tlansec
@tlansec.bsky.social
📤 757
📥 252
📝 38
Threat Intel
@volexity.com
n stuff. London, UK.
reposted by
tlansec
RandomAccessMusings
about 13 hours ago
This was an interesting one to work on! tldr: Chinese aligned actor uses LLM to empower their malware development, target gathering, and phishing operation. Goes wrong and starts randomly including pornographic material and other random files/info.
www.volexity.com/blog/2025/10...
loading . . .
APT Meets GPT: Targeted Operations with Untamed LLMs
Starting in June 2025, Volexity detected a series of spear phishing campaigns targeting several customers and their users in North America, Asia, and Europe. The initial observed campaigns were tailor...
https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/
0
4
4
reposted by
tlansec
Volexity
about 14 hours ago
APT meets GPT:
@volexity.com
#threatintel
is tracking
#threatactor
UTA0388's spear phishing campaigns against targets in North America, Europe & Asia, appearing to use LLMs to assist their ops. Letting
#AI
run your espionage operations? What could go wrong?
loading . . .
APT Meets GPT: Targeted Operations with Untamed LLMs
Starting in June 2025, Volexity detected a series of spear phishing campaigns targeting several customers and their users in North America, Asia, and Europe. The initial observed campaigns were tailor...
https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms
0
2
2
reposted by
tlansec
Volatility
1 day ago
We would like to thank
@volexity.com
for sponsoring the
#FTSCon
2025 Evening Reception, which will be at VUE Rooftop DC this year! If you haven’t registered for FTSCon yet, there’s still time! Registration closes Sunday Oct 12; learn more + register here:
volatilityfoundation.org/from-the-sou...
0
3
4
reposted by
tlansec
PJ 🇨🇦 🧬🔬📡💻 🥃
3 days ago
youtube.com/watch?v=5Z6a...
loading . . .
Bran Van 3000 - Drinking in LA (live at Nulle Part Ailleurs)
YouTube video by Pascal Burger
https://youtube.com/watch?v=5Z6aSO_BqIA&si=Wdy9UrCe3mebsf-v
0
1
1
reposted by
tlansec
State of Statecraft Conference
10 days ago
⏰ The inaugural SOS conference is 30 days away! Have you gotten your ticket yet?!? Listen to expert discussions on state-sponsored operations covering espionage, sabotage, and attribution of Russia, China, Iran, and more. Registration is still open!
stateofstatecraft.com/agenda
0
7
4
reposted by
tlansec
Wesley Shields
13 days ago
www.zscaler.com/blogs/securi...
- Nice writeup by zscaler on some COLDRIVER malware. I'm talking about this stuff at
#FTSCon
in a few weeks and will have lots more details there.
loading . . .
COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz
The Russia-linked group COLDRIVER targeted dissidents and their supporters using a ClickFix technique, resulting in the deployment of BAITSWITCH and SIMPLEFIX.
https://www.zscaler.com/blogs/security-research/coldriver-updates-arsenal-baitswitch-and-simplefix
0
7
4
reposted by
tlansec
The Banshee Queen 👑
14 days ago
First public report at Recorded Future by yours truly is out! RedNovember (formerly TAG-100, a.k.a. Storm-2077) is a Chinese state-sponsored threat group focused on intelligence collection, especially on flashpoint issues of strategic interest to China.
www.recordedfuture.com/research/red...
loading . . .
RedNovember Targets Government, Defense, and Technology Organizations
RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the lates...
https://www.recordedfuture.com/research/rednovember-targets-government-defense-and-technology-organizations
2
22
14
reposted by
tlansec
Greg Lesnewich
15 days ago
Couple of openings here in our threat research org! Staff Security Research Engineer:
proofpoint.wd5.myworkdayjobs.com/en-US/Proofp...
Senior Threat Researcher (ecrime team):
proofpoint.wd5.myworkdayjobs.com/ProofpointCa...
loading . . .
Staff Security Research Engineer
About Us: We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to s...
https://proofpoint.wd5.myworkdayjobs.com/en-US/ProofpointCareers/job/Staff-Security-Research-Engineer_R12883-1
0
10
5
reposted by
tlansec
Adam Sharp
17 days ago
In Swedish, a word for what you eat to bridge the gap between meals (or while waiting for the main course to cook) is stödmacka. It means "support sandwich." A similar word in Norwegian is ventepølse, or "waiting sausage."
61
2184
547
reposted by
tlansec
PJ 🇨🇦 🧬🔬📡💻 🥃
19 days ago
www.welivesecurity.com/en/eset-rese...
loading . . .
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/
0
1
1
reposted by
tlansec
Volatility
20 days ago
#FTSCon
Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track. See the full list of speakers + event info, including how to register, here:
volatilityfoundation.org/from-the-sou...
0
4
7
reposted by
tlansec
Dirk-jan
22 days ago
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io/obtaining-gl...
loading . . .
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
9
85
43
reposted by
tlansec
Wesley Shields
23 days ago
I’ll be giving a talk at FTS this year. Not going to lie, I’m doing it just so I can heckle Sir Tom of The House of Lancaster (
@tlansec.bsky.social
) in person.
volatilityfoundation.org/from-the-sou...
loading . . .
From The Source 2025
Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou…
https://volatilityfoundation.org/from-the-source-2025/
0
5
1
reposted by
tlansec
qntm
about 1 month ago
ME, IN TEARS: you can't just say every single part of a computer system is a file UNIX, POINTING AT THE MOUSE: file
39
2330
526
reposted by
tlansec
Andrew Case
about 1 month ago
The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques
memoryanalysis.net/courses-malw...
loading . . .
Malware and Memory Forensics Training - Memory Analysis
Malware and memory forensics training courses offered by the Memory Analysis Team.
https://memoryanalysis.net/courses-malware-memory-forensics/#course-availability
0
6
6
reposted by
tlansec
Ben Read
about 1 month ago
Now up to 22 different Cinnamon Toast Crunch related products. The quest continues.
add a skeleton here at some point
0
2
1
reposted by
tlansec
Pasquale Stirparo 🇺🇦 🇪🇺
about 1 month ago
TL;DR I am launching my
#startup
and we are going to change how to evaluate,cluster and reason about
#malware
, delivering accurate,contextual intelligence on samples. Say Hi to RationalEdge
@rationaledge.bsky.social
rationaledge.io
#threatintel
#threathunting
#cti
#reverseengineering
#detection
1/9
loading . . .
RationalEdge - Intelligence Meets Accuracy
Advanced malware analysis and threat intelligence solutions by RationalEdge
https://rationaledge.io
2
25
15
reposted by
tlansec
Volexity
about 2 months ago
And that’s a wrap for our 2025
#summerinternship
program! This was a great summer of challenging impactful projects & fun team-building excursions. We wish our students all the best as they settle back into their Dept of Computer Science programs at University of Notre Dame & University of Maryland!
0
2
2
reposted by
tlansec
Joe
about 2 months ago
I don't think children should have phones. They should have huge beige desktop computer with "Windows 9x Operating System", "Dedicated 3D accelerator", and "SoundBlaster compatible sound card"
75
1793
359
reposted by
tlansec
Volatility
about 2 months ago
Coming this October:
#FTSCon
2025, hosted by
@volatilityfoundation.org
! And this year there are TWO in-person training opportunities!👇
#dfir
#memoryforensics
#volatility3
#hardwarehackingbasics
#grandideastudio
1
2
5
reposted by
tlansec
Volatility
2 months ago
We are thrilled to announce that
@joegrand.bsky.social
is this year’s
#FTSCon
Keynote speaker! Joe will be sharing stories & technical details about his wallet hacking adventures to kickoff our full-day event on Monday, Oct 20, 2025. You don’t want to miss this!
1
4
6
reposted by
tlansec
Volexity
about 2 months ago
@volexity.com
has released updates to its
#opensource
GoResolver project and more! This work was part of a project for one of our
#summerinternship
students. Read more details about Volexity’s updated GoResolver projects + other
#golang
tools in our special blog post!
loading . . .
Go Get 'Em: Updates to Volexity Golang Tooling
Volexity’s GoResolver tool was released in April 2025 to help with analysis of these samples, reducing analyst load when working with obfuscated Golang binaries. However, there are still some difficul...
https://www.volexity.com/blog/2025/08/11/go-get-em-updates-to-volexity-golang-tooling/
1
10
10
reposted by
tlansec
ESET Research
about 2 months ago
#ESETresearch
has discovered a zero-day vulnerability in WinRAR, exploited in the wild by Russia-aligned
#RomCom
@dmnsch @cherepanov74
www.welivesecurity.com/en/eset-rese...
1/7
1
17
13
reposted by
tlansec
Wesley Shields
2 months ago
YARA-X 1.5.0 is out. Nice new features (including a crx module) and bug fixes. Congratulations to Victor and all the contributors!
github.com/VirusTotal/y...
loading . . .
Release v1.5.0 · VirusTotal/yara-x
Implement the crx module for parsing Chrome Extension files (#423). Allow underscores in integer and float literals (#405). Adopt Anomali's symhash algorithm for Mach-O files (#425). Support boolea...
https://github.com/VirusTotal/yara-x/releases/tag/v1.5.0
0
4
1
Incredible writeup from Eye Security on their adventures logging into internal-only MS services:
research.eye.security/consent-and-...
2 months ago
0
0
0
reposted by
tlansec
Ken Cheng
2 months ago
A radiologist called me yesterday. I was prepared for the worst
2
146
21
I think about this quote alot:
youtu.be/8J8A9ZiIeUQ?...
loading . . .
"I don't know shit about fuck" - Ruth Langmore - Ozark
YouTube video by Bee4Brendan
https://youtu.be/8J8A9ZiIeUQ?si=XUczKVk8pqRtmpzj&t=30
2 months ago
0
0
0
reposted by
tlansec
SwiftOnSecurity
2 months ago
15
503
106
reposted by
tlansec
Jeffrey Vagle
2 months ago
Jen Easterly was a supremely effective leader of CISA and you would be very hard pressed to find anyone who's a more qualified and quietly competent professional than her. This administration and its gormless hacks continue to cut off our collective noses to spite our face.
add a skeleton here at some point
1
93
36
reposted by
tlansec
Andy Greenberg
2 months ago
Microsoft found Turla, Russia's elite FSB cyberespionage group, hacking foreign embassies' staff in Moscow by directly meddling with ISP traffic to infect targets with spyware that silently stripped away encryption on their communications and credentials.
www.wired.com/story/russia...
loading . . .
The Kremlin's Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware
The FSB cyberespionage group known as Turla seems to have used its control of Russia's network infrastructure to meddle with web traffic and trick diplomats into infecting their computers.
https://www.wired.com/story/russia-fsb-turla-secret-blizzard-apolloshadow-isp-cyberespionage/
1
121
74
reposted by
tlansec
Tibet Action Institute
2 months ago
First cell-phone network cyberattack on Tibetan leader detected
@tibcert.bsky.social
www.phayul.com/2025/07/29/5...
loading . . .
First cell-phone network cyberattack on Tibetan leader detected - Phayul
Phayul.com is one of the most popular & successful Tibetan news website in English. With daily readers touching over 12,500 and still growing. It features news and views on Tibet.
https://www.phayul.com/2025/07/29/52703/
0
6
4
reposted by
tlansec
piggo
2 months ago
~Paloalto~ Nation-state actor Liminal Panda uses custom malware like GTPDoor to infiltrate telecom networks for persistent access and potential location tracking. - IOCs: GTPDoor, ChronosRAT, NoDepDNS -
#GTPDoor
#LiminalPanda
#ThreatIntel
loading . . .
Nation-State Actor Targets Global Telecoms
https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/
0
4
6
When your CTI blog uses AI art, it immediately loses 10 respect points. Discuss.
2 months ago
0
1
0
reposted by
tlansec
@volexity.com
is looking to grow our Threat Intelligence team. New job posting for Senior Analyst role is up here:
www.volexity.com/company/care...
If you have any questions, don't hesitate to ask.
loading . . .
Open Position
Career Opportunity: Volexity is currently looking to hire Senior Threat Intelligence Analyst to join its rapidly growing services team.
https://www.volexity.com/company/careers/senior-threat-intelligence-analyst/
3 months ago
2
12
9
reposted by
tlansec
Wesley Shields
3 months ago
First question: Will I be fired for only referring to you as Sir Tom of The House of Lancaster? Seriously though, if you’re looking this is one of the teams I would consider.
add a skeleton here at some point
0
4
1
@volexity.com
is looking to grow our Threat Intelligence team. New job posting for Senior Analyst role is up here:
www.volexity.com/company/care...
If you have any questions, don't hesitate to ask.
loading . . .
Open Position
Career Opportunity: Volexity is currently looking to hire Senior Threat Intelligence Analyst to join its rapidly growing services team.
https://www.volexity.com/company/careers/senior-threat-intelligence-analyst/
3 months ago
2
12
9
reposted by
tlansec
Saher
3 months ago
New from the one and only pun-king
@mkyo.bsky.social
on the increased and ongoing Chinese targeting of semiconductor-related organisations in Taiwan. Edge device exploitation may be the TTP of the moment, but Chinese groups still go phishing when the chips are down
www.proofpoint.com/us/blog/thre...
loading . . .
Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting | Proofpoint US
Key findings Between March and June 2025, Proofpoint Threat Research observed three Chinese state-sponsored threat actors conduct targeted phishing campaigns against the Taiwanese
https://www.proofpoint.com/us/blog/threat-insight/phish-china-aligned-espionage-actors-ramp-up-taiwan-semiconductor-targeting
1
9
6
reposted by
tlansec
Volexity
3 months ago
This training course will be led by Andrew Case
@attrc.bsky.social
, Michael Ligh & Dave Lassalle. This is a great opportunity to gain valuable knowledge about
#Volatility3
+ learn all about
#memoryforensics
from Volatility core developers! Seats are filling up quickly so don't wait!
add a skeleton here at some point
0
6
8
reposted by
tlansec
Calwarez
4 months ago
🚨 We’re hiring at Recorded Future’s Insikt Group Two senior analyst roles are open right now. Both focus on tracking nation-state threats. 🧵
1
6
4
reposted by
tlansec
Kat Tenbarge
4 months ago
People who don’t like AI aren’t in denial about how useful it is. People who like AI are in denial about how useful it is
52
2503
563
reposted by
tlansec
Andrew Case
4 months ago
The CFP for our 2nd annual From the Source event is now open! The event includes two tracks, the first for Makers of open source DFIR tools and the second for Hunters who have performed the most interesting investigations of the last year.
volatilityfoundation.org/announcing-f...
loading . . .
Announcing FTSCon 2025 & In-person Malware and Memory Forensics Training!
Mark your calendars for Monday, October 20, 2025! We will again be hosting FTSCon in Arlington, Virginia.You can read more event details here. Registration is now open!
https://volatilityfoundation.org/announcing-ftscon-2025-in-person-malware-and-memory-forensics-training/
0
2
3
reposted by
tlansec
ESET Research
4 months ago
#ESETresearch
analyzed a campaign deployed by BladedFeline, an Iran-aligned threat actor with likely ties to
#OilRig
. We discovered the campaign, which targeted Kurdish and Iraqi government officials, in 2024.
www.welivesecurity.com/en/eset-rese...
1/6
loading . . .
BladedFeline: Whispering in the dark
ESET researchers analyzed a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group with likely ties to OilRig.
https://www.welivesecurity.com/en/eset-research/bladedfeline-whispering-dark/
1
8
6
Upcoming birthday of a partner? Anniversary? Babyshower? Look no further than this for the perfect gift for any occasion:
www.crowdstrikeswag.com/Scattered-Sp...
loading . . .
Scattered Spider Skateboard
https://www.crowdstrikeswag.com/Scattered-Spider-Skateboard-P907.aspx
4 months ago
1
5
0
reposted by
tlansec
Wesley Shields
4 months ago
New YARA-X release! In fact, Victor released 1.0.0. Lots of hard work by Victor and others to make this happen, congratulations to everyone involved!
github.com/VirusTotal/y...
loading . . .
Release v1.0.0 · VirusTotal/yara-x
First stable release! Raise warning when loops can have too many iterations (#352). Raise warning when comparing a string that is known to be lowercase (like the result of hash.md5) with a stri...
https://github.com/VirusTotal/yara-x/releases/tag/v1.0.0
0
7
4
reposted by
tlansec
David Buchanan
4 months ago
cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort()
6
441
77
reposted by
tlansec
Olúfẹ́mi O. Táíwò
4 months ago
the modern information environment
115
4094
1000
reposted by
tlansec
Volatility
5 months ago
We are excited to announce FTSCon 2025 on October 20, 2025, in Arlington VA! Registration is now OPEN + we have a Call for Speakers. Following FTSCon will be a 4-day Malware & Memory Forensics Training course with Volatility 3. See the full details here:
volatilityfoundation.org/announcing-f...
loading . . .
Announcing FTSCon 2025 & In-person Malware and Memory Forensics Training!
Mark your calendars for Monday, October 20, 2025! We will again be hosting FTSCon in Arlington, Virginia.You can read more event details here. Registration is now open!
https://volatilityfoundation.org/announcing-ftscon-2025-in-person-malware-and-memory-forensics-training/
0
7
11
reposted by
tlansec
5 months ago
EU Council 🇪🇺 has issued sanctions against Stark Industries, a hosting company registered in the UK 🇬🇧, as "they have been acting as enablers of various Russian state-sponsored and affiliated actors to conduct destabilising [...] the Union and third countries"
www.consilium.europa.eu/en/press/pre...
loading . . .
Russian hybrid threats: EU lists further 21 individuals and 6 entities and introduces sectoral measures in response to destabilising activities against the EU, its member states and international part...
The Council imposed restrictive measures against 21 individuals and 6 entities responsible for Russia’s destabilising actions against the EU and its member states and broadened the scope of the sancti...
https://www.consilium.europa.eu/en/press/press-releases/2025/05/20/russian-hybrid-threats-eu-lists-further-21-individuals-and-6-entities-and-introduces-sectoral-measures-in-response-to-destabilising-activities-against-the-eu-its-member-states-and-international-partners/
0
15
12
reposted by
tlansec
John Hultquist
5 months ago
If you’ve been laid off from a cyber intel position, please reach out if you’d like to come to
@sleuthcon.bsky.social
.
3
69
49
reposted by
tlansec
The Banshee Queen 👑
5 months ago
Not me losing my mind tracking ORBs lalalala I can't hear you over the sound of how many darned ORB networks there are 🫠
2
16
4
Load more
feeds!
log in