Azeria Labs is probably the most complete free resource for learning ARM security research that exists.
ARM assembly from zero. Shellcode development. Stack overflows. ROP chains. Heap exploitation. iOS kernel heap grooming. TrustZone internals. GDB debugging. QEMU lab setup. Even an online ARM assembler.
If ARM exploitation is something you want to understand, start here.
https://t.co/MnfDCdNtrG
https://t.co/QtCZ3nhujT
Author: @Fox0x01
#ReverseEngineering #ExploitDevelopment #InfoSec
Article on the many false flag operations that russia is executing NOW in Europe:
“The men had poured green paint on Paris’ Holocaust Museum and several synagogues and left plastic skeletons at the Brandenburg Gate in Berlin, a short distance from the Holocaust memorial.
The goal of the operation, the court concluded, was to “incite religious and national intolerance” between Jews and Muslims and “destabilize the situation” in Germany and France.
Finally at the point where I feel good enough to release my LORA Project:
-Decodes Meshtastic, Meshcore, LoraWAN, and other protocols.
-Detects on non-standard frequencies across the entire bandwidth.
-Supports Soapy, BladeRF, and USRP
-Add custom keys
https://t.co/cFbctRxPIS
A careless code blunder just blew the lid off Beijing’s multi-million dollar AI propaganda operation targeting the West. France's digital interference watchdog, Viginum, has officially exposed "Fawn Mianju," a covert network of 13 multilingual fake news sites running on advanced automation and generative AI. The sophisticated network was completely compromised after a computer engineer working as a Senior Project Manager at China's state-run CGTN Digital accidentally left his login credentials exposed in the code.
This operation, which expanded on findings first uncovered by U.S. cybersecurity firm Graphika in 2025, operated with deep financial backing. The domains were registered in Beijing, hosted on Alibaba Cloud, and utilized expensive infrastructure alongside paid plugins to artificially manipulate search engine rankings. Using digital keys linked directly to AI language models, the network automatically scraped CGTN articles, lightly rewrote them, and republished over 2,300 articles, often within less than an hour of the original state media broadcast.
Sites like the French-language "Actu Méridien" were weaponized to manipulate public opinion across 89 countries, heavily targeting Western audiences and Francophone African youth. The articles aggressively peddled pro-Beijing narratives, painting China as the undisputed leader of the Global South and green energy transition while explicitly telling Western readers that aligning with Chinese interests would bring them massive benefits.
Despite the cutting-edge tech and heavy state funding, the operation was an organic flop. The articles struggled to breach 15,000 views, with nearly 40 percent of its top social media engagement traced back to fake accounts in Burundi whose sole purpose was to artificially inflate the content. While the reach was limited, French authorities warn that the operation exposes Beijing’s rapidly escalating capability to launch fully automated, stealth disinformation campaigns designed to quietly erode Western democratic alignment.
#Disinformation #CyberSecurity #France #China #AIPropaganda #Geopolitics #Viginum #NationalSecurity
Jeff Bezos reveals why compromise is one of the worst ways to resolve a disagreement
"An example of a really bad way of coming to agreement is compromise. If I say the ceiling is 11 feet and you say 12 feet, we say let's call it 11 and a half. That's compromise"
"The advantage of compromise is it's low energy. But it doesn't lead to truth"
"Another really bad resolution mechanism is who's more stubborn. Two executives disagree, they have a war of attrition, and whichever one gets exhausted first capitulates. You haven't arrived at truth, and this is very demoralizing"
"Escalation is better than a war of attrition. Escalate to your boss and say, we can't agree, we like each other, we're respectful, but we strongly disagree, we need you to make a decision"
"Exhausting the other person is not truth seeking. Compromise is not truth seeking"
The world’s largest residential proxy network runs on consent, TLS and vibes. The TV is always watching and apparently it is also available for contract work in surveillance or data acquisition? Bright Data sells access to a residential proxy network, the kind customers use to route requests through real home IP addresses instead of datacenter IPs that Cloudflare, DataDome and HUMAN are trained to block. The supply comes from an SDK embedded in consumer apps. So: CTV games, messengers, mobile apps and screensavers. With consent somewhere upstream, the device becomes an exit node. The TV is perfect for this job. It is plugged in, on WiFi, often unattended and barely supervised. It also asks for consent through a privacy policy and a remote-control UI, which is one way to make “informed choice” look like an endurance sport. One config flag tells the SDK to ignore whether the screen is on. Another tells it to ignore whether the user is on a call. In this economy, watching TV counts as downtime. https://t.co/WvFVvEFrzY
shipping v5 of LitterBox after way too many late nights
real EDR in the loop now. drop an agent on your VM, fire payloads at it, alerts land back with full call stacks. Elastic Defend + Fibratus work. new UI + better performance — notes in the release.
https://t.co/NWCd3KIxXh
Introducing a new side project called Model Regression. It tests daily Claude, GPT, and Grok on various benchmark statistics to determine how well its performing and to identify model degrades over time.
@edskoudis had an idea for model testing before they conducted offensive testing to ensure the model was performing as expected, and @BlasikRandy pushed me down this road with actually going and doing it.
The main intent here is the frontier models will experience outages, issues, bugs, intentional/unintentional nerfing of the models without notice. You can't typically trust day to day activities in these models for stability, so leveraging this on your daily routine to see how well the model is performing for that day is something I'll be using everyday.
Runs every morning in my DGX sparks environment and automatically updates with how well its performing.
Enjoy!
https://t.co/1Pep6NyGoh
Also open-sourced the project, can run on your own server as well and look at the benchmarks and how they are calculated:
https://t.co/GFPigpRtUF
A business owner living in Brazil who disappeared in January 2023 was revealed to be a deep-cover Russian illegal agent who is now likely back in Moscow.
Gerhard Daniel Campos Wittich lived in Rio de Janeiro for more than five years, where he ran a 3D printing firm called 3D Rio. He claimed to be the son of an Austrian father and Brazilian mother, and grew up in Vienna, which explained his accented Portuguese. His company had contracts with Brazilian military and government organizations. When he disappeared, he was in the final stages of closing on a new commercial space located just down the street from the US Consulate in Rio.
According to reporting by Shaun Walker in the Guardian, an Argentinian couple living in Slovenia were arrested in December 2022 and revealed to be Russian spies. Those arrests likely led Campos Wittich to be recalled by Moscow to avoid being arrested in a widening investigation. He told his girlfriend he would be attending a 3D printing convention in Malaysia, then disappeared in early January shortly after arriving in Kuala Lumpur.
Weeks later, Greek media reported that a photographer named Maria Tsalla living in Greece was actually a Russian spy named Irina Alexandrovna Smireva and she was secretly married to another Russian spy named Artem Smirev, AKA Gerhard Campos Wittich. The married couple were living thousands of miles apart, carrying out separate missions, and building entirely separate lives from each other.
A years-long investigation by Brazil’s intelligence community and law enforcement has identified at least nine Russian illegals who have used Brazilian identities to create their own legends. Many of them (including Campos Wittich AKA Smirev) were in the early stages of their decades-long missions when their new lives were disrupted by investigations and media revelations.
A fully electric autonomous tractor that lifts 4 tons, pulls 8 tons, runs 24 hours, and you can repair it in the middle of a field. This is Voltrac. 🦾 Made in Europe 🇪🇺
How would you design a futuristic autonomous tractor? Voltrac threw out everything and started from scratch. 70% fewer parts. One motor per wheel. Hot-swap batteries. Backwards compatible with any attachment a farmer already owns.
Voltrac is more than a tractor, it’s the brain of the farm. One operator supervises multiple tractors across multiple farms. Every drive analyzes the crops, catches disease early, cuts fertilizer costs.
And the same hitch that connects to farm tools connects to demining gear and resupply payloads for the front line.
Disclaimer: I'm an early investor, because this is exactly what Europe needs.
Europe had 70 million farmers in 2020. Projected 7 million by 2030. Our population keeps growing. Everyone still wants to eat. Somebody has to solve this.
They build in Valencia, not China. Because the talent, the precision manufacturing, and the know-how are all here.
We just forget how good we are. If we don't build this, someone in China will and sell it to European farmers. 🇪🇺🔥
Full Video on YT!
The attack also works on physical machines- use a usb to com cable- get one that dont require its driver to download.
It works all the way back to windows xp.
I have no azure account-but I think that the emm driver is auto loaded even in not RE there.
You can then without logging in still dump any process to none encrypted drive.
ps. booting in safe mode dont trigger tpmlock but downgrade lsaiso to just ppl.
pps. without login can also kill ppl process like defender.
3 times it stop starting again.
Discovered a new method for detecting if someone is using Incognito in Chrome:
Write 512 tiny 1-byte responses into a scratch Cache API cache, then read:
https://t.co/gsVNLl57y6.estimate().usageDetails.caches
Normal Chrome: ~393kb
Incognito: ~85kb
Why? When you're in incognito, Chrome writes to memory instead of disk, which leaves less metadata residue
Most people learn security research by reading finished writeups. This one shows the actual process.
The messy, organic, step-by-step reality of reversing an unknown Windows mitigation from scratch. WinDbg. IDA. Hex Rays. Guard page violations. Trap flags. Zero prior knowledge of the target.
If you want to learn how to actually approach unknown Windows internals, start here.
https://t.co/Xq8xbSnG75
Author: @yarden_shafir
#ReverseEngineering #WindowsInternals #InfoSec
Cleaned up my old ETW notes from Obsidian and put them into one post.
No new research here.
Just a practical map of the parts I keep coming back to, providers, sessions, kernel loggers, ETWTI, tampering, and detection.
https://t.co/e068LAH8p7
Your face is leaking data in virtual meetings: a new attack reveals what you’re viewing with 99% accuracy. 👩🏻💻🎥👀👨🏻💻💡
More details on:
LinkedIn: https://t.co/uDX1bKCx9H
Substack: https://t.co/Z16ieYS4q1
We’re opening the Exodus research vault.
Over the coming weeks, we’ll publish technical writeups highlighting vulnerability research, exploit development, and deep reverse engineering from our team.
First up: Michele Campa’s Adobe Acrobat Reader Escript.api use-after-free RCE.
https://t.co/iycMuZQLix
#VulnerabilityResearch #ExploitDevelopment #ReverseEngineering #OffensiveSecurity #CyberSecurity