Released v1.3.3. of #Yaralyzer, my surprisingly popular tool for visualizing YARA rule matches with colors (a lot of colors).

1. --export-png images lets you export images of the analysis

2. almost all command line options (including multi argument ones like --yara-rules-dir) can be permanently set via environment variables or .yaralyzer file

3. couple of small bug fixes and debugging related command line options

You can try it on the web here: https://yaratoolkit.securitybreak.io/
(I didn't build this website, Thomas Roccia from Microsoft just integrated Yaralyzer into his existing site)

- Github: https://github.com/michelcrypt4d4mus/yaralyzer
- Pypi: https://pypi.org/project/yaralyzer/
- on macOS you can also get it with #Homebrew by installing Pdfalyzer: brew install pdfalyzer

#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #GPL #hacking #infosec #KaliLinux #maldoc #malware #malwareAnalysis #malwareDetection #openSource #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #YARA #YARArule #YARArules

UK authorities have acknowledged a cyber incident involving a Foreign Office system, describing the risk to individuals as low and confirming that access was contained quickly.

The response underscores familiar challenges for public-sector security teams: early detection, rapid containment, careful attribution, and responsible communication while investigations continue.

From an InfoSec perspective, what stands out most - detection timing, risk assessment language, or disclosure strategy?

Source: https://therecord.media/uk-foreign-office-hacked-china

Share your insights and follow TechNadu for steady, practitioner-focused cyber coverage.

#InfoSec #GovernmentCyber #IncidentResponse #ThreatAssessment #CyberOperations #RiskCommunication #TechNadu

🛡️ FINAL CHANCE TO REGISTER for tomorrow’s training in Dublin for faith communities.

The event covers threat assessments, the Faith Guardian reporting tool, identification of vulnerabilities in Places of Worship and guidance on counter-narratives.

https://docs.google.com/forms/d/e/1FAIpQLSd-4RfzUx6c2qvrQy4pw2W561kVf0Kut_Z5O0P_UcsLIy80Tw/viewform

#PARTESSCOM #FaithCommunities #SecurityResearch #CounterExtremism #ThreatAssessment #PlacesOfWorship #CommunitySafety

Security Review Philosophy: Collaboration Over Compliance

Application security reviews fail when they become gates instead of partnerships—here's how to build a process that actually works through collaboration and shared understanding.

https://islandinthenet.com/collaboration-over-compliance/

@cR0w
If any if this were true, the writer would know that it's guerilla warfare, NOT "gorilla," unless the writer was Harambe.
Remember Harambe.
I do.
#Harambe #ThreatAssessment #NavySeals

Newsom’s press office under scrutiny for social media post targeting Kristi Noem

California Democratic Gov. Gavin Newsom’s press office could be investigated for a social media post that some Republicans…
#NewsBeep #News #Headlines #BillEssayli #California #CentralDistrictofCalifornia #GavinNewsom #HomelandSecurity #kristi-noem #pressoffice #secretservice #threatassessment #UnitedStates #Us #USA
https://www.newsbeep.com/136740/

Released v1.17.0 of The Pdfalyzer, the surprisingly popular tool for analyzing (possibly malicious) PDFs I created after my own unpleasant experience. Now ships with two command line tools for extracting stuff from PDF files:

1. extract_text_from_pdfs() - brute force extract all text from a PDF, including doing an #OCR extraction of any embedded images

2. extract_pdf_pages() - rip a page range from a #PDF and write them to a new one

* Github: https://github.com/michelcrypt4d4mus/pdfalyzer
* Pypi: https://pypi.org/project/pdfalyzer/
* Homebrew: https://formulae.brew.sh/formula/pdfalyzer
* Fun thread someone made last week using Pdfalyzer to explain some of how byzantine the PDF format is: https://x.com/VikParuchuri/status/1965773078585344215

#pypi #python #pdf #pdfs #malware #Threatassessment #maldoc #malwareanalysis #homebrew #infosec #cybersecurity #yararule #PdfFies

⚯ Michel de Cryptadamus ⚯ (@[email protected])

Attached: 1 image Just published version 1.16.6 of The Pdfalyzer, the surprisingly popular tool for analyzing (possibly malicious) PDFs I created after my own unpleasant encounter with such a creature. Includes a (kind of janky) #YARA rule for #GIFTEDCROOK infostealer PDFs. * Github: https://github.com/michelcrypt4d4mus/pdfalyzer * Pypi: https://pypi.org/project/pdfalyzer/ * Homebrew: https://formulae.brew.sh/formula/pdfalyzer #pypi #python #pdf #pdfs #malware #Threatassessment #maldoc #malwareanalysis #homebrew #infosec #cybersecurity #yararule

Universeodon Social Media

Exploit a #zeroday then self-patch the #vulnerability so other hackers can't use the same exploit? AND you maintain #persistence while hiding in plain sight for longer? Damn - that's really fuckin clever.

https://www.darkreading.com/cyber-risk/initial-access-broker-self-patches-zero-days

#CyberWarfare #Hacking #ThreatAssessment #BeCyberSafe #StayCyberAware #F5