Bring Your Own RWX Region DLL (BYORWXDLL)
New Medium post, today we are exploring a technique I call Bring Your Own RWX Region DLL, inspired by the well-known BYOVD (Bring Your Own Vulnerable Driver)
https://t.co/slNKv9qF4W
🚨 BREAKING: Miasma is back.
The Shai-Hulud variant has returned to npm, impacting 57 packages with a combined 647K+ monthly downloads.
⚠️ GitHub token theft
⚠️ Cloud credential theft
⚠️ npm account compromise
⚠️ 118+ infected GitHub repos
Full technical analysis to come — follow @OX__Security for updates
#CyberSecurity #SupplyChainSecurity #AppSec #npm #OpenSource
We think of WASM as a mechanism to run compiled code in your browser, but what if we shimmed in all the host APIs necessary to run full implants with ALL logic entirely in the WASM VM? This post walks through what that looks like.
https://t.co/xGVpPe2zyC
#wasm#malware#sliver
🚨 Cybersecurity Alert: The HSE is experiencing IT disruption today due to a ransomware attack on an external vendor. The health service itself wasn't directly targeted, proving once again that your security is only as strong as your weakest third-party link. Read more: https://t.co/cebf46722b
#Cybersecurity #hse #ransomware #cyberattack #nis2 #3rdPartyRisk
The attackers demonstrated strong operational security and evasion discipline during a 5-month campaign focused on stealing an executive’s Outlook mailbox.
Their primary goal was to remain undetected by minimizing noise, blending with legitimate activity, and avoiding common detection triggers.
❗️Google employees are flooding an internal meme board with posts about how bad the company's AI is.
A source says dozens of anti-AI memes post weekly, spiking when models update or their internal coding tool Jetski breaks. One showed Jetski admitting it fabricated report metrics with over 400 upvotes.
Engineers say AI removed the code-gen bottleneck but jammed everything else: testing, build times, and human review now drowning in code nobody wrote.
CEO Pichai says 75% of new code is AI-generated, btw.
Via 404Media
Flashpoint reports that XSS, once a unified Russian-speaking cybercrime hub, fractured into competing factions after a July 2025 takedown, with DamageLib, Rehub, XSS[.pro], and XSSF emerging. https://t.co/CZaoIw85fW
IRFlow Timeline v1.0.7 is live.
This one focuses on a problem I think DFIR teams will see more often: AI assistant usage becoming part of the investigation surface.
You can now collect and normalize local AI usage history from tools like Claude Code, ChatGPT Desktop, Cursor, GitHub Copilot, OpenAI Codex, Gemini CLI, Continue, Windsurf, and Claude Desktop into a unified timeline view.
Also added AI Secret Hunt, which helps identify secrets, tokens, API keys, private keys, and credentials that may have been pasted into AI assistants during real investigations or day-to-day engineering work.
The goal is simple: make AI app activity easier to preserve, search, tag, and correlate during incident response. AI usage is becoming part of the forensic record. We need tooling that treats it that way.
Link in the comment ⬇️
#DFIR #IncidentResponse
#Gamaredon
This report analyses over a decade of malware families and establishes a unified naming taxonomy to cut through the fragmented nomenclature.
1:
https://t.co/pjywWtlIkQ
2:
https://t.co/fKcZ0hSaEf
3:
https://t.co/vcMDWqD47S
"Re: Family Room Reservation"
fake #booking spam email
⛔️https://haddjskak827sja.]com/v
drop zip > lnk
👇
drop genuine node-v24.13.0-win-x64. zip
👇
tonajukbhuakpo2.]shop
Samples
https://t.co/7BiTfkUY8d
New short article on a real-world exploitation case rather than pure research, demonstrating how a specific mistake in Next.js can lead to a systematic zero-click SXSS on its latest versions (w/@inzo____):
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
https://t.co/0JWjH6yzC2
Using Nezha RMM as C2 - No Detection
Earlier we spoke on this issue. RMMs are dangerous when not monitored. Here is an example of Nezha that doesn't trigger any AV alert and works really well if abused by hackers. The victim won't even see anything suspicious when hackers connect to their computer. We also showed the forensic artifacts it might leave.
So, you better monitor them all
Learn more: https://t.co/8np8jXJkF0
RMMs to monitor: https://t.co/CtFNVxjnlM
@three_cube@_aircorridor #blueteam #redteam #apt
Microsoft Unveils Always-On AI Agent Scout to Integrate With Teams, Outlook, and More
Source: https://t.co/exJB9akU8p
Microsoft has officially introduced Microsoft Scout, its first-ever "Autopilot" AI agent, a persistent, always-on autonomous assistant designed to operate continuously across Microsoft 365 apps without waiting to be prompted.
Microsoft is launching a new category of AI agents it calls Autopilots, always-on, identity-bearing systems that act autonomously on a user's behalf. Unlike traditional AI assistants that respond only when queried, Autopilots remain active in the background, monitoring signals, reacting to triggers, and resuming tasks without user initiation. Scout is the first of this new class, and Microsoft has indicated more Autopilots will follow.
#cybersecuritynews #Technews
The Bloop Museum is a non-profit, interactive living museum of electronic entertainment dedicated to the history of computers, video games, & retro gadgets
@bloopmuseum continually adds new rooms & exhibits, focusing on computer & game history. It showcases retro tech with early computing displays & a recreated 80s living room.
Microsoft Admits Windows 11’s Right-Click Menu Needs Work, Customization Coming
After years of user feedback, Microsoft has acknowledged frustrations with Windows 11’s redesigned right-click context menu and is introducing new customization options.
- Users will be able to customize the right-click menu to suit their workflow
- The current menu has been widely criticized for hiding common actions behind the “Show more options” button
- Microsoft says the changes aim to make frequently used commands easier to access
- Developers will gain more flexibility in how their apps integrate with the context menu
- The update is expected to reduce clutter and give users greater control
Since Windows 11 launched in 2021, the context menu redesign has been one of the most common complaints from users.
https://t.co/ybapmSBQiq
Is this a washing machine? Nope!
This is the DEC TU80 (Digital Equipment Corporation TU80). It is an industry-standard 9-track streaming magnetic tape drive subsystem. It was heavily used for data storage, disk backup, and archiving for DEC's systems, such as the PDP-11 and VAX systems.
Fun fact: the TU80 was manually loaded, so an operator had to physically thread the half-inch magnetic tape into the drive before it could read or write data. That sounds like more work, but it makes me love it even more.
https://t.co/rl88U7fqdd
https://t.co/YtG7TDnPi7
#RetroTech #VintageComputing #TechHistory
Unit 42 analyses Operation FlutterBridge, a macOS malvertising campaign that seems to be the next stage of JSCoreRunner. The attackers now deliver adware with full backdoor capabilities through a payload dubbed FlutterShell. https://t.co/byUr7EynSt