惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
腾讯CDC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
WordPress大学
WordPress大学
Engineering at Meta
Engineering at Meta
M
MIT News - Artificial intelligence
H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
N
Netflix TechBlog - Medium
罗磊的独立博客
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
美团技术团队
MongoDB | Blog
MongoDB | Blog
雷峰网
雷峰网
Recent Announcements
Recent Announcements
The Cloudflare Blog
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
The GitHub Blog
The GitHub Blog
博客园 - Franky
博客园 - 三生石上(FineUI控件)
T
Tenable Blog
A
Arctic Wolf
www.infosecurity-magazine.com
www.infosecurity-magazine.com
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
V2EX - 技术
V2EX - 技术
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Threat Research - Cisco Blogs
D
Docker
Y
Y Combinator Blog
博客园 - 叶小钗
PCI Perspectives
PCI Perspectives
P
Privacy & Cybersecurity Law Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
C
CERT Recently Published Vulnerability Notes
P
Proofpoint News Feed
NISL@THU
NISL@THU
C
Cyber Attacks, Cyber Crime and Cyber Security
GbyAI
GbyAI
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
Spread Privacy
Spread Privacy
L
LangChain Blog
N
News and Events Feed by Topic
量子位

DomainTools Investigations

DomainTools Investigations DomainTools Investigations | Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026 Eighteen Newsletters and a Dozen Roses Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026 The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations SecuritySnack - Hijacking Corporate Sessions Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential Edge of Seventeen (Newsletters) Cybersecurity Reading List - Week of 2026-06-01 Chinese Malware Delivery Domains Part II: Data Collection Sixteen going on Seventeen Newsletters DPRK Contagious Interview: Developer Workflow Compromise The AI Frame Campaign Continues MOIS Linked MOIST GRASSHOPPER / Homeland Justice / KarmaBelow80 / Handala Hackers / Campaigns and Evolution Fifteen (Newsletters) On A Skateboard Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment Cybersecurity Reading List - Week of 2026-04-06 DPRK Malware Modularity: Diversity and Functional Specialization SecuritySnack - OpenAI Anti-Ads Malware Exposure of TLS Private Key for Myclaw 360 in Qihoo 360 “Security Claw” AI Platform SecuritySnack - CloudFlare Anti-Security For Phishing Fourteen Newsletters and Fifteen Winters Cybersecurity Reading List - Week of 2026-03-02 Doppelgänger / RRN Disinformation Infrastructure Ecosystem 2026 SecuritySnack - Idolized Crypto Scams Lotus Blossom (G0030) and the Notepad++ Supply-Chain Espionage Campaign Seven Nation Newsletter: I'm goin' to Wichita! Guess who's back, back again? DTI’s back, tell a friend! CTI Grapevine Becomes DomainTools Investigations Thirteen Silver Newsletters Newsletter Number 9, Keep On Movin' Down The Line Eight Days a Newsletter: I lo-o-o-ove research! Newsletter No. 5: A Little Bit of Research in my life… Tenth Newsletter Freeze-Out Newsletter 11 Could Take Forever 1, 2, 3, 4 Tell Me That You Love Newsletters It's 6’n the Mornin’ (and my Newsletter at your door!) DT Investigations - Security Research for the Community March 2025 DTI Newsletter: I Like Newsletters and I Cannot Lie
Cybersecurity Reading List - Week of 2026-05-04
DomainTools · 2026-05-09 · via DomainTools Investigations

The more I understand about the overall threat environment, the less I know about the overall threat environment. 

The more I understand about the interconnected systems in the overall threat environment, the more I understand about defense. 

If you query the right kind of security nerd, roughly 10% of infosec practitioners by my anecdotal count, you will find not just someone who learned about Systems Thinking and keeps it in the mental toolbox for the right moment, but someone who the topic is formative for, someone who dived deep into the nature of different types of systems, and how similar and different systems can interact with each other. I’ve found it goes well beyond computer systems - we have colleagues who have studied deeply on natural or artificial ecosystems, on the vast array of biological systems at hand, on industrial production systems and complex gas processes. Governance systems familiarity is a hit due to its proximity to compliance systems. Firearms systems are a regular special interest of American security practitioners. 

The lessons we learn from studying disparate systems often come to fruition in a completely unrelated discipline - or one that appears unrelated, anyway. Or overlaps serendipitously with a current puzzle or problem to overcome. It’s one of the reasons that Bioanalytics graduates are highly sought-after as business data analysts.

In the early 1980s as genetic engineering took some of its first truly artificial strides, one of the primary problems to overcome was how to introduce a desired gene into a cell experimentally without engaging with the larger multicellular organism - breeding the gene in, in other words. Then some mad scientist decided to coat particles of hard metal with genetic material, sprinkle them on a projectile, and fire it straight into a cell with a .22 caliber bullet’s worth of gunpowder.

Voila. The entire field of biological ballistics - or biolistics - was born. Usage continues to the present day. Some scientist, somewhere, is firing live ammo (probably at plant cells) in order to induce genetic transformation. 

The sheer brute novelty of this method continues to amaze me.

“Normal science,” wrote the philosopher Thomas Kuhn in his ironically paradigmatic book The Structure of Scientific Revolutions, “the activity in which most scientists inevitably spend almost all their time, is predicated on the assumption that the scientific community knows what the world is like.”

As an industry, we largely seem to be convinced, or are at least trying to convince others, that we know what the world is like. Often to my embarrassment, I can only say that I’ve never been confident about knowing what the world is like, whether we’re talking about life in general or cybersecurity in particular. That internal posture of curious insecurity shapes not only my reticence, but also my expansive experience of the possible. 

And I often worry that as a sort of industrial science, we really have convinced ourselves that we know what the world is like, and most of our time is wasted dawdling in mop-up operations. All available incentives push us toward the middle of information security as a science rather than the edges. Most leave us tired at the end of the day, without the energy or resources to push imaginative boundaries. 

What happens if I start looking at each problem not from the perspective of someone who’s supposed to know what the world is like already and simply be reactive to it, but from the perspective of the madman that fired the first gene-coated bullet into a cluster of cells and then carefully watched for signs of transformation to appear?

Podcasts

  • Lawfare - The Shadowy World of Ransomware with Professor Anja Shortland - The interview was strong enough that I insta-ordered Shortland’s book “Dark Screens” - so definitely worth listening to. Worth keeping in mind it’s from a political economy standpoint, in order to set expectations, but the more perspectives we have on this the better.

Articles

  • FBI/IC3 - Cyber-Enabled Strategic Cargo Theft Surging - Between this and the use of insecure webcams to better target kinetic strikes, getting more and more interesting to see how perverse incentives in the technology sphere lead to dire consequences in meatspace.
  • UK NCSC - International cyber agencies share fresh advice to defend against China-linked covert networks - Despite not meriting many headlines in recent news cycles, this activity and advice is becoming more and more relevant as PRC activity continues to evolve.
  • Mxsasha - Taking down a European network with a TLS certificate: my RIPE NCC RPKI exploit chain - “A single shared session cookie and missing CSRF protection allowed me to make authenticated changes to the RPKI Dashboard and RIPE Database, which control routing configuration for networks from Europe, the Middle East, and Central Asia.” - Clever research that continues to show how paper-thin our protections are at a global scale. 
  • watchtowr Labs - The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - “Hello! Yes, it's all a disaster again!” - This cPanel auth bypass is the stuff of nightmares. I’m surprised more havoc hasn’t bubbled to the surface.
  • NTPpool - DNS configuration tampering on one of our GeoDNS servers - “We found that a volunteer who provided hosting for one of our GeoDNS servers used their access to manipulate DNS zone weights for the NTP Pool service domain.” - Fascinating bit of malice here. Timing can do weird things to computers and other equipment, so an attack on the NTP pool can have widesweeping, unanticipated repercussions. On my to-do list to start looking more deeply at hypothetical NTP attack impacts now.
  • Quad9 - Negative Trust Anchors - I had never heard of Negative Trust Anchors before, but came across it as a result of the DENIC .de DNSSEC debacle yesterday. Really fascinating mechanism with very complicated incentives and consequences. Also, I very much appreciate how cautiously Quad9 approaches it.
  • Twitter - eth[.]limo DNS hijack post-mortem - Credit where is due, looks like the eth[.]limo folks set things up right, with services reliant on DNSSEC, so when DNS was compromised, the blast radius was severely limited. 
  • Cloudflare - Agents can now create Cloudflare accounts, buy domains, and deploy - Even laying aside the likelihood of misconfigurations leading to massive unexpected spends, I’m just going to say this is the worst and most abusable idea I’ve heard all year. 
  • BIML - Recursive Pollution and Model Collapse Are Not the Same - “The number one risk in LLMs today is recursive pollution. This happens when an LLM model is trained on the open Internet (including errors and misinformation), creates content that is wrong, and then later eats that content when it (or another generation of models) is trained up again on a data ocean that includes its own pollution. Wrongness grows just like guitar feedback through an amp does.” - A good, quick post about an important difference in LLM training risks, and given the abuse of LLMs for influence operations lately and subsequent re-ingestion of that material by LLM scrapers, something that looks to be a clear possibility, if not probability.
  • CNN - US special forces soldier arrested after allegedly winning $400,000 on Maduro raid - The prediction market folks are speedrunning what insider trading folks found out a while ago: while the methods are complicated, once established, it’s very very easy to connect an uncannily “lucky bet” to an individual. 

Research Papers and Reports

Tools and Resources

  • BushidoToken - Awesome-Ransomware - Github repo of ransomware-fighting resources curated by a first-rate threat intel analyst from Team Cymru.

Cybersecurity Reading List - Week of 2026-06-01

Commentary followed by links to cybersecurity articles and resources that caught our interest internally.

SecuritySnack - Hijacking Corporate Sessions

A sophisticated AiTM phishing kit bypassing traditional MFA to steal Microsoft 365 session cookies. Get the full breakdown and IOCs.

DPRK Contagious Interview: Developer Workflow Compromise

Analyze the DPRK "Contagious Interview" campaign targeting developers. Get technical deep-dives into VS Code task abuse, Node.js malware obfuscation, and a full Sigma/EDR detection pack to defend your CI/CD pipeline and identity perimeter.