Posts by malwaretech@infosec.exchange
(DIR) Post #B4AoSNUMA3pvqmRezo by malwaretech@infosec.exchange
0 likes, 0 repeats
I'm convinced this technology was invented purely just to troll me
(DIR) Post #B4OiZqlJqFrh9izwCu by malwaretech@infosec.exchange
0 likes, 0 repeats
After years of planning a potential collab, I finally got to sit down with fellow cybersecurity YouTuber David Bombal for an in person interview! Below you can check out the video from what will hopefully be the first of many more collaborations 😃 : https://www.youtube.com/watch?v=KsXzTz5H2QQ
(DIR) Post #B5Yge8us4p1y5hV3UO by malwaretech@infosec.exchange
0 likes, 0 repeats
I spent nearly 4 months investigating the inner workings of a North Korean state-sponsored hacking group. Here's what I found:- The group used generative AI tools to aid in almost every part of their operations.- They exfiltrated 26,584 cryptocurrency wallets from victim systems, with a combined value totaling as much $12 million dollars.- In several cases, the threat actors set up entire front companies to lure in developers via fake job posting, then infected them with malware.- The threat actors successfully pulled off a supply-chain attack by compromising a VS Code extension developer's system.🔗 Full article: https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/
(DIR) Post #B5Yxo1qcuVVWHjoY3U by malwaretech@infosec.exchange
0 likes, 0 repeats
@johnbrown I have less than zero interest in justifying 4 months of my own extensive intelligence work to some dipshit tankie
(DIR) Post #B5Yxte5u8eVILtdfBQ by malwaretech@infosec.exchange
0 likes, 0 repeats
@Lee_Holmes Thank you 🙏
(DIR) Post #B5ZHPrjcrAZZ3OIMmu by malwaretech@infosec.exchange
0 likes, 0 repeats
@gimulnautti Before Mythos is was zero day exploits in general. Cybersecurity has always been fixated on novel, rare, and unrealistic attacks while ignoring the hacks that happen on a daily basis
(DIR) Post #B5ZrLVD8FtVEO7JcAa by malwaretech@infosec.exchange
0 likes, 0 repeats
@johnbrown let’s not. I’d rather not take the dual HP and IQ loss from listening to your insane tankie conspiracy theories. I do actual analysis for a living and I came to my own conclusion based on my own first hand sourcing of data. Your beef with the US and your layman’s understanding of pop culture news stories about intelligence agencies is entirely irrelevant to me.
(DIR) Post #B5p1kmsPcnt7KViafo by malwaretech@infosec.exchange
5 likes, 1 repeats
Listening to cybersecurity people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.
(DIR) Post #B5ycF58XdyxXQGeA2S by malwaretech@infosec.exchange
0 likes, 0 repeats
I built an AI that autonomously finds zero day exploits https://www.youtube.com/watch?v=BLqRiL_GY3A
(DIR) Post #B63twADHJd5Cd7n5QO by malwaretech@infosec.exchange
0 likes, 1 repeats
I found a zero day in a security vendor's firewall software that allows you to remotely crash the entire system by sending it a single malicious packet. Since the firewall is responsible for inspecting traffic prior to the operating system handling it, no ports even need to be open for it to work.
(DIR) Post #B64toynpXFduN8QDhI by malwaretech@infosec.exchange
0 likes, 0 repeats
@wfh Nice work dude! I assume this locks down the ABE bypasses that work via injecting into the broker and hijacking the COM session? Does it also apply to Chrome processes launched via CreateProcess suspended for process hollowing purposes?
(DIR) Post #B6bBMjJ9ZCpcROTBZY by malwaretech@infosec.exchange
0 likes, 0 repeats
Slowly setting up my video/livestream studio again. The amount of tech required for even a half decent experience is crazy
(DIR) Post #B6bzF6F5PPPGxi7f72 by malwaretech@infosec.exchange
0 likes, 0 repeats
@heckinteagan I keep forgetting every time I upgrade it
(DIR) Post #B6bzGQKEE6F7XP9vVo by malwaretech@infosec.exchange
0 likes, 0 repeats
@Chas4 Not sure what you mean
(DIR) Post #B6d1jcxQjVTOBFVaUK by malwaretech@infosec.exchange
0 likes, 0 repeats
@GossiTheDog That is indeed oddly specific
(DIR) Post #B6milogobkSKxcPvG4 by malwaretech@infosec.exchange
0 likes, 0 repeats
My thoughts on Microsoft's threat to prosecute researchers for dropping zero day exploitshttps://www.youtube.com/watch?v=gCkfWo5rie8
(DIR) Post #B6mj1RIXLRnZ2vViRk by malwaretech@infosec.exchange
0 likes, 0 repeats
@salakala lol, wild. Really cool to see though
(DIR) Post #B6zVEm4qGwwKuyqi92 by malwaretech@infosec.exchange
0 likes, 0 repeats
It's been a while since I did a vulnerability research article. How about a little DoS zero-day as a treat? https://malwaretech.com/2026/06/exploiting-a-remote-kernel-pool-overflow-in-comodo-internet-security.html
(DIR) Post #B6zWnxxQC3Y1qzisCG by malwaretech@infosec.exchange
0 likes, 0 repeats
It's been a while since I did a vulnerability research article. How about a little DoS zero-day as a treat? https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html?1
(DIR) Post #B6zflC0AQ5sm87l8j2 by malwaretech@infosec.exchange
0 likes, 0 repeats
ComoDoS - Exploiting a Remote Kernel Zero-Day Vulnerability in Comodo Internet SecurityHow an IP parsing vulnerability makes it possible to remotely crash systems with a single TCP/IP packethttps://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html