tlansec's Avatar

tlansec

@tlansec.bsky.social

Threat Intel @volexity.com n stuff. London, UK.

757 Followers  |  252 Following  |  38 Posts  |  Joined: 01.06.2023  |  1.7158

Latest posts by tlansec.bsky.social on Bluesky

Bran Van 3000 - Drinking in LA (live at Nulle Part Ailleurs)
YouTube video by Pascal Burger Bran Van 3000 - Drinking in LA (live at Nulle Part Ailleurs)

youtube.com/watch?v=5Z6a...

06.10.2025 00:06 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

⏰ The inaugural SOS conference is 30 days away! Have you gotten your ticket yet?!?

Listen to expert discussions on state-sponsored operations covering espionage, sabotage, and attribution of Russia, China, Iran, and more.

Registration is still open! stateofstatecraft.com/agenda

29.09.2025 03:01 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz The Russia-linked group COLDRIVER targeted dissidents and their supporters using a ClickFix technique, resulting in the deployment of BAITSWITCH and SIMPLEFIX.

www.zscaler.com/blogs/securi... - Nice writeup by zscaler on some COLDRIVER malware. I'm talking about this stuff at #FTSCon in a few weeks and will have lots more details there.

26.09.2025 14:45 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
RedNovember Targets Government, Defense, and Technology Organizations RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the lates...

First public report at Recorded Future by yours truly is out! RedNovember (formerly TAG-100, a.k.a. Storm-2077) is a Chinese state-sponsored threat group focused on intelligence collection, especially on flashpoint issues of strategic interest to China. www.recordedfuture.com/research/red...

24.09.2025 18:57 β€” πŸ‘ 22    πŸ” 14    πŸ’¬ 2    πŸ“Œ 0
Preview
Staff Security Research Engineer About Us: We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to s...

Couple of openings here in our threat research org!

Staff Security Research Engineer:
proofpoint.wd5.myworkdayjobs.com/en-US/Proofp...

Senior Threat Researcher (ecrime team):

proofpoint.wd5.myworkdayjobs.com/ProofpointCa...

24.09.2025 01:59 β€” πŸ‘ 10    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

In Swedish, a word for what you eat to bridge the gap between meals (or while waiting for the main course to cook) is stΓΆdmacka. It means "support sandwich."

A similar word in Norwegian is ventepΓΈlse, or "waiting sausage."

21.09.2025 15:34 β€” πŸ‘ 2184    πŸ” 444    πŸ’¬ 61    πŸ“Œ 103
Preview
Gamaredon X Turla collab ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.

www.welivesecurity.com/en/eset-rese...

19.09.2025 22:57 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting β€œCOLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...

18.09.2025 16:29 β€” πŸ‘ 4    πŸ” 6    πŸ’¬ 0    πŸ“Œ 1
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

17.09.2025 13:20 β€” πŸ‘ 85    πŸ” 38    πŸ’¬ 9    πŸ“Œ 5
Preview
From The Source 2025 Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou…

I’ll be giving a talk at FTS this year. Not going to lie, I’m doing it just so I can heckle Sir Tom of The House of Lancaster (@tlansec.bsky.social) in person.

volatilityfoundation.org/from-the-sou...

15.09.2025 18:25 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

ME, IN TEARS: you can't just say every single part of a computer system is a file

UNIX, POINTING AT THE MOUSE: file

07.09.2025 11:01 β€” πŸ‘ 2330    πŸ” 508    πŸ’¬ 39    πŸ“Œ 18
Preview
Malware and Memory Forensics Training - Memory Analysis Malware and memory forensics training courses offered by the Memory Analysis Team.

The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques

memoryanalysis.net/courses-malw...

03.09.2025 17:11 β€” πŸ‘ 6    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0

Now up to 22 different Cinnamon Toast Crunch related products. The quest continues.

03.09.2025 16:19 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
RationalEdge - Intelligence Meets Accuracy Advanced malware analysis and threat intelligence solutions by RationalEdge

TL;DR I am launching my #startup and we are going to change how to evaluate,cluster and reason about #malware, delivering accurate,contextual intelligence on samples. Say Hi to RationalEdge
@rationaledge.bsky.social
rationaledge.io

#threatintel #threathunting #cti #reverseengineering #detection 1/9

28.08.2025 12:22 β€” πŸ‘ 25    πŸ” 15    πŸ’¬ 2    πŸ“Œ 0
Post image Post image

And that’s a wrap for our 2025 #summerinternship program! This was a great summer of challenging impactful projects & fun team-building excursions. We wish our students all the best as they settle back into their Dept of Computer Science programs at University of Notre Dame & University of Maryland!

22.08.2025 15:45 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

I don't think children should have phones. They should have huge beige desktop computer with "Windows 9x Operating System", "Dedicated 3D accelerator", and "SoundBlaster compatible sound card"

17.08.2025 00:21 β€” πŸ‘ 1793    πŸ” 333    πŸ’¬ 75    πŸ“Œ 26

Coming this October: #FTSCon 2025, hosted by @volatilityfoundation.org! And this year there are TWO in-person training opportunities!πŸ‘‡

#dfir #memoryforensics #volatility3 #hardwarehackingbasics #grandideastudio

13.08.2025 14:43 β€” πŸ‘ 2    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1
Post image

We are thrilled to announce that @joegrand.bsky.social is this year’s #FTSCon Keynote speaker! Joe will be sharing stories & technical details about his wallet hacking adventures to kickoff our full-day event on Monday, Oct 20, 2025. You don’t want to miss this!

06.08.2025 20:12 β€” πŸ‘ 4    πŸ” 5    πŸ’¬ 1    πŸ“Œ 1
Preview
Go Get 'Em: Updates to Volexity Golang Tooling Volexity’s GoResolver tool was released in April 2025 to help with analysis of these samples, reducing analyst load when working with obfuscated Golang binaries. However, there are still some difficul...

@volexity.com has released updates to its #opensource GoResolver project and more! This work was part of a project for one of our #summerinternship students. Read more details about Volexity’s updated GoResolver projects + other #golang tools in our special blog post!

11.08.2025 19:05 β€” πŸ‘ 10    πŸ” 10    πŸ’¬ 1    πŸ“Œ 0

#ESETresearch has discovered a zero-day vulnerability in WinRAR, exploited in the wild by Russia-aligned #RomCom @dmnsch @cherepanov74 www.welivesecurity.com/en/eset-rese...
1/7

11.08.2025 09:08 β€” πŸ‘ 17    πŸ” 11    πŸ’¬ 1    πŸ“Œ 2
Preview
Release v1.5.0 Β· VirusTotal/yara-x Implement the crx module for parsing Chrome Extension files (#423). Allow underscores in integer and float literals (#405). Adopt Anomali's symhash algorithm for Mach-O files (#425). Support boolea...

YARA-X 1.5.0 is out. Nice new features (including a crx module) and bug fixes. Congratulations to Victor and all the contributors!

github.com/VirusTotal/y...

08.08.2025 14:35 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Incredible writeup from Eye Security on their adventures logging into internal-only MS services: research.eye.security/consent-and-...

08.08.2025 08:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A radiologist called me yesterday.

It sounded serious.

They said they spotted an anomaly on my x-rays.

I was prepared for the worst.

They found a strange shape and the word "Quantamonster."

That's the company logo of my new startup.

Years ago I asked a surgeon to engrave it onto my patella.

Now, every time I go for an X-ray, the radiologist sees it, gets intrigued.

If they search it, they'll find that we've just opened a new seed round. They sign up.

Some say to raise investor money you have to think outside the box.

I say you need to think inside the body.

Venture capitalism is in my bones.

A radiologist called me yesterday. It sounded serious. They said they spotted an anomaly on my x-rays. I was prepared for the worst. They found a strange shape and the word "Quantamonster." That's the company logo of my new startup. Years ago I asked a surgeon to engrave it onto my patella. Now, every time I go for an X-ray, the radiologist sees it, gets intrigued. If they search it, they'll find that we've just opened a new seed round. They sign up. Some say to raise investor money you have to think outside the box. I say you need to think inside the body. Venture capitalism is in my bones.

A radiologist called me yesterday. I was prepared for the worst

06.08.2025 09:29 β€” πŸ‘ 146    πŸ” 18    πŸ’¬ 2    πŸ“Œ 3
"I don't know shit about fuck" - Ruth Langmore - Ozark
YouTube video by Bee4Brendan "I don't know shit about fuck" - Ruth Langmore - Ozark

I think about this quote alot:

youtu.be/8J8A9ZiIeUQ?...

05.08.2025 16:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
QUIZ: Are You Even Good Enough to Have Imposter Syndrome?

QUIZ: Are You Even Good Enough to Have Imposter Syndrome?

05.08.2025 09:49 β€” πŸ‘ 503    πŸ” 93    πŸ’¬ 15    πŸ“Œ 13

Jen Easterly was a supremely effective leader of CISA and you would be very hard pressed to find anyone who's a more qualified and quietly competent professional than her. This administration and its gormless hacks continue to cut off our collective noses to spite our face.

31.07.2025 18:26 β€” πŸ‘ 93    πŸ” 35    πŸ’¬ 1    πŸ“Œ 1
Preview
The Kremlin's Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware The FSB cyberespionage group known as Turla seems to have used its control of Russia's network infrastructure to meddle with web traffic and trick diplomats into infecting their computers.

Microsoft found Turla, Russia's elite FSB cyberespionage group, hacking foreign embassies' staff in Moscow by directly meddling with ISP traffic to infect targets with spyware that silently stripped away encryption on their communications and credentials. www.wired.com/story/russia...

31.07.2025 16:01 β€” πŸ‘ 121    πŸ” 71    πŸ’¬ 1    πŸ“Œ 3
Preview
First cell-phone network cyberattack on Tibetan leader detected - Phayul Phayul.com is one of the most popular & successful Tibetan news website in English. With daily readers touching over 12,500 and still growing. It features news and views on Tibet.

First cell-phone network cyberattack on Tibetan leader detected @tibcert.bsky.social

www.phayul.com/2025/07/29/5...

30.07.2025 08:11 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Nation-State Actor Targets Global Telecoms

~Paloalto~
Nation-state actor Liminal Panda uses custom malware like GTPDoor to infiltrate telecom networks for persistent access and potential location tracking.
-
IOCs: GTPDoor, ChronosRAT, NoDepDNS
-
#GTPDoor #LiminalPanda #ThreatIntel

30.07.2025 04:03 β€” πŸ‘ 4    πŸ” 5    πŸ’¬ 0    πŸ“Œ 1

When your CTI blog uses AI art, it immediately loses 10 respect points. Discuss.

28.07.2025 12:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@tlansec is following 18 prominent accounts