@MkumarCyberi
iAccount based inIndia!
About this account
- Account based in
- India
- Connected via
- India Android App
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
Just a caffeine-dependent human with a really cool day job …
India
Joined August 2019
- Tweets1.6K
- Following315
- Followers223
- Likes949
Proud to represent @viehgroup at the International Businessmen Group at Radisson Blu, New Delhi.
Shared our vision, our work, and what VIEH Group is bringing to the table - building meaningful impact at the intersection of cybersecurity, technology, and innovation.
M kumar retweeted
🚨 VIEH Security analyzed the latest WaterPlum activity and identified a critical weakness in modern developer security: 𝘁𝗵𝗲 𝗵𝗶𝗿𝗶𝗻𝗴 𝗽𝗿𝗼𝗰𝗲𝘀𝘀 𝗶𝘁𝘀𝗲𝗹𝗳 𝗰𝗮𝗻 𝗯𝗲𝗰𝗼𝗺𝗲 𝗮𝗻 𝗶𝗻𝗶𝘁𝗶𝗮𝗹-𝗮𝗰𝗰𝗲𝘀𝘀 𝘃𝗲𝗰𝘁𝗼𝗿.
A joint advisory from Japan, the US, Australia and Germany says WaterPlum compromised:
• 30,000+ devices
• 100+ countries
• Funds or credentials from 7,000+ cryptocurrency wallets
• 1.7 billion JPY (~$10.71M) in cryptocurrency transferred to DPRK
𝗩𝗜𝗘𝗛 𝗔𝘁𝘁𝗮𝗰𝗸-𝗖𝗵𝗮𝗶𝗻 𝗔𝗻𝗮𝗹𝘆𝘀𝗶𝘀
The intrusion starts before employment.
• Fake recruiter / company
• Targeted IT professional
• Technical interview or coding assignment
• Malicious project/package downloaded
• Victim executes the code
• Malware establishes access
• Credentials, browser data and cryptocurrency information targeted
𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗜𝗱𝗲𝗻𝘁𝗶𝗳𝗶𝗲𝗱
• BeaverTail
• InvisibleFerret
• OtterCookie
• OtterCandy
• StoatWaffle
𝗩𝗜𝗘𝗛 𝗞𝗲𝘆 𝗙𝗶𝗻𝗱𝗶𝗻𝗴
The dangerous part is the 𝘁𝗿𝘂𝘀𝘁 𝗰𝗵𝗮𝗶𝗻.
𝗔 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿 𝗶𝘀 𝗮𝗹𝗿𝗲𝗮𝗱𝘆 𝗲𝘅𝗽𝗲𝗰𝘁𝗲𝗱 𝘁𝗼:
• Clone repositories
• Install packages
• Run scripts
• Open VS Code projects
• Troubleshoot code
• Execute unfamiliar development tooling
The attacker is therefore not convincing the victim to do something obviously suspicious.
𝗧𝗵𝗲𝘆 𝗮𝗿𝗲 𝘄𝗲𝗮𝗽𝗼𝗻𝗶𝘇𝗶𝗻𝗴 𝘀𝗼𝗺𝗲𝘁𝗵𝗶𝗻𝗴 𝘁𝗵𝗲 𝘃𝗶𝗰𝘁𝗶𝗺 𝗻𝗼𝗿𝗺𝗮𝗹𝗹𝘆 𝗱𝗼𝗲𝘀 𝗳𝗼𝗿 𝘄𝗼𝗿𝗸.
That makes this different from conventional phishing.
𝗩𝗜𝗘𝗛 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗔𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁
The infected developer endpoint can potentially sit at the intersection of:
𝗣𝗲𝗿𝘀𝗼𝗻𝗮𝗹 𝗰𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝘀 -> 𝗦𝗼𝘂𝗿𝗰𝗲 𝗰𝗼𝗱𝗲 -> 𝗖𝗹𝗼𝘂𝗱 𝗮𝗰𝗰𝗼𝘂𝗻𝘁𝘀 -> 𝗗𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿 𝘁𝗼𝗼𝗹𝗶𝗻𝗴 -> 𝗖𝗼𝗿𝗽𝗼𝗿𝗮𝘁𝗲 𝗮𝗰𝗰𝗲𝘀𝘀
This creates a high-value bridge between social engineering and software-development environments.
Organizations should therefore treat externally supplied interview code as 𝘂𝗻𝘁𝗿𝘂𝘀𝘁𝗲𝗱 𝘀𝗼𝗳𝘁𝘄𝗮𝗿𝗲.
• Sandbox technical assessments
• Use isolated VMs
• Keep corporate credentials away from assessment environments
• Review npm/PyPI and repository dependencies
• Use VS Code Restricted Mode for untrusted projects
• Monitor unusual credential-store and browser-data access
⚠️ The 30,000+ infections do not mean 30,000 corporate breaches.
But the attack model creates a credible pathway from 𝗳𝗮𝗸𝗲 𝗿𝗲𝗰𝗿𝘂𝗶𝘁𝗺𝗲𝗻𝘁 -> 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿 𝗰𝗼𝗺𝗽𝗿𝗼𝗺𝗶𝘀𝗲 -> 𝗽𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗰𝗼𝗿𝗽𝗼𝗿𝗮𝘁𝗲 𝗲𝘅𝗽𝗼𝘀𝘂𝗿𝗲.
- VIEH Security team
#VIEHThreatHunt #ThreatIntel #CyberSecurity #SupplyChainSecurity
Cisco ISE just got hit with a CVSS 10 auth bypass that’s already being exploited. No credentials needed.
The scary part isn’t the score
It’s that the system deciding who gets network access can itself be bypassed.
M kumar retweeted
Grateful for the people behind VIEH.
A memorable meetup with our Hyderabad team - the security professionals, interns, Business Development team, and everyone contributing to VIEH every day.
Your commitment, ideas, and trust are what make this journey possible.
Special thanks to Sriram: from VIEH Security, sai Raja and Sahid for the kind gesture
One team. One vision. One VIEH.
📍 Hyderabad, India
𝗡𝗲𝘄 𝗨𝗣𝗜 𝗿𝘂𝗹𝗲: merchant payments above ₹𝟮,𝟬𝟬𝟬 can attract a fee. The shop pays it, not you.
So the 𝗩𝗜𝗘𝗛 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿𝘀 built Slice. It splits one collection into ₹1,999 pieces so each scan stays under the line. Free for vendors.
Cisco's Email Gateway zero-day is being exploited for root access.
Same week: Iran-linked malware turned Telegram into a live C2 - mic recording, screenshots, silent exfil.
Patch fatigue isn't an IT problem anymore. It's a national security one.
Patching, or logging CVEs?
CISA just joined 5 national cyber agencies to publish 17 techniques attackers use to break Active Directory.
Not theory. The exact playbook adversaries run right now.
If your SOC hasn't mapped these against your own environment this month, you're not defending - you're hoping.
Browser extensions are becoming part of the AI attack surface.
A malicious extension can turn trusted browser access into control over an AI agent.
The browser isn’t just where AI runs anymore - it’s becoming what AI can control.
AI agents are moving from “security risk” to real-world attack capability. Spain’s data regulator says it received a breach report involving an AI agent finding vulnerabilities, accessing a system, modifying personal data and viewing invoices.
The next AI security problem isn’t the model itself.
It’s what the model is allowed to do.
Give an agent internet access, credentials and tools, and a harmless mistake can become an incident very quickly.
M kumar retweeted
🚨 𝗩𝗜𝗘𝗛 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝘂𝗻𝗰𝗼𝘃𝗲𝗿𝗲𝗱 𝗮 𝗺𝗮𝗷𝗼𝗿 𝘃𝗶𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆 𝗴𝗮𝗽 𝗶𝗻 𝘁𝗵𝗲 𝗦𝗼𝘂𝗿𝗧𝗿𝗮𝗱𝗲 𝗺𝗮𝗹𝘃𝗲𝗿𝘁𝗶𝘀𝗶𝗻𝗴 𝗶𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲.
Our analysis shows the campaign’s infrastructure was leaving signals months before many domains were formally identified as IOCs.
From 96 reported domains, researchers mapped:
• 186 associated IPs
• 184 confirmed malicious
• 348 email-connected domains
• 131 confirmed malicious
• 14 domains showing malicious-registration indicators
The most interesting finding:
Some infrastructure appeared in malicious-domain feeds 𝟭𝟯𝟵–𝟮𝟬𝟳 𝗱𝗮𝘆𝘀 𝗯𝗲𝗳𝗼𝗿𝗲 𝗯𝗲𝗶𝗻𝗴 𝗶𝗱𝗲𝗻𝘁𝗶𝗳𝗶𝗲𝗱 𝗮𝘀 𝗰𝗮𝗺𝗽𝗮𝗶𝗴𝗻 𝗜𝗢𝗖𝘀.
SourTrade has been active since late 2024, using malvertising to distribute unfinished malware while impersonating brands including TradingView, Solana and Luno.
The lesson:
𝗧𝗵𝗿𝗲𝗮𝘁 𝗶𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝘀𝗵𝗼𝘂𝗹𝗱𝗻'𝘁 𝘀𝘁𝗮𝗿𝘁 𝘄𝗵𝗲𝗻 𝗮𝗻 𝗜𝗢𝗖 𝗯𝗲𝗰𝗼𝗺𝗲𝘀 𝗳𝗮𝗺𝗼𝘂𝘀.
- VIEH Security Team
#VIEHThreatHunt #ThreatIntel #Malvertising #CyberSecurity #OSINT
If your girl:
- runs hot
- works day & night
- drinks a lot of water
- burns through insane amounts of energy
That’s not your girl.
That’s a GPU.
M kumar retweeted
There’s a LOT to learn in cybersecurity.
But finding the 𝗿𝗶𝗴𝗵𝘁 𝗿𝗲𝘀𝗼𝘂𝗿𝗰𝗲𝘀 is half the battle.
So I’m starting 𝗖𝘆𝗯𝗲𝗿𝗩𝗮𝘂𝗹𝘁 - a series where I’ll uncover the cybersecurity resources actually worth knowing.
Labs. Tools. CTFs. Bug bounty. Certifications. Research. And more.
𝟭𝟬𝟬+ 𝗿𝗲𝘀𝗼𝘂𝗿𝗰𝗲𝘀. 𝗢𝗻𝗲 𝘃𝗮𝘂𝗹𝘁.
First episode coming soon.
Link of the first video is in the comment box
AI agents are becoming a new attack surface.
Not just tools attackers use - targets attackers can compromise, impersonate, or manipulate.
We’ve spent years securing users and servers.
Now we have to secure the agents in between.
The scary part of AI in cyber isn’t just better phishing. It’s speed.
AI agents can now handle recon, steal credentials, troubleshoot attacks, and move to the next target with far less human input.
The attack cycle is getting much faster.
The scary part about AI agents isn’t that they can find zero-days.
It’s that they’re getting good enough to chain vulnerabilities, credentials and tools without waiting for a human at every step.
The attack surface is becoming autonomy itself
M kumar retweeted
‼️ BREAKING: Your LG TV is eavesdropping on you. It transcribes what you say, copies what is on your screen, and scans every device on your network, and researchers say the collection keeps running after you disconnect it, uploading the moment it reconnects.
LG's ad-tech arm says it out loud: "We own the glass." It pitches marketers on the ability to "own the living room," using data harvested from the TV you paid thousands for.
Gamers Nexus, working with Level1Techs and independent researchers, compromised an LG G5 and turned it into a listening device: it recorded room audio while the screen appeared off and the Ethernet cable was unplugged, then exfiltrated the file once the TV was back online.
LG has publicly said its TVs "do not collect, record, or store ambient conversations." Gamers Nexus found the TV converts speech to plain text and stores it in on-device logs, and that the mic window stays open 10 to 15 seconds after talking stops, sweeping up bystanders who never addressed the TV.
These sets are everywhere: hospitals, waiting rooms, boardrooms, hotels. ACR keeps running even when the TV is a dumb HDMI monitor, and a compromised set can pull the audio of a call off that HDMI feed. A surgeon asked Gamers Nexus where that leaves patient confidentiality.
Researchers advise disconnecting LG TVs from any network.