tlansec
@tlansec.bsky.social
📤 770
📥 259
📝 40
Threat Intel
@volexity.com
n stuff. London, UK.
reposted by
tlansec
Łukasz
4 days ago
🎵🎶All I want for Christmas is… electrons 🎶🎵
add a skeleton here at some point
0
2
1
reposted by
tlansec
Wesley Shields
5 days ago
Yara-x 1.10.0 released today! It can now automatically fix some warnings, and some improvements in code generation. This is another great step forward for the project.
github.com/VirusTotal/y...
loading . . .
Release v1.10.0 · VirusTotal/yara-x
New yr fix warnings command (#493). Generate more efficient WASM code for some expressions, reducing the size of compiled rules (5efc214, a865681). Improve the API for traversing the AST in DFS ord...
https://github.com/VirusTotal/yara-x/releases/tag/v1.10.0
0
7
3
reposted by
tlansec
Cynthia Brumfield
6 days ago
Really digging this year’s CYBERWARCON logo
1
9
4
reposted by
tlansec
PIVOTcon
12 days ago
#PIVOTcon26
registration is now OPEN 🤟📷
#ThreatResearch
#ThreatIntel
📷https://pivotcon.org Please read carefully the whole 🧵 for the rules about invite -> registration (1/6)🌐
1
15
13
Enhance your CyberChef experience with GeoCities mode!
11 days ago
0
2
1
reposted by
tlansec
Marcus Hutchins
12 days ago
This post from the President of Windows basically reads like someone trained an AI on those SF billboards that just say incomprehensible nonsense.
18
191
24
reposted by
tlansec
Lorenzo Franceschi-Bicchierai
14 days ago
Remember NFTs? 😂😂😂😂😂😂😂
11
78
15
This is so good. bahahaha:
www.youtube.com/watch?v=dr9M...
loading . . .
Private jets don't pay fuel tax. Now I don't either.
YouTube video by Oli Frost
https://www.youtube.com/watch?v=dr9MH0NuUtg
18 days ago
0
3
0
reposted by
tlansec
Ollie Whitehouse
18 days ago
At
@ncsc.gov.uk
we have just launched the CyberUK tech talks call for papers across three topics - Cyber applications of AI - What works: approaches that reduce cyber harm - The evolving threat
www.cyberuk.uk/2026/call-fo...
loading . . .
Tech Talks - Call for Papers
https://www.cyberuk.uk/2026/call-for-papers
0
5
9
reposted by
tlansec
Greg Otto
18 days ago
my response to this is the loudest OK BRO you've ever heard in your life
add a skeleton here at some point
1
16
2
reposted by
tlansec
Saher
20 days ago
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story
www.proofpoint.com/us/blog/thre...
loading . . .
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report. Key findings Between June and August 2025,
https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution
2
18
12
reposted by
tlansec
CYBERWARCON
19 days ago
Meet our speaker Patrick Whitsell! Patrick has expertise in monitoring and defending against cyber espionage threat actors. His talk, "Cyber(trade)war: Paradigm Shift in Economic Espionage", will cover the shift in PRC state-sponsored cyber espionage. Learn more!
www.cyberwarcon.com
0
4
4
reposted by
tlansec
Alex Lanstein
about 1 month ago
i heard my kids singing about "APT"s and i was sorely disappointed
www.youtube.com/watch?v=ekr2...
loading . . .
ROSÉ & Bruno Mars - APT. (Official Music Video)
YouTube video by ROSÉ
https://www.youtube.com/watch?v=ekr2nIex040
0
2
1
reposted by
tlansec
Wesley Shields
about 1 month ago
Thanks to @xorhex for an interesting discussion that is worth sharing here. I knew I read this somewhere but here's a fun thing you can do in YARA-X: 2 of ($a*, $b*, 3 of ($c*)) This is documented but not widely known:
virustotal.github.io/yara-x/docs/...
loading . . .
Differences with YARA
Documents the differences between YARA-X and YARA.
https://virustotal.github.io/yara-x/docs/writing_rules/differences-with-yara/#of-statement-accepts-tuples-of-boolean-expressions
2
5
5
reposted by
tlansec
We're just normal men
about 1 month ago
We’re just normal men
loading . . .
11
1632
640
reposted by
tlansec
RandomAccessMusings
about 2 months ago
This was an interesting one to work on! tldr: Chinese aligned actor uses LLM to empower their malware development, target gathering, and phishing operation. Goes wrong and starts randomly including pornographic material and other random files/info.
www.volexity.com/blog/2025/10...
loading . . .
APT Meets GPT: Targeted Operations with Untamed LLMs
Starting in June 2025, Volexity detected a series of spear phishing campaigns targeting several customers and their users in North America, Asia, and Europe. The initial observed campaigns were tailor...
https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/
0
5
4
reposted by
tlansec
Volexity
about 2 months ago
APT meets GPT:
@volexity.com
#threatintel
is tracking
#threatactor
UTA0388's spear phishing campaigns against targets in North America, Europe & Asia, appearing to use LLMs to assist their ops. Letting
#AI
run your espionage operations? What could go wrong?
loading . . .
APT Meets GPT: Targeted Operations with Untamed LLMs
Starting in June 2025, Volexity detected a series of spear phishing campaigns targeting several customers and their users in North America, Asia, and Europe. The initial observed campaigns were tailor...
https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms
0
3
3
reposted by
tlansec
Volatility
about 2 months ago
We would like to thank
@volexity.com
for sponsoring the
#FTSCon
2025 Evening Reception, which will be at VUE Rooftop DC this year! If you haven’t registered for FTSCon yet, there’s still time! Registration closes Sunday Oct 12; learn more + register here:
volatilityfoundation.org/from-the-sou...
0
3
4
reposted by
tlansec
PJ 🇨🇦 🧬🔬📡💻 🥃
about 2 months ago
youtube.com/watch?v=5Z6a...
loading . . .
Bran Van 3000 - Drinking in LA (live at Nulle Part Ailleurs)
YouTube video by Pascal Burger
https://youtube.com/watch?v=5Z6aSO_BqIA&si=Wdy9UrCe3mebsf-v
0
1
1
reposted by
tlansec
State of Statecraft Conference
about 2 months ago
⏰ The inaugural SOS conference is 30 days away! Have you gotten your ticket yet?!? Listen to expert discussions on state-sponsored operations covering espionage, sabotage, and attribution of Russia, China, Iran, and more. Registration is still open!
stateofstatecraft.com/agenda
0
8
4
reposted by
tlansec
Wesley Shields
about 2 months ago
www.zscaler.com/blogs/securi...
- Nice writeup by zscaler on some COLDRIVER malware. I'm talking about this stuff at
#FTSCon
in a few weeks and will have lots more details there.
loading . . .
COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz
The Russia-linked group COLDRIVER targeted dissidents and their supporters using a ClickFix technique, resulting in the deployment of BAITSWITCH and SIMPLEFIX.
https://www.zscaler.com/blogs/security-research/coldriver-updates-arsenal-baitswitch-and-simplefix
0
7
4
reposted by
tlansec
The Banshee Queen 👑
2 months ago
First public report at Recorded Future by yours truly is out! RedNovember (formerly TAG-100, a.k.a. Storm-2077) is a Chinese state-sponsored threat group focused on intelligence collection, especially on flashpoint issues of strategic interest to China.
www.recordedfuture.com/research/red...
loading . . .
RedNovember Targets Government, Defense, and Technology Organizations
RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the lates...
https://www.recordedfuture.com/research/rednovember-targets-government-defense-and-technology-organizations
2
21
14
reposted by
tlansec
Greg Lesnewich
2 months ago
Couple of openings here in our threat research org! Staff Security Research Engineer:
proofpoint.wd5.myworkdayjobs.com/en-US/Proofp...
Senior Threat Researcher (ecrime team):
proofpoint.wd5.myworkdayjobs.com/ProofpointCa...
loading . . .
Staff Security Research Engineer
About Us: We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to s...
https://proofpoint.wd5.myworkdayjobs.com/en-US/ProofpointCareers/job/Staff-Security-Research-Engineer_R12883-1
0
10
5
reposted by
tlansec
Adam Sharp
2 months ago
In Swedish, a word for what you eat to bridge the gap between meals (or while waiting for the main course to cook) is stödmacka. It means "support sandwich." A similar word in Norwegian is ventepølse, or "waiting sausage."
61
2183
544
reposted by
tlansec
PJ 🇨🇦 🧬🔬📡💻 🥃
2 months ago
www.welivesecurity.com/en/eset-rese...
loading . . .
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/
0
1
1
reposted by
tlansec
Volatility
2 months ago
#FTSCon
Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track. See the full list of speakers + event info, including how to register, here:
volatilityfoundation.org/from-the-sou...
0
4
7
reposted by
tlansec
Dirk-jan
2 months ago
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io/obtaining-gl...
loading . . .
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
9
87
42
reposted by
tlansec
Wesley Shields
2 months ago
I’ll be giving a talk at FTS this year. Not going to lie, I’m doing it just so I can heckle Sir Tom of The House of Lancaster (
@tlansec.bsky.social
) in person.
volatilityfoundation.org/from-the-sou...
loading . . .
From The Source 2025
Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou…
https://volatilityfoundation.org/from-the-source-2025/
0
5
1
reposted by
tlansec
qntm
3 months ago
ME, IN TEARS: you can't just say every single part of a computer system is a file UNIX, POINTING AT THE MOUSE: file
39
2317
522
reposted by
tlansec
Andrew Case
3 months ago
The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques
memoryanalysis.net/courses-malw...
loading . . .
Malware and Memory Forensics Training - Memory Analysis
Malware and memory forensics training courses offered by the Memory Analysis Team.
https://memoryanalysis.net/courses-malware-memory-forensics/#course-availability
0
7
6
reposted by
tlansec
Ben Read
3 months ago
Now up to 22 different Cinnamon Toast Crunch related products. The quest continues.
add a skeleton here at some point
0
2
1
reposted by
tlansec
Pasquale Stirparo 🇺🇦 🇪🇺
3 months ago
TL;DR I am launching my
#startup
and we are going to change how to evaluate,cluster and reason about
#malware
, delivering accurate,contextual intelligence on samples. Say Hi to RationalEdge
@rationaledge.bsky.social
rationaledge.io
#threatintel
#threathunting
#cti
#reverseengineering
#detection
1/9
loading . . .
RationalEdge - Intelligence Meets Accuracy
Advanced malware analysis and threat intelligence solutions by RationalEdge
https://rationaledge.io
2
24
14
reposted by
tlansec
Volexity
3 months ago
And that’s a wrap for our 2025
#summerinternship
program! This was a great summer of challenging impactful projects & fun team-building excursions. We wish our students all the best as they settle back into their Dept of Computer Science programs at University of Notre Dame & University of Maryland!
0
2
2
reposted by
tlansec
Joe
3 months ago
I don't think children should have phones. They should have huge beige desktop computer with "Windows 9x Operating System", "Dedicated 3D accelerator", and "SoundBlaster compatible sound card"
75
1785
355
reposted by
tlansec
Volatility
3 months ago
Coming this October:
#FTSCon
2025, hosted by
@volatilityfoundation.org
! And this year there are TWO in-person training opportunities!👇
#dfir
#memoryforensics
#volatility3
#hardwarehackingbasics
#grandideastudio
1
2
5
reposted by
tlansec
Volatility
4 months ago
We are thrilled to announce that
@joegrand.bsky.social
is this year’s
#FTSCon
Keynote speaker! Joe will be sharing stories & technical details about his wallet hacking adventures to kickoff our full-day event on Monday, Oct 20, 2025. You don’t want to miss this!
1
4
6
reposted by
tlansec
Volexity
4 months ago
@volexity.com
has released updates to its
#opensource
GoResolver project and more! This work was part of a project for one of our
#summerinternship
students. Read more details about Volexity’s updated GoResolver projects + other
#golang
tools in our special blog post!
loading . . .
Go Get 'Em: Updates to Volexity Golang Tooling
Volexity’s GoResolver tool was released in April 2025 to help with analysis of these samples, reducing analyst load when working with obfuscated Golang binaries. However, there are still some difficul...
https://www.volexity.com/blog/2025/08/11/go-get-em-updates-to-volexity-golang-tooling/
1
10
10
reposted by
tlansec
ESET Research
4 months ago
#ESETresearch
has discovered a zero-day vulnerability in WinRAR, exploited in the wild by Russia-aligned
#RomCom
@dmnsch @cherepanov74
www.welivesecurity.com/en/eset-rese...
1/7
1
17
13
reposted by
tlansec
Wesley Shields
4 months ago
YARA-X 1.5.0 is out. Nice new features (including a crx module) and bug fixes. Congratulations to Victor and all the contributors!
github.com/VirusTotal/y...
loading . . .
Release v1.5.0 · VirusTotal/yara-x
Implement the crx module for parsing Chrome Extension files (#423). Allow underscores in integer and float literals (#405). Adopt Anomali's symhash algorithm for Mach-O files (#425). Support boolea...
https://github.com/VirusTotal/yara-x/releases/tag/v1.5.0
0
4
1
Incredible writeup from Eye Security on their adventures logging into internal-only MS services:
research.eye.security/consent-and-...
4 months ago
0
0
0
reposted by
tlansec
Ken Cheng
4 months ago
A radiologist called me yesterday. I was prepared for the worst
2
147
21
I think about this quote alot:
youtu.be/8J8A9ZiIeUQ?...
loading . . .
"I don't know shit about fuck" - Ruth Langmore - Ozark
YouTube video by Bee4Brendan
https://youtu.be/8J8A9ZiIeUQ?si=XUczKVk8pqRtmpzj&t=30
4 months ago
0
0
0
reposted by
tlansec
SwiftOnSecurity
4 months ago
15
501
106
reposted by
tlansec
Jeffrey Vagle
4 months ago
Jen Easterly was a supremely effective leader of CISA and you would be very hard pressed to find anyone who's a more qualified and quietly competent professional than her. This administration and its gormless hacks continue to cut off our collective noses to spite our face.
add a skeleton here at some point
1
93
36
reposted by
tlansec
Andy Greenberg
4 months ago
Microsoft found Turla, Russia's elite FSB cyberespionage group, hacking foreign embassies' staff in Moscow by directly meddling with ISP traffic to infect targets with spyware that silently stripped away encryption on their communications and credentials.
www.wired.com/story/russia...
loading . . .
The Kremlin's Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware
The FSB cyberespionage group known as Turla seems to have used its control of Russia's network infrastructure to meddle with web traffic and trick diplomats into infecting their computers.
https://www.wired.com/story/russia-fsb-turla-secret-blizzard-apolloshadow-isp-cyberespionage/
1
121
74
reposted by
tlansec
Tibet Action Institute
4 months ago
First cell-phone network cyberattack on Tibetan leader detected
@tibcert.bsky.social
www.phayul.com/2025/07/29/5...
loading . . .
First cell-phone network cyberattack on Tibetan leader detected - Phayul
Phayul.com is one of the most popular & successful Tibetan news website in English. With daily readers touching over 12,500 and still growing. It features news and views on Tibet.
https://www.phayul.com/2025/07/29/52703/
0
6
4
reposted by
tlansec
piggo
4 months ago
~Paloalto~ Nation-state actor Liminal Panda uses custom malware like GTPDoor to infiltrate telecom networks for persistent access and potential location tracking. - IOCs: GTPDoor, ChronosRAT, NoDepDNS -
#GTPDoor
#LiminalPanda
#ThreatIntel
loading . . .
Nation-State Actor Targets Global Telecoms
https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/
0
4
6
When your CTI blog uses AI art, it immediately loses 10 respect points. Discuss.
4 months ago
0
1
0
reposted by
tlansec
@volexity.com
is looking to grow our Threat Intelligence team. New job posting for Senior Analyst role is up here:
www.volexity.com/company/care...
If you have any questions, don't hesitate to ask.
loading . . .
Open Position
Career Opportunity: Volexity is currently looking to hire Senior Threat Intelligence Analyst to join its rapidly growing services team.
https://www.volexity.com/company/careers/senior-threat-intelligence-analyst/
4 months ago
2
12
9
reposted by
tlansec
Wesley Shields
4 months ago
First question: Will I be fired for only referring to you as Sir Tom of The House of Lancaster? Seriously though, if you’re looking this is one of the teams I would consider.
add a skeleton here at some point
0
4
1
Load more
feeds!
log in