Devon Kerr
@_devonkerr_
Director of Threat Research and @ElasticSecLabs team lead; custodian of secret histories. Posts are my own.
You might like
📋 In the latest Microsoft report, the DART team discovered a new backdoor dubbed SesameOp, abusing the OpenAI Assistants API to run covert C2 communication without any model inference! I made a diagram to show how the backdoor works! Great work 👏 microsoft.com/en-us/security…
Awesome new threat report from Google Threat Intel Group documenting how threat actors are leveraging Gemini. A lot of information and actionable avalable in the report! Great work 👌 services.google.com/fh/files/misc/…
tfw generative AI behaves more like degenerative AI, amirite
Elastic PM @jamesspi joins security expert @_JohnHammond to unpack how Elastic’s powerful SIEM, XDR, and EDR solutions—enhanced with cutting-edge AI—help teams detect and respond to threats faster. Watch now: go.es.io/4hkLrDB
The HackingTeam is back! New name, new malware, new exploits securelist.com/forumtroll-apt…
One downside no one tells you about aging, is that so much of what you remember is the past. Thoughts inspired by Ghostbusters.
Some really cool research from @saab_sec on alternatives to sleep masking 🔥🔥
Interested in an alternative approach to sleep masking for you malware? Check-out our latest blog post "Function Peekaboo: Crafting self masking functions using LLVM" by @saab_sec mdsec.co.uk/2025/10/functi…
Growing up, I really thought the Bermuda Triangle and quicksand would play bigger roles in daily life.
REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally. elastic.co/security-labs/…
Great research from Mandiant, learned a lot from their analysis. cloud.google.com/blog/topics/th… Found more trojanized JavaScripts communicating with the same transaction hash. Sometimes it’s shocking how well DPRK actors understand blockchain mechanics and weaponize them.…
@0xkyle dropping some heat on clustering PDFs with PDF object hashing 🔥🤖 This has been paying dividends in our hunting & tracking efforts in house, excited to see it open sourced! proofpoint.com/us/blog/threat…
Time-to-Patch Metrics: A Survival Analysis Approach Using Qualys and Elastic — Elastic Security Labs elastic.co/security-labs/…
Elastic Security Labsが、公開済みのASP[.]NET machineKeyを悪用したグローバルなIIS感染キャンペーン(REF3927)を公開しました。 elastic.co/security-labs/……
#ElasticSecurityLabs joins forces with @tamusystem and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57
Your team and the customer squashing it from the get go was great! Love talking about good folks doin' the good work!
This is good analysis:
Anyway, we wanted to tell a bit later, but we had to rush it now, as fellows did publish about the same toolset today (as "TOLLBOOTH"). We're fewer guys but we may still have found a bit more. IOCs & Yaras: harfanglab.io/insidethelab/r…
Always great to work with y'all, we always seem to do some cool stuff when we get together!
Thanks for being generous with your time and expertise on this @SreekarMad! Good stuff! @ValidinLLC
#ElasticSecurityLabs joins forces with @tamusystem and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57
United States Trends
- 1. Marshawn Kneeland 19.3K posts
- 2. Nancy Pelosi 23.1K posts
- 3. #MichaelMovie 31.9K posts
- 4. #영원한_넘버원캡틴쭝_생일 24.7K posts
- 5. ESPN Bet 2,233 posts
- 6. #NO1ShinesLikeHongjoong 25.3K posts
- 7. Gremlins 3 2,706 posts
- 8. Jaafar 9,703 posts
- 9. Chimecho 4,895 posts
- 10. #thursdayvibes 2,894 posts
- 11. Good Thursday 35.8K posts
- 12. Joe Dante N/A
- 13. Baxcalibur 3,449 posts
- 14. Madam Speaker N/A
- 15. Chris Columbus 2,440 posts
- 16. #BrightStar_THE8Day 37.1K posts
- 17. Votar No 28K posts
- 18. Penn 9,536 posts
- 19. Happy Friday Eve 1,009 posts
- 20. Barstool 1,643 posts
You might like
-
Steve YARA Synapse Miller
@stvemillertime -
Will Schroeder
@harmj0y -
Roberto Rodriguez 🇵🇪
@Cyb3rWard0g -
Sean Metcalf
@PyroTek3 -
Olaf Hartong
@olafhartong -
Christopher Glyer
@cglyer -
Nick Carr
@ItsReallyNick -
Matthew Dunwoody
@matthewdunwoody -
Paul Melson
@pmelson -
Lee Chagolla-Christensen
@tifkin_ -
Matt Nelson
@enigma0x3 -
Ryan Cobb
@cobbr_io -
Tim MalcomVetter
@malcomvetter -
Jared Atkinson
@jaredcatkinson -
Jason Lang
@curi0usJack
Something went wrong.
Something went wrong.