Navodno je kompromitovan telefon potpredsednice Narodne skupštine, izvor: https://twitter.com/protivdictature/stat...7369214976, arhivirano: https://archive.ph/wpq4p.
Quote:Location: Remote (CET +/- 3hrs) or Amsterdam/Sarajevo office.
Application Deadline: 5 August 2023 at 11:59 P.M. CET
About OCCRP
The Organized Crime and Corruption Reporting Project (OCCRP) is a growing, global nonprofit media organization that is reinventing investigative journalism for the public good. By developing and equipping a global network of investigative journalists and publishing their stories, we expose crime and corruption so the public can hold power to account. We see a future where organized crime and corruption are drastically reduced and democracy is strengthened. Our global team includes editors, researchers, data engineers, security specialists, administrators, technologists, and strategists, each with areas of in-depth expertise.
Position Overview
The Information Security team is responsible for providing the tools, processes, analysis and training of staff. We provide services for OCCRP and external journalists cooperating with OCCRP. Information we protect is used in investigations leading to publications like Suisse Secrets, the Pegasus Project, or the Daphne Project. We provide the tools and support needed to keep information and, most importantly, people safe and secure.
The nature of our work means that we deal with real attacks and threats daily. State actors and organised crime entities do and will continue to target our staff.
We are looking for an experienced security analyst to join our small team.
Although remote, you must be within a time zone that is CET/CEST +/- 3hrs. We do provide support to users globally, so from time to time; there may be a need to talk to someone outside traditional work hours.
There is a limited amount of travel associated with this role, including possible attendance at conferences. So the ideal candidate must be willing to travel occasionally (1-4 times a year).
This is a “doing” role, with an expectation that threat hunting, intelligence gathering and forensic analysis are something that you enjoy. The role will have input into wider Governance, Risk and Compliance activities, but these are not the direct mandate of this role.
This role suits someone who enjoys the technical side of information security analysis and providing guidance to others. You must be able to communicate excellently in both written and verbal forms in English.
Responsibilities:
Protect, detect, and respond to information/cyber security incidents.
Perform threat hunting and threat intelligence activities.
Perform forensic analysis using a variety of E/XDR tooling across user endpoint devices (predominantly Apple).
Work with our platform engineers to ensure secure practices are used to operate our cloud environments (SaaS solutions plus Kubernetes etc).
Provide guidance to developers around secure coding practices.
Assist with risk assessments and other GRC work.
Be our contact person with our partners, e.g., CiviCert and smaller informal networks.
Participate in selecting security solutions or enhancements to existing ones to improve overall security.
Perform as a named delegate for the CISO on occasion.
Provide monthly input to internal newsletters about security tips or items of note.
Qualifications/Education - Minimum Requirements:
At least four years of experience in cyber security.
Proven hands-on experience with security tooling, intrusion prevention systems, endpoint protection, security incident analysis.
Ideal Additional Knowledge & Skills:
Previous work experience in a security operations centre.
Previous work experience dealing with staff with low technical literacy.
Relevant security certifications.
Experience in automation and orchestration.
Follow international news closely and react if it might affect our network of journalists.
What’s In It For You?
Work in an organisation that’s at the forefront of investigative journalism.
Working in an organisation where the threats and both real and actionable.
Being able to work from home (remote). Or from an office (Amsterdam/Sarajevo).
Working with a small but friendly team where there is no office politics.
Professional development opportunities are available depending on your goals.
To Apply
To apply, please email your CV and a Cover Letter to jobs[at]occrp.org
All applications must be submitted in English. Incomplete applications will not be considered. Whilst we have internal goals to reply to unsuccessful candidates, we regret that the high number of applicants greatly exceeds our capacity to respond to each person. We apologize that we will not be able to reply to any unsuccessful applicants.
As an equal opportunity employer, OCCRP values having a diverse workforce and continuously strives to maintain an inclusive and equitable workplace. We offer competitive compensation and benefits and encourage people with a diverse range of backgrounds to apply. We do not discriminate against any person based upon race, religion, color, national origin, sex, medical conditions, family status, sexual orientation, gender identity, gender expression, age, disability, genetic information, or any other legally protected characteristics. If you are a qualified applicant requiring assistance or an accommodation to complete any step of the application process, please contact hr[at]occrp.org
Izvor: https://www.occrp.org/en/occrp-jobs/seni...ty-analyst
Nije domaća kampanja, ali je izletalo po webu, lepo cene u dinarima cak u jednom trenutku sve po 750rsd, meni je prijavila kuma.
Nema malicioznih elemenata, samo prevara: hxxps[:]//mammutsam[.]store
Nema ni detekcija jer je Creation Date: 2023-06-28T09:54:16.OZ
Reportovah.
Izgleda je kompromitovan prim-kostolac.rs. IP: 135.181.136.67, zemlja Finska, provajder Hetzner.
VirusTotal: https://www.virustotal.com/gui/url/a22e7...?nocache=1
Sucuri: https://sitecheck.sucuri.net/results/prim-kostolac.rs
Quote:Sve ovo zvuči kao veoma uspešna i tehnološki napredna akcija evropskih policija. Međutim, imajući u vidu da još uvek ne postoje nedvosmisleni, javno dostupni podaci o načinu otkrivanja sadržaja i kompromitacije Encrochata (a i drugih platformi poput Sky ECC i ANOM), barem nekoliko važnih pitanja o pravnom uporištu ovakvih radnji organa reda zasad ostaje bez odgovora.
Enkripcija podataka i komunikacija nije zabranjena, kao ni usluge koje je pružao Encrochat. Takođe, iako je postojala osnovana sumnja da je veliki broj korisnika njihovih usluga bio povezan sa kriminalnim grupama i aktivnostima, definitivno je bilo i onih koji su bili „čisti“ i plaćali proizvod zarad poverljive poslovne ili privatne komunikacije. Zato je prvo pitanje da li se ovde radilo o targetiranom nadzoru u krivičnom postupku ili masovnom nadzoru, s obzirom na to da je ugrožena tajnost komunikacije i nedužnih građana.
Drugo pitanje se tiče tehnike pribavljanja dokaznih materijala. Britanski stručnjaci su veštačenjem ustanovili da je francuska žandarmerija zarazila sve uređaje Encrochat korisnika tako što im je podmetnula lažnu softversku zakrpu, pa je na taj način izbegla potrebu za razbijanjem enkripcije, jer je uvid u sadržaj komunikacije bio moguć i pre slanja tj. šifrovanja, ili nakon dešifrovanja poruke na prijemnom uređaju. Kao i u mnogim zemljama u svetu, u Srbiji je pravljenje i unošenje računarskih virusa krivično delo predviđeno članom 300 Krivičnog zakonika, pa bi upotreba dokaza pribavljenih na ovaj način bila zabranjena.
Ova pitanja su opsežno analizirana u radu „Encrochat i Sky ECC komunikacija kao dokaz u krivičnom postupku“ dr Vanje Bajović sa Pravnog fakulteta u Beogradu.
Izvor: https://www.sharefoundation.info/sr/encr...ja-hakuje/.
Izgleda da je kompromitovan finvest.rs. IP: 94.127.7.160, zemlja Srbija, provajder SBB.
VirusTotal: https://www.virustotal.com/gui/url/0d860...?nocache=1
Sucuri: https://sitecheck.sucuri.net/results/finvest.rs
Navodno je bio oboren pametnoibezbedno.gov.rs: https://twitter.com/AnonZenn/status/1673854245676761088.
Izgleda da je kompromitovan hajdeda.org.rs. IP: 168.119.145.17, zemlja Nemačka, provajder: Hetzner.
Sucuri: https://sitecheck.sucuri.net/results/htt...eda.org.rs
By CyberBalkan:
https://twitter.com/balkanssec/status/16...-BQ0d7xxxw
There are numerous posts like this targeting various public companies and non-governmental organizations in Serbia
Another example. These accounts are appearing out of nowhere. They stay for a while, until Meta deletes them. Something fishy is going on on that platform in Serbia.
Na sajtu alleybachelorchasecliff[.]com se reklamira Gazprom investiciona platforma, sire se i kampanje na zalost nemam screenshot a istekla je, u tekstu se navodi da su tu investirali i Djokovic i Bikovic, na naslovnoj strani je neki text o Bikovicu koji se nesto tuzi sa NBS jer nece da otkrije kako je zaradio svoje bogatstvo 
Lepo osmisljeno, ali jadno uradjeno
Sajt sam proveravao na vise servisa tipa urlquery, scumware, checkphish i jos uvek niko ne registruje kao phishing, moguce je da je zato sto je skoro registrovan domen
Creation Date: 2023-06-12T15:06:17.00Z
Registrant Email: [email protected]
Registrant City: Kharkiv
hxxps[:]//alleybachelorchasecliff[.]com/?_lp=1&_token=uuid_1k1mac31eq9g_1k1mac31eq9g64a68cef812813.99943286&utm_campaign={utm_campaign}&utm_source={utm_source}&utm_content={utm_content}&utm_medium={utm_medium}&fb={fb}&funnel={funnel}
