Log inSign up
Greg Lesnewich
7,316 posts
@greglesnewich

Greg Lesnewich

@greglesnewich
great, now I'm on twitter
Joined May 2020
800
Following
3,857
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @greglesnewich
    Greg Lesnewich
    @greglesnewich
    Aug 22
    Happy to announce I enjoyed Project Hail Mary
    4
  • @greglesnewich
    Greg Lesnewich
    @greglesnewich
    Aug 12
    Shout out to LLMs because I am learning about so much fun syntax and capabilities in querying databases that I probably never would have learned about from just googling
  • @greglesnewich
    Greg Lesnewich
    @greglesnewich
    Aug 12
    Pure slop (the good kind) 🕵️
    Image
    2
  • @greglesnewich
    Greg Lesnewich
    @greglesnewich
    Aug 11
    Reflecting on the magnet of threats concept - having a diverse customer base (the other 98% who rarely see something “interesting”) is critically important - otherwise everything in that 2% bucket will be anomalous that you can’t easily filter out
  • @greglesnewich
    Greg Lesnewich
    @greglesnewich
    Aug 4
    Question on this for Kostas and the whole group - do any EDR platforms instrument the browser to see the JS? Or too noisy?
    @Kostastsale
    Kostas
    @Kostastsale
    Jul 30
    Proofpoint published research on OWAReaper, a browser implant exploiting CVE-2026-42897 in Outlook Web Access. What stands out is that everything happens inside the browser. It uses GitHub queries for commands and CDN proxies or DNS tunnelling for exfil. For most orgs out there,
    Flowchart detailing OWAReaper's operation in exploiting Outlook Web Access vulnerabilities for theft, command control, and data exfiltration. Credit: Proofpoint
    5
Advertisement
Advertisement