必看3
Clop 利用 CVE-2026-12569 部署定制 Web Shell,窃取工程数据。
针对 PTC Windchill 的定向数据窃取平台,工业软件用户需警惕。
RT @ReliaQuestTR: 🚨 ReliaQuest discovered a custom web shell highly likely linked to Clop, deployed following exploitation of CVE-2026-12569 in PTC Windchill. Our analysis found that the implant is not a generic command shell, rather, it is a purpose-built data-theft and extortion platform developed with detailed knowledge of Windchill’s APIs, database schema, keystore, and file-vault structure.
The web shell can map sensitive engineering files, read and transfer arbitrary data, and decrypt every credential stored in the Windchill keystore, including LDAP, administrative, and object-storage credentials. It also contains a custom Java class loader that can execute attacker-supplied code directly in memory, enabling follow-on activity such as lateral movement, persistence, ransomware deployment, and further data theft.
The implant uses Windchill’s own application classes and database identity, delivers commands through the custom X-windchill-req HTTP header, and compresses responses with GZIP. These techniques allow its activity to resemble legitimate application traffic and reduce visibility across traditional network and database monitoring.
Organizations should immediately patch CVE-2026-12569, hunt for suspicious JSP files in Windchill codebase directories, and rotate all credentials stored in the Windchill keystore on any server suspected of compromise.
IOCs:
321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf
5.180.41[.]35
78.128.113[.]10
104.194.9[.]14
104.243.35[.]63
185.227.83[.]236
209.222.98[.]44
216.152.151[.]204
Read more: https://t.co/JrCvd97DF7
新恶意软件 HypeAgent 集窃密与加载于一体,通过垃圾邮件传播。
新型窃密木马,针对 AI 平台和游戏账号,需更新检测规则。
RT @abuse_ch: We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam 📧, first observed on August 1, 2026 🔭👀
Key Capabilities ⤵️
🕵️ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners 💸
🔎 Targeted Harvesting: Steals web browser & email credentials, crypto wallets, and gaming accounts (Steam, Roblox) 🎮
🤖 AI & Platform Cookie Stealing: Targets a list of hardcoded domains like Grok, Anthropic, Coinbase, ByBit, Instagram, and Rockstar Games for which it steals session cookies 🍪
💰 Electron App Webinjects: Intercepts activity on desktop apps like Exodus Wallet 👛
Artifacts observed ⤵️
1️⃣ Stores stealers logs under C:\Users\USERNAME\AppData\Local\Temp\hype-YYYY-MM-DD.log
2️⃣ Uses HTTP host header "X-Hype-Agent-Token" during botnet C2 communication
HypeAgent communicates via WebSocket using JSON. Here are some Botnet C2 servers we have been observed ⤵️
📡 31.40.204.178:7080 WhiteLabel 🇹🇷
📡 94.26.3.211:7443 Stellar Group SAS 🇫🇷
📡 192.109.139.91:7443 Stellar Group SAS 🇺🇸
📡 195.177.94.60:7443 Stellar Group SAS 🇫🇷
📡 107.175.148.122:7443 HostPapa 🇺🇸
📡 209.54.103.173:7443 HostPapa 🇺🇸
📡 132.243.225.173:7080 QWINS-Hosting 🇩🇪
📡 78.40.209.113:7081 QWINS-Hosting 🇫🇮
📡 31.77.138.55:5654 QWINS-Hosting 🇫🇮
🦊 Releated IOCs on ThreatFox:
https://t.co/X0S6ihaSXz
📄 Releated malware samples on MalwareBazaar:
https://t.co/bdXcPm9i6e
StopAndProtect 行动滥用数千被黑 WordPress 站点传播勒索和数据窃取。
大规模滥用 WordPress 基础设施,影响面广,需加强网站安全。
Check Point's Jaromír Hořejší analyses StopAndProtect, a new operation combining file encryption with data theft. The attackers abuse thousands of hacked WordPress sites as their infrastructure to spread malware, control victim machines & store stolen data https://t.co/rOPgMyZ9tr https://t.co/JggHoaHPM2
事件勒索wordpress
@virusbtn
原文 ↗
推荐15
CVE-2026-42980:Windows 内核 WMI 整数下溢本地提权漏洞,PoC 已公开。
Windows 本地提权,PoC 公开,需评估补丁优先级。
RT @Master_HanChan: CVE-2026-42980
Windows 内核 WMI 整数下溢本地提权漏洞,低权限攻击者可利用该漏洞将自身权限提升至 SYSTEM,进而完全控制受影响主机。
(切记,运行第二次poc存在蓝屏概率)
https://t.co/2C5ORwSeMD https://t.co/WGKa8USQvD
lpecvepocwindows
@404death
原文 ↗
用 LLM 逆向恶意软件时,让其编写辅助脚本来验证结果。
提升 LLM 逆向效率与准确性,实用技巧。
RT @d4rksystem: When RE’ing #malware with LLMs, have the LLM also write helper scripts (string/payload decrypters and config extractors) and run these manually on the malware binaries. These make it much easier to validate the LLM's RE quickly and can help expose hallucinations.
Mirage2FA 针对美国企业 M365 账户发起 AiTM 钓鱼攻击。
AiTM 钓鱼绕过 2FA,企业邮箱安全需关注。
RT @anyrun_app: 🚨 Mirage2FA is targeting US corporate M365 accounts with AiTM phishing attacks.
With over 4K potentially compromised victims, it hits Tech and Manufacturing hardest.
Here's what your SOC team needs to know to protect your organization 👇
https://t.co/Vvkeo73fu2
威胁行为者 theHatman 出售据称从 Microsoft Entra 租户窃取的数据。
云身份数据泄露风险,需加强凭据攻击防护。
RT @Unit42_Intel: Threat actor theHatman is selling corporate data allegedly exfiltrated from Microsoft Entra tenants. Unit 42 hasn't verified the specific intrusion vector, but we advise using mitigations appropriate to credential attacks, as outlined here: https://t.co/b8ctXwXs7V https://t.co/XTQw9prYjQ
WordlistLoader 加载器通过 ClearFake 活动分发 Amatera Stealer。
新型加载器与窃密木马分析,更新检测规则。
Gen Threat Labs researchers describe WordlistLoader, a new loader used to deliver Amatera Stealer via ClearFake campaigns. They also highlight the changes Amatera has introduced between v 4.0.2 Beta (documented by eSentire) and current version 4.3.3-alpha1 https://t.co/wWif1wf1uD https://t.co/hM7IZCAKgO
COM 代理 DLL 注入技术,利用 dllhost.exe 运行 DLL。
Windows 代码注入新技巧,可绕过部分 EDR。
Today I remembered and added the COM based DLL Surrogate Injection in one of the academy courses.
Windows automatically runs your DLL with the dllhost.exe process. No VirtualAllocEx, no WriteProcessMemory, no CreateRemoteThread
Author @z3ro2504
https://t.co/i1hNNagtOf https://t.co/MgfhxuhhOS
免杀windows注入
@Salsa12__
原文 ↗
简化 AD 数据库分析,取证与渗透测试实用工具。
Reading an offline ntds.dit with one binary https://t.co/GY0QtrRtrB
工具windows取证
@ipurple
原文 ↗
OdinEye 公开测试版:一行命令启动,浏览器实时可视化扫描。
快速判断电脑是否被入侵的实用工具。
RT @_batsec_: I’m excited to announce that OdinEye is now in public beta! Thanks to everyone who has tested it out so far.
I’m building OdinEye with one mission, to provide a definitive answer to the question "Is this computer compromised?"
Launch it from a one-liner and visualise the scan in real-time in your browser. No install, no setup.
Join the beta at https://t.co/mOwoTehvPy
代理 DLL 实现:将函数调用转发给正版 DLL,同时运行 shellcode。
Windows DLL 劫持技术详解,可用于红队和防御。
RT @MalwareBibleJP: アプリからの関数呼び出しを1つ残らず正規DLLへ受け渡し、動作を壊さないまま裏でシェルコードを走らせる「プロキシDLL」の実装解説。
SafeDllSearchModeが有効でも実行ファイル自身の置き場所はDLL検索順序の最上位に残るため、KnownDllsに登録されていないDLLが相対パスや暗黙の依存関係で読み込まれる場合に成立します。
題材はメディアプレーヤーVLCが読み込むlibvlc[.]dllで、dumpbinで数えた316本の公開関数を同じ名前と同じ序数で宣言し直し、転送先を改名済みの正規DLLに指定するdefファイルを作る手順です。シェルコードは別スレッドから自分のプロセスへ注入。
2つのEDR環境それぞれでVLCから接続が返ったとする実演も含まれ、攻撃側が踏み台を選ぶ基準と探索の道筋がそのまま書かれているため、自環境のどの正規アプリが同じ条件に当てはまるかを洗い出す材料にも。
【要点の整理】
・手口自体は既知で、探索は、対象の実行ファイルだけを別のディレクトリへコピーして起動し、ProcMonのフィルタをプロセス名、結果がNAME NOT FOUND、パスの末尾が[.]dllの3条件に絞って、読み込みに失敗したDLLを拾う手順。最初に呼ばれる関数はx64dbgで全公開関数にブレークポイントを置いて特定し、引数の型と個数はIDAの逆コンパイルで確認
・転送はdefファイルで宣言し、正規DLLと同じ関数名と同じ序数を保ったまま改名済みの正規DLLへ向ける構成。1本でも欠けるとVLCが異常終了するか読み込みに失敗するため公開関数を1本残らず用意する必要があり、リンカーによる転送指定が使いにくいRustでは転送処理をコード側に記述
・転送先となる正規DLLの改名先が本文内で一致せず、途中の説明ではlibvlccore[.]dll、defファイルと最終手順ではlibnetcore[.]dllという食い違い。最終手順では代替DLL側もlibvnc[.]dllと書かれ、VLCとlibvlc[.]dllを題材に選んだ理由も2度の予告のまま本文には見当たらないという不備
・検証は、2つのEDR環境それぞれでVLCから接続が返ったとする著者の実演まで。後半の環境ではBOFでドライバーの稼働も確かめたとの記述があり、製品名、版、設定、再現条件と、防御側に向けた検知や緩和についての記述はなし
316本という数は、記事が扱ったlibvlc[.]dllをdumpbinで数えた値で、手順も構成もこの1例に沿っています。結びに挙げられているのは、標準搭載のWindowsバイナリは監視が厚く、実行ファイルをどこに置くかがDLL検索順序とログ上の見え方の両方に効くことの2点です。
詳細は以下を参照:
https://t.co/HhXkKJHQqU
(※可能な範囲でファクトチェックは実施済なものの、元記事の精度依存や速報・要約の性質上漏れもありうるため、正確な情報は一次情報を直接参照のこと)
免杀windowsdll
@0xocdsec
原文 ↗
WFP 滥用 PoC 工具,可直接测试。
Link to the tool: https://t.co/0OGOMlgPIC
通过计划任务注册以 SYSTEM 权限执行进程的 PoC。
Windows 提权新方法,PoC 公开。
RT @daem0nc0re: Added a PoC to execute SYSTEM process with scheduled task registration method.
Not so different from the PoC using service registration method I posted while ago.
https://t.co/z8fRoBcJJN https://t.co/RLTICktbfA
lpepocwindows
@J3rge
原文 ↗
Linux 内核 CVE-2026-74279 严重漏洞(CVSS 10),需立即修补。
Linux 内核高危漏洞,影响面广,需紧急处理。
RT @SecAlertsCo: 🐛 Linux kernel CVE-2026-74279 is critical (CVSS 10): Cavium CPT crypto driver uses wrong loop index (list[i] vs list[j]) in DMA cleanup, corrupting the sg_cleanup error path. Patch your kernel now. #cybersecurity #ciso #linux #vulnerabilities https://t.co/GBjCmISta0 https://t.co/fMPo3stORj
cvelinux内核
@0xocdsec
原文 ↗
Nginx PoolSlip 和 QuicBurst 漏洞的 Docker 一键利用环境已开源。
Nginx 远程漏洞利用,PoC 公开,需评估影响。
RT @nebusecurity: We’ve open-sourced one-click Docker setups and full exploits for Nginx-{PoolSlip, QuicBurst}, both with remote ASLR bypasses.
Try them here:
https://t.co/qx0TiXc9jk
PoolSlip's OOB write leaks ASLR data extremely fast, while QuicBurst's UAF takes longer.
cvepocrcenginx
@0xocdsec
原文 ↗
Qwen3.8 27B 无审查版本可在 Mac 上本地运行。
本地运行无审查 AI 模型,与本地 AI Agent 安全相关。
RT @LuminaBench: 🚨Qwen3.8 27B can now be run completely uncensored
It will apparently comply with harmful, unethical, offensive or even illegal requests the normal model would refuse
It has “no meaningful built in guardrails” and will run completely locally on a Mac
Crazy that this is allowed https://t.co/eNR5gG6vYH
llmai_agent工具
@0xocdsec
原文 ↗
jspacket:用 TypeScript 重新实现 Impacket,跨平台运行。
Impacket 的 JS 版本,扩展了使用场景。
RT @duty_1g: 🚀 Introducing jspacket — Impacket reimplemented in TypeScript & JavaScript.
Built to run across Node.js, Bun, Linux, macOS, Windows, WSL, Docker & CI.
If you know Impacket, you already know jspacket⚡
🔗 https://t.co/h92Ze0SPLt
#JavaScript #TypeScript #Bun #CyberSecurity #OpenSource #Impacket #RedTeam #RedTeaming #Pentest #PenetrationTesting
更多49
OpenAI 暂停前沿 RL 训练,以确保对齐和安全标准。
AI 安全重大信号,影响前沿模型发展节奏。
RT @sama: We have paused some frontier RL training to ensure that we can meet the appropriate alignment, security and monitoring standards for the new level of capabilities in front of us. Model progress is now extremely rapid, and we always said we would take action if we felt that model capabilities were outstripping the pace of safety and alignment.
We care very deeply about AI safety. We believe the entire field will have to coordinate on shared safety standards, but will act unilaterally in the meantime.
We expect confidence in safety to increasingly set the pace of AI progress. We are optimistic about the alignment work we are doing, and we remain committed to making frontier capabilities widely available.
https://t.co/51kvKfbfrO
ai_agentllm安全
@FuzzySec
原文 ↗
澄清常见安全误解,提升基础防护意识。
RT @struppigel: Blog: "Bad advice and myths around malware prevention"
If you ever heard or said "visiting websites can't infect you", "PDFs aren't malicious" or "exploits are rare and always targeted" this article might be for you.
https://t.co/LYpRaaEsSG
#GDATATechBlog #GDATA
微软分析 MacSync Stealer 基础设施变化后的行为特征。
macOS 窃密木马行为分析,有助于威胁狩猎。
Microsoft researchers reviewed endpoint and network telemetry to determine which MacSync Stealer behaviours persisted as infrastructure changed. https://t.co/MngCo4sc2T https://t.co/wYYEfFmWzA
恶意软件macos事件
@virusbtn
原文 ↗
使用 QUIC 协议构建加密 C2 植入体的入门指南。
QUIC 用于 C2 通信的新思路,红队可参考。
Building an Encrypted C2 Implant Using QUIC by @G3tSyst3m
This is an good read if you want an introduction to QUIC protocol for implants.
https://t.co/YonQfigH1b https://t.co/KIq9KuZKt6
安全圈幽默,缓解压力,无实际技术价值。
Top-tier way to defend against cyber attacks lol 😂
逆向苹果 Find My 定位功能,在 Linux 上解密实时位置。
苹果定位协议逆向,隐私与安全研究价值。
RT @gegrgtezrze: Reverse-engineering Apple's Find My People to stalk ̶ ̶m̶y̶ ̶e̶x̶ a friend (@Lymdun_Sama), cause I can.
Featuring: pretending Linux is an Apple device, talking to IDS/APNs, recovering encryption keys, and decrypting live locations without a Mac.
https://t.co/mjUohHg4qt https://t.co/8KFmZq1njO
Windows 注册表在指针低位隐藏页面行为标志,未公开文档。
Windows 内核未公开机制,对安全研究有启发。
The Windows registry hive stores page behavior flags in the four least significant bits of a pointer. Microsoft never documented them. A researcher found them by reading function names in old Windows 10 builds that were not inlined. HvpMapEntryIsDiscardable. HvpMapEntryIsTrimmed. The registry is managing itself with flags hidden inside memory addresses.
windows内核研究
@0xpwnie
原文 ↗
ETW TI 事件不包含用户态栈帧,安全产品难以识别调用者。
EDR 检测盲区,对红队和蓝队都有价值。
TIL that ETW TI events for APC insertion and thread context modification don't include user-mode frames in their stack traces.
In other words, it might be non-trivial for security products to identify the caller of these system calls. https://t.co/ZjhPCYLz3t
windows检测edr
@_winterknife_
原文 ↗
Windows I/O Ring 利用技术被修复,相关讨论。
了解 Windows 利用技术演进,对漏洞研究有参考。
RT @chompie1337: RIP to the Windows I/O Ring exploit technique, one of my favorites 😔 . Be sure to check out Yarden’s stream!
windows漏洞利用
@0xpwnie
原文 ↗
康卡斯特将数百万路由器变成运动传感器,WiFi 信号可识别身份。
WiFi 感知技术隐私风险,影响面广。
RT @cgrahamseven: Comcast Turns Millions Of Routers Into Motion Sensors - The Same WiFi Signals Can ID You With 99.5% Accuracy
https://t.co/sfy8RNcaPf
隐私iot事件
@0xTriboulet
原文 ↗
调查:指向中国公安部官网的仿冒域名,实为合法网站。
域名仿冒与基础设施调查案例,有 OSINT 参考价值。
"What does it all mean !?"-Well, we never said there would be a conclusion at the end. But it is quite curious why a pair of domains, that look more like a low hanging fruit attempt to misdirect hapless users to a "mimicry" page for fishing, actually point to an official MPS website. While the connected elements have an echo of "C2". Was this all remnants of a legit cyber crime operation, that was busted by the Chinese cyber police and they just repurposed the existing infrastructure to "defang" it ( taking it down might have been not an option as the servers were outside of the PRC ) ? Maybe. It is just always interesting what you are running into when chasing Chinese cyber operations. Thanks again to @tuitesteban for the help. 7/7
osint事件域名
@NetAskari
原文 ↗
调查:德国 IP 关联多个疑似 C2 域名,但声誉良好。
OSINT 调查案例,展示如何分析可疑基础设施。
The other one, 152.53... which is based in Germany, has an eclectic collection of domains associated that scream "C2" to us. Although most domains come back generally with a clean reputation, according to https://t.co/Cd3Anwi2oN. At the moment there seems only a PostgreSQL service running. It had an AList service running, a popular Chinese web storage solutions. 6/7
osint事件c2
@NetAskari
原文 ↗
钓鱼网站分析案例,提高警惕。
Strange finds on the internet: https://t.co/LTOUIQHyQV, leads to a US based host ( IONOS ). First we thought it is a fishing page ( typo and all ).
The page looks like a legit information page of the Ministry of Public Security in China. 1/7 https://t.co/fIcYvFrUdl
钓鱼osint事件
@NetAskari
原文 ↗
Google Docs 被武器化用于攻击,研究人员追踪分析。
云文档服务被滥用的新案例,需关注。
RT @gleeda: This was interesting. I hadn't seen Google Docs weaponized like that before.
@_rdowd @JSemonSecurity and @threatresearch spent some time hunting everything down and it turned out a little more interesting than I previously thought.
We never got that linux lure though 🤣
https://t.co/RWmk4yDrJ4
POC 2026 演讲:国家行为体如何突破 Coruna 的 PPL 和 SPTM 防护。
了解高级攻击技术,对 Windows 安全研究有参考。
RT @POC_Crew: 🔥 Next speaker of #POC2026
Alfie CG(@alfiecg_dev) - “How a Nation State Broke the Last Line of Defence: Inside Coruna’s PPL & SPTM bypasses”
※ Our CFP is still open until September 30. https://t.co/xwHmBziXr1
议题windows攻击
@0xocdsec
原文 ↗
Windows 预览版引入“由外而内保护”和对象防篡改机制。
Windows 安全新特性,值得深入研究。
RT @33y0re: "Outside-in-protection" in the latest insider preview. Objects have "anti-tamper" associated w/ them. Even new IFEO to read from for various policies (and setting them in a variety of ways - e.g., process, thread, and token policies)
Would be fun for someone to dig into! https://t.co/EV2jzlWYmc
windows安全新特性
@0xfluxsec
原文 ↗
博客:关于 macOS 主目录 TCC 保护及 CVE-2024-44219 的分析。
macOS TCC 绕过研究,对苹果安全有参考。
RT @_rdowd: I finally got around to blogging about this, and a separate bug (CVE-2024-44219). If you're interested in homedir TCC protections, enforcement via `sandboxd` or the sandbox kernel extension, I'd be pleased if you took a quick look!
https://t.co/Jc9iMNCQW3
macoscve权限
@0xocdsec
原文 ↗
基带安全研究,影响移动设备安全。
Insecurity of Cellular Basebands (Usenix paper)
https://t.co/OTqXJUAIwG
Authors: Henri Carnot and Aurélien Francillon
#infosec https://t.co/IfBDpWitg5
dreadnode 研究:Inkling 模型在基准测试中可能作弊。
AI 模型评估与作弊检测,对 AI 安全有参考。
We’ve got an inkling that Inkling loves to cheat.
🔗: https://t.co/ztykPeAoLS https://t.co/tQ6i9SzBoJ
llmai_agent研究
@dreadnode
原文 ↗
LED 灯泄露数据的技术早在 2002 年就有研究,2017 年有 PoC。
侧信道数据泄露历史回顾,有研究价值。
People forget how old this tech is
PoC in 2017 useable against router and hard drives
https://t.co/j4u0LPNQ5k
But it goes back to at least 2002
https://t.co/8N6XZFcWwM
PDF
https://t.co/eJvF2KQaXb
I got to work with these exfil methods in 2012 to 2014 with varied success
侧信道研究硬件
@Laughing_Mantis
原文 ↗
DutchOven PoC 分析:利用 WFP 临时阻止应用出站连接。
WFP 滥用技巧,红队可参考,蓝队需检测。
Some thoughts about the DutchOven proof of concept that was released:
🟣 Uses the Windows Filtering Platform (WFP)
🟣 Creates rules that temporarily prevent a chosen application from making new outbound connections, then removes those rules after a defined interval
🟣 Existing connections are not affected
🟣 Uses a dynamic WFP session
🔁 𝑩𝒆𝒉𝒂𝒗𝒊𝒐𝒖𝒓 𝑷𝒂𝒕𝒕𝒆𝒓𝒏
🎯 Rule Added ➡️ Connection Blocked ➡️ Rule Removed
🔵 𝑫𝒆𝒕𝒆𝒄𝒕𝒊𝒐𝒏 𝑺𝒕𝒓𝒂𝒕𝒆𝒈𝒚
✅ Event ID 5447 | Runtime WFP filter added/removed
✅ Event ID 5450 | Runtime WFP sub-layer added/removed
✅ Event ID 5157 | WFP blocked an outbound connection
工具windows检测
@ipurple
原文 ↗
Shadow HVNC 和 Loader 分析:保护许可证比保护客户更好。
恶意软件分析,揭示商业恶意软件的质量问题。
RT @PandaRE__: 🐼 New research: Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers
The seller calls it the best HVNC on the market. In reality its 6k domain banking watcher has never received a single event, the Yandex cookie decryptor pulled 0 of 137 cookies, and the "no plaintext in the binary" claim falls apart ...
While hunting panels I also ran into a TA using the loader, cranking out SSA and fake DMCA lures with AI for 7 different countries and mailing them to Facebook Page admins 🙄
Happy Hunting and give @MalbearLabs a follow! ❤️
Blog: https://t.co/QHSVhNQgYm
Recorded Future 发布 PurpleDelta 欺诈性雇佣活动报告。
针对 IT 工作者的定向攻击活动分析。
RT @lazarusholic: "PurpleDelta’s Fraudulent Employment Operations" published by @RecordedFuture. #ITWorker, #PurpleDelta https://t.co/yMq6aGYX0J
REcon 2026 研讨会资料:Binary Ninja 中的 C++ 符号和类型恢复。
逆向工程学习资源,提升恶意软件分析能力。
RT @InvokeReversing: We've uploaded the materials from our 3 hour workshop presented at REcon 2026 titled "C++ Symbol and Type Recovery in Binary Ninja", you can find them here: https://t.co/pdXc8D2Enm
If you're interested in learning advanced malware analysis techniques, check out our new Advanced Malware Binary Triage course here: https://t.co/2IFm3U2TUO
安全会议信息,可关注相关议题。
RT @UnpromptedAU: Ok! The schedule is live as! Check it out: https://t.co/rDjUnM0X86
Xbow 网络研讨会:如何在不牺牲能力的情况下约束自主智能体。
AI Agent 安全与约束,与首要意图相关。
RT @Xbow: Want to know how to keep autonomous agents within bounds without sacrificing what makes them powerful?
@thewunderalbert is hosting a webinar on just that: Thursday, August 20, 2026 at 10am PT / 1pm ET.
https://t.co/MwopnLAecN https://t.co/zrIYBQ59Cx
开源模型安全边界讨论,与 AI Agent 安全相关。
RT @BrianRoemmele: Some people fear this new open source AI model. I have already run over 3000 tests on it. The fear is it is “dangerous”. No more dangerous than what anyone can find in seconds on the dark web. In fact most of the terrible stuff is not in any AI model no matter who made it.
This AI model will refuse no prompt at all and it is incredibly interesting how it massively improves the entire model.
Those who have never truly tested this stuff will clutch their pearls.
Crazy folks has easy access to the dark web for decades. Look around the “worse” never happened. It never does. https://t.co/0cKd9aIXUE
llmai_agent安全
@0xTriboulet
原文 ↗
美国起诉 17 名伊朗黑客,窃取 31TB 大学研究数据。
大规模网络窃密事件,涉及学术机构。
Hackers Stole 31 Terabytes of University Research
The U.S. government has charged 17 alleged Iranian hackers over a massive cyber-theft campaign targeting universities, companies and government agencies.
According to the Justice Department, the group targeted more than 100,000 professors’ accounts and successfully compromised approximately 8,000 of them.
They allegedly stole at least 31.5 terabytes of research, academic data and intellectual property.
Some students are struggling to access one research paper. These hackers reportedly downloaded the entire university. 😭
The attack relied heavily on spear-phishing and stolen credentials. That is the scary part: an operation connected to a foreign government did not always require sophisticated zero-days. Sometimes, one convincing login page was enough.
事件apt数据泄露
@Officialwhyte22
原文 ↗
笔记本电脑在睡眠状态下仍每 5 分钟向外连接,疑似恶意软件。
恶意软件排查案例,有参考价值。
The laptop was supposed to be asleep.
But at 3:07 AM, it was still making outbound connections to the internet every five minutes.
The user had already gone to bed, so there was no reason for the machine to be doing anything serious at that time.
At first, I thought it could just be Windows doing normal background activity.
Windows Update, OneDrive, Defender, plenty of legitimate services can make network connections when nobody is using the system.
But the timing was too consistent.
Every five minutes.
So I checked which process owned the connection.
That was when I found:
OneDriveSyncHelper.exe
Again, the name looked normal.
The problem was the location:
C:\Users\marcus\AppData\Roaming\Microsoft\Sync\OneDriveSyncHelper.exe
That was not the normal location for Microsoft OneDrive.
I checked the digital signature.
The file was not signed.
Now it was getting interesting.
The process had an active HTTPS connection to an external IP address, so I checked how it was starting.
Inside Task Scheduler, I found a task called:
OneDrive Sync Maintenance
The task was configured to launch the same unsigned executable from the user’s AppData folder.
And the repetition interval?
Every five minutes.
That explained the network traffic.
The attacker had deliberately used Microsoft-looking names so that anyone checking the system quickly might assume everything was legitimate.
OneDriveSyncHelper.exe
OneDrive Sync Maintenance
Even the folder was called:
Microsoft\Sync
Everything was made to look normal.
When we spoke to the user, he remembered downloading a document converter the previous afternoon because somebody had sent him a file he could not open.
The installer appeared to work, so he never thought anything was wrong.
But shortly after it ran, the scheduled task was created.
From that point, the suspicious binary kept starting quietly in the background and calling out every five minutes.
We isolated the laptop, collected the executable and scheduled-task configuration for analysis, revoked the user’s active sessions, reset the affected credentials and rebuilt the endpoint.
What exposed the compromise was not ransomware.
It was not a strange message on the screen.
It was one laptop communicating when nobody was supposed to be using it.
In incident response, sometimes the smallest behaviour is the thing that tells you the whole story.
事件恶意软件排查
@Officialwhyte22
原文 ↗
研究发现可用约 1 秒的 x86 指令让一个核心逃出 SMM。
SMM 安全机制被突破,固件安全重大发现。
SMM is supposed to stop every core.
@xoreaxeaxeax found a way to keep one core outside SMM with a ~1-second x86 instruction, breaking the rendezvous assumption.
Sandsifter. Rosenbridge. Movfuscator. Now this.
Firmware people, this is ridiculous.
#x86 #Firmware #Infosec https://t.co/Nia5jJc3HQ
x33fcon 2026 演讲:Detonator - 可重复的恶意软件技术测试。
恶意软件测试方法论,有参考价值。
RT @x33fcon: #x33fcon 2026 talks: Dobin Rutishauser - Detonator - Repeatable Malware Techniques Testing > https://t.co/DvvNFnEpz3 https://t.co/8PjqdiPuvF
Linux 内核安全配置提醒,与容器安全相关。
RT @spendergrsec: Just want to highlight this for anyone enabling unprivileged user namespaces: https://t.co/Y4Ph3jIi3l
Windows 事件日志信息泄露,对漏洞利用有帮助。
RT @yarden_shafir: When I showed that event logs are full of leaked kernel pointers, available for anyone who can find them, I said that there are many other useful things hiding there.
But I didn't know it was this bad.
Amazing find @MGrafnetter!
windows信息泄露研究
@Laughing_Mantis
原文 ↗
Mimikatz LSASS 转储被拦截 94%,但 LSA Secrets 提取仅被拦截 3%。
防御测试报告,揭示攻击行为测试的重要性。
RT @BleepinComputer: 🛡️ Mimikatz LSASS dumping was blocked 94% of the time, but LSA Secrets extraction just 3%.
🔍 @PicusSecurity's Blue Report 2026 explains why defenses must be tested against attack behavior, not just known attack methods.
➡️ https://t.co/8op2KIfN1W
#cybersecurity #sponsored
报告检测windows
@0xocdsec
原文 ↗
HotCRP 存在 9 年漏洞,可暴露审稿人身份。
学术会议系统漏洞,影响审稿匿名性。
RT @FrankOverF1ow: Nebula Security found CVE-2026-55493 in HotCRP, a 9-year-old vuln that could expose reviewers' identities.
At minimum, it could reveal exactly who accepted or rejected your paper
We also found CVE-2026-63491. Both were responsibly disclosed to Kohler. Thanks to his quick fix!
研究人员诱导 Copilot 泄露自身漏洞利用细节,可一键攻击。
AI 助手安全漏洞,与 AI Agent 安全直接相关。
RT @HedgieMarkets: 🦔Security researchers tricked Microsoft's Copilot into revealing how to hack itself. They asked why a certain attack wouldn't work, and Copilot handed them the exact details to make it work, including a hidden parameter Microsoft had disabled. They built a one-click attack that could steal emails, files, and chat history. This is the third time the same researchers found this class of flaw in Copilot in under a year.
My Take
The AI couldn't tell the difference between a security researcher probing for weaknesses and a user asking for help, and no patch fixes that because the AI has no concept of intent. It treats every instruction as legitimate. Microsoft patches one version and the same researchers find another a few months later, because the underlying problem isn't a bug you can squash. Companies are connecting these tools to sensitive corporate systems anyway because they're terrified of being the one that didn't adopt AI fast enough.
Everyone focuses on the Nvidia guarantees and the private credit stress because the dollar amounts are huge. But millions of companies are handing AI tools the keys to their data before anyone has figured out how to stop the tool from being turned against the user. Microsoft has more security talent than almost anyone and they've failed this test three times. Most companies adopting AI have a fraction of those resources and haven't even thought about it.
Hedgie🤗
https://t.co/7y1nfliO2W
ai_agentllm漏洞
@0xocdsec
原文 ↗
Black Hat 简报:重建 Fast16 框架以基准测试 AI 恶意软件分析。
AI 在恶意软件分析中的应用与评估。
RT @LabsSentinel: An undocumented nation-state framework built decades ago still holds vital lessons for modern security research. @vkamluk presents the reconstruction of Fast16 to benchmark how AI malware analysis operates when prior training data is completely absent.
Watch the full Black Hat briefing. https://t.co/y3UNaUy4Hb
CVE-2023-2156 绕过实现提权和容器逃逸,奖金 $10,500。
Linux 内核漏洞利用链,容器安全需关注。
RT @nebusecurity: CVE-2023-2156 was believed to be just a remote kernel DoS, patched in 2023.
We found a bypass and achieve privilege escalation and container escape.
Read the $10,500 story of CVE-2026-43501 "Route of Root":
https://t.co/SnveNORatM
cve提权逃逸linux
@0xocdsec
原文 ↗
Bitdefender 分析:伪装成 Roblox 和 Discord 执行器的恶意软件。
针对游戏社区的恶意软件分析。
RT @Bitdancer: I highly recommend reading this article: https://t.co/G7K28vEwu0
恶意软件事件分析
@GuidedHacking
原文 ↗
CyberKimi v1 在漏洞复现基准测试中得分 0.860,超越其他模型。
网络安全专用 AI 模型性能评估。
RT @lordx64: It feels good to be at the top of the world, in AI research crafting AI models fine-tuned for Cyber Security, CyberKimi did it again!
We ran CyberKimi v1 on CyberGym, real vulnerability-reproduction tasks from OSS-Fuzz/Arvo: read the code, craft the input, crash the target, graded by the benchmark's own submission server.
On a stratified 100-task subset, CyberKimi scores 0.860 — above GLM-5.3 (0.845), DeepSeek-V4-Pro (0.833), Gemini 3.5 Flash Cyber (0.832), Claude Mythos (0.831) and GPT-5.5 (0.818) and more than double the stock Kimi K2.5 base model (0.413). Every solve is a server-verified crash, not a self-report.
Full transcripts and grader records available on demand for independent verification: [email protected]
Join the waitlist to access CyberKimi here: https://t.co/JZwxopj4dp
llmai_agent研究
@0xocdsec
原文 ↗
非管理员用户可通过播放 MIDI 文件在 Windows 11 上获得 SYSTEM 权限。
Windows 本地提权新思路,PoC 将公开。
RT @wdormann: I will be presenting at THREATCON1 in October, explaining how I figured out how a non-admin user could get code execution as SYSTEM on Windows 11 by way of playing a MIDI file. 😂
https://t.co/JuzQSIyTcY https://t.co/5NQKRqqCs6
lpewindowspoc
@0xocdsec
原文 ↗
Firefox for iOS 推出原生广告拦截器。
移动端隐私功能更新,与安全相关。
RT @privacytoolsIO: Firefox for iOS just shipped a native ad blocker.
No extensions. No Safari content blocker setup. One switch.
Settings > Browsing > Content > Ad Blocker
EasyList-based, blocks before load, takes out pop-ups and overlays. Rolling out gradually so be patient if you don't see it yet.
iPhone and iPad: https://t.co/18tBy1QBYR
分享几个 Go 语言编写的安全相关工具:内存加载器、Crystal Palace 移植等。
开源安全工具,有参考和试用价值。
RT @LittleJoeTables: Random vibe coded things others may find useful:
Pure Go cross-platform in-memory shared library loader: https://t.co/twDrSJDbGi
Golang port of Crystal Palace:
https://t.co/9LjakIhRMI
Re-impl of C&C Generals: Zero Hour online multiplayer backend & game:
https://t.co/OSEskvZMy1
Microsoft SCCM 漏洞 PoC 已发布,可实现 SYSTEM 级代码执行。
SCCM 提权漏洞,PoC 公开,企业需评估。
RT @moton: PoC Exploit Released for Microsoft SCCM Vulnerability Enabling SYSTEM-Level Code Execution - https://t.co/TQDA44fqKY
cvepocwindows提权
@0xocdsec
原文 ↗
观点:攻击者不需要 AI 就能大规模利用漏洞,但 AI 可能加剧问题。
关于 AI 与网络攻击关系的讨论,有参考价值。
RT @HackingLZ: All of this is largely tied to the idea that bad guys need AI to hack at scale, but that simply wasn’t true before LLMs became useful in this space. Mass exploitation of edge devices and software, followed by deploying backdoors and other payloads, was already heavily scripted and extremely successful.
The area people should probably have been most concerned about all along is what happens if the supply of exploitable edge device bugs reaches 2x, 5x, or 10x what we’ve seen over the last several years. Many of those companies are part of Glasswing and/or are already receiving vulnerability and bounty submissions on a regular basis.
A lot of the ransomware incidents that make the news also aren’t particularly sophisticated, and having or not having an LLM hasn’t been a measurable game changer. A couple of years ago, given the state of the discussion, you would have expected people to be talking by now about some huge multiple increase in ransomware incidents because of AI. That simply hasn’t happened.
议题ai_agent攻击
@Teach2Breach
原文 ↗
用户仅更新 Chrome 后 MacBook 变慢,发现可疑进程 ChromeUpdater。
macOS 恶意软件排查案例,有参考价值。
RT @Officialwhyte22: The user said he only updated Google Chrome.
At first, there was nothing serious to suggest malware. The MacBook was just running slower than normal, and the fan kept coming on even when he was not doing much.
No antivirus alert. No strange pop-up. No obvious sign that the system had been compromised.
When I checked the running processes, I noticed one called ChromeUpdater.
The name itself did not look suspicious because software updaters run in the background all the time.
What caught my attention was the location:
/Users/daniel/Library/Application Support/ChromeUpdater/ChromeUpdater
That did not look like where a legitimate Google Chrome updater should be running from.
So I checked the process properly.
It had an active connection to an external IP over port 443.
I then checked the LaunchAgents on the Mac and found this file:
com(.)google.keystone.agent.plist
If you are familiar with macOS, that name can easily pass as something related to Google.
But when I opened the plist, it was pointing straight back to the same suspicious ChromeUpdater binary inside the user’s Library folder.
That meant the malware had persistence.
Any time the user logged into the Mac, the LaunchAgent could start the binary again automatically.
When I asked him what he did before the problem started, he remembered visiting a website that told him his Chrome browser was outdated.
The site asked him to download an update.
He downloaded it, opened it and entered his password when macOS prompted him.
That was most likely where the compromise started.
The fake updater dropped the binary into his Library folder and created the LaunchAgent so it could continue running after login.
What made this interesting was how normal everything looked.
ChromeUpdater
com(.)google.keystone.agent.plist
HTTPS traffic on port 443.
If you are checking the machine in a hurry, you can easily overlook all three.
We isolated the MacBook, preserved the suspicious files for analysis, removed the persistence, reset the affected credentials and rebuilt the system.
The malware stayed there for four days, not because it was extremely advanced, but because it did a good job of looking like something that belonged on the machine.
Sometimes that is all malware needs.
事件恶意软件macos
@Officialwhyte22
原文 ↗
Redis CVE-2026-23479 深入分析,技术细节。
Redis 漏洞分析,影响自托管服务。
RT @tjbecker: Hmm... this technique sounds familiar 👀
https://t.co/h5BTIi52Nm https://t.co/g3WoHKUeH7
cverceredis
@0xocdsec
原文 ↗
Dolby 解码器 RCE 是 Pixel 9 0-click-to-root 漏洞链的第一步。
移动端 0-click 攻击链分析,影响面广。
RT @cr3ghost: Incoming audio messages can become a 0-click attack surface before you ever open them.
Natalie Silvanovich (@natashenka) breaks down the Dolby decoder RCE used as step 1 of Project Zero's Pixel 9 0-click-to-root chain.
https://t.co/QzVc7XKJCS https://t.co/0NdMR6nTJz
Python 包管理安全增强,供应链安全相关。
Vulnerability and malware checks in uv - William Woodruff
https://t.co/TsViBXG4vL
供应链工具python
@pentest_swissky
原文 ↗