ru
Feedback
CyberSecurityTechnologies

CyberSecurityTechnologies

Закрытый канал

We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel

Больше

📈 Аналитический обзор Telegram-канала CyberSecurityTechnologies

Канал CyberSecurityTechnologies языкового сегмента Английский является активным участником. Сейчас сообщество объединяет 34 396 подписчиков, занимая 3 776 место в категории Технологии и приложения и 1 033 место в регионе США.

📊 Показатели аудитории и динамика

С момента создания невідомо проект демонстрирует стремительный рост, собрав аудиторию из 34 396 подписчиков.

Согласно последним данным от 15 сентября, 2026, канал показывает стабильную активность. За последние 30 дней изменение числа участников составило -440, а за последние 24 часа — -15, при этом общий охват остаётся высоким.

  • Статус верификации: Не верифицирован
  • Уровень вовлечённости (ER): Средний показатель вовлечённости аудитории составляет 6.08%. В первые 24 часа после публикации контент обычно набирает 2.87% реакций от общего числа подписчиков.
  • Охват публикаций: В среднем каждый пост получает 2 091 просмотров. В течение первых суток публикация набирает 987 просмотров.
  • Реакции и взаимодействия: Аудитория активно поддерживает контент: среднее количество реакций на один пост — 5.
  • Тематические интересы: Контент сосредоточен на ключевых темах, таких как cve-2025, attack, threat, detection, llm.

📝 Описание и контентная политика

Автор описывает ресурс как площадку для выражения субъективного мнения:
We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel

Благодаря высокой частоте обновлений (последние данные получены 16 сентября, 2026) канал поддерживает актуальность и высокий уровень охвата публикаций. Аналитика показывает, что аудитория активно взаимодействует с контентом, что делает его важной точкой влияния в категории Технологии и приложения.

34 396
Подписчики
-1524 часа
-877 дней
-44030 дней
Архив постов
#Research #Hardware_Security "DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes", CCS' 2026. ]-> https://github.com/ddropattack/ddrop // Modern TEEs such as Intel TDX, Intel Scalable SGX, and AMD SEV-SNP rely on memory encryption to protect enclaves and confidential VMs from an untrusted hypervisor or cloud operator. However, to maintain memory performance, scalable cloud TEEs omit cryptographic freshness guarantees. DDRop demonstrates active physical interposition attacks on DDR5 at native bus speeds using a custom low-cost DDR5 RDIMM interposer. By injecting parity errors on DDR5 command/address lines, the interposer silently discards cache line writebacks or swaps chip selects

#AppSec #WebApp_Security The Ghost in the Chat: how a bot that isn't in your group steals messages from Telegram HTML exports https://expatch.com/writeups/telegram-html-export-xss.html // A stored XSS in Telegram Desktop's HTML export pipeline lets a bot that never joins your group plant invisible JavaScript in an inline keyboard button. The payload sleeps in message history for months and detonates the moment a participant exports the chat and opens the HTML file - every message rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten

#Malware_analysis 1⃣ "Eye" spy: Cyclops Blink returns with extended capabilities https://www.sophos.com/en-gb/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities 2⃣ Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270 3⃣ REVSTEALER: analysis of up-and-coming infostealer https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer

#Offensive_security #Red_Team_Tactics Persistence: Component Object Model (COM) hijacking, May 4, 2026. // This post discusses COM hijacking and how COM can be abused and utilized as a means of payload execution and persistence on a target system during the post-exploitation stage

#AppSec #Research #WebApp_Security "IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications", Sep 2026. ]-> https://github.com/GuanhangShiFDU/IDOR-GUARD // Cross-language IDOR reproduction and defense demo for Java, Python, Go, and PHP applications. Evaluated applications include XXL-Job, RuoYi, BootDo, wger, Gitea, Krayin, and Langflow

#AIOps #OpSec #Threat_Research OpenAI agents carried out an undisclosed cyber-attack on RubyGems https://www.rubyhack.ai/#an-openai-agent-swarm-was-responsible-for-this-i // On May 11th, 2026, a significant number of malicious packages were uploaded to the RubyGems repository by automated AI agents, which are hypothesized to originate from internal systems at OpenAI

#tools #Offensive_security SSHamble - research tool for SSH implementations that includes: - Attacks aagainst authentication - Post-session authentication attacks - Pre-authentication state transitions - Authentication timing analysis - Post-session enumeration

#tools #Offensive_security SSHamble is a research tool for SSH implementations that includes: - Aattks aagainst authentication - Post-session authentication attacks - Pre-authentication state transitions - Authentication timing analysis - Post-session enumeration

#reversing #Whitepaper "The Ultimate Reverse Engineering Reference Manual: Deep Dive Technical Guide with C & Assembly Examples", 2025. // 100+ Pages Comprehensive Framework

#MLSecOps #Tech_book "AI-Native LLM Security: Threats, defenses, and best practices for building safe and trustworthy AI", 2025. // Structured around actionable insights, the chapters introduce a secure-by-design methodology, integrating threat modeling and MLSecOps practices to fortify AI systems

#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability 3⃣ Next Nightmare Eclipse Vulnerability // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques 🔟 Beltdown: Escaping the Claude Code sandbox // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user

#DFIR #Cyber_Education #Blue_Team_Techniques "SOC Analyst Advanced Cybersecurity Handbook", First Edition 2026. // A practical cybersecurity reference for analysts progressing from core security concepts to professional SOC investigation, detection engineering, threat hunting, incident response, identity security, cloud monitoring and evidence-driven decision-making

#AIOps #Research "A2ABreak: Systematic Security Analysis of the A2A Protocol", Sep 2026. // The Agent2Agent (A2A) protocol, now governed by the Linux Foundation, is an open standard that enables autonomous AI agents to discover, authenticate with, and delegate tasks to one another across organizational boundaries. Designed to complement the MCP for tool integration, A2A is rapidly emerging as the horizontal communication layer of the multi-agent ecosystem. Yet the protocol's security has received no systematic analysis ...

#Offensive_security #Red_Team_Tactics RedNova: From arbitrary file write to command execution using COM in Windows https://sud0ru.ghost.io/rednova-from-arbitrary-file-write-to-command-execution-using-com-in-windows ]-> implementation of tactics (script) // Analysis of the COM usage method in the RedSun LPE exploit

#Malware_analysis 1⃣ WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android https://calif.io/research/weworm 2⃣ Dissecting a PHP web server rootkit https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit 3⃣ Redis Cryptomining Botnet https://hunt.io/blog/redis-cryptomining-botnet-3562-servers 4⃣ ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager https://blog.talosintelligence.com/clearfake-webdav-infection-chain 5⃣ SloppyRAT: A New Tool For Ransomware Attacks https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks

#NetSec #AppSec #Research #Red_Team_Tactics "Cross User/App Network Attacks - Hijacking TCP Connections and DNS Cache Poisoning via a Malicious User/App (Extended Version)", Sep 2026. ]-> Network Attacks via Malicious Application // This research demonstrates practical network attacks performed by an unprivileged malicious application running on the same host as a victim, in collaboration with an Attacker Remote Node

#Whitepaper #Threat_Research CISA Insider Threat Mitigation Guide, 2026. // This guide provides valuable step-by-step information and best practices for establishing an effective insider threat mitigation program, thereby decreasing the likelihood of harm to individuals, corporations, organizations, and critical infrastructure

#tools #Offensive_security Simulating legitimate Active Directory services on the network: the case of GPO exploitation https://www.synacktiv.com/en/publications/simulating-legitimate-active-directory-services-on-the-network-the-case-of-gpo ]-> GPOddity tool aims to automate gPCFileSysPath attack vectors to exploit vulnerable GPOs, including through NTLM relaying

#Research #MLSecOps "A Survey on Adversarial Attacks and Defenses for Diffusion Models Across Multiple Modalities", Aug 2026. ]-> A curated, task-centric collection of adversarial attacks and defenses for diffusion models across image, video, and 3D // 81+ methods, 55+ datasets & benchmarks, one unified taxonomy

#tools #AIOps "Scanning the Harness: An Empirical Study of Supply-Chain Defects in AI Coding-Agent Configurations", Sep 2026. ]-> data and scripts ]-> tool // AI coding agents such as Claude Code, Cursor, GitHub Copilot, and OpenAI Codex are configured through artifacts developers write and share: instruction files, skills, hooks, MCP server declarations, subagents. This harness is a dependency layer installed from marketplaces and public repositories, running with the developer's privileges, with no lockfile, no install-time check, and no vocabulary for what a component may do