Google says Gmail security is “strong and effective” as it denies major breach
Google refutes claims that all 2.5 billion Gmail users are at risk.
Google refutes claims that all 2.5 billion Gmail users are at risk.
Persistent trend in open-source offensive tooling & implications for defenders
Bumblebee malware, active as an initial access tool since late 2021, has been leveraged in recent campaigns using SEO poisoning to distribute payloads by impersonating legitimate IT tools in search results. The malware has been observed delivering AdaptixC2 and Akira ransomware in coordinated attack chains that begin with compromised search engine results. This campaign represents an evolution in Bumblebee's delivery tactics, shifting from earlier methods to search-based social engineering attacks.
In this episode, I sit down with Jaron Bradley, author of the upcoming book Threat Hunting macOS. With the recent release of the new 13Cubed training course Investigating macOS Endpoints, this felt like the perfect time to bring Jaron on the channel to discuss his new book — a resource I believe will be an excellent companion to the course. 📘 Order Jaron’s Book – Threat Hunting macOS
Welcome to a special Windows Memory Forensics Challenge from 13Cubed. This is an excellent opportunity to get some hands-on practice with Windows memory forensics. You'll find the questions below, as well as a link to download the memory sample needed to answer those questions.
The Interlock ransomware group has deployed a new PHP-based variant of their remote access trojan, marking a significant shift from their previous JavaScript implementation known as NodeSnake. Researchers from The DFIR Report and Proofpoint have observed this evolved RAT being distributed through a campaign leveraging KongTuke FileFix, with notable activity detected since May 2025. This variant demonstrates increased resilience and represents an escalation in the group's technical capabilities.
A password spray attack against an internet-facing RDP server in November 2024 provided initial access to a victim environment, with the threat actor using known malicious IPs to attempt logins across multiple accounts. Following successful RDP authentication hours after the initial spray attempt, the attacker proceeded to deploy RansomHub ransomware. The intrusion demonstrates the persistent threat posed by exposed remote access services and the need for defensive measures against credential-based attacks.
We expand our view to include CWE and OWASP, and we also examine the latest overall trends for June 2025.
Sensor Intel Series: May 2025 CVE Trends
This tutorial covers Windows Access Tokens, the Logon Session, Token Elevation, AdjustTokenPrivileges and the Windows Access Control Model. This is part of our IDA Pro reverse engineering series. The full series can be found on our patron...
I met Jonathan in 2018 at the CCC when he was just 18 years old. Back then he referenced my videos which had a little bit of impact on his life. Now a lot of time has passed and in this interview I want to get to know Jonathan better. How did he get into hacking, founding of the CTF team perfect blue, working as a vulnerability researcher and ultimately transitioning into a new career.
Testing MCP plugins for IDA and Ghidra live with @mrexodia IDA MCP
This tutorial walks through the process of reverse engineering malware which uses AdjustTokenPrivileges to enable SeDebugPrivilege. No steps are skipped in the process! This is Module 2.2 of our IDA Pro reverse engineering series. The full series can be found on our patron...
An amazing event for aspiring German hackers is happening right now. I went to the finals in 2024, share a few impressions and tell you about this year's event.
Discover how to mitigate CVE-2024-53900 and CVE-2025-23061, which expose Node.js APIs to remote attacks.
When auditing code it's crucial to know about common issues. In this video we explore a Go issue that I was not aware of.
Reverse engineering all stages with line by line code analysis. e3f57d5ebc882a0a0ca96f9ba244fe97fb1a02a3297335451b9c5091332fe359 OP
"There are not that many people that do Android research [...] There is no lack of targets. If people would actually look, there is lots to it. The scope is huge." - This is a conversation with Kristoffer Blasiak about Google's Mobile Vulnerability Rewards Program (VRP).
If you are just getting started with reverse engineering this the place to start. In this tutorial we provide an overview the current setup that we currently run, this is also the same setup used in all of our live streams and tutorials. The full notes for this tutorial are unlocked for everyone on our Patreon including links to all of the tools mentioned