Advertisement
khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access
Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.
CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence
CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.
Post-Exploitation Tactics: Persistence and Lateral Movement Analysis
Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.
Hermes AI Agent Automates Post-Exploitation Against Thai Ministry
Hermes AI agent automates post-exploitation during alleged breach of Thai Ministry of Finance. Learn TTPs, impact, and mitigation for AI-driven threats.
CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation
Discover how threat actors are leveraging LLM agents to automate post-exploitation tasks after compromising Marimo notebooks via CVE-2026-39987.
RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement
Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.
Advertisement
Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges
Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.
Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis
The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.