Excited to announce our first TyphoonCon 2026 training! "Exploiting 10x Faster: LLM Agents and MCPs for Modern Vulnerability Research" by @beta_b0t and @G1ND1L4
https://t.co/CqHbDrrW9t
Stay tuned for more!
#BHASIA Trainings "Exploiting 10x Faster: LLM Agents and MCPs for Modern Vulnerability Research" 4-day course is for experienced vulnerability researchers who want to use LLM agents and Model Context Protocols (MCPs) to speed up reverse engineering, bug discovery, and exploit development. Learn more >> https://t.co/Zl4MYNqaFn
I’m teaching at @BlackHatEvents ASIA 2026, together with @G1ND1L4 .
It's for vulnerability researchers who want to really deep dive into it in practice.
Very hands on. Lots of labs, real bugs, real tooling. Plenty of room to experiment and break things.
#BlackHatTrainings
@BlackHatEvents@G1ND1L4 Here's an example of the kind of work this is about. Vladimir recently published a VirtualBox exploit uncovered using custom LLM agents. These are exactly the kinds of workflows we teach:
https://t.co/BsF6ohfn3W
Better Late Then Never! two zero days that finally have been patched:
CVE-2023-2569, CVE-2023-2570 which both may lead to KCE.
(2023/06/13Foxboro SCADA)
#security#energy#windows#cves#kernel#cybersecurity
https://t.co/C6tfYqkNS2
New findings bring the total number of malicious packages in this recent attack to 1000+, including JS ransomware packages.
Read more here:
https://t.co/cYag3DxnwG
#BHASIA Briefing: “Alarm.DISARM - Remotely Exploiting and Disarming Popular Physical Security System from Public Internet” - in this talk, @omri9741 will present two remote code execution vulnerabilities (CVE-2020-25189 and CVE-2020-25185). Learn more: https://t.co/ONjdmDP4LM
Our research team came across a technique that allowed code to run on hundreds of servers worldwide without an installation.
What we found is when a user only downloads a Python package, the code inside will automatically run on the developer's system.
https://t.co/6BP8VMtud8
Last week a novel open-source software supply-chain attack was discovered by @alxbrsn.
During this weekend, hackers started copycatting this (link in comments)
In order to detect if you are vulnerable, we have released “DustiLock” an open-source tool - https://t.co/qmpZXzmQeL
I'm very excited about this achievement and partnering with @OpenViewVenture.
@IntezerLabs team, thank you! It is amazing to work with such passionate people, that believe in our vision, and want to make a real difference in the cybersecurity space.
https://t.co/PFPY7oTfay
Research conducted in a joint effort between Intezer and @_CPResearch_ maps the Russian #APT ecosystem on an unprecedented scale. Learn more: https://t.co/yG1jTD6qJx
This Saturday at #r2con2019: Intezer researcher @ulexec will present “ELF Crafting: Uncovering Advanced Anti-Analysis Techniques for the Linux Platform." More info: https://t.co/FtKHl6bSHH
At BlackHat Arsenal Intezer’s researcher, @omri9741 revealed an open-source tool called MoP (“Master of Puppets”)- a framework for reverse engineers who wish to create and operate trackers for new malware found in the wild. Read more: https://t.co/eeCw2udPGH
MoP ("Master of Puppets") is an open source framework for reverse engineers who wish to create and operate trackers for new malware found in the wild for research purposes. See a demo by @omri9741 at #BHUSA Arsenal https://t.co/4n0UszPAUV
Intezer researcher @omri9741 will demo his open-source tool, MoP (Master of Puppets) during #BHUSA Arsenal. MoP is an advanced #malware tracking framework for reverse engineers. More info: https://t.co/sytzwi1p5g
I like @IntezerLabs because it could have helped everyone that has no own code similarity engine with the attribution of the USCYBERCOM sample.
They also show which "string" similarities exist between families.
https://t.co/fnHmnOOjU3
New @ESET Research: We analyzed #LightNeuron, a #Turla malware targeting Microsoft Exchange servers
- Abuses the Transport Agent feature
- Can read/modify/block any email
- Backdoor controlled by email attachments
Full WP: https://t.co/9Ct47e2VPC
Blogpost: https://t.co/sd3FNDrwqa