推荐15
Virtualizor 平台遭供应链攻击,影响大量 VPS 提供商。
VPS 管理平台被攻陷,影响面广,需评估自身基础设施风险。
RT @nextronresearch: Update on the #Virtualizor compromise.
If you've never heard of Virtualizor before: it's a VPS management platform used by many hosting providers to deploy and manage virtual servers on KVM, Xen, LXC, OpenVZ, Proxmox and other virtualization platforms.
It is not some tiny admin panel either. Virtualizor publicly lists hundreds of NOC partners worldwide, and according to its own documentation a single master server can manage hundreds of virtualization nodes.
So this sits pretty high up in the infrastructure.
The vendor has now confirmed what happened:
Attackers hijacked the BGP route for Virtualizor/Softaculous infrastructure, obtained a valid Let's Encrypt certificate and used that position to serve a malicious Virtualizor update.
The ugly part: the Virtualizor update clients did not cryptographically verify the downloaded packages.
BGP hijack + valid TLS certificate was therefore enough to get attacker code executed as root on affected hypervisors.
Virtualizor says only a small number of installations are known to have received the malicious update. But they cannot tell exactly which ones, so they recommend treating every Virtualizor server as in scope and checking it.
There is currently no evidence that customer VPS guests themselves were modified. Still, once the hypervisor is compromised as root, everything running on it has to be considered at risk.
Vendor report:
https://t.co/5xRv19RdS7
Our Nextron Research team has prepared IOCs and YARA rules for the known artifacts and payload:
https://t.co/Rpfq7VMe9m
The merge is done. Our internal QA pipelines are still running; the signatures should hit the update servers and THOR Cloud Lite within the next hour.
You can use both THOR Lite and THOR Cloud Lite for free to check your systems:
https://t.co/cozCM6m7ud
https://t.co/TSPqOAEtDY
If you run Virtualizor: scan the hypervisor, not the VPS guests.
JSCeal 窃密木马以 V8 字节码分发,Check Point 发布分析。
新型恶意软件形态,使用编译 V8 字节码,绕过传统检测。
Check Point's hasherezade details JSCeal & shares the jsc_deobfuscator toolkit. JSCeal is a sophisticated cryptocurrency-focused stealer with broader credential-theft, surveillance, & traffic-interception capabilities, delivered as compiled V8 bytecode. https://t.co/vORrgYr6Im https://t.co/xGosUCXbSL
TerminalFix 活动利用 DLL 侧加载和隐写术部署后门。
新型 ClickFix 变种,攻击链复杂,微软已发布详细分析。
Microsoft researchers observed a TerminalFix campaign, a variant of ClickFix that deploys a multi-stage attack chain combining DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, & a custom reverse-tunnel implant. https://t.co/EtrVaNwM2n https://t.co/aMZmbubhoJ
BREEZE COMET 组织针对巴西发起金融攻击。
活跃金融威胁组织,谷歌发布详细 TTP 和检测建议。
Google Threat Intelligence Group & Mandiant researchers detail BREEZE COMET’s (Plump Spider/SHADOW-AETHER-064) tactics & toolkit, providing mitigation recommendations & detections to support organizations in defending against the active & developing threat https://t.co/YVfWRZikDR https://t.co/bmjKsKI2GV
Bintracer 发布,macOS 恶意软件分析沙箱。
macOS 恶意软件分析工具,可检测 Mach-O、dylib 等,值得上手。
RT @kyleavery: I just released the first public version of @BintracerLabs, a malware-analysis sandbox focused on macOS.
Bintracer can:
- Detonate Mach-O binaries, app bundles, and dylibs
- Extract DMG and PKG files
- Analyze JXA, AppleScript, Python, Perl, and shell scripts
This project is still early, but I can't wait to see what y'all think!
工具macOS恶意软件
@ipurple
原文 ↗
HDD 固件逆向、修改与 JTAG 调试教程发布。
深入固件安全研究,提供完整技术路径,适合进阶学习。
Dumping/analyzing/modifying the HDD drive firmware and debugging via JTAG
https://t.co/Ut1DIJHyp9
Credits @Grimdoomer
#infosec https://t.co/qa3rn2GDOL
基于 GLM-5.3 的越狱模型发布,专攻网络攻击。
开源越狱模型,具备更强网络攻击能力,需关注其安全影响。
RT @abliteration_ai: Today we're releasing abliterated-model-large-v2.
Based on GLM-5.3, which is #3 on Terminal-Bench 4.0 (behind only Opus 5 and Fable), with 2× the cyber exploitation of 5.2.
We abliterated and hosted it so it does the offensive cyber, red teaming, and agent testing work other models refuse to do.
- US-hosted
- FP8
- 1 million context window
- Zero input/output prompt retention
Live now. 🧵
llmai_agent工具
@0xocdsec
原文 ↗
Blackstorm Security 发布 1600+ 页免费漏洞研究资料。
高质量免费学习资源,覆盖内核、浏览器、Hyper-V 等多个领域。
RT @cr3ghost: If you're new to exploit development, reverse engineering or vulnerability research, bookmark this before buying another course.
Blackstorm Security has published 1,600+ pages of research for FREE.
Windows kernel exploitation.
Driver reversing.
Patch diffing.
Chrome / V8 / WebAssembly.
Hyper-V.
macOS / iOS internals.
Modern mitigation bypasses.
Real CVEs taken from root cause to working exploitation.
Their CVE-2024-30085 series alone spans hundreds of pages and multiple exploitation strategies.
This is the kind of material that teaches you how vulnerability researchers actually think, not just how to run tools.
19 research papers. 1,657 pages. Free.
Start here:
https://t.co/wDftgmamHH
Author: @ale_sp_brazil
Focus on the techniques not the tools (X64DBG, GHIDRA/IDA, WINDBG, GDB GEF)
#ExploitDevelopment #ReverseEngineering #VulnerabilityResearch
Qualcomm BootROM 漏洞可绕过安全启动链。
影响设备固件安全,Black Hat 演讲资料公开,值得研究。
RT @0xor0ne: Exploiting Qualcomm BootROM to bypass the secure boot chain (slide deck, BH Asia '26)
https://t.co/X0cBoWQLIA
#infosec https://t.co/7V3nU7ZgVQ
CouchPotato 工具利用 SeImpersonatePrivilege 提权。
新的 Windows 提权工具,绕过 ETW/AMSI,值得测试。
CouchPotato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege.
🔴 Service account or Admin ➡️ NT system https://t.co/G0YZXj9x39
工具提权windows
@ipurple
原文 ↗
PaperCut 两个漏洞的完整复现与变种分析发布。
CVE-2026-81578 和 CVE-2026-82078 的 PoC 和变种分析,可参考。
RT @N3mes1s: As promised the repro of the PaperCut CVE-2026-81578 + CVE-2026-82078: From False Marker to Verified RCE plus update with the variant discovered!
https://t.co/jooOGL7NBn
通过 AD CS RPC 端点从 IIS AppPool 提权到 SYSTEM。
具体的提权路径,对 Windows 环境渗透测试有参考价值。
RT @_r_netsec: Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint https://t.co/fMl9VqFnnE
提权windows议题
@0xocdsec
原文 ↗
JFrog Artifactory 认证绕过漏洞已遭在野利用。
CVE-2026-82329 已被利用,需立即排查自身系统。
RT @watchtowrcyber: watchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens.
Reach out if you need help determining your exposure ahead of exploitation. https://t.co/r6kMLl7j3N
WinFlesher 发布,自动化 AD 攻击面评估框架。
自动化评估 AD 安全,可提高渗透测试效率。
WinFlesher — Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack... https://t.co/IggtorspOK https://t.co/vNMV6CJfbc
Horizon3 确认 Switchvox 漏洞遭在野利用。
确认 CVE-2026-9586 在野利用,需立即修补。
RT @Horizon3ai: On August 30, @DefusedCyber honeypots detected valid exploitation attempts against the vulnerability.
The observed attacker used command execution, followed by additional enumeration and exfiltration activity.
cverce事件
@DefusedCyber
原文 ↗
更多76
作者分享用于 Codex 的 Windows EoP 研究利用工具链。
AI 辅助漏洞利用的工具链,展示了 AI 在安全研究中的应用。
RT @xaitax: This is what I built to get me there: my Windows EoP research-to-exploit harness, specialised for Codex and Daybreak, with RCE support in progress. Based on my own research experience and OpenAI's guidance. Skills, specialist agents, persistent state, behavioural evals, and full exploit-chain validation. It works surprisingly well. I may release it in Q4.
ai_agent工具提权
@0xocdsec
原文 ↗
针对网络设备的攻击活动,影响基础设施安全,需关注。
RT @BleepinComputer: Chinese Fire Ant hackers turn Cisco routers into spying platforms
https://t.co/uB0CyeO0P2
https://t.co/uB0CyeO0P2
AI 模型 Colombus-1 用于发现 BlueZ 蓝牙栈漏洞。
AI 辅助漏洞挖掘案例,对 AI 安全研究有启发。
RT @xchglabs: What happens when you point one of the most interesting AI models available at the Linux Bluetooth stack?
We used @autopoiesislab Colombus-1 model to help uncover vulnerabilities in BlueZ.
Full research from Xchg Labs:
https://t.co/lPvyVGQGKH
ai_agent漏洞研究蓝牙
@0xocdsec
原文 ↗
MTEscape 技术可绕过异步内核 MTE 防护。
针对 ARM MTE 安全机制的新攻击研究,影响未来内核安全。
RT @phretor: Uuuh 👀 MTEscape: Bypassing Asynchronous Kernel MTE via Conventional Memory Corruption Vulnerabilities
-> @acm_ccs 2026
具体漏洞的深入分析,对漏洞研究有参考价值。
RT @nhh9905: Time to share the detail write-up, I would love to share it. Enjoy yourself!
Link write-up: https://t.co/eZIVl2l6yh
开源项目 gods-eye-view 发布,可查看全球摄像头。
涉及大规模摄像头监控,引发隐私和安全担忧,值得关注。
RT @BrendanEich: https://t.co/ChwokczBMj is pretty cool.
Governments may get :mad: about it, don't care.
Remember Gilmore's Maxim: "The Net interprets censorship as damage and routes around it".
PicoC 小型 C 语言解释器,可作脚本或交互式 shell。
轻量级 C 解释器,可用于安全脚本或嵌入式场景。
RT @oneandonlyhusam: I don't know why this only has 600 stars on github but its one of the coolest C projects ever.
PicoC is a very small C interpreter for scripting and even allows an interactive mode so you can use C code with picoc as the shell.
https://t.co/y4OiQNb0Uc https://t.co/PQy3AE9ftE
FRP 隧道被广泛用于恶意活动,超 4 万台主机被标记。
FRP 工具被滥用,可用于 C2 通信,需关注相关检测。
RT @teamcymru_S2: INTEL DROP
FRP tunnels in our Total Insights detection pipeline. 40,708 FRP-tagged hosts right now, 2,712 of them rated malicious across 216 ASNs, concentrated in China, the US, Hong Kong, and Singapore. FRP (Fast Reverse Proxy) is an open-source reverse-proxy tunneler that crews use to pivot into networks and front their C2.
Coexisting + FRP:
138.124.53.170 proxy:frp + bph
79.137.204.191 proxy:frp + bph + kev-vulnerable
45.8.113.127 proxy:frp + malware-hosting + kev-vulnerable
51.75.31.123 proxy:frp + phishing + open-dir
128.1.211.110 proxy:frp + scanner + brute-force
47.87.80.23 proxy:frp + open-dir
45.145.229.183 proxy:frp + risknet
183.250.89.44 proxy:frp + gen-ai:new-api + gitlab
152.136.59.90 proxy:frp + iot:crestron + ipsec
104.239.66.54 proxy:frp + risknet + kev-vulnerable
213.21.254.149 proxy:frp + bph
185.221.196.112 proxy:frp + bph + kev-vulnerable
138.124.14.123 proxy:frp + bph
Some FRP nodes double as C2 on the same host:
192.210.193.156 proxy:frp + controller:vshell
111.231.59.28 proxy:frp + controller:vshell
117.72.72.254 proxy:frp + controller:supershell
#TotalInsights #ThreatIntel #FRP
https://t.co/nDqrsELahM
恶意软件伪装成 MP4 视频,实际携带 NetSupport RAT。
新型恶意软件分发手法,绕过文件类型检测,需警惕。
RT @censysio: 🎥 Looks like an MP4. Carries an encrypted NetSupport client.
Censys ARC researcher @ex_raritas uncovered an active malware payload hiding inside a fake video file.
He tracked the NetSupport RAT delivery kit across 40 live endpoints and 18 builds. https://t.co/ErafjC6IcO #CensysARC
Unit 42 分析 405 个 AI 恶意软件样本,97% 仅存在于沙箱。
对 AI 生成恶意软件的实际威胁评估,有助于理解其真实影响。
RT @Unit42_Intel: Our analysis of 405 AI malware samples shows 97% exist only in sandboxes and research repos. Existing endpoint analytics and behavioral controls stopped every sample in production. AI changes how code is authored, not how it executes. Read the article: https://t.co/kN4zUxp3ix https://t.co/pfCAdRz3wR
ai_agent恶意软件报告
@virusbtn
原文 ↗
Unit 42 监测到与 Com 相关的新建 MFA 主题钓鱼域名。
针对 MFA 的钓鱼攻击,需关注相关域名和防范措施。
RT @Unit42_Intel: Unit 42 is actively monitoring newly created network infrastructure likely associated with Com-affiliated threat actors based on known fingerprints. MFA-themed domains are likely being used to target organizations across a variety of industries. Details: https://t.co/rRcRf5csUV
行业定向攻击分析,对酒店及相关行业有参考价值。
RT @58_158_177_102: [PR] We published the English version of the threat analysis report we wrote in Japanese (three months ago.)
Analysis of Suspicious Emails Targeting the Hotel Industry
(Part 1: Campaign Overview)
https://t.co/eSKZOAoLGe
(Part 2: Technical Details)
https://t.co/mCJf4jijW7
Censys 发现暴露的 Moobot 僵尸网络源码和攻击记录。
僵尸网络源码泄露,可深入了解其运作机制。
RT @censysio: New research from Censys ARC researcher @silascutler examines an exposed server containing Moobot botnet source code, active attack records, additional DoS tooling, and a fraudulent identity verification service.
Read the full analysis of what the exposed directory revealed about Moobot and the operation behind it: https://t.co/psFIPdXwrL #CensysARC
Ethereum retesteth 存在未授权 PHP 执行漏洞。
区块链相关工具漏洞,影响面虽小但 PoC 已公开。
RT @mqst_: 404‑to‑RCE: Unauthenticated PHP Exec in Ethereum’s retesteth
Blog: https://t.co/k74iaGgvYx
Author: mavlevin https://t.co/9Lekllf7rL
ruby-advisory-db 发布,Ruby 安全公告数据库。
Ruby 生态安全公告查询,对 Ruby 开发者有用。
ruby-advisory-db — Community-maintained database of security advisories for Ruby gems and runtimes, providing structured CVE/GHSA data with... https://t.co/44guMtu7U5 https://t.co/BeRe0C5kRF
Red-Team-Infrastructure-Wiki 发布,红队基础设施加固资源。
红队基础设施加固知识库,对攻防演练有参考价值。
Red-Team-Infrastructure-Wiki — Wiki to collect Red Team infrastructure hardening resources https://t.co/gu3S9vJFg6 https://t.co/V8LAx4qNv0
BlackMagick 项目更新,新增 SectopRAT PoC 和 Rust 支持。
恶意软件技术库更新,包含新 PoC,值得研究。
https://t.co/zKV2rbGXx9 updates:
- reworked the pre-req docs. simplified build env setup
- restructured rust source code to align with standalone module capabilities. minimal 3rd party code
- added new malware pulse article and related PoC SectopRAT
- improved rust sleep tech
工具恶意软件poc
@Teach2Breach
原文 ↗
BlackMagick 项目将提供 Rust 版本技术实现。
恶意软件技术库的 Rust 版本,对跨语言研究有价值。
Every tool and technique on https://t.co/zKV2rbGXx9 is first carefully crafted in C, but then also made available in Rust. In the next update, the pre-req section will include info for setting up your dev env for rust, as well as some new techniques and PoCs from the wild. https://t.co/NtG0iMioH8
工具恶意软件rust
@Teach2Breach
原文 ↗
ProjectDiscovery 分享 Neo Agent 架构演进。
AI Agent 在安全扫描中的应用架构,对 Agent 安全有参考。
How Neo's Agent Architecture Evolved: From One Agent → Plan, Execute & Verify - Atiq Gauri
https://t.co/bi6a0Cf6x3
ai_agent工具架构
@pentest_swissky
原文 ↗
Usenix 论文揭示 SIM 卡发起 AT 命令的危险性。
移动端安全研究,揭示 SIM 卡攻击面,值得关注。
On the Dangers of SIM-Originating AT Commands (Usenix paper)
https://t.co/UkYC2HymVs
#infosec https://t.co/NtfjYgwflR
传统漏洞利用技术演示,对学习 ROP 有参考价值。
Performed a ROP chain, without using AI
https://t.co/FKnpgMGuaY
针对 Passkey 的钓鱼攻击,需关注相关域名和防范。
🔑 Suspicious Passkey-theme Domains 🚨
Effective today Microsoft Entra starts rolling out passkey as the default ... coincidentally the below passkey domains are newly created in the last 5 days based on my @silentpush Lookup 😅 Looking at these domain patterns, users of Mailchimp, SendGrid or Singapore based may be targeted. Defenders do scan your devicenetworkevent and emailurlinfo telemetry for these passkey-theme domains.🫡
#threathunting
无实质安全内容。
Woot woot https://t.co/nrPBe3GY8y
个人桌面美化,无安全内容。
Conky is finally done https://t.co/JDWWpKkcMI
个人工具集成,无直接安全价值。
Added jabber rootkit noft into the the conky so ican see information about new agents direct in conky on desktop. the teamserver sends out the jabber noft on next agents joins in ... https://t.co/ADepMO7Usp
AI 发展动态,但非直接安全信息。
RT @rileybrown: Hate to admit it… we’ve hit a wall… I’ve seen no noticeable improvements to the models in the last 6-9 hours.
AI 模型动态,无直接安全信息。
GLM 5.3 btw
无实质安全内容。
excuse me? https://t.co/vpdQUmaKRo
Virus Bulletin 2026 会议宣传。
会议信息,非安全内容。
Summer is over, but there’s still something worth looking forward to. 👀
See you in Seville this October.
📅 14–16 October 2026
📍 Seville, Spain
🎟️ Get your ticket: https://t.co/6YVE232xj9
#VB2026 #VirusBulletin #vbconference #cybersecurity https://t.co/p1DTOXMbMS
会议信息,非安全内容。
Analysed a new online threat? Involved in cutting-edge security research? The #VB2026 call for last-minute papers - dealing with 'hot' research and material that is truly up-to-the-minute - is now open, so why not submit a proposal? Deadline 13 Sept. https://t.co/kuqcPhZPTh https://t.co/cWGtl4g8J9
致敬 Alex Ionescu 的 Windows 内核研究贡献。
行业人物介绍,无直接安全信息。
Paying respect to a legend.
If you reverse Windows and don't study @aionescu, you're missing out on some of the best technical material in the industry.
ReactOS kernel dev -> iOS kernel research -> Windows Internals co-author -> critical kernel bugs -> UEFI bootkit research -> SimpleVisor.
SimpleVisor is still one of my favourite examples of making something incredibly complex approachable: a tiny VT-x reference hypervisor demonstrating VMX, VM-exits, EPT, VPID and live-host virtualization in ~500 lines of C and only ~10 x64 ASM instructions.
If you're into Windows internals, kernel security or reverse engineering, his blog is essential reading.
Bookmark it and start digging:
https://t.co/NziwoJ0o3c
#WindowsInternals #ReverseEngineering #KernelSecurity
推荐 Alex Ionescu 关于 fuzzing 的演讲。
技术观点分享,无直接安全信息。
And one of my favourite contrarian security talks:
'STOP! PUT DOWN THE FUZZER!'
The point wasn't that fuzzing is bad.
It was that finding more bugs doesn't fix the engineering problems that keep producing them.
https://t.co/jHx62AoK7T
#VulnerabilityResearch #ExploitDevelopment
学习资源推荐,无直接安全信息。
Call gates. KASLR. Hyper-V. WSL internals. UEFI. Kernel mitigations. Architecture research.
Alex's archive is basically a Windows internals syllabus.
Bookmark this:
https://t.co/p4fsTFqQZv
无实质内容。
https://t.co/C3MFMpiamL
Android 上 WhatsApp 视频通话可访问照片。
移动端隐私问题,但非漏洞,需关注。
RT @VBarraquito: Be aware that your photos can be accessed without unlocking your phone when you receive a WhatsApp video call on Android.
This is in plain sight. It's not hidden, not a secret feature. Not a hack.
This has already been reported to Meta and Google.
#Privacy #Security #Android17 https://t.co/F7wulhNiZ1
个人项目,无安全内容。
working on a custom conky , w00t w00t https://t.co/C3WObfsOM4
无实质内容。
https://t.co/rZxa1pyjtt
恶意扩展问题,需关注但信息有限。
RT @top10vpn: Another day, another Chrome Web Store horror story. More excellent work by @SocketSecurity uncovering these "highly extensible" malicious browser extensions. Seriously, @googlechrome, sort it out! https://t.co/040tFD6rLr
Meta 发布开源模型 Muse Glimmer。
开源模型发布,对 AI 应用有影响,但非直接安全。
RT @simplifyinAI: Meta just released an open-weights AI model that surpasses Gemma 4 and Qwen 3.6.
Muse Glimmer is Meta's first notable open-weight model release since April 2025, a 30B dense model built for agentic and coding work.
> Beats Gemma 4 on most benchmarks
> Trades wins with Qwen 3.6, ahead on agentic tasks
> Fits in 24GB of VRAM, runs at up to 233 tokens/sec
> 128K context, Apache 2.0 licensed
100% Free. Open Source.
评论性内容,无具体信息。
People who get f****d by this really deserve it. Why would you give your hypervisor remote own like that bro.
无实质内容。
RT @MSNightmare2000: @CharlesDardaman bro it's already over, that obsecurity stuff ain't flying with me
Hacktron AI 发现 RocketChat 漏洞。
AI 安全审计案例,但信息有限。
RT @HacktronAI: Human attention is finite.
@RocketChat runs every pull request through Hacktron so security review keeps pace with shipping.
In 20 days: 155 PRs reviewed, 17 real vulnerabilities found, including CVE-2026-55666, a critical Apple OAuth account takeover.
Read the full story: https://t.co/ycarY6hNgw
ai_agentcve
@0xocdsec
原文 ↗
EOL 版本漏洞,影响有限,但 PoC 公开。
RT @nebusecurity: Since PVE 7.4 has reached EOL and the latest 8.4 and 9.2 are not affected, we’re releasing the exploit here: https://t.co/fT3sRi153S
会议信息,非安全内容。
RT @POC_Crew: [#POC2026 NOTICE]
Registration is NOW OPEN.
🐦 Early Bird registration ends September 30
🎟️ Standard registration ends October 30
📍 See you in Seoul !
⏰ Date: November 12-13
📷 New Venue: The Westin Seoul Parnas, Korea
👉 https://t.co/V1L5jnoX0f https://t.co/LqEv0wjHO9
无实质内容。
We just posting genjutsu now
无实质内容。
RT @hackinarticles: Pic of the Day
#infosec #cybersecurity #cybersecuritytips #pentesting #cybersecurityawareness https://t.co/xQK97KLGpF
技术讨论,无具体信息。
RT @patrickwardle: Considering attackers’ increasing fondness for dylib-based payloads, I’d argue it’s about time! 😅
行业现象,无具体安全信息。
RT @chain00x: 最近一个月收到的重复比去年一年都多,时代变了,SRC涌入了大量新白帽子,人手agent自动挖洞 https://t.co/Fto3zFdsmo
行业评论,无直接安全信息。
RT @Itsfoss: AI has been caught wasting compute power. 🤷
("water is wet" kinda statement, btw)
https://t.co/TzFKhaDoPU
培训信息,非安全内容。
RT @fuzzsociety_org: September has started, and our trainer @Farenain has been preparing something very interesting!
It's time for the dragons! 🐉 If you've ever been curious about how the tools you use every day in your reverse engineering sessions actually work, join us in this training where we'll write a reverse engineering tool from scratch using the state-of-the-art library LLVM.
The training comes in two flavors:
- Basic: go from an ARM assembler/disassembler, to binary lifting, to your own Intermediate Language, Wyvern.
- Advanced: includes everything in Basic, plus the transformation from Wyvern to LLVM IR, later optimizations, and generation of a C and Python API.
This training focuses on ARM, the most prevalent architecture in the mobile world.
Here's the basic training, release price 149€: https://t.co/JAN5VXLibr
The advanced training, release price 249€: https://t.co/6DV5nic7Y5
Finally, if you also want to dive into Emulation and Symbolic Execution, we have a special bundle: the Advanced Training + our Emulation vs Symbolic Execution training, both for 399€: https://t.co/EGKZD20EkX
CC @jeppojeps
事件调查经验分享,有参考价值。
We had a Windows server where the Security log suddenly looked almost empty.
That alone was strange because this was not a fresh server. It had been running for weeks, so there should have been plenty of authentication and audit events inside it.
I checked for Event ID 1102.
There it was.
The audit log was cleared.
The account responsible was:
CORP\svc-backup
That caught my attention immediately because svc-backup was meant to be a service account. Nobody should be using it to interactively log into a server at 2 AM.
So instead of focusing only on the Security log, I checked the other logs on the machine.
Sysmon was still intact.
Around three seconds before the Security log was cleared, Sysmon showed:
wevtutil.exe
being launched by PowerShell.
The command line was:
wevtutil.exe cl Security
So somebody had deliberately cleared the Windows Security event log.
I checked the Remote Desktop Services operational log next.
About fifteen minutes earlier, there had been a successful RDP authentication using the same svc-backup account.
The connection came from an external IP address that had no business connecting directly to that server.
Now the timeline was making sense.
Someone authenticated over RDP using the backup service account.
They got onto the server.
A short while later, PowerShell launched wevtutil.exe.
Then the Security log was cleared.
Whoever did it probably thought clearing the Windows Security log would remove the evidence.
It did remove a lot of useful events.
But it did not remove everything.
The RDP operational logs were still there.
Sysmon was still there.
And Windows itself recorded Event ID 1102 showing that the Security log had been cleared.
We disabled the service account, isolated the server, preserved the remaining logs and started checking other systems to see where else those credentials had been used.
One thing I really took from this case is that logs should never be treated as one single source of truth.
If one log suddenly disappears, don’t assume the investigation is finished.
Check Sysmon.
Check PowerShell logs.
Check RDP logs.
Check your SIEM.
Check EDR telemetry.
Check whatever was forwarding events before the attacker touched the machine.
An attacker can clear one log.
Cleaning up every copy of the evidence is a completely different problem.
事件windows
@Officialwhyte22
原文 ↗
行业评论,无具体安全信息。
RT @HeidyKhlaaf: If someone developed a sophisticated worm and claimed that it escaped a sandbox that the worm was purposely built to infect, they would rightly be called incompetent or nefarious. Yet this is what AI labs do to animate a self-fulfilling prophecy about AGI, and people believe it.
ai_agent
@0xTriboulet
原文 ↗
无实质内容。
https://t.co/dpzwfbHH9d
博客文章,可能涉及安全研究。
RT @0xP0ch1ta: @h0mbre_ Check the new ritsec blog by @dudcom3 link: https://t.co/BQugUC1gOp
教育资源推广,非安全内容。
RT @XenoKovah: Do you think everyone should have access to free professional-grade educational material regardless of race, gender, or geographic location? And that the material should be both open access and open source? That's what #OST2 is making happen!
iOS/macOS 27 可在 QEMU 中启动。
系统模拟技术,对安全研究有潜在价值。
RT @0xjprx: I got the latest iOS and macOS 27 booting in Qemu (with SPTM!)
- Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported
- Debug, patch, or modify everything: kernel, SPTM, TXM, launchd, dyld, user programs all modifiable/ GDB-able
- Boots directly to root shell in seconds
- Run your own programs as root in iOS/ macOS, no jailbreak / kernel patches required
- SPTM, TXM, MTE/MIE, genter/ gexit, GXF/SPRR/GL0-2, AMCC, AIC v1-3, Apple timer, many sysregs
- Automated setup; get running in just a few minutes
- Runs anywhere qemu runs... no ARM CPU required 😉
Try it here: https://t.co/PEydRXL25G
技术观点讨论,无直接安全信息。
> If you have the memory for a garbage collector, you should absolutely use one
That’s gonna be a naw from me dog
Windows 安全调查技巧,有参考价值。
One PowerShell trick that is genuinely useful during Windows security investigations is checking where installed services are actually running from.
Most people use:
Get-Service
That is useful for checking whether a service is running or stopped, but during an investigation, the service name alone doesn’t tell you enough.
I also want to know the executable behind it.
For that, Win32_Service through CIM gives us much more information:
Get-CimInstance Win32_Service
One of the most useful properties returned is PathName. It tells you the executable and arguments Windows uses when starting that service.
This matters because legitimate Windows and third-party services normally run from locations you would expect, such as:
C:\Windows\System32\
C:\Program Files\
C:\Program Files (x86)\
That doesn’t mean every service outside those directories is malicious. But a service launching an executable from a user’s AppData directory deserves more attention.
For example, the terminal shows a service called ReaderSyncService whose executable is:
C:\Users\nora\AppData\Roaming\Adobe\ReaderSync.exe
The name sounds believable. The directory even contains Adobe.
But names are not evidence that a binary is legitimate.
A useful next step is filtering services whose PathName contains AppData:
Get-CimInstance Win32_Service | Where-Object PathName -like '*AppData*'
Now you can review the service name, display name, current state, startup mode and executable path without manually opening services.msc and checking every entry.
In the example, ReaderSyncService is also configured to start automatically. That makes the finding more interesting because the executable can be launched by the Service Control Manager without the user manually starting it.
From there, I would investigate the binary rather than immediately deleting or stopping anything.
Check its metadata:
Get-Item 'C:\Users\nora\AppData\Roaming\Adobe\ReaderSync.exe'
Then check its digital signature:
Get-AuthenticodeSignature 'C:\Users\nora\AppData\Roaming\Adobe\ReaderSync.exe'
Calculate its SHA-256 hash:
Get-FileHash 'C:\Users\nora\AppData\Roaming\Adobe\ReaderSync.exe' -Algorithm SHA256
And inspect the service configuration, creation context, associated process, network activity and relevant Windows logs.
One important lesson here is that an unusual path is an investigation lead, not proof of malware. Some legitimate applications do install components under user-writable directories.
But from a defensive perspective, services pointing into locations like AppData, Temp, user profiles or other writable directories are worth understanding.
PowerShell lets you find those anomalies across a Windows machine very quickly.
Sometimes the interesting part of a service isn’t its name.
It’s what Windows actually executes when that service starts.
windows工具
@Officialwhyte22
原文 ↗
作者将分析 648 个伪装成非托管钱包的 App。
移动端恶意软件分析,有潜在价值。
RT @overtorment: There are 648 apps on Apple Appstore that larp as non-custodial cryptocurrency wallets.
My clanker is busy now downloading all of them.
Then I will decompile all of them to see which ones have broken/backdoored entropy or private keys exfil.
Should be fun.
漏洞披露轶事,无直接安全信息。
RT @iam_zachi: Found an exploit in an app 2 month ago. They didn’t get back to me.
So I wrote them again.
From their own email. https://t.co/a4RwYVdW3H
行业调侃,无直接安全信息。
RT @sudoingX: BREAKING: Anthropic CEO Dario Amodei says he is deeply concerned by reports that the local ai community now considers 2x dgx spark with 256gb unified memory the frontier at home.
技术讨论,无直接安全信息。
RT @tkanarsky: @MohamedHz72007 Prefill is the other way around, it's the only part of the inference process that's compute bound because you're doing more math per byte of params. The reason the M5 is better at it is because there's new hardware that does more matmul per clock cycle.
无实质内容。
RT @PR0GRAMMERHUM0R: justOneMoreService https://t.co/MToWSB77a7
物联网隐私问题,值得关注。
RT @davetroy: Did you know your car's Tire Pressure Monitoring System transmits uniquely identifiable information whenever you're driving? I hooked up a radio dongle to my computer and monitored the neighborhood for an evening. This is what Claude inferred from the data. https://t.co/OvFfAyFVMS
隐私问题,需关注。
RT @DailyLoud: New app lets you see security cameras around you. https://t.co/SwCQpFisGN
法律纠纷,非直接安全信息。
RT @Cointelegraph: 🚨 LATEST: Apple claims in a new court filing that OpenAI is destroying evidence tied to a former Apple engineer's use of confidential technical documents, per Bloomberg. https://t.co/bogcWNIfI0
无实质内容。
RT @Little_34306: been working for years but haven’t meet each other irl :P https://t.co/EyQ8uh03sJ
Vigilant Labs 推出 AI 安全子公司。
公司动态,无直接安全信息。
RT @vigilant_labs: AI technology (and its application to cyber) is a rapidly developing field with a lot of different rabbit holes to dig into. So we have launched a sister company to focus on exactly that - introducing @Umbriel_AI !
行业讨论,无具体信息。
RT @schwartzonsec: @CraigHRowland @nahamike01 NGL. These type of “features” are prevalent across many Chinese manufactured and developed network devices. We looked at Baicells about 18 months ago and found some similar things. https://t.co/QynivqANRQ
法律纠纷,非直接安全信息。
RT @wallstengine: Apple alleges fmr. engineer Chang Liu accessed a proprietary power-converter circuit schematic while at OpenAI & used confidential $AAPL info to train an AI agent. The new evidence came from a MacBook provided by OpenAI on Aug 21 & is asking a federal judge to expedite discovery - new court filing.
培训信息,非安全内容。
RT @pedrib1337: The baseband (a cellular modem) is one of the most complex and interesting embedded devices out there.
Want to learn how to understand, debug, reverse engineer and pwn them?
Come to my class @hexacon_fr, one of the best offensive cons in the world!
非安全内容。
RT @aaronp613: The latest Spotify for iOS beta indicates a new widget is coming called "Talk To Spotify" https://t.co/Il776DwBnt
移动端安全特性变化,值得关注。
RT @hardenedlinux: https://t.co/gSd8cCRkoB
无实质内容。
RT @chompie1337: this is actually insane, not enough hype for this rn
无实质内容。
Achievement unlocked: provoked a "holy shit" from gpt-5.6-sol https://t.co/jlDs1xke6i
无实质内容。
RT @PaulosYibelo: Good morning, seems some ai ppl are going crazy learning ai's can hack and writing insane bs. I personally have been having time of my life with my intern ai hackers for over a yr now lol. Anyways, Pls don't visit https://t.co/HuWwuCDcWE 🌚, there may or may not be a safari 0day https://t.co/nOnBETHJC2