uk
Feedback
Source Byte

Source Byte

Відкрити в Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

Показати більше
8 113
Підписники
+1524 години
+627 днів
+29330 день
Архів дописів
Repost from reconcore
CobaltStrike-Linux-Beacon
Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons
#poc #beacon #linux @reconcore

The general counsel of Paragon, uploaded a picture on Linkedin today showing the Paragon spyware control panel. https://x.com
The general counsel of Paragon, uploaded a picture on Linkedin today showing the Paragon spyware control panel. https://x.com/DrWhax/status/2021608609595945442?s=20

Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector https://www.csa.gov.sg/news-events/press-releases/largest-multi-agency-cyber-operation-mounted-to-counter-threat-posed-by-advanced-persistent-threat--apt--actor-unc3886-to-singapore-s-telecommunications-sector/

Repost from N/a
New post: "Browser Dumping — The Core Tactic Behind Most Infostealers" (This blog is mainly for sharing my personal notes and learning journey)
This blog contains my own research collected from the internet, along with ideas from other blogs and studies. While many parts are written in my own words, the Most sections were copied directly from external sources because they were already very well written and clearly expressed. This blog is mainly for sharing my personal notes and learning journey.
#stealer #browser #Chrome_AppBound

SectorC: a C compiler in 512 bytes https://xorvoid.com/sectorc.html

Repost from MILITA CAMP
● پس از چراغ سبز آقا طاها نیروی هوایی ارتش اوکراین یک فروند پهپاد انتحاری‌ شاهد ۱۳۶ روسی را با جت جنگنده F-16 ساقط نمود. @Milita_Camp

Israel’s zero-click future: How cyber veterans are reinventing offensive intelligence https://www.jpost.com/israel-news/defense-news/article-885789

Decompiler internals: microcode This presentation is about the Hex-Rays Decompiler. It is a de-facto standard tool used by the security professionals. Its main features include:
• Interactive, fast, robust, and programmable decompiler • Can handle x86, x64, ARM, ARM64, PowerPC • Runs on top of the IDA Pro disassembler • Has been evolving for more than 10 years • Internals have not been published yet • Namely, the intermediate language
https://blackhat.com/us-18/briefings/schedule/#decompiler-internals-microcode-10076

Metro4Shell: Exploitation of React Native’s Metro Server in the Wild https://www.vulncheck.com/blog/metro4shell_eitw#network-infrastructure #CVE-2025-11953 , #glassworm , #rust Samples : [ Link ]

i wonder what is Hezbollah threat actor name🤔

Hackers, Epstein, & Zero-Days: An Insider's Guide to the Exploit Economy What do the NSA, Mossad, a ransomware gang, and Hezbollah have in common? They all shop in the same marketplace. The latest Epstein file dump revealed something my industry has known for years but rarely discusses publicly: the exploit economy has no loyalty. The same vulnerability that protects you can be weaponized against you—depending on who buys it first. https://x.com/gothburz/status/2018695140718649469

Iranian,chines,north korea ... APTs trying their best to prove their attack have an impact like by sharing POCs while God tier APTs like 8200 , NSA , BND hear about about their impact in news and how their malware change whole cyber ecosystem, every time they do a sabotage. (their espionage is not something you detect)

Exclusive: US used cyber weapons to disrupt Iranian air defenses during 2025 strikes The U.S. military last year digitally disrupted Iranian air missile defense systems as part of a coordinated operation to destroy the country’s nuclear program, according to several U.S. officials, another sign of America’s growing comfort with employing cyber weapons in warfare.The strike on a separate military system connected to the nuclear sites at Fordo, Natanz and Isfahan helped to prevent Iran from launching surface-to-air missiles at American warplanes that had entered Iranian airspace, the officials said. https://therecord.media/iran-nuclear-cyber-strikes-us

Bypassing Kernel32.dll for Fun and Nonprofit https://ziglang.org/devlog/2026/#2026-02-03

Repost from N/a
Slides and recordings for our @FOSDEM talks are up! Join [Björn Ruytenberg] and [Sina Karvandi] for an in-depth introduction
Slides and recordings for our @FOSDEM talks are up! Join [Björn Ruytenberg] and [Sina Karvandi] for an in-depth introduction into @HyperDbg 's features and internals, or find out what's the latest in anti-anti-debugging techniques and HV transparency for malware reversing: - https://fosdem.org/2026/schedule/event/APB9WC-mbec_slat_and_hyperdbg_hypervisor-based_kernel-_and_user-mode_debugging/ - https://fosdem.org/2026/schedule/event/CDPRDX-invisible_hypervisors_debugging_with_hyperdbg/

according to Coincap around 1 billion dollars being blocked by tether company ! following addresses are leaked and publicly available,this wallet addresses are related to Iran Central bank , it's so funny Iran Gov still relay on Emirati companies to bypass sanctions, aren't they an ally to Israel ? TBaxHwoXQjAmiNZgRKECoA3b6fsrtmoZvB THwJSxR9qREsgEQjX1cpRw4Rw9WbmPSHVh source : link

The Central Bank of Iran has acquired US dollar stablecoins worth at least half a billion dollars https://www.elliptic.co/blo
The Central Bank of Iran has acquired US dollar stablecoins worth at least half a billion dollars https://www.elliptic.co/blog/iran-has-acquired-us-dollar-stablecoins-worth-at-least-half-a-billion-dollars

The CTI team at Graph Inc. has successfully identified and tracked a large-scale campaign leveraging a supply chain attack, which spreads globally through the compromise of mirror websites and the poisoning of trusted Git repositories, backed by a large and well-structured infrastructure, multiple malware families, and advanced infostealer techniques. The campaign represents a new level of operational maturity, combining: - Compromised legitimate websites & GitHub repositories - Cross-platform malware delivery at scale - Credential, document, browser data, and access-token theft - Evasion techniques designed to bypass traditional security controls #apt #iran #hacking #malware #github #threathunting #threatintel

Virus disguised Sogou input method, malicious script embedded in formal signature https://zhuanlan.zhihu.com/p/19495536691891
Virus disguised Sogou input method, malicious script embedded in formal signature https://zhuanlan.zhihu.com/p/1949553669189116360