CyberSecurityTechnologies
We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel
Больше📈 Аналитический обзор Telegram-канала CyberSecurityTechnologies
Канал CyberSecurityTechnologies языкового сегмента Английский является активным участником. Сейчас сообщество объединяет 35 239 подписчиков, занимая 3 761 место в категории Технологии и приложения и 992 место в регионе США.
📊 Показатели аудитории и динамика
С момента создания невідомо проект демонстрирует стремительный рост, собрав аудиторию из 35 239 подписчиков.
Согласно последним данным от 20 июля, 2026, канал показывает стабильную активность. За последние 30 дней изменение числа участников составило -446, а за последние 24 часа — -14, при этом общий охват остаётся высоким.
- Статус верификации: Не верифицирован
- Уровень вовлечённости (ER): Средний показатель вовлечённости аудитории составляет 6.65%. В первые 24 часа после публикации контент обычно набирает 2.94% реакций от общего числа подписчиков.
- Охват публикаций: В среднем каждый пост получает 2 345 просмотров. В течение первых суток публикация набирает 1 035 просмотров.
- Реакции и взаимодействия: Аудитория активно поддерживает контент: среднее количество реакций на один пост — 11.
- Тематические интересы: Контент сосредоточен на ключевых темах, таких как cve-2025, attack, threat, detection, llm.
📝 Описание и контентная политика
Автор описывает ресурс как площадку для выражения субъективного мнения:
“We have been working for YOU for more than 8 years!!!
https://t.me/+9vdG4JOSgY8xMzdi
See also:
https://t.me/Cognitive_Security
https://t.me/CyberSecurityOSINT
https://t.me/Wireless_Cybersecurity
For All Questions: in messages to the channel”
Благодаря высокой частоте обновлений (последние данные получены 21 июля, 2026) канал поддерживает актуальность и высокий уровень охвата публикаций. Аналитика показывает, что аудитория активно взаимодействует с контентом, что делает его важной точкой влияния в категории Технологии и приложения.
Загрузка данных...
| Дата | Привлечение подписчиков | Упоминания | Каналы | |
| 21 июля | 0 | |||
| 20 июля | +1 | |||
| 19 июля | 0 | |||
| 18 июля | 0 | |||
| 17 июля | 0 | |||
| 16 июля | 0 | |||
| 15 июля | 0 | |||
| 14 июля | 0 | |||
| 13 июля | 0 | |||
| 12 июля | 0 | |||
| 11 июля | 0 | |||
| 10 июля | 0 | |||
| 09 июля | 0 | |||
| 08 июля | 0 | |||
| 07 июля | +1 | |||
| 06 июля | +1 | |||
| 05 июля | +1 | |||
| 04 июля | 0 | |||
| 03 июля | +1 | |||
| 02 июля | 0 | |||
| 01 июля | 0 |
| 2 | #SCA
#MLSecOps
"ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks",
Jul 2026.
// novel attacks against PTMs and model hubs called SHADOWPICKLE. SHADOWPICKLE includes three stealthy pickle deserialization attacks that enable malicious behaviors and evade SOTA model scanners. These attacks leverage the external module import mechanism of the Pickle Virtual Machine to execute malicious payloads during deserialization | 637 |
| 3 | #exploit
#Kernel_Security
1⃣ CVE-2026-36425:
OPSWAT AppRemover Arbitrary Process Termination
https://github.com/redteamfortress/CVE-2026-36425
2⃣ CVE-2026-31694:
Unprivileged root via an out-of-bounds write in the FUSE readdir cache
https://cyberstan.co.uk/fuse-readdir-oob
// Disclaimer | 944 |
| 4 | #AIOps
#reversing
"Automatically Attacking Software Reverse Engineering AI Agents", May 2026.
// The paper demonstrates that LLM-based reverse engineering tools (e.g., tool-using systems built around Ghidra) can be deceived through adversarial prompt injections, highlighting new cybersecurity vulnerabilities | 1 257 |
| 5 | #AppSec
#Threat_Research
1⃣ OpenSSL HollowByte: A DoS Hiding in 11 Bytes
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes
2⃣ Windows AppResolver LPE:
From AppContainer to SYSTEM
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system
// PoC for an AppResolver authorization issue fixed in the July 2026 Windows security update and investigated in connection with CVE-2026-50454, a Windows User Interface Core EoP vulnerability
3⃣ wp2shell - Code Trace Deep Dive
https://blog.zsec.uk/wp2shell-code-trace-deep-dive
// wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137 | 1 187 |
| 6 | #CogSec
#Analytics
"Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence", June 2026.
// Modern SOCs face a deepening burnout crisis; 44% of cybersecurity practitioners report experiencing severe work-related stress and burnout. This exhaustion is increasingly driven by the cognitive demands of operationalizing a relentless stream of incoming threat data - particularly the verbose, unstructured CTI reports, vendor advisories, and incident post-mortems. This paper hypothesizes that deploying accessible, free-tier, single-agent LLMs strictly as Human-in-the-Loop "cognitive aids" can effectively automate the initial intake and operationalization of unstructured CTI, achieving a minimum 80% Human-Aligned Mitigation Score | 1 159 |
| 7 | 1⃣ RedLine Stealer
https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster
2⃣ HelloNet campaign - new malicious modules launched through the ViPNet update system
https://securelist.com/tr/hellonet-vipnet/120700
3⃣ DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
4⃣ Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault
5⃣ OkoBot malware framework
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660 | 1 332 |
| 8 | #Analytics
#Threat_Research
An analytical review of the main cybersecurity events (July 05 - 18, 2026)
1⃣ NGINX Vulnerability
// NGINX map Directive Heap Overflow and Data Plane Risk (CVE-2026-42533)
2⃣ Zoom Account Takeover Patch
// CVE-2026-53412 (CVSS 9.8)
3⃣ Firewalld 2.5.0
4⃣ Forgotten UEFI shims undermining Secure Boot
// 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulns
5⃣ A backdoor in Tenda firmware allows root access
// CVE-2026-11405
6⃣ OpenSSH 10.4
7⃣ ASUS bsitf.sys (CVE-2026-13585)
// Arbitrary Physical Memory Mapping 0-day writeup + PoC
8⃣ SpecterOps NTLM Relay Egress Operator Guide
// NTLM relay attacks are far from dead
9⃣ A collection of techniques for process injection on Windows
🔟 Clawdefender v.1.0.4
// Security scanner and input sanitizer for AI agents | 1 465 |
| 9 | #NetSec
#AppSec
#Mobile_security
"MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNs", 2026.
]-> tools
// research investigates the security of the VPN and circumvention tool ecosystem through a combination of empirical system evaluations and user-centered studies | 1 376 |
| 10 | #Research
#Threat_Research
"SoK: PHILTER: Uncovering Security and Functional Gaps in AI-based Phishing Website Detection Literature via an LLM-based Reasoning Framework", Feb. 2026.
// Many SOC teams are implementing AI solutions to filter phishing, but attackers are constantly adapting their tactics. The authors developed PHILTER framework, which uses LLM to automatically audit security systems. The article reveals systemic gaps in 55 popular academic and commercial approaches to phishing detection | 1 501 |
| 11 | #exploit
#Blue_Team_Techniques
LegacyHive: Windows user profile service arbitrary hive load EoP vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive
// The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root
]-> Detections (scripts) for LegacyHive exploitation
]-> BlueHammer (CVE-2026-33825) Yara/Sigma rules
]-> Sigma rule for MiniPlasma (CVE-2020-17103)
]-> Sigma rule for GreenPlasma (CVE-2026-45586)
]-> GreatXML detect rules
]-> RedSun (CVE-2026-41091), BlueHammer, UnDefend (CVE-2026-45498) Detection Pack | 1 463 |
| 12 | // The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root | 1 |
| 13 | #AppSec
#WebApp_Security
"TRANSPARENT: Taint-style Vulnerability Detection in Generic Single Page Applications through Automated Framework Abstraction", Feb. 2026.
]-> Artifact Evaluation
// Presentation of a new static analysis framework, TRANSPARENT, aimed at identifying hidden vulnerabilities (incl. DOM-based XSS and context injection) in modern front-end apps | 1 689 |
| 14 | #SCA
#reversing
"SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMs", Jun 2025.
]-> Repo
// The report focuses on offensive security analysis of secure execution environments. Researchers developed the SNPeek toolkit for side-channel tracing on commercial AMD processors with SEV-SNP technology | 1 859 |
| 15 | #Hardware_Security
Vulnerabilities of Realtek SD Card Reader
Part 1 - Vulnerabilities in RtsPer*sys (PoCs)
Part 2 - DMA vulnerability (PoC)
// CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432, CVE-2024-25476 | 1 753 |
| 16 | #tools
#reversing
#Malware_analysis
"Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications", REcon 2025.
]-> gooMBA - Hex-Rays Decompiler plugin
]-> SiMBA - tool for simplification of linear MBAs expressions
// A presentation of a new mathematical plugin (v.1.3) for Binary Ninja that simplifies complex MBA (Mixed Boolean-Arithmetic) expressions on the fly, often used by malware authors to disguise algorithms. The document includes a code decompilation analysis and examples of corrupted disassembly | 2 368 |
| 17 | #exploit
#Offensive_security
#Red_Team_Tactics
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
]-> PoC (Rust)
// a new call stack spoofing technique that combines thread pool execution, call rescheduling via enumeration callbacks, and indirect system calls into a chain that creates a completely legitimate call stack at the time of syscall execution
// Disclaimer | 2 139 |
| 18 | #AIOps
"When Agents Remember Too Much:
Memory Poisoning Attacks on Large Language Model Agents", Jul 2026.
// GhostWriter - new attack vector, which exploits current memory subsystems in tool-using personal agents to poison their memory store. GhostWriter operates in two phases: injection, where an adversary sends a hidden attack payload to the target agent; and activation, in which the poisoned memory is retrieved | 1 903 |
| 19 | #Hardware_Security
Unfit to Boot: Breaking U-Boot's FIT Signature Verification
https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification
// six vulnerabilities in critical U-Boot logic that is responsible for validating untrusted FIT images - exactly the kind of payload an attacker can tamper with. It is commonly believed that such an attack requires physical access to the device, for example, in order to reflash the SPI flash chip. In reality, this is often not the case.. | 1 891 |
| 20 | #IoT_Security
#WLAN_Security
"Entropy Bootstrapping for Wireless Embedded Systems", July 2026.
]-> https://github.com/perlab-uc3m/randlab
// Zephyr and ESP32 experiments around boot-time entropization for boot-starved wireless sensors | 2 109 |
