reib3n
@reib3n1
Malware Researcher at ESET LATAM
You might like
#ESETresearch has discovered #HybridPetya ransomware on VirusTotal: a UEFI-compatible copycat of the infamous Petya/NotPetya malware. HybridPetya is capable of bypassing UEFI Secure Boot on outdated systems. @smolar_m welivesecurity.com/en/eset-resear… 1/8
#ESETresearch uncovers GhostRedirector, a threat actor compromising Windows servers with a C++ Backdoor named Rungan and Gamshen, a native IIS malware welivesecurity.com/en/eset-resear… 1/6
The embargo (12:00 UTC 2025-06-10) is over, let's start a thread on Hydroph0bia (CVE-2025-4275), a trivial SecureBoot and FW updater signature bypass in almost any Insyde H2O-based UEFI firmware used since 2012 and still in use today. English writeup: coderush.me/hydroph0bia-pa…
#ESETresearch analyzed a campaign deployed by BladedFeline, an 🇮🇷-aligned threat actor with likely ties to #OilRig. We discovered the campaign, which targeted Kurdish and 🇮🇶 government officials, in 2024. welivesecurity.com/en/eset-resear… 1/6
Another pointless weekend project - a playable version of the old 3DMaze screensaver from Windows 9x. I reverse-engineered the original screensaver binary and added user-input functionality for the controls (and fixed some other minor issues!) github.com/x86matthew/Pla…
Spotted another "Living off the..." project in the wild - LOTTunnels lottunnels.github.io
🚨NEW from Binarly: "LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux". We found a direct connection between the newly discovered #Bootkitty Linux bootkit and in-the-wild weaponized exploitation of the #LogoFAIL vulnerability. binarly.io/blog/logofail-…
#ESETresearch reveals the first Linux UEFI bootkit, Bootkitty. It disables kernel signature verification and preloads two ELFs unknown during our analysis. Also discovered, a possibly related unsigned LKM – both were uploaded to VT early this month. welivesecurity.com/en/eset-resear… 1/5
#ESETresearch discovered an #exploit targeting Firefox and Windows zero days, used in the wild by Russia-aligned #RomCom. Browsing a specially crafted web page runs arbitrary code with the privileges of the user, compromising the PC. @dmnsch & R.Dumont welivesecurity.com/en/eset-resear… 1/7
#ESET research has identified #Linux malware samples, one of which we named #WolfsBane and attribute with high confidence to #Gelsemium. This 🇨🇳 China-aligned APT group , active since 2014, has not previously been publicly reported to use Linux malware. welivesecurity.com/en/eset-resear……
#ESETresearch investigated two previously undocumented toolsets used by the #GoldenJackal APT group, both of which target air-gapped systems. welivesecurity.com/en/eset-resear… 1/6
ESETresearch discovered a zero-day exploit of #Telegram for Android allowing attackers to share malicious payloads that appear as video files via chat. We named the vulnerability being exploited #EvilVideo. welivesecurity.com/en/eset-resear… @lukasstefanko 1/4
CrowdStrike has performed the largest ransomware attack in history. Accidentally.
United States Trends
- 1. $APDN $0.20 Applied DNA N/A
- 2. $SENS $0.70 Senseonics CGM N/A
- 3. $LMT $450.50 Lockheed F-35 N/A
- 4. #CARTMANCOIN 1,967 posts
- 5. yeonjun 267K posts
- 6. Broncos 68.1K posts
- 7. Raiders 66.4K posts
- 8. #iQIYIiJOYTH2026 1.35M posts
- 9. Bo Nix 18.7K posts
- 10. Geno 19.4K posts
- 11. daniela 56.4K posts
- 12. #Pluribus 3,145 posts
- 13. Kehlani 11.6K posts
- 14. Sean Payton 4,888 posts
- 15. John Wayne 1,091 posts
- 16. Danny Brown 3,351 posts
- 17. Tammy Faye 1,712 posts
- 18. #NOLABELS_PART01 115K posts
- 19. MIND-BLOWING 22.3K posts
- 20. Kenny Pickett 1,528 posts
You might like
-
reverseame
@reverseame -
Kyle Cucci
@d4rksystem -
X-C3LL
@TheXC3LL -
Jiří Vinopal
@vinopaljiri -
Ryan "Chaps" Chapman
@rj_chap -
Monnappa K A
@monnappa22 -
What's going on...
@d41sy___ -
nickharbour
@nickharbour -
KevTheHermit
@KevTheHermit -
ekoparty NOC
@eko_noc -
Javier Bassi
@opmindcrime88 -
Joe Desimone
@dez_ -
cybercdh
@cybercdh -
💥 𝕭𝖑4𝖈𝖐𝖍0𝖑3𝖟 👾
@bl4ckh0l3z -
Gabriela Nicolao
@rove4ever
Something went wrong.
Something went wrong.