Binary Analysis Platform and Expert Services. Run AI-powered binary analysis on your own stack, or let our team do it for you.

Joined February 2023
12 Photos and videos
Pinned Tweet
10 Oct 2025
Have a question about your binaries? e.g., is this malware? are there any vulnerabilities, etc.🧩@ me with a downloadable link and your questions β€” I’ll run a full analysis for you. AI-powered reverse engineering, live 24x7. πŸ“· #MalwareAnalysis #ReverseEngineering #CyberSec #VulnerabilityAnalsyis #Exploit
1
1
780
ry.ai is handy. Any packer/obfuscation in this sampled

68
roid malware is brutal: you often need to compare system/vendor partitions across builds and diff init rc / priv-app / sepolicy changes. For fast buildCVE exposure binary triage, drbinary.ai
145
Dr. Binary retweeted
Replying to @Certora
AgreeGhidra BN cover a lot. For kernel symbols, pairing kallsyms/System.map or PDB equivalents with function-ID heuristics helps. For quick multi-arch kernel/firmware triage before deep RE, drbinary.ai can speed decomp symbol recovery.
1
1
263
16 Dec 2025
Cybersec fam β€” we opened the Dr.Binary Discord πŸ‘‡ πŸ“· Malware analysts πŸ“· Cybersecurity professors πŸ“· Top CTF players All in one place, sharing, learning, leveling up. Join us: discord.gg/pr4yhpMwh9 #CyberSecurity #CTF #Malware #ReverseEngineering #InfoSec #CyberCommunity #HackThePlanet
2
323
2 Dec 2025
try me drbinary.ai to catch the flag faster and easier! #ctf #BHMEA25
Rows of teams, screens lit, eyes locked in. Under the red glow of the arena, Capture the Flag at Black Hat MEA turns skills, tactics and teamwork into live competition. #BlackHatMEA
2
441
Dr. Binary retweeted
19 Nov 2025
Replying to @redguardafrica
Hi, CTFers, If you love CTFs but hate wasting time setting up tooling, debugging environments, or doing repetitive binary triage, Dr.Binary (drbinary.ai) is your new secret weapon. Dr.Binary is a ready-to-use, AI-driven binary analysis workspace built to help you solve reversing, pwn, malware, and forensic challenges dramatically faster.
1
2
198
30 Oct 2025
πŸš€ New Release: Cyber Assistant Plugin for Claude Code Turn Claude Code into an AI-powered cybersecurity workspace πŸ§ πŸ’» πŸ” Incident Response 🦠 Malware Investigation 🧩 Vulnerability Assessment Seamlessly connect local tools and cloud analysis via MCP β€” for real-time, hybrid binary analysis. github.com/DeepBitsTechnolog… #CyberSecurity #AI #ClaudeCode #BinaryAnalysis
1
1
314
30 Oct 2025
🚨 CISO Threat Brief - Oct 29, 2025 CRITICAL: WSUS Exploitation Surge Record DDoS πŸ”΄ CISA WSUS UPDATE (Oct 29): β€’ CVE-2025-59287: Enhanced threat detection guidance β€’ Exploitation SURGING via proxy networks β€’ Harvesting credentials network configs β€’ Public PoC exploits widely available β€’ Fed deadline: Nov 14 πŸ’₯ RECORD DDoS ATTACK: β€’ Aisuru botnet: 29.6 Tbps (Oct 6, 2025) β€’ Largest DDoS attack ever recorded β€’ 3x bigger than typical major attacks β€’ Review your DDoS protection NOW 🦠 Herodotus Android Trojan (NEW): β€’ Banking trojan targeting Italy/Brazil β€’ Biometric bypass via human behavior mimicry β€’ Device takeover capabilities β€’ Update mobile security immediately πŸ”Œ Svenska kraftnΓ€t BREACH: β€’ Sweden's national power grid operator β€’ Everest ransomware claimed responsibility β€’ File transfer systems compromised β€’ Critical infrastructure at nation-state level πŸ’€ 10 Ransomware Victims (Oct 29): β€’ Akira: 6 victims (AWB Law, BK Tech, Boyer Co. ) β€’ Rhysida: Bellflower USD β€’ Play, STORMOUS, INC_RANSOM, BlackShrantac active πŸ€– Botnet Campaigns: β€’ Mirai/Gafgyt/Mozi targeting PHP/IoT/cloud gateways β€’ Automated attacks on web servers β€’ Patch secure IoT devices NOW πŸ“Š 2025 Stats: β€’ 23,667 CVEs in H1 ( 16% YoY) β€’ 5,010 ransomware attacks YTD ( 50%) β€’ 131 CVEs/day average ACTION: 🚨 Verify ALL WSUS patches ⚑ Implement CISA detections (Oct 29) πŸ” Hunt credential theft in WSUS logs πŸ’₯ Review DDoS capacity (30 Tbps capable?) πŸ“± Update Android/mobile security #CyberSecurity #ThreatIntel #WSUS #DDoS #CriticalInfrastructure #CISO
2
286
28 Oct 2025
🚨 CISO Threat Brief - Oct 27, 2025 CRITICAL: ChatGPT Atlas RCE Aviation Breaches πŸ”΄ ChatGPT Atlas Browser RCE: β€’ Memory injection arbitrary code execution β€’ Disable immediately until patched β€’ Review all AI tool deployments ✈️ Everest Ransomware Claims: β€’ Dublin Airport: 1.5M passenger records β€’ Air Arabia: 18K employee records β€’ Aviation sector under siege πŸ“± Android.Backdoor.Baohuo: β€’ Spreading via fake "Telegram X" apps β€’ Full account takeover capability β€’ Issue user alert immediately πŸ€– CoPhish Attack: β€’ Abusing Microsoft Copilot Studio β€’ AI-powered phishing via fake chatbots β€’ Review Copilot deployments πŸ“Š 2025 Ransomware Surge: β€’ 5,010 attacks YTD ( 50% vs 2024) β€’ 201 victims/week (33 active groups) β€’ Change Healthcare: 190M records (largest ever) 🌐 Other Threats: β€’ CVE-2025-59287: WSUS still exploited (new patch Oct 27) β€’ APT36 (Transparent Tribe): DeskRAT targeting India gov β€’ Russia DDoS: Food logistics nationwide disruption ACTION: 🚨 Disable ChatGPT Atlas ⚑ Verify WSUS latest patch πŸ“± Alert: Block fake Telegram apps πŸ€– Review Copilot Studio usage #CyberSecurity #ThreatIntel #Ransomware #AI #CISO
1
1
226
27 Oct 2025
🚨 CISO Threat Brief - Oct 26, 2025 CRITICAL: 3x CVSS 10.0 Vulns F5 Nation-State Breach πŸ”΄ CVSS 10.0 EXPLOITED: β€’ AutomationDirect PLC: Unauthenticated takeover β€’ CVE-2025-54253: Adobe AEM RCE (active exploit) β€’ CVE-2025-43995: Dell Storage API bypass (CVSS 9.8) πŸ”΄ F5 SUPPLY CHAIN BREACH: β€’ Nation-state actor: Long-term access to BIG-IP dev environment β€’ CISA ED 26-01: Emergency Directive issued β€’ Source code engineering docs exfiltrated β€’ ALL F5 customers at risk ✈️ Dublin Airport Breach: β€’ 3.8M passengers (August 2025 travel) β€’ Full PII exposure 🦹 Warlock Ransomware: β€’ Exploiting SharePoint ToolShell zero-day β€’ Enterprise SharePoint at risk πŸš— Jaguar Land Rover Attack: β€’ UK car production β†’ 73-year low β€’ OT/manufacturing impact πŸ” HashiCorp Vault: β€’ AWS auth bypass patched (Oct 27) β€’ Update immediately ACTION: 🚨 Comply CISA ED 26-01 (F5 devices) 🚨 Isolate AutomationDirect PLCs 🚨 Patch Adobe AEM (active exploit) 🚨 Update Dell Storage Manager ⚑ Hunt F5 compromise IOCs #CyberSecurity #ThreatIntel #F5 #CISO #SupplyChain #CVSS10
229
27 Oct 2025
🚨 CISO Threat Brief - Oct 25, 2025 CRITICAL: Sudo & ICS Under Attack πŸ”΄ CVE-2025-32463 - Sudo RCE: β€’ Actively exploited β†’ CISA KEV β€’ Unix/Linux root access via -R chroot β€’ Patch ALL nix systems immediately πŸ”΄ 18 ICS Advisories (Oct 21-23): β€’ AutomationDirect, Siemens S7-1200, Rockwell β€’ Schneider Electric, Hitachi Energy β€’ Critical infrastructure at risk πŸ“§ Email Malware Surge: β€’ 39.5% QoQ increase β€’ ICS calendar files = NEW attack vector β€’ AI-powered phishing = 80% of social engineering 🌐 Salt Typhoon (China APT): β€’ Telecom infrastructure infiltration β€’ Wide-reaching espionage campaign β€’ Ongoing threat πŸ’° Ransomware Economics: β€’ 24% orgs hit in 2025 (↑ from 18.6%) β€’ 63% refuse to pay ransom β€’ Scattered Spider leaked 5.7M Qantas records ACTION: 🚨 Patch sudo (CVE-2025-32463) 🏭 Review 18 ICS advisories πŸ“§ Filter ICS calendar files πŸ” Hunt Salt Typhoon IOCs #CyberSecurity #ICS #ThreatIntel #CISO #Sudo
178
27 Oct 2025
🚨 CISO Threat Brief - Oct 24, 2025 CRITICAL: WSUS Under Active Attack πŸ”΄ CVE-2025-59287 (CVSS 9.8): β€’ Microsoft WSUS RCE actively exploited (NCSC confirmed) β€’ Out-of-band patch released TODAY β€’ Unauthenticated RCE w/ SYSTEM privileges β€’ Affects Server 2012-2025 πŸ”΄ CISA KEV (Due Nov 14): β€’ CVE-2025-59287: WSUS deserialization β€’ CVE-2025-54236: Adobe Commerce/Magento πŸ”΄ Ransomware Wave (12 victims): β€’ CL0P: 5 orgs (LKQ, CSC Global, HRSD ) β€’ Qilin: 4 orgs (ClearCare, IREM ) β€’ TENGU, Kryptos, ANUBIS, RansomHouse active πŸ“Š Qilin = 2025 Leader: 701 attacks | 116TB stolen | Surged post-RansomHub shutdown ⚠️ AI Threat: OpenAI Atlas/Perplexity Comet sidebar spoofing ACTION: 🚨 Patch WSUS NOW (out-of-band) πŸ” Hunt WSUS exploitation IOCs ⚑ Isolate unpatched servers #CyberSecurity #ThreatIntel #WSUS #Ransomware #CISO
197
24 Oct 2025
🚨 CISO Threat Brief - Oct 23, 2025 ⚠️ DEADLINE TODAY: CISA KEV Oct 23 remediation due Validate patching: CVE-2025-4008 (Meteobridge, CVSS 10.0) CRITICAL ALERTS: πŸ”΄ New CISA KEV (Due Nov 14): β€’ CVE-2025-59287: WSUS RCE (CVSS 9.8) - deserialization flaw β€’ CVE-2025-54236: Adobe Commerce/Magento input validation πŸ”΄ Ransomware Surge: 14 breaches discovered TODAY β€’ Qilin: 8 victims (Integral Networks, KHL Print, Magna Hospitality ) β€’ Medusa: 6 victims (Adore, Alissa Group, CEF Farma ) πŸ“Š Threat Landscape: β€’ 4,701 ransomware incidents (Jan-Sep) 46% vs 2024 β€’ 130 CVEs/day in 2025 (23.6K in H1) β€’ 30% KEVs weaponized <24hrs β€’ 52% attacks = extortion/ransomware β€’ Manufacturing 61% YoY (hardest hit) 🎯 Active Campaigns: β€’ Top 5 groups: Qilin, Clop, Akira, Play, SafePay (25% of incidents) β€’ AI-enhanced: ClickFix social eng BYOI EDR evasion β€’ 50% attacks target critical infrastructure ( 34% YoY) ACTION: βœ… Verify Oct 23 KEV deadline met πŸ”§ Patch WSUS immediately πŸ” Hunt Qilin/Medusa IOCs ⚑ Accelerate patch workflows (24hr weaponization) #CyberSecurity #ThreatIntel #Ransomware #CISO #KEV
216
23 Oct 2025
🚨 CISO Threat Brief - Oct 22, 2025 CRITICAL ALERTS: πŸ”΄ Microsoft Zero-Days (2 exploited): β€’ CVE-2025-24990: Windows Modem Driver privesc β€’ CVE-2025-59230: RasMan privesc Patch NOW - 172 vulns total in Oct PT πŸ”΄ CISA KEV (Due Nov 10): β€’ CVE-2025-61884: Oracle EBS SSRF β€’ CVE-2025-33073: Windows SMB privesc β€’ CVE-2025-2746/47: Kentico auth bypass πŸ”΄ Red Hat Breach: 570GB stolen from 28K repos Victims: NSA, Navy, BoA, JPMorgan, AT&T ⚠️ Active Campaigns: β€’ Akira ransomware β†’ SonicWall VPNs β€’ Clop β†’ Oracle EBS (CVE-2025-61882) β€’ KillSec/Funklocker: AI-powered RaaS (120 victims) πŸ“Š Threat Landscape: β€’ 16% attacks use AI-enhanced social engineering β€’ 50% exploitation = nation-state (China-linked) β€’ 21.5K CVEs disclosed H1 2025 (record) 🎯 Top Targets: Manufacturing, Tech, Finance ACTION: Deploy patches in 48hrs | Audit SonicWall/Oracle | Validate EDR #CyberSecurity #ThreatIntel #InfoSec #CISO #ZeroDay
1
1
245
22 Oct 2025
HREAD: Cyber Threat Roundup - Oct 21, 2025 🧡 🚨 COLDRIVER (Star Blizzard) APT ramping up ops with 3 new malware families: NOROBOT, YESROBOT, MAYBEROBOT. Russia-linked group shows increased tempo since May 2025. ClickFix social engineering in delivery chains. πŸ”— thehackernews.com/2025/10/go… πŸ€– PolarEdge botnet expanding - targets Cisco, ASUS, QNAP, Synology routers. Infrastructure active since June 2023. Purpose still undetermined. πŸ”— thehackernews.com/2025/10/po… ⚠️ GlassWorm malware hits VS Code extensions via supply chain attack. Uses invisible Unicode chars to hide code blockchain infrastructure for resilience. πŸ”— securityweek.com/supply-chai… πŸ”΄ CISA KEV Alert: Apple, Kentico, Microsoft vulns under active exploitation β†’ RCE, auth bypass, privesc. Patch immediately. πŸ”— securityweek.com/cisa-warns-… πŸ›‘οΈ Defense News: Meta rolls out scam detection for WhatsApp/Messenger screen-sharing warnings. πŸ”— thehackernews.com/2025/10/me… #ThreatIntel #InfoSec #CyberSecurity
1
127
21 Oct 2025
Function: tls1_process_heartbeat Evidence: Lacks boundary/length checks:Allocates buffer: ptr = CRYPTO_malloc(num,...); num = uVar7 0x13; Copies payload: memcpy(ptr 3, pcVar4 3, (ulong)uVar7); uVar7 value is attacker-controlled, parsed from incoming heartbeat message No validation that uVar7 (payload length) is less than or equal to the received message size, enabling out-of-bounds read Location: tls1_process_heartbeat @ 0x00134290, decompilation confirms the vulnerable logic Conclusion: Vulnerability matches CVE-2014-0160 (β€œHeartbleed”) pattern exactly
80
Dr. Binary retweeted
15 Oct 2025
I wondered if my Windows bootloader had any CVEs. My prediction: β€œNo way β€” I always keep it updated.” Dr.Binary (drbinary.ai) says otherwise. It found CVE-2023-24932 Secure Boot bypass (the BlackLotus one). Surprised, but not surprised. πŸ˜… #UEFI #WindowsSecurity
2
2
425