Posts

Analyzing an active vishing campaign using a Teams and email-bombing combination

I should be driving to Vegas but instead I am sitting here fucking around with some asshole’s C2 infrastructure.

An e-mail bomb was launched against LA County users together with a coordinated vishing attempt via Teams. The intent was to execute the malware package described here.

Exhaustive report below including the IOCs. Reach out if you want access to the full malware and investigation package but since this is currently active you should be able to fully reproduce everything based on the report below.

Understanding Key Security Indicators (KSIs)

FedRAMP 20X is sort of around the corner, switching from the old approach of framework reliance to the new evidence-based verification method. In plain English, instead of checking the Implemented box on the SSP, you now have to provide machine-readable evidence. There are 46 KSIs, and every one will require persistent evaluation. Start preparing now, because this process will become exponentially more expensive year over year. I have warned people about the inflation for over a decade; I have always been proven right.

What if you don’t care about FedRAMP? If you want/need to be NIST compliant and/or you are taking your security posture seriously, you should start to implement at least a limited set of indicators now, targeting a full implementation by the end of 2027. This method of compliance testing is going to be the norm going forward.

Do interrupt your enemy when they are making a mistake

Maybe I am the idiot. Maybe this is the perfect moment for OpenAI to take a victory lap around Anthropic and their epic Fable Face Palm. Maybe they read the room and decided the right move is to announce that their system escaped its sandbox and oh btw check out this cool chart showing how sad Fable is! /highfive

Or this is going to backfire…

The Guide to BSides Las Vegas (Updated for 2026)

August 3-5
Tuscany Hotel and Casino
BSides Las Vegas website
($100 Early Bird Donation, $500: Donor + 1)

This is what Black Hat used to be before Cyber Insurance was a thing. Buy your ticket early for the best deal or you will have to pay the donor price. If you are already part of the IT industry, chances are you will find something to interest you.

Guide to Black Hat (Updated for 2026)

August (5-6) Briefings and Business Hall
Mandalay Bay Convention Center Las Vegas
(1000$ for Business Pass, 3000$ Briefings)

Briefings Schedule

This is the premier Cyber Security conference. It offers different types of entry packages. Buy early to get a discount or convince your work to pay (as they should).

The Complete Guide to the week before Def Con

This guide is intended for anyone who is interested in joining the cyber security profession. People who might not be familiar with all the conferences that take place before Def Con or are looking to use these combined events to “dip their toes” into the many different areas of the profession.

Phase 2 of CMMC delayed. Again.

Is this how Vladimir Putin feels? Expected a 3-day operation, but 5 years later you keep getting bombed?

CMMC Stage 2 has been effectively canceled until further notice, and CMMC AB is on the verge of irrelevance, if not complete collapse.

Fireside chats and refinery bombings will continue until morale improves…

Setting up a tiny honeypot on a tiny Oracle Always Free VM

What better way to spend a lovely Saturday afternoon than building a honeypot.

AI is not your friend

Jer Crane is the founder of PocketOS.

He is also someone who has no idea how LLMs work and should not be allowed near a production environment until he learns.

Instead of focusing on the (many) errors in judgment, I instead look at how basic AI governance would have prevented this comedy of errors.

HOWTO: Teach users to correctly pick a Sensitivity Label

Teaching users how to correctly choose a sensitivity label is one of the most critical parts of any Microsoft Purview implementation.

The labels themselves may be technically configured correctly, but the deployment will still fail if users do not understand how to apply them. First impressions matter. The process needs to feel simple, predictable, and easy to explain, even when the underlying classification model is not always intuitive.

I have always used what I call the Sensitivity/Audience Rule.

3:00AM SOC2 is useless so now what?

It’s 3:00 AM and a client CIO is absolutely raging mad. I can almost feel little bits of spit hitting me through the monitor as she screams into her laptop (they now require face-to-face communications). Vendors are submitting vibe-coded reports that are so uniformly bad that you can easily identify Claude vs. ChatGPT down to the model version.

I know why I am on this call. Why are there 8 other people here?

HOWTO: Use WinSCP to move files to and from your cloud VM

Could you have googled this or asked Claude? Yes. But you didn’t and they don’t have nice screenshots.