CyberSecurityTechnologies
We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel
Ko'proq ko'rsatish📈 Telegram kanali CyberSecurityTechnologies analitikasi
CyberSecurityTechnologies Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 34 376 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 3 779-o'rinni va AQSH mintaqasida 1 035-o'rinni egallagan.
📊 Auditoriya ko‘rsatkichlari va dinamika
невідомо sanasidan buyon loyiha tez o‘sib, 34 376 obunachiga ega bo‘ldi.
16 Sentabr, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni -436 ga, so‘nggi 24 soatda esa -15 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.
- Tasdiqlash holati: Tasdiqlanmagan
- Jalb etish (ER): Auditoriya o‘rtacha 6.06% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 2.93% ini tashkil etuvchi reaksiyalarni to‘playdi.
- Post qamrovi: Har bir post o‘rtacha 2 084 marta ko‘riladi; birinchi sutkada odatda 1 009 ta ko‘rish yig‘iladi.
- Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 5 ta reaksiya keladi.
- Tematik yo‘nalishlar: Kontent cve-2025, attack, threat, detection, llm kabi asosiy mavzularga jamlangan.
📝 Tavsif va kontent siyosati
Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
“We have been working for YOU for more than 8 years!!!
https://t.me/+9vdG4JOSgY8xMzdi
See also:
https://t.me/Cognitive_Security
https://t.me/CyberSecurityOSINT
https://t.me/Wireless_Cybersecurity
For All Questions: in messages to the channel”
Yuqori yangilanish chastotasi (oxirgi ma’lumot 17 Sentabr, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.
Ma'lumot yuklanmoqda...
| Sana | Obunachilarni jalb qilish | Esdaliklar | Kanallar | |
| 17 Sentabr | 0 | |||
| 16 Sentabr | +1 | |||
| 15 Sentabr | 0 | |||
| 14 Sentabr | 0 | |||
| 13 Sentabr | 0 | |||
| 12 Sentabr | 0 | |||
| 11 Sentabr | +1 | |||
| 10 Sentabr | +1 | |||
| 09 Sentabr | 0 | |||
| 08 Sentabr | 0 | |||
| 07 Sentabr | 0 | |||
| 06 Sentabr | 0 | |||
| 05 Sentabr | 0 | |||
| 04 Sentabr | 0 | |||
| 03 Sentabr | 0 | |||
| 02 Sentabr | +1 | |||
| 01 Sentabr | 0 |
| 2 | #Whitepaper
#Malware_analysis
"When Git History Lies:
Commit-Date Spoofing as Malware Cover", 2026.
// Four public GitHub repositories show a shared obfuscated stage-0 JavaScript loader appended to executable config files | 705 |
| 3 | #WebApp_Security
"Plug 'n' Pray: Agentic LLM-based Detection of Potential Log File Exposures in Third-Party Content Management System Plugins", ACM CCS 2026.
]-> Repo
// presented is an agentic, LLM-based framework that automatically detects potential log file exposures in plugins of the most popular CMS WordPress | 959 |
| 4 | #Kernel_Security
SCTPhantom (CVE-2026-64564):
An 18-Year-Old SCTP ASCONF Transport Use-After-Free
https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
// SCTPhantom - Linux kernel UaF in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated LPE and container-to-host escape on the tested systems | 912 |
| 5 | #tools
#Malware_analysis
#Blue_Team_Techniques
RuleAutoPilot: Synthesizing Deployable Suricata Rules from Network Traffic", Sep 2026.
// RuleAutoPilot - end-to-end agentic framework that generates deployable Suricata rules directly from malware network traffic, with no prior threat intelligence required. A key challenge is noise: network traffic captures often contain a small amount of security-relevant traffic mixed with large volumes of background traffic, which reduces LLM reasoning quality and increases cost. RuleAutoPilot addresses this challenge with a Benign Traffic Fingerprinting stage that removes known benign background flows before LLM processing | 1 097 |
| 6 | #Whitepaper
"Detecting and Mitigating Active Directory Compromises", 2026.
// This guide informs organizations of recommended strategies to mitigate the 17 most common techniques used by adversaries and malicious actors to compromise Active Directory
See also (AD security tools):
]-> https://github.com/netwrix/pingcastle
]-> https://github.com/Brets0150/AD-PowerAdmin
]-> https://github.com/Trimarc/Invoke-TrimarcADChecks | 1 013 |
| 7 | #Infosec_Standards
NIST IR 8587:
"Protecting Tokens and Assertions from Forgery, Theft, and Misuse Implementation Recommendations for Agencies and Cloud Service Providers", Sep 2026.
// Implementation Recommendations for Agencies and Cloud Service Providers | 1 113 |
| 8 | #AppSec
#Threat_Research
#Sec_code_review
"Python Import as an Execution Boundary: An Empirical Study of Bugs, Vulnerabilities, and Analysis Gaps", 2026.
]-> Repo
// Python import does more than resolve dependencies: it executes code during module and package initialization. This behavior can trigger failures, load dynamic or native code, access resources, or change security-sensitive state before an application calls a package API... | 1 256 |
| 9 | #AIOps
#Threat_Modelling
From Recon to Exploit:
Chaining Attacks on AI Agents
(MITRE ATLAS & Zenity Labs)
https://labs.zenity.io/post/mitre-atlas-ai-agent-attack-techniques
// 11 new techniques and subtechniques covering real-world agent reconnaissance, manipulation and abuse | 1 181 |
| 10 | #Research
#Hardware_Security
"DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes", CCS' 2026.
]-> https://github.com/ddropattack/ddrop
// Modern TEEs such as Intel TDX, Intel Scalable SGX, and AMD SEV-SNP rely on memory encryption to protect enclaves and confidential VMs from an untrusted hypervisor or cloud operator. However, to maintain memory performance, scalable cloud TEEs omit cryptographic freshness guarantees. DDRop demonstrates active physical interposition attacks on DDR5 at native bus speeds using a custom low-cost DDR5 RDIMM interposer. By injecting parity errors on DDR5 command/address lines, the interposer silently discards cache line writebacks or swaps chip selects | 1 319 |
| 11 | #AppSec
#WebApp_Security
The Ghost in the Chat: how a bot that isn't in your group steals messages from Telegram HTML exports
https://expatch.com/writeups/telegram-html-export-xss.html
// A stored XSS in Telegram Desktop's HTML export pipeline lets a bot that never joins your group plant invisible JavaScript in an inline keyboard button. The payload sleeps in message history for months and detonates the moment a participant exports the chat and opens the HTML file - every message rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten | 1 469 |
| 12 | #Malware_analysis
1⃣ "Eye" spy: Cyclops Blink returns with extended capabilities
https://www.sophos.com/en-gb/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities
2⃣ Angry Birds: Toy Ghouls’ new toys
https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270
3⃣ REVSTEALER: analysis of up-and-coming infostealer
https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer | 1 424 |
| 13 | #Offensive_security
#Red_Team_Tactics
Persistence: Component Object Model (COM) hijacking,
May 4, 2026.
// This post discusses COM hijacking and how COM can be abused and utilized as a means of payload execution and persistence on a target system during the post-exploitation stage | 1 955 |
| 14 | #AppSec
#Research
#WebApp_Security
"IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications", Sep 2026.
]-> https://github.com/GuanhangShiFDU/IDOR-GUARD
// Cross-language IDOR reproduction and defense demo for Java, Python, Go, and PHP applications. Evaluated applications include XXL-Job, RuoYi, BootDo, wger, Gitea, Krayin, and Langflow | 1 632 |
| 15 | #AIOps
#OpSec
#Threat_Research
OpenAI agents carried out an undisclosed cyber-attack on RubyGems
https://www.rubyhack.ai/#an-openai-agent-swarm-was-responsible-for-this-i
// On May 11th, 2026, a significant number of malicious packages were uploaded to the RubyGems repository by automated AI agents, which are hypothesized to originate from internal systems at OpenAI | 1 541 |
| 16 | #tools
#Offensive_security
SSHamble - research tool for SSH implementations that includes:
- Attacks aagainst authentication
- Post-session authentication attacks
- Pre-authentication state transitions
- Authentication timing analysis
- Post-session enumeration | 1 992 |
| 17 | #tools
#Offensive_security
SSHamble is a research tool for SSH implementations that includes:
- Aattks aagainst authentication
- Post-session authentication attacks
- Pre-authentication state transitions
- Authentication timing analysis
- Post-session enumeration | 1 |
| 18 | #reversing
#Whitepaper
"The Ultimate Reverse Engineering Reference Manual: Deep Dive Technical Guide with C & Assembly Examples", 2025.
// 100+ Pages Comprehensive Framework | 1 842 |
| 19 | #MLSecOps
#Tech_book
"AI-Native LLM Security:
Threats, defenses, and best practices for building safe and trustworthy AI", 2025.
// Structured around actionable insights, the chapters introduce a secure-by-design methodology, integrating threat modeling and MLSecOps practices to fortify AI systems | 1 851 |
| 20 | #Analytics
#Threat_Research
An analytical review of the main cybersecurity events (Sep 05-12, 2026)
1⃣ Sonicwall SMA1000 Attack
// CVE-2026-15409
2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
3⃣ Next Nightmare Eclipse Vulnerability
// Microsoft has failed to properly patch ShieldBreak CVE-2026-69414..
4⃣ FortiPAM Vulnerability
// CVE-2026-84388
5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel
// CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560, CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274
6⃣ Netscaler ADC Exploit
7⃣ Critical vulnerabilities in MikroTik RouterOS
8⃣ GRAYRABBIT One-click backdoor
// One click. Three critical failures. One backdoor
9⃣ Attacks using browser-in-browser (BiTB) phishing techniques
🔟 Beltdown: Escaping the Claude Code sandbox
// An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user | 1 912 |
