Volexity @volexity.com · 28/09/2026Steven Adair keynotes at our Volexity Cyber Sessions in Amsterdam (Oct 29) on Chinese APTs exploiting Chrome vulns fixed in Chromium but not released. Identical exploit code points to a shared supplier, plus a false-flag op pinning it on Russia. Seating is limited! Register here: luma.com/0qtkw49c 011
Volexity @volexity.com · 25/09/2026Feike Hacquebord will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about Russia-, China- & DPRK-aligned APTs targeting Europe: IoT proxy networks, DPRK's Russian IPs, Pawn Storm's evolution & China's AI shift. Seating is limited! Register here: luma.com/0qtkw49c 032
Volexity @volexity.com · 22/09/2026Roey Shua will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about automating edge device forensics, from fingerprinting unknown routers & IoT devices to reconstructing symbols and acquiring memory on unsupported architectures. Seating is limited! Register here: luma.com/0qtkw49c 021
Volexity @volexity.com · 21/09/2026Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.volexity.comMind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day ExploitsOn September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2... 154
Reposted by VolexityVolatility @volatilityfoundation.org · 21/09/2026Volatility New Release: #volatility3 v2.28.2 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir 012
Volexity @volexity.com · 17/09/2026Christopher Lopez will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about the current macOS threat landscape: lures, targets, recently discovered malware, plus the artifacts that drive forensic analysis & durable detections. Seating is limited! Register here: luma.com/0qtkw49c 011
Volexity @volexity.com · 10/09/2026Volexity Volcano v26.09.01 expands what you can analyze, and where! This release adds a powerful MCP server, threat intel integration, memory support for Linux 7.x kernels and Windows 26H1 on Snapdragon X2 ARM64. 121
Volexity @volexity.com · 09/09/2026Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). #DFIR #threatintelvolexity.comMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & WindowsOn September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta... 1126
Reposted by VolexityVolatility @volatilityfoundation.org · 13/08/2026The 14th annual #Volatility #PluginContest is officially OPEN! This is your chance to contribute to open source forensics, gain community-wide visibility for your work, and win a cash prize! See our blog post for details! Submission Deadline: 31 December 2026 #dfir #memoryforensicsvolatilityfoundation.orgThe 14th Annual Volatility Plugin Contest is Open!We are excited to announce that the 14th Annual Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open sourc… 045
Volexity @volexity.com · 28/07/2026Heading to Las Vegas next week? Connect with our team to discuss the latest in #DFIR, #memoryforensics, active threat actor campaigns we're tracking, and more! Let us know when you'd like to meet: www.volexity.com/contact/meet... 032
Volexity @volexity.com · 22/07/2026Volexity is hiring! Join a team that develops concrete solutions to challenging real-world problems. Whether your focus is bringing new products to market or delivering cybersecurity services globally, the work you do here helps real people and moves the industry forward. See how you can plug in!volexity.comCareersJoin a team where your contributions will have an impact on cybersecurity & develop concrete solutions to the most challenging real-world cyber problems. 011
Volexity @volexity.com · 21/07/2026Volexity is heading to Las Vegas! Members of our leadership, development, engineering & threat intelligence teams will be on site August 4–6. If you would like to connect to discuss the latest in #DFIR, #memoryforensics, or the current threat landscape, let us know when you’d like to meet!volexity.comSchedule a Meeting with Volexity in Las VegasIf you would like to schedule time with members of Volexity's leadership, development, engineering, or threat intelligence teams to learn more about our recent investigations and next-generation memor... 021
Reposted by VolexityAndrew Case @attrc.bsky.social · 20/07/2026Thank you to @jags.bsky.social for the @volexity.com shout out in the latest Three Buddy Problem episode! If you aren't performing memory forensics in your environments, then you cannot make any definitive claims on whether you are compromised! podcasts.apple.com/us/podcast/h... 054
Volexity @volexity.com · 17/07/2026Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintelvolexity.comProxying to Compromise: SonicWall Secure Mobile Access 0-day ExploitationIn early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil... 156
Reposted by VolexityAndrew Case @attrc.bsky.social · 19/06/2026I am very excited to announce that my @volatilityfoundation.org 3 workshop with David McDonald and Pierre Breton was accepted for @defcon.bsky.social this summer!! 0103
Volexity @volexity.com · 15/06/2026Great conversations at #FIRSTCON26 so far! Come say hello to the @volexity.com team at Booth 7 & see how to rapidly resolve your investigations and find what other tools are missing. #DFIR #FIRSTCON #memoryforensics 023
Reposted by VolexityAndrew Case @attrc.bsky.social · 08/06/2026Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale. 021
Volexity @volexity.com · 08/06/2026Heading to Denver for #FIRSTCON26 next week? Stop by the @volexity.com booth to see a demo of Volcano! We’ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. #DFIR #FIRSTCON 132
Reposted by VolexityAndrew Case @attrc.bsky.social · 04/06/2026Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices. 042
Volexity @volexity.com · 04/06/2026@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. [1/4]volexity.comVerdantBamboo: Just Another BRICKSTORM in the FirewallIn September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The... 186
Volexity @volexity.com · 02/06/2026We are excited to welcome our 2026 #summerinternship students from Notre Dame Computer Science and Engineering, University of Maryland Department of Computer Science, and Maryland Applied Graduate Engineering! 142
Volexity @volexity.com · 19/05/2026The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks for mentioning our work! 142
Volexity @volexity.com · 12/05/2026@volexity.com Volcano Server & Volcano One v26.04.27 adds memory analysis for arm64 Windows, memory-only .NET assemblies, SRUM database, Linux systemd units, history & timers from RAM. #memoryforensics #memoryanalysis #dfir 142
Reposted by VolexityVolatility @volatilityfoundation.org · 01/05/2026Volatility New Release: #volatility3 v2.28.0 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir 022
Reposted by VolexityAndrew Case @attrc.bsky.social · 17/04/2026I am excited to announce that I will be speaking at BSides Nashville on May 15th. Be sure to attend to see all the latest Volatility 3 (@volatilityfoundation.org) plugins against the most sophisticated and devastating malware from the wild! bsidesnash.orgbsidesnash.orgBSides Nashville 035
Reposted by VolexityAndrew Case @attrc.bsky.social · 14/04/2026Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malw... 099
Reposted by VolexityVolatility @volatilityfoundation.org · 13/03/2026We have announced the winners of the 2025 #Volatility #PluginContest! And the First Place is: Daniel Baier for XFRM Inspector Read the full Contest Results in our blog post: volatilityfoundation.org/the-2025-vol... Congrats to all winners & thank you to all participants! #DFIR #memoryforensicsvolatilityfoundation.orgThe 2025 Volatility Plugin Contest results are in!Results from the 13th Annual Volatility Plugin Contest are in! We received 8 submissions from 7 different countries that included 20 plugins. Contest submissions included a range of features… 011
Volexity @volexity.com · 10/03/2026@volexity.com recently released GoResolver v1.4, bringing significant updates to our #opensource tool for recovering symbol data from obfuscated Go binaries. This release is available on GitHub: github.com/volexity/GoR... [1/8]github.comGitHub - volexity/GoResolver: GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the function symbols of an obfuscated Go ...GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the function symbols of an obfuscated Go binary. - volexity/GoResolver 184
Reposted by VolexityVolatility @volatilityfoundation.org · 06/03/2026We are excited to announce the First Place winner of the 2025 #Volatility #PluginContest is: Daniel Baier for XRFM Inspector See the full Contest Results in our blog post: volatilityfoundation.org/the-2025-vol... Congrats to all winners & thank you to all participants! #DFIR #memoryforensicsvolatilityfoundation.orgThe 2025 Volatility Plugin Contest results are in!Results from the 13th Annual Volatility Plugin Contest are in! We received 8 submissions from 7 different countries that included 20 plugins. Contest submissions included a range of features… 153
Reposted by VolexityVolatility @volatilityfoundation.org · 30/01/2026Volatility New Release: #volatility3 v2.27.0 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir 033
Volexity @volexity.com · 05/01/2026Volexity Volcano Server & Volcano One v25.12.18 adds 300+ YARA rules, full parsing of Windows prefetch and Linux cron jobs, inline syscall hooking detection, and 5-level page table support. [1/3] 111
Reposted by VolexityVolatility @volatilityfoundation.org · 01/01/2026And that’s it! The 2025 #Volatility #PluginContest is now closed. Stay tuned for winner announcements in the coming weeks! And good luck to all contenders! #memoryforensics #opensource #dfir 042
Reposted by VolexityVolatility @volatilityfoundation.org · 31/12/2025Today is the last day to submit entries to the #PluginContest! This is your chance to gain industry-wide visibility for your work, contribute to an important open-source project, and compete for cash prizes! More details below!👇 021
Reposted by VolexityVolatility @volatilityfoundation.org · 29/12/2025There are only 2 days left to submit your entries to the #Volatility #PluginContest! The deadline is Wednesday! 011
Reposted by VolexityVolatility @volatilityfoundation.org · 26/12/2025You have 5 more days to submit your entries to the #Volatility #PluginContest! 012
Reposted by VolexityVolatility @volatilityfoundation.org · 22/12/2025There are 9 days left to submit entries to the #Volatility #PluginContest! Make sure to get your submissions in by the deadline! 022
Reposted by VolexityVolatility @volatilityfoundation.org · 08/12/2025The @volatilityfoundation.org #PluginContest closes on Dec 31, 2025! Make sure to submit your entry by the deadline! If you’re looking for inspiration, take a look at our roll call of past contest submissions: volatilityfoundation.org/volatility-p.... #memoryforensicsvolatilityfoundation.orgVolatility Plugin Contest | The Volatility FoundationVisit the post for more. 021
Volexity @volexity.com · 04/12/2025@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355’s campaigns impersonating European security events.volexity.comDangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing AttacksIn early 2025, Volexity published two blog posts detailing a new trend among Russian threat actors targeting organizations through the abuse of Microsoft 365 OAuth and Device Code authentication workf... 0108
Volexity @volexity.com · 03/12/2025@stevenadair.bsky.social recently spoke with Here & Now’s Scott Tong (@npr.org @wbur.org) about @volexity.com’s discovery of China-aligned threat actor UTA0388 using AI + LLMs in targeted phishing attacks. Listen here: www.wbur.org/hereandnow/2...wbur.orgHow AI is changing hackingThe tech company Anthropic’s AI technology was used by Chinese-backed hackers trying to breach foreign governments and major corporations. 021
Volexity @volexity.com · 14/11/2025@volexity.com has continued to see nation-state threat actors use AI + LLMs to assist in cyber attacks. Our recent research on a Chinese APT threat actor (UTA0388) using AI in its operation was something @stevenadair.bsky.social recently discussed with the @wsj.com. 144
Reposted by VolexityVolatility @volatilityfoundation.org · 29/10/2025The 13th annual @volatility #PluginContest is OPEN for submissions until 31 Dec 2025! This contest is designed to encourage research & development in the field of #memoryanalysis. Every year, contributions from all around the world continue to help build the next generation of #memoryforensics.volatilityfoundation.orgThe 13th Annual Volatility Plugin Contest is Open!We are excited to announce that the Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open source forensics … 014
Reposted by VolexityVolatility @volatilityfoundation.org · 21/10/2025We had a great day yesterday at #FTSCon 2025! FTSCon Week continues with @joegrand.bsky.social's Hardware Hacking Basics + #Volatility Malware & Memory Forensics training with @attrc.bsky.social, Michael Ligh + Dave Lassalle. 024
Reposted by VolexityCYBERWARCON @cyberwarcon.bsky.social · 15/10/2025@stevenadair.bsky.social is back again! Founder + President of Volexity leading a team of experts that deal w/ complex cyber intrusions from nation-state level intruders. His talk will cover a Chinese APT actor that Volexity tracks as UTA0388. Check out the official agenda: cyberwarcon.com 025
Reposted by VolexityVolatility @volatilityfoundation.org · 10/10/2025Registration for #FTSCon 2025 closes tomorrow! We are really excited to see everyone on Monday, October 20th! 001
Volexity @volexity.com · 08/10/2025APT meets GPT: @volexity.com #threatintel is tracking #threatactor UTA0388's spear phishing campaigns against targets in North America, Europe & Asia, appearing to use LLMs to assist their ops. Letting #AI run your espionage operations? What could go wrong?volexity.comAPT Meets GPT: Targeted Operations with Untamed LLMsStarting in June 2025, Volexity detected a series of spear phishing campaigns targeting several customers and their users in North America, Asia, and Europe. The initial observed campaigns were tailor... 033
Reposted by VolexityVolatility @volatilityfoundation.org · 07/10/2025We would like to thank @volexity.com for sponsoring the #FTSCon 2025 Evening Reception, which will be at VUE Rooftop DC this year! If you haven’t registered for FTSCon yet, there’s still time! Registration closes Sunday Oct 12; learn more + register here: volatilityfoundation.org/from-the-sou... 034
Reposted by VolexityAndrew Case @attrc.bsky.social · 06/10/2025The full lineup for our From the Source event is out! The event take places on October 20th in Arlington, VA. Joe Grand will keynote followed by an amazing speaker line up across two tracks. All proceeds will be donated to Connect Our Kids. volatilityfoundation.org/from-the-sou...volatilityfoundation.orgFrom The Source 2025Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou… 033
Reposted by VolexityVolatility @volatilityfoundation.org · 06/10/2025If you plan to attend the #FTSCon 2025 conference or training sessions, make sure to register before seats sell out! Registration closes this Sunday, October 12! 011