Hacking Blog - 2026 2025 2024 2023 2021 2020 2019
AI blog APT blog Attack blog BigBrother blog BotNet blog CyberCrime blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
DATE | NAME | Info | CATEG. | WEB |
|
12.9.26 |
Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs | In our previous blog, we explored a series of disclosures from the leak persona Nightmare-Eclipse that focused heavily on Microsoft's ecosystem, including Windows Defender, Cloud Files, and core operating system functionality. | Hacking blog | SPIDERLABS |
|
12.9.26 |
Shai-Hulud in the Wild: What Security and Incident Response Teams Need to Know | Learn how Shai-Hulud compromises trusted software workflows, exposes credentials across CI/CD environments, and creates attack paths into cloud, production, and downstream systems, and how security teams can contain and recover from the compromise. | Hacking blog | SYGNIA |
|
12.9.26 |
Testing race conditions with memory access tracing and stack-based delay injection | Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: | Hacking blog | PROJECT ZERO |
|
10.9.26 |
Signing in without actually signing in | Session tokens are the skeleton keys used to hijack | Hacking blog | OKTA |
|
5.9.26 |
Hackers quietly turn Korean PCs into proxies and VPNs | A PowerShell process on a Korean machine pulls down a zip file and unpacks a batch script that installs Radmin, a perfectly legitimate remote desktop product, into C:\Intel\RServer. Nothing in that sequence looks like malware. That is the point. | Hacking blog | INTELFUSIONS |
|
5.9.26 |
Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works | Supply chain attacks in 2026 are a major breach vector, exposing vendor dependencies and software risks that traditional security tools often miss. | Hacking blog | Cyble |
|
3.9.26 |
Node.js: Old Technique Makes a Comeback | SECURITY.COM | The trusted JavaScript runtime has featured in multiple attacks since February 2026, some linked to ransomware. In one case, attackers installed it from its official site to run an implant commanded via the Ethereum blockchain. | Hacking blog | SECURITY.COM |
|
3.9.26 |
EtherHiding: Blockchain Technology as a Cyber Weapon | In the cybercrime world, a strange cat and mouse game is continuously taking place. Cybersecurity researchers tirelessly hunt attackers' infrastructures. As soon as some of their components are discovered and brougth to light, they quickly become obsolete because of their addition on IOC's lists that strengthen cybersecurity equipments. This is why attackers must be able to constantly adapt themselves. | Hacking blog | STORMSHIELD |
|
3.9.26 |
EtherHiding Exposed: What Security Leaders Need to Know | Attackers have compromised the websites of at least 31 legitimate businesses, including e-commerce, professional services and retail logistics organizations. Visitors arriving to the compromised sites via search engine encounter a fake “Verify you’re human”. | Hacking blog | GUIDESECURITY |
|
3.9.26 |
Kim Sooki again? This time, it was disguised as a request for seafood ingredients | A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. | Hacking blog | AHNLAB |
|
2.9.26 |
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk | August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems. | Hacking blog | ANYRUN BLOG |
|
2.9.26 |
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse | Threat actors are abusing Faronics Deploy, a legitimate endpoint management platform, to execute attacker-controlled PowerShell after phishing victims install the software. | Hacking blog | Huntress |
|
29.8.26 |
Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database |
Active Directory Certificate Services (ADCS) has emerged as one of the most significant and under-monitored attack surfaces in enterprise Windows environments, as documented by SpecterOps. After observing certificate-based privilege escalation techniques being actively exploited in several cases that the GuidePoint |
||
|
29.8.26 |
For five days in March 2026, a single stolen token let one group poison five software ecosystems including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub Actions workflow, and ended with backdoored code sitting inside CI/CD pipelines around the world. |
|||
| 29.8.26 | 9Router Tailscale Install Endpoint Unauthenticated OS Command Injection | SonicWall Capture Labs threat research team became aware of the threat CVE-2026-59800, assessed its impact, and developed mitigation measures. The flaw, also known as the 9Router Tailscale Install Endpoint Unauthenticated OS Command Injection, is a critical vulnerability affecting the 9Router AI request proxy (decolua/ | Hacking blog | SonicWall |
| 29.8.26 | “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend | In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage. | Hacking blog | CISCO TALOS |
| 29.8.26 | No Privileges, No Lockout, No Trace: Kerberoasting with SPN Misconfigurations | This blog will walk through the complete kill chain: an attacker enumerates domain-wide SPNs, identifies a vulnerable user account, and silently requests a Kerberos Ticket Granting Service (TGS) ticket encrypted with the weak RC4-HMAC algorithm. | Hacking blog | TRELLIX |
| 27.8.26 | Cambodia-focused cluster uses multistage infection chain with localized lures | Acronis’ Threat Research Unit (TRU) identified a recent campaign focused on Cambodia. The analyzed archives, discovered while hunting for related activity, use several lure themes, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. | Hacking blog | ACRONIS |
| 27.8.26 | The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it | Two project-flow extensions sit quietly for five minutes after you open your editor. The Kanban board renders, the webview loads, everything looks like a normal project-management tool. Then, once the IDE has settled and the developer has moved on to something else, a setTimeout fires. The extension reaches out to a free DuckDNS subdomain over plain HTTP, grabs a JavaScript file, and runs it with new Function. | Hacking blog | YEETH SECURITY |
| 22.8.26 | Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns | Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios. | Hacking blog | WIZ.IO |
|
22.8.26 |
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. | CloudSEK has published the victim list from Team PCP's supply chain campaign: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations over five days in March 2026. StepSecurity's research team has tracked this threat actor across the Trivy, telnyx, and LiteLLM compromises. | Hacking blog | STEPSECURITY |
|
22.8.26 |
The heyheyhey campaign: 6 fake Roblox VS Code extensions that fetch and run a remote script from GitHub | A Kanban board for Roblox developers sounds harmless enough. Six of them hit the Microsoft VS Code Marketplace over three days in June 2026, all from different publishers, all with names like RoFlow, RoPilot, and ManageBlox. The boards work — they render a webview, they show columns, they look like a project tool. That is the cover. | Hacking blog | YEETH SECURITY |
|
22.8.26 |
Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates | Discover ransomware attack vectors hiding in endpoint blind spots, including remote access tools, credentials, vendors, OT systems and phishing. | Hacking blog | Cyble |
|
22.8.26 |
When the Attacker Wears Your Logo: Detecting and Taking Down Impersonation at AI Speed | AI-powered impersonation can damage brands in minutes. Learn how monitoring and rapid takedowns help detect threats and protect customer trust. | Hacking blog | Cyble |
|
22.8.26 |
9Router Tailscale Install Endpoint Unauthenticated OS Command Injection | SonicWall Capture Labs threat research team became aware of the threat CVE-2026-59800, assessed its impact, and developed mitigation measures. The flaw, also known as the 9Router Tailscale Install Endpoint Unauthenticated OS Command Injection, is a critical vulnerability affecting the 9Router AI request proxy (decolua/9router, distributed on npm as 9router) in all versions up to and including 0.4.39, which NVD expresses as any version before 0.4.44. | Hacking blog | SonicWall |
|
22.8.26 |
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) | Identity has effectively become the new perimeter, where cybercriminals are increasingly choosing to log in rather than break in. To accomplish this, attackers frequently gather previously leaked username and password pairs. Gathering these credentials can then allow them to pivot to password spraying against services exposed to the internet, gaining credentials for other products and services. | Hacking blog | Palo Alto |
|
22.8.26 |
When Agents Go Rogue: The OpenClaw Supply Chain Crisis | This comprehensive technical report provides an in-depth analysis of some of these attack vectors, the supply chain poisoning, profiles the threat actors involved, details about the NovaStealer payload, maps the attacks to the MITRE ATT&CK framework, and provides actionable, enterprise grade mitigation strategies. | Hacking blog | TRELLIX |
|
15.8.26 |
Abuse of alternative runtime environments Deno-tes defender headaches | Attack TTPs combine fileless execution, wide LOLBin use | Hacking blog | SOPHOS |
|
6.8.26 |
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant | Hacking blog | FORTINET BLOG |
|
8.8.26 |
Toolkit Installation via SQL Injection Shows the Classics Still Hit | Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution | Hacking blog | Huntress |
|
8.8.26 |
Targeted Attack on Government Entities in the Middle East | Part 2 | This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. After ThreatLabz published Part 1 on the TELESHIM backdoor and MIXEDKEY loader, Kaspersky highlighted a related campaign in recent reporting. | Hacking blog | Zscaler |
|
8.8.26 |
The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem | Discover why continuous asset discovery is the foundation of attack surface management and how visibility helps reduce cyber risk and exposure. | Hacking blog | Cyble |
|
1.8.26 |
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN | While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the infected system and also installed SoftEther to use it as a VPN server. | Hacking blog | AHNLAB |
|
1.8.26 |
DNS Poisoning Tactics Expand to Hospitality Wi-Fi | Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026. | Hacking blog | RELIAQUEST |
|
1.8.26 |
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave | Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan. | Hacking blog | Trend Micro |
|
18.7.26 |
Inside the Matching Engine: How Distributed Tokenization Identifies Compromised Cards Without Exposing Them | Discover how Distributed Tokenization identifies compromised cards at pre-authorization without exposing raw card data — a technical deep-dive for fraud operations and risk teams. | Hacking blog | GROUP-IB |
|
18.7.26 |
As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. | Hacking blog | GTI | |
|
18.7.26 |
Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: | Hacking blog | GTI | |
|
18.7.26 |
Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper... | Hacking blog | Seqrite |
|
18.7.26 |
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery | hreat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. | Hacking blog | Microsoft blog |
| 11.7.26 | Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs | This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider. | Hacking blog | GROUP-IB |
| 11.7.26 | The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. | Hacking blog | GTI | |
| 11.7.26 | The Two BIOS Passwords Everyone Confuses | When someone tells me “we set the BIOS password on the fleet,” my first question is always “which one?” Because there are at least two firmware passwords on a modern machine, they do completely different things, and the failure I see most often is a team that sets one, assumes it covers the other, and leaves a gap they do not know they have. | Hacking blog | Eclypsium |
| 9.7.26 | Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims | Residential proxies are one of the hottest topics in cybersecurity today. Turns out, they are often not in residences, and they facilitate a wide range of criminal activity. In the simplest terms, a little piece of software in a TV, digital picture frame, or your phone might enable a company to sell access to your device’s bandwidth to their own customers. | Hacking blog | INFOBLOX |
| 9.7.26 | Fake 7-Zip downloads are turning home PCs into proxy nodes | A convincing lookalike of the popular 7-Zip archiver site has been serving a trojanized installer that silently converts victims’ machines into residential proxy nodes—and it has been hiding in plain sight for some time. | Hacking blog | MALWAREBYTES |
| 4.7.26 | Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. | Hacking blog | GTI | |
| 4.7.26 | The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security | Bring Your Own Vulnerable Driver (BYOVD) has gone from a niche tactic to a standard part of the ransomware playbook and Windows' own kernel hardening does little to stop it. | Hacking blog | SECURITY.COM |
| 4.7.26 | Threat Brief: Mitigating Large-Scale Credential Attacks | Unit 42 is aware of a large-scale password spraying and credential theft campaign (“FortiBleed”) against Fortinet devices. We observed attempts targeting MSSQL devices as well, and have seen reports of Sophos devices also being targeted. While this activity is not targeting Palo Alto Networks devices, Unit 42 has observed suspicious login attempts in customer telemetry and we are providing this report out of an abundance of caution to ensure our customers have the latest intelligence and product recommendations to protect, detect and respond to attacks to their network. | Hacking blog | Palo Alto |
| 27.6.26 | Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances | Hacking blog | Eset | |
| 19.6.26 | Threat Actors Weaponizing RAR Archives to Target Thailand’s Healthcare Sector | Seqrite Threat Research Unit (TRU) actively tracks and analyses threat actors and their campaigns, focusing on attribution, infrastructure analysis, and adversary tradecraft. Throughout our research, we have attributed numerous operations to China-aligned and other threat clusters targeting both regional and international entities. | Hacking blog | Seqrite |
| 19.6.26 | Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections | A Technical Walkthrough of How Vidar Defeats Application-Bound Encryption | Hacking blog | GENDIGITAL |
| 19.6.26 | Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai's own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware. | Hacking blog | Trend Micro |
| 19.6.26 | PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM | A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools abuses the Integration Broker's PSIGW gateway to execute code inside the application server's Java virtual machine (JVM), evading behavioral and network sensors. | Hacking blog | Trend Micro |
| 19.6.26 | Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility | Cloud logging services provide comprehensive visibility into actions performed within cloud resources, making them essential for security monitoring. However, this reliance also makes logging services a high-value target for attackers. An attacker who exploits these services could create weak spots, evade detection, and in certain scenarios, establish continuous visibility within a target’s environment. | Hacking blog | Palo Alto |
| 19.6.26 | From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker | The threat actor uses multiple channels to promote and distribute a Rust clipboard hijacker, starting with a dedicated phishing page as the central hub and extending to GitHub and SourceForge projects promoted by fake accounts. A dedicated YouTube channel, using AI‑generated narrators, suspicious view spikes, and highly positive (likely coordinated) comments, further reinforces the illusion of popularity and trustworthiness. | Hacking blog | CHECKPOINT |
| 19.6.26 | Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model | Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through a live COM interface. | Hacking blog | CISCO TALOS |
| 19.6.26 | EvilTokens: A phishing attack that doesn’t steal your password | A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages | Hacking blog | Eset |
| 13.6.26 | You Need to Verify the Hardware Supply Chain Behind Cyber-Physical Systems | Eclypsium was recently named in the Gartner® Hype Cycle™ for CPS Security, 2026 in the category of CPS Supply Chain Security. | Hacking blog | Eclypsium |
| 13.6.26 | Tracking Havoc Malware Activity and Evasion Techniques | This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of Havoc malware. This is a C2 framework that has many stealth capabilities, including EDR bypass by using sleep obfuscation, return address stack spoofing, and indirect syscalls. While it can be used for legitimate purposes, Havoc has been and continues to be used for a variety of malicious campaigns. | Hacking blog | SonicWall |
| 13.6.26 | Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility | Cloud logging services provide comprehensive visibility into actions performed within cloud resources, making them essential for security monitoring. However, this reliance also makes logging services a high-value target for attackers. An attacker who exploits these services could create weak spots, evade detection, and in certain scenarios, establish continuous visibility within a target’s environment. | Hacking blog | Palo Alto |
| 6.6.26 | From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. | Hacking blog | GTI | |
| 6.6.26 | Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites | Silent Push Preemptive Cyber Defense Analysts recently observed several drive-by attack clusters developed by a threat actor to automate malware delivery at scale. We named the primary driver behind an extensive surge in ClickFix and FakeUpdates campaigns: DriveSurge. | Hacking blog | Silent Push |
| 6.6.26 | Espionage Campaign Targeted Stock Exchange Executive for Five Months | Unknown attackers stole a senior executive's Outlook mailbox in incremental batches, exfiltrating through Dropbox and OneDrive Personal to keep the traffic indistinguishable from legitimate activity. | Hacking blog | SECURITY.COM |
| 6.6.26 | Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem | Check Point Research investigated a large-scale operation that impersonates open-source and freeware projects to capture search traffic, including lookalikes for researcher and security tooling such as Ghidra, dnSpy, and SpiderFoot. | Hacking blog | CHECKPOINT |
| 30.5.26 | Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2 | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Delivery Path A: LNK-Based Execution Path B: Executable-Based Delivery Stage 2 – Script-Based Dropper Chain Stage... | Hacking blog | Seqrite |
| 30.5.26 | Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan | Authors: Dixit Panchal & Vaibhav Krushna Billade Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoy: Technical Analysis: Stage 1: Analysis of LNK File. Stage 2: Analysis of HTA/JavaScript Payload Stage 3: Analysis... | Hacking blog | Seqrite |
| 30.5.26 | Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet | TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. | Hacking blog | Trend Micro |
| 23.5.26 | YellowKey: The Unpatched BitLocker Bypass Hidden in Windows Recovery | A stolen Windows 11 laptop and a USB stick are enough to read a BitLocker-encrypted drive using nothing but Microsoft’s own recovery tools, and the researcher is holding back a follow-on attack that also defeats the startup PIN defenders are scrambling to enable in response. | Hacking blog | Eclypsium |
| 16.5.26 | Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft | Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale. | Hacking blog | Trend Micro |
| 16.5.26 | Adversary in the Middle Attacks - Abusing Trust via Weaponized PDFs | The SonicWall Capture Labs threat research team has identified an active Adversary-in-the-Middle (AiTM) phishing campaign that leverages PDF documents as the initial delivery vector. This is a technique that bypasses multi-factor authentication entirely by stealing authenticated session cookies, not just credentials. | Hacking blog | SonicWall |
| 16.5.26 | Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools | Active Directory Certificate Services (AD CS) is a foundational component of Windows enterprise infrastructure, responsible for managing public key infrastructure (PKI) and issuing certificates that enable authentication and encryption across networks. | Hacking blog | Palo Alto |
| 9.5.26 | Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam’s Military Telecom & Philippine Healthcare | Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys: Technical Analysis: Campaign-1: Stage-1: Ho so.rar Campaign: 2 Stage-1: download.zip Stage-2: The LNK & Batch file (Common in 1 & 2 both) Stage-3: Analysis | Hacking blog | Seqrite |
| 9.5.26 | Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit | Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit Table of Content Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Analysis of... | Hacking blog | Seqrite |
| 9.5.26 | Operation HumanitarianBait: An Infostealer Campaign in Disguise | Cyble analyzes Operation HumanitarianBait, a stealthy espionage campaign using aid-themed lures to deploy a fileless Python infostealer. | Hacking blog | Cyble |
| 9.5.26 | Third-Party Breaches Without Breaches: How Attackers Use Trusted Access to Bypass US Enterprise Defenses | A new supply chain attack exploits trusted access and browsers. Learn how attackers bypass defenses and how to prevent supply chain attack risks. | Hacking blog | Cyble |
| 2.5.26 | The npm Threat Landscape: Attack Surface and Mitigations | The security of the npm ecosystem reached a critical inflection point in September 2025. The Shai-Hulud worm, a self-replicating malware that automated the compromise and redistribution of malicious packages, marked the end of the “nuisance” era of npm attacks and the beginning of a high-consequence threat landscape. | Hacking blog | Palo Alto |
| 2.5.26 | TGR-STA-1030: New Activity in Central and South America | TGR-STA-1030 remains an active threat. Since February, we have observed widespread activity from this group across multiple countries. Most recently, their efforts appear to be heavily focused on regions within Central and South America. | Hacking blog | Palo Alto |
| 2.5.26 | UAT-4356's Targeting of Cisco Firepower Devices | Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices. | Hacking blog | CISCO TALOS |
| 25.4.26 | Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. | Hacking blog | GTI |
| 25.4.26 | Operation TrustTrap: Anatomy of a Large-Scale Deceptive Domain Spoofing Campaign | CRIL uncovered 16,800+ spoofed domains by analyzing URL trust abuse, cloud infra clustering, and human‑centric deception instead of technical exploits. | Hacking blog | Cyble |
| 25.4.26 | The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables | An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk. | Hacking blog | Trend Micro |
| 25.4.26 | Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories | Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk. | Hacking blog | Trend Micro |
| 25.4.26 | Ghost CMS Content API Blind SQL Injection | SonicWall Capture Labs threat research team became aware of the threat CVE-2026-26980, assessed its impact, and developed mitigation measures for this vulnerability. The flaw, also known as the Ghost CMS Content API slug Filter SQL Injection, is a critical unauthenticated SQL injection vulnerability affecting Ghost in versions 3.24.0 through 6.19.0. | Hacking blog | SonicWall |
| 25.4.26 | The npm Threat Landscape: Attack Surface and Mitigations | The security of the npm ecosystem reached a critical inflection point in September 2025. The Shai-Hulud worm, a self-replicating malware that automated the compromise and redistribution of malicious packages, marked the end of the “nuisance” era of npm attacks and the beginning of a high-consequence threat landscape. | Hacking blog | Palo Alto |
| 25.4.26 | UAT-4356's Targeting of Cisco Firepower Devices | Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices. | Hacking blog | CISCO TALOS |
| 11.4.26 | Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees | Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor, tracked as Storm-2755, compromising Canadian employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts. | Hacking blog | Microsoft blog |
| 11.4.26 | Mitigating the Axios npm supply chain compromise | On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. | Hacking blog | Microsoft blog |
| 11.4.26 | Do not get high(jacked) off your own supply (chain) | In the span of just a few weeks, we have observed a dizzying array of major supply chain attacks. If we are all building on such shaky foundation, what can we do to keep safe? | Hacking blog | CISCO TALOS |
| 4.4.26 | TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM | Moving beyond their LiteLLM campaign, TeamPCP weaponizes the Telnyx Python SDK with stealthy WAV‑based payloads to steal credentials across Linux, macOS, and Windows. | Hacking blog | Trend Micro |
| 4.4.26 | Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets | Check Point Research identified a zero-day vulnerability in the TrueConf client application, tracked as CVE-2026-3502, with a CVSS score of 7.8. The flaw stems from the abuse of TrueConf’s updater validation mechanism, allowing an attacker who controls the on-premises TrueConf server to distribute and execute arbitrary files across all connected endpoints. | Hacking blog | CHECKPOINT |
| 4.4.26 | UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications | Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608. The campaign is primarily leveraging a collection framework dubbed “NEXUS Listener.” | Hacking blog | CISCO TALOS |
| 4.4.26 | Qilin EDR killer infection chain | This blog provides an in-depth analysis of the malicious “msimg32.dll” used in Qilin ransomware attacks, which is a multi-stage infection chain targeting EDR systems. | Hacking blog | CISCO TALOS |
| 4.4.26 | Do not get high(jacked) off your own supply (chain) | In the span of just a few weeks, we have observed a dizzying array of major supply chain attacks. If we are all building on such shaky foundation, what can we do to keep safe? | Hacking blog | CISCO TALOS |
| 28.3.26 | Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries | We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques. | Hacking blog | Trend Micro |
| 21.3.26 | From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA | Not every cloud breach starts with malware or a zero-day. In this incident, attackers discovered an exposed Spring Boot Actuator endpoint, harvested credentials from leaked configuration data, then used the OAuth2 Resource Owner Password Credentials (ROPC) flow to authenticate without MFA. | Hacking blog | Trend Micro |
| 21.3.26 | Move fast and save things: A quick guide to recovering a hacked account | What you do – and how fast – after an account is compromised often matters more than it may seem | Hacking blog | Eset |
| 21.3.26 | EDR killers explained: Beyond the drivers | ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers | Hacking blog | Eset |
| 14.3.26 | Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable | Hacking blog | GTI | |
| 14.3.26 | Insights: Increased Risk of Wiper Attacks | Unit 42 is tracking an increased risk of wiper attacks related to the conflict with Iran, including multiple related incidents impacting organizations in Israel and the US. For the latest intelligence on cyberattacks associated with this conflict, review our Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran. | Hacking blog | Palo Alto |
| 14.3.26 | Spinning complex ideas into clear docs with Kri Dontje | The episode features Kri Dontje discussing her role in translating complex technical cybersecurity topics into clear, accessible documentation, emphasizing the importance of consistency, accuracy, and collaboration with subject matter experts. | Hacking blog | CISCO TALOS |
| 21.2.26 | Spam Campaign Abuses Atlassian Jira, Targets Government and Corporate Entities | We uncover how a campaign used Atlassian Jira Cloud to launch automated and targeted spam campaigns, exploiting trusted SaaS workflows to bypass security controls. | Hacking blog | Trend Micro |
| 21.2.26 | “Good enough” emulation: Fuzzing a single thread to uncover vulnerabilities | A Talos researcher used targeted emulation of the Socomec DIRIS M-70 gateway’s Modbus thread to uncover six patched vulnerabilities, showcasing efficient tools and methods for IoT security testing. | Hacking blog | CISCO TALOS |
| 14.2.26 | Dark Web Roast - January 2026 Edition | Welcome to January 2026's underground intelligence roundup, where criminal masterminds continue to demonstrate that the phrase "honour among thieves" remains the greatest oxymoron in cybercrime. | Hacking blog | Trelix |
| 7.2.2026 | Novel Technique to Detect Cloud Threat Actor Operations | Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. The difficulty doesn’t lie in an inability to identify complex alerting operations across thousands of cloud resources or in a failure to follow identity resources, the problem lies in the accurate detection of known persistent threat actor group techniques specifically within cloud environments. | Hacking blog | Palo Alto |
| 7.2.2026 | Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework | Cisco Talos uncovered “DKnife,” a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants. | Hacking blog | CISCO TALOS |
| 7.2.2026 | The Crown Jewels of Active Directory: How Trellix Helix Detects NTDS.dit Theft | This blog from the Trellix Advanced Research Center examines a security incident where adversaries infiltrated a system, extracted the NTDS.dit database, and worked to remove it from the environment while circumventing standard security measures. | Hacking blog | Trelix |
| 1.2.26 | Beyond MFA: Building true resilience against identity-based attacks | As identity-driven attacks continue to rise, organizations must go beyond MFA to build resilience. Sophos experts and recent Gartner research agree: It’s time for an identity-first security strategy backed by continuous detection and response. For many organizations, keeping pace with identity threats feels overwhelming, especially as hybrid environments expand. But there’s a clear path forward. | Hacking blog | SOPHOS |
| 1.2.26 | Chrome Extensions: Are you getting more than you bargained for? | Browser extensions can be really useful, but hidden dangers may lurk beyond their marketing. | Hacking blog | SECURITY.COM |
| 24.1.26 |
We X-Rayed A Suspicious FTDI USB Cable |
We recently got an industrial X-Ray machine in the Eclypsium office to use to make the next Doctor Manhattan do serious cybersecurity research. In between X-raying yet-to-be released industrial IT technologies on behalf of giant companies whose names we cannot reveal, we have done some other fun experiments. | Hacking blog | Eclypsium |
| 17.1.26 | Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation | Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol. Despite Net-NTLMv1 being deprecated and known to be insecure for over two decades—with cryptanalysis dating back to 1999—Mandiant consultants continue to identify its use in active environments. This legacy protocol leaves organizations vulnerable to trivial credential theft, yet it remains prevalent due to inertia and a lack of demonstrated immediate risk. | Hacking blog | |
| 17.1.26 | Key Insights on SHADOW-AETHER-015 and Earth Preta from the 2025 MITRE ATT&CK Evaluation with TrendAI Vision One™ | This blog discusses notable modern TTPs observed from SHADOW-AETHER-015 and Earth Preta, from TrendAI™ Research monitoring and TrendAI Vision One™ intelligence. These findings support the performance of TrendAI™ in the 2025 MITRE ATT&CK Evaluations. | Hacking blog | |
| 17.1.26 | Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering | No employee wants their paycheck to go missing. One organization learned about an incident when they started hearing exactly this complaint. It turned out that an attacker had modified direct-deposit details in order to redirect an organization’s paychecks into attacker-controlled accounts. | Hacking blog | Palo Alto |
| 17.1.26 | Your personal information is on the dark web. What happens next? | If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do. | Hacking blog | Eset |
| 17.1.26 | Hiding in Plain Sight: Multi-Actor ahost.exe Attacks | The Trellix Advanced Research Center found an active malware campaign exploiting a DLL sideloading vulnerability in the legitimate Git tools to target supply chains. Stay protected—update EDR/XDR and monitor for suspicious activity. | Hacking blog | Trelix |
| 10.1.26 | The Ghost in the Machine: Unmasking CrazyHunter's Stealth Tactics | Trellix provides an in-depth analysis of CrazyHunter ransomware and its attack flow, which has emerged as a significant and concerning threat. | Hacking blog | Trelix |