Volexity @volexity.com · 28/09/2026Steven Adair keynotes at our Volexity Cyber Sessions in Amsterdam (Oct 29) on Chinese APTs exploiting Chrome vulns fixed in Chromium but not released. Identical exploit code points to a shared supplier, plus a false-flag op pinning it on Russia. Seating is limited! Register here: luma.com/0qtkw49c 011
Volexity @volexity.com · 25/09/2026Feike Hacquebord will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about Russia-, China- & DPRK-aligned APTs targeting Europe: IoT proxy networks, DPRK's Russian IPs, Pawn Storm's evolution & China's AI shift. Seating is limited! Register here: luma.com/0qtkw49c 032
Volexity @volexity.com · 22/09/2026Roey Shua will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about automating edge device forensics, from fingerprinting unknown routers & IoT devices to reconstructing symbols and acquiring memory on unsupported architectures. Seating is limited! Register here: luma.com/0qtkw49c 021
Volexity @volexity.com · 21/09/2026UTA0565 used multiple fake websites, posing as media orgs & an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening. 020
Volexity @volexity.com · 21/09/2026Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.volexity.comMind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day ExploitsOn September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2... 154
Reposted by VolexityVolatility @volatilityfoundation.org · 21/09/2026Volatility New Release: #volatility3 v2.28.2 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir 022
Volexity @volexity.com · 17/09/2026Christopher Lopez will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about the current macOS threat landscape: lures, targets, recently discovered malware, plus the artifacts that drive forensic analysis & durable detections. Seating is limited! Register here: luma.com/0qtkw49c 011
Volexity @volexity.com · 10/09/2026Contact us to schedule a Volexity Volcano demo! www.volexity.com/contact/demo...volexity.comDemo RequestVolexity’s solutions provide advanced analytics about the state of your devices and rapid insights into the risk those devices pose to your organization. These solutions are used by organizations acro... 010
Volexity @volexity.com · 10/09/2026Volexity Volcano v26.09.01 also adds MFT parsing from disk, file magic detection, importing from GCP buckets, and complete AWS GovCloud support. 110
Volexity @volexity.com · 10/09/2026Volexity Volcano v26.09.01 expands what you can analyze, and where! This release adds a powerful MCP server, threat intel integration, memory support for Linux 7.x kernels and Windows 26H1 on Snapdragon X2 ARM64. 121
Volexity @volexity.com · 09/09/2026Read the full analysis of the exploit chain and post-exploitation tradecraft here: www.volexity.com/blog/2026/09...volexity.comMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & WindowsOn September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta... 010
Volexity @volexity.com · 09/09/2026Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE). 110
Volexity @volexity.com · 09/09/2026Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). #DFIR #threatintelvolexity.comMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & WindowsOn September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta... 1126
Reposted by VolexityVolatility @volatilityfoundation.org · 13/08/2026The 14th annual #Volatility #PluginContest is officially OPEN! This is your chance to contribute to open source forensics, gain community-wide visibility for your work, and win a cash prize! See our blog post for details! Submission Deadline: 31 December 2026 #dfir #memoryforensicsvolatilityfoundation.orgThe 14th Annual Volatility Plugin Contest is Open!We are excited to announce that the 14th Annual Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open sourc… 045
Volexity @volexity.com · 28/07/2026Heading to Las Vegas next week? Connect with our team to discuss the latest in #DFIR, #memoryforensics, active threat actor campaigns we're tracking, and more! Let us know when you'd like to meet: www.volexity.com/contact/meet... 032
Volexity @volexity.com · 22/07/2026Volexity is hiring! Join a team that develops concrete solutions to challenging real-world problems. Whether your focus is bringing new products to market or delivering cybersecurity services globally, the work you do here helps real people and moves the industry forward. See how you can plug in!volexity.comCareersJoin a team where your contributions will have an impact on cybersecurity & develop concrete solutions to the most challenging real-world cyber problems. 011
Volexity @volexity.com · 21/07/2026Volexity is heading to Las Vegas! Members of our leadership, development, engineering & threat intelligence teams will be on site August 4–6. If you would like to connect to discuss the latest in #DFIR, #memoryforensics, or the current threat landscape, let us know when you’d like to meet!volexity.comSchedule a Meeting with Volexity in Las VegasIf you would like to schedule time with members of Volexity's leadership, development, engineering, or threat intelligence teams to learn more about our recent investigations and next-generation memor... 021
Reposted by VolexityAndrew Case @attrc.bsky.social · 20/07/2026Thank you to @jags.bsky.social for the @volexity.com shout out in the latest Three Buddy Problem episode! If you aren't performing memory forensics in your environments, then you cannot make any definitive claims on whether you are compromised! podcasts.apple.com/us/podcast/h... 054
Volexity @volexity.com · 17/07/2026SonicWall has released patches (versions 12.4.3-03453 and 12.5.0-02835) following their July 14 public disclosure. Organizations using affected SMA 1000 series devices should upgrade immediately. 001
Volexity @volexity.com · 17/07/2026Volexity attributes this activity to a #threatactor it tracks as UTA0533, with the earliest signs of compromise dating back to June 22, 2026. 101
Volexity @volexity.com · 17/07/2026Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintelvolexity.comProxying to Compromise: SonicWall Secure Mobile Access 0-day ExploitationIn early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil... 156
Reposted by VolexityAndrew Case @attrc.bsky.social · 19/06/2026I am very excited to announce that my @volatilityfoundation.org 3 workshop with David McDonald and Pierre Breton was accepted for @defcon.bsky.social this summer!! 0103
Volexity @volexity.com · 15/06/2026Great conversations at #FIRSTCON26 so far! Come say hello to the @volexity.com team at Booth 7 & see how to rapidly resolve your investigations and find what other tools are missing. #DFIR #FIRSTCON #memoryforensics 023
Reposted by VolexityAndrew Case @attrc.bsky.social · 08/06/2026Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale. 021
Volexity @volexity.com · 08/06/2026Come find us at Booth 7 to talk threat hunting and triage workflows with our team, including @stevenadair.bsky.social & @attrc.bsky.social 011
Volexity @volexity.com · 08/06/2026Heading to Denver for #FIRSTCON26 next week? Stop by the @volexity.com booth to see a demo of Volcano! We’ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. #DFIR #FIRSTCON 132
Reposted by VolexityAndrew Case @attrc.bsky.social · 04/06/2026Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices. 042
Volexity @volexity.com · 04/06/2026For more details on how the incident unfolded, the malware used by the threat actor, and the end goal of the intrusion, check out the full blog post: www.volexity.com/blog/2026/06... [4/4]volexity.comVerdantBamboo: Just Another BRICKSTORM in the FirewallIn September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The... 022
Volexity @volexity.com · 04/06/2026VerdantBamboo used a #0day privilege escalation exploit in the process and was also observed using administrative access to the victim organization's firewall to enable a custom VPN. [3/4] 111
Volexity @volexity.com · 04/06/2026This case involved the breach of the victim organization’s MSP and multiple malware implants found on firewalls, cloud storage sync devices & NAS appliances. [2/4] 111
Volexity @volexity.com · 04/06/2026@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. [1/4]volexity.comVerdantBamboo: Just Another BRICKSTORM in the FirewallIn September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The... 186
Volexity @volexity.com · 02/06/2026Over the next few months, they will be working alongside our engineering and threat intelligence teams on core software development and #memoryforensics research. Learn more about our program and future opportunities: www.volexity.com/internships/ #dfirvolexity.comInternshipsA Volexity internship is an excellent way to build your resume. Apply your knowledge & expertise to some of the most challenging cybersecurity problems. 022
Volexity @volexity.com · 02/06/2026We are excited to welcome our 2026 #summerinternship students from Notre Dame Computer Science and Engineering, University of Maryland Department of Computer Science, and Maryland Applied Graduate Engineering! 142
Volexity @volexity.com · 19/05/2026@volexity.com’s detection & response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild. Read our blog post for the original research mentioned: www.volexity.com/blog/2022/06...volexity.comDriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious BreachVolexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizat... 012
Volexity @volexity.com · 19/05/2026The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks for mentioning our work! 142
Volexity @volexity.com · 12/05/2026Contact us for more information: volexity.com/company/cont....volexity.comContactIf you'd like to learn more about Volexity, please contact us! 010
Volexity @volexity.com · 12/05/2026This release also adds detection of AppleScript usage, cleared Windows event logs, AV scanning of files & deployments across AWS accounts. 111
Volexity @volexity.com · 12/05/2026@volexity.com Volcano Server & Volcano One v26.04.27 adds memory analysis for arm64 Windows, memory-only .NET assemblies, SRUM database, Linux systemd units, history & timers from RAM. #memoryforensics #memoryanalysis #dfir 142
Reposted by VolexityVolatility @volatilityfoundation.org · 01/05/2026Volatility New Release: #volatility3 v2.28.0 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir 022
Reposted by VolexityAndrew Case @attrc.bsky.social · 17/04/2026I am excited to announce that I will be speaking at BSides Nashville on May 15th. Be sure to attend to see all the latest Volatility 3 (@volatilityfoundation.org) plugins against the most sophisticated and devastating malware from the wild! bsidesnash.orgbsidesnash.orgBSides Nashville 035
Reposted by VolexityAndrew Case @attrc.bsky.social · 14/04/2026Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malw... 099
Reposted by VolexityVolatility @volatilityfoundation.org · 13/03/2026We have announced the winners of the 2025 #Volatility #PluginContest! And the First Place is: Daniel Baier for XFRM Inspector Read the full Contest Results in our blog post: volatilityfoundation.org/the-2025-vol... Congrats to all winners & thank you to all participants! #DFIR #memoryforensicsvolatilityfoundation.orgThe 2025 Volatility Plugin Contest results are in!Results from the 13th Annual Volatility Plugin Contest are in! We received 8 submissions from 7 different countries that included 20 plugins. Contest submissions included a range of features… 011
Volexity @volexity.com · 10/03/2026Follow the GoResolver GitHub repo for future updates: github.com/volexity/GoR... Special thanks to Killian Raimbaud for these updates & Ivan Maldenov for his work on the type recovery feature during his Volexity internship. [8/8] 010
Volexity @volexity.com · 10/03/2026Existing report files remain fully compatible with GoResolver v1.4. Previously generated JSON reports can still be imported using the latest plugin versions; there is no need to re-analyze old samples. [7/8] 110
Volexity @volexity.com · 10/03/2026GoResolver’s Ghidra plugin now includes an ANALYZE mode for in-SRE analysis. After running, GoResolver automatically imports recovered symbols and types into Ghidra's database. Go version management for Ghidra still requires the CLI. [6/8] 110
Volexity @volexity.com · 10/03/2026The IDA Pro plugin for GoResolver now supports full in-SRE analysis. GoResolver is available in Hex-Rays’s plugin repository and is installable via HCLI. The updated interface displays installed/available Go versions & allows version management without the CLI. [5/8]plugins.hex-rays.comHex-Rays Plugin RepoDiscover powerful plugins for IDA Pro to streamline reverse engineering and binary analysis. Improve efficiency with automation, visualization, and advanced decompilation tools. 110
Volexity @volexity.com · 10/03/2026GoResolver v1.4 introduces Go type recovery via the new "-y" flag, and includes new capabilities to extract type names, structures, and kinds from obfuscated binaries. Browsing the binary’s types is now much easier and works with your SRE’s cross-referencing feature. [4/8] 110
Volexity @volexity.com · 10/03/2026To improve accuracy, GoResolver can now automatically detect which Go version a binary was compiled with and select the closest available version for analysis. This release also optimizes how users list, install & remove Go versions directly from the CLI. [3/8] 110
Volexity @volexity.com · 10/03/2026With this release, GoResolver’s CLI has been restructured into two core commands, "resolve" for binary analysis & "manage" for handling Go installations, making the toolchain cleaner and easier to navigate. [2/8] 110