Sign in

Lasq

@lasq.pl
158 followers 111 following 37 posts

Advanced Practices 🦅 @Google Threat Intelligence Group Threat Attribution, Frontline Intelligence, Malware Analysis, Threat Hunting, Incident Response #attributionmatters

PostsRepliesMedia
Lasq @lasq.pl · 25/06/2026
Oops, might need a bigger plan. 😉 GLM 5.2 is an absolute powerhouse, but I miss how incredibly efficient GLM 5.1 was on the wallet—felt like I could push 4x the volume and never even blink at a rate limit. Back to Composer for now. #AI #LLM #GLM5
110
Lasq @lasq.pl · 02/04/2026
New blog post, tested a few Qwen 3.5 models with Hermes-Agent to see how it tackles simple powershell obfuscation: malfind.com/posts/2026-0...
malfind.com
Testing local LLMs: Qwen 3.5 vs. PowerShell Obfuscation
Malware Analysis and AI Research Blog
000
Lasq @lasq.pl · 26/11/2025
Google #antigravity taking over the manual testing in the browser from you, all the blue cursor actions are automated by Gemini3, I only sit and watch (and record). Then it takes screenshots and write a report for you. Very impressive.
000
Lasq @lasq.pl · 08/10/2025
🚨 NEW VIDEO! I tested the AI-powered #PromptLock ransomware, and it failed spectacularly! 🤯 Impact: 0/10. Fun: 11/10. Watch it here: www.youtube.com/watch?v=-qex... #Ransomware #AI #Cybersecurity
youtube.com
I Tested The World's First "AI Ransomware"... And It Was A Disaster
YouTube video by Malfind Labs
000
Reposted by Lasq
tlansec @tlansec.bsky.social · 21/07/2025
@volexity.com is looking to grow our Threat Intelligence team. New job posting for Senior Analyst role is up here: www.volexity.com/company/care... If you have any questions, don't hesitate to ask.
volexity.com
Open Position
Career Opportunity: Volexity is currently looking to hire Senior Threat Intelligence Analyst to join its rapidly growing services team.
2127
Lasq @lasq.pl · 23/07/2025
Microsoft, what in seven hells is that? This just randomly popped up on my screen, and yes it's animated. Also how cool is the fact that according to Microsoft I need to throw away my $5k PC just because I don't have TPM module (yes I know there are workarounds)
010
Reposted by Lasq
Sean Morrow @snmrrw.bsky.social · 19/05/2025
Wow: after 15 years, YouTube has taken down the original 'Rick Roll' video due to a "licensing issue," likely due to the acquisition of Astley's record lable. The metadata remains, but if you click through it goes to 'video not found': www.youtube.com/watch?v=dQw4...
youtube.com
Rick Astley - Never Gonna Give You Up (Official Music Video)
YouTube video by Rick Astley
49456222675
Lasq @lasq.pl · 05/05/2025
Current vibes... 😅
000
Lasq @lasq.pl · 30/04/2025
Vibe coding is real…
media2.giphy.com
https://media2.giphy.com/media/1lDEYJWZYBowUTrwIL/200.gif
000
Lasq @lasq.pl · 25/04/2025
I was just blown away by Gemini 2.5 Pro capabilities to write python code. It took ~5 minutes to refactor 1500 LOC python script the way I wanted. What's even better is that it also fixed a few other minor bugs, added comments, debug messages, and improved the overall readability of the code. 1/3
110
Reposted by Lasq
J. A. Guerrero-Saade (JAGS) @jags.bsky.social · 09/04/2025
Oooh!!
141
Reposted by Lasq
ESET Research @esetresearch.bsky.social · 26/03/2025
In July 2024, #ESETresearch discovered that the China-aligned #FamousSparrow APT group, thought at the time to have been inactive since 2022, compromised the network of a US trade group and a Mexican research institute. www.welivesecurity.com/en/eset-rese... 1/5
welivesecurity.com
You will always remember this as the day you finally caught FamousSparrow
ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor.
21311
Reposted by Lasq
Eliot Higgins @eliothiggins.bsky.social · 26/03/2025
Following multiple denials from Trump and participants in the "Houthi PC small group" Signal group that information shared was classified, The Atlantic is now sharing information posted in the group. It's fair to say it has a big "Classified" energy around it. www.theatlantic.com/politics/arc...
theatlantic.com
Here Are the Attack Plans That Trump’s Advisers Shared on Signal
The administration has downplayed the importance of the text messages inadvertently sent to The Atlantic’s editor in chief.
25561152
Reposted by Lasq
Dakota @dakotaindc.bsky.social · 26/03/2025
Chinese hacking is becoming bigger, better and stealthier @euben.bsky.social and I on the beat economist.com/china/2025/0...
economist.com
Chinese hacking is becoming bigger, better and stealthier
Experts say it is the main shift in the cyber-threat landscape in a decade
02613
Reposted by Lasq
Lesley Carhart @hacks4pancakes.com · 25/03/2025
There’s been infinite memes and commentary on the single breach, but this is worth your time, this is a much bigger issue. www.washingtonpost.com/technology/2... by @jik.federate.social.ap.brid.gy ht @zackwhittaker.com
washingtonpost.com
Why government workers and military planners all love Signal now
The encrypted chat app beloved by Elon Musk and foreign dissidents has been embraced by federal government workers, DOGE and military planners.
47830
Reposted by Lasq
Dan Black @danwblack.bsky.social · 25/03/2025
Developing low visibility, low signature forms of compromise for signal accounts is a clear area of investment for Russia's services as well. Generally speaking if you use the app for sensitive comms: audit your linked devices. Do it now. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
0156
Lasq @lasq.pl · 19/03/2025
Love this commentary on our recent blog, pineapples vs ananas 😂 If you don't yet listen to "Three Buddy Problem" podcast you are missing out! www.youtube.com/watch?v=KHhr...
youtube.com
Chinese backdoors on Juniper routers
YouTube video by Three Buddy Problem
000
Lasq @lasq.pl · 15/03/2025
Great to see our UNC3886 Juniper malware blog mentioned in my favorite podcast 🥰
082
Reposted by Lasq
Alexis Brignoni🪫 @abrignoni.com · 14/03/2025
And old, powerful, and mysterious language... #regex #DigitalForensics
55112
Reposted by Lasq
John @bigbadw0lf.bsky.social · 12/03/2025
🔥 new blog covering recent UNC3886 ops. Massive S/O to all the authors for dropping such a great blog.
081
Lasq @lasq.pl · 12/03/2025
Super happy this blog is finally released. Dive into the intricacies of backdoors targeting Juniper devices, veriexec bypass zero-day and other interesting TTPs, all with UNC3886, a China-nexus cyber espionage group as your guide! cloud.google.com/blog/topics/...
cloud.google.com
Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers | Google Cloud Blog
We discovered China-nexus threat actors deployed custom backdoors on Juniper Networks’ Junos OS routers.
064
Lasq @lasq.pl · 26/02/2025
This is a "clip" that the POTUS publishes on his social media account, regarding a region that has been impacted by one of the greatest humanitarian crisis of our times. I try not to comment publicly on the US politics, but... REALLY??? truthsocial.com/@realDonaldT...
010
Reposted by Lasq
Eliot Higgins @eliothiggins.bsky.social · 26/02/2025
Woke up to see Donald Trump sharing a video on Truth Social about turning Gaza into a holiday resort with a giant gold statue of Trump, ending with a final shot of Trump and Netanyahu enjoying the beach together. Absolutely unhinged. truthsocial.com/@realDonaldT...
1491115343
Reposted by Lasq
Andy Greenberg @agreenberg.bsky.social · 10/02/2025
As an IRS agent, Tigran Gambaryan was perhaps the most effective crypto investigator in history. Then last year he was charged in Nigeria with money laundering and thrown in prison. Throughout, he was texting with me from a secret phone. This is his full, untold story. www.wired.com/story/untold...
wired.com
The Untold Story of a Crypto Crimefighter’s Descent Into Nigerian Prison
As a US federal agent, Tigran Gambaryan pioneered modern crypto investigations. Then at Binance, he got trapped between the world’s biggest crypto exchange and a government determined to make it pay.
22957247
Reposted by Lasq
Silas Cutler @silascutler.bsky.social · 10/02/2025
I started doing victim notification (vn) work back in 2011. At the time, I was working as a Security Analyst at #SecureWorks in their Security Operation Center. In between the alerts for malware, there would be an occasional alert for malware check-in, but the domain had expired. 🧵
2457
Reposted by Lasq
Gabriel @morecoffeeplz.bsky.social · 08/02/2025
The Com is a group of criminals, responsible for serious and disturbing online attacks. The fact that one of their former members has access to sensitive information should be of immediate concern. krebsonsecurity.com/2025/02/teen...
krebsonsecurity.com
Teen on Musk’s DOGE Team Graduated from ‘The Com’
Wired reported this week that a 19-year-old working for Elon Musk's so-called Department of Government Efficiency (DOGE) was given access to sensitive US government systems even though his past associ...
24726
Reposted by Lasq
Adwersarz.pl @adwersarz.pl · 03/02/2025
Czas na wywiad! Rozmawiamy z pi3 i Solarem o LKRG (Linux Runtime Kernel Guard), które może znacznie utrudnić zhackowanie Linuxa. Co słychać i jak przebiega rozwój projektu, czy ktoś próbował skutecznie obejść LKRG? Zapraszamy do lektury! adwersarz.pl/polskie-proj...
adwersarz.pl
Polskie projekty IT Security – co słychać w LKRG? – adwersarz.pl
042
Reposted by Lasq
Grzegorz Wróbel @lochtcant.pl · 03/02/2025
Ruszyłem z własnym portalem o bezpieczeństwie (i nie tylko) :) To będzie skromny projekt realizowany z pasji i dla pasjonatów. Zapraszam więc do wywiadu o LKRG, który poniekąd otwiera oficiajlnie portal! :)
011
Reposted by Lasq
Andrew (🎃) @athomashemlock.bsky.social · 30/01/2025
For anyone who cares what Google thinks about Russian Espionage, this is really, really good news. Gabby is one of the smartest people currently working in cyber.
171
Reposted by Lasq
OSINTtechnical @osinttechnical.bsky.social · 30/01/2025
For many in the DC-area flying community, the crash tonight wasn’t a matter of if, but when. DC airspace is some of the most congested in the world, with helicopters and jets forced into a small operating area. Doesn’t exactly help that the Army uses it as a training ground.
24873154
Reposted by Lasq
Auschwitz Memorial @auschwitzmemorial.bsky.social · 27/01/2025
Auschwitz was at the end of a long process. It did not start from gas chambers. This hatred was gradually developed by humans. From ideas, words, stereotypes & prejudice through legal exclusion, dehumanization & escalating violence... to systematic and industrial murder. Auschwitz took time.
A bird's-eye view of a former Auschwitz II-Birkenau camp showing a wide dirt pathway flanked by parallel rows of barbed-wire fences. Groups of visitors walk along the path, surrounded by the remnants of brick structures and barracks, now reduced to foundations. Green grass contrasts with the somber history of the site, as the path leads toward a guard tower in the distance.
10505284922436
Reposted by Lasq
visi stark @invisig0th.bsky.social · 22/01/2025
I feel like I'm watching the train I'm riding derail in slow motion. Meanwhile the majority of the other passengers are doing their best to ensure that it derails with the maximum amount damage possible.
2242
Reposted by Lasq
Eric Geller @ericjgeller.com · 21/01/2025
DHS has terminated the memberships of everyone on its advisory committees. This includes several cyber committees, like CISA's advisory panel and the Cyber Safety Review Board, which was investigating Salt Typhoon. That review is "dead," person familiar says. www.documentcloud.org/documents/25...
501059595
Lasq @lasq.pl · 21/01/2025
Ok, today have finally done it. I removed my X account, I was struggling with this decision for long as there's still a bunch of cool people doing cool stuff over there. But there's a time when enough is enough. I guess this means I should be a tad more active here.
130
Reposted by Lasq
Matthew Green @matthewdgreen.bsky.social · 19/01/2025
One of the places I’ve departed from the “cypherpunk dream” over the years is the idea that all speech is good for a healthy democracy. I’m saying nothing that hasn’t been said before, but social media can be incredibly toxic.
2738
Lasq @lasq.pl · 15/01/2025
Some good books last year 📕
010
Lasq @lasq.pl · 11/01/2025
#100daysofRUST Day 11 - I decided not to spam with this every day, since this is not so interesting. I will be sending a summary each 10 days. So far I covered basic IO, syscalls, spawning processes and basic IPC. I am also using Gemini more and more. Link to repo below. 1/2
100
Lasq @lasq.pl · 10/01/2025
Pan redaktor pewnego "alternatywnego" portalu o bezpieczeństwie, aktywnie namawia do ludobójstwa. Tego nie było w moim bingo...
100
Reposted by Lasq
Austin Larsen @handle.invalid · 09/01/2025
🚨 New: Zero-day vulnerability #CVE-2025-0282 in Ivanti Connect Secure VPN is being actively exploited, including by suspected China-nexus cyber espionage groups. Our team at Mandiant in partnership with Ivanti just published our initial findings. 🧵 cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
181
Reposted by Lasq
John @bigbadw0lf.bsky.social · 09/01/2025
🔥 new blog detailing 0day exploitation of Ivanti appliances as well as some newly observed malware families tracked as PHASEJAM and DRYHOOK. We also detail activity related to the previously observed SPAWN* malware ecosystem tied to China-nexus cluster UNC5337. cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
03322
Lasq @lasq.pl · 09/01/2025
New Year - New Ivanti Zero-Day. Almost exactly 1 year later, UNC5337 returns with their SPAWN malware family. Blog: cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
153
Reposted by Lasq
Gynvael Coldwind @gynvael.bsky.social · 07/01/2025
(please re-post for reach - thank you!) Learned a cool new Linux trick? Know an interesting quirk in a network protocol? Or have something else to share? Write a 1-page article for the #6 issue of Paged Out! :) pagedout.institute?page=cfp.php Soft deadline is Feb 1st.
03033
Reposted by Lasq
David Oxley @oxley.io · 06/01/2025
I’m generally bullish on the use of GenAI to make our lives better. I also really appreciate Apple’s notification summaries. Less so this: scam SMS comes in and is summarized, but whereas the initial language was “scammy,” Apple Intelligence “upscales” it to be more professional in the process.
173
Lasq @lasq.pl · 04/01/2025
Day 4 of #100DaysOfRUST - writing to files github.com/lasq88/100da... #100DaysOfCode
github.com
030
Lasq @lasq.pl · 03/01/2025
This year I decided to do a personal #100DaysofRust challenge. I try to not upload only dry code snippets, but understand and explain the code that was unclear to me. So maybe someone will find it useful. You can follow my progress here: github.com/lasq88/100da... #100DaysOfCode
github.com
040
Reposted by Lasq
Debugger @debugger.bsky.social · 31/12/2024
Wishing everyone a Happy and Healthy 2025! 🎉- In case you missed it, I created a GitHub repository in 2024 covering Windows Debugging topics. It includes using tools like WinDbg to analyze memory dumps and more. If you're into Windows, check it out here: github.com/DebugPrivile...
github.com
GitHub - DebugPrivilege/InsightEngineering: Hardcore Debugging
Hardcore Debugging. Contribute to DebugPrivilege/InsightEngineering development by creating an account on GitHub.
071