Intrusion aficionado. @Google/@Mandiant GTIG Frontline Intelligence Operations

127.0.0.1
New Blog: Sponsored by Russian military intelligence, APT44 is a dynamic and operationally mature threat actor that is actively engaged in the full spectrum of espionage, attack, and influence operations. cloud.google.com/blog/topics…
2
11
31
3,938
Tyler McLellan retweeted
Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world. The Dutch High-Tech Crime Unit arrested the suspect under Dutch law. That's exactly how the "best athlete" model in the new FBI Cyber Strategy is meant to work: the partner with the strongest authority and access leads. The @FBI is grateful to everyone who has assisted us in the ShinyHunters investigation, especially the Dutch National Police and the industry partners who shared information with us.
79
321
1,396
152,765
Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. cloud.google.com/blog/topics…
17
75
5,157
‼️ BREAKING: Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide. The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate. Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.
30
283
1,335
74,066
Tyler McLellan retweeted
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group has revealed it had a mole inside the hackers’ inner circle. wired.com/story/an-undercove…
2
31
87
23,841
UNC6671 has secretly diversified extortion operations across multiple brands, aggressively targeting financial services, private equity, and law firms with tailored vishing and AiTM tactics. Check out the breakdown below ⬇️ Read the full report: goo.gle/3RB9Mg3
1
8
41
5,052
Tyler McLellan retweeted
BREAKING: Google warns of a massive ransomware campaign targeting Wall Street firms including Blackstone, Apollo, CME Group & more.
127
201
1,545
129,424
Tyler McLellan retweeted
Blackfile (UNC6671) is still at it and has been operating under a series of rebrands. They are currently hitting the financial sector hard with vishing attacks. New blog on their ops with remediation and hardening guidance. cloud.google.com/blog/topics…
1
15
45
5,589
Tyler McLellan retweeted
Today Mandiant announced that they're a bunch of soft blooded cowards and need to make names more catchy, or something. They're abandoning their APT naming convention (i.e. APT29) and replacing it with codenames, like SANDWORM RELIC Weak bro cloud.google.com/blog/topics…
43
61
705
69,687
Great article covering some of the stranger details of unc3753’s recent targeting of US law firms.
Replying to @snlyngaas
Link: "When cybercriminals hire burglars: Inside an alleged Russian effort to infiltrate multibillion-dollar US law firms" (4/4) cnn.com/2026/06/27/politics/…
1
4
771
Peoplesoft orgs should follow our mitigation advice here cloud.google.com/blog/topics…
🚨 The Council of Europe has allegedly been breached. Over 297 GB of HR and payroll data, more than 429,000 files, has been compromised. It marks the second major hit on European institutions this year. In March, the EU Commission, ENISA, and the Directorate-General for Digital Services were breached.
1
394
Tyler McLellan retweeted
That's how we do it in Buffalo. ❤️🤍
After a microphone issue in Buffalo, the entire crowd helps with the singing of O Canada ahead of Game 5 👏
867
1,353
16,623
522,207
JSFuck obfuscation eww
So, this is what I was busy working on.. A really interesting (and sophisticated) Adobe Reader PDF "fingerprinting" exploit involving zero-day and allowing to launch additional maybe RCE/SBX exploitation!
4
957