CYBERWARCON
@CYBERWARCON
Stay tuned for #CYBERWARCON 2025 | 📧 Subscribe to receive updates at https://www.cyberwarcon.com
At #CYBERWARCON, Emerson Brooking, Dina Sadek & Max Rizzuto explored how foreign interference claims are evolving & whether growing attribution is helping or hurting, based on this tracker ⬇️ Tracker: interference2024.org Talk: youtube.com/watch?v=pJXmMY…
UNC512 targeted a Ukrainian drone operator using a phishing doc + missed calls to trigger a custom malware chain. From Google Forms to GitHub, this was frontline cyber espionage. Watch the full CYBERWARCON 2024 talk w/ Dan Black + Anton Prokopenko youtube.com/watch?v=0DMSkv…
At CYBERWARCON 2023, Kristin Del Rosso + Dakota Cary joined us to explain how China’s mandatory vulnerability reporting laws reshaped global cybersecurity. Watch the full video here >> youtube.com/watch?v=xbeRnH… CYBERWARCON is returning November 19, 2025 in Arlington, VA + online.
The "Com" isn't simply a hacker group, it's an online phenomenon that has changed the cybercrime landscape in the past several years. Allison Nixon shares more in this short clip from her SLEUTHCON 2025 talk with Ben Coon. Watch the full talk here >> youtube.com/watch?v=TydZRu…
🚨 Sponsorships are OPEN for CYBERWARCON 2025! Spots are limited + interest is already high. Help us keep the event independent + accessible to the folks doing the work. 📍 Crystal City, VA 📅 Nov 19, 2025 📩 cyberwarcon.com Let’s build something solid again this year.

CYBERWARCON is back! Join us on Wednesday, November 19, 2025, in Arlington, VA + virtually. Follow us to stay up to date for CFPs, volunteer opportunities + more! Check out for more information + sponsorship opportunities >> cyberwarcon.com

Did you know there are over 50 #CYBERWARCON talks public on our YouTube, ready for you to watch RIGHT NOW? Learn something new, or rewatch one of your favorites. Check them out here: youtube.com/@cyberwarcon Let us know what some of your favorite talks are below!

PRC hacker in custody. The USG has been trying to make this happen for a very long time. This won't break Chinese cyberespionage but it might damage their talent pipeline. 1/x
#BREAKING Xu Zewei, a suspected hacker who worked for the Ministry of State Security (China’s largest and most active spy agency), has been arrested by FBI Houston agents in Italy. He is one of the first hackers linked to Chinese intelligence services to be captured by the FBI.
At CYBERWARCON 2024, Matthieu Faou exposed Operation Texonto, a Russia-aligned information operation. Watch his full talk here >> youtube.com/watch?v=X5lLxb… Read the research here >> welivesecurity.com/en/eset-resear… #CYBERWARCON #ThreatIntel #InformationOperations #Disinformation
I think CitrixBleed vuln is being exploited at a higher rate than I’ve seen discussed publicly B/c it leaks data from memory it’s harder to directly tie exploitation to follow on activity Reminder: I documented first session replay impact of Heartbleed cloud.google.com/blog/topics/th…
Make sure you stay connected with us so that you don't miss any announcements or updates! Website: cyberwarcon.com YouTube: youtube.com/@cyberwarcon... Linkedin: linkedin.com/company/cybe... Bsky: bsky.app/profile/cyberw… #CYBERWARCON #cybersecurity

At CYBERWARCON 2023, Aleksandar Milenkoski & Tom Hegel shared DPRK threat actor insights. They're back with new research tracking a China-nexus cyberespionage campaign hitting global orgs (PurpleHaze & ShadowPad clusters). sentinelone.com/labs/follow-th…
ESET’s Matthieu Faou exposed “Operation Texonto”, a pro-Russian information operation targeting Ukrainian speakers. He shared the full breakdown at #CYBERWARCON. Watch his talk: youtube.com/watch?v=X5lLxb… Read the research⬇️welivesecurity.com/en/eset-resear…
This year at #SLEUTHCON @spiderspiders_ + Jim Walter joined us to share details on AkiraBot, a Python framework used to promote a low-quality SEO service by spamming website chats and contact forms. Read their full report from @LabsSentinel here >> sentinelone.com/labs/akirabot-…
At CWC24, Kyle O'Meara + Casey Brooks shared info on CyberAv3ngers and more groups that attack critical infrastructure. Andy Greenberg dives deeper into this group in his article from April. Watch here: youtube.com/watch?v=h15ic7… Read the article here: wired.com/story/cyberav3…
Vanessa Molter shared a talk on GLASSBRIDGE, a group of 4 companies that push pro-PRC narratives by operating networks of inauthentic news sites & newswire services. Talk here >>> youtube.com/watch?v=Pl9wDu… Here research here >>> cloud.google.com/blog/topics/th…
wisdom from Mr. @CYBERWARCON himself ⤵️
Spent a lot of time this week talking Iranian cyber capability, but the threat I lose sleep over is Scattered Spider. They are already taking food off shelves and freezing businesses. The Iranian hackers may not even have Internet access, but these kids are in play right now.
New from Google Threat Intelligence: An actor who may be related to APT29 is abusing ASP to target Russian critics. Collaboration with our good friends @citizenlab. More info on the activity and TTP in the blog. cloud.google.com/blog/topics/th…
Google TAG warns of attacks on U.S. insurance firms resembling Scattered Spider. “The insurance industry should be on high alert.” — @JohnHultquist, founder of SLEUTHCON + CYBERWARCON Check out Eric Loui’s 2024 talk that covers Scattered Spider activity: youtu.be/i0vPoKc9jG0
Select talks from past SLEUTHCONs are up and ready for you to watch on our YouTube channel. Check them out + subscribe so you're one of the first to know when talks from this year are available. 🐍 youtube.com/@sleuthcon #cybersecurity #cybercrime #SLEUTHCON