Big things are coming to Los Angeles! Acting Director Nick Andersen recently met with @LA28 leaders to talk safety, security, & cyber readiness for the 2028 Games. From FIFA to Super Bowl LXI to the Olympics, we’re keeping LA secure!🛡️
But the GDID data exists on every Windows machine, including yours. The infrastructure that handed his entire digital life to the FBI is the same infrastructure running on your laptop right now. #Cybersecurity#fbi
Tallinn, New York, Thailand, Germany. Different IPs. Same machine. Same person.
Microsoft had already identified him in October 2024 and filed a criminal referral. He was still 17. So they waited till He turned 18. Then they moved.
Yes, Stokes is accused of serious crimes.
19-year-old hacker used VPNs, tunneling tools, and rotated IPs across 3 countries. The FBI still caught him. Here's the Windows feature that made it possible and why it should concern everyone.
🔍 July’s President’s Cup #GameOfTheMonth: "The Triple Lindy” (PC6, R1)! This challenge has the participant navigate a compromised ship, break into restricted services, and recover mission-critical data. Play now: presidentscup.cisa.gov/game-of-the-mo…#PresCup
Our most important mission is to protect the American people. As the nation comes together for large-scale events this summer, like #FIFAWorldCup & Freedom250, we’re here to help everyone stay safe. Get started with our tips & resources: cisa.gov/staying-secure…@WHTaskForceFIFA
If you notice behavior that seems odd such as someone avoiding security checks, acting nervous, or taking photos of entrances and exits—report it. Remember people aren’t suspicious but their behavior can be. Your awareness can make a difference: go.dhs.gov/5qz
Check out our most recent guidance in the Journey to Zero Trust series on how the Trusted Internet Connections (TIC) 3.0 initiative is helping to modernize agencies & securely connect users to applications across cloud & distributed environments. 🔗 go.dhs.gov/5xe
$47M in criminal crypto assets restricted — those wallets had a history before this operation. Infrastructure takedowns are the end of the chain. The behavioral trail starts much earlier.
🛑 Cybercrime crews just lost part of their malware supply chain.
Operation Endgame disrupted infrastructure behind Amadey and StealC — malware used to steal data and deliver additional payloads.
Authorities say the operation led to:
- 326 servers dismantled
- 142 domains
Microsoft and Europol disrupt 200+ StealC and Amadey C2 domains on June 24, 2026, exposing the full MaaS infostealer pipeline from credential theft to ransomware deployment.
Key findings:
- StealC (C++) defeats Chromium App-Bound Encryption via APC injection into a suspended process, writing decrypted credentials to C:\ProgramData\<HWID>.txt before exfil. It also raids Outlook profiles under HKCU\Software\Microsoft\Office\<version>\Outlook\Profiles, WinSCP sessions from HKCU\Software\Martin Prikryl\WinSCP 2\Sessions, and Steam files including ssfn* and loginusers.vdf. All data is RC4-encrypted and Base64-encoded before POST to C2. Self-delete fires last if the flag is set.
- Amadey (active since 2018) persists as nudwee.exe under C:\Users\<user>\e079729711 via scheduled task, communicates over HTTP with RC4+hex encoding, and supports 20+ backdoor commands including enabling RDP (fDenyTSConnections=0), creating hidden admin accounts, and loading cred.dll and clip.dll plugins at runtime.
- IOCs from the report: StealC C2 at hxxp://polse[.]us/62ea47cac2534aa18f74.php and hxxp://bluescry[.]com/01f96fd710e905ca2326.php; Amadey C2 at hxxp://microsoft-telemetry[.]at/cvdfnaFJBmC0/index.php. Full hash and URL list in the Microsoft Security blog.
Hunt for nudwee.exe, scheduled tasks pointing to the e079729711 directory, rundll32 loading cred.dll or clip.dll, and outbound HTTP POST to .php endpoints with RC4+Base64 bodies.
#DFIR_Radar
『On first glance at Figure 6, we clearly see that, indeed, there is no shared infrastructure, but rather several smaller sub-botnets with one clearly dominating.』🧐
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
welivesecurity.com/en/eset-resear…
Operation Endgame disrupted 66 domains and 296 servers linked to StealC and Amadey malware families on June 24, 2026. This coordinated effort involved Microsoft and law enforcement agencies across several countries.
2K Followers 4K FollowingProviding daily updates from Switzerland with a focus on the latest news, trends, and economic insights.
Stay informed with accurate and timely information
123 Followers 224 Following58 yr old proud grandma. ,
Former older adult protective services supervisor
Former volunteer coordinator for hospice agency
Took vaccine now can't work
2K Followers 2K FollowingThe host of Operation GCD, a Comedy + "Conspiracy Theory" podcast. Welcome to a shenanigan infused journey into the mind of this particular Garbage Can Dood!
21 Followers 173 FollowingI'm 39 years old I was born in Conroe Texas I've lived in Fort Collins Colorado for 35 years I love the outdoors and meeting new people
292 Followers 424 Followingjust here for the news and updates.
not looking for relationships, scams, or anything else. Just Trump news, and updates. tyvm
561 Followers 1K FollowingMom to an amazing son, blessed wife, teacher and forever a student of life, MN sports fan, eternal optimist, and believer. That about sums it up.
55K Followers 229 FollowingYouTuber, Business Owner, Constitutionalist, Second Amendment Advocate, Political Analyst, & Purveyor of Constitutional Liberty.
YouTube: Braden Langley
465 Followers 756 FollowingHildegard's nemesis.
I didn't choose the Thadlife, the Thadlife chose me. Thad's Bee Girl.
Face of Shewee.
Also a Horticulturist.
🇺🇦
205 Followers 417 FollowingA true American Trump supporter, I stand for our flag 🇺🇸 I support our military & police, our 2nd amendment, our freedom of speech. I believe in God.
384 Followers 934 FollowingNutrition scientist, mum, feminist and all around opinionated bint. Combining working and family life with secondary cancer. Views are mine