I analyzed Trend Micro Deep Security Agent for Linux and found that a local event storm can force bmhook/tmhook reload cycles, opening a repeatable temporary protection bypass window.
Full write-up:
https://t.co/bZFOyMptG5
#linux#edr#rootkit#cybersec#security#research
A LINUX KERNEL DEVELOPER PROVED THE THING YOU PUSH CODE TO IS SECRETLY A DATABASE THAT CAN VERSION ALMOST ANYTHING AND THAT MOST DEVS HAVE ONLY EVER TOUCHED A TENTH OF IT
42 minutes from Josh Triplett -- a longtime Linux kernel and Debian developer -- showing that Git is a general-purpose, tamper-evident versioning engine that just happens to be famous for code.
-> The moment it clicks, Git stops being "Where my code lives" and becomes what it really is underneath: a content-addressable store that can version almost anything -- your configs, your notes, your servers' state, entire datasets.
People run whole wikis on it. They version their entire machine's configuration with it. They ship websites by pushing to it. They track data too big to email. None of it is a hack -- it's the same handful of objects you already use for code, pointed somewhere new.
Treating Git as a code-only tool was never the ceiling -> it's a versioning engine for anything, and the people who see that automate what the rest of the team still does by hand. And as AI agents start spitting out not just code but configs, docs and data, the one system that can version and audit all of it at once is already sitting on your machine.
You learned five commands to survive. This is the talk that shows you were standing on top of a database the whole time.
It changes what you think the tool is even for.
Bookmark & Watch it today ↓
Czytam sobie o sikhach i ich, wprowadzonym w 1699r, religijnym obowiązku noszenia kirpanów (ceremonialnych mieczy), który to religijny obowiązek jest szanowany/uznawany na całym Zachodzie, w tym w Polsce.
Uważam, że katolicy powinni mieć religijny obowiązek noszenia dwuręcznych mieczy, na podstawie wezwania papieża Urbana II na soborze w Clermont w 1095.
Es gibt Männer, die von Frauen die Nase voll haben und sich friedlich abwenden und auf ihr eigenes Leben konzentrieren. Nennen sich MGTOW (men going their own way). Sie gelten als gestörte, hasserfüllte Terroristen und enge Verwandte von Satan.
Syscalls in C# — Red Team Tradecraft Beyond Win32 APIs 💀🔴
A deep dive into how offensive tooling can invoke Windows syscalls directly from C#.
• Explains Windows internals, syscall execution, and unmanaged code integration
• Covers delegates, P/Invoke, memory management, and syscall assembly execution
• Walks through building a proof-of-concept using NtCreateFile
• Useful for understanding modern EDR evasion techniques and offensive tooling design
A solid resource for red teamers, malware analysts, and anyone interested in Windows internals and low-level security research.
🔗 https://t.co/sSfbgK5NJN
#RedTeam #WindowsInternals #CSharp #MalwareAnalysis #ThreatResearch #CyberSecurity #OffensiveSecurity #InfoSec
Back in 2002, I wrote a super-simple tool to dump the memory of a live process to a file. This was a cool way to grab "screenshots" of SSH sessions, editors, etc.
I recently non-vibe-coded a new version that works on modern Linux, if you want to have fun: https://t.co/To6C3Vmib6
Themida turns a few lines of code into thousands of VM handler instructions. Completely unreadable.
back engineering built a static devirtualizer that lifts it all to IR, resolves the control flow, and recovers the original logic.
The before/after in the repo is genuinely shocking.
Works on pretty much any VM obfuscator, not just Themida.
Blog: https://t.co/fY4YkY2aH3
Devirt output: https://t.co/p2gkKi1vXp
Author: @BackEngineerLab
#ReverseEngineering #InfoSec #Malware
#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: https://t.co/5Dzgqwuz9q
"Fileless malware" started as Code Red's pure in-memory worm in 2001 and has evolved to cover other forms of evasion, including living-off-the-land. I traced the journey of the term through its 25-year history.
https://t.co/RPKv40DL2T
C# MCP server for kernel & user-mode Windows debugging — DbgEng COM, KDNET, Frida, dbgsrv, TTD, and integrated VM control. 29 tools for LLM agents. https://t.co/kKVpaRo0X2
Rust reverse engineering is about to get a lot easier. 🦀
I'm thrilled to announce that Oxidizer, the first Rust decompiler, has been officially merged into angr!
Try it out: https://t.co/D9ILIgVH1K
You can also find the paper here: https://t.co/k97qZRvEAm
''GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks''
#infosec#pentest#redteam#blueteam
https://t.co/XzKe9I5h68