Sign in

tlansec

@tlansec.bsky.social
852 followers 308 following 50 posts

Threat Intel @volexity.com n stuff. London, UK.

PostsRepliesMedia
Reposted by tlansec
Volexity @volexity.com · 25/09/2026
Feike Hacquebord will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about Russia-, China- & DPRK-aligned APTs targeting Europe: IoT proxy networks, DPRK's Russian IPs, Pawn Storm's evolution & China's AI shift. Seating is limited! Register here: luma.com/0qtkw49c
032
Reposted by tlansec
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Reposted by tlansec
Saher @saffronsec.bsky.social · 23/09/2026
Excited to share I'm presenting a last-minute talk @virusbtn.bsky.social! Come watch me hype @greg-l.bsky.social's research on Russia-aligned TA488's operational evolution, complete with half-click XSS exploits, zero-days, webmail stealers, & browser implants www.virusbulletin.com/conference/v...
092
Reposted by tlansec
Saher @saffronsec.bsky.social · 23/09/2026
We're one month out from @what-is-sos.bsky.social in Brussels with a packed and stacked agenda on all things intel, espionage, sabotage, physical ops, and attribution - get your tickets asap!! www.stateofstatecraft.com/agenda
stateofstatecraft.com
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
033
tlansec @tlansec.bsky.social · 22/09/2026
If you're in BENELUX, or happen to be in Amsterdam the week commencing the 26th October, check out the Volexity Cyber Sessions: luma.com/0qtkw49c We've announced Christopher Lopez (macOS guru) as our first speaker and we have some more great speakers announcing later this week!
luma.com
Volexity Cyber Sessions – Amsterdam | October 2026 · Luma
Join Us in Amsterdam! We are excited to announce our first Volexity Cyber Sessions meetup in Amsterdam! Agenda 15:00 Registration & Welcome 15:45…
000
Reposted by tlansec
Volexity @volexity.com · 21/09/2026
Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.
volexity.com
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2...
154
Reposted by tlansec
Volexity @volexity.com · 17/09/2026
Christopher Lopez will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about the current macOS threat landscape: lures, targets, recently discovered malware, plus the artifacts that drive forensic analysis & durable detections. Seating is limited! Register here: luma.com/0qtkw49c
011
Reposted by tlansec
Saher @saffronsec.bsky.social · 14/09/2026
Back by popular demand, it's time for Volume II of State of Statecraft @what-is-sos.bsky.social! Come check out the latest in state-sponsored operations across espionage, cyber/physical sabotage, disruption, attribution, and all the -INTs you could dream of - Oct 22 www.stateofstatecraft.com/agenda
stateofstatecraft.com
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
0125
Reposted by tlansec
State of Statecraft Conference @what-is-sos.bsky.social · 11/09/2026
BEHOLD: the 🆘 AGENDA is OUT! VOLUME II features numerous discussions on developments in state-sponsored operations covering digital espionage, cyber/physical sabotage, economic tradecraft, disruption, attribution and dare we say, more? Agenda 👉 stateofstatecraft.com/agenda 🧵
143
Reposted by tlansec
Alex Lanstein @lanstein.bsky.social · 10/09/2026
Models two years ago were 1). Models today are 2). We spent a trillion dollars to make a tool that is way way better at SQL than I am. Will that be better for society in 10 years? I have literally no idea.
141
Reposted by tlansec
Volexity @volexity.com · 09/09/2026
Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).   #DFIR #threatintel
volexity.com
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta...
1126
Reposted by tlansec
Wesley Shields @wxs.bsky.social · 24/08/2026
New release with lots of new features and bug fixes. Again, congratulations to Victor and everyone who contributed to making this happen! It’s great to see the continued progress. github.com/VirusTotal/y...
github.com
Release v1.20.0 · VirusTotal/yara-x
Implement SIMD-accelerated masked literal matching (#691). Improve atom extraction heuristics for better performance (#690, 1e14f60). Improve scan performance by applying file size and file header ...
032
Reposted by tlansec
DilDog 🅅 @dildog.l0pht.com · 16/08/2026
when you're really good at making stuff but only get halfway through before starting the next thing you're a black belt in partial arts
2306
Reposted by tlansec
Wesley Shields @wxs.bsky.social · 10/08/2026
Three positions opened up in GTIG. If you have questions I'd be happy to answer! Koreas: www.google.com/about/career... Exploits (US and CH based): www.google.com/about/career... www.google.com/about/career...
021
Reposted by tlansec
austin (e/accordion 🪗) @thebadcode.com · 05/08/2026
KFC announces their frontier-class model briefly escaped its sandbox and attempted to exfiltrate the 27 herbs and spices
142261351
Reposted by tlansec
Jimmy Wylie @mayahustle.com · 05/08/2026
We have two malware analyst openings at Dragos! In many malware jobs, your work disappears into the void. But at Dragos, it's easy to see the impact of your work across the company and community. And you get to work on interesting cases across OT verticals. job-boards.greenhouse.io/dragos/jobs/...
job-boards.greenhouse.io
Associate Principal Malware Analyst
United States
035
Reposted by tlansec
We're just normal men @wejustinnocentmen.bsky.social · 04/08/2026
We’re just normal men
91356468
Reposted by tlansec
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22414
Reposted by tlansec
Volexity @volexity.com · 28/07/2026
Heading to Las Vegas next week? Connect with our team to discuss the latest in #DFIR, #memoryforensics, active threat actor campaigns we're tracking, and more! Let us know when you'd like to meet: www.volexity.com/contact/meet...
032
Reposted by tlansec
Wesley Shields @wxs.bsky.social · 28/07/2026
This came out while I was traveling last week and it's a good read on a single campaign from this group we've been tracking: dslua.org/publications... - They are fairly active doing this kind of phishing and also other nefarious activities.
dslua.org
Phishing Campaign Against “Civil Network OPORA” – Gmail Account Takeover via OAuth – Лабораторія цифрової безпеки
042
Reposted by tlansec
Volexity @volexity.com · 17/07/2026
Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintel
volexity.com
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil...
156
Reposted by tlansec
State of Statecraft Conference @what-is-sos.bsky.social · 14/07/2026
Reminder: CFP for 🆘 ends August 14! That's in 30 days... 1 month... four weeks. This is the event that places state-sponsored operations front & center. The mic is all yours. Now prepare to drop it. Submission Link: stateofstatecraft.com/cfp #what_is_sos
012
Reposted by tlansec
Alex Lanstein @lanstein.bsky.social · 08/07/2026
gotta give some respect to student S22
021
Reposted by tlansec
Michael @matonis.bsky.social · 07/07/2026
ICYMI: the State of Statecraft conference (@what-is-sos) returns to Brussels for Volume II on October 22, 2026. Registration is open & the CFP runs until Aug. 14 SOS is an event focused on state-sponsored operations: stateofstatecraft.com 🧵👇
163
Reposted by tlansec
We're just normal men @wejustinnocentmen.bsky.social · 06/07/2026
We’re just innocent men
152935993
Reposted by tlansec
SwiftOnSecurity @swiftonsecurity.com · 02/07/2026
I admire IT people 20 years in who still run home labs. It's like coming home from the egg salad sandwich factory, hearing, "what do you want for dinner, honey?" And saying, "same thing we have every night: egg salad sandwiches."
3028725
Reposted by tlansec
Wesley Shields @wxs.bsky.social · 24/06/2026
github.com/VirusTotal/y... This fixes an issue with certain header constraints that you really should update for. There are other nice bug fixes and features too, but the header constraints is a big one.
github.com
Release v1.19.0 · VirusTotal/yara-x
Add missing machine architecture types to pe module (#687). Add warning for single-byte patterns (71baa67). Add warning for duplicate patterns in a rule (9061803). Small optimization when generatin...
042
Reposted by tlansec
We're just normal men @wejustinnocentmen.bsky.social · 22/06/2026
We’re just normal men
3806305
Reposted by tlansec
Vale @vale.rocks · 19/06/2026
There are only two file formats: disguised zips and renamed text files. JSON? Text. EPUB? Zip. CSV? Text. EXE? Zip. SVG? Text. DOCX? Zip. ICS? Text. APK? Zip.
451063264
Reposted by tlansec
We're just normal men @wejustinnocentmen.bsky.social · 15/06/2026
We’re just innocent men
61020383
Reposted by tlansec
Volexity @volexity.com · 08/06/2026
Heading to Denver for #FIRSTCON26 next week? Stop by the @volexity.com booth to see a demo of Volcano! We’ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. #DFIR #FIRSTCON
132
Reposted by tlansec
Andrew Case @attrc.bsky.social · 04/06/2026
Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices.
042
Reposted by tlansec
Volexity @volexity.com · 04/06/2026
@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. [1/4]
volexity.com
VerdantBamboo: Just Another BRICKSTORM in the Firewall
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The...
186
Reposted by tlansec
Volexity @volexity.com · 12/05/2026
@volexity.com Volcano Server & Volcano One v26.04.27 adds memory analysis for arm64 Windows, memory-only .NET assemblies, SRUM database, Linux systemd units, history & timers from RAM. #memoryforensics #memoryanalysis #dfir
142
Reposted by tlansec
Andrew Case @attrc.bsky.social · 14/04/2026
Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malw...
099
Reposted by tlansec
Wesley Shields @wxs.bsky.social · 13/04/2026
github.com/VirusTotal/y... - congrats to all involved! These new features are really great!
github.com
Release v1.15.0 · VirusTotal/yara-x
Add full support for WASM. The whole yara-x create now can be built for WASM (#583, #588, #598). New playground at https://virustotal.github.io/yara-x/playground/ (#601). The yr check command now n...
171
Reposted by tlansec
evacide @evacide.bsky.social · 09/04/2026
High five to everyone who has suffered from anxiety, burnout, and depression without even once stealing 0-days from their employer and selling them to the Russians. www.zetter-zeroday.com/trenchant-ex...
zetter-zeroday.com
Trenchant Exec Says He Had Depression, Money Troubles When He Decided to Sell Zero Days to Russian Buyer; Also, New Info Reveals Nature of His Work for Australian Intelligence Agency
Peter Joseph Williams, a former L3 Trenchant executive recently convicted of secretly selling zero-day exploits to a Russian broker, says he was suffering anxiety, burnout, years of depression, and financial difficulties when he decided to steal exploits from his US employer and sell them to the Russian buyer. Williams, who
730252
Reposted by tlansec
Museum of Twitter @museum-of-twitter.bsky.social · 05/04/2026
@revrrlewis

I've played over 1,000 hours of Civilization VI. Here's how Ukraine can defeat Russia. (1/47)

Anthony Smith - 2h 
Replying to @revrrlewis

one game of Civ VI and you think you're an expert????
81829328
Reposted by tlansec
Joseph Cox @josephcox.bsky.social · 19/03/2026
The complete and utter failure of the metaverse is a reminder [...] that quite often these oligarchs quite simply cannot relate to real people, don’t know how or why people use their products, and very often have no idea what they’re doing www.404media.co/rip-metavers...
404media.co
RIP Metaverse, an $80 Billion Dumpster Fire Nobody Wanted
Who could have possibly predicted this, besides everyone?
522466
Reposted by tlansec
PIVOTcon @pivotcon.bsky.social · 10/03/2026
📣 #PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's edition! 2⃣ days and 19 talks from leading #ThreatResearch experts. The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵 #CTI #ThreatIntel 1/15
11610
Reposted by tlansec
Volexity @volexity.com · 10/03/2026
@volexity.com recently released GoResolver v1.4, bringing significant updates to our #opensource tool for recovering symbol data from obfuscated Go binaries. This release is available on GitHub: github.com/volexity/GoR... [1/8]
github.com
GitHub - volexity/GoResolver: GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the function symbols of an obfuscated Go ...
GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the function symbols of an obfuscated Go binary. - volexity/GoResolver
184
Reposted by tlansec
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/02/2026
This is a bad take. You can’t counter far right narratives on a platform that is designed to amplify only those narratives. Politicians should set the example. And journalist should get off of it too.
25211
Reposted by tlansec
State of Statecraft Conference @what-is-sos.bsky.social · 19/02/2026
SOS returns to Brussels on October 22, 2026! As the geopolitical landscape rifts, hybrid threats continue to adapt & evolve. We provide a forum for observers of state-aligned sabotage, espionage, and more to share research with an action-oriented community. Stay tuned for more announcements!
075
Reposted by tlansec
We're just normal men @wejustinnocentmen.bsky.social · 10/02/2026
We’re just normal men
172391877
Reposted by tlansec
thesilence @thesilence.bsky.social · 03/02/2026
Reminder that the #PIVOTcon2026 CFP closes this Friday, February 6. Get those papers in. We want to see you at @pivotcon.bsky.social in Malaga! 😎
media.tenor.com
two purple beach chairs on the beach with the words these are waiting for us
ALT: two purple beach chairs on the beach with the words these are waiting for us
075
tlansec @tlansec.bsky.social · 03/02/2026
You say "Security Feature Bypass"... I say.... "Remote Code Execution": msrc.microsoft.com/update-guide...
msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
1126
Reposted by tlansec
Kamil Bojarski @lawsecnet.counterintelligence.pl · 02/02/2026
For folks looking for Notepad++ IoCs, @rapid7.com just dropped a write-up. www.rapid7.com/blog/post/tr...
rapid7.com
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
175
Reposted by tlansec
StrikeReady Labs @strikereadylabs.com · 30/01/2026
#apt #unk via VT BULLETEN_H.doc 7c396677848776f9824ebe408bbba943 1291.doc d47261e52335b516a777da368208ee91 Courses.doc 2f7b4dca1c79e525aef8da537294a6c4 Consultation_Topics_Ukraine(Final).doc 95e59536455a089ced64f5af2539a449 freefoodaid[.]com wellnessmedcare[.]org
021
Reposted by tlansec
SwiftOnSecurity @swiftonsecurity.com · 30/01/2026
I promise you. I absolutely guarantee. You are not ready for what happens when you click this link. ovu.moe
11824542