Reverse engineers often spend significant time deciphering third-party libraries within firmware. My talk, scheduled for Friday at 5 PM at Reverse, introduces SightHouse, an open-source initiative aimed at automatically identifying third-party functions to enhance analysis efficiency.
Ghidra, scripting, LLM, automagic automation. That should grab the attention for this thread. If you want to read the complete blog, you can do so here: www.trellix.com/blogs/resear... 1/n
Many many folks in this effort over the years. Thankful for everyone and hope its of use.
The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry. nattothoughts.substack.com/p/stories-of...
From the World of “Hacker X Files” to the Whitewashed Business Sphere
Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry
nattothoughts.substack.com
The May release for ACCE includes updates and support including #AurotunStealer #rutserv #PupkinStealer #PE32Ransomware #Interlock www.ciphertechsolutions.com/acce-release...
ACCE Release Notes v2.9.20250508 – Cipher Tech Solutions, Inc.
ciphertechsolutions.com
France just called out GRU Unit 20728 (166th Research Information Centre), posted up in Rostov-on-Don, for cyberattacks. Kremlin got new ops on the board. www.diplomatie.gouv.fr/en/country-f... @wylienewmark.bsky.social
Russia – Attribution of cyber attacks on France to the Russian military intelligence service (APT28) (29.04.25)
France condemns in the strongest terms the use by Russia's military intelligence service (GRU) of the APT28 attack group, at the origin of several (…)
diplomatie.gouv.fr
Yall are beyond not ready about the shit we're cooking up with @censys.bsky.social and @greynoise.io powers combined censys.com/blog/hunting...
Hunting Botnets With CursorAI, GreyNoise, Censys, and Censeye
Threat hunting is made easier and simpler by combining the power of Censys, GreyNoise, CursorAI, and Censeye.
censys.com
I'm always a big fan of @agreenberg.bsky.social's writing, but I don't see a clear reason to believe these six stories are connected to "lesser-known hacker groups."
We at Wired put together six stories on lesser known hacker groups who have quietly become some of the most harmful in the world. Case in point: The turncoat Ukrainian spies working for Russia who some analysts say are the top cyberespionage threat to Ukraine today. www.wired.com/story/gamare...
Kyle's talk at Insomni'Hack is live! youtu.be/I0PoE0IdtmE?... Check it out if you're interested in a slice of modern program analysis and try the latest version of Tanto as well, in the plugin manager or at github.com/Vector35/tanto
"A Slice Of" Modern Program Analysis - Kyle Martin
youtu.be
Cool stuff. Kudos to whoever at Censys wrote this. I researched the ORB network myself but lack access to historical data. Thanks for providing historical visibility. censys.com/junos-and-re...
JunOS and RedPenguin
censys.com
The R&D team at JuniperNetworks released a detailed 35-page malware analysis report "The RedPenguin Malware Incident", covering the #TINYSHELL components used by #UNC3886, including the C2 protocol structure. supportportal.juniper.net/sfc/servlet.shepherd/document/download/069Dp00000FzdmIIAR
The R&D team at JuniperNetworks released a detailed 35-page malware analysis report "The RedPenguin Malware Incident", covering the #TINYSHELL components used by #UNC3886, including the C2 protocol structure. supportportal.juniper.net/sfc/servlet.shepherd/document/download/069Dp00000FzdmIIAR
supportportal.juniper.net
APT27 & i-soon hackers charged by DOJ—12 caught as the cats are out of the bag now. Yet APT27’s infra still purrs. Let’s see how they claw back from this! www.justice.gov/opa/pr/justi...
Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers in Global Computer Intrusion Campaigns
The Justice Department, FBI, Naval Criminal Investigative Service, and Departments of State and the Treasury announced today their coordinated efforts to disrupt and deter the malicious cyber activiti...
justice.gov
Epic collab, UNC4899 🤝 UNC5267 FBI official advisory on Bybit crypto theft www.ic3.gov/PSA/2025/PSA...
Internet Crime Complaint Center (IC3) | North Korea Responsible for $1.5 Billion Bybit Hack
ic3.gov
@shodanhq.bsky.social Awesome! Shodan History is back in the UI. Nice!!! Thank you. But I have a question regarding trends.shodan.io. all trends I do are stopping at October 2024. Why? Please make them to the current data again. I love it and need it. :)
Shodan
Shodan Trends - Discover how the Internet has changed over time.
trends.shodan.io
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. cloud.google.com/blog/topics/...
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
cloud.google.com
This latest blog from Cyfirma on Cl0p/Cleo exploitation is utter garbage, ignore it. LLM YARA rule (not even valid syntax), massively inflated statistics, and misleading IOCs and analysis. www.cyfirma.com/research/cl0...
CL0P Ransomware : Latest Attacks - CYFIRMA
INTRODUCTION The Cl0p group has been active since early 2019, leveraging vulnerabilities and exploits to encrypt files for ransom. The...
cyfirma.com
Excited to receive the @abuse-ch.bsky.social& @spamhaus.bsky.social swag! 🎁 Thank you for sending this amazing package. It means a lot to be recognized as a Top Contributor in the fight against cybercrime. Looking forward to continuing our battle together! 💪 #StrengthINUnity
A BIG thank you to our top contributors🎖️for sharing valuable technical cyber threat intelligence on our platforms over the past year. 🙏 Your efforts had a significant impact on cyber security, making the internet a safer place👏💪🛡️ A nice surprise is coming your way! 🎁 👀👇
#CMS8000 backdoor Hardcoded IP: 202.114.4[.]119 (h/t @craiu.bsky.social) registered to Tsinghua University 👀 VT link: www.virustotal.com/gui/file/4e4... 📝 www.cisa.gov/sites/defaul...
cisa.gov
The blog feels like a retro FLARE blog from the good old FireEye days! Shout out to Nino Isakovic, @qutluch.bsky.social and @lukejenx.bsky.social cloud.google.com/blog/topics/...
ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator | Google Cloud Blog
We been tracking multiple espionage operations conducted by China-nexus actors utilizing POISONPLUG.SHADOW malware.
cloud.google.com
⚖️EU sanctions three Russian GRU Unit 29155 officers for cyberattacks against Estonia in 2020. www.consilium.europa.eu/en/press/pre... Individuals Sanctioned: 1️⃣Nikolay Alexandrovich KORCHAGIN 2️⃣Vitaly SHEVCHENKO 🆕 3️⃣Yuriy Fedorovich DENISOV 📎 eur-lex.europa.eu/legal-conten...
Cyber-attacks: three individuals added to EU sanctions list for malicious cyber activities against Estonia
The Council imposed restrictive measures on three individuals involved in cyber-attacks against Estonia.
consilium.europa.eu
⚖️EU sanctions three Russian GRU Unit 29155 officers for cyberattacks against Estonia in 2020. www.consilium.europa.eu/en/press/pre... Individuals Sanctioned: 1️⃣Nikolay Alexandrovich KORCHAGIN 2️⃣Vitaly SHEVCHENKO 🆕 3️⃣Yuriy Fedorovich DENISOV 📎 eur-lex.europa.eu/legal-conten...
Cyber-attacks: three individuals added to EU sanctions list for malicious cyber activities against Estonia
The Council imposed restrictive measures on three individuals involved in cyber-attacks against Estonia.
consilium.europa.eu
Spent a bit of time adding some new features to “yr fmt” that I suspect will be well liked and very useful if you write a lot of rules and like consistency. I have the gist of it but am stumbling over some rust intricacies for the first time. Maybe by the end of the year I’ll have it done.