Sign in

Drew

@bugfire.io
149 followers 167 following 429 posts

malware detection and analysis, hunting and gathering, threat research Views are my own.

PostsRepliesMedia
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 28/09/2026
New blog: OpenSUpdater Hides in Recompiled 7zip SFX blog.gdatasoftware.com/2026/09/3849...
011
Reposted by Drew
James Wilson @jameswilson.io · 23/09/2026
Ransom payments end up in the wallets of drug and other crime gangs too. This changed my mind about ransom payment regulation. Geoff White (CyberHack, Conti Files, Lazarus Heist) and I sat down for a chat about just how ransomware gangs turn traceable bitcoin into cash. 🎧 risky.biz/RBFEATURES40/
risky.biz
How to launder illicit Bitcoin - Risky Business Media
In this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware [Read More]
043
Reposted by Drew
Brad @malware-traffic-analysis.net · 23/09/2026
To combat the spread of AI slop, I've hand-crafted an image to represent a ClickFix campaign I'm calling "Macfinger ClickFix." Think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore. More info at: isc.sans.edu/diary/33360
031
Reposted by Drew
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 20/09/2026
I’m speechless all over again. 😭 Thanks for including me in this week’s Good News Corner of your weekinsecurity.com newsletter @zackwhittaker.com ! And thanks forever to the @sentinelone.com SentinelLabs LABSCON crew & community for bringing knowledge & magic people together all these years 💜💖🎉
weekinsecurity.com
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
0163
Drew @bugfire.io · 16/09/2026
Great write up on Mythic C2 from Andrew Northern censys.com/blog/mythic-...
censys.com
Mythic C2 Activity at Internet Scale - Censys
Censys tracks 131 hosts exposing Mythic to the public Internet. Learn about the C2 framework and how to defend against it.
001
Reposted by Drew
Ryan Naraine @ryanaraine.bsky.social · 15/09/2026
"That is straight-up fraud."
122
Drew @bugfire.io · 09/09/2026
Facts. The human bar of intelligence is decreasing while the artificial bar is increasing. They will meet sooner than expected.
000
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 06/09/2026
🦔 📹 New Video: Hooking V8 JavaScript ➡️ compiled V8 ➡️ we write a reusable hook script ➡️ we overcome basic anti-hooking #MalwareAnalysisForHedgehogs #V8 #JavaScript www.youtube.com/watch?v=Y8_A...
youtube.com
Malware Analysis - Hooking V8 JavaScript bytecode
YouTube video by MalwareAnalysisForHedgehogs
041
Drew @bugfire.io · 29/08/2026
@bajiri.bsky.social Big shoutout to you as I recently made good use of your EvilAI blog from earlier this year! Excellent content and IOCs!
120
Drew @bugfire.io · 21/08/2026
That timeline tracks with my typical requests
010
Reposted by Drew
James Wilson @jameswilson.io · 11/08/2026
ICYMI: I published a pod on private AI inference. Hosted LLMs that hide your chats from the provider. Trusted execution environments, GPU confidential computing, attestation, KV-cache side channels, and why “we don’t train on your data” is not the same as “we can’t see it.” risky.biz/RBFEATURES34/
risky.biz
How private LLM inference actually works - Risky Business Media
In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without t [Read More]
032
Drew @bugfire.io · 06/08/2026
I second the brain turning off notion!
010
Drew @bugfire.io · 06/08/2026
Ahh. I still need to try Connections.
110
Drew @bugfire.io · 06/08/2026
What has been your longest streak? Or perhaps you’ve never missed one, lol
100
Drew @bugfire.io · 01/08/2026
This was outstanding! Also loved to hear the backstory on Greg breaking into the industry and his relationship with the buddies.
121
Drew @bugfire.io · 31/07/2026
Highly recommend this podcast!
010
Drew @bugfire.io · 31/07/2026
I absolutely LOVE the work you’re doing in this arena! I learn so much from each of these pods, thank you and please keep it going!
100
Reposted by Drew
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22415
Reposted by Drew
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026
Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre....
232
Drew @bugfire.io · 27/07/2026
Sprinkle on some AI and it will be AI slop
000
Drew @bugfire.io · 26/07/2026
Touché
010
Drew @bugfire.io · 24/07/2026
Cynicism is unavoidable with these companies
000
Drew @bugfire.io · 24/07/2026
Amen. It’s absolutely ridiculous how this is being architected.
000
Drew @bugfire.io · 19/07/2026
And AI was not your friend here?
001
Drew @bugfire.io · 18/07/2026
Sums it up
000
Drew @bugfire.io · 16/07/2026
Request denied. I’m sensing a callback phishing opportunity for scammers, however!
010
Drew @bugfire.io · 06/07/2026
Love it!
010
Reposted by Drew
Tim Blazytko @mrphrazer.bsky.social · 02/07/2026
New Binary Cartography episode: Pinpointing Interesting Code in Binaries We cover heuristics for protocols, crypto routines, library functions, RC4, decryption loops -- and how these signals guide agents youtu.be/HQA3U5MnD5U Slides & samples: github.com/mrphrazer/bi...
youtu.be
Pinpointing Interesting Code in Binaries: Heuristics, Statistics, and Agents
YouTube video by Tim Blazytko
031
Reposted by Drew
Censys @censys.bsky.social · 29/06/2026
New research from Censys Senior Security Researcher Aidan Holland maps the AsyncRAT family across ~40 variants. The detection signal is its inherited TLS certificate metadata that persists across forks. Read more: bit.ly/4eQP03m
052
Drew @bugfire.io · 29/06/2026
And apparently needed vice grips to open
110
Reposted by Drew
Tim Blazytko @mrphrazer.bsky.social · 29/06/2026
Premiering at this year's @hexacon.bsky.social: my reworked Software Deobfuscation Techniques training. It now combines deep technical know-how with agentic workflows to automate large-scale deobfuscation. www.hexacon.fr/trainer/soft...
121
Drew @bugfire.io · 26/06/2026
In solitary for sure
000
Drew @bugfire.io · 23/06/2026
This was so insightful getting Katie’s perspective!
000
Drew @bugfire.io · 20/06/2026
Well played
000
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 19/06/2026
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6...
012
Drew @bugfire.io · 19/06/2026
You’ll definitely get a good one soon. Oh and keep saving!
010
Drew @bugfire.io · 19/06/2026
Nice work!
020
Reposted by Drew
ThreatInsight @threatinsight.proofpoint.com · 18/06/2026
#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame. ❌ 100 servers and domains worldwide dismantled ❌ 14,971 websites remediated Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️
141
Drew @bugfire.io · 15/06/2026
Maybe they can close a few for you
000
Drew @bugfire.io · 15/06/2026
Set daily reminders, that always helps me with these things
010
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 14/06/2026
🦔 📹 Poison X kernel mode rootkit analysis ➡️ kernel mode driver theory ➡️ Ghidra markup ➡️ basic string deobfuscation #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=yx6A...
youtube.com
Malware Analysis - PoisonX rootkit, Kernel driver rootkit markup in Ghidra
YouTube video by MalwareAnalysisForHedgehogs
131
Drew @bugfire.io · 14/06/2026
Close enough, good for you
000
Drew @bugfire.io · 07/06/2026
Seems very vibe codable
010
Drew @bugfire.io · 29/05/2026
Nice!
000
Drew @bugfire.io · 29/05/2026
You, LLM or both?
110
Reposted by Drew
Lenny Zeltser @lennyzeltser.com · 26/05/2026
Much of our security work is communicating with colleagues throughout the org. 10 habits that sharpen how the technical work gets heard. zeltser.com/strong-communication-sk…
zeltser.com
10 Communication Tips for Security and IT Professionals
Explaining security and IT work is often harder than the work itself. Ten habits will sharpen how you explain it to specialists, executives, and everyone in between.
061
Drew @bugfire.io · 25/05/2026
It also repels spouses and keeps them from breeding
010
Drew @bugfire.io · 22/05/2026
Need to confirm it's still a problem, makes sense
010
Drew @bugfire.io · 21/05/2026
100%
000
Drew @bugfire.io · 21/05/2026
As long as you're not getting heckled
110