Targeted threat analysis, Incident Response, Malware Analysis and Forensics (memory/disk/network). Co-Founder @Volexity

...
5ck retweeted
Following @Volexity's September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched. UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening. Full details and IOCs can be found here: volexity.com/blog/2026/09/21… #DFIR #threatintel
3
30
75
6,288
5ck retweeted
.@Volexity Volcano v26.09.01 expands what you can analyze, and where! This release adds a powerful MCP server, threat intel integration, memory support for Linux 7.x kernels and Windows 26H1 on Snapdragon X2 ARM64, as well as MFT parsing from disk, file magic detection, importing from GCP buckets, and complete AWS GovCloud support. Contact us to schedule a demo: volexity.com/contact/demo-re…
5
6
785
5ck retweeted
Earlier this month, @Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE). Read the full analysis of the exploit chain and post-exploitation tradecraft here: volexity.com/blog/2026/09/09… #DFIR #threatintel
2
49
100
13,656
5ck retweeted
@Volexity has published details on a recent incident response investigation involving the exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. Volexity attributes this activity to a #threatactor it tracks as UTA0533, with the earliest signs of compromise dating back to June 22, 2026. SonicWall has released patches (versions 12.4.3-03453 and 12.5.0-02835) following their July 14 public disclosure. Organizations using affected SMA 1000 series devices should upgrade immediately. Read the full technical breakdown, including the vulnerability workflow, malware analysis, and IOCs: volexity.com/blog/2026/07/17… #dfir #memoryforensics #threatintel
30
48
12,976
5ck retweeted
Quick update. I am now with @Volexity :) super excited! Last few months were not the easiest but thankfully I have great friends in the field and was able to stay afloat and find the right place. I got lucky in this current job market. Back to reversing malware and drifting :)
10
7
78
2,901
5ck retweeted
.@Volexity #threatintel tracks a wide variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials. And these techniques continue to see success due to creative social engineering. [1/2]
1
10
16
3,942
Detecting and Preventing Obfuscated Script Execution with Tree-sitter, presented by David McDonald, Software Engineer at Volexity. This talk shows how tree-sitter can detect and block obfuscated scripts, strengthening defenses against AMSI bypasses and malware attacks. #BSidesNYC
4
16
2,720
5ck retweeted
APT meets GPT: @Volexity #threatintel is tracking #UTA0388's spear phishing campaigns against targets in North America, Europe & Asia, that appear to use LLMs to assist the #threatactor’s ops. Letting #AI run your espionage operations? What could go wrong? [1/2]
1
24
68
20,182
#FTSCon Speaker Spotlight: Andrew Case (@attrc) is presenting “Detection and Analysis of Memory-Only Linux Rootkits” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/fro…
7
9
2,474
#FTSCon 2025 is just a little over a month away. There are some really amazing talks lined up this year. Don't miss out on one of the best events focused on #DFIR. Hear from researchers that build tools and analysts that work on some of the most advanced IR investigations!
We are counting down to #FTSCon 2025! We have a slate of great speakers — you don't want to miss this event! If you haven't registered yet, register here: events.humanitix.com/from-th…. See the event page for details: volatilityfoundation.org/fro… Stay tuned for speaker spotlights!
3
3
1,497
Replying to @joegrand
This training is hosted by @Volatility in conjunction with From The Source (#FTSCon). Course registration includes a complimentary ticket to FTSCon on Monday, Oct 20, 2025. For more details about FTSCon, visit the event page: volatilityfoundation.org/fro….
3
2
793
Replying to @Volexity
@Volexity is looking to grow our Threat Intelligence team. New job posting for Senior Analyst role is up here: volexity.com/company/care... If you have any questions, don't hesitate to ask.
11
16
1,423
Nice work, lots of good info in this blog by @_xDeJesus!
Did a write-up on OAuth phishing (offense and defense). It's based on phishing campaign's reported by @Volexity earlier this year. - What are OAuth phishing links; what is the workflows behind them - How to emulate (examples) and use ROADtools for further compromise - Approaches to writing detections and key telemetry I do believe we are likely to see more of these campaigns over time - I hope this blog serves y'all well. Happy hunting folks! #azure #cloudsecurity #phishing elastic.co/security-labs/ent…
1
3
210
We are excited to announce FTSCon 2025 on October 20, 2025, in Arlington VA! Registration is now OPEN + we have a Call for Speakers. Following FTSCon will be a 4-day Malware & Memory Forensics Training course with Volatility 3. See the full details here: volatilityfoundation.org/ann…
11
12
10,539
New research from the team: Involves clever m365 OAuth tricks + phishing via Signal and WhatsApp to compromise accounts. #dfir #threatintel
.@Volexity #threatintel: Multiple Russian threat actors are using Signal, WhatsApp & a compromised Ukrainian gov email address to impersonate EU officials. These phishing attacks abuse 1st-party Microsoft Entra apps + OAuth to compromise targets. volexity.com/blog/2025/04/22… #dfir
2
3
1,430
.@Volexity #threatintel: Multiple Russian threat actors are using Signal, WhatsApp & a compromised Ukrainian gov email address to impersonate EU officials. These phishing attacks abuse 1st-party Microsoft Entra apps + OAuth to compromise targets. volexity.com/blog/2025/04/22… #dfir
1
61
196
133,470
5ck retweeted
Today, @Volexity released GoResolver, open-source tooling to assist reverse engineers with obfuscated Golang samples. @r00tbsd & Killian Raimbaud presented details at INCYBER Forum earlier today. Learn how GoResolver works + where to download it: volexity.com/blog/2025/04/01… #dfir
1
49
114
10,371
5ck retweeted
.@Volexity regularly assists customers in combatting advanced threat actors & we enjoy being able to assist our partners as well, including LE & federal agencies like US DOJ, as we work together to combat these advanced cyber threats. justice.gov/opa/pr/justice-d… #dfir #threatintel
3
19
2,871
Check out the new blog: Russian APT adopts a well-known technique of m365 device code phishing. When combined with clever lures this technique proved to be extremely successful. 1/2
.@Volexity recently identified multiple Russian threat actors targeting users via #socialengineering + #spearphishing campaigns with Microsoft 365 Device Code authentication (a well-known technique) with alarming success: volexity.com/blog/2025/02/13… #dfir #threatintel #m365security
1
5
8
1,661
One of the main takeaways -- block device code authentication flow via conditional access 2/2 #Microsoft365 #DFIR #ThreatIntel
5
6
1,006