Sign in

Volexity

@volexity.com
1.2K followers 7 following 76 posts

Volexity is a cybersecurity firm founded by the pioneers of memory forensics. Volexity delivers transformative solutions & services to governments & organizations worldwide, increasing enterprise visibility & facilitating rapid intrusion detection.

PostsRepliesMedia
Volexity @volexity.com · 28/09/2026
Steven Adair keynotes at our Volexity Cyber Sessions in Amsterdam (Oct 29) on Chinese APTs exploiting Chrome vulns fixed in Chromium but not released. Identical exploit code points to a shared supplier, plus a false-flag op pinning it on Russia. Seating is limited! Register here: luma.com/0qtkw49c
011
Volexity @volexity.com · 25/09/2026
Feike Hacquebord will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about Russia-, China- & DPRK-aligned APTs targeting Europe: IoT proxy networks, DPRK's Russian IPs, Pawn Storm's evolution & China's AI shift. Seating is limited! Register here: luma.com/0qtkw49c
032
Volexity @volexity.com · 22/09/2026
Roey Shua will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about automating edge device forensics, from fingerprinting unknown routers & IoT devices to reconstructing symbols and acquiring memory on unsupported architectures. Seating is limited! Register here: luma.com/0qtkw49c
021
Volexity @volexity.com · 21/09/2026
UTA0565 used multiple fake websites, posing as media orgs & an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.
020
Volexity @volexity.com · 21/09/2026
Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.
volexity.com
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2...
154
Reposted by Volexity
Volatility @volatilityfoundation.org · 21/09/2026
Volatility New Release: #volatility3 v2.28.2 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir
022
Volexity @volexity.com · 17/09/2026
Christopher Lopez will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about the current macOS threat landscape: lures, targets, recently discovered malware, plus the artifacts that drive forensic analysis & durable detections. Seating is limited! Register here: luma.com/0qtkw49c
011
Volexity @volexity.com · 10/09/2026
Contact us to schedule a Volexity Volcano demo! www.volexity.com/contact/demo...
volexity.com
Demo Request
Volexity’s solutions provide advanced analytics about the state of your devices and rapid insights into the risk those devices pose to your organization. These solutions are used by organizations acro...
010
Volexity @volexity.com · 10/09/2026
Volexity Volcano v26.09.01 also adds MFT parsing from disk, file magic detection, importing from GCP buckets, and complete AWS GovCloud support.
110
Volexity @volexity.com · 10/09/2026
Volexity Volcano v26.09.01 expands what you can analyze, and where! This release adds a powerful MCP server, threat intel integration, memory support for Linux 7.x kernels and Windows 26H1 on Snapdragon X2 ARM64.
The stylized blue, orange and black Volexity Volcano logo is centered, with the Volcano wordmark below it. The words “by Volexity” appear below the Volcano logo. There is a dark blue banner in the upper left with white letters that read “New Release”. The background is a faded gray abstract illustration evoking smoke.
121
Volexity @volexity.com · 09/09/2026
Read the full analysis of the exploit chain and post-exploitation tradecraft here: www.volexity.com/blog/2026/09...
volexity.com
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta...
010
Volexity @volexity.com · 09/09/2026
Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).
110
Volexity @volexity.com · 09/09/2026
Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).   #DFIR #threatintel
volexity.com
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta...
1126
Reposted by Volexity
Volatility @volatilityfoundation.org · 13/08/2026
The 14th annual #Volatility #PluginContest is officially OPEN! This is your chance to contribute to open source forensics, gain community-wide visibility for your work, and win a cash prize! See our blog post for details! Submission Deadline: 31 December 2026 #dfir #memoryforensics
volatilityfoundation.org
The 14th Annual Volatility Plugin Contest is Open!
We are excited to announce that the 14th Annual Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open sourc…
045
Volexity @volexity.com · 28/07/2026
Heading to Las Vegas next week? Connect with our team to discuss the latest in #DFIR, #memoryforensics, active threat actor campaigns we're tracking, and more! Let us know when you'd like to meet: www.volexity.com/contact/meet...
032
Volexity @volexity.com · 22/07/2026
Volexity is hiring! Join a team that develops concrete solutions to challenging real-world problems. Whether your focus is bringing new products to market or delivering cybersecurity services globally, the work you do here helps real people and moves the industry forward.   See how you can plug in!
volexity.com
Careers
Join a team where your contributions will have an impact on cybersecurity & develop concrete solutions to the most challenging real-world cyber problems.
011
Volexity @volexity.com · 21/07/2026
Volexity is heading to Las Vegas! Members of our leadership, development, engineering & threat intelligence teams will be on site August 4–6. If you would like to connect to discuss the latest in #DFIR, #memoryforensics, or the current threat landscape, let us know when you’d like to meet!
volexity.com
Schedule a Meeting with Volexity in Las Vegas
If you would like to schedule time with members of Volexity's leadership, development, engineering, or threat intelligence teams to learn more about our recent investigations and next-generation memor...
021
Reposted by Volexity
Andrew Case @attrc.bsky.social · 20/07/2026
Thank you to @jags.bsky.social for the @volexity.com shout out in the latest Three Buddy Problem episode! If you aren't performing memory forensics in your environments, then you cannot make any definitive claims on whether you are compromised! podcasts.apple.com/us/podcast/h...
054
Volexity @volexity.com · 17/07/2026
SonicWall has released patches (versions 12.4.3-03453 and 12.5.0-02835) following their July 14 public disclosure. Organizations using affected SMA 1000 series devices should upgrade immediately.
001
Volexity @volexity.com · 17/07/2026
Volexity attributes this activity to a #threatactor it tracks as UTA0533, with the earliest signs of compromise dating back to June 22, 2026.
101
Volexity @volexity.com · 17/07/2026
Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintel
volexity.com
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil...
156
Reposted by Volexity
Andrew Case @attrc.bsky.social · 19/06/2026
I am very excited to announce that my @volatilityfoundation.org 3 workshop with David McDonald and Pierre Breton was accepted for @defcon.bsky.social this summer!!
0103
Volexity @volexity.com · 15/06/2026
Great conversations at #FIRSTCON26 so far! Come say hello to the @volexity.com team at Booth 7 & see how to rapidly resolve your investigations and find what other tools are missing. #DFIR #FIRSTCON #memoryforensics
023
Reposted by Volexity
Andrew Case @attrc.bsky.social · 08/06/2026
Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale.
021
Volexity @volexity.com · 08/06/2026
Come find us at Booth 7 to talk threat hunting and triage workflows with our team, including @stevenadair.bsky.social & @attrc.bsky.social
011
Volexity @volexity.com · 08/06/2026
Heading to Denver for #FIRSTCON26 next week? Stop by the @volexity.com booth to see a demo of Volcano! We’ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. #DFIR #FIRSTCON
132
Reposted by Volexity
Andrew Case @attrc.bsky.social · 04/06/2026
Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices.
042
Volexity @volexity.com · 04/06/2026
For more details on how the incident unfolded, the malware used by the threat actor, and the end goal of the intrusion, check out the full blog post: www.volexity.com/blog/2026/06... [4/4]
volexity.com
VerdantBamboo: Just Another BRICKSTORM in the Firewall
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The...
022
Volexity @volexity.com · 04/06/2026
VerdantBamboo used a #0day privilege escalation exploit in the process and was also observed using administrative access to the victim organization's firewall to enable a custom VPN. [3/4]
111
Volexity @volexity.com · 04/06/2026
This case involved the breach of the victim organization’s MSP and multiple malware implants found on firewalls, cloud storage sync devices & NAS appliances.  [2/4]
111
Volexity @volexity.com · 04/06/2026
@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. [1/4]
volexity.com
VerdantBamboo: Just Another BRICKSTORM in the Firewall
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The...
186
Volexity @volexity.com · 02/06/2026
Over the next few months, they will be working alongside our engineering and threat intelligence teams on core software development and #memoryforensics research.   Learn more about our program and future opportunities: www.volexity.com/internships/   #dfir
volexity.com
Internships
A Volexity internship is an excellent way to build your resume. Apply your knowledge & expertise to some of the most challenging cybersecurity problems.
022
Volexity @volexity.com · 02/06/2026
We are excited to welcome our 2026 #summerinternship students from Notre Dame Computer Science and Engineering, University of Maryland Department of Computer Science, and Maryland Applied Graduate Engineering!
142
Volexity @volexity.com · 19/05/2026
@volexity.com’s detection & response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild. Read our blog post for the original research mentioned: www.volexity.com/blog/2022/06...
volexity.com
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizat...
012
Volexity @volexity.com · 19/05/2026
The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks for mentioning our work!
142
Volexity @volexity.com · 12/05/2026
Contact us for more information: volexity.com/company/cont....
volexity.com
Contact
If you'd like to learn more about Volexity, please contact us!
010
Volexity @volexity.com · 12/05/2026
This release also adds detection of AppleScript usage, cleared Windows event logs, AV scanning of files & deployments across AWS accounts.
111
Volexity @volexity.com · 12/05/2026
@volexity.com Volcano Server & Volcano One v26.04.27 adds memory analysis for arm64 Windows, memory-only .NET assemblies, SRUM database, Linux systemd units, history & timers from RAM. #memoryforensics #memoryanalysis #dfir
142
Reposted by Volexity
Volatility @volatilityfoundation.org · 01/05/2026
Volatility New Release: #volatility3 v2.28.0 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir
022
Reposted by Volexity
Andrew Case @attrc.bsky.social · 17/04/2026
I am excited to announce that I will be speaking at BSides Nashville on May 15th. Be sure to attend to see all the latest Volatility 3 (@volatilityfoundation.org) plugins against the most sophisticated and devastating malware from the wild! bsidesnash.org
bsidesnash.org
BSides Nashville
035
Reposted by Volexity
Andrew Case @attrc.bsky.social · 14/04/2026
Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malw...
099
Reposted by Volexity
Volatility @volatilityfoundation.org · 13/03/2026
We have announced the winners of the 2025 #Volatility #PluginContest! And the First Place is: Daniel Baier for XFRM Inspector Read the full Contest Results in our blog post: volatilityfoundation.org/the-2025-vol... Congrats to all winners & thank you to all participants! #DFIR #memoryforensics
volatilityfoundation.org
The 2025 Volatility Plugin Contest results are in!
Results from the 13th Annual Volatility Plugin Contest are in! We received 8 submissions from 7 different countries that included 20 plugins. Contest submissions included a range of features…
011
Volexity @volexity.com · 10/03/2026
Follow the GoResolver GitHub repo for future updates: github.com/volexity/GoR... Special thanks to Killian Raimbaud for these updates & Ivan Maldenov for his work on the type recovery feature during his Volexity internship. [8/8]
010
Volexity @volexity.com · 10/03/2026
Existing report files remain fully compatible with GoResolver v1.4. Previously generated JSON reports can still be imported using the latest plugin versions; there is no need to re-analyze old samples. [7/8]
110
Volexity @volexity.com · 10/03/2026
GoResolver’s Ghidra plugin now includes an ANALYZE mode for in-SRE analysis. After running, GoResolver automatically imports recovered symbols and types into Ghidra's database. Go version management for Ghidra still requires the CLI. [6/8]
110
Volexity @volexity.com · 10/03/2026
The IDA Pro plugin for GoResolver now supports full in-SRE analysis. GoResolver is available in Hex-Rays’s plugin repository and is installable via HCLI. The updated interface displays installed/available Go versions & allows version management without the CLI. [5/8]
plugins.hex-rays.com
Hex-Rays Plugin Repo
Discover powerful plugins for IDA Pro to streamline reverse engineering and binary analysis. Improve efficiency with automation, visualization, and advanced decompilation tools.
110
Volexity @volexity.com · 10/03/2026
GoResolver v1.4 introduces Go type recovery via the new "-y" flag, and includes new capabilities to extract type names, structures, and kinds from obfuscated binaries. Browsing the binary’s types is now much easier and works with your SRE’s cross-referencing feature. [4/8]
110
Volexity @volexity.com · 10/03/2026
To improve accuracy, GoResolver can now automatically detect which Go version a binary was compiled with and select the closest available version for analysis. This release also optimizes how users list, install & remove Go versions directly from the CLI. [3/8]
110
Volexity @volexity.com · 10/03/2026
With this release, GoResolver’s CLI has been restructured into two core commands, "resolve" for binary analysis & "manage" for handling Go installations, making the toolchain cleaner and easier to navigate. [2/8]
110