Sign in

Jamie Levy 🦉

@gleeda.bsky.social
2.8K followers 782 following 148 posts

@volatilityfoundation.org Core Dev | Art of Memory Forensics co-author | DFIR trainer and enthusiast | Director of Adversary Tactics @huntress.com

PostsRepliesMedia
Jamie Levy 🦉 @gleeda.bsky.social · 19/08/2026
I hadn't seen Google Docs weaponized like that before. Jonathan Semon, Ryan Dowd, and @threatresearch.bsky.social spent some time hunting everything down and it turned out a little more interesting than previously thought. We never got that linux lure though 🤣 www.huntress.com/blog/defcon-...
huntress.com
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware | Huntress
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
021
Jamie Levy 🦉 @gleeda.bsky.social · 12/02/2026
We're looking for a Principal Threat Intel Incident Commander here at @huntress.com ! Do you love to: 🔍 Conduct #DFIR analysis? 👀 Track threat actors? 🕸️ Work with others across different departments? ✍️ Write about your findings? 👩‍💼 Present your work? Apply!: job-boards.greenhouse.io/huntress/job...
job-boards.greenhouse.io
Principal Threat Intel Incident Commander
United States of America
052
Reposted by Jamie Levy 🦉
✨[redacted]✨ @britculpsapp.bsky.social · 29/01/2026
just choked on my beverage
daendeleon 2d
@ Threads
Greg Bovino was asked how he felt about his demotion today. "Well, obviously, I'm not happy", he replied.
Someone in the crowd shouted back, "So which one are you?"
57183083184
Jamie Levy 🦉 @gleeda.bsky.social · 07/11/2025
There's an open role for a Staff CTI Analyst on my team here @huntress.com 📢💫 ✨Do you love doing correlations between different incidents, sometimes digging into them, or doing malware analysis? ✨Do you like doing data analysis, and using this to make threat reports? 👇
175
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 01/08/2025
We are excited to announce that we are hosting a second training course for #FTSCon week! Join @joegrand.bsky.social as he leads his popular 2-day Hardware Hacking Basics course on Oct. 21-22 in Arlington VA! Registration is now OPEN!
events.humanitix.com
Joe Grand's Hardware Hacking Basics [FTSCon 2025]
This two-day comprehensive course teaches fundamental hardware hacking concepts and techniques used to explore, manipulate, and exploit electronic devices.
145
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 15/09/2025
We are so excited to have @joegrand.bsky.social keynoting at #FTSCon 2025! Come join us on October 20th!
023
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
We are counting down to #FTSCon 2025! We have a slate of great speakers—you don't want to miss this event! 
If you haven't registered yet, register here: events.humanitix.com/from-the-sou.... Stay tuned for speaker spotlights!
volatilityfoundation.org
From The Source 2025
Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou…
003
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Juan Andrés Guerrero-Saade is presenting “From Threat Hunting to Threat Gathering” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
014
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Toni de la Fuente is presenting “Open Cloud Security, lessons learned building Prowler” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
003
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
046
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Aleksandra Doniec (@hasherezade.bsky.social) is presenting “Uncovering Malware's Secrets with TinyTracer” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
026
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Joseph Edwards (@eflags.bsky.social) is presenting “The Forensics of Zoom's Remote Control” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
014
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Andrew Case (@attrc.bsky.social) is presenting “Detection and Analysis of Memory-Only Linux Rootkits” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
024
Reposted by Jamie Levy 🦉
Joseph @eflags.bsky.social · 18/09/2025
Excited to speak at FTSCon next month!
032
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 19/09/2025
#FTSCon Speaker Spotlight: Joe FitzPatrick (@securelyfitz.bsky.social) is presenting “Rethinking DMA Attacks with Erebus” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
015
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 19/09/2025
#FTSCon Speaker Spotlight: Daniel Gordon (@validhorizon.bsky.social) is presenting “When the AppleJeus GitHub is Worth the Squeeze: Citrine Sleet Investigation” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
063
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 19/09/2025
#FTSCon Speaker Spotlight: Denis Bueno is presenting “CTADL: Customizable Static Taint Analysis” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
004
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 19/09/2025
#FTSCon Speaker Spotlight: Michael Horka is presenting “Lilac Typhoon aboard the Indigo Train - The Current State of Chinese Obfuscation Networks” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
065
Reposted by Jamie Levy 🦉
Taggart @taggart-tech.com · 09/09/2025
An incredible firsthand glimpse into threat actor operations from Huntress:
huntress.com
An Attacker’s Blunder Gave Us a Look Into Their Operations | Huntress
An attacker installed Huntress onto their operating machine, giving us a detailed look at how they’re using AI to build workflows, searching for tools like Evilginx, and researching targets like software development companies.
052
Reposted by Jamie Levy 🦉
CYBERWARCON @cyberwarcon.bsky.social · 18/08/2025
CYBERWARCON is back. 🗓️ Wednesday, Nov 19, 2025 | Crystal City + virtual 🔗 cyberwarcon.com
1125
Reposted by Jamie Levy 🦉
BSidesNoVA @bsidesnova.bsky.social · 16/08/2025
Last chance to be a part of *THE* premier #InfoSec event in Northern Virginia, #BSidesNoVA! Submit a talk or workshop by 11:59PM ET tonight, August 15th. sessionize.com/bsidesnova-2...
Call for Presentations. Deadline is 11:59PM ET Friday, August 15th. October 10-11 Arlington, Virginia. sessionize.com/bsidesnova-2025. #BSidesNoVA
023
Jamie Levy 🦉 @gleeda.bsky.social · 04/08/2025
We've seen quite a lot of intrusions involving SonicWall devices here at @huntress.com We decided to write a bit about what attacker tradecraft we've seen on the other end of these intrusions: 🔎 www.huntress.com/blog/exploit...
huntress.com
Active Exploitation of SonicWall VPNs | Huntress
A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access...
031
Reposted by Jamie Levy 🦉
BSidesNYC @bsidesnyc.org · 31/07/2025
BSidesNYC thanks @gleeda.bsky.social and the rest of the 0x05 Technical CFP Committee, @cyb3rkitties.bsky.social, Cesar Vargas, Jase English, Jamie Williams, Jessica Hyde, @rmettig.com, and Stephanie Aceves for volunteering their time to review talks. Many thanks for curating our programming.
022
Reposted by Jamie Levy 🦉
BSidesNYC @bsidesnyc.org · 27/06/2025
The BSidesNYC call for papers is still open. Submit your topic today! bsidesnyc.org
034
Reposted by Jamie Levy 🦉
Brendan Dolan-Gavitt @moyix.net · 24/06/2025
This is the first of a series of posts we're doing on some of the vulns found as part of the HackerOne work – we have lots more fun ones coming up about some great SSRF, SQLi, and RCE vulns it discovered, with very clever exploit techniques :)
083
Reposted by Jamie Levy 🦉
alden @re.wtf · 18/06/2025
excited bc today @huntress.com is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🤠 we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)! www.huntress.com/blog/inside-...
huntress.com
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
12919
Reposted by Jamie Levy 🦉
Volexity @volexity.com · 22/04/2025
@volexity.com #threatintel: Multiple Russian threat actors are using Signal, WhatsApp & a compromised Ukrainian gov email address to impersonate EU officials. These phishing attacks abuse 1st-party Microsoft Entra apps + OAuth to compromise targets. www.volexity.com/blog/2025/04...

#dfir
volexity.com
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows
Since early March 2025, Volexity has observed multiple suspected Russian threat actors conducting highly targeted social engineering operations aimed at gaining access to the Microsoft 365 (M365) acco...
01712
Reposted by Jamie Levy 🦉
Volexity @volexity.com · 16/05/2025
Congratulations to all of the Volatility contributors - this was no small feat! We are proud to be a sustaining sponsor of this important open-source project that remains the world’s most widely used memory forensics platform. #dfir
0107
Reposted by Jamie Levy 🦉
Volatility @volatilityfoundation.org · 23/05/2025
We are excited to announce FTSCon 2025 on October 20, 2025, in Arlington VA! Registration is now OPEN + we have a Call for Speakers. Following FTSCon will be a 4-day Malware & Memory Forensics Training course with Volatility 3. See the full details here: volatilityfoundation.org/announcing-f...
volatilityfoundation.org
Announcing FTSCon 2025 & In-person Malware and Memory Forensics Training!
Mark your calendars for Monday, October 20, 2025! We will again be hosting FTSCon in Arlington, Virginia.You can read more event details here. Registration is now open!
079
Jamie Levy 🦉 @gleeda.bsky.social · 07/06/2025
It’s raining, and feeding time, so what do we do? Sheep and goat dance set!!! 💣💥 turn up the volume! 🔊🔊
050
Reposted by Jamie Levy 🦉
Whitney Merrill @wbm312.bsky.social · 03/05/2025
Lots of new stickers! thegarbagefile.etsy.com
1118922
Reposted by Jamie Levy 🦉
CyberRaiju @jaiminton.com · 07/05/2025
We have reached out to Samsung. There is active exploitation in the wild. Be sure to look for new files created in the server directory of your MagicInfo install, and child processes spawning from the Apache Tomcat process.
101
Reposted by Jamie Levy 🦉
CyberRaiju @jaiminton.com · 07/05/2025
The version offered on their website via the download button is currently not even the latest, so even if it was patched (it isn't, the vulnerable class has not changed at all) anyone downloading the software is getting an outdated version! No updates here: security.samsungtv.com/securityUpda...
101
Reposted by Jamie Levy 🦉
CyberRaiju @jaiminton.com · 07/05/2025
I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below. ssd-disclosure.com/ssd-advisory... The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
132
Jamie Levy 🦉 @gleeda.bsky.social · 30/04/2025
Today’s mood m.youtube.com/watch?v=bWur...
m.youtube.com
Parliament - Flashlight (HQ)
YouTube video by Trellheim
020
Reposted by Jamie Levy 🦉
Huntress @huntress.com · 22/04/2025
Huntress continues to observe in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in Gladinet CentreStack and Triofox
112
Reposted by Jamie Levy 🦉
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 23/04/2025
Some good takeaways from @huntress.com’s recent Tradecraft Tuesday ft. Patrick Wardle: -The impact of Apple bringing TCC events to Endpoint Security -#Mac malware persistence techniques vs BTM -Security alert inundation for #macOS users Catch up here⤵️ www.huntress.com/blog/say-hel...
huntress.com
Say Hello to Mac Malware | Huntress
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
023
Reposted by Jamie Levy 🦉
Huntress @huntress.com · 16/04/2025
Exposed RDP can lead to anything—even attempted ransomware attacks. Here’s what went down at this manufacturing business👇
122
Jamie Levy 🦉 @gleeda.bsky.social · 14/04/2025
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild! We've got some post exploitation and detection opportunities for you: #DFIR #threatintel #CTI www.huntress.com/blog/cve-202...
huntress.com
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild | Huntress
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
110
Reposted by Jamie Levy 🦉
Huntress @huntress.com · 14/04/2025
Huntress has observed in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in the Gladinet CentreStack enterprise file-sharing platform.
143
Jamie Levy 🦉 @gleeda.bsky.social · 10/04/2025
When you've replied to a tweet from S1 a couple months ago asking for an updated url for a panel Chris Krebs was on, and wake up to a hate bot storm demanding his head. oh what a time to be alive 🫠
050
Jamie Levy 🦉 @gleeda.bsky.social · 08/04/2025
CVE-2025-2825 or CVE-2025-31161: A vulnerability by any other name is still a threat 😇: We've updated the blog to reflect some new attacker tradecraft observed yesterday cc @huntress.com @re.wtf @johnhammond.bsky.social #DFIR #vuln #CVE www.huntress.com/blog/crushft...
huntress.com
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation | Huntress
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
031
Jamie Levy 🦉 @gleeda.bsky.social · 01/04/2025
✅Are you well versed in Linux? ✅Do you understand Linux internals and eBPF? ✅ Do you like building out POCs? ✅Do you understand cyber threats and forensic artifacts? 💥Become a Principal Linux Researcher at @huntress.com Apply here: 👉 job-boards.greenhouse.io/huntress/job...
job-boards.greenhouse.io
Principal Security Researcher - Linux
Remote US
064
Jamie Levy 🦉 @gleeda.bsky.social · 12/03/2025
🤣🤣🤣🤣
060
Reposted by Jamie Levy 🦉
PatriotTakes 🇺🇸 @patriottakes.bsky.social · 11/03/2025
They like it!
29759129
Reposted by Jamie Levy 🦉
David Gilbert @davidgilbert.bsky.social · 11/03/2025
MUSK: A sophisticated cyberattack from Ukraine took out Twitter's servers REALITY: Twitter's servers were not secured properly and were publicly visible Great explainer here from @lhn.bsky.social www.wired.com/story/x-ddos...
wired.com
What Really Happened With the DDoS Attacks That Took Down X
Elon Musk said a “massive cyberattack” disrupted X on Monday and pointed to “IP addresses originating in the Ukraine area” as the source of the attack. Security experts say that's not how it works.
17865482356
Jamie Levy 🦉 @gleeda.bsky.social · 05/03/2025
👏👏👏👏
020
Reposted by Jamie Levy 🦉
Blue Heron Farm @blueheronfarm.bsky.social · 28/02/2025
Everybody's already mad at me today, so I will just say, as a farmer, whoever this lady is -- she's right. The price of cheap eggs is paid for in abusive labor practices, abuse to animals, and abuse to the planet. I know I've said this before. People weren't as mad at me then. Lol
1155980
Reposted by Jamie Levy 🦉
Volexity @volexity.com · 26/02/2025
@volexity.com Volcano Server & Volcano One v25.02.21 adds 300 new YARA rules; consistent Bash/ZSH history & sessions from Linux/macOS memory and files; and parses Linux systemd journals, macOS unified logs, and Windows USNs (search + timeline for all). [1/2] #dfir #memoryforensics #memoryanalysis
An image of the blue and orange Volexity Volcano logo with a New Release banner to announce the release of Volcano Server & Volcano One v25.02.21
165