Head of Cyber Threat Intelligence @ WΓΌrth Group, GCTI/CPENT/CEH/CND/CSA/ECSA/ECIH/CTIA, owner of SATAYO CTI platform & deepdarkCTI - member of @Curatedintel

Joined January 2009
196 Photos and videos
πŸ“’A new interview is available on #deepdarkCTI. This time, we wanted to delve deeper into the #NoName057 threat actor ☒️The pro-Russia hacktivist collective emerged in March 2022 following the Russian invasion of Ukraine πŸ‘‰ You can read the interview at deepdarkcti.com/interview-11…
1
749
πŸ“’ A new interview is available on #deepdarkCTI. This time, we wanted to delve deeper into the #BreachForums, interviewing the forum owner, diencracked πŸ•΅οΈβ€β™‚οΈ The interview, which we publish in full, was conducted in May 2026. πŸ‘‰ You can read the interview at deepdarkcti.com/interview-10…
3
16
128
10,513
πŸ“’ A new interview is available on #deepdarkCTI. This time, we wanted to delve deeper into the #MedusaLocker ransomware gang. πŸ•΅οΈβ€β™‚οΈ The interview, which we publish in full, was conducted in May 2026 by Erez. πŸ‘‰ You can read the interview at deepdarkcti.com/interview-9-…
3
6
1,548
βš”οΈ The #SATAYO TIP becomes a key element in the continuous #threat #hunting process thanks to seamless integration with long-standing benchmark tools like Elastic Security and #MISP. πŸ‘‰πŸΌ Read the full article at the link neteye-blog.com/2026/03/from…
3
2,718
☒️ In recent days, the pro-Iran group #Handala has publicly released information regarding more than 180 profiles associated to the #Israeli #Air #Force and other strategic organizations/sectors. πŸ‘‰πŸΌ Full article at deepdarkcti.com/handala-and-…
1
6
3,362
πŸ“’ New #Insomnia ransomware gang. ☒️ Active since October 2025, 17 victims published on their data leak site. πŸ‘‰πŸΌ Onion link and TOX ID already available on #deepdarkCTI github.com/fastfire/deepdark…
1
5
31
4,802
πŸ“Œ How is the ransomware gang landscape evolving after the #RAMP forum seizure? πŸ”΄ Another well-known forum seems to be becoming a point of reference in this field. πŸ‘‰πŸΌ We discuss it in the article you can read at this link neteye-blog.com/2026/02/from…
6
2,162
With 2025 now behind us, we can make some observations regarding the landscape of double-extortion #ransomware #attacks. ❓ Which ransomware gangs were the most active? ❓ Which sectors and countries were most affected? πŸ‘‰πŸ» Read the full article here neteye-blog.com/2026/01/rans…
2
1
2,277
31 Dec 2025
πŸ“’ Recap of what happened in #deepdarkCTI in 2025: βœ… 586 commits βœ… 35 contributors βœ… 6,400 stars on GitHub βœ… 8 articles on deepdarkcti.com βœ… 129 active users within the Telegram channel βœ… a total of 2,465 sources πŸ™ Many thanks to the #deepdarkCTI community!
3
966
23 Dec 2025
A new interview is available on the #deepdarkCTI project blog. This time, the interview concerns the #Benzona ransomware gang. πŸ‘‰ You can read the full interview here deepdarkcti.com/interview-8-…
1,072
5 Nov 2025
πŸ”΄The problem of properly integrating #Threat #Intelligence into #Security #Operations processes is a recurring one. πŸ“Œ I wrote an article in which I described the integration process we have implemented. πŸ‘‰πŸ» Read the article here neteye-blog.com/2025/11/embe…
1
2,336
fastfire retweeted
#Ransomware πŸ“£ NEW FEATURE La nuova sezione RF Domain Monitor permette il monitoraggio costante dei domini sotto controllo #Ransomfeed e di deepdarkCTI project (@fastfire), alla ricerca di variazioni DNS e law enforcement. 1/2
1
1
3
2,693
8 Sep 2025
πŸ“’ On October 23rd, I will have the pleasure of participating in the #NetEye #Conference 2025 as a speaker with the talk "From Intelligence to Action: Embedding TI into Your Security Operations". πŸ‘‰πŸΌ You can register here wuerth-phoenix.com/neteye-co…
3,652
3 Sep 2025
πŸ“’ We interviewed Gabi, a member of the #Cyber ​​#Toufan group. This group, active since October 2024, has carried out several attacks against #Israeli targets. The full interview is available at the link deepdarkcti.com/interview-7-…
1
6
4,214
5 Aug 2025
πŸ“’ At deepdarkcti.com/details-of-t…, you can find a detailed timeline of the main events related to the alleged seizure of the #XSS forum. ⏰ The timeline is constantly updated, taking into account relevant events that are also occurring in recent days. #deepdarkCTI
7
4,446
15 Jul 2025
πŸ“’ A new interview is available on the #deepdarkCTI website. This time, community member #Erez interviewed the founder of the #Devman ransomware gang. πŸ‘‰πŸ» You can read the full interview at this link deepdarkcti.com/interview-6-…
2
5
4,230
17 Jun 2025
πŸ“’ New Critical Vulnerabilities Disclosed for Citrix Netscaler support.citrix.com/support-h…

2
2,738
10 Jun 2025
We interviewed #Se7en, the founder of #Exodus #Market, a platform for selling #infostealers #logs. Read the full interview here deepdarkcti.com/interview-5-…
15
54
7,827
15 Apr 2025
πŸ“’ Hey #community! ⭐️ ⭐️ ⭐️ ⭐️ ⭐️ We have reached 5000 stars on #deepdarkCTI! βœ”οΈ 99 contributors βœ”οΈ 119 people within Telegram channel βœ”οΈ more than 2000 sources added! βœ”οΈ official website deepdarkcti.com πŸ–€ A huge thank you goes to the whole community!
1
4
14
4,414