Andrew Case

20.5K posts

Andrew Case banner
Andrew Case

Andrew Case

@attrc

@Volatility Core developer, Dir. of Research @Volexity, @lsucyber, The Art Of Memory Forensics Co-Author

New Orleans, LA Katılım Mart 2010
5.2K Takip Edilen28.1K Takipçiler
Sabitlenmiş Tweet
Andrew Case
Andrew Case@attrc·
To summarize: HuggingFace got autonomously compromised by a model from an American company. HF then tried to use American frontier model(s) to defend themselves, but were blocked by guardrails. HF then had to turn to open source Chinese models to defend themselves from another American company.
OpenAI@OpenAI

We're partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation. Sharing preliminary findings to help defenders understand emerging risks: openai.com/index/hugging-…

English
281
2.5K
23.6K
1.7M
Andrew Case
Andrew Case@attrc·
Modern intrusions and the malware that powers them share three traits: 1) Target edge devices without security software, such as VPN appliances and firewalls 2) For desktops and servers with security software, disable telemetry and alerts 3) Leave no traces on the local file system At @Volexity, our proactive threat assessments are powered by memory forensics of enterprise edge devices and Linux, Windows, and macOS endpoints, and are specifically tailored to find the malware that other software is either incapable of finding or is blinded to. Follow the link below to learn more: volexity.com/services-overv…
English
0
12
37
3.3K
Andrew Case
Andrew Case@attrc·
I will be in Vegas along with many other of my Volexity colleagues. If you want to discuss detecting memory-only malware at scale, edge device memory forensics, or anything else DFIR and threat intel related then reach out to us below!
Volexity@Volexity

@Volexity is heading to Las Vegas! Members of our leadership, development, engineering & threat intelligence teams will be on site August 4–6. If you would like to connect to discuss the latest in #DFIR, #memoryforensics, or the current threat landscape, let us know when you’d like to meet: volexity.com/contact/meet-u…

English
0
7
23
11.9K
Andrew Case retweetledi
J. A. Guerrero-Saade
J. A. Guerrero-Saade@juanandres_gs·
Curious what 'frontier-class' intelligence gets you these days? So were we. As cyber threat intel practitioners, coding benchmarks and obsessing over vuln research means very little, so we turned our fast16 investigation into a multi-stage benchmark 🧵 s1.ai/sol-eval
English
3
28
75
18.1K
Andrew Case
Andrew Case@attrc·
We have several open positions! Half in MD and half remote USA. Please apply if qualified, or share with those who are!
Volexity@Volexity

@Volexity is hiring! Join a team that develops concrete solutions to the most challenging real-world problems. Whether your focus is bringing new products to market or delivering cybersecurity services to customers worldwide, the work you do here helps real people and moves the industry forward. See how you can plug in: volexity.com/company/career… #dfir #hiring #memoryforensics #threatintel #cybersecurity

English
1
2
11
2.2K
Andrew Case
Andrew Case@attrc·
@XciD_ If/When possible, please give a conference talk or two on this investigation!
English
1
1
28
2.7K
Adrien Carreira
Adrien Carreira@XciD_·
Hardest IR of my career: one narrow objective, endless parallel paths, machine speed. One takeaway, we fought back with open models, in the open. AI security won’t be solved by one company in secret. Open source puts these tools in every defender’s hands
Adrien Carreira tweet media
English
70
161
1K
485K
Andrew Case retweetledi
Alex Rad
Alex Rad@defendtheworld·
Join us at DEF CON where we'll talk about how mac malware could bypass entitlements and encryption to dump all the icloud passkeys, passwords, +more on a mac, no privileges required (CVE-2026-28860) "Grabbing the Keys to the iCloud Kingdom" co-presented with @jbradley89
English
1
12
49
3.9K
Andrew Case retweetledi
Steven Adair
Steven Adair@stevenadair·
In early July, @Volexity discovered a threat actor we track as UTA0533 had chained together multiple 0day exploits to compromise two of our customer's SonicWall SMA VPN appliances. While a patch came out on July 13, we found one of the devices had been compromised on June 22. We were able to obtain system memory and disk images from the devices. The most interesting thing we found, besides multiple 0day exploits, was that UTA0533 had setup a loader called KNUCKLEBALL to deploy two backdoors specifically tailored for SonicWall SMA devices. It allowed specially crafted web requests to take one of two routes. The first route would proxy traffic internally, to facilitate lateral movement via a tunneling tool called Suo5. The second route traffic to a custom Java-based webshell Volexity calls ORANGETAIL. UTA0533 modified the nginx config of the device to allow routing of special requests to either Suo5 or ORANGETAIL. They then further setup gating on the requests by looking for a specific User-Agent. At the end of the day -- this was a pretty interesting attack that required a threat actor to do some real legwork SonicWall SMA appliances both for exploitation and for their malware deployment. Take a look at our blog to read more about it and to get a solid list of indicators of compromise. Anyone running a public facing SonicWall SMA appliance should examine their logs and systems for the items we include in our blog.
Volexity@Volexity

@Volexity has published details on a recent incident response investigation involving the exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. Volexity attributes this activity to a #threatactor it tracks as UTA0533, with the earliest signs of compromise dating back to June 22, 2026. SonicWall has released patches (versions 12.4.3-03453 and 12.5.0-02835) following their July 14 public disclosure. Organizations using affected SMA 1000 series devices should upgrade immediately. Read the full technical breakdown, including the vulnerability workflow, malware analysis, and IOCs: volexity.com/blog/2026/07/1… #dfir #memoryforensics #threatintel

English
1
20
46
8.1K
Andrew Case retweetledi
tlansec
tlansec@tlansec·
If you're looking into the newest SonicWall exploitation (CVE-2026-15409 & CVE-2026-15410), the Volexity blog is a must read: volexity.com/blog/2026/07/1…
English
0
23
57
7.2K
Andrew Case retweetledi
Volexity
Volexity@Volexity·
@Volexity has published details on a recent incident response investigation involving the exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. Volexity attributes this activity to a #threatactor it tracks as UTA0533, with the earliest signs of compromise dating back to June 22, 2026. SonicWall has released patches (versions 12.4.3-03453 and 12.5.0-02835) following their July 14 public disclosure. Organizations using affected SMA 1000 series devices should upgrade immediately. Read the full technical breakdown, including the vulnerability workflow, malware analysis, and IOCs: volexity.com/blog/2026/07/1… #dfir #memoryforensics #threatintel
English
0
30
49
12.6K
Andrew Case retweetledi
Christopher Stanley
Christopher Stanley@cstanley·
@HackingDave @X @nikitabier @elonmusk This is being looked at and fixed by the safety eng team - please send me all cases of security researchers getting banned, I will make sure they are reinstated. I can confirm this one was a false positive by some automation, and that automation has since been disabled.
English
2
5
31
1.7K
Andrew Case
Andrew Case@attrc·
PostSilo has created a novel platform that will redefine both the privacy guarantees and the value of AI for enterprises. If you have the skills and meet the requirements for one of their Founding Engineer roles, you should apply today.
PostSilo@PostSilo

PostSilo is hiring Founding Engineers in AI Infrastructure and Data & Retrieval to take our prototype architecture to production scale. If you are interested in leading the technical direction of a company that is poised for massive growth apply at  postsilo.ai/resources/.

English
1
2
2
2.9K
Andrew Case retweetledi
Jamie Levy🦉
Jamie Levy🦉@gleeda·
it happens
Jamie Levy🦉 tweet media
English
5
8
33
2.7K
Andrew Case
Andrew Case@attrc·
I am very excited to announce that my @volatility 3 workshop with David McDonald and Pierre Breton was accepted for @defcon this summer!!
Andrew Case tweet media
English
2
9
59
5.2K