@xorhex.bsky.social
Join us today from 3-5pm ET to learn to recognize and apply types to decompiled C++ that's using virtual functions, inheritance, and vtables. We'll recover missing parameters, apply types, clean up decompilation, and everything else you need to get started reversing C++! youtube.com/live/QmsUmvH...
28.01.2026 15:44 β π 7 π 4 π¬ 0 π 0The CertGraveyard is now being leveraged by MagicSword.
MagicSword makes use of certificates we report and blocks them within your environment.
I was really amazed by the work they do to block RMM and bad drivers. Now this further enables orgs to block malicious signers.
x.com/magicswordio/s...
New blog post is live! Xusheng tears apart a tiny Linux binary that really does not want to be reversed. Malformed ELF headers, segment tricks, layered XOR and RC4, plus a bunch of Binary Ninja tricks along the way. Read it here: binary.ninja/2026/01/23/r...
27.01.2026 15:31 β π 6 π 3 π¬ 0 π 0π¦ πΉ New Video: Can office files be malicious without Macros?
β‘οΈ VSTO Add-Ins
β‘οΈ External Templates
β‘οΈ Checklist for Office analysis
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=RtHH...
Awesome, time for me to update #BinYars again π
26.01.2026 17:07 β π 0 π 0 π¬ 0 π 0#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malwareβs design clearly indicates destructive intent. 1/5
23.01.2026 16:30 β π 35 π 30 π¬ 1 π 5Great work by Kim and ESET to get this story out there. The cyber threat has been off the front pages with everything else going on, but is still very real.
23.01.2026 17:48 β π 7 π 1 π¬ 0 π 0New Children's Health Defense site registered on 1/9/26 and currently in development:
covidjustice[.]org
covidjustice[.]metalteam[.]dev (69.16.249[.]248, dev site)
That's awesome! Have a hash that can be shared?
16.01.2026 20:08 β π 0 π 0 π¬ 1 π 0We are less than a month away from #PIVOTcon26 #CfP deadline,come present your best research in a trusted,vetted environment attended by some of the best researchers. We created such an environment so that we can feel safe to exchange beyond the blogposts #CTI #ThreatResearch #ThreatIntel #MemeGuide
12.01.2026 15:20 β π 12 π 6 π¬ 0 π 1Carl Svensson is bringing Age of Empires II Definitive Edition to RE//verse 2026 as a playground for tooling. This talk walks through Binary Ninja automation to decrypt and deobfuscate...
08.01.2026 21:15 β π 4 π 1 π¬ 1 π 1github.com/VirusTotal/y... - 1.11.0 is out! Lots of new features, modules and bug fixes. Read the release notes and congrats to Victor and the contributors!
09.01.2026 13:43 β π 7 π 3 π¬ 0 π 0π¨#100DaysofYARA lives!!
2 time reigning champ Yashraj
has kindly offered to take the helm for this community effort! Give the homie a follow π
Check the repo to contribute: github.com/100DaysofYARA
And gear up for Jan 1 when #100DaysofYARA will kick off!
You asked for our traditional #CfP meme-guideline for #PIVOTcon26 - here it is π₯³π
Reminder:
- one track,30m
- no recording/streaming/tweeting.
- No TLP:WHITE
- Original content only
#CTI #ThreatIntel #ThreatResearch 1/7
π£π¦ Announcing: TWO 2026 sessions for our Rust reverse engineering course, Deconstructing Rust Binaries!
1) Ringzer0 COUNTERMEASURE, March 23-26, Remote: ringzer0.training/countermeasu...
2) NorthSec (@nsec.io), May 11-13, MontrΓ©al & Remote: nsec.io/training/202...
#malware #infosec #rustlang
Excited to bring Deconstructing Rust Binaries to NorthSec in March! Chat with me here or at @decoderloop.com if you have questions about the training.
Take advantage of the early bird rate for the onsite option! Pricing is in CAD, take advantage of the exchange rate (:
nsec.io/training/202...
Targeting of Lithuania's government today cc @lithuaniaineu.bsky.social 0c6ba3f0ab6f48c84175db68eb4f0d19
17.12.2025 15:20 β π 2 π 2 π¬ 0 π 0I feel seen lol
17.12.2025 10:28 β π 1 π 0 π¬ 0 π 0I spent a couple months arguing with Claude and Copilot while building FrostyGoop variants for DNP3 (and Modbus), keeping detailed notes on what worked and what didn't. At S4, Iβll share my honest assessment of these tools and how they might lower barriers to ICS malware dev. See you in Miami!
16.12.2025 15:00 β π 3 π 1 π¬ 0 π 0Proud to share new research by Amazon Threat Intelligence detailing recent activity by Sandworm/APT44 π·πΊ targeting US and European energy, critical infrastructure, and managed security provider networks via vulnerable and misconfigured network edge devices. #threatintel aws.amazon.com/blogs/securi...
15.12.2025 19:51 β π 18 π 9 π¬ 1 π 0Able to share the hash/sample of `[REDACTED].bin`?
15.12.2025 20:44 β π 0 π 0 π¬ 0 π 0Ongoing european government targeting from this susp ru actor. Surely others are focused on the politics of Transnistria, but not too many. strikeready.com/blog/russian...
15.12.2025 20:31 β π 2 π 2 π¬ 0 π 1π¦ Looking for Rust malware samples to practice analyzing? Our Rust Malware Sample Gallery just received a major update, with 20 new families added! github.com/decoderloop/...
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing
Nice reporting! IOCs π«Ά
Also, I'm so used to markdown that I almost didn't notice this:
I'm hiring a senior threat researcher! If you want to help me build out a team to track the most advanced actors targeting cloud environments, this is the job for you. This job is open to remote, but us-bases only. Feel free to reach out with questions.
www.wiz.io/careers/job/...
Just posted my thoughts on maldev academy! Apologies if itβs a little messy, itβs reporting week at work so itβs all text editing all day right now.
www.winterknight.net/maldev-acade...
Quality of life improvement for yara-x:
I realized the functions that output hash values do not have constraints on them like the hash module functions do. See virustotal.github.io/yara-x/blog/... for details on why this is useful to extend everywhere.
PR that fixes it: github.com/VirusTotal/y...
#BinYars (write #YARA-X rules inside of #BinaryNinja) is now available in Binja's plugin manager!
I want to give a special shout out to @cxiao.net (Thank You π) who provided valuable feedback making the plugin experience better.
Happy rule writing!
Learn more @ github.com/xorhex/BinYars
the amount of businesses that use GoPhish as an otherwise legitimate mailer is ... concerning
08.12.2025 15:51 β π 7 π 1 π¬ 1 π 0