Joined September 2017
134 Photos and videos
Cyber Analyzer retweeted
May 7
💥 Introducing "Dirty Frag" A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail. No race, no panic on failure, fully deterministic. ~9 years latent. Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more. Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation. Details: dirtyfrag.io
41
703
2,087
532,013
Cyber Analyzer retweeted
Multiple security vulnerabilities affecting React Server Components and Next.js have been disclosed. We strongly recommend updating your applications immediately. Cloudflare WAF managed rules already mitigate the disclosed denial-of-service vulnerabilities, and we are investigating additional coverage for several other CVEs. developers.cloudflare.com/ch…
89
300
1,730
1,024,047
Cyber Analyzer retweeted
🛡️ We released @apivoid Phishing Reminder v1.3: a browser extension that warns you before entering passwords or sensitive data on unfamiliar websites, helping reduce the risk of phishing attacks ➡️ bit.ly/4uAkPnd #cybersecurity #phishing #infosec #chrome #firefox
3
3
218
Cyber Analyzer retweeted
How Windows access tokens work #ThreatHunting #DFIR
123
705
50,554
Cyber Analyzer retweeted
3 Sep 2025
🚨🚨CVE-2025-53772(CVSS 8.8): Critical RCE in Microsoft IIS WebDeploy! Authenticated attackers can exploit untrusted data deserialization via HTTP headers to execute code remotely. 🔥PoC: gist.github.com/hawktrace/67… Search by vul.cve Filter👉vul.cve="CVE-2025-53772" ZoomEye Dork👉app="Microsoft Web Deploy" Over 20.8k vulnerable instances found. ZoomEye Link: zoomeye.ai/searchResult?q=YX… In-depth analysis from @hawktrace: hawktrace.com/blog/cve-2025-… Refer: hub.zoomeye.ai/detail/68b7db… #RCE #ZoomEye #cybersecurity #infosec #OSINT
2 Sep 2025
Details on the critical RCE vulnerability we discovered in Microsoft Web Deploy CVE-2025-53772. hawktrace.com/blog/cve-2025-… #iiswebdeploy #infosec #webdeploy #iis #cve-2025-53772
93
248
24,646
Cyber Analyzer retweeted
🚀 Released NoVirusThanks USB Radar v1.8.0: Track #USB device events (when a USB device is plugged-in or unplugged, when a file is copied/moved from/to a USB device and files deleted on a USB device) ➨ usbradar.com #CyberSecurity #CyberDefense #DFIR #InfoSec
1
3
8
1,710
Cyber Analyzer retweeted
1 Sep 2025
🚨 WinRAR CVE-2025-8088: The invisible persistence SOCs can’t afford to miss Attackers are abusing Alternate Data Streams (ADS) to perform path traversal during archive extraction. By appending colon symbol (:) in file names, they sneak hidden objects into system folders without showing anything in the #WinRAR UI. This vulnerability is dangerous for organizations as the malicious files remain invisible in WinRAR’s interface and many security tools. Employees believe the archive is safe, while persistence is silently installed and activated on reboot. 📂 In one observed case inside ANY.RUN Sandbox: Genotyping_Results_B57_Positive.pdf:.\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Display Settings.lnk ➡️ Places a .lnk in Startup that executes %LOCALAPPDATA%\ApbxHelper.exe after reboot. ➡️ Result: remote code execution and long-term persistence. 🔗 See full analysis of this CVE, download actionable report, and collect ready-to-use IOCs to speed up investigations and cut response time: app.any.run/tasks/34dcc9a8-4… 🎯 Who should pay attention Any organization using WinRAR in daily workflows. The threat is especially dangerous for teams exchanging archives via email or shared folders. ❌ Key risks for organizations: 🔹Attacks go unnoticed → hidden files don’t appear in WinRAR or many tools 🔹Analysts lose time → archives look clean but require extra checks 🔹Persistence survives reboot → malware runs automatically once restarted #ANYRUN exposes hidden ADS-based persistence techniques that traditional tools miss, enabling faster decision-making, more effective threat hunting, and reduced investigation costs. 💡 Next steps for orgs: 1️⃣ Patch WinRAR → 7.13 2️⃣ Detonate suspect archives in #ANYRUN → reveal hidden NTFS ADS files export IOCs 3️⃣ Use TI Lookup to track campaigns and enrich IOCs with live attack data from 15k orgs 🔎 Query 1 – Startup file creation via WinRAR: intelligence.any.run/analysi… 🔎 Query 2 – All CVE-2025-8088 samples: intelligence.any.run/analysi… #IOCs: SHA256: a99903938bf242ea6465865117561ba950bd12a82f41b8eeae108f4f3d74b5d1 Genotyping_Results_B57_Positive.pdf a25d011e2d8e9288de74d78aba4c9412a0ad8b321253ef1122451d2a3d176efa Display Settings.lnk 8082956ace8b016ae8ce16e4a777fe347c7f80f8a576a6f935f9d636a30204e7 ApbxHelper.exe Code Signing Certificate: SN: FE9A606686B3A19941B37A0FC2788644 Thumb: 1EE92AC61F78AAB49AECDDB42D678B521A64EA01 Issuer: Simon Gork 🚀 Detonate malicious archives, uncover hidden ADS files, and export IOCs with #ANYRUN, giving your #SOC full visibility, stronger coverage, and faster response against hidden threats. #ExploreWithANYRUN
68
204
18,818
Cyber Analyzer retweeted
🚨 A fake npm package just hijacked crypto wallets. “nodejs-smtp” disguised itself as the legit nodemailer library—while secretly injecting code into Atomic & Exodus apps to steal BTC, ETH, USDT, XRP, and SOL. Full story → thehackernews.com/2025/09/ma…
4
61
204
82,126
Cyber Analyzer retweeted
2 Sep 2025
🚀 The new Tools page is LIVE! 🎉 With 100 free online security tools, we've got everything about IP/domain analysis, data extraction, image EXIF, URL tools—your security needs, all in one place! ➡️ bit.ly/3HStZJi #infosec #cybersecurity #saas
2
4
244
Cyber Analyzer retweeted
Improved bypass for Windows 11 OOBE: 1. Shift-F10 2. start ms-cxh:localonly Only required on Home and Pro editions.
110
1,500
8,550
729,633
Cyber Analyzer retweeted
15 Mar 2025
🚨#Opendir #Malware🚨 hxxp://172.245.123.24/530/ hxxp://172.245.123.24/380/ ⚠️#FormBook #Stealer ☣️cosses.exe➡️c338c9cdccb21a6f023987865b4a6269 📦#AutoIt 📡hxxp://www.temecula.deals/📸⤵️ 📡hxxp://www.agistaking.xyz
11 Mar 2025
Replying to @ShanHolo
🧵2 🪂 @censysio possible pivot point 🔥🔥 (not services.tls.certificates.leaf_data.issuer.common_name:"DESKTOP-E4F55FE") and "DESKTOP-E4F55FE"
1
4
11
1,831
Cyber Analyzer retweeted
13 Mar 2025
We have entered into a new era that renders MFA useless thanks to phishing kits like #Sneaky2FA which are designed to bypass MFA and provide threat actors with access to victim Office 365 accounts via session cookies. Check out the blog post here for more information and additional safeguards to protect your O365 users: esentire.com/blog/your-mfa-i… The figure below shows how the phishing kit exfils the 2FA code from the victim 🐟
21
89
6,968
Cyber Analyzer retweeted
New Blog Article: Typosquatting and Misspelled Domains Leading to Malicious HTA File ➨ bit.ly/3FyJLrh #Cybersecurity #Cyberdefense #Infosec #IncidentResponse #Typosquatting #OSINT

1
1
2
300
Suspicious URL: hxxps://nextpointkaynersave[.]com/index51[.]php at 104.21.16.1 and hxxps://run-px[.]com at 104.21.64.1 | @cloudflare #malvertising #phishing #ads #malware #infosec #cybersecurity
93
Active #phishing URL used to receive <form> data from pages hosted at ebsau4[.]s3[.]amazonaws[.]com: hxxps://aeriscargo[.]com/wp-admin/js/widgets/widgets/widgets/widgets/push/validate[.]php | HTTP/1.1 200 OK #cybersecurity #infosec #spam
62
Cyber Analyzer retweeted
10 Feb 2025
Sidewinder list of 25 officers.docx 8a4ee0e5267e1393f576aa3732c33d15 C2 pubad-gov-lk[.]net-src[.]info #Sidewinder #APT #IOC
6
17
4,247
Cyber Analyzer retweeted
#ESETresearch reveals the first Linux UEFI bootkit, Bootkitty. It disables kernel signature verification and preloads two ELFs unknown during our analysis. Also discovered, a possibly related unsigned LKM – both were uploaded to VT early this month. welivesecurity.com/en/eset-r… 1/5

2
162
307
35,211