The FLARE Learning Hub is launching with three modules:
- Malware Analysis Crash Course
- The Go Reverse Engineering Reference
- Introduction to Time Travel Debugging (TTD)
📟 Start learning: https://t.co/iw6SGpq9St
AV/EDR Lab Environment Setup
A curated list of various resources helpful in building own malware-centric research lab.
A post by Udayveer Singh (@m4lici0u5)
Source: https://t.co/ZM3A1n1zNQ
#redteam#blueteam#maldev#malwaredevelopment
🚨 CVE-2026-1731 🚨
Our team discovered a critical pre-auth RCE affecting BeyondTrust Remote Support & Privileged Remote Access.
SaaS/Cloud instances have been patched. If you're running self-hosted deployments, apply the patches immediately. More info in the comments.
I've developed a professional and technical tool for Next.js (CVE-2025-55182) 🥳
I'm offering this tool, which allows you to perform both bulk and individual scans, as well as testing on live subdomains.
github;
https://t.co/6OXSyNHz2T
#DevTools#python#bugbountytip #bugbountytips #InfoSec #recon #nextjs #React2Shell
𝗘𝗫𝗣𝗟𝗢𝗜𝗧 𝗗𝗘𝗩𝗘𝗟𝗢𝗣𝗠𝗘𝗡𝗧 🐌
🔗 Part 1 : Intro :-
https://t.co/AHjVYNvAcu
🔗 Part 2 : Understanding Stack Memory :-
https://t.co/RnXPbpAZyG
🔗 Part 3 : Understanding Heap Memory :-
https://t.co/DwIitKVWfL
🔗 Part 4 : Understanding Binary Files :-
https://t.co/a504lhs7lE
🔗 Part 5 : Dealing with Windows PE files programmatically :-
https://t.co/j5MgycQtZc
🔗 Part 6 : Dealing with ELF files programmatically :-
https://t.co/jMty8otCIj
🔗 Part 7 : How to do magic with string format bugs :-
https://t.co/WxI5VAIsrl
🔗 Part 8 : Buffer Over-Read Attacks and Developing a Real Exploit :-
https://t.co/BFQgofxFkO
@BlueTeamKit #exploit_development #binary_exploitation #vulnerability_research #buffer_overread
Turns out my #PHRACK article is live! 🔥
> The Art of PHP — My CTF Journey and Untold Stories!
Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the @Phrack crew for keeping it real! 🎉
https://t.co/BMCLlHti7q
Today we are releasing our FREE educational course: "Intro to Exploit Dev"!
This course is perfect for those trying to start exploit dev and covers:
- Tooling
- Fuzzing
- Exploitation techniques
- And more!
You can take the course here: https://t.co/kejXkinsGR
#DPRK#CTI
installerfofo[.]kro[.]kr redirecting to open-dir --> hxxp://158.247.238[.]12/FOFO/installer1.exe
Hash of insaller1.exe: 0191091229F19899B0C150399846FCE328C3F362B6FEE4894C0C793E9C4EBA66
Related: 6d721baeffb6e3cb931460558541357940f4aec41337982277aaad7ba564204c (chrome1.vbs)
a1bd69ddf6bc05df5e4513c2e580391995cc634eb288ebe4d0c157d75c81253e (installer1.exe) --> Making use of telegram api. This file is related to yootube[.]kr which redirects to a dead-end dropbox link --> https://www.dropbox[.]com/scl/fi/zctep2ysunyxld1xt73zm/chrome1.exe?rlkey=onyfdwa0sldm04qelu5q2i5i3&st=lzvfi0xr&dl=0/file.jpg?rlkey=%3ctoken.b%3e&dl=1
Even more open-dirs to find with the following on censys:
services.banner_hashes="sha256:57db00b79f077bfc439e4410a5d922438062d2f9d5316df6b602b64a4dd9d0ad" . Thank you @eastside_nci for pointing that out!
Especially http://183.105.107[.]132 has some weird stuff with an interesting .cmd file
Has anyone seen this kind of activity, especially the insaller1.exe files? Not quite sure what family those belong to @unpacker