Reposted by DrewKarsten Hahn @struppigel.bsky.social · 28/09/2026New blog: OpenSUpdater Hides in Recompiled 7zip SFX blog.gdatasoftware.com/2026/09/3849... 011
Reposted by DrewJames Wilson @jameswilson.io · 23/09/2026Ransom payments end up in the wallets of drug and other crime gangs too. This changed my mind about ransom payment regulation. Geoff White (CyberHack, Conti Files, Lazarus Heist) and I sat down for a chat about just how ransomware gangs turn traceable bitcoin into cash. 🎧 risky.biz/RBFEATURES40/risky.bizHow to launder illicit Bitcoin - Risky Business MediaIn this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware [Read More] 043
Reposted by DrewBrad @malware-traffic-analysis.net · 23/09/2026To combat the spread of AI slop, I've hand-crafted an image to represent a ClickFix campaign I'm calling "Macfinger ClickFix." Think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore. More info at: isc.sans.edu/diary/33360 031
Reposted by DrewKatie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 20/09/2026I’m speechless all over again. 😭 Thanks for including me in this week’s Good News Corner of your weekinsecurity.com newsletter @zackwhittaker.com ! And thanks forever to the @sentinelone.com SentinelLabs LABSCON crew & community for bringing knowledge & magic people together all these years 💜💖🎉weekinsecurity.com~this week in security~a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more. 0163
Drew @bugfire.io · 16/09/2026Great write up on Mythic C2 from Andrew Northern censys.com/blog/mythic-...censys.comMythic C2 Activity at Internet Scale - CensysCensys tracks 131 hosts exposing Mythic to the public Internet. Learn about the C2 framework and how to defend against it. 001
Drew @bugfire.io · 09/09/2026Facts. The human bar of intelligence is decreasing while the artificial bar is increasing. They will meet sooner than expected. 000
Reposted by DrewKarsten Hahn @struppigel.bsky.social · 06/09/2026🦔 📹 New Video: Hooking V8 JavaScript ➡️ compiled V8 ➡️ we write a reusable hook script ➡️ we overcome basic anti-hooking #MalwareAnalysisForHedgehogs #V8 #JavaScript www.youtube.com/watch?v=Y8_A...youtube.comMalware Analysis - Hooking V8 JavaScript bytecodeYouTube video by MalwareAnalysisForHedgehogs 041
Drew @bugfire.io · 29/08/2026@bajiri.bsky.social Big shoutout to you as I recently made good use of your EvilAI blog from earlier this year! Excellent content and IOCs! 120
Reposted by DrewJames Wilson @jameswilson.io · 11/08/2026ICYMI: I published a pod on private AI inference. Hosted LLMs that hide your chats from the provider. Trusted execution environments, GPU confidential computing, attestation, KV-cache side channels, and why “we don’t train on your data” is not the same as “we can’t see it.” risky.biz/RBFEATURES34/risky.bizHow private LLM inference actually works - Risky Business MediaIn this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without t [Read More] 032
Drew @bugfire.io · 06/08/2026What has been your longest streak? Or perhaps you’ve never missed one, lol 100
Drew @bugfire.io · 01/08/2026This was outstanding! Also loved to hear the backstory on Greg breaking into the industry and his relationship with the buddies. 121
Drew @bugfire.io · 31/07/2026I absolutely LOVE the work you’re doing in this arena! I learn so much from each of these pods, thank you and please keep it going! 100
Reposted by DrewGreg Lesnewich @greg-l.bsky.social · 29/07/2026So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...proofpoint.comCleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint USThreat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release 22415
Reposted by DrewThreatInsight @threatinsight.proofpoint.com · 28/07/2026Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre.... 232
Drew @bugfire.io · 16/07/2026Request denied. I’m sensing a callback phishing opportunity for scammers, however! 010
Reposted by DrewTim Blazytko @mrphrazer.bsky.social · 02/07/2026New Binary Cartography episode: Pinpointing Interesting Code in Binaries We cover heuristics for protocols, crypto routines, library functions, RC4, decryption loops -- and how these signals guide agents youtu.be/HQA3U5MnD5U Slides & samples: github.com/mrphrazer/bi...youtu.bePinpointing Interesting Code in Binaries: Heuristics, Statistics, and AgentsYouTube video by Tim Blazytko 031
Reposted by DrewCensys @censys.bsky.social · 29/06/2026New research from Censys Senior Security Researcher Aidan Holland maps the AsyncRAT family across ~40 variants. The detection signal is its inherited TLS certificate metadata that persists across forks. Read more: bit.ly/4eQP03m 052
Reposted by DrewTim Blazytko @mrphrazer.bsky.social · 29/06/2026Premiering at this year's @hexacon.bsky.social: my reworked Software Deobfuscation Techniques training. It now combines deep technical know-how with agentic workflows to automate large-scale deobfuscation. www.hexacon.fr/trainer/soft... 121
Reposted by DrewKarsten Hahn @struppigel.bsky.social · 19/06/2026New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6... 012
Reposted by DrewThreatInsight @threatinsight.proofpoint.com · 18/06/2026#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame. ❌ 100 servers and domains worldwide dismantled ❌ 14,971 websites remediated Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️ 141
Reposted by DrewKarsten Hahn @struppigel.bsky.social · 14/06/2026🦔 📹 Poison X kernel mode rootkit analysis ➡️ kernel mode driver theory ➡️ Ghidra markup ➡️ basic string deobfuscation #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=yx6A...youtube.comMalware Analysis - PoisonX rootkit, Kernel driver rootkit markup in GhidraYouTube video by MalwareAnalysisForHedgehogs 131
Reposted by DrewLenny Zeltser @lennyzeltser.com · 26/05/2026Much of our security work is communicating with colleagues throughout the org. 10 habits that sharpen how the technical work gets heard. zeltser.com/strong-communication-sk…zeltser.com10 Communication Tips for Security and IT ProfessionalsExplaining security and IT work is often harder than the work itself. Ten habits will sharpen how you explain it to specialists, executives, and everyone in between. 061