-
HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside what appears to be an almost empty desktop.ini file. At just 12,288 bytes, the x64 implant was observ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections, allowing the execution of unsigned code within highly…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Armored Likho, also tracked as Eagle Werewolf, has expanded its espionage capability with a Rust-based toolkit that can hijack Telegram sessions and transform compromised Windows endpoints into automated audio-surveillance devices. The newly documented…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Nightmare-Eclipse, also known as Chaotic Eclipse, has released a new Windows privilege escalation exploit named ShieldBreak. This exploit claims to bypass Microsoft’s July 2026 fix for the RoguePlanet Windows Defender vulnerability,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers Alejandro Hernando, also known as 0xedh, and Borja Martínez have unveiled a research project titled “Plug & Pwn.” This project demonstrates how the Windows Plug and Play (PnP) driver installation workflows can be ex…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encryp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Micros…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


