Volexity
volexity · B · active
https://www.volexity.com/blog/
Memory forensics and APT research; strong on Ivanti/edge-device 0-days. Cadence is sparse — when the feed is empty in the window, flag as 'no items'. 2026-05-08 audit confirmed dated posts. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.volexity.com/blog/ (listing) then webfetch per-post URL for body. AVOID: Cadence is sparse — long gaps between posts (latest Jun 4 2026, prior was Dec 2025). When the window has no new post, flag 'no items' rather than escalating; the source isn't broken.. | 2026-07-05 admiralty audit: B — independent APT/forensics research lab, original first-hand research; sparse cadence is expected, not a failure. No status change.
Cited in 7 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 7).
- Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation2026-07-19
- SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533's full appliance-to-network kill chain2026-07-18
- VerdantBamboo (UNC5221 / WARP PANDA) — BSD-compiled BRICKSTORM confirmed on pfSense, plus a new PLENET backdoor2026-06-14
- VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past Conditional Access2026-06-05
- VerdantBamboo / UNC5221 / WARP PANDA — 18-month undetected China-nexus intrusion through MSP pfSense2026-06-01
- Unit 42 — ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration2026-05-23
- Midnight Blizzard and others operationalise ROADtools for Entra ID abuse2026-05-18