Our team recently did a deep-dive technical analysis of SolyxImmortal, a Python-based infostealer targeting Windows environments.
Read the full post for a step-by-step breakdown of the full execution flow: https://t.co/VMwlc9coBT
New and improved Pulsedive Docs now live!
We just released a dedicated documentation site with a complete API reference, live playgrounds, and MCP server support for AI-assisted development.
https://t.co/Nh7ZqRWyzj
What to know about the Aisuru-Kimwolf botnet: https://t.co/Qyk5fMBWPl
- Massive botnet, 1M+ compromised devices
- Kimwolf = specialized Android variant
- Aisuru = parent botnet that has spawned other botnets
- Used in DDoS and other attacks
Expect more news and updates on this threat in the coming weeks.
VoidLink - a nascent threat developed using AI, according to @CheckPointSW's research team.
What We Know:
- Advanced Linux malware framework
- 30+ modules for a plug-in based design
- Cloud-native and cloud-aware
- First observed late 2025, not seen in the wild yet
More news at: https://t.co/xJcfUi9f3w
The blog examines the malware, PowerShell loader, execution chain, and mitigation recommendations.
We also share indicators of compromise and artifacts from the analysis (available in our GitHub repo).
IOCs: https://t.co/PR7rl9Dzyu
Artifacts: https://t.co/MFFlCTBKrd
Newly Added Threat Page: PeckBirdy
- JScript-based C2 framework
- Used by threat actors aligned with China
- Since 2023
- New primary research from @trendaisecurity: https://t.co/e16XYm6JtX
Latest news, TTPs, IOCs available on Pulsedive's PeckBirdy Threat page: https://t.co/hPIF2p7Ak0
A lot happened in 2025 - some surprising, some expected.
2024: we predicted increased adoption Gen AI by threat actors for social engineering lures & malicious tooling.
2025: we saw that threat actors have integrated AI into malware and used prompt engineering to bypass AI safety controls.
Notably, @Anthropic reported on the first AI-orchestrated cyber espionage campaign.
See below for the breakdown by task & AI v. human activity.
Read our full recap of the last 12 months in our Year in Review: https://t.co/Wq2FyEOPR5
Exploitation attempts for #React2Shell (CVE-2025-55182) have been widespread over the last week. Three resources that outline exploitation are:
https://t.co/rxa4WI7QoD
https://t.co/jQgUM8fnpQ
https://t.co/v84uIceGsg
Recommendation: Deploy patches as soon as possible
LAST CALL
Get 30% off Pro with code BLACKFRIDAY25: https://t.co/UR6LMiksoz
Less than a day left for our biggest deal of the year for Pro. Pulsedive Pro comes with an upgraded API, Feed, and additional features.
Monthly and annual plans both apply for first-time customers.
More info available on our blog: https://t.co/n0FxnLk02P
Some additional deals with @PentesterLab@pulsedive Cyber Plumbers Lab, @cyberwarfarelab , @nostarch - no affiliate codes just a good time to learn and grab gear 🙂 feel free to submit PRs or DM me to add. I know a few others have lists too, check them out - I do this for fun.
Black Friday is on.
What: 30% off a year of Pulsedive Pro
When: Valid through December 1, 2025
How: use code BLACKFRIDAY25 at https://t.co/XQ5solZ5Ey
More info: https://t.co/ShylCyIlMu
SpearSpecter TL;DR
- Ongoing espionage campaign
- Iranian threat actors (APT42)
- Targeting high-level Middle Eastern government & defense officials
- Social engineering for initial access
- Technical analysis by the Israeli National Defense Agency on TAMECAT modules, multi-channel C&C infrastructure, payload staging, and credential theft via native Windows functionality
Learn more on Pulsedive's SpearSpecter threat page:
https://t.co/HwaBoHsfl8
Original research: https://t.co/d3nMoM8Axn