Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks
In early 2025, Volexity published two blog posts detailing a new trend among Russian threat actors targeting organizations through the abuse of Microsoft 365 OAuth and Device Code authentication workf...
@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355βs campaigns impersonating European security events.
04.12.2025 18:36 β π 10 π 8 π¬ 0 π 0
How AI is changing hacking
The tech company Anthropicβs AI technology was used by Chinese-backed hackers trying to breach foreign governments and major corporations.
@stevenadair.bsky.social recently spoke with Here & Nowβs Scott Tong (@npr.org @wbur.org) about @volexity.comβs discovery of China-aligned threat actor UTA0388 using AI + LLMs in targeted phishing attacks. Listen here: www.wbur.org/hereandnow/2...
03.12.2025 20:04 β π 2 π 1 π¬ 0 π 0
@volexity.com has continued to see nation-state threat actors use AI + LLMs to assist in cyber attacks. Our recent research on a Chinese APT threat actor (UTA0388) using AI in its operation was something @stevenadair.bsky.social recently discussed with the @wsj.com.
14.11.2025 16:28 β π 4 π 4 π¬ 1 π 0
With Volcano, security teams can automate the entire workflow of acquisition of memory and select files to deep analysis to automated alerts that directly point to signs of memory only malware and attacker activity throughout RAM and key artifacts sources from disk.
03.10.2025 17:05 β π 4 π 2 π¬ 0 π 0
From The Source 2025
Learn Directly from the Worldβs Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fouβ¦
The full lineup for our From the Source event is out! The event take places on October 20th in Arlington, VA. Joe Grand will keynote followed by an amazing speaker line up across two tracks. All proceeds will be donated to Connect Our Kids. volatilityfoundation.org/from-the-sou...
06.10.2025 15:49 β π 3 π 3 π¬ 0 π 0
We would like to thank @volexity.com for sponsoring the #FTSCon 2025 Evening Reception, which will be at VUE Rooftop DC this year! If you havenβt registered for FTSCon yet, thereβs still time! Registration closes Sunday Oct 12; learn more + register here: volatilityfoundation.org/from-the-sou...
07.10.2025 16:47 β π 3 π 4 π¬ 0 π 0
New Release: #volatility3 v2.26.2 - visit github.com/volatilityfo... for details and downloads.
#memoryforensics #dfir
29.09.2025 22:19 β π 4 π 3 π¬ 0 π 0
The stylized blue, orange and black Volexity Volcano logo is centered, with the Volcano wordmark below it. The words βby Volexityβ appear below the Volcano logo. There is a dark blue banner in the upper left with white letters that read βNew Releaseβ. The background is a faded gray abstract illustration evoking smoke.
@volexity.com Volcano Server & Volcano One v25.09.21 adds memory analysis support for ARM64 Linux, macOS 26 (Tahoe) & Windows 25H2, plus 75+ new YARA rules, 10+ new IOCs, analysis of udev rules & rolling upgrades for managed endpoints.
For more information, contact us: volexity.com/company/cont...
01.10.2025 18:06 β π 5 π 2 π¬ 0 π 1
Coming up the week of October 20th: #FTSCon + TWO in-person #training opportunities!
Learn more here: volatilityfoundation.org/from-the-sou...
#dfir #memoryforensics #hardwarehacking
29.09.2025 17:16 β π 3 π 4 π¬ 0 π 1
#FTSCon Speaker Spotlight: Michael Carson is presenting βThoriumβ in the MAKER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
19.09.2025 19:46 β π 1 π 2 π¬ 0 π 0
#FTSCon Speaker Spotlight: Tom Lancaster (@tlansec.bsky.social) & Josh Duke are presenting βMission Auth Possible: Passwordless Phishingβ in the HUNTER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
19.09.2025 18:43 β π 3 π 4 π¬ 0 π 0
#FTSCon Speaker Spotlight: Denis Bueno is presenting βCTADL: Customizable Static Taint Analysisβ in the MAKER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
19.09.2025 17:06 β π 0 π 4 π¬ 0 π 0
#FTSCon Speaker Spotlight: Daniel Gordon (@validhorizon.bsky.social) is presenting βWhen the AppleJeus GitHub is Worth the Squeeze: Citrine Sleet Investigationβ in the HUNTER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
19.09.2025 15:34 β π 6 π 3 π¬ 0 π 1
#FTSCon Speaker Spotlight: Joe FitzPatrick (@securelyfitz.bsky.social) is presenting βRethinking DMA Attacks with Erebusβ in the MAKER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
19.09.2025 13:23 β π 1 π 5 π¬ 0 π 0
#FTSCon Speaker Spotlight: Michael Horka is presenting βLilac Typhoon aboard the Indigo Train - The Current State of Chinese Obfuscation Networksβ in the HUNTER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
19.09.2025 11:23 β π 6 π 5 π¬ 0 π 0
#FTSCon Speaker Spotlight: Andrew Case (@attrc.bsky.social) is presenting βDetection and Analysis of Memory-Only Linux Rootkitsβ in the MAKER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
18.09.2025 21:34 β π 2 π 4 π¬ 0 π 0
#FTSCon Speaker Spotlight: Joseph Edwards (@eflags.bsky.social) is presenting βThe Forensics of Zoom's Remote Controlβ in the HUNTER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
18.09.2025 19:56 β π 1 π 4 π¬ 0 π 1
#FTSCon Speaker Spotlight: Aleksandra Doniec (@hasherezade.bsky.social) is presenting βUncovering Malware's Secrets with TinyTracerβ in the MAKER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
18.09.2025 18:10 β π 2 π 6 π¬ 0 π 0
#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting βCOLDRIVER: NOROBOT/YESROBOT/MAYBEROBOTβ in the HUNTER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
18.09.2025 16:29 β π 4 π 6 π¬ 0 π 1
#FTSCon Speaker Spotlight: Toni de la Fuente is presenting βOpen Cloud Security, lessons learned building Prowlerβ in the MAKER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
18.09.2025 14:46 β π 0 π 3 π¬ 0 π 0
#FTSCon Speaker Spotlight: Juan AndrΓ©s Guerrero-Saade is presenting βFrom Threat Hunting to Threat Gatheringβ in the HUNTER track.
See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
18.09.2025 13:15 β π 1 π 4 π¬ 0 π 0
From The Source 2025
Learn Directly from the Worldβs Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fouβ¦
We are counting down to #FTSCon 2025! We have a slate of great speakersβyou don't want to miss this event!
β¨If you haven't registered yet, register here: events.humanitix.com/from-the-sou....
Stay tuned for speaker spotlights!
18.09.2025 12:02 β π 0 π 3 π¬ 0 π 0
We are so excited to have @joegrand.bsky.social keynoting at #FTSCon 2025! Come join us on October 20th!
15.09.2025 16:30 β π 2 π 3 π¬ 0 π 0
Malware and Memory Forensics Training - Memory Analysis
Malware and memory forensics training courses offered by the Memory Analysis Team.
The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques
memoryanalysis.net/courses-malw...
03.09.2025 17:11 β π 7 π 6 π¬ 0 π 0
Event Schedule
BSides NYC is an Information / Security conference thatβs different. Weβre a 100% volunteer organized event put on by and for the community, and we truly strive to keep information free.
I am very happy to announce that @volexity.com will be well represented at @bsidesnyc.org! David McDonald will be speaking on his latest automated Powershell Deobfuscation research & I will present the latest Volatility 3 advancements against sophisticated Windows malware:
bsidesnyc.org/schedule/
08.09.2025 15:19 β π 3 π 4 π¬ 1 π 0
And thatβs a wrap for our 2025 #summerinternship program! This was a great summer of challenging impactful projects & fun team-building excursions. We wish our students all the best as they settle back into their Dept of Computer Science programs at University of Notre Dame & University of Maryland!
22.08.2025 15:45 β π 2 π 2 π¬ 0 π 0
Oct 21β24: Join the Volatility core development team for Malware & Memory Forensics Training! This 4-day training course is your opportunity to learn about new capabilities in Volatility 3 and what motivated recent design changes. memoryanalysis.net/courses-malw...
13.08.2025 14:43 β π 2 π 3 π¬ 0 π 0
Oct 21β22: Join @joegrand.bsky.social for Hardware Hacking Basics! This 2-day course teaches fundamental hardware hacking concepts & techniques used to reverse engineer + defeat the security of electronic systems. No prior hardware experience is required. events.humanitix.com/joe-grands-h...
13.08.2025 14:43 β π 2 π 3 π¬ 1 π 0
A 501c3 rescue and sanctuary. Thepipsqueakery.org
linktr.ee/the_pipsqueakery
Historian. Author. Professor. Budding Curmudgeon. I study the contrast between image and reality in America, especially in politics.
Nature comics (Bird and Moon). Books about nature. Talks. Bird facts. rosemarymosco.com She/her.
We're Shrimp and Grits! Shrimp is orange/white and Grits is gray/white
I RT a lot of adoptable cats!
Rescued by @friendsofbear.bsky.social
Cat dad: @jansten.bsky.social
Freelance writer and editor. Formerly of The Atlantic, Boston Review. Copy chief at Columbia Magazine.
Hi! I'm Mom's first cat, and I have a lot to teach her! She's a bit of a slow learner, but I love her anyway. I also love treats, brushies, naps, and my toys. I'm (at)RollerRoxie on the bird app. Crypto and Only Fans get blocked.
She/her. I write books about carriages, corsets, and smartwatches. Mother of (emoji) dinosaurs π¦π¦. ηΎ½ηη΅εΌ¦ fan. Fan of tea. Born at 332 ppm.
This biography should not be taken as a complete description.
courtneymilan.com
Always fighting for the people.
Wife, Momala, Auntie. She/her.
107 Days, my behind-the-scenes account of the shortest campaign in history, is available now at https://kamalaharris.link/107Days.
iβm not a girl, not interested in being polite or cisgender. jewish, anarchist, still punk, in my daddy era.
this is not a place of honor.
no highly esteemed thoughts are skeeted here.
ngl.link/armageddon1312
donβt explain, youβll only make it worse
Senior Scientist | Vaccine Research & Development | NIH | NIAID | VRC | π§¬π§«π¦ π¬ππ₯Όπ₯½ | π³οΈβπ | @coralchimera.bsky.social π | @phoenixnest.bsky.social & @multicolorbark.com & @likeapalette.com π§΅πͺ‘
Digital colorist, history buff, bestselling author, Forbes Under 30, loves dogs and coffee, etc. #actuallyautistic
Signed copies of Getting Naked available for preorder π©΅ https://talkshop.live/watch/TgZuUwV1NOK9
Professor, UW Biology / Santa Fe Institute
I study how information flows in biology, science, and society.
Book: *Calling Bullshit*, http://tinyurl.com/fdcuvd7b
LLM course: https://thebullshitmachines.com
Corvids: https://tinyurl.com/mr2n5ymk
he/him
noun | a reference source containing words alphabetically arranged along with information about their forms, pronunciations, functions, and etymologies
Hardware hacker, computer engineer, former L0pht member and juvenile delinquent, sometimes known as Kingpin. https://linktr.ee/joegrand
Nature photographer, amateur naturalist & arthropod enthusiast. Florida natives, here. Pics my own. Dead Name Walking. Man't. They/Them (she/her even, if you're not creepy about it)
IG: @apsciencebylyn
Discord: evelyndroid
Tumblr: apsciencebylyn
Lord of Loaders at Volexity
Dad, husband, host @Marketplace. IPAs. Soccer referee, trail runner, mountain biker. Veteran. kryssdal@marketplace.org
The largest collection of malware source code, samples, and papers on the internet.
Password: infected
(unofficial, this is a bot! Maintained by @yjb.bsky.social, the bot can't handle retweets, video, and maybe a few other things)