CyberSecurityTechnologies
We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel
نمایش بیشتر📈 تحلیل کانال تلگرام CyberSecurityTechnologies
کانال CyberSecurityTechnologies در بخش زبانی انگلیسی بازیگری فعال است. در حال حاضر جامعه شامل 34 121 مشترک است و جایگاه 3 840 را در دسته فناوری و برنامهها و رتبه 1 184 را در منطقه الولايات المتحدة الأمريكية دارد.
📊 شاخصهای مخاطب و پویایی
از زمان ایجاد در невідомо، پروژه رشد سریعی داشته و 34 121 مشترک جذب کرده است.
بر اساس آخرین دادهها در تاریخ 05 اکتبر, 2026، کانال فعالیت پایداری دارد. در ۳۰ روز گذشته تغییر اعضا برابر -418 و در ۲۴ ساعت گذشته برابر -8 بوده و همچنان دسترسی گستردهای حفظ شده است.
- وضعیت تأیید: تأیید نشده
- نرخ تعامل (ER): میانگین تعامل مخاطب 5.84% است و در ۲۴ ساعت نخست پس از انتشار، محتوا معمولاً 2.95% واکنش نسبت به کل مشترکان کسب میکند.
- دسترسی پستها: هر پست به طور میانگین 1 994 بازدید دریافت میکند. در اولین روز معمولاً 1 005 بازدید جمعآوری میشود.
- واکنشها و تعامل: مخاطبان بهطور فعال حمایت میکنند؛ میانگین واکنش به هر پست 6 است.
- علایق موضوعی: محتوا بر موضوعات کلیدی مانند cve-2025, attack, threat, detection, llm تمرکز دارد.
📝 توضیح و سیاست محتوایی
نویسنده این فضا را محل بیان دیدگاههای شخصی توصیف میکند:
“We have been working for YOU for more than 8 years!!!
https://t.me/+9vdG4JOSgY8xMzdi
See also:
https://t.me/Cognitive_Security
https://t.me/CyberSecurityOSINT
https://t.me/Wireless_Cybersecurity
For All Questions: in messages to the channel”
به لطف بهروزرسانیهای پرتکرار (آخرین داده در تاریخ 06 اکتبر, 2026)، کانال همواره بهروز و دارای دسترسی بالاست. تحلیلها نشان میدهد مخاطبان بهطور فعال با محتوا تعامل دارند و آن را به نقطه اثرگذاری مهم در دسته فناوری و برنامهها تبدیل کردهاند.
در حال بارگیری داده...
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 06 اکتبر | 0 | |||
| 05 اکتبر | 0 | |||
| 04 اکتبر | 0 | |||
| 03 اکتبر | 0 | |||
| 02 اکتبر | 0 | |||
| 01 اکتبر | 0 |
| 2 | #NetSec
#Research
#cryptography
"Mind the Gap: Proving and Improving RPKI", 2026.
]-> https://github.com/shaycohen988/routinator-multi-resolver
// This work presents the first rigorous security analysis of the Resource Public Key Infrastructure, an IETF standard for protecting inter-domain routing from basic yet effective attacks: prefix and subprefix hijacks. It focuses on rigorous, modular security specifications and analysis of RPKI, including its interactions with BGP and IP. It shows that existing RPKI deployments do not always meet these conditions, e.g., because of circular dependencies, and proposes standard-compliant improvements that restore them | 911 |
| 3 | #RAG_Security
"Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM", Oct. 2026.
]-> https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack
// GraphRAG pipelines construct auxiliary structures during offline indexing - semantic summaries, hierarchical edges, and pre-computed scores - that determine how retrieval is prioritized at query time. Prior attacks target only instance-level components (nodes, edges, triples), overlooking these schema-level structures. This work formalizes the Auxiliary Schema-Level Entity as a novel attack surface and proposes the 3S Framework (Semantics, Structure, Scoring) for its systematic exploitation. Its Hop-Decayed Influence attack identifies high-impact targets through query-aware influence propagation and corrupts their auxiliary structures post-indexing | 891 |
| 4 | #Malware_analysis
1⃣ CloudSyncD: macOS backdoor hidden in a fake Zoom installer
https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer
2⃣ knock-outd: an undetected port-knocking backdoor in the wild
https://www.virlabs.ai/blog/knock-outd
3⃣ Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis
https://github.com/Kavan00/Android-Projector-C2-Malware | 1 108 |
| 5 | #Tech_book
#Offensive_security
#Red_Team_Tactics
"Red Team Engineering: The Art of Building Offensive Tools and Infrastructure", 2026.
]-> Various course materials, scripts, and configurations | 2 051 |
| 6 | #Analytics
#Threat_Research
An analytical review of the main cybersecurity events (Sep 26 - Oct 03, 2026)
1⃣ Here We Go Again:
Citrix NetScaler DTLS Preauth Memory Overflow
// CVE-2026-88772
2⃣ A Realistic Code Execution Exploit Chain in OpenBao and Vault
3⃣ Attackers abuse ChatGPT to deliver RAT via ClickFix
4⃣ Poper Blocker: The Adblocker That Spies on You
5⃣ PoC for macOS CoreServices Priv. Escalation
// CVE-2026-43786
6⃣ PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578
7⃣ CVE-2026-86950: The Great Glyph Grift
// An in-the-wild iOS bug with a possible WhatsApp zero-click path
8⃣ Stopping a coordinated campaign to distill models
9⃣ nDPI TCP Fingerprint: A Stable, Patent-Free Way to Fingerprint TCP Stacks | 1 479 |
| 7 | #SCA
#compilers
#Kernel_Security
"Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries", Oct. 2026.
]-> Repo
]-> BTR end-to-end exploit on cBPF
// A new BTR (Branch Target Reuse) attack method has been developed, belonging to the Spectre-v2 class, allowing for the bypass of memory isolation mechanisms on systems with Intel, AMD, ARM processors. Memory leaks are initiated during speculative instruction execution during a BTR attack by manipulating JIT compilers. The feasibility of attacking through the cBPF JIT engines in the Linux kernel, Oracle GraalVM, and SpiderMonkey in Firefox has been analyzed | 1 386 |
| 8 | #SCA
#Whitepaper
"Invisible by Default: The Polyglot Smuggler", Sep 2026.
// This paper demonstrates a novel data smuggling mechanism: Sub-Channel Steganography. By weaponizing uninspected MP4 subtitle tracks within a structurally compliant ISO base media file, adversaries can encapsulate malicious payloads and exfiltrate sensitive data. Utilizing entirely native LotL interpreters for bidirectional extraction, this polyglot methodology successfully circumvents network DLP and CDR systems while eliminating the forensic artifacts traditionally monitored by endpoint defenses | 1 329 |
| 9 | #AppSec
1⃣ Sender spoofing in Proton Mail via display-name homograph
https://alonsovidales.github.io/protonmail-sender-spoofing
2⃣ Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610
https://www.intrinsec.com/cve-2026-50610-elevation-privileges-acer-nitrosense
3⃣ Spoofing Arbitrary Apple iCloud Identities
https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities
4⃣ Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)
https://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html | 1 298 |
| 10 | #MLSecOps
#Threat_Research
#Malware_analysis
"The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching", Oct. 2026.
// In this paper, the authors demonstrate with LLMLeak a novel attack vector where malicious software that runs locally but cannot communicate directly with the internet abuses LLMs to establish a covert channel. While inputs that instruct the LLM to send data directly via generated code are easy to detect and network libraries are typically restricted, LLMLeak relies only on the LLM’s tool to fetch websites for further information | 1 267 |
| 11 | #NetSec
JA4Scan: Active Server Fingerprinting for TLS and QUIC
https://foxio.io/blog/introducing-ja4scan-active-server-fingerprinting-for-tls-and-quic
// JA4Scan-TLS and JA4Scan-QUIC - latest additions to the JA4+ suite of fingerprinting methods. Together they fingerprint the TLS and QUIC libraries running on any given server, uncovering both the running TLS/QUIC stack and its configuration | 1 310 |
| 12 | #MLSecOps
"CodeMimicry Exploiting Safety Generalization Lag in Large Language Models via Structured Code Completion", Sep 2026.
]-> https://github.com/lzzzr123/CodeMimicry
// In this work, it identifies a previously underexplored failure mode - safety generalization lag - where alignment trained predominantly on natural language fails to transfer to the code domain. The work shows that this lag induces a code-completion blind spot, allowing malicious intent embedded within syntactically valid code to evade safety mechanisms | 1 422 |
| 13 | #NetSec
#hardening
Cisco Catalyst SD-WAN Hardening Guide
https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide
]-> Cisco IOS XE Software Hardening Guide | 1 463 |
| 14 | #tools
#Hardware_Security
"Implementing Data Diodes Using Commodity Hardware and Open Source Software", Sep 2026.
]-> https://github.com/ClarkuCSCI/pydiode
// The authors tested three existing open source programs for one-way data transfers: netcat, UDPcast, and lidi. Although these programs were unreliable in their default configurations, reliable configurations were identified for UDPcast and lidi. Finally, these findings were incorporated into pydiode, a cross-platform program for reliable one-way data transfers | 1 719 |
| 15 | #Threat_Research
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
]-> How to Fix CVE-2026-88771 and CVE-2026-88772 | 1 665 |
| 16 | #cryptography
"Forging 1024-bit RSA signatures in nearly SNFS time", Sep 2026.
]-> https://github.com/ucsd-hacc/NSNFSSSFSFN
// In this paper, we carry out an attack that allows us to forge arbitrary 1024-bit RSA digital signatures (or decrypt arbitrary ciphertexts) using academic computational resources, without factoring the modulus. This attack reduces RSA security levels below acceptable thresholds for modern cryptographic deployments, and demonstrates a theoretical gap in RSA-based security assumptions and practical parameter choices | 2 170 |
| 17 | #Malware_analysis
1⃣ NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations
2⃣ The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
https://labs.k7computing.com/index.php/the-stealer-factory-unpacking-a-python-based-maas-infostealer-builder
3⃣ Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
https://securelist.com/tr/payload-ransomware-via-group-policy/121335 | 1 653 |
| 18 | #tools
#Malware_analysis
"DeScrypt: A Multi-Tool Framework for Automated Unpacking and Analysis of Malicious Scripts", Aug. 2026.
]-> DeScrypt - automated, recursive unpacking of obfuscated malicious JavaScript and PowerShell
// Scripting languages are increasingly dominant malware vectors that often employ layered obfuscation techniques to slow down manual analysis by reverse engineers and to prevent pattern recognition. Existing deobfuscators are often developed for specific encoding mechanisms or programming languages, resulting in complex analysis pipelines that require multiple tools or techniques to analyze samples fully | 2 219 |
| 19 | #NetSec
#Offensive_security
I’ll hack you via a SYN packet, OFFZONE 2026.
// CVE-2026-10817 in the TCP stack of NetScaler ADC and Gateway. Yes, attackers can leak decrypted data via a truncated TCP timestamp
See also:
]-> NetScaler NSE script
]-> Various scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler) | 1 834 |
| 20 | #NetSec
#Threat_Modelling
Overview of Passive Optical Networks (PONs) Security
https://blog.quarkslab.com/overview-of-passive-optical-networks-pons-security.html
// This article provides a technical overview of the security features in ITU-T specifications: Gigabit-capable PON (GPON), 10-G-capable PON (XG-PON), 10-G-capable Symmetric PON (XGS-PON), Next-generation PON 2 (NG-PON2), and 50-G-capable PON (50G-PON). The analysis covers authentication schemes, key derivation, encryption methods, and associated security implications | 2 001 |
