𝙍𝙤𝙤𝙩𝙎𝙚𝙘
Open in Telegram
Free content of OFF-SEC, SANS, ec-council, INE, eLearnSecurity, udemy coupons and many more #Malware_analysis #RootSec
Show more1 773
Subscribers
+224 hours
+127 days
+2830 days
Posts Archive
1 774
Repost from CrackCodes 🇮🇳
🇮🇳नान्यो मन्त्रो नान्यचिन्तनं नान्यद्देशहिताद्धि ऋते।
🇮🇳देश के हित के अलावा कोई अन्य उद्देश्य, कोई अन्य विचार या और कुछ भी नहीं है।
There is no purpose, thought, or concern beyond the nation's interest.
वन्दे नितरां भारतवसुधाम्। 🙏
📢 A good nation requires a great vision and people who will put in hard work to make it happen. But if you want a GREAT nation, it takes more than that, it demands sacrifices, a lot of them.
And our country is full of people who will sacrifice everything they have. In fact, सेवा (service), दान (charity) and बलिदान (sacrifice) are rooted in our culture, and these values are what our forefathers taught us.
We will inculcate these values in us and we will make a great Nation.
गणतंत्र दिवस पर सभी को हार्दिक शुभकामनाएं 🎉
🇮🇳जय हिंद जय भारत 🫡
1 774
Repost from Rootsec
#tools
#Kernel_Security
#Offensive_security
AV/EDR Killer: AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)
https://github.com/xM0kht4r/AV-EDR-Killer
// This project demonstartes how a legit, and signed driver can be weponized to gain kernel level access
1 774
Repost from Rootsec
#Whitepaper
#Threat_Research
#Threat_Modelling
"Cyber Threat Intelligence Capability Maturity Model",
Ver.1.3, Jan 2026.
// In version 1.3, we provided significant fine-tune updates to the various domain use cases and practices based up on feedback from the community. The assessment tool was updated to reflect the updates
1 774
Repost from Rootsec
#info
#AIOps
#MLSecOps
OWASP Cheat Sheet Series:
1⃣ AI Agent Security Cheat Sheet
2⃣ Secure AI/ML Model Ops Cheat Sheet
3⃣ LLM Prompt Injection Prevention Cheat Sheet
See also:
]-> All [100+] OWASP Security Cheat Sheets
1 774
Repost from Rootsec
#AIOps
#MLSecOps
"CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents", Jan 2026.
]-> Defeating Prompt Injections by Design
// The authors apply architectural isolation to CUAs by splitting planning from perception, then use Single Shot Planning where a trusted planner generates a complete branching execution graph before any potentially malicious UI observation
1 774
Repost from Rootsec
#Malware_analysis
1⃣ Decoding malware C2 with CyberChef
https://www.netresec.com/?page=Blog&month=2026-01&post=Decoding-malware-C2-with-CyberChef
2⃣ VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun
https://research.checkpoint.com/2026/voidlink-early-ai-generated-malware-framework
3⃣ SolyxImmortal: Python Malware Analysis
https://www.cyfirma.com/research/solyximmortal-python-malware-analysis
4⃣ From Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers
https://www.trendmicro.com/es_es/research/26/a/analysis-of-the-evelyn-stealer-campaign.html
1 774
#MLSecOps
#Offensive_security
"Reasoning Hijacking: Subverting LLM Classification via Decision-Criteria Injection", 2026.
]-> Criteria Attack Dataset
// Current LLM safety research predominantly focuses on mitigating Goal Hijacking, preventing attackers from redirecting a model's high-level objective. In this paper, we argue that this perspective is incomplete and highlight a critical vulnerability in Reasoning Alignment. We propose a new adversarial paradigm: Reasoning Hijacking and instantiate it with Criteria Attack, which subverts model judgments by injecting spurious decision criteria without altering the high-level task goal
1 774
#NetSec
#Analytics
"VPN Risk Report",
Zscaler ThreatLabz, 2025.
// Key Findings:
- Obsolescence of VPNs Accelerates
- Escalation of VPN-Exploited Cyberattacks and Ransomware Concerns
- End-User Dissatisfaction Influences Security Redirection
- The Zero Trust Shift from VPN: From Concept to Implementation
1 774
#AIOps
#MLSecOps
#Threat_Research
"Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale", 2026.
// The rise of AI agent frameworks has introduced agent skills, modular packages containing instructions and executable code that dynamically extend agent capabilities. While this architecture enables powerful customization, skills execute with implicit trust and minimal vetting, creating a significant yet uncharacterized attack surface
