following post: www.linkedin.com/posts/spyclo... 5/5

20.06.2025 00:17 👍 1 🔁 0 💬 0 📌 0