This is pretty freaking cool. #IMHO
Dump and disassemble a running memory region WITH NO DEBUGGER NEEDED. So no gdb or lldb will be detected.
You must own the process or be root.

dd if=/proc/11223/mem bs=1 skip=$((16#7f9ba80f3000)) count=128 2>/dev/null \
| objdump -D -b binary -m i386:x86-64 -M intel /dev/stdin

The 16# is a bashism to interpret as hex.

#Linux #Forensics #Debugging #ThreatHunting

๐Ÿ”ต THREAT INTELLIGENCE

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

Vulnerability | CRITICAL
CVEs: CVE-2026-48907

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla...

Full analysis:
https://www.yazoul.net/news/article/cisa-warns-of-actively-exploited-joomla-jce-flaw-allowing-php-code-execution

#ThreatIntel #Malware #ThreatHunting

CISA Warns of Actively Exploited Joomla JCE Flaw Allowi

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabi

Yazoul Security

๐Ÿ”ต THREAT INTELLIGENCE

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

Vulnerability | CRITICAL
CVEs: CVE-2026-48907

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla...

Full analysis:
https://www.yazoul.net/news/article/cisa-warns-of-actively-exploited-joomla-jce-flaw-allowing-php-code-execution

#ThreatIntel #Malware #ThreatHunting

CISA Warns of Actively Exploited Joomla JCE Flaw Allowi

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabi

Yazoul Security

๐Ÿšจ I'm teaching SANS FOR577: Linux Incident Response & Threat Hunting in Virginia Beach, VA August 24-29, this will be the first public run with completely updated course material.

What's new:

๐Ÿชจ Expanded btrfs coverage โ€” not just artifacts, but the tools you can actually use to examine disk images containing btrfs filesystems. Btrfs is now the default on Fedora, openSUSE, and increasingly Ubuntu. If you've hit that tooling gap during a real investigation, this is for you.

๐Ÿงช All-new labs - rebuilt from the ground up

๐Ÿ New capstone - a comprehensive, updated challenge that ties the course together

๐Ÿค– AI Investigations - a brand new section covering:

* LLM evidence artifacts
* Coding assistant forensics
* AI Agents & MCP (Model Context Protocol)
* Prompt injection attacks and how to investigate them

AI tools are already embedded in attacker workflows and user environments alike. Knowing how to find and interpret AI-related evidence is becoming a core DFIR skill.

๐ŸŽค Free SANS @night Talk โ€” Aug 26 @ 6:00 PM
"Extending Protocol-SIFT to Linux" โ€” Protocol-SIFT has been Windows-only. We're changing that.

๐Ÿ’ฐ Save $500 with Early Bird code EarlyBirdNA โ€” must pay by July 9, 2026

๐Ÿ“ Hilton Virginia Beach Oceanfront
๐Ÿ“… August 24-29, 2026

๐Ÿ”— Register: https://www.sans.org/cyber-security-training-events/virginia-beach-2026

#DFIR #SANS #FOR577 #LinuxForensics #IncidentResponse #ThreatHunting #AIForensics #PromptInjection #btrfs #Cybersecurity #DigitalForensics #InfoSec #GLIR

SANS Virginia Beach 2026

Achieve the expertise you need to succeed in days, not months. Immerse yourself in a week of elite training designed for all skill-levels at SANS Virginia Beach 2025. From hands-on labs to cutting-edge techniques taught by industry-leading instructors, you'll gain the skills to excel and the certifications to prove it.

SANS Institute
Reported an obvious Trojan downloader disguised as a fake video player to Cloudflare last night. Their response? "No evidence found."

Either your AI detection is broken or your abuse team isn't even looking at the links. Do better.

#cloudflare #security #threathunting #threat
I Accidentally Logged as Admin Into a Threat Actor Website

I accidentally logged into a malicious website operated by threat actors after scrolling X. Here's how I do that.

Jonias Fortuna

Basecamp Briefing: June 11, 2026 ๐Ÿ”๏ธ #InfoSec + #DataPrivacy news along with tools and resources for your professional climb.

Appearing in today's newsletter: Azerbaijan, Messi, and information about the upcoming
@Antisy_Training #ThreatHunting Summit!

https://sherpaintelligence.substack.com/p/basecamp-briefing-june-11-2026

๐Ÿ”ต THREAT INTELLIGENCE

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Vulnerability | CRITICAL
CVEs: CVE-2026-11645

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The...

Full analysis:
https://www.yazoul.net/news/article/chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-patch-now

#InfoSec #ZeroDay #ThreatHunting

Chrome V8 zero-day CVE-2026-11645 exploited in wild

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS

Yazoul Security

๐Ÿ”ต THREAT INTELLIGENCE

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Vulnerability | CRITICAL
CVEs: CVE-2026-11645

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The...

Full analysis:
https://www.yazoul.net/news/article/chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-patch-now

#InfoSec #ZeroDay #ThreatHunting

Chrome V8 zero-day CVE-2026-11645 exploited in wild

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS

Yazoul Security

If you don't think MDASH is having an effect on Microsoft's ability to secure its products, take a look at this:

โœ… Microsoft breaks Patch Tuesday record with fixes for over 200 security flaws
https://www.techradar.com/pro/security/microsoft-breaks-patch-tuesday-record-with-fixes-for-over-200-security-flaws

For more on MDASH, visit: https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/
#security #vulnerabilities #threathunting