See the full #BSidesNYC conference schedule here: bsidesnyc.org/schedule/
Volexity
@volexity.com
Volexity is a cybersecurity firm founded by the pioneers of memory forensics. Volexity delivers transformative solutions & services to governments & organizations worldwide, increasing enterprise visibility & facilitating rapid intrusion detection.
Join @attrc.bsky.social, Volexity’s Director of Research, at #BSidesNYC on Oct 17 at 10AM ET (Blue Track). In “Finding Evil Fast: Windows Memory Triage with Volatility 3,” he'll share five automated checks for quickly finding malicious activity in Windows memory.
#memoryforensics #dfir #volatility
See the full #BSidesNYC conference schedule here: bsidesnyc.org/schedule/
Catch Volexity’s Josh Duke at #BSidesNYC on Oct 17 at 5PM ET (Other Track). Josh will present “No Safe Harbor: OceanLotus and ROGUEHARBOR,” sharing details from a recent #OceanLotus campaign that used WhatsApp to target human rights organizations and deploy the ROGUEHARBOR RAT.
The full lineup for the Volexity Cyber Sessions in Amsterdam (Oct 29) is set! Talks cover Chrome & Windows vulnerabilities exploited by Chinese threat actors, edge device memory forensics, macOS lures & malware, and APTs targeting Europe in 2026.
Seating is limited. Register here: luma.com/0qtkw49c
Steven Adair keynotes at our Volexity Cyber Sessions in Amsterdam (Oct 29) on Chinese APTs exploiting Chrome vulns fixed in Chromium but not released. Identical exploit code points to a shared supplier, plus a false-flag op pinning it on Russia.
Seating is limited! Register here: luma.com/0qtkw49c
Feike Hacquebord will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about Russia-, China- & DPRK-aligned APTs targeting Europe: IoT proxy networks, DPRK's Russian IPs, Pawn Storm's evolution & China's AI shift.
Seating is limited! Register here: luma.com/0qtkw49c
Roey Shua will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about automating edge device forensics, from fingerprinting unknown routers & IoT devices to reconstructing symbols and acquiring memory on unsupported architectures.
Seating is limited! Register here: luma.com/0qtkw49c
UTA0565 used multiple fake websites, posing as media orgs & an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.
Following our Sept 9 blog on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity found a third actor, UTA0565 using the same exploits Sept 3-4, while they were still unpatched.
Volatility New Release: #volatility3 v2.28.2 - visit github.com/volatilityfo... for details and downloads.
Christopher Lopez will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about the current macOS threat landscape: lures, targets, recently discovered malware, plus the artifacts that drive forensic analysis & durable detections.
Seating is limited! Register here: luma.com/0qtkw49c
Contact us to schedule a Volexity Volcano demo! www.volexity.com/contact/demo...
Volexity Volcano v26.09.01 also adds MFT parsing from disk, file magic detection, importing from GCP buckets, and complete AWS GovCloud support.
Volexity Volcano v26.09.01 expands what you can analyze, and where! This release adds a powerful MCP server, threat intel integration, memory support for Linux 7.x kernels and Windows 26H1 on Snapdragon X2 ARM64.
Read the full analysis of the exploit chain and post-exploitation tradecraft here: www.volexity.com/blog/2026/09...
Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).
Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).
#DFIR #threatintel
@volexity.com’s latest blog post describes in detail how a Russian APT used a new attack technique, the “Nearest Neighbor Attack”, to leverage Wi-Fi networks in close proximity to the intended target while the attacker was halfway around the world.
Read more here: www.volexity.com/blog/2024/11...
