home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. New.

    "The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."

    Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors rapid7.com/blog/post/tr-dprk-a @Rapid7Official #infosec #cybercrime #threatresearch #Linux

  2. New.

    "The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."

    Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors rapid7.com/blog/post/tr-dprk-a @Rapid7Official #infosec #cybercrime #threatresearch #Linux

  3. New.

    "The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."

    Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors rapid7.com/blog/post/tr-dprk-a @Rapid7Official #infosec #cybercrime #threatresearch #Linux

  4. New.

    "The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."

    Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors rapid7.com/blog/post/tr-dprk-a @Rapid7Official #infosec #cybercrime #threatresearch #Linux

  5. New.

    "The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."

    Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors rapid7.com/blog/post/tr-dprk-a @Rapid7Official #infosec #cybercrime #threatresearch #Linux

  6. REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.

    Technical highlights:
    • Migration to Ubuntu 24.04 (modern kernel + LTS support)
    • Cast-based installer replacing legacy CLI deployment
    • AI-assisted workflows via MCP server
    • Integration support for Ghidra with AI plugins

    Tooling refresh includes:
    YARA-X (Rust rewrite for performance improvements)
    GoReSym (symbol recovery for Go binaries)
    APKiD (Android packer detection)
    Manalyze (PE/ELF/MachO static parsing)
    This release signals an industry shift toward AI-augmented reverse engineering pipelines.
    Is AI-assisted RE the new baseline for threat labs?

    Source: cyberpress.org/remnux-v8-relea

    Engage below.
    Follow @technadu for deep technical cybersecurity updates.

    #ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting

  7. REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.

    Technical highlights:
    • Migration to Ubuntu 24.04 (modern kernel + LTS support)
    • Cast-based installer replacing legacy CLI deployment
    • AI-assisted workflows via MCP server
    • Integration support for Ghidra with AI plugins

    Tooling refresh includes:
    YARA-X (Rust rewrite for performance improvements)
    GoReSym (symbol recovery for Go binaries)
    APKiD (Android packer detection)
    Manalyze (PE/ELF/MachO static parsing)
    This release signals an industry shift toward AI-augmented reverse engineering pipelines.
    Is AI-assisted RE the new baseline for threat labs?

    Source: cyberpress.org/remnux-v8-relea

    Engage below.
    Follow @technadu for deep technical cybersecurity updates.

    #ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting

  8. REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.

    Technical highlights:
    • Migration to Ubuntu 24.04 (modern kernel + LTS support)
    • Cast-based installer replacing legacy CLI deployment
    • AI-assisted workflows via MCP server
    • Integration support for Ghidra with AI plugins

    Tooling refresh includes:
    YARA-X (Rust rewrite for performance improvements)
    GoReSym (symbol recovery for Go binaries)
    APKiD (Android packer detection)
    Manalyze (PE/ELF/MachO static parsing)
    This release signals an industry shift toward AI-augmented reverse engineering pipelines.
    Is AI-assisted RE the new baseline for threat labs?

    Source: cyberpress.org/remnux-v8-relea

    Engage below.
    Follow @technadu for deep technical cybersecurity updates.

    #ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting

  9. REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.

    Technical highlights:
    • Migration to Ubuntu 24.04 (modern kernel + LTS support)
    • Cast-based installer replacing legacy CLI deployment
    • AI-assisted workflows via MCP server
    • Integration support for Ghidra with AI plugins

    Tooling refresh includes:
    YARA-X (Rust rewrite for performance improvements)
    GoReSym (symbol recovery for Go binaries)
    APKiD (Android packer detection)
    Manalyze (PE/ELF/MachO static parsing)
    This release signals an industry shift toward AI-augmented reverse engineering pipelines.
    Is AI-assisted RE the new baseline for threat labs?

    Source: cyberpress.org/remnux-v8-relea

    Engage below.
    Follow @technadu for deep technical cybersecurity updates.

    #ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting

  10. OpenAI has released GPT-5.2-Codex, positioning it as a more capable agentic coding system for long-horizon engineering and defensive cybersecurity workflows.

    The company reports improvements in vulnerability research support, terminal-based task execution, and large-scale code reasoning, while also emphasizing controlled access and safeguards due to dual-use implications.

    As AI becomes more embedded in security tooling, the focus increasingly shifts to governance, validation, and responsible deployment.

    Source: openai.com/index/introducing-g

    How do you see agentic AI fitting into real-world security operations?

    Share your insights and follow TechNadu for grounded InfoSec coverage.

    #InfoSec #CyberDefense #AIinSecurity #SecureCoding #ThreatResearch #ResponsibleDisclosure #TechNadu

  11. OpenAI has released GPT-5.2-Codex, positioning it as a more capable agentic coding system for long-horizon engineering and defensive cybersecurity workflows.

    The company reports improvements in vulnerability research support, terminal-based task execution, and large-scale code reasoning, while also emphasizing controlled access and safeguards due to dual-use implications.

    As AI becomes more embedded in security tooling, the focus increasingly shifts to governance, validation, and responsible deployment.

    Source: openai.com/index/introducing-g

    How do you see agentic AI fitting into real-world security operations?

    Share your insights and follow TechNadu for grounded InfoSec coverage.

    #InfoSec #CyberDefense #AIinSecurity #SecureCoding #ThreatResearch #ResponsibleDisclosure #TechNadu

  12. OpenAI has released GPT-5.2-Codex, positioning it as a more capable agentic coding system for long-horizon engineering and defensive cybersecurity workflows.

    The company reports improvements in vulnerability research support, terminal-based task execution, and large-scale code reasoning, while also emphasizing controlled access and safeguards due to dual-use implications.

    As AI becomes more embedded in security tooling, the focus increasingly shifts to governance, validation, and responsible deployment.

    Source: openai.com/index/introducing-g

    How do you see agentic AI fitting into real-world security operations?

    Share your insights and follow TechNadu for grounded InfoSec coverage.

    #InfoSec #CyberDefense #AIinSecurity #SecureCoding #ThreatResearch #ResponsibleDisclosure #TechNadu

  13. OpenAI has released GPT-5.2-Codex, positioning it as a more capable agentic coding system for long-horizon engineering and defensive cybersecurity workflows.

    The company reports improvements in vulnerability research support, terminal-based task execution, and large-scale code reasoning, while also emphasizing controlled access and safeguards due to dual-use implications.

    As AI becomes more embedded in security tooling, the focus increasingly shifts to governance, validation, and responsible deployment.

    Source: openai.com/index/introducing-g

    How do you see agentic AI fitting into real-world security operations?

    Share your insights and follow TechNadu for grounded InfoSec coverage.

    #InfoSec #CyberDefense #AIinSecurity #SecureCoding #ThreatResearch #ResponsibleDisclosure #TechNadu

  14. AI-driven fraud is hitting holiday shoppers at machine speed. In today’s Cyberside Chats episode, Sherri Davidoff and Matt Durrin unpack what that looks like in the real world. They discuss how phishing kits, prebuilt configs, and bot-driven takeovers are giving attackers a near-instant launchpad for credential abuse.

    This breakdown shows how quickly these tools scale—and why teams need to shore up people, passwords, and payments before the rush.

    Listen here: chatcyberside.com/e/holiday-ha

    Watch the video: youtu.be/TpMD5v5JUNc

    Or find Cyberside Chats wherever you get your podcasts.

    #CyberDefense #SecurityAwareness #OnlineFraud #DigitalRisk #ThreatResearch #AIinSecurity #Malvertising #HolidayThreats

  15. AI-driven fraud is hitting holiday shoppers at machine speed. In today’s Cyberside Chats episode, Sherri Davidoff and Matt Durrin unpack what that looks like in the real world. They discuss how phishing kits, prebuilt configs, and bot-driven takeovers are giving attackers a near-instant launchpad for credential abuse.

    This breakdown shows how quickly these tools scale—and why teams need to shore up people, passwords, and payments before the rush.

    Listen here: chatcyberside.com/e/holiday-ha

    Watch the video: youtu.be/TpMD5v5JUNc

    Or find Cyberside Chats wherever you get your podcasts.

    #CyberDefense #SecurityAwareness #OnlineFraud #DigitalRisk #ThreatResearch #AIinSecurity #Malvertising #HolidayThreats