Advertisement · 728 × 90

Posts by Dan Black

Post image

State of Statecraft (SOS) is a new security and intelligence conference that brings together experts on espionage, sabotage, influence, and other unique forms of covert statecraft to share their work with a community hyper-focused on tackling state-sponsored operations.

9 months ago 17 5 1 3
Post image

APT28 🤝 war crimes

9 months ago 8 1 0 0

Extending the veneer of grassroots activism «by default» to an entire category of threat activity routinely orchestrated (if not carried out directly) by intelligence agencies is just flat out irresponsible at this point.

I beg of you: stop using the label "hacktivism".

9 months ago 4 0 1 0

... maybe Teams isn't so bad

10 months ago 308 36 9 3

Short thread (hopefully in plain English) on the nuclear deterrence dynamics in the India-Pakistan relationship and where this goes if escalation continues. <1>

11 months ago 1346 554 25 79
Preview
CTO at NCSC Summary: week ending May 4th The age of advanced cryptography techniques edges ever closer..

Weekly summary is out..

ctoatncsc.substack.com/p/cto-at-ncs...

11 months ago 5 3 0 1
Preview
Russie – Attribution de cyberattaques contre la France au service de renseignement militaire russe (APT28) (29.04.25) La France condamne avec la plus grande fermeté le recours par le service de renseignement militaire russe (GRU) au mode opératoire d'attaque APT28, (…)

Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service?

www.diplomatie.gouv.fr/fr/dossiers-...

11 months ago 17 7 3 0

Finally

1 year ago 3 0 1 0
Preview
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents Chinese police in the northeastern city of Harbin have accused the United States National Security Agency (NSA) of launching "advanced" cyberattacks during the Asian Winter Games in February, targeting essential industries.

Credibility of claims aside, the slow creep toward direct mirroring of US public attribution has reached its final stop:

www.reuters.com/technology/c...

1 year ago 10 2 0 2
Preview
Flying Saucers: An Opening Salvo of the Cold War? Sensational stories of flying saucers dominated U.S. newspaper headlines from June to July 1947. Could they have been purposely planted as part of a U.S. strategic deception operation, aimed at bre...

This is very cool. "Sensational stories of flying saucers dominated U.S. newspaper headlines from June to July 1947. Could they have been purposely planted as part of a U.S. strategic deception operation, aimed at breaking the Soviet Diplomatic Code?" www.tandfonline.com/doi/abs/10.1...

1 year ago 142 31 7 2
Advertisement
Preview
SignalGate Isn’t About Signal The Trump cabinet’s shocking leak of its plans to bomb Yemen raises myriad confidentiality and legal issues. The security of the encrypted messaging app Signal is not one of them.

Incredibly important piece here, bravo @lhn.bsky.social and @agreenberg.bsky.social

www.wired.com/story/signal...

1 year ago 22 9 0 0

In order to help protect people from falling victim to sophisticated phishing attacks, Signal introduced new user flows and in-app warnings. This work has been completed for some time and is unrelated to any current events. 5/

1 year ago 789 55 2 4

The memo used the term ‘vulnerability’ in relation to Signal—but it had nothing to do with Signal’s core tech. It was warning against phishing scams targeting Signal users. 3/

1 year ago 1016 104 2 8

One piece of misinfo we need to address is the claim that there are ‘vulnerabilities’ in Signal. This isn’t accurate. Reporting on a Pentagon advisory memo appears to be at the heart of the misunderstanding: npr.org/2025/03/25/n.... 2/

1 year ago 1079 147 12 13
Preview
How to tell if your online accounts have been hacked | TechCrunch This is a guide on how to check whether someone compromised your online accounts.

It's never a bad time to take a look at your online accounts and see if you spot a weird device or login.

We have a comprehensive guide on how to check if your Gmail, Apple ID, Facebook, IG, WhatsApp, Telegram, Discord, etc have been hacked.

techcrunch.com/2025/03/25/h...

1 year ago 149 78 5 4

Russia's intelligence services have spent time and resources to develop Signal-specific tradecraft because it is best-in-class for secure communications.

It is Signal's lack of vulnerability that makes the app the high priority target that it is.

1 year ago 36 14 4 2

It's really crucial to understand how badly framed this is. There is no Signal vulnerability. The Pentagon email did a bad job explaining a Google report from a month ago and NPR repeated it.

This is like saying because you got a phishing email at your Gmail address, there's a Google vulnerability.

1 year ago 483 149 15 11
Preview
Research Analyst This position sits in RUSI’s Cyber and Tech Research group, which seeks to shine a light on UK and international cyber and technology issues. We take what can sometimes be complex and technical subjec...

We are looking for a motivated Research Analyst to join our cyber and tech team at @rusi.bsky.social. You need to be able to work in London. Full job spec below 👇

royalunitedservicesinstitute.peoplehr.net/Pages/JobBoa...

1 year ago 36 25 0 0
Advertisement

Developing low visibility, low signature forms of compromise for signal accounts is a clear area of investment for Russia's services as well.

Generally speaking if you use the app for sensitive comms: audit your linked devices. Do it now.

cloud.google.com/blog/topics/...

1 year ago 15 6 0 0

Right now a single technical organization is being asked to defend (at least) one side in a major regional war, the political communications of the entire US administration, the communications of anyone opposed to that administration, big piles of NGOs, and millions of “ordinary” folks to boot.

1 year ago 33 4 2 0
Preview
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.

For no reason at all, re-upping this blog from @danwblack.bsky.social, which shows the high interest that Russian APTs have in getting access to Signal messages.

cloud.google.com/blog/topics/...

1 year ago 20 10 2 0
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations
By Bill Marczak, John Scott-Railton, Kate Robertson, Astrid Perry, Rebekah Brown, Bahr Abdul Razzak, Siena Anstis, and Ron Deibert March 19, 2025 
Clicca qui per leggere un riassunto del report in italiano.

Key Findings
Introducing Paragon Solutions. Paragon Solutions was founded in Israel in 2019 and sells spyware called Graphite. The company differentiates itself by claiming it has safeguards to prevent the kinds of spyware abuses that NSO Group and other vendors are notorious for.
Infrastructure Analysis of Paragon Spyware. Based on a tip from a collaborator, we mapped out server infrastructure that we attribute to Paragon’s Graphite spyware tool. We identified a subset of suspected Paragon deployments, including in Australia, Canada, Cyprus, Denmark, Israel, and Singapore. 
Identifying a Possible Canadian Paragon Customer. Our investigation surfaced potential links between Paragon Solutions and the Canadian Ontario Provincial Police, and found evidence of a growing ecosystem of spyware capability among Ontario-based police services.
Helping WhatsApp Catch a Zero-Click. We shared our analysis of Paragon’s infrastructure with Meta, who told us that the details were pivotal to their ongoing investigation into Paragon. WhatsApp discovered and mitigated an active Paragon zero-click exploit, and later notified over 90 individuals who it believed were targeted, including civil society members in Italy.

Please drop me a reply or note letting me know if this alt text helps you.

Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations By Bill Marczak, John Scott-Railton, Kate Robertson, Astrid Perry, Rebekah Brown, Bahr Abdul Razzak, Siena Anstis, and Ron Deibert March 19, 2025 Clicca qui per leggere un riassunto del report in italiano. Key Findings Introducing Paragon Solutions. Paragon Solutions was founded in Israel in 2019 and sells spyware called Graphite. The company differentiates itself by claiming it has safeguards to prevent the kinds of spyware abuses that NSO Group and other vendors are notorious for. Infrastructure Analysis of Paragon Spyware. Based on a tip from a collaborator, we mapped out server infrastructure that we attribute to Paragon’s Graphite spyware tool. We identified a subset of suspected Paragon deployments, including in Australia, Canada, Cyprus, Denmark, Israel, and Singapore. Identifying a Possible Canadian Paragon Customer. Our investigation surfaced potential links between Paragon Solutions and the Canadian Ontario Provincial Police, and found evidence of a growing ecosystem of spyware capability among Ontario-based police services. Helping WhatsApp Catch a Zero-Click. We shared our analysis of Paragon’s infrastructure with Meta, who told us that the details were pivotal to their ongoing investigation into Paragon. WhatsApp discovered and mitigated an active Paragon zero-click exploit, and later notified over 90 individuals who it believed were targeted, including civil society members in Italy. Please drop me a reply or note letting me know if this alt text helps you.

Android Forensic Analysis: Italian Cluster. We forensically analyzed multiple Android phones belonging to Paragon targets in Italy (an acknowledged Paragon user) who were notified by WhatsApp. We found clear indications that spyware had been loaded into WhatsApp, as well as other apps on their devices. 
A Related Case of iPhone Spyware in Italy. We analyzed the iPhone of an individual who worked closely with confirmed Android Paragon targets. This person received an Apple threat notification in November 2024, but no WhatsApp notification. Our analysis showed an attempt to infect the device with novel spyware in June 2024. We shared details with Apple, who confirmed they had patched the attack in iOS 18.
Other Surveillance Tech Deployed Against The Same Italian Cluster. We also note 2024 warnings sent by Meta to several individuals in the same organizational cluster, including a Paragon victim, suggesting the need for further scrutiny into other surveillance technology deployed against these individuals.

Please drop me a note /reply letting me know if this alt text helps you.

Android Forensic Analysis: Italian Cluster. We forensically analyzed multiple Android phones belonging to Paragon targets in Italy (an acknowledged Paragon user) who were notified by WhatsApp. We found clear indications that spyware had been loaded into WhatsApp, as well as other apps on their devices. A Related Case of iPhone Spyware in Italy. We analyzed the iPhone of an individual who worked closely with confirmed Android Paragon targets. This person received an Apple threat notification in November 2024, but no WhatsApp notification. Our analysis showed an attempt to infect the device with novel spyware in June 2024. We shared details with Apple, who confirmed they had patched the attack in iOS 18. Other Surveillance Tech Deployed Against The Same Italian Cluster. We also note 2024 warnings sent by Meta to several individuals in the same organizational cluster, including a Paragon victim, suggesting the need for further scrutiny into other surveillance technology deployed against these individuals. Please drop me a note /reply letting me know if this alt text helps you.

🚨NEW REPORT: first forensic confirmation of #Paragon mercenary spyware infections in #Italy...

Known targets: Activists & journalists.

We also found deployments around the world. Including ... #Canada?

And a lot more... Thread on our @citizenlab.ca investigation 1/

citizenlab.ca/2025/03/a-fi...

1 year ago 183 110 4 11

Gorbachev believed the Soviet Union had to reform or die. But his reforms were so incoherent and inconsistent, yet persistent, he wound up destroying the USSR-something practically no one when he started thought was a possible outcome.

1 year ago 25 6 3 4

One of things I miss the most now that I'm fully remote is the old in-office nerding out about what was in the news.

This podcast has really helped to fill that void. Highly recommend.

1 year ago 16 2 1 0
Preview
The lesson from Trump’s Ukrainian weapons freeze And the grim choice facing Volodymyr Zelensky

Our new leader. The @economist.com has always been staunchly Transatlanticist. We don't say this lightly: "Europe must prepare to be abandoned or extorted. Not to prepare for that could leave Europe vulnerable to Russia and to an increasingly hostile America" www.economist.com/leaders/2025...

1 year ago 1029 397 23 35
Advertisement
Preview
Russia launches largest drone attack since start of full-scale invasion Ukraine’s air defense shot down 138 drones while 119 decoy drones were lost.

⚡️Russia launches largest drone attack since start of full-scale invasion.

Ukraine’s air defense shot down 138 drones while 119 decoy drones were lost out of a total of 267 drones launched by Russia, the Ukrainian Air Force said.

1 year ago 503 143 16 12
Preview
Ransom War: How Cyber Crime Became a Threat to National Security Buy Ransom War: How Cyber Crime Became a Threat to National Security by Smeets, Max (ISBN: 9781911723912) from Amazon's Book Store. Everyday low prices and free delivery on eligible orders.

Ransom War: How Cyber Crime Became a Threat to National Security is officially out in Europe today! Thanks to everyone who helped make this possible. It has been a fascinating research journey.

www.amazon.co.uk/Ransom-War-B...

1 year ago 26 8 0 1
Preview
New RUSI Report: Drones Now Inflicting Two Thirds Of Russian Losses A report from UK thinktank RUSI acknowledges — slightly grudgingly — that tactical drones are the most lethal weapon in the Ukrainian arsenal and are transforming warfare

“A key finding is that tactical drones are inflicting roughly two-thirds of Russian losses…twice as effective as every other weapon in the Ukr arsenal put together…remarkable…for weapons which did not officially exist in the Ukr mil at start of the war” www.forbes.com/sites/davidh...

1 year ago 430 126 13 9

Regarding the anatomy of what is now a highly consequential disinformation narrative: has anyone sourced where the claim that Zelenskyy has four percent approval ratings originates from?

1 year ago 17 1 4 1

I feel like that point has maybe been underappreciated about this historic era we're living through. Governance not just by the historically wealthy, but by people consumed by mass, often shared delusions. People have always been wrong on some facts, but not sure it's ever been quite like this.

1 year ago 51 9 3 0