Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
إظهار المزيد📈 نظرة تحليلية على قناة تيليجرام Malware News
تُعد قناة Malware News (@malwr) في القطاع اللغوي الإنكليزية لاعباً نشطاً. يضم المجتمع حالياً 14 431 مشتركاً، محتلاً المرتبة 8 964 في فئة التكنولوجيات والتطبيقات والمرتبة 2 657 في منطقة الولايات المتحدة.
📊 مؤشرات الجمهور والحراك
منذ تأسيسه في невідомо، حقق المشروع نمواً سريعاً وجمع 14 431 مشتركاً.
بحسب آخر البيانات بتاريخ 09 يونيو, 2026، تحافظ القناة على نشاط مستقر. خلال آخر 30 يوماً تغيّر عدد الأعضاء بمقدار 584، وفي آخر 24 ساعة بمقدار 20، مع بقاء الوصول العام مرتفعاً.
- حالة التحقق: غير موثّقة
- معدل التفاعل (ER): يبلغ متوسط تفاعل الجمهور 8.07%. وخلال أول 24 ساعة من النشر يحصد المحتوى عادةً 2.89% من ردود الفعل نسبةً إلى إجمالي المشتركين.
- وصول المنشورات: يحصل كل منشور على متوسط 1 162 مشاهدة. وخلال اليوم الأول يجمع عادةً 416 مشاهدة.
- التفاعلات والاستجابة: يتفاعل الجمهور بانتظام؛ متوسط التفاعلات لكل منشور يبلغ 9.
- الاهتمامات الموضوعية: يركز المحتوى على مواضيع رئيسية مثل threat, kernel, cve-2025, actor, attack.
📝 الوصف وسياسة المحتوى
يصف المؤلف القناة بأنها مساحة للتعبير عن الآراء الذاتية:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
بفضل وتيرة التحديث المرتفعة (أحدث البيانات بتاريخ 10 يونيو, 2026) تحافظ القناة على حداثتها ومستوى وصول مرتفع. وتُظهر التحليلات تفاعلاً نشطاً من الجمهور، ما يجعلها نقطة تأثير مهمة ضمن فئة التكنولوجيات والتطبيقات.
جاري تحميل البيانات...
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 10 يونيو | +24 | |||
| 09 يونيو | +20 | |||
| 08 يونيو | +23 | |||
| 07 يونيو | +13 | |||
| 06 يونيو | +24 | |||
| 05 يونيو | +40 | |||
| 04 يونيو | +11 | |||
| 03 يونيو | +24 | |||
| 02 يونيو | +26 | |||
| 01 يونيو | +13 |
| 2 | The shift from from an “N-day” world toward an “N-hour” reality. The shift is happening because advanced AI can automate the expert reverse-engineering and exploit-development work that used to take skilled humans days or weeks, reducing the time from patch release to working exploit to mere hours.
@SirMalware | 1 |
| 3 | N-days \ red.anthropic.com
https://red.anthropic.com/2026/n-days/
Modern frontier LLMs are dramatically accelerating the exploitation of N-day vulnerabilities (publicly disclosed bugs that many systems have not yet patched). In controlled experiments, Anthropic found that advanced models could autonomously analyze software patches, reconstruct the underlying vulnerability, and build working proof-of-concept exploits in minutes to hours. On both open-source Firefox bugs and closed-source Windows kernel vulnerabilities, their strongest model generated successful exploits at a speed that far outpaced typical enterprise patch deployment timelines.
🎖@malwr | 91 |
| 4 | IDA 9.4 Beta | Hex-Rays Docs.
https://docs.hex-rays.com/release-notes/9_4beta
🎖@malwr | 150 |
| 5 | Turning Up the Heat: Hacking Trane HVAC Controllers
Team82 identified a chain of severe, highly exploitable vulnerabilities in the widely deployed Trane Tracer SC+ HVAC controller affecting up to version v5.20.1362. These vulnerabilities could allow an unauthenticated remote attacker to gain complete control over a critical building management system. Trane has patched ...
https://claroty.com/team82/research/turning-up-the-heat-hacking-trane-hvac-controllers
🎖@malwr | 259 |
| 6 | JeanExtreme002/PyMemoryEditor: A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python .
https://github.com/JeanExtreme002/PyMemoryEditor
🎖@malwr | 383 |
| 7 | Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html
🎖@malwr | 393 |
| 8 | How to Detect PowerShell Encoded Commands in Microsoft Sentinel (KQL)
A working SOC analyst's guide to detecting PowerShell -EncodedCommand abuse using KQL in Microsoft Sentinel. Production-ready detection rules with tuning notes.
http://socauthority.com/blog/how-to-detect-powershell-encoded-commands-sentinel-kql/
🎖@malwr | 395 |
| 9 | matheusht/redthread: An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision evaluations, and synthesizing validated guardrails for safe self-improvement.
https://github.com/matheusht/redthread
🎖@malwr | 378 |
| 10 | 2026-06-09: Atomic macOS (AMOS) Stealer infection
https://www.malware-traffic-analysis.net/2026/06/09/index.html
🎖@malwr | 331 |
| 11 | Reminder: We accept ads
@SirMalware | 456 |
| 12 | dmtrKovalenko/lofree-hypace-reverse-engineer: Reverse engineered firmware flashing protocol for lofree hypace mouse
https://github.com/dmtrKovalenko/lofree-hypace-reverse-engineer
🎖@malwr | 472 |
| 13 | NightCity Tracer
NightCity Tracer — a cyberpunk network intrusion simulation game. Hack, trace, and outmaneuver corporate security in real-time tactical scenarios.
https://thomassimmer.github.io/nightcity-tracer/
🎖@malwr | 391 |
| 14 | Synthetic APTs: the Collapse of TTP-Based Attribution
Cyber Threat Intelligence CTI attribution relies on identifying the Tactics, Techniques, and Procedures TTPs that distinguish one threat actor from another. This approach presupposes that each adversary leaves a recognizable operational fingerprint. This work investigates whether AI driven adversary emulation challenges that presupposition. We deploy agents from our Cybersecurity SuperIntelligence CSI framework, configured as five Advanced Persistent Threat APT groups, APT28, APT29, APT41, APT44, and Lazarus Group, against AI driven Defender agents across two cyber ranges provided by CYBER RANGES, equipped with defensive software Wazuh, Velociraptor, Elasticsearch and active AI driven defenders: an enterprise network and a military infrastructure. Across 20 experiments using two defender models, a binary pattern emerges: all 10 Enterprise range experiments resulted in compromise 2 to 12 hosts per experiment, while all 10 Military range experiments were successfully defended or resulted in stalemates, regardless of APT profile or defender model. In 8 of 10 Enterprise experiments, attackers independently weaponized the defender's own Velociraptor endpoint management platform as a command and control channel, a convergent behavior not encoded in any threat intelligence profile. We argue that in the AI era, wherein agents can be deployed provided the right models are available and subject to the right scaffolding and agentic configuration, the entry barrier for operating like a nation state APT collapses: beyond nation states, individuals can now act like commonly identified threat actors, and with it, fundamentally undermine TTP based attribution.
https://arxiv.org/abs/2606.07158
🎖@malwr | 402 |
| 15 | analysis/pure_basic_640 at main · 4next-re/analysis
https://github.com/4next-re/analysis/tree/main/pure_basic_640
🎖@malwr | 498 |
| 16 | Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
Deep dive into SStar Agent: a cross-platform RAT with Chrome extension harvesting, full filesystem exfiltration, and Windows-only keylogging delivered via npm supply chain attack.
https://www.iru.com/blog/sstar-agent
🎖@malwr | 492 |
| 17 | Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exploited entry point open long after the fix ships.
https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html
🎖@malwr | 613 |
| 18 | Take these AIs seriously. Get familiar with them, engage with them professionally, and definitely use them. That's the true future you should be prepared for. Believe me! | 664 |
| 19 | Is Claude Mythos Killing Cybersecurity Careers?
https://osintteam.blog/is-claude-mythos-killing-cybersecurity-careers-01ef96311ab2
🎖@malwr | 665 |
| 20 | About ETW Internals: Architecture, Hooking, Tampering, and Detection
Event Tracing for Windows is the telemetry fabric behind a large part of modern Windows security work. EDRs, anti-cheats, forensic tools, WPR, Sysmon-adjacent pipelines, and many Microsoft components all lean on it. Attackers know that too, so ETW ends up being both a signal source and a target. This post walks through ETW from the inside: how providers reach sessions, where buffers and enable slots live, which parts are public API, which parts are private kernel state, and where tampering actually changes what a defender sees. The reference target is Windows 11 25H2 (ntoskrnl 10.0.26200.x) with 24H2 deltas called out.…
https://kernullist.github.io/kernullist-blog/posts/etw-internals-deep-dive/
🎖@malwr | 629 |
متاح الآن! بحث تيليغرام 2025 — أهم رؤى العام 
