Engineer | Investigator @meta, PhD in Applied Data Analytics x Criminology. #animalrights advocate. Founded @threatminer. Calisthenic hobbyist. Views are my own

Joined July 2010
123 Photos and videos
Michael Yip | yip@infosec.exchange retweeted
23 Jul 2024
Notable discovery from @DragosInc on a newly weaponized ICS capability referred to as "FrostyGoop" used in a real-world disruptive event leading to a power outage in Western Ukraine in January 2024. This finding is important for the global Energy sector relying on internet-accessible ENCO devices. “The fact that it can interact with devices remotely means it doesn't necessarily need to be deployed to a target environment,” [Magpie] Graham says. “You may potentially never see it in the environment, only its effects.” A remotely deployable capability in-the-wild combined with prevalent exposure of ENCO devices is likely to increases the risk profile of horizontal escalations in the event of cyber-misfires resulting from testing, refinement, mis-attribution of infrastructure, or misguided cyber attacks.
In January, Russia-linked hackers used a new form of malware to sabotage monitoring equipment in a heating utility in Lviv, Ukraine, turning off heat and hot water to 600 buildings for close to 48 hours in the midst of freezing winter temperatures. wired.com/story/russia-ukrai…
2
5
23
4,451
#TheGazaYouDontSee is a fascinating hashtag that shows a different perspective of what life in Gaza is/was like
1
357
Michael Yip | yip@infosec.exchange retweeted
ShodanHQ offers again a lifetime membership for one time 5 USD (you have to login with a free account to see the offer) @shodanhq account.shodan.io/billing/me…
25
240
857
202,040
Threads by @instagram is live!
158
Michael Yip | yip@infosec.exchange retweeted
Financially motivated cybercriminal group Sangria Tempest (ELBRUS, FIN7) has come out of a long period of inactivity. The group was observed deploying the Clop ransomware in opportunistic attacks in April 2023, its first ransomware campaign since late 2021.
4
83
222
108,812
Michael Yip | yip@infosec.exchange retweeted
3 May 2023
Orqa claims a 'greedy former contractor' secretly installed malicious code into the headset's firmware years ago. But the contractor claims it all boils down to a licensing dispute. pcmag.com/news/headset-maker…
2
3
2,689
ICYMI - We published our Q1 2023 Adversarial Threat Report today: about.fb.com/news/2023/05/me… #threatintel #cybersecurity #disinformation

129
Michael Yip | yip@infosec.exchange retweeted
24 Apr 2023
Introducing VirusTotal Code Insight: empowering threat analysis with generative AI. This tool is based on Sec-PaLM (LLM) and helps explaining behavior of suspicious scripts. Code Insight is available now for all our users! More details by @bquintero: blog.virustotal.com/2023/04/…
10
504
1,475
269,188
Michael Yip | yip@infosec.exchange retweeted
Today VirusTotal announced that each sample uploaded will be accompanied by "Code Insight". Code Insight uses Sec-PaLM, one of the generative AI models by Google, to explain what the malicious binary is doing. Code Insight is available to all users. tl;dr "they took my job"
31
473
2,265
212,209
Michael Yip | yip@infosec.exchange retweeted
A recent leak of sensitive US intelligence documents, including some marked “Top Secret”, has caught the attention of the US Justice Department and Pentagon. But where and how did these documents appear online? Bellingcat investigates: bellingcat.com/news/2023/04/…
55
587
2,108
872,938
Michael Yip | yip@infosec.exchange retweeted
In response to the #3CXpocalypse / #3CX, a group of us have put together a self-service site to look up if you were potentially impacted. If you're connecting from an IP address that was flagged, the header will turn red. checkmyoperator.com/
13
176
351
221,013
A small glimpse into how AI will fundamentally change our lives in the coming years.
25 Mar 2023
#GPT4 saved my dog's life. After my dog got diagnosed with a tick-borne disease, the vet started her on the proper treatment, and despite a serious anemia, her condition seemed to be improving relatively well. After a few days however, things took a turn for the worse 1/
196
Quite possibly the easiest info op ever
19 Nov 2022
Reinstate former President Trump
If you're looking for readings for your morning coffee, let it be this.
16 Oct 2022
Replying to @guyro
The spoof was set up as a free trial Workplace account under the name “Instagram” and using the IG brand as its profile pic. We've locked the account for violating policies and are continuing to investigate. We'll provide further updates as warranted here: about.fb.com/news/2022/10/wh…
1
Took about 80 years to develop but the V-3 rocket is finally live...
17 Oct 2022
Photos of one of the Russian Geran-2 loitering munitions that struck Kyiv this morning from @YasuyoshiChiba.
1
It had to be on a Friday
Replying to @vxunderground
Update: A Threat Actor claims to have completely compromised Uber - they have posted screenshots of their AWS instance, HackerOne administration panel, and more. They are openly taunting and mocking @Uber.
Michael Yip | yip@infosec.exchange retweeted
Just a reminder that Queen Elizabeth has reigned for 30% of U.S. history.
562
8,795
76,775