Don’t eat the ChocoPoCs! Vulnerability researchers were targeted by trojanised exploits
A suspicious contribution request led YesWeHack and Sekoia researchers to uncover sophisticated malware targeting the vulnerability research supply chain.
https://www.yeswehack.com/news/chocopocs-vulnerability-researchers-trojanised-exploits?utm_source=reddit&utm_medium=social&utm_campaign=chocopocs-vulnerability-researchers
🎖@malwr
A suspicious contribution request led YesWeHack and Sekoia researchers to uncover sophisticated malware targeting the vulnerability research supply chain.
https://www.yeswehack.com/news/chocopocs-vulnerability-researchers-trojanised-exploits?utm_source=reddit&utm_medium=social&utm_campaign=chocopocs-vulnerability-researchers
🎖@malwr
YesWeHack
Don’t eat the ChocoPoCs! Vulnerability researchers targeted by trojanised exploits
A suspicious contribution request led YesWeHack and Sekoia researchers to uncover sophisticated malware targeting the vulnerability research supply chain.
Silent Swap: A Crypto Clipper Extension Campaign
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/
🎖@malwr
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/
🎖@malwr
McAfee Blog
Silent Swap: A Crypto Clipper Extension Campaign | McAfee Blog
Researchers uncover browser extension malware that steals cryptocurrency by swapping wallet addresses during transactions.
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
The Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.
https://securelist.com/the-gentlemen-raas/120447/
🎖@malwr
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.
https://securelist.com/the-gentlemen-raas/120447/
🎖@malwr
CodeXTF2/OpenUDC2: open source implementation of the UDC2 spec used in Cobalt Strike
https://github.com/CodeXTF2/OpenUDC2
🎖@malwr
https://github.com/CodeXTF2/OpenUDC2
🎖@malwr
GitHub
GitHub - CodeXTF2/OpenUDC2: open source implementation of the UDC2 spec used in Cobalt Strike
open source implementation of the UDC2 spec used in Cobalt Strike - CodeXTF2/OpenUDC2
OSIRIS — The Open-Source Palantir Alternative | Live Flights, CCTV, Satellites & OSINT Tools
Track 10K+ aircraft, 2K satellites & worldwide CCTV on a 3D globe. Run Nmap, DNS, WHOIS & threat intel scans from your browser. 20+ live intelligence feeds. Free. Open source.
https://osirisai.live/
🎖@malwr
Track 10K+ aircraft, 2K satellites & worldwide CCTV on a 3D globe. Run Nmap, DNS, WHOIS & threat intel scans from your browser. 20+ live intelligence feeds. Free. Open source.
https://osirisai.live/
🎖@malwr
OSIRIS
🛰️ OSIRIS — Open Source Palantir Alternative | Live Tracking + OSINT Tools
Track 10K+ flights, satellites & CCTV worldwide. Run Nmap, DNS, WHOIS scans from your browser. 20+ live intel feeds. Free & open source.
pIat0n/BareMetal-RAM-Dumper: A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.
https://github.com/pIat0n/BareMetal-RAM-Dumper
🎖@malwr
https://github.com/pIat0n/BareMetal-RAM-Dumper
🎖@malwr
GitHub
GitHub - pIat0n/BareMetal-RAM-Dumper: A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold…
A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory. - pIat0n/BareMetal-RAM-Dumper
xTeardx/diaphora-mcp
https://github.com/xTeardx/diaphora-mcp
🎖@malwr
https://github.com/xTeardx/diaphora-mcp
Diaphora MCP is an MCP (Model Context Protocol) server for automated binary diffing. It connects Diaphora (the diffing engine) and IDA Pro (the disassembler) via the MCP protocol, allowing AI agents (such as Claude Code) to perform binary file comparison, find security patches, and analyze changes.
🎖@malwr
GitHub
GitHub - xTeardx/diaphora-mcp: MCP server for automated binary diffing.
MCP server for automated binary diffing. Contribute to xTeardx/diaphora-mcp development by creating an account on GitHub.
Big-Comfy/deadair: Finds the detection rules in your SIEM that are running blind
https://github.com/Big-Comfy/deadair
🎖@malwr
https://github.com/Big-Comfy/deadair
🎖@malwr
GitHub
GitHub - Big-Comfy/deadair: Finds the detection rules in your SIEM that are running blind
Finds the detection rules in your SIEM that are running blind - Big-Comfy/deadair
Three Weeks in the Trenches: Hunting a 4GB Native Memory Leak That .NET Couldn’t See
https://medium.com/@kalyanjv/three-weeks-in-the-trenches-hunting-a-4gb-native-memory-leak-that-net-couldnt-see-0713935776d0
🎖@malwr
https://medium.com/@kalyanjv/three-weeks-in-the-trenches-hunting-a-4gb-native-memory-leak-that-net-couldnt-see-0713935776d0
🎖@malwr
Medium
Three Weeks in the Trenches: Hunting a 4GB Native Memory Leak That .NET Couldn’t See
TL;DR
RasheedFarhat/DaC-Pipeline: Automated Detection-as-Code (DaC) CI/CD pipeline for validating and programmatically deploying SIEM detection rules via GitHub Actions and the Wazuh API
https://github.com/RasheedFarhat/DaC-Pipeline
🎖@malwr
https://github.com/RasheedFarhat/DaC-Pipeline
🎖@malwr
GitHub
GitHub - RasheedFarhat/DaC-Pipeline: Automated Detection-as-Code (DaC) CI/CD pipeline for validating and programmatically deploying…
Automated Detection-as-Code (DaC) CI/CD pipeline for validating and programmatically deploying SIEM detection rules via GitHub Actions and the Wazuh API - RasheedFarhat/DaC-Pipeline
Windows Service
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …
https://ipurple.team/2026/07/06/windows-service/
🎖@malwr
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …
https://ipurple.team/2026/07/06/windows-service/
🎖@malwr
Purple Team
Windows Service
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …
ItsMehRAWRXD/RawrXDA: RawrXDA
https://github.com/ItsMehRAWRXD/RawrXDA
🎖@malwr
https://github.com/ItsMehRAWRXD/RawrXDA
This is a complete PE32+ writer and machine code emitter implemented in pure x64 MASM assembly with zero dependencies and no CRT usage. It generates runnable Windows executables from scratch.
🎖@malwr
GitHub
GitHub - ItsMehRAWRXD/RawrXDA: RawrXDA
RawrXDA. Contribute to ItsMehRAWRXD/RawrXDA development by creating an account on GitHub.
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/
🎖@malwr
https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/
🎖@malwr
Check Point Research
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework - Check Point Research
Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government…
ridgelinecyberdefence/Enterprise-Detection-Engineering: Production-validated detection queries and hunting artifacts across 9 platforms (KQL, Sigma, Splunk, Athena, PowerShell, Velociraptor, YARA, Suricata, osquery). Each with triggers, false positives, tuning guidance, and validation steps.
https://github.com/ridgelinecyberdefence/Enterprise-Detection-Engineering
🎖@malwr
https://github.com/ridgelinecyberdefence/Enterprise-Detection-Engineering
🎖@malwr
GitHub
GitHub - ridgelinecyberdefence/Enterprise-Detection-Engineering: Production-validated detection queries and hunting artifacts across…
Production-validated detection queries and hunting artifacts across 9 platforms (KQL, Sigma, Splunk, Athena, PowerShell, Velociraptor, YARA, Suricata, osquery). Each with triggers, false positives,...
FuturesLab/Binvariants
https://github.com/FuturesLab/Binvariants
🎖@malwr
https://github.com/FuturesLab/Binvariants
This repository provides the source code for Binvariants: a prototype fuzzing framework that leverages register-level likely invariant violations for fuzzing binaries.
🎖@malwr
GitHub
GitHub - FuturesLab/Binvariants: Binvariants: Register-Level Invaraint-Guided Fuzzing for Binaries
Binvariants: Register-Level Invaraint-Guided Fuzzing for Binaries - FuturesLab/Binvariants
I'm Building a Secure USB Drive That Hides Itself
This article was written by a human, for humans. Link to support this project.
Many places don't respect privacy laws, in certain situations you …
https://rootkitlabs.com/2026/06/22/I%27m-Building-a-Secure-USB-Drive/
🎖@malwr
This article was written by a human, for humans. Link to support this project.
Many places don't respect privacy laws, in certain situations you …
https://rootkitlabs.com/2026/06/22/I%27m-Building-a-Secure-USB-Drive/
🎖@malwr
Rootkit Labs Blog
I'm Building a Secure USB Drive That Hides Itself
This article was written by a human, for humans.
Many places don’t respect privacy laws, in certain situations you may be forced to unencrypt …
Many places don’t respect privacy laws, in certain situations you may be forced to unencrypt …
Vidar Infostealer Being Spread through Phishing Emails
1. Overview First identified in 2018, Vidar operates under a Malware-as-a-Service (MaaS) model and continues to be distributed through various attack cases to this day. AhnLab SEcurity intelligence Center (ASEC) has been monitoring cases of Vidar distribution targeting Korea, and this report summarizes the Vidar distribution cases identified in the first half of 2026. […]
https://asec.ahnlab.com/en/94363/
🎖@malwr
1. Overview First identified in 2018, Vidar operates under a Malware-as-a-Service (MaaS) model and continues to be distributed through various attack cases to this day. AhnLab SEcurity intelligence Center (ASEC) has been monitoring cases of Vidar distribution targeting Korea, and this report summarizes the Vidar distribution cases identified in the first half of 2026. […]
https://asec.ahnlab.com/en/94363/
🎖@malwr
ASEC
Vidar Infostealer Being Spread through Phishing Emails - ASEC
Vidar Infostealer Being Spread through Phishing Emails ASEC
❤1
UAT-7810 continues building ORB networks using new malware
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
https://blog.talosintelligence.com/uat-7810/
🎖@malwr
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
https://blog.talosintelligence.com/uat-7810/
🎖@malwr
Cisco Talos
UAT-7810 continues building ORB networks using new malware
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
Claude Code Is Steganographically Marking Requests
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.
https://thereallo.dev/blog/claude-code-prompt-steganography
🎖@malwr
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.
https://thereallo.dev/blog/claude-code-prompt-steganography
🎖@malwr
Thereallo
Claude Code Is Steganographically Marking Requests
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.