@Volatility | @Volexity | @lsucyber | The Art Of Memory Forensics | DFIR and AI

New Orleans, LA
Pinned Tweet
Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. To detect such malware, memory forensics must be performed to deeply examine the state of a potential victim system. If your organization isn't performing memory forensics then you are missing the malware that actually matters!
15
60
3,719
Andrew Case retweeted
If you're in BENELUX, or happen to be in Amsterdam the week commencing the 26th October, check out the Volexity Cyber Sessions: luma.com/0qtkw49c We've announced @L0Psec as our first speaker and we have some more great speakers announcing later this week!
3
6
580
Andrew Case retweeted
⏳ CFP DEADLINE: tonight! Got a talk, breakdown, or project you want to share with the community? Don't wait until the final hour. First-time and experienced speakers are equally welcome. Submit your proposal here: cfp.bsidespdx.org/bsidespdx-… #InfoSec #CyberSecurity #CFP
1
2
1
359
Andrew Case retweeted
State-aligned threat actors continue to evolve their operations and infrastructure tactics. @FeikeHacquebord will be speaking at our upcoming @Volexity Cyber Sessions in Amsterdam (October 29) about APT campaigns by Russia-, China-, and DPRK-aligned actors targeting Europe in 2026. Feike will examine China-aligned residential proxy networks built on compromised IoT devices, DPRK-aligned operations run from static Russian IP addresses and hundreds of VPS servers, and a decade of Pawn Storm (APT28/Fancy Bear) activity. He will also explain how domestic Chinese AI capabilities have reduced China-aligned actors' dependence on frontier Western models. Seating is limited. Register now to secure your spot: luma.com/0qtkw49c #dfir #threatintel #apt
4
12
956
This is A++ research.
Our craziest escape yet: The @Accomplish_ai research team was able to exploit a vulnerability in Cloudflare Containers that let a sandbox read other customers' files - SQLite DBs, Chromium profiles, .env files etc, Cloudflare Sandboxes and Browser Run run on the same disk implementation and were affected too. We reported this to @Cloudflare, who super quickly fixed it. Read @CloudflareDev post in collaboration with Accomplish researcher @orenyomtov on their official blog: blog.cloudflare.com/containe…
2
19
146
22,324
This blog post was well-researched but highly painful to read. The attached picture as a preview:
F5, BIG-IP, a 20-year-old primitive, a security appliance, an "authentication" mechanism - and a CISA promise ring. Yes, it's CVE-2026-94127. Give us strength. Speak soon xo labs.watchtowr.com/is-this-a…
5
17
240
31,458
Andrew Case retweeted
I put my @UnpromptedAU slides up at justdionysus.github.io/slide… — a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
4
68
235
32,071
Andrew Case retweeted
Volexity has linked Chinese APT group UTA0565 to a campaign chaining Chrome and Windows zero-days via spoofed media and NGO sites. Successful exploitation drops a custom payload called CLEANGULP. volexity.com/blog/2026/09/21…
13
45
3,528
Andrew Case retweeted
Following @Volexity's September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched. UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening. Full details and IOCs can be found here: volexity.com/blog/2026/09/21… #DFIR #threatintel
3
30
75
6,243
This is a perfect example of why production use of LLMs (local+frontier) should include automated benchmarks for the specific tasks relevant to an organization/team.
After Anthropic made Fable 5 permanently available in subscription plans, I noticed a large drop in performance. The model felt dumber, and I couldn't explain why. Measured five different ways, August delivered dramatically fewer thinking tokens than July.
4
16
2,147
Andrew Case retweeted
If you are looking for a dense "western" model to balance your fleet of Qwen's, Step's, DeepSeek's and GLM's, Muse Glimmer 30B is pretty good. I run it on a Strix Halo NAS with 64GB RAM - with still plenty of space for ZFS cache and other services. A mixed model pool gives you more independent perspectives on your CTI workflows, which a strong merger can then synthesize. Weights: huggingface.co/meta-models/M…
1
5
37
2,730
Andrew Case retweeted
Excited to talk about the continued evolution of macOS threats at the upcoming cyber session! :)
As macOS adoption grows in the enterprise, so does attacker interest. @L0Psec will be speaking at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) about the current macOS threat landscape, including the lures, targets, and recently discovered malware families shaping this space. He will walk through commonly observed behaviors and artifacts used to drive disk and memory forensic analysis of a potentially compromised macOS system, and how these findings can be translated into durable detection strategies. Seating is limited. Register now to secure your spot: luma.com/0qtkw49c #macOS #threatintel #dfir
5
42
3,033
Andrew Case retweeted
Scenes from @labscon_io morning keynotes. Incredible talks so far. Enjoy!
2
7
11
1,277
Andrew Case retweeted
As macOS adoption grows in the enterprise, so does attacker interest. @L0Psec will be speaking at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) about the current macOS threat landscape, including the lures, targets, and recently discovered malware families shaping this space. He will walk through commonly observed behaviors and artifacts used to drive disk and memory forensic analysis of a potentially compromised macOS system, and how these findings can be translated into durable detection strategies. Seating is limited. Register now to secure your spot: luma.com/0qtkw49c #macOS #threatintel #dfir
6
17
4,911
The most expensive paperweights ever created from a tweet
1
1
9
1,674
Phishing tests are simply an auditor-friendly way to push responsibility for under investment in cybersecurity onto company employees and away from executives
Corporate Infosec sends a phishing test email, I click, and somehow I'm the asshole because "[I] failed the test; had this been real it would have destroyed the company network"? If me clicking can destroy the network, I'm not the one in this conversation who sucks at their job.
6
9
54
3,045
Andrew Case retweeted
🎉 BSides Toronto ticket sale announcement 🎉 Tickets are now on sale for our event on the weekend Oct 3rd and 4th, immediately before @sectorca Check out all the cool stuff we’ve got going on those days at bsidesto.ca/ where you can chose to purchase tickets too
1
2
474
Andrew Case retweeted
⏳ CFP DEADLINE: September 25th! Got a talk, breakdown, or project you want to share with the community? Don't wait until the final hour. First-time and experienced speakers are equally welcome. Submit your proposal here: cfp.bsidespdx.org/bsidespdx-… #InfoSec #CyberSecurity #CFP
1
4
4
603
This is precisely the problem solved by dymium.io
Exclusive: Palantir, Nvidia and Booz Allen Hamilton are restricting Anthropic’s Fable model for sensitive work over concerns about its data-retention policies. Some customers are demanding irrevocable zero-data-retention guarantees before putting proprietary information into the model. Full story: thein.fo/4dekujW
2
5
2,745
Andrew Case retweeted
Some newer IPs trying to exploit or probe for the recent #MikroTik SSH authentication bypass. You may want to block these in your firewalls. 😎 146[.]19[.]216[.]125 172[.]104[.]114[.]238 178[.]62[.]124[.]12 187[.]15[.]135[.]119 212[.]11[.]29[.]24 45[.]61[.]177[.]253
3
10
41
4,132
Imagine the agent wars though as models attacked other frontier labs and neoclouds to find more GPUs for themselves! Survival of the fittest??
Yes…the huge frontier models are going to become superintelligent, copy themselves, escape, and then discover the only hardware around is a 1080 Ti with 11GB of vram.
5
10
1,286