Additional info on the Fancy Bear kit being reported on. Cheers to @Laughing_Mantis for writing backdoors so good that APTs plagiarize it.
kroll.com/en/publication…
The Proofpoint team have observed an increase in opportunistic cybercriminals using malware based on Stealerium, an open-source malware that is available “for educational purposes”. proofpoint.com/us/blog/threat…
🖱️💥 Wanna see how ClickFix attacks work behind the scenes?
Meet our good ol’ friend ClickGrab 🐇🔍
It runs nightly 🌙 and automatically captures ➡️ all the juicy artifacts, payloads, and behaviors attackers use. Perfect for defenders, researchers, & curious nerds 🤓⚔️
What you…
1/ Nice catch by @g0njxa: ads drop #macOS#stealer as well. First stage: signed DMG "Alli-Ai.dmg". Inside: Mach-O file named sudoku?🤷♀️ Seems to be a Swift app, in real a wrapper (loader/launcher) that spawns a child process and hands it AppleScript that does the actual data theft
1/ Nice catch by @g0njxa: ads drop #macOS#stealer as well. First stage: signed DMG "Alli-Ai.dmg". Inside: Mach-O file named sudoku?🤷♀️ Seems to be a Swift app, in real a wrapper (loader/launcher) that spawns a child process and hands it AppleScript that does the actual data theft https://t.co/4i1dginXXH
My favourite finding from @SLCyberSec's Security Research team in 2025 so far is a secondary context path traversal in Omnissa Workspace One UEM (CVE-2025-25231). Really interesting bug, and fun kill chain to RCE. slcyber.io/assetnote-secu…
Facebook Messenger for Windows RCE worth $112K via Slack/Viber DLL files override using path traversal in attachments by @vulnanovulnano.com/2025/09/remote…
CVE-2025-52915 assigned - my first vulnerability!🥳
A classic BYOVD case: kernel driver with unrestricted process termination.
Vendor coordination turned out more challenging than the exploit itself.
Technical write-up: blacksnufkin.github.io/posts/BYOVD-CV…#ExploitDev#CVE#BYOVD#RedTeam
My new article: "Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"⚡️
I tell a bug collision story and introduce my pet project kernel-hack-drill, which helped me to exploit the hard bug that received @PwnieAwards 2025
a13xp0p0v.github.io/2025/09/02/ker…
ICYMI: The transformation of China’s digital attack capabilities is the most important change in the cyber threat to the West in more than a decade, writes Ciaran Martin. rusi.org/explore-our-re…@RUSI_org
Insane that this extension published today on the VS marketplace is showing 2.5 million installs, obviously manipulated. A copy of malicious extensions seen in Open VSX. The VS marketplace is no safe haven.
VitalikButerin-EthFoundation.blan-co
marketplace.visualstudio.com/items?itemName…
🦠 𝗡𝗲𝘄 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵: 𝗙𝗿𝗼𝗺 𝗣𝗮𝗻𝗲𝗹 𝘁𝗼 𝗣𝗮𝘆𝗹𝗼𝗮𝗱 – 𝗜𝗻𝘀𝗶𝗱𝗲 𝘁𝗵𝗲 𝗧𝗶𝗻𝘆𝗟𝗼𝗮𝗱𝗲𝗿 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗢𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻
TinyLoader is more than a loader.
It spreads through USB drives and shares, hijacks clipboard crypto addresses, and delivers Redline…
We definitely want to see that, and learn more about the 0-days and all the vulnerabilities they are finding in @Xbow. Well, guess what? They did a recording for us to share. Go to youtube.com/@BugBountyVill… and subscribe, to get notified about @niemand_sec and @djurado9's talk!
We definitely want to see that, and learn more about the 0-days and all the vulnerabilities they are finding in @Xbow. Well, guess what? They did a recording for us to share. Go to youtube.com/@BugBountyVill… and subscribe, to get notified about @niemand_sec and @djurado9's talk!
Much like humans, CPUs heal in their sleep.
CPUs are *technically* replaceable / wear items. They don’t last forever.
Yet, the moment stress is removed, transistor degradation (partially) reverses.
It's called Bias Temperature Instability (BTI) recovery:
67K Followers 8K FollowingHacker, Researcher, Podcast Producer (Tribe of Hackers, Darknet Diaries). Proud dad of the fastest climber in the world. Ever. “Ut scandis, alios subleva”
25K Followers 26K FollowingA Hacker who is A Lover of People, and Life @RetroTwinz @Secbsd, @GrumpyHackers, @NovaHackers, @deadpixelsec @hacknotcrime Advocate @PositivelyBlue_ OSCP, OSWP
4K Followers 600 FollowingElastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
2K Followers 1K FollowingBrazilian Security Analyst | Malware Analysis | Responsible for the Slowest Algo in HashDB | Can barely reverse Hello World | PTC
1K Followers 478 FollowingPh.D. computer security researcher @TrailOfBits. Editor of and frequent contributor to #pocorgtfo. My CV is a PDF that’s also an NES ROM https://t.co/lDrC4Hz6AI
3K Followers 709 FollowingSecurity of AI, AI for Security
AI Red Team @ NVIDIA
Using bad guys to catch math since 2010
`from standard_disclaimers import *`
61K Followers 804 FollowingSecurity Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
5K Followers 235 FollowingI do software, a tiny bit of hardware and a lot of security.
I got carried away with my conference filming hobby and now film over 30 cons each year.
453 Followers 85 FollowingRural cybersecurity practitioner and seasoned brewer. Opinions are my own, I work @HarfangLab (former GREAT, CISO and FR Gov).
763 Followers 705 FollowingAdvance-sec platform: is one of the top leaders in research and acquisition of vulnerabilities and 0day exploits.
Email: [email protected]
Wire: @advance_sec
16K Followers 2 FollowingThe Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks - made with ❤️ by @evilsocket
17K Followers 348 FollowingHackers On Planet Earth - August 15-17, 2025 - Queens, New York City, USA 🗝💻📻☎️ 🐘:@[email protected] • 🦋:@hope.net • ig/threads:hopeconf
5K Followers 9 FollowingPaged Out! is a free magazine about programming, hacking, security hacking, retro computers, modern computers, electronics, demoscene, and other amazing topics.
655 Followers 1K Following🇮🇹 | IT Engineer with Cyber Security passion | Malware Analysis | Reverse Engineering | CTI
- views and opinions are solely my own -
95K Followers 2K FollowingHacker, marketer. I manage socials and produce amazing technical blogs for cybersecurity orgs. Founder of @hacker_content and @haksecio
2K Followers 5K Followingsecurity, drum and bass, stuff and things. AHAtian, w00er, professional hard chatter. moderator @ https://t.co/cuKZCaVhGJ - blog @ https://t.co/cvnX7XrYVg - he/him
7K Followers 597 FollowingHacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg