7 Aug 2026, 10:01 UTC62 views8 reactionsread 8 August 2026 Photo
💡 The more AI adoption grows in cybersecurity, the more valuable human analysts become.
AI can handle alert volume, but not the adversarial challenge. Attackers can adapt their techniques to bypass AI-driven detection, making the remaining threats harder to identify❗️
That's why skilled analysts who validate and investigate alerts are becoming more important, not less.
📖 AI in cybersecurity, SOC future & #ANYRUN v…
❤4💯2🔥2
6 Aug 2026, 13:31 UTC113 views10 reactionsread 8 August 2026 Photo
🚨 Kali365 leaves one of its most useful pivots inside the browser: the runtime JS configuration.
#ANYRUN Sandbox reveals the decrypted code behind the SharePoint lure, showing how the page sets up the device-code flow, generates the user code, and communicates with backend session endpoints.
This turns the rendered page into a stronger investigation lead: analysts can move beyond the visible lure to session logic, …
❤5😱3👍2
6 Aug 2026, 11:30 UTC101 views13 reactionsread 8 August 2026 Photo
🏦 Financial institutions are the #1 target for ransomware, credential theft, and social engineering.
A SOC at an investment bank prevented hundreds of attempts with #ANYRUN.
📈 See how to strengthen security for banks
❤6🔥5👍2
6 Aug 2026, 09:01 UTC111 views15 reactionsread 8 August 2026 Video
⚡ Threat hunting without query syntax. Describe the behavior in plain language, #ANYRUN TI Lookup returns risk scores, threat names, indicators, and sandbox session links.
🎁 Using TI Lookup in your workflow? Tell us how — take a short survey and get a reward
Not in TI Lookup yet? Reveal the malware behind any IOC, hunt related infrastructure across 50M+ samples, and review the sandbox evidence that connects it all.…
❤8🔥5👏2
5 Aug 2026, 13:01 UTC124 views15 reactionsread 8 August 2026 Photo
🚨 PhantomEnigma shows the difference between blocking today’s C2 and tracking the operation behind it.
#ANYRUN analysts recovered a Node.js/Electron backdoor with /nbw/ beaconing, 180-second task checks, eval()-based JavaScript execution, EXE delivery, and login persistence — capabilities that can turn a clean-looking sample into longer access, follow-on payload delivery, and higher fraud or data-exposure risk ⚠️
🔍…
❤9🔥4👍2
5 Aug 2026, 10:01 UTC115 views13 reactionsread 8 August 2026 Photo
🌐 ChongLuaDao protects 200M people against scams.
#ANYRUN helps their team complete threat validation fast and produce reports for international partners like Interpol.
👉 Check out their lessons for SOC teams wanting to scale their impact.
❤8👏3👍2
5 Aug 2026, 07:01 UTC125 views12 reactionsread 8 August 2026 Photo
⚠️ Active in July 2026. Three PhaaS kits targeting US organizations right now.
🔹 Sneaky 2FA: AiTM kit intercepting M365 session cookies, with Cloudflare CAPTCHA blocking automated analysis.
🔹 EvilTokens: captures OAuth tokens after victims complete real MFA on Microsoft's own login page.
🔹 EvilProxy: reverse-proxy PhaaS intercepting credentials in real time, evades automated detection systems.
🔍 All three tracked…
❤7👾3🔥2
4 Aug 2026, 13:01 UTC126 views15 reactionsread 8 August 2026 Photo
🚨 July’s major attacks put cloud accounts, financial activity, and sensitive data at risk.
Attackers abused 20+ government portals, used fake AI summit invitations, and manipulated Microsoft device code flows across the US, Europe, Brazil, and beyond.
🔍 See how your team can detect and respond faster
❤8🔥4👾3
4 Aug 2026, 10:01 UTC125 views11 reactionsread 8 August 2026 Photo
⚡ Faster response starts with faster triage.
With #ANYRUN's Interactive Sandbox files and URLs detonate in seconds, Automated Interactivity handles evasive threats, and Tier 1 reports give a structured verdict ready to act on.
👉 See how it works
❤5🔥4👍2
4 Aug 2026, 07:01 UTC126 views12 reactionsread 8 August 2026 Photo
Phishing activity in the past 7 days 🐟
Track latest phishing threats in TI Lookup
#TopPhishingThreats
❤7👾3🤔2
3 Aug 2026, 13:30 UTC125 views9 reactionsread 8 August 2026 Photo
🚨 PhantomEnigma hijacks .gov.br portals to deliver backdoors while bypassing SPF, DKIM, and DMARC.
Companies it targets face banking fraud and persistent RMM access ⚠️
➡️ Update your SOC defense with our actionable research
❤5👏2🔥2
3 Aug 2026, 11:01 UTC125 views14 reactionsread 8 August 2026 Photo
🚨 Remember Lazarus APT's IT workers scheme?
Last year, we showed how the operation looked from the inside. Now there’s more to the story 🔥
New details are coming in Part 2, first presented by Mauro Eldritch & Heiner García at DEF CON 34 on August 8.
Don't miss it. Stay tuned 🚀
❤8🔥4🤯2
Showing the 12 most recent of 19 posts we hold for @anyrun_app. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.