IMO itβs often used as a generic catch all title for those who wear a lot of hats in their jobs such as threat research, malware analysis, detection engineering, etc.
IMO itβs often used as a generic catch all title for those who wear a lot of hats in their jobs such as threat research, malware analysis, detection engineering, etc.
You are hitting it hard this week, well done!
Wait, AI canβt replace that right?
On this episode of Discarded, our team explores how #artificialintelligence is shaping modern #malware analysis and detection workflows.
Listen now on your favorite #podcast platform, and you'll get a balanced view of AI's growing impact on cybersecurity.
ποΈ: www.proofpoint.com/us/podcasts/...
π€ Happy to see that my DEFCON talk on crypto money laundering and tracking techniques was featured in the DEFCON 33 Almanac!
Read it here: https://harris.uchicago.edu/sites/default/files/the_def_con_33_hackers_almanack.pdf
I started making comics, in part, as a respite from the grind that is cybersecurity.
Only hackers/scammers are everywhere. Iβm no @johnhammond.bsky.social but here is my video on how scammers try to take advantage of creators on Kickstarter.
This looks very interesting! π
Episode 2 of Breach Log is now available! Special thanks to Max Margolis for joining me and telling his story.
If you have a story you'd like to share, get in contact and we can have some fun! breachlogpodcast [@] gmail[.]com
open.spotify.com/episode/4SDz...
π€ Let me introduce you to MoltThreats: The first AI Threat Intel Feed for Ai Agents!
In one week, OpenClaw became a widely used general AI agent. People started to run their own agents all over the world and connect them directly to the internet.
But this [β¦]
[Original post on infosec.exchange]
You do an amazing job of staying on top of all these things!
Nothing says optimal workout recovery like cream cheese
2026-01-31 (Friday): I've posted a new traffic analysis exercise. It's Lumma in the room-ah! Join the fun at www.malware-traffic-analysis.net/2026/01/31/i...
I mean, this guy looks like he's having fun.
yolo
Screenshot from an infected Windows host showing Remcos RAT and how it is persistent.
2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at www.malware-traffic-analysis.net/2026/01/06/i...
I've released my new course:
Practical Threat Hunting for Beginners
Similar courses: $$$$
This course: $$
academy.bluraven.io/course/pract...
#ThreatHunting #DetectionEngineering
π¦ πΉ New Video: Can office files be malicious without Macros?
β‘οΈ VSTO Add-Ins
β‘οΈ External Templates
β‘οΈ Checklist for Office analysis
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=RtHH...
Nice work on this one and how it works with blockchain for storing payloads. Do you have any IOCs for the initial html/javascript from the compromised websites? Thanks!
Karsten's samplepedia is a great resource for malware samples and analysis solutions!
How quaint that was
It keeps you employed
Is the 9-5 a thing of the past? π Dhillon Kannabhiran (HITB) says the "hacker ethos" is replacing the corporate ladder. From on-demand bug hunting to working across time zones, the rules of the game have changed.
podcasts.apple.com/us/podcast/e...
Hopefully you got most of your birthday back!
Is drunk Bajiri good for IR?
Nice work, Lenny! I plan to take advantage of this tool.
π΅βπ« The Chrome extension ecosystem really is the wild west, and remains largely uncharted territory for security teams. You need visibility into whatβs actually running in the browser.
cc: @campuscodi.risky.biz @zackwhittaker.com @bleepingcomputer.com
Nice work from @malware-traffic-analysis.net in the ISC diary blog on Lumma scheduled tasks from yesterday: isc.sans.edu/diary/Infect...
Good for you, glad itβs helping
I always think first about the personality, how well would they fit into the team and work well with others. Assuming some base level of technical expertise is there.
I released a tool for making your website or docs easily available to AI assistants via an MCP server. This helps ensure people's AI tooling can access the latest details at the right time. For instance, this is how REMnux users now can get info about its malware analysis tools.
Recommending this one, itβs a great idea! π