Blog and monthly digest of Cyber Threat Intelligence (CTI) information sources, tools, articles, events, and helpful tips.

Latest

Mar
29

Backdoor Discovered in xz/liblzma Compression Library

A sophisticated backdoor was uncovered in recent versions of the widely-used xz/liblzma compression library, potentially compromising any Linux system
2 min read
Mar
10

Sources & Methods Newsletter #17 - March 2024

๐Ÿ“ Sources Cloud Threat Landscape - Cloud-focused compilation of incidents, targeted tech, threat groups, tools, and techniques. Maintained by Wiz, who
2 min read
Jan
29

Sources & Methods Newsletter #16 - January 2024

Happy New Year! I hope your holidays were restful and you're ready to get back to it. At
2 min read
Dec
22

Sources & Methods Newsletter #15 - December 2023

I hope everyone had a great yearโ€”it was for Sources & Methods: * Moved the newsletter to Ghost.io to
3 min read
Dec
14

Evilginx Phishing Proxy

Learn about the threat of free Adversary-in-the-Middle (AiTM) phishing proxy Evilginx and how to mitigate it.
4 min read
Nov
22

Sources & Methods Newsletter #14 - November 2023

Have questions or suggestions? Send them my way at sources.methods@protonmail.com. Thanks for reading, Matthew Conway (@mattreduce) ๐Ÿ“ Sources
2 min read
Oct
17

Sources & Methods Newsletter #13 - October 2023

๐Ÿ“ Sources Living off the Foreign Land Cmdlets and Binaries - In the style of LOLBins, a collection of trusted Microsoft
2 min read
Sep
10

Sources & Methods Newsletter #12 - September 2023

I'm glad to share issue 12, representing a year of the Sources & Methods monthly newsletter. Starting this
2 min read
Aug
11

How I Make Sources & Methods Newsletter

I'd like to expand on my recent Mastodon post about how I compile and publish Sources & Methods
9 min read
Aug
05

Sources & Methods Newsletter #11 - August 2023

Hello again! This week, while I'm putting together issue 11, the weather is perfect for reading the new
2 min read