Volexity
volexity · B · active
https://www.volexity.com/blog/
Memory forensics and APT research; strong on Ivanti/edge-device 0-days. Cadence is sparse, when the feed is empty in the window, flag as 'no items'. 2026-05-08 audit confirmed dated posts. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.volexity.com/blog/ (listing) then webfetch per-post URL for body. AVOID: Cadence is sparse, long gaps between posts (latest Jun 4 2026, prior was Dec 2025). When the window has no new post, flag 'no items' rather than escalating; the source isn't broken.. | 2026-07-05 admiralty audit: B, independent APT/forensics research lab, original first-hand research; sparse cadence is expected, not a failure. No status change. | 2026-09-13 quality audit (G3 broken-recipe duty, closing 2026-09-06 recommendation 3): RECIPE FIXED. The recorded 'RSS returns zero items' failure was an attempt to find a feed on a host that has none. VERIFIED WORKING: `python3 tools/fetch_source.py extract https://www.volexity.com/blog/` returns the full dated listing (titles, dates, lead paragraphs) via trafilatura-direct; newest item this run 'Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows', 2026-09-09, the primary behind this store's BlueMoon entry. fetch_method webfetch -> bridge (the `extract` subcommand). Do NOT look for an RSS feed here.
Cited in 4 entries
Citation cadence
Citation days per ISO week (17 weeks of coverage span, total 4).
- BlueMoon: five separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week2026-09-10
- CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited2026-07-14
- VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past Conditional Access2026-06-05
- Unit 42, ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration2026-05-23