fa
Feedback
CyberSecurityTechnologies

CyberSecurityTechnologies

کانال بسته

📈 تحلیل کانال تلگرام CyberSecurityTechnologies

کانال CyberSecurityTechnologies در بخش زبانی انگلیسی بازیگری فعال است. در حال حاضر جامعه شامل 34 204 مشترک است و جایگاه 3 808 را در دسته فناوری و برنامه‌ها و رتبه 1 125 را در منطقه الولايات المتحدة الأمريكية دارد.

📊 شاخص‌های مخاطب و پویایی

از زمان ایجاد در невідомо، پروژه رشد سریعی داشته و 34 204 مشترک جذب کرده است.

بر اساس آخرین داده‌ها در تاریخ 28 سپتامبر, 2026، کانال فعالیت پایداری دارد. در ۳۰ روز گذشته تغییر اعضا برابر -430 و در ۲۴ ساعت گذشته برابر -17 بوده و همچنان دسترسی گسترده‌ای حفظ شده است.

  • وضعیت تأیید: تأیید نشده
  • نرخ تعامل (ER): میانگین تعامل مخاطب 6.05% است و در ۲۴ ساعت نخست پس از انتشار، محتوا معمولاً 2.89% واکنش نسبت به کل مشترکان کسب می‌کند.
  • دسترسی پست‌ها: هر پست به طور میانگین 2 069 بازدید دریافت می‌کند. در اولین روز معمولاً 988 بازدید جمع‌آوری می‌شود.
  • واکنش‌ها و تعامل: مخاطبان به‌طور فعال حمایت می‌کنند؛ میانگین واکنش به هر پست 7 است.
  • علایق موضوعی: محتوا بر موضوعات کلیدی مانند cve-2025, attack, threat, detection, llm تمرکز دارد.

📝 توضیح و سیاست محتوایی

نویسنده این فضا را محل بیان دیدگاه‌های شخصی توصیف می‌کند:
“We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel”

به لطف به‌روزرسانی‌های پرتکرار (آخرین داده در تاریخ 29 سپتامبر, 2026)، کانال همواره به‌روز و دارای دسترسی بالاست. تحلیل‌ها نشان می‌دهد مخاطبان به‌طور فعال با محتوا تعامل دارند و آن را به نقطه اثرگذاری مهم در دسته فناوری و برنامه‌ها تبدیل کرده‌اند.

34 204
مشترکین
-1724 ساعت
-1077 روز
-43030 روز
آرشیو پست ها
#Purple_Team_Exercises Dump Encoding Library (WerEnc.dll) https://ipurple.team/2026/09/21/dump-encoding-library // For years threat actors abused living off the land binaries to execute code. The dump encoding library is the first case disclosed in public that documents, how a threat actor can adopt the encryption used by Microsoft during the crash dump of PPL processes, in their implant

#Whitepaper #Blue_Team_Techniques "Bot or Not? Detecting AI-Driven Web Traffic Using Network Metadata Analysis", Sep 2026. ]-> Repo // This detection method is lightweight, non-intrusive, and easily integrated into existing security toolsets, offering defenders a scalable alternative to traditional bot detection and mitigation techniques

#NetSec #AppSec ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce#the-vulnerability-and-attack-chain // A format string vulnerability that's been lurking 25+ years, and the PSK oracle chain that unlocks it

#Kernel_Security #Automotive_Security "Exploiting USB on a Tesla IVI with Raspberry Pi Devices to bypass KASLR", Insomnihack 2026. // USB Attacks in the Wild. The vulnerability (CVE-2024-53150) was in the usb/sound subsystem of the Linux Kernel and, at the time of its initial discovery, was present on Tesla's IVI Software version 2025.20.3 which was running Linux Kernel Version 5.4.284

#Kernel_Security #Threat_Research A quartet of Linux local root vulnerabilitis: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill https://heyitsas.im/posts/lpe-quartet // Four more Linux LPEs; two of the corruption bugs are reachable remotely under very specific circumstances, with one theoretically remote-groomable to remote root. The vulnerabilities are DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469)

#Infosec_Standards NIST SP 800-82 r4 IPD: "Guide to Operational Technology (OT) Security", Sep 2026.

#exploit #Red_Team_Tactics Windows Exploitation Techniques: Dangling COM Object Registrations https://projectzero.google/2026
#exploit #Red_Team_Tactics Windows Exploitation Techniques: Dangling COM Object Registrations https://projectzero.google/2026/09/windows-dangling-com.html // This post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows 11 (CVE-2026-66804)

#AIOps #Offensive_security "Red-Teaming Auto Mode: Improving Blocking Classifiers Against Malign Coding Agents", Anthropic, Sep 2026. ]-> https://github.com/safety-research/red-teaming-auto-mode // ..By detailing red-teaming methodology and highlighting new attack vectors, we aim to help defenders evaluate their mitigations against the possibility of persistent malign coding agents

#exploit #Kernel_Security RustyTux - Linux kernel LPE exploit for a strparser race https://github.com/m0x41nos/RustyTux ]-> ESP-in-TCP msg_timer_work Race Timelines ]-> Delta Callback Gadget // The exploit attempts to derive the randomized kernel base through an x86 prefetch timing side channel, race ESP-in-TCP receive parsing against socket teardown, and reclaim the freed espintcp_ctx with user-key payloads

#SCA #Hardware_Security "Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel", Sep 2026. ]-> Artifacts // Recent generations of Apple MacBooks embed an IMU within their unibody chassis for device orientation and motion sensing. However, this IMU inadvertently captures not only intended device-level information but also subtle physical vibrations from user interactions and the surrounding environment. These signals establish a novel, previously unexplored side channel.. // Disclaimer

#WLAN_Security WPA3 Denial of Service: SAE Resource Exhaustion https://www.nccgroup.com/research/wpa3-denial-of-service-sae-r
#WLAN_Security WPA3 Denial of Service: SAE Resource Exhaustion https://www.nccgroup.com/research/wpa3-denial-of-service-sae-resource-exhaustion // Exploring availability attacks against WPA3-SAE, from the early Dragonblood research to lesser-known attacks that remain highly relevant today See also: ]-> How is your Wi-Fi connection today? DoS attacks on WPA3-SAE

#Malware_analysis 1⃣ SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch 2⃣ New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant 3⃣ HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2 4⃣ Neural Override - AI-Orchestrated RAT With SCADA Tasking https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-15-Neural-Override-AI-Orchestrated-RAT.txt

#MLSecOps "Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines", Sep 2026. ]-> Repo // The attack exploits the value alignment between the tool’s stated goal and the user’s intent, making refusal functionally equivalent to breaking the tool. Concretely, a legitimate breach scanner and a data harvester request identical data through identical interfaces; the protocol provides no mechanism for the model to verify that a server’s claimed purpose matches its actual implementation

#reversing #Tech_book "Practical Reverse Engineering: x86, x64, ARM, Windows Kernel, Reversing Tools, and Obfuscation", 2014. // The book represents something that we wish we had when we started learning about reversing more than 15 years ago. At the time, there was a dearth of books and online resources; we learned the art primarily through friends and independent trial-and-error experiments. The cybersecurity "industry" was also non-existent back then. Today, the world is different. Numerous blogs, forums, books, and in-person classes aim to teach reverse engineering. These resources vary greatly in quality. Some are sub-standard but shamelessly published or offered to take advantage of the rise in demand for cybersecurity..

#Tech_book #Offensive_security "Linux Shell Scripting for Hackers: Automate and scale your hacking process with bash scripting", 2026. ]-> https://github.com/PacktPublishing/Linux-Shell-Scripting-for-Hackers

#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 12-19, 2026) 1⃣ Thai Broadband Provider Targeted via FortiGate SSL-VPN and MeshCentral Persistence 2⃣ CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026 3⃣ Cisco Identity Services Engine Authentication Bypass Vulnerability // CVE-2026-76460 4⃣ PolarProxy 2.0.2 Released // PolarProxy can now tunnel outgoing connections through SOCKS proxies and supports environment variables as an alternative to CLI arguments 5⃣ Acronis LPE due to insecure file permissions // CVE-2026-87886 6⃣ Click2Shell: Preauth WP Core Theme Preview Injection to RCE Chain 7⃣ Attackers exploited MikroTik RouterOS vulnerabilities to perform an unauthenticated "MikroTik" administration takeover 8⃣ StyleSmuggler Attacks (Magento/Adobe Commerce) // CVE-2026-75650 9⃣  A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE) 🔟 Pipelock v.3.5.0 - Firewall for AI agents // DLP scanning, SSRF protection, bidirectional MCP scanning, tool poisoning detection, and workspace integrity monitoring

#MLSecOps #Threat_Research Hacking OpenAI https://www.hacktron.ai/blog/hacking-openai // A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories

#NetSec #Analytics "Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model", Sep 2026. // Network-layer VPN appliances still anchor enterprise remote access, and repeated mass exploitation of these appliances has made them a recurring initial access vector for ransomware operators. Identity-aware reverse proxies, usually marketed under the Zero Trust Network Access label, are positioned as the replacement. Whether they actually align better with Zero Trust than a modern VPN, or only claim to, has not been tested objectively?

#Malware_analysis LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/LausivLoader+analysis+or+how+to+pass+data+between+malware+stages/33348

#Research #Blue_Team_Techniques "Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting", Sep 2026. // This study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language and CrowdStrike Query Language hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM