Sign in

Greg Lesnewich

@greg-l.bsky.social
574 followers 367 following 1.5K posts

oh great, now I’m on bluesky

PostsRepliesMedia
Reposted by Greg Lesnewich
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Reposted by Greg Lesnewich
Magnum, T.I.(M.) @hydrationchimp.bsky.social · 18/09/2026
it’s time to give Ms Rachel a gundam
5051411132
Reposted by Greg Lesnewich
ESET Research @esetresearch.bsky.social · 01/09/2026
#ESETresearch hunted for additional context and found that we detected this backdoor between 2020-11 and 2023-11, targeting financial services sector in the Netherlands and Kazakhstan. 1/6 x.com/genthreatlab...
x.com
Gen Threat Labs (@GenThreatLabs) on X
A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021. It kept trying for 11 months. Read more -> https://t.co/z7SSDdpWAq
186
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22414
Reposted by Greg Lesnewich
Saher @saffronsec.bsky.social · 23/07/2026
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
proofpoint.com
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
21815
Reposted by Greg Lesnewich
Yael Grauer @yaelwrites.com · 04/05/2026
I am honored to share the 2026 Pulitzer Prize for Best International Reporting with Dake Kang, Byron Tau, Aniruddha Ghosal and Garance Burke for our reporting revealing how Silicon Valley largely designed and built China's surveillance state and enabled human rights abuses.
The 2026 Pulitzer Prize Announcement
International Reporting
Winner: Dake Kang, Garance Burke, Byron Tau, Aniruddha Ghosal of the Associated Press and Yael Grauer, contributor.

US government allowed and even helped US firms sell tech used for surveillance in China, AP finds.
41822204
Reposted by Greg Lesnewich
Star Wars Holocron @swholocron.bsky.social · 01/05/2026
On this day 35 years ago, HEIR TO THE EMPIRE was released
716539
Reposted by Greg Lesnewich
Carson @neohazard.bsky.social · 16/05/2025
Dodgers broadcast was discussing the science behind the perception of time between children and adults. After hearing the explanation, the color commentator pauses and asks, "Am I gonna feel any better?" Andy Pages then smashes a dinger into space, thus ending the existential crisis on commentary.
4760402176
Reposted by Greg Lesnewich
Wesley Shields @wxs.bsky.social · 23/04/2026
So @xorhex.bsky.social asked (in our YARA keybase chat) how one might only iterate through the last 10 matches of a string in YARA. I took a shot at answering it by logging the last 10 locations of a match in descending order: for all i in (0..10): (console.log(@a[#a - i]))
132
Reposted by Greg Lesnewich
Vitaly Kamluk @vkamluk.bsky.social · 24/04/2026
After 11 years of silence at Black Hat, I am delivering a speech today. In memory of a legendary APT Hunter, Mr Sergey Mineev, who passed away 40 days ago. If you cannot attend, here is the write-up: www.sentinelone.com/labs/fast16-...
sentinelone.com
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet
A previously unknown 2005 cyber sabotage framework patches high-precision calculation software in memory to silently corrupt results.
061
Reposted by Greg Lesnewich
Vitaly Kamluk @vkamluk.bsky.social · 23/04/2026
After 11 years, I'm returning to the Black Hat stage. The last time, in 2015, I gave a joint talk with INTERPOL - their first-ever appearance at Black Hat. If you're around, come support me tomorrow - I promise the talk goes well beyond what you'll find in the abstract.
011
Greg Lesnewich @greg-l.bsky.social · 18/04/2026
PEMDAS, but for the correct order to eat fruit snacks
010
Greg Lesnewich @greg-l.bsky.social · 11/04/2026
Easter dinner was a movie (a delicious Dune knock off)
050
Reposted by Greg Lesnewich
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 09/04/2026
#binjaextras has been updated to allow for type information to be applied to both struct members and global variables. Local instance of OALab's hashdb has been added as well - see setup info here: github.com/xorhex/binja... Install/update binjaextras via the plugin manager! #BinaryNinja
github.com
021
Reposted by Greg Lesnewich
Andy Gill @zephrfish.yxz.red · 04/04/2026
This is what happens when I take time off, I actually write silly length blog posts and deep dive things blog.zsec.uk/bullyingllms/ the post dives into a MCP pipeline I've put together for autonomous 0day hunts.
blog.zsec.uk
Autonomous Vulnerability Hunting with MCP
Alt title: Bullying LLMs into submission to find 0days at scale
031
Reposted by Greg Lesnewich
Pasquale Stirparo 🇺🇦 🇪🇺 @pstirparo.bsky.social · 31/03/2026
RationalEdge #REDS new release: Maliciousness #Score, #AI Assisted Full Sample Analysis, and a new #Behaviour Panel. rationaledge.io/blog/malicio... @rationaledge.bsky.social #ThreatResearch #ThreatIntel #CTI #Malware #MalwareAnalysis #ReverseEngineering 1/4
rationaledge.io
Maliciousness Scoring, AI Sample Analysis, and a New Behaviour Panel | RationalEdge - Know Why
REDS ships maliciousness risk scoring powered by Malcontent, a dedicated behaviour panel, and AI-assisted full sample analysis with built-in analyst feedback.
182
Reposted by Greg Lesnewich
ThreatInsight @threatinsight.proofpoint.com · 27/03/2026
Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵
11713
Reposted by Greg Lesnewich
Solomon @solomonrmissouri.com · 14/03/2026
I’m not interested in skinny propaganda in any form I was on board when Oprah was built up like a Baltimore row house
234035
Reposted by Greg Lesnewich
Solomon @solomonrmissouri.com · 14/03/2026
Them Europeans cannot be your standard for beauty… they almost died because they wouldn’t wash their hands
3461106
Greg Lesnewich @greg-l.bsky.social · 11/03/2026
Bam Adebayo is doing WHAT right now???
100
Reposted by Greg Lesnewich
PIVOTcon @pivotcon.bsky.social · 10/03/2026
📣 #PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's edition! 2⃣ days and 19 talks from leading #ThreatResearch experts. The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵 #CTI #ThreatIntel 1/15
11610
Greg Lesnewich @greg-l.bsky.social · 07/03/2026
Can someone smarter than me tell me if the cyber strategy for america from the regime means anything for me personally?
330
Reposted by Greg Lesnewich
Solomon @solomonrmissouri.com · 04/03/2026
Christopher Kempczinski bit into that burger like it was the first time he'd every tasted a McDonalds burger AND... This is actually a case study on how American companies no longer promote within
1231646
Greg Lesnewich @greg-l.bsky.social · 02/03/2026
Since things are #rough out here right now, I figured I’d share a fun story Back in the early 00’s, my uncle worked at some manufacturer that sponsored a bunch of NASCAR cars and would regularly get tickets to the events
media.tenor.com
a race car is driving down a track with spike written on the bottom of the screen
ALT: a race car is driving down a track with spike written on the bottom of the screen
130
Greg Lesnewich @greg-l.bsky.social · 09/02/2026
Staying off socials to keep my mentals in order but had to come in here to say that I’m certain Bad Bunny had more yards from scrimmage than the Pats in that first half
360
Reposted by Greg Lesnewich
ESET Research @esetresearch.bsky.social · 23/01/2026
#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5
13429
Reposted by Greg Lesnewich
Solomon @solomonrmissouri.com · 22/01/2026
You fear innovation
0224
Reposted by Greg Lesnewich
Kim Zetter @kimzetter.bsky.social · 22/01/2026
"A superpower is choosing to self-immolate and torch its remaining global trust and friendships, including and especially NATO...at the precise moment when it had been reinvigorated and renewed...in the wake of Russia’s large-scale invasion of Ukraine in 2022" - by @vermontgmg.bsky.social
wired.com
We Are Witnessing the Self-Immolation of a Superpower
With Donald Trump’s actions in Greenland, Minneapolis, and Venezuela, a foreign enemy could not invent a better chain of events to wreck the standing of the United States.
04717
Reposted by Greg Lesnewich
Aaron Sojourner @aaronsojourner.org · 16/01/2026
They have quite an operation going. www.mprnews.org/episode/2026...
mprnews.org
Minneapolis church has delivered more than 12,000 boxes of groceries to families in hiding
DHH church has hundreds of volunteers packing and delivering groceries to families who have been too scared to leave their homes during the immigration operation.
11465511890
Greg Lesnewich @greg-l.bsky.social · 16/01/2026
I don’t think we’ve collectively paid enough attention to the fact that Annie’s is now the regent of boxed Mac and cheese Kraft got their chain snatched and now it just tastes like dog water compared to Annie’s
340
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 14/01/2026
#100daysofYARA - day 12 VirusTotal uses CAPE sandbox to identify many malware families and determine if they can extract the malware's configuration. Since they use CAPE, we can often see their logic. Today, we'll suggest edits to a rule for AgentTesla. Rule at end. 1/10
176
Reposted by Greg Lesnewich
Nick from Weymouth 🇺🇦🇺🇸 @nicastronaut.bsky.social · 13/01/2026
Imagine publishing a blog on "Lazarus" in the year of our lord 2026
462
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 12/01/2026
#100DaysofYARA - Day 11 In looking at automatic YARA generation, yarGen-Go is a must. Just released by @cyb3rops, it is a rewrite and advancement from the original yarGen. We'll look at the same malware from day 10; a targeted HavocC2 loader with decoy. rule at bottom 1/5
162
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 10/01/2026
This scripts are deceptive as they contain 10,000 empty lines. BTW #malcat loads scripts like these better than most text editors. If I get the chance, I may revise it to see how to find ones without the matching text or if you have ideas, hmu. github.com/Squiblydo... 3/3
github.com
100DaysofYARA/Squiblydoo/Day9.yara at main · Squiblydoo/100DaysofYARA
Rules shared by the community from 100 Days of YARA 2026 - Squiblydoo/100DaysofYARA
041
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 10/01/2026
The rule is fairly simple but it seems that at least one DPRK team is using the same consistent message in the header. I validated this using ReversingLab's YARA scanning. A slightly different header is seen in Huntress' analysis: www.huntress.com/blo... 2/3
huntress.com
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
111
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 10/01/2026
#100DaysofYARA - Day 9 YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems. Script is delivered to victims disguised as a Zoom meeting launcher. e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892 Rule at end 1/3
132
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 08/01/2026
#100DaysofYARA - Day 8 For many years, many attackers tried to keep their binaries small. However, the others found the opposite works too: extremely large binaries can cause problems with analysis. What can be done about these large executables? Rule at end 1/6
112
Reposted by Greg Lesnewich
Solomon @solomonrmissouri.com · 08/01/2026
The same people spent the last decade justifying Black folks being choked to death on camera… they’ve been practicing
6728190
Reposted by Greg Lesnewich
sina @rejectionking.bsky.social · 07/01/2026
congress should behave like a co equal branch impeachment defunding filing suits subpoenas writing laws hearings, hearings, hearings what else?
1165
Reposted by Greg Lesnewich
X_Hunt3r @x-hunt3r.bsky.social · 07/01/2026
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
recordedfuture.com
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
175
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 07/01/2026
#100DaysofYARA - Day 7 @malwrhunterteam identified a suspicious file signed by "Xiamen Jialan Guang Information Technology Service Co., Ltd." While we have a pretty good idea it'll be abused, it hasn't been yet. So, lets watch for it to be abused. Rule at end 1/5
121
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 06/01/2026
#100DaysofYARA - Day 6 In December and again in January, an unknown actor replaced the download on EmEditor's website with a malicious installer. Each time, the download was a trojan installer with a valid code-signing signature. How can we detect this? Rule at end 1/6
162
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 05/01/2026
YARA-X can dump the certificate details of a MACHO binary. "yr dump [file]" shows the data produced by the modules We can output it to JSON and pass it to jq as like this: yr dump -o=json [file] | jq '.macho.certificates' 3/7
231
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 04/01/2026
#100DaysofYARA - Day 4 One heavy user of code-signing certificates is Rhysida Ransomware. In June, I created a YARA rule focusing on their malware to help me find and report their certificates. To do so, I had to create a YARA rule on the Rich PE Header. Rule at end 1/7
142
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 05/01/2026
#100DaysofYARA - day 5 The Cert Graveyard project reports and documents abuse code-signing including Apple issued certificates. When reporting a certificate, we want to ensure Apple has all the identifiers they need to investigate and act. Rule at end 1/7
173
Reposted by Greg Lesnewich
hakan @hatr.bsky.social · 05/01/2026
I really do love|hate RegExes. This week, a short walkthrough on how to use them to find DPRK hackers. buttondown.com/readwrite/ar...
buttondown.com
Edition 6 – Using RegEx to catch state-sponsored hackers
Hi, Hakan here. This one is going to be straightforward. Both Jan and I are using RegEx quite regularly, so this is a how to: using RegEx to find out more...
2126
Greg Lesnewich @greg-l.bsky.social · 04/01/2026
Listening to a lot of A Thousand Suns recently Not sure why, surely not some subliminal or subconscious reason
110
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 03/01/2026
#100DaysofYARA - Day 3 This relates to obfusheader discussed by @RussianPanda95 and @c0ner0ne. If the dev is going to use hard-coded strings, lets use them to our advantage. This thread will demo Malcat's YARA features. Rule at end of thread 1/5
143
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 02/01/2026
For making the rule, I again used #malcat. I highlighted the smaller icon and added it to the YARA rule: "right-click" > "add selection to YARA" > "New rule". Couldn't be easier. github.com/Squiblydo... 4/4
041
Reposted by Greg Lesnewich
Squiblydoo @squiblydoo.bsky.social · 02/01/2026
#100DaysofYARA - Day 2 YARA rule to detect the default Delphi darkmode dib icon. I've seen this icon excessively over the years. Using @unpacme 's YARA hunting tools, I saw 0 known goodware and 800 packed junk. Rule at end 1/4
283