Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Danny Palmer

@dannyjpalmer@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Cybersecurity writer.

1301 Followers
798 Following
29 Posts
Joined November 08, 2022
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting routers used to provide public Wi-Fi to visitors to hotels, conference centers and other shared venues frequently visited by corporate employees. These compromised Wi-Fi gateways were identified around the world, including across multiple US cities, India and Saudi Arabia. (Researchers point out that the tactics look suspiciously similar to APT28/Fancy Bear... 👀 ) https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/ #cybersecurity
infosecurity-magazine.com
17
8
26
4
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Want to read about how the Ferrari Formula 1 team deals with evolving cyber threats? Well, in this interview with Luca Pierro, Head of Enterprise Cybersecurity at Ferrari, you can! (Write-up by me) https://www.infosecurity-magazine.com/interviews/interview-ferrari-head-of/ #infosec #F1
infosecurity-magazine.com
4
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Suddenly found myself with an urge to revist Half-Life...
3
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
I, for one, think it's a damning indictment on how the cybercriminal industry so rarely meets even the lowest levels of gender diversity quotas that seeing a wanted poster for female hacker is still quite surprising. smh. https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting #cybersecurity #cybercrime
US unseals indictment against alleged operators of Russian bulletproof hosting service
therecord.media

US unseals indictment against alleged operators of Russian bulletproof hosting service

The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud.

3
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
The average cost of a data breach has risen to almost $5m, analysis of the consequences of cyber incidents which took place during the last year has revealed. The figure was published in the 2026 edition of the annual IBM Cost of a Data Breach Report, released on July 29, and based on source material from breaches experienced by 602 organizations around the world between March 2025 and February 2026. According to IBM, the global average breach cost climbed 12% during the last year, reaching a record $4.99 million (£3.75m). One key factors behind the financial cost of a data breach or cyber-attack is lost business costs, either as a result of business lost immediately because the incident meaning the organization couldn’t sell products or services, or losing customers in the long run because they have lost trust in the affected organization. Cybercriminals know that this is a significant risk for organizations and are factoring this into their playbooks, especially around ransomware and extortion attacks... (My write-up for Infosecurity Magazine is linked below!) https://www.infosecurity-magazine.com/news/cost-of-a-data-breach-5m-ibm/ #cybersecurity #IBM
infosecurity-magazine.com
2
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

A surge in phishing attacks which exploit email routing settings and misconfigured domain spoofing protections to spoof domains and make malicious emails appear as if they were sent from within the organization are targeting Microsoft 365 accounts.

Microsoft Threat Intelligence has warned that the attacks are themed around phoney messages from HR departments and IT security teams and are being deployed in attempts to steal login credentials.

While the attack vector isn’t new, Microsoft said there’s been a significant rise in attacks deploying these techniques since May 2025 and they’re commonly used in conjunction with phishing-as-a-service kits like Typhoon2FA.

(By me for Infosecurity Mag)

https://www.infosecurity-magazine.com/news/phishing-exploits-misconfigured/

#cybersecurity #phishing

infosecurity-magazine.com
17
1
12
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Replying to
@garthc@sfba.social @AAKL@infosec.exchange From what I have been told by JAMF, it was revoked when they contacted Apple. (Still waiting for Apple to get back to me for their take!)
2
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Russian state-supported hackers are targeting organizations with a new attack technique using a Zero-Click method which doesn’t require users to interact with the phishing email. The campaign is designed to compromise networks and gain persistent access, a joint advisory from western cyber intelligence agencies including National Cyber Security Centre has warned. “This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said Beth Hopkins, COO of the NCSC. More via the link below! https://www.infosecurity-magazine.com/news/russian-hackers-zero-click/
infosecurity-magazine.com
1
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Replying to
Fun fact: I still apparently know the full script of TF2 short 'Meet The Spy' uh, 17 years(!) on from when it first came out. https://www.youtube.com/watch?v=OR4N5OhcY9s

Meet the Spy

1
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 8mo ago

The Microsoft Digital Crimes Unit has just announced the take down and seizure of infrastructure used by RedVDS, which has been used to conduct phishing and BEC attacks which have cost victims millions.

One thing I find particularly interesting about this announcement is how Microsoft praises the victims of some of these campaigns for coming forward: therefore helping the investigation and disruption of the cybercriminal infrastructure.

“Their cooperation made this action possible and will help protect future victims. Falling victim to a scam should never carry stigma... Every report helps dismantle networks like RedVDS and brings us closer to stopping cybercrime at scale."

Some of the most well-received features I've ever written have been interviews with CISOs at organisations which have fallen victim to cybercrime. I understand why people don't want to talk about it: but talking about those lessons learns can really help others!

#cybersecurity

https://www.infosecurity-magazine.com/news/criminal-subscription-service/

infosec.exchange

Infosec Exchange

6
0
5
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 7mo ago

The National Cyber Security Centre has issued an alert to critical national infrastructure providers, urging them to act now to protect against “severe” cyber threats.

The alert comes following coordinated cyber-attacks which targeted Poland’s energy infrastructure with malware in December.

Jonathon Ellison OBE has urged CNI operators that they must act now to ensure they can respond to any similar campaigns targeting the UK.

“Cyber-attacks disrupting everyday essential services may sound far-fetched, but we know it’s not,” he said.

https://www.infosecurity-magazine.com/news/ncsc-warning-severe-cyberattacks/

#cybersecurity

infosecurity-magazine.com
4
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

Well, I suppose it's time for one of those posts looking back at the working year, isn't it? Put simply, did I expect 2025 to be the year I went freelance? In all honesty, probably not, but circumstances pushed me down that path.

(I got laid off by the company I worked for not long after they were bought by a private equity firm...)

But, I think even though I'm really still making my first tentative steps at making things work for myself and as my own, for want of a better phrase, 'brand', it can count as successful so far, I think?

At a fundamental level, working for myself is doing more than enough to keep a roof over my head and pay the bills, so that's good!

On a more professional level, I'm so pleased with all the new publications and podcasts I've been able to work with this year - while it's also been satisfying to provide editorial consultation for companies and agencies behind the scenes.

(Turns out you don't spent 15 years working as a journalist without learning a thing or two on what makes good writing and narrative storytelling, huh?)

But it hasn't been easy. I didn't anticipate how quiet opportunities would get in the summer which caused a bit of a panic, but I know now for next year to organise the budgeting so that the August lull doesn't have me worrying about paying the bills. (Or maybe I should just go away on holiday? Or figure out a way of getting to that big cybersecurity conference in the US that month without destroying my bank balance...)

But overall, despite the challenging start to the year, I'm pleased with how things have gone. And not to be all vague and mysterious, but I've got a very interesting opportunity on the horizon, but that can wait until 2026.

Thank you to everyone who has commissioned me, read my articles, shared my posts and just generally supported me this year, it's really, really, appreciated. Have a good Christmas break!

4
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

A new Cyber Unit to coordinate responses to cyber threats across the public sector and an ambassador scheme to help encourage secure software development have been announced as part of the UK government’s new Cyber Action plan.

While the plan has broadly been welcomed by cybersecurity leaders – although there concerns that the budget of £210m isn’t enough to have a significant impact.

(Also, I'm Deputy Editor of Infosecurity Magazine now...)

https://www.infosecurity-magazine.com/news/uk-launches-new-cyber-unit/

#cybersecurity

infosecurity-magazine.com
3
2
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

Well chuffed that @gcluley@mastodon.green invited me back to guest on Smashing Security.

Come for our discussion about research from Black Hat Europe, stay for me yammering on about playing Tomb Raider Remastered and what makes it different to the original I played as a kid back in the 90s - most important for me being, that unlike the original, this version didn't just crash to a black screen of death in the middle. Very serious business.

https://open.spotify.com/episode/3JQ4Ul21LNU2W9kzxQN4xp?si=ef9bebcef155429b

#cybersecurity

open.spotify.com
3
2
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 8mo ago

Are cybercriminals shifting towards cutting out the middle-man in ransomware attacks? That is, why bother encrypting a whole network when you can just steal the data and demand payment from that alone?

An increasing number of cybercriminals are relying on data theft alone to extort ransom payments out of victims, a new research paper by Symantec has warned.

Analysis of data leak sites suggests that there were almost 1500 incidents that relied on data theft alone for extortion attacks in 2025. The figure for 2024 was only 28.

“While attacks involving encrypting ransomware remain as prevalent as ever and still pose a threat, the advent of new types of encryptionless attacks adds another degree of risk."

https://www.infosecurity-magazine.com/news/hackers-shun-encryption-in-favour/

#cybersecurity

infosecurity-magazine.com
2
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 8mo ago

Analysis by Symantec and Carbon Black Threat Hunter Team has concluded that the cybercriminals behind PureRAT are using AI tools to write scripts and code. One of the reasons for this conclusion is that sections of the code powering PureRAT contain emojis.

“Many AIs have a tendency to insert emojis in code comments because they’ve been trained using data from social platforms such as Reddit,” researchers said.

(Write-up by me for Infosecurity Magazine)

https://www.infosecurity-magazine.com/news/emojis-in-purerats-code/

#cybersecurity #malware

infosecurity-magazine.com
1
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 8mo ago

So, about VoidLink, the sophisticated Linux malware which came to light last week. Researchers have spent more time examining it and they've concluded that rather than being developed by a crack team of cyber criminals... it was developed largely by AI.

(Helped along with prompts from one person.)

"VoidLink demonstrates that the long-awaited era of sophisticated AI-generated malware has likely begun,” said the Check Point Software Research.

“In the hands of individual experienced threat actors or malware developers, AI can build sophisticated, stealthy and stable malware frameworks that resemble those created by sophisticated and experienced threat groups.”

Write-up by me for Infosecurity Magazine.

(I only had to self-edit myself twice after I typed VoidLink as Voidsent - a type of monster from Final Fantasy XIV...)

https://www.infosecurity-magazine.com/news/voidlink-linux-malware-built-using/

#cybersecurity

infosecurity-magazine.com
1
1
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 8mo ago

A quick one from me on what Trellix describes as surge in browser-in-the-browser attacks to steal Facebook passwords.

No, I'm not quite sure why one of the phishing lures claims that YOU have infringed copyright by sharing the music of *checks paper* Lewis Capaldi either.

https://www.infosecurity-magazine.com/news/phishing-scams-exploit-browser/

#cybersecurity

infosecurity-magazine.com
1
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 8mo ago

Phishing attacks and cyber fraud have overtaken ransomware as the top cybersecurity concern of business leaders, according to the World Economic Forum’s Global Cybersecurity Outlook for 2026. 👀

“As cyber risks become more interconnected and consequential, cyber-enabled fraud has emerged as one of the most disruptive forces in the digital economy, undermining trust, distorting markets and directly affecting people’s lives,” said Jeremy Jurgens, managing director, World Economic Forum.

(Write-up by me)

https://www.infosecurity-magazine.com/news/fraud-overtakes-ransomware-as-top/

#cybersecurity

infosecurity-magazine.com
1
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

The rising use of generative AI tools like LLMs in the workplace is increasing the risk of cyber-security violations as organizations struggle to keep tabs on how employees are using them - especially if they're using their personal accounts. (By me)

https://www.infosecurity-magazine.com/news/personal-llm-accounts-drive-shadow/

#cybersecurity #AI

infosecurity-magazine.com
1
0
1
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

This data breach is from before 2021, but I can't help but wonder what happens the next time there's inevitably some sort of breach and it involves people's identifiable information because government legislation means you need to verify your identity to access these sites now...

https://www.theguardian.com/technology/2025/dec/17/hackers-access-pornhub-premium-users-viewing-habits-and-search-history

theguardian.com
1
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago

Big thanks to SDxCentral for commissioning two features from me for their new Cybersecurity Supplement!

In the first piece - 𝗭𝗲𝗿𝗼 𝗧𝗿𝘂𝘀𝘁: 𝗙𝗿𝗼𝗺 𝗕𝘂𝘇𝘇𝘄𝗼𝗿𝗱 𝘁𝗼 𝗕𝗮𝘀𝗲𝗹𝗶𝗻𝗲 - I examine the current status of Zero Trust and why even many of those organizations which are implementing it are yet to roll it out across their entire network.

In the second piece - 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗮𝘁 𝗠𝗮𝗰𝗵𝗶𝗻𝗲 𝗦𝗽𝗲𝗲𝗱 - I take a look at the advantages and challenges around using agentic AI in the SOC to defend networks against ever-evolving cyber threats.

You can check out the full SDxCentral Cybersecurity Supplement here. 👇

It's behind a reg wall, but I'd say it's worth signing up to read my work, if I do say so myself.😅

#cybersecurity

https://www.sdxcentral.com/resources/the-cybersecurity-supplement/

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago
Replying to
@doqunbop Thank you! :)
0
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago
Replying to
@0x58@infosec.exchange @jerry@infosec.exchange When they boost the anti-mass spectrometer to 105%, no doubt.
0
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 9mo ago
Replying to
@jerry@infosec.exchange Now that sounds much of interesting and exciting to report on than something called 'React2Shell'
0
2
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Replying to
@realcainmosni@mastodon.me.uk Thank you! :)
0
0
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Replying to
@johnleonard@mastodon.social My brain initially read this as over-weight...
0
2
0
0
Open post
Danny Palmer @dannyjpalmer@infosec.exchange
· 2mo ago
Replying to
@johnleonard@mastodon.social Good point. Well made.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:53:46 UTC