Python developers, be careful! Someone tries to phish PyPI accounts using the domain pypj[.]org.
https://discuss.python.org/t/pypi-org-phishing-attack/100267/7
DFIR / CERT / CSIRT @google - nice person - All opinions are mine... . Doing @TimesketchProj stuff. 🏊♂️ 🚲 🏃♂️
Time matters
| https://twitter.com/alexanderjaeger | |
| Blog | https://www.alexanderjaeger.de/news/ |
Python developers, be careful! Someone tries to phish PyPI accounts using the domain pypj[.]org.
https://discuss.python.org/t/pypi-org-phishing-attack/100267/7
Help request. My brother has Stage 4 colorectal cancer.
His life insurance has refused to pay out on a technicality, meaning he and his loved ones cannot afford the mortgage on their home.
I've never asked for anything in return for infosec stuff, but if you have anything spare, please chuck it this direction instead:
Burnout is NOT a badge of honour
As malware authors increasingly adopt .NET for its ease of development and stability, they rely on sophisticated obfuscation techniques to thwart analysis. Traditional static deobfuscation approaches often fail against modern protections that incorporate runtime integrity checks. This presentation introduces a framework that leverages .NET profilers to perform dynamic binary instrumentation at the MSIL level. We demonstrate how this approach can bypass dynamic checks in obfuscation schemes, extract encrypted strings, and trace execution flows—all without modifying the original binary. Through real-world case studies and live demonstrations, we show how this technique provides reverse engineers with a powerful new tool to analyze obfuscated .NET malware.
Detecting malicious Unicode in #curl
https://daniel.haxx.se/blog/2025/05/16/detecting-malicious-unicode/
In a recent educational trick, curl contributor James Fuller submitted a pull-request to the project in which he suggested a larger cleanup of a set of scripts. In a later presentation, he could show us how not a single human reviewer in the team nor any CI job had spotted or remarked on one of … Continue reading Detecting malicious Unicode →
There will be hackathon during the @firstdotorg annual conference (Sunday
June 22, 2025 09:00-17:00). If you want to join, don't forget to register and also add your project to the discourse below.
🔗 https://www.first.org/conference/2025/program#pHackathon-Registration-Required-See-Abstract-Below
🔗 https://discourse.ossbase.org/t/about-the-hackathon-firstcon25-category/90
Aus gegebenem Anlass: Ihr kennt die Empfehlungen des Bundesamtes für Bevölkerungsschutz und Katastrophenhilfe?
https://www.bbk.bund.de/DE/Warnung-Vorsorge/Vorsorge/vorsorge_node.html
Hey DFIR Peeps! I am hiring incident responders in two locations - Boulder, CO and Sunnyvale, CA. It'd be hard to find a bigger CSIRT with more scope and more interesting stuff to do than this one. :D
SVL: https://www.google.com/about/careers/applications/jobs/results/102534126464049862
BLD: https://www.google.com/about/careers/applications/jobs/results/73189312706814662