Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
Show more๐ Analytical overview of Telegram channel Malware News
Channel Malware News (@malwr) in the English language segment is an active participant. Currently, the community unites 14 456 subscribers, ranking 8 948 in the Technologies & Applications category and 2 646 in the USA region.
๐ Audience metrics and dynamics
Since its creation on ะฝะตะฒัะดะพะผะพ, the project has demonstrated rapid growth, gathering an audience of 14 456 subscribers.
According to the latest data from 11 June, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 575 over the last 30 days and by 21 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 6.12%. Within the first 24 hours after publication, content typically collects 2.39% reactions from the total number of subscribers.
- Post reach: On average, each post receives 884 views. Within the first day, a publication typically gains 345 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 5.
- Thematic interests: Content is focused on key topics such as threat, kernel, cve-2025, actor, attack.
๐ Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
โThe latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwrโ
Thanks to the high frequency of updates (latest data received on 12 June, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
Data loading in progress...
| Date | Subscriber Growth | Mentions | Channels | |
| 12 June | +8 | |||
| 11 June | +21 | |||
| 10 June | +24 | |||
| 09 June | +20 | |||
| 08 June | +23 | |||
| 07 June | +13 | |||
| 06 June | +24 | |||
| 05 June | +40 | |||
| 04 June | +11 | |||
| 03 June | +24 | |||
| 02 June | +26 | |||
| 01 June | +13 |
| 2 | Weaponizing SMB Shares to Steal Domain Credentials
In internal penetration tests and red team engagements, an account with write privileges over an SMB share can be your best bet to go furtherContinue reading
https://securitycafe.ro/2026/04/21/weaponizing-smb-shares-to-steal-domain-credentials/
๐@malwr | 305 |
| 3 | Reminder: We take ads
@SirMalware | 267 |
| 4 | S3cur3Th1sSh1t/NimSyscallPacker
https://github.com/S3cur3Th1sSh1t/NimSyscallPacker
This tool was made public after a talk at x33fcon and is now considered deprecated and is not maintained anymore. This Packer can be used to pack any C# Assembly, PE-File or Shellcode into a Nim binary. It will encrypt the target payload, build the corresponding Nim source code according to the given arguments and compiles it to an Nim binary.
๐@malwr | 269 |
| 5 | SpaceMoehre/windbg_struct_importer: Import local header files into your windbg to use the macro !dt on them
https://github.com/SpaceMoehre/windbg_struct_importer
๐@malwr | 247 |
| 6 | User-to-User Authentication: Down the Rabbit Hole - Part 1
A deep dive into Kerberos User-to-User (U2U) authentication and the primitives behind UnPAC-the-Hash, ADCS and shadow credentials.
https://specterops.io/blog/2026/06/09/user-to-user-authentication-down-the-rabbit-hole-part-1/
๐@malwr | 264 |
| 7 | OceanLotus: From external espionage to domestic targeting
ESET researchers show how OceanLotus, a Vietnam-aligned APT group, has put an increasing focus on domestic espionage between 2024 and 2026.
https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/
๐@malwr | 356 |
| 8 | From SQLi to RCE โ Exploiting LangGraphโs Checkpointer
https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/
๐@malwr | 423 |
| 9 | Cyber-Enabled Maritime Sanctions Evasion
Discover how Iranian and Russian shadow fleets use a vast network of fake maritime websites and fraudulent documents to evade international sanctions
https://www.recordedfuture.com/research/cyber-maritime-sanctions-evasion
๐@malwr | 382 |
| 10 | The Adversarial PE Analysis Series, Part 1 โ Why PE Parsers Break: Introducing the 99 Adversarialโฆ
An exploration of malformed Portable Executable structures and how analysis tools really behave when the rules stop making sense.
https://medium.com/@malx-labs/the-adversarial-pe-analysis-series-part-1-why-pe-parsers-break-introducing-the-99-adversarial-1769556ab473
๐@malwr | 409 |
| 11 | The shift from an โN-dayโ world toward an โN-hourโ reality. The shift is happening because advanced AI can automate the expert reverse-engineering and exploit-development work that used to take skilled humans days or weeks, reducing the time from patch release to working exploit to mere hours.
@SirMalware | 523 |
| 12 | The shift from from an โN-dayโ world toward an โN-hourโ reality. The shift is happening because advanced AI can automate the expert reverse-engineering and exploit-development work that used to take skilled humans days or weeks, reducing the time from patch release to working exploit to mere hours.
@SirMalware | 1 |
| 13 | N-days \ red.anthropic.com
https://red.anthropic.com/2026/n-days/
Modern frontier LLMs are dramatically accelerating the exploitation of N-day vulnerabilities (publicly disclosed bugs that many systems have not yet patched). In controlled experiments, Anthropic found that advanced models could autonomously analyze software patches, reconstruct the underlying vulnerability, and build working proof-of-concept exploits in minutes to hours. On both open-source Firefox bugs and closed-source Windows kernel vulnerabilities, their strongest model generated successful exploits at a speed that far outpaced typical enterprise patch deployment timelines.
๐@malwr | 498 |
| 14 | IDA 9.4 Beta | Hex-Rays Docs.
https://docs.hex-rays.com/release-notes/9_4beta
๐@malwr | 507 |
| 15 | Turning Up the Heat: Hacking Trane HVAC Controllers
Team82 identified a chain of severe, highly exploitable vulnerabilities in the widely deployed Trane Tracer SC+ HVAC controller affecting up to version v5.20.1362. These vulnerabilities could allow an unauthenticated remote attacker to gain complete control over a critical building management system. Trane has patched ...
https://claroty.com/team82/research/turning-up-the-heat-hacking-trane-hvac-controllers
๐@malwr | 538 |
| 16 | JeanExtreme002/PyMemoryEditor: A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python .
https://github.com/JeanExtreme002/PyMemoryEditor
๐@malwr | 531 |
| 17 | Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html
๐@malwr | 507 |
| 18 | How to Detect PowerShell Encoded Commands in Microsoft Sentinel (KQL)
A working SOC analyst's guide to detecting PowerShell -EncodedCommand abuse using KQL in Microsoft Sentinel. Production-ready detection rules with tuning notes.
http://socauthority.com/blog/how-to-detect-powershell-encoded-commands-sentinel-kql/
๐@malwr | 505 |
| 19 | matheusht/redthread: An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision evaluations, and synthesizing validated guardrails for safe self-improvement.
https://github.com/matheusht/redthread
๐@malwr | 488 |
| 20 | 2026-06-09: Atomic macOS (AMOS) Stealer infection
https://www.malware-traffic-analysis.net/2026/06/09/index.html
๐@malwr | 443 |
Available now! Telegram Research 2025 โ the year's key insights 
