466 Followers
1.2K Following
2.4K Posts
šŸ‡ŗšŸ‡¦ Malware Researcher šŸ‡ŗšŸ‡¦
Posts are my own and do not reflect my employer.
mlgethttp://github.com/xorhex/mlget
bloghttps://blog.xorhex.com
twittodonhttps://twittodon.com/share.php?t=xorhex&[email protected]
REcon 2026 is next week in Montreal! Join @jershmagersh on Friday at 1PM for a 3 hour workshop on recovering C++ Symbol and Type information with Binary Ninja

Wake up binjas, new Binary Ninja 5.3.9757 stable just dropped. No functionality this time (head over to dev for that!) but lots of stability fixes for the appropriately named stable branch:

https://binary.ninja/2026/06/09/5.3-release-2.html

Binary Ninja - 5.3 Release 2

Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.

Binary Ninja
Cloudflare has finally started signing the cloudflared tunneling utility, after years of ignoring the issue. Of course they ignored my other request to also populate the original filename, because that would make sense... It's still used by ransomware gangs and it's often renamed. Anyway, it's now easier to yeet this from your environment as you don't have to babysit a list of hashes.

We offer a free and simple API endpoint to grab all the hostnames for a domain based on the certificate transparency logs: https://ctl.shodan.io/

Sample Python code available in the Shodan book: https://book.shodan.io/developer-apis/certificate-transparency/

(considering *I* know how to track these... and have considered writing software to see who/what is constantly in the neighborhood or just driving by... it' not difficult to see how a company would attempt to commercialize this)

"...SignalTrace ā€œbridges license plate recognition data with sensor-captured device identifiers—such as those from mobile phones, Bluetooth wearables, and vehicle systems—to create a unique, trackable ā€˜electronic fingerprint’ for investigative use,ā€ according to a product sheet describing the tool, written by surveillance company Leonardo, which advertises SignalTrace.

The sort of data Leonardo says SignalTrace can sweep up includes the RFID tags in key cards and pet microchips; devices with Bluetooth such as wireless headphones, fitness trackers, and mobile phones; components of a car like tire pressure sensors and infotainment systems; and Wi-Fi sources such as vehicle hotspots and laptops, according to the product sheet..."

#privacy

Mini Shai-Hulud/Miasma/Hades are now targeting bioinformatics and MCP developers in a newer PyPI wave.

We found 23 newly compromised PyPI package-version artifacts using multiple execution paths.

The payload also includes a fake prompt-injection header at the top of _index.js to interfere with LLM-based malware triage before scanners reach the obfuscated code.

Full breakdown:
https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels

Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.

Socket

SignalTrace "links devices that regularly travel together, correlating them to license plate." It is a surveillance product that will sweep up and add all sorts of Bluetooth and other data to license plate readers, linking specific devices—and people—to cars.

https://www.404media.co/this-company-will-add-phone-airpod-and-smartwatch-trackers-to-license-plate-readers/

This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers

SignalTrace ā€œlinks devices that regularly travel together, correlating them to license plate.ā€ It is a surveillance product that will sweep up and add all sorts of Bluetooth and other data to license plate readers, linking specific devices—and people—to cars.

404 Media

Do you like T-shirts? How about coffee mugs?

You can support IFIN's mission and also get some cool merch! All proceeds go directly to operational costs and building our capacity to produce and share free cyber threat intelligence resources.

(stickers coming soon)

https://shop.ifin-intel.org

Evan is presenting at RVAsec tomorrow at 1pm! Be sure to check out his talk and grab some Zeek stickers.

Other community news & more in our newsletter: https://community.zeek.org/t/zeek-newsletter-issue-63-may-2026/7994/1

@rvasec

#Zeek #NetworkSecurity #RVAsec

Our team at Amnesty Security Lab is hiring for a technologist to help protect civic space from unlawful surveillance. The work is varied, blending digital forensics research with threat intelligence, industry collaboration and community work.

We are encouraging candidates of all backgrounds to apply - come fight bad guys with us.

https://careers.amnesty.org/jobs/vacancy/technologist-4246/4274/description/

Amnesty International Careers

Amnesty International Careers, Jobs, Search and Apply

Amnesty International Careers