liba2k retweeted
The @LastPass TIME team and Delphos identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub. The payload delivered a Microsoft-attested kernel driver that terminated 145 antivirus and EDR processes from kernel mode. It scored 0 out of 72 on VirusTotal as of August 20. The driver is a renamed copy of CcProtect.sys, which LOLDrivers already catalogues as a BYOVD process killer, with public PoC code. Same product string, version, and submitter. The operators changed the filename to Alinubx.sys. That was the evasion. Detections keyed to the known name did not match, and renaming a file changes its bytes, so the SHA256 moved with it. A blocklist of known bad hashes does not have this one. Same driver, same version, same submitter, one new filename. That was enough. Joint writeup with @LastPass. Hashes, hunt queries, and the full CcProtect comparison are in the post. delphoslabs.com/blog/alinubx…
2
3
13
722
liba2k retweeted
Kamil Leoniak found a descriptor parser bug in usbvideo.sys, the USB Video Class driver in Windows, during an automated Delphos Labs review of the compiled driver. The validator accepts a descriptor that cannot advance the parser. The old path rejected bLength=0 because it checked whether the pointer would actually move forward. The newer path, behind Feature_Servicing_UvcDescriptPointerFix and on by default, checks only that the length fits in the remaining buffer. Zero fits, so the caller advances by zero and the loop parses the same descriptor forever. 34 bytes of configuration descriptor were enough, served from a Teensy 3.2 as a single-function UVC device. One core pinned at 100% in kernel mode, USB enumeration stopped system-wide, unplugging did not recover it, normal reboot blocked. Three times from a clean boot. MSRC closed it on July 23 as not a bug. No CVE, no patch.
1
3
4
400
liba2k retweeted
One of our security researchers at Delphos Labs, Kamil Leoniak, triggered kernel memory corruption on Windows using a custom USB device and a user-mode stress PoC. Microsoft assigned CVE-2026-50321, classified it as a Windows USB Driver elevation of privilege, and shipped the fix on July 14. The bug is that the freed object reference stayed reachable long enough for another path to use it. WinUSB_FreePipe frees a pipe context and only nulls the shared pointer afterward. In that window the interface pipe array still points at freed memory, and device-control IOCTLs dispatch on a WDF parallel queue, so nothing serializes access to that array. 16 threads were enough. 12 calling pipe policy APIs, 4 toggling alternate settings. A policy call read the stale pointer and took a spinlock inside a freed 0xF0-byte NonPagedPool object. Without Special Pool that allocation stays mapped and reclaimable. With it, the machine bugchecks. Full writeup on the Delphos Labs blog, with the PoC on GitHub. delphoslabs.com/blog/cve-202…
5
18
979
liba2k retweeted
A credential stealer took the name of libpsl-5.dll, a Windows library of approximately 200KB, and inflated itself to 55MB. Zero detections across 60+ AV engines when we analyzed it. The Delphos Labs platform pulled it apart on day one; the automated run took 8 minutes, with no human intervention. The vendors did not catch up for six days. The bloated size is the primary evasion mechanism. The real code ends at about 3.3MB. The other 52MB is a single four-byte pattern repeated across the entire overlay, sitting outside every PE section and outside the image the Windows loader maps. The loader never reads it. It executes nothing. Its only job is to push the file past the size most engines and sandboxes scan. No signatures. Detection came from the size mismatch, plus an import table pairing process injection with network enumeration, nothing a suffix-list library would do. Its code overlaps several known stealer families. delphoslabs.com/blog/39d4237…
5
3
411
liba2k retweeted
One of our security researchers demonstrated a local root shell on Linux using a page-cache poisoning primitive in AF_RXRPC’s RxGK path. We call it DirtyCBC: a sibling to DirtyFrag in the broader CopyFail / DirtyFrag / Fragnesia family. The issue is fixed on mainline. The candidate path was surfaced through Delphos’s agentic analysis workflow, then manually verified and exploited end to end. AES-256 was not broken. It just wasn’t the boundary that mattered. RxGK decrypted data in place before authentication completed. Under the right conditions, that write could land in the page cache. The HMAC check still failed and the connection was aborted, but the page-cache mutation had already happened. Two RESPONSE packets were enough to place a tiny ELF into the cached first page of a readable SUID-root binary. The file on disk stayed unchanged. The next exec produced a root shell. Full writeup and PoC on the Delphos Labs GitHub. delphoslabs.com/blog/3614237…
5
68
291
62,986
We’re hiring 🚀 Security Researcher & Software Engineer @ Delphos Labs Build AI-powered systems for reverse engineering — tools where AI understands software, automates binary analysis, and scales how we reason about code. 🔗 jobs.ashbyhq.com/delphos-lab… #securityresearch #hiring
1
89
XZ backdoor (liblzma.so.5.6.1) fully exposed in minutes with Delphos Labs. Black-box binaries? No more. Traditional tools would still be unpacking. That’s software, verified.
Black-box binaries? Over. We ran the xz-utils backdoor (liblzma.so.5.6.1) through our AI and it lit up: runtime JMP patching, custom byte-table crypto, encrypted IPC—caught in minutes. Full teardown 👉 delphoslabs.com/uploads/f382… What would you audit next? #xzbackdoor #ReverseEngineering
3
5
565
Binary highlight: “Cyberpunk 7777 / QubePi” ELF. Text-menu game with hard-coded Postgres creds. Every login/chat/coord sent in clear on 5432—no TLS, no sanitization. Delphos auto-exposed the creds & flow in minutes. Sample: delphoslabs.com/uploads/26cc… #ReverseEngineering
1
3
8
459
At @DelphosLabs, we're building tools to automate reverse engineering, no source code required. Help shape what we build next 👇 docs.google.com/forms/d/e/1F… It takes just a few minutes. Anonymous unless you opt in. Thanks for your input! 🙏
2
70
Machine Learning Meets Malware. If cognition becomes an API call and malware can be reverse-engineered by an LLM, then what’s left of “zero trust”? Caleb Fenton joined @patio11 for a chat on AI, nation-states, and the new front in software security. 🎧complexsystemspodcast.com/ep…
1
5
4
285
If you like building platforms and infrastructure and want to get in on the ground floor of a cyber security startup doing AI and reverse engineering, DM me.
2
6
909
Why not 3d printing #ChatGPT
2
2
283
Of course the code doesn't work, but it's a start :D
2
91
Happy Friday everyone! Want a ProcMon for macOS? Ever wish you had your own Endpoint Security client you could task? Want to peer behind the macOS EDR curtain? Have a go and let us know what you think! github.com/redcanaryco/mac-m…
9
173
441
54,858
liba2k retweeted
New Tiny #tinyML #AIoT module M0S coming out~ Based on BL616, WiFi6+BT5.2+Zigbee, 384MHz #RISCV RV32GCP, 4MB Flash + 512KB SRAM, and USB2.0 HS in tiny 10x11mm stamp module! It would be <2$ ~
33
196
1,023
180,707
The talk that @assaf_carlsbad and I presented at #INS22 is up on youtube. piped.video/watch?v=ge_TnLfT…
8
25
Yesterday @liba2k and I presented our talk "Breaking Secure Boot with SMM" at @1ns0mn1h4ck. The slides, exploit code, and some additional resources are now online and available here: github.com/liba2k/Insomni-Ha… Thanks to everyone who attended, we hope to see you all again next time!
2
58
157
In what seems like nearly perfect conjunction with the latest @binarly_io disclosure, today we publish the 6th installment of our UEFI blog post series where we dissect 6 new vulnerabilities in HP's firmware that allow privilege escalation to SMM. sentinelone.com/labs/another… @liba2k
2
21
37