Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
Ko'proq ko'rsatish📈 Telegram kanali Malware News analitikasi
Malware News (@malwr) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 14 452 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 8 949-o'rinni va AQSH mintaqasida 2 652-o'rinni egallagan.
📊 Auditoriya ko‘rsatkichlari va dinamika
невідомо sanasidan buyon loyiha tez o‘sib, 14 452 obunachiga ega bo‘ldi.
10 Iyun, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 572 ga, so‘nggi 24 soatda esa 24 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.
- Tasdiqlash holati: Tasdiqlanmagan
- Jalb etish (ER): Auditoriya o‘rtacha 7.06% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 2.51% ini tashkil etuvchi reaksiyalarni to‘playdi.
- Post qamrovi: Har bir post o‘rtacha 1 019 marta ko‘riladi; birinchi sutkada odatda 362 ta ko‘rish yig‘iladi.
- Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 6 ta reaksiya keladi.
- Tematik yo‘nalishlar: Kontent threat, kernel, cve-2025, actor, attack kabi asosiy mavzularga jamlangan.
📝 Tavsif va kontent siyosati
Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
Yuqori yangilanish chastotasi (oxirgi ma’lumot 11 Iyun, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.
Ma'lumot yuklanmoqda...
| Sana | Obunachilarni jalb qilish | Esdaliklar | Kanallar | |
| 11 Iyun | +21 | |||
| 10 Iyun | +24 | |||
| 09 Iyun | +20 | |||
| 08 Iyun | +23 | |||
| 07 Iyun | +13 | |||
| 06 Iyun | +24 | |||
| 05 Iyun | +40 | |||
| 04 Iyun | +11 | |||
| 03 Iyun | +24 | |||
| 02 Iyun | +26 | |||
| 01 Iyun | +13 |
| 2 | From SQLi to RCE – Exploiting LangGraph’s Checkpointer
https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/
🎖@malwr | 236 |
| 3 | Cyber-Enabled Maritime Sanctions Evasion
Discover how Iranian and Russian shadow fleets use a vast network of fake maritime websites and fraudulent documents to evade international sanctions
https://www.recordedfuture.com/research/cyber-maritime-sanctions-evasion
🎖@malwr | 219 |
| 4 | The Adversarial PE Analysis Series, Part 1 — Why PE Parsers Break: Introducing the 99 Adversarial…
An exploration of malformed Portable Executable structures and how analysis tools really behave when the rules stop making sense.
https://medium.com/@malx-labs/the-adversarial-pe-analysis-series-part-1-why-pe-parsers-break-introducing-the-99-adversarial-1769556ab473
🎖@malwr | 269 |
| 5 | The shift from an “N-day” world toward an “N-hour” reality. The shift is happening because advanced AI can automate the expert reverse-engineering and exploit-development work that used to take skilled humans days or weeks, reducing the time from patch release to working exploit to mere hours.
@SirMalware | 456 |
| 6 | The shift from from an “N-day” world toward an “N-hour” reality. The shift is happening because advanced AI can automate the expert reverse-engineering and exploit-development work that used to take skilled humans days or weeks, reducing the time from patch release to working exploit to mere hours.
@SirMalware | 1 |
| 7 | N-days \ red.anthropic.com
https://red.anthropic.com/2026/n-days/
Modern frontier LLMs are dramatically accelerating the exploitation of N-day vulnerabilities (publicly disclosed bugs that many systems have not yet patched). In controlled experiments, Anthropic found that advanced models could autonomously analyze software patches, reconstruct the underlying vulnerability, and build working proof-of-concept exploits in minutes to hours. On both open-source Firefox bugs and closed-source Windows kernel vulnerabilities, their strongest model generated successful exploits at a speed that far outpaced typical enterprise patch deployment timelines.
🎖@malwr | 439 |
| 8 | IDA 9.4 Beta | Hex-Rays Docs.
https://docs.hex-rays.com/release-notes/9_4beta
🎖@malwr | 448 |
| 9 | Turning Up the Heat: Hacking Trane HVAC Controllers
Team82 identified a chain of severe, highly exploitable vulnerabilities in the widely deployed Trane Tracer SC+ HVAC controller affecting up to version v5.20.1362. These vulnerabilities could allow an unauthenticated remote attacker to gain complete control over a critical building management system. Trane has patched ...
https://claroty.com/team82/research/turning-up-the-heat-hacking-trane-hvac-controllers
🎖@malwr | 474 |
| 10 | JeanExtreme002/PyMemoryEditor: A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python .
https://github.com/JeanExtreme002/PyMemoryEditor
🎖@malwr | 492 |
| 11 | Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html
🎖@malwr | 469 |
| 12 | How to Detect PowerShell Encoded Commands in Microsoft Sentinel (KQL)
A working SOC analyst's guide to detecting PowerShell -EncodedCommand abuse using KQL in Microsoft Sentinel. Production-ready detection rules with tuning notes.
http://socauthority.com/blog/how-to-detect-powershell-encoded-commands-sentinel-kql/
🎖@malwr | 464 |
| 13 | matheusht/redthread: An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision evaluations, and synthesizing validated guardrails for safe self-improvement.
https://github.com/matheusht/redthread
🎖@malwr | 450 |
| 14 | 2026-06-09: Atomic macOS (AMOS) Stealer infection
https://www.malware-traffic-analysis.net/2026/06/09/index.html
🎖@malwr | 408 |
| 15 | Reminder: We accept ads
@SirMalware | 509 |
| 16 | dmtrKovalenko/lofree-hypace-reverse-engineer: Reverse engineered firmware flashing protocol for lofree hypace mouse
https://github.com/dmtrKovalenko/lofree-hypace-reverse-engineer
🎖@malwr | 529 |
| 17 | NightCity Tracer
NightCity Tracer — a cyberpunk network intrusion simulation game. Hack, trace, and outmaneuver corporate security in real-time tactical scenarios.
https://thomassimmer.github.io/nightcity-tracer/
🎖@malwr | 454 |
| 18 | Synthetic APTs: the Collapse of TTP-Based Attribution
Cyber Threat Intelligence CTI attribution relies on identifying the Tactics, Techniques, and Procedures TTPs that distinguish one threat actor from another. This approach presupposes that each adversary leaves a recognizable operational fingerprint. This work investigates whether AI driven adversary emulation challenges that presupposition. We deploy agents from our Cybersecurity SuperIntelligence CSI framework, configured as five Advanced Persistent Threat APT groups, APT28, APT29, APT41, APT44, and Lazarus Group, against AI driven Defender agents across two cyber ranges provided by CYBER RANGES, equipped with defensive software Wazuh, Velociraptor, Elasticsearch and active AI driven defenders: an enterprise network and a military infrastructure. Across 20 experiments using two defender models, a binary pattern emerges: all 10 Enterprise range experiments resulted in compromise 2 to 12 hosts per experiment, while all 10 Military range experiments were successfully defended or resulted in stalemates, regardless of APT profile or defender model. In 8 of 10 Enterprise experiments, attackers independently weaponized the defender's own Velociraptor endpoint management platform as a command and control channel, a convergent behavior not encoded in any threat intelligence profile. We argue that in the AI era, wherein agents can be deployed provided the right models are available and subject to the right scaffolding and agentic configuration, the entry barrier for operating like a nation state APT collapses: beyond nation states, individuals can now act like commonly identified threat actors, and with it, fundamentally undermine TTP based attribution.
https://arxiv.org/abs/2606.07158
🎖@malwr | 464 |
| 19 | analysis/pure_basic_640 at main · 4next-re/analysis
https://github.com/4next-re/analysis/tree/main/pure_basic_640
🎖@malwr | 532 |
| 20 | Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
Deep dive into SStar Agent: a cross-platform RAT with Chrome extension harvesting, full filesystem exfiltration, and Windows-only keylogging delivered via npm supply chain attack.
https://www.iru.com/blog/sstar-agent
🎖@malwr | 538 |
Endi mavjud! Telegram Tadqiqoti 2025 — yilning asosiy insaytlari 
