tlansec
tlansec.bsky.social
tlansec
@tlansec.bsky.social
Threat Intel @volexity.com n stuff.

London, UK.
Reposted by tlansec
Feike Hacquebord will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about Russia-, China- & DPRK-aligned APTs targeting Europe: IoT proxy networks, DPRK's Russian IPs, Pawn Storm's evolution & China's AI shift.

Seating is limited! Register here: luma.com/0qtkw49c
September 25, 2026 at 2:49 PM
Reposted by tlansec
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
bindinghook.com
September 24, 2026 at 1:52 PM
Reposted by tlansec
Excited to share I'm presenting a last-minute talk @virusbtn.bsky.social! Come watch me hype @greg-l.bsky.social's research on Russia-aligned TA488's operational evolution, complete with half-click XSS exploits, zero-days, webmail stealers, & browser implants www.virusbulletin.com/conference/v...
September 23, 2026 at 1:55 PM
Reposted by tlansec
We're one month out from @what-is-sos.bsky.social in Brussels with a packed and stacked agenda on all things intel, espionage, sabotage, physical ops, and attribution - get your tickets asap!! www.stateofstatecraft.com/agenda
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
www.stateofstatecraft.com
September 23, 2026 at 2:51 PM
If you're in BENELUX, or happen to be in Amsterdam the week commencing the 26th October, check out the Volexity Cyber Sessions: luma.com/0qtkw49c

We've announced Christopher Lopez (macOS guru) as our first speaker and we have some more great speakers announcing later this week!
Volexity Cyber Sessions – Amsterdam | October 2026 · Luma
Join Us in Amsterdam! We are excited to announce our first Volexity Cyber Sessions meetup in Amsterdam! Agenda 15:00 Registration & Welcome 15:45…
luma.com
September 22, 2026 at 10:09 AM
Reposted by tlansec
Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2...
www.volexity.com
September 21, 2026 at 9:13 PM
Reposted by tlansec
Christopher Lopez will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about the current macOS threat landscape: lures, targets, recently discovered malware, plus the artifacts that drive forensic analysis & durable detections.

Seating is limited! Register here: luma.com/0qtkw49c
September 17, 2026 at 6:52 PM
Reposted by tlansec
Back by popular demand, it's time for Volume II of State of Statecraft @what-is-sos.bsky.social! Come check out the latest in state-sponsored operations across espionage, cyber/physical sabotage, disruption, attribution, and all the -INTs you could dream of - Oct 22 www.stateofstatecraft.com/agenda
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
www.stateofstatecraft.com
September 14, 2026 at 8:52 AM
Reposted by tlansec
BEHOLD: the 🆘 AGENDA is OUT!

VOLUME II features numerous discussions on developments in state-sponsored operations covering digital espionage, cyber/physical sabotage, economic tradecraft, disruption, attribution and dare we say, more?

Agenda 👉 stateofstatecraft.com/agenda

🧵
September 11, 2026 at 3:39 AM
Reposted by tlansec
Models two years ago were 1). Models today are 2). We spent a trillion dollars to make a tool that is way way better at SQL than I am. Will that be better for society in 10 years? I have literally no idea.
1. Most people find AI only modestly useful, a more clever Google.

2. Many people building AI or using it obsessively worry it could severely damage or destroy humanity.

The gap between these realities helps explain why confusion and fear are exploding.
We're living in an AI twilight zone
The technology is simultaneously underwhelming in daily use and terrifying in its trajectory.
www.axios.com
September 10, 2026 at 11:21 AM
Reposted by tlansec
Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).
 
#DFIR #threatintel
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta...
www.volexity.com
September 9, 2026 at 5:43 PM
Reposted by tlansec
New release with lots of new features and bug fixes. Again, congratulations to Victor and everyone who contributed to making this happen! It’s great to see the continued progress.

github.com/VirusTotal/y...
Release v1.20.0 · VirusTotal/yara-x
Implement SIMD-accelerated masked literal matching (#691). Improve atom extraction heuristics for better performance (#690, 1e14f60). Improve scan performance by applying file size and file header ...
github.com
August 24, 2026 at 3:30 PM
Reposted by tlansec
when you're really good at making stuff but only get halfway through before starting the next thing

you're a black belt in partial arts
August 16, 2026 at 1:58 PM
Reposted by tlansec
Three positions opened up in GTIG. If you have questions I'd be happy to answer!

Koreas: www.google.com/about/career...

Exploits (US and CH based): www.google.com/about/career...

www.google.com/about/career...
August 10, 2026 at 4:45 PM
Reposted by tlansec
KFC announces their frontier-class model briefly escaped its sandbox and attempted to exfiltrate the 27 herbs and spices
August 5, 2026 at 10:26 PM
Reposted by tlansec
We have two malware analyst openings at Dragos!
In many malware jobs, your work disappears into the void. But at Dragos, it's easy to see the impact of your work across the company and community. And you get to work on interesting cases across OT verticals.

job-boards.greenhouse.io/dragos/jobs/...
Associate Principal Malware Analyst
United States
job-boards.greenhouse.io
August 5, 2026 at 3:40 PM
Reposted by tlansec
We’re just normal men
August 4, 2026 at 12:31 PM
Reposted by tlansec
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb?

Well...

We kinda lied

Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper

www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 29, 2026 at 9:12 AM
Reposted by tlansec
Heading to Las Vegas next week? Connect with our team to discuss the latest in #DFIR, #memoryforensics, active threat actor campaigns we're tracking, and more!
Let us know when you'd like to meet: www.volexity.com/contact/meet...
Volexity is heading to Las Vegas! Members of our leadership, development, engineering & threat intelligence teams will be on site August 4–6.

If you would like to connect to discuss the latest in #DFIR, #memoryforensics, or the current threat landscape, let us know when you’d like to meet!
Schedule a Meeting with Volexity in Las Vegas
If you would like to schedule time with members of Volexity's leadership, development, engineering, or threat intelligence teams to learn more about our recent investigations and next-generation memor...
www.volexity.com
July 28, 2026 at 6:08 PM
Reposted by tlansec
This came out while I was traveling last week and it's a good read on a single campaign from this group we've been tracking: dslua.org/publications... - They are fairly active doing this kind of phishing and also other nefarious activities.
Phishing Campaign Against “Civil Network OPORA” – Gmail Account Takeover via OAuth – Лабораторія цифрової безпеки
dslua.org
July 28, 2026 at 1:35 PM
Reposted by tlansec
Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs.

#dfir #memoryforensics #threatintel
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil...
www.volexity.com
July 17, 2026 at 10:34 PM
Reposted by tlansec
Reminder: CFP for 🆘 ends August 14! That's in 30 days... 1 month... four weeks.

This is the event that places state-sponsored operations front & center. The mic is all yours. Now prepare to drop it.

Submission Link: stateofstatecraft.com/cfp #what_is_sos
July 14, 2026 at 4:04 PM
Reposted by tlansec
gotta give some respect to student S22
absolutely insane story, and yeah, just looking at this chart... with the exception of maybe two people, this entire class was cheating like motherfuckers
July 8, 2026 at 1:16 PM
Reposted by tlansec
ICYMI: the State of Statecraft conference (@what-is-sos) returns to Brussels for Volume II on October 22, 2026. Registration is open & the CFP runs until Aug. 14

SOS is an event focused on state-sponsored operations: stateofstatecraft.com

🧵👇
Registration and CFP for 🆘VOLUME II is officially OPEN!

On October 22, 2026, we return to Brussels to showcase a day of community and discussions on the latest developments in state-sponsored operations and the actors & institutions that champion them.
July 7, 2026 at 10:47 AM