Philippe Lagadec

@decalage.bsky.social

Author of open-source projects oletools, olefile, ViperMonkey, ExeFilter, Balbuzard. Posting about #DFIR, #malware analysis, maldocs, file formats and #Python. https://linktr.ee/decalage

"Zombie ZIP" CVE-2026-0866 is not really a vulnerability which can evade AV engines, because the resulting ZIP file cannot be opened by normal tools, it's malformed. It's more like a steganography/obfuscation trick, you need malicious code already running to extract the payload.

BleepingComputer@bleepingcomputer.com · 5mo ago

A new technique dubbed "Zombie ZIP" helps conceal payloads in compressed files specially created to avoid detection from security solutions such as antivirus and endpoint detection and response (EDR) products.

Honestly, AI slop PRs are becoming increasingly draining and demoralizing for #Godot maintainers. If you want to help, more funding so we can pay more maintainers to deal with the slop (on top of everything we do already) is the only viable solution I can think of: fund.godotengine.org

Adriaan@adriaan.games · 6mo ago

Godot's GitHub has increasingly many pull requests generated by LLMs and it's a MASSIVE time waster for reviewers – especially if people don't disclose it. Changes often make no sense, descriptions are extremely verbose, users don't understand their own changes… It's a total shitshow. #godotengine

At hack.lu I gave a presentation about "How to better identify (weaponized) file formats": - Why do we need to identify file formats accurately? - Why can the current tools (libmagic, magika) sometimes be bypassed? - How can we do better? You can now see it here: youtu.be/Qp5GDh2sj6A #HackLu

hack.lu 2025

Hack.lu (and CTI summit) is an open convention/conference where people can discuss about computer security, privacy, information technology and its cultural/technical implication on society. It’s the ...

hack.lu

This week I'm going to hack.lu, to give a presentation about file format identification: Why do we need to identify file formats accurately? Why can the current tools sometimes be bypassed, or make mistakes? How can we do better? 2025.hack.lu/agenda/ Send me a DM if you'd like to meet there.

hack.lu 2025

Hack.lu (and CTI summit) is an open convention/conference where people can discuss about computer security, privacy, information technology and its cultural/technical implication on society. It’s the ...

hack.lu

Even though I've been away from the field for years, it's great to see that a simple tool that I initially launched in 2018 and with great collaborators (Artur Marzano, Corey Forman and Christian Clauss) has been used by so many professionals. www.helpnetsecurity.com/2025/03/26/m... #malware

Malwoverview: First response tool for threat hunting - Help Net Security

Malwoverview is an open-source threat hunting tool designed for the initial triage of malware samples, URLs, IP addresses, domains, malware families,

helpnetsecurity.com

New DCOM lateral movement technique discovered that bypasses traditional defenses. Unlike previous attacks relying on IDispatch interfaces, this method exploits undocumented COM interfaces within MSI, specifically targeting IMsiServer and IMsiCustomAction interfaces. 1/7

Forget PSEXEC: DCOM Upload & Execute Backdoor

Join Deep Instinct Security Researcher Eliran Nissan as he exposes a powerful new DCOM lateral movement attack that remotely writes custom payloads to create an embedded backdoor.

deepinstinct.com