Advertisement
Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence
CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.
CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys
Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.
Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT
Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.
Junior Hacker's Tailscale & OpenSSH Post-C2 Persistence
Analysis of a junior hacker's TTPs, leveraging Tailscale and OpenSSH for persistent access to a French automotive business after their Havoc C2 server went offline.
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.
Advertisement
Active Directory Post-Breach Persistence: Why Password Resets Fail
Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.
UNC6692 Targets Microsoft Teams to Deploy Snow Malware
UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.
FIRESTARTER Backdoor Exploits Cisco Firepower ASA Software
CISA and NCSC reveal FIRESTARTER, a persistent backdoor targeting Cisco Firepower devices running ASA software, used in federal agency compromises.
Firestarter Backdoor Infects Cisco Firewall at US Federal Agency
Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.
FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall
CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.
Detecting Malicious Web Shells: Analysis of Persistence and TTPs
Discover how attackers use deceptive naming and pre-set credentials in web shells to maintain persistence and how to detect these malicious files on servers.
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…
Telecom Sleeper Cells and LLM Jailbreak Trends: Weekly Analysis
An analysis of long-term persistence in telecom networks, LLM jailbreak methodologies, and regulatory shifts in UK age verification for Apple users.
GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact
Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.
Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.
BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…