At #BlackHat2026, I’ll walk through the #JSCeal #malware case study and the static deobfuscation toolkit I built to recover readable code from the obfuscated #V8 compiled bytecode. If you’ll be at #BlackHat, I’d be glad to see you there! blackhat.com/us-26/briefi...
@hasherezade.bsky.social
Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc) ; https://hasherezade.net
Two members of the Scattered Spider hacking group—Thalha Jubair and Owen Flowers—pleaded guilty to hacking Transport for London last year www.bbc.com/news/article...
Two men plead guilty over £39m Transport for London cyber attack
The data breach affected 10m customers and disrupted some services for three months in summer 2024.
bbc.com
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6...
-China arrests members of Silver Fox cybercrime group -EU to help Ukraine in major cyberattacks -MS-ISAC loses 70% of members -SBOM still not widely adopted -Infosec execs call for lifting Anthropic ban Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS578/
New #TinyTracer (4.0) is ready: github.com/hasherezade/... - refactored for compatibility with the latest PIN - and with some new features!
This is the point AI fanboys keep missing. Yes, AI can help you ship faster. That does not mean it understands architecture, consistency, maintainability, or long term technical debt for you. You still need to know what you are doing
Long overdue, but here’s my writeup for #FlareOn12 Task 9: hshrzd.wordpress.com/2025/11/20/f...
Flare-On 12 – Task 9
In this mini-series I describe the solutions of my favorite tasks from this year’s Flare-On competition. To those of you who are not familiar, Flare-On is a marathon of reverse engineering. T…
hshrzd.wordpress.com
Heeey, ncurses/terminfo has a small virtual machine! And if there's a VM, there are CTF challenges :) hackarcana.com/public-exerc... hackarcana.com/public-exerc... (third one coming next week, will be a bit harder)
The 13th annual @volatility #PluginContest is OPEN for submissions until 31 Dec 2025! This contest is designed to encourage research & development in the field of #memoryanalysis. Every year, contributions from all around the world continue to help build the next generation of #memoryforensics.
The 13th Annual Volatility Plugin Contest is Open!
We are excited to announce that the Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open source forensics …
volatilityfoundation.org
-iOS 26 change deletes clues of old spyware infections -Starlink disables 2.5k scam compound terminals -Caribbean hospital still down 5 months after ransomware attack -Poland charges officials in Pegasus scandal Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS495/
Today I'm launching my new app, Hacktivate. It teaches real-world computer science skills through 240 "capture the flag" challenges, and works on iPhone, iPad, and Mac with one purchase. I've poured a ton of love into it, and I'd love to hear what you think 🙌 apps.apple.com/gb/app/hackt...
Hacktivate: Capture the Flag
Crack codes. Break firewalls. Conquer the map. Hacktivate is the ultimate cybersecurity challenge: a world map of 240 missions where every puzzle is built on real cybersecurity techniques hackers us...
apps.apple.com
I used PE-bear for the first time to dump an embedded binary. Its intuitive UI made extraction effortless. Because malware often embeds payloads with the form A in B to evade detection, pulling out the inner binary was crucial for deeper analysis and IoCs hunting.
Finally done with #FlareOn12. What a ride! I am looking forward to read other people’s solutions, especially of those who did the 9th task quickly.
#FTSCon Speaker Spotlight: Aleksandra Doniec (@hasherezade.bsky.social) is presenting “Uncovering Malware's Secrets with TinyTracer” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
My intermediate level malware analysis course is there. 60% off for the next two weeks. malwareanalysis-for-hedgehogs.learnworlds.com/course/inter...
Malware Analysis - Intermediate Level
Signature writing, deobfuscation, dynamic API resolving, syscalls, hooking, shellcode analysis and more
malwareanalysis-for-hedgehogs.learnworlds.com
Beyond good ol’ Run key, Part 148 www.hexacorn.com/blog/2025/07...
New #TinyTracer (v3.0) is out - with many cool features: github.com/hasherezade/... - check them out!
1. Pause thread midway in exploit races (even ⓪). 2. Or block entire CPU core. Kernel APCs run at APC_LEVEL (🤯), so thread scheduling kinda disabled (think priority == ∞). 3. Or build upon @hasherezade.bsky.social work & generalize #WaitingThreadHijacking — making it, in fact, Waitless.
Heard of #ContextJail? It's a nasty new technique: puts target thread into ⓪ deadloop, for as long as you can afford. Requires THREAD_GET_CONTEXT right. The gist? Just spam NtGetContextThread(tgt).😸 Target will be jailed, running nt!PspGetSetContextSpecialApc 🔁. Src & binary in [ALT]. Usecases: ⤵️
My new blog for CPR: introducing Waiting Thread Hijacking - a remote process injection technique targeting waiting threads: research.checkpoint.com/2025/waiting... #ProcessInjection
Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking - Check Point Research
Research by: hasherezade Key Points Introduction Process injection is one of the important techniques used by attackers. We can find its variants implemented in almost every malware. It serves purpose...
research.checkpoint.com
Zscaler has published a technical report on HijackLoader (IDAT Loader, GhostPulse) and its recent changes, such as its new call stack spoofing module, anti-VM module, and support for scheduled task persistence www.zscaler.com/blogs/securi...
New HijackLoader Evasion Tactics | ThreatLabz
Learn how HijackLoader has introduced call stack spoofing and new modules to improve its evasion and anti-analysis capabilities.
zscaler.com
Abolish April Fool’s day. Society has moved past the need for April Fool’s day
KELA has published a profile on Rey and Pryx, the two main individuals behind the Hellcat hacking group, responsible for several breaches over the past months, such as Schneider Electric, Telefónica, and Orange Romania. www.kelacyber.com/blog/hellcat...
Hellcat Hacking Group Unmasked: Investigating Rey and Pryx | KELA Cyber
KELA’s latest research uncovers key insights into two key threat actors of Hellcat Group, Pryx and Rey. Read more.
kelacyber.com
We all knew this day would arrive when the DNA samples you willingly provided 23andMe would be up for sale. Company now says it's seeking a buyer as it files for bankruptcy. 23andMe says any buyer will have to adhere to privacy laws for customer DNA/data they acquire. people.com/23andme-file...
23andMe Files for Bankruptcy as CEO Anne Wojcicki Resigns — What Will Happen to Your DNA Data?
Genetics company 23andMe has filed for bankruptcy and its CEO is stepping down, leaving many users concerned about the future of their data.
people.com
Clevo Boot Guard Keys Leaked in Update Package www.binarly.io/blog/clevo-b...
Clevo Boot Guard Keys Leaked in Update Package
Over the past few years, the Binarly Research team has led the way in documenting security problems haunting the entire UEFI ecosystem. We presented our discoveries at major security conferences like ...
binarly.io