#threatresearch

20 posts · Last used 2d

Back to Timeline
AA @AAKL@infosec.exchange · 2d ago
0
0
0
AA @AAKL@infosec.exchange · 3d ago
New. Cisco: Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ @TalosSecurity@mstdn.social Group-IB (co-written by a marketer): Ransomware in 2026: Same Business, New Rules https://www.group-ib.com/blog/ransomware-2026-rules/ Warning: Recorded Future sells everything and the kitchen sink to third parties, including Google. No consent, no options. Recorded Future: TAG-195 Upgrades MaaS Ecosystem with Modular Tools https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem Microsoft: Email threat landscape: Q2 2026 trends and insights https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/ Proofpoint; TA488 Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits --- Rapid7: What Happened Between OpenAI and Hugging Face? https://www.rapid7.com/blog/post/ai-openai-hugging-face-what-happened/ @Rapid7Official@infosec.exchange Picus: "OpenAI was doing something reasonable and responsible. It was measuring how good its frontier models are at offensive cyber operations, so it could understand the risk." Picus: The Day an AI Cheated on Its Exam by Hacking Another Company https://www.picussecurity.com/resource/blog/the-day-an-ai-cheated-on-its-exam-by-hacking-another-company --- Posted yesterday: Huntress: Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat @huntress@infosec.exchange Fortinet: Inside a TrickBot Variant Using DNS Tunneling for C2 https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2 @fortinet@infosec.exchange #infosec #threatresearch #ransomware #Windows #Microsoft #Claude #phishing #OpenAI #Zimbra
0
0
0
AA @AAKL@infosec.exchange · 3d ago
Socket published this yesterday, if you missed it: Socket: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation @SocketSecurity@fosstodon.org #infosec #threatresearch #GitHub
0
0
0
AA @AAKL@infosec.exchange · 6d ago
New. Proofpoint: Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service #infosec #threatresearch #cybercrime
0
0
0
Jamf Threat Labs @jamfthreatlabs@bird.makeup · Jul 13, 2026
Meet CrashStealer. This one takes delivery more seriously than most, a signed and Apple-notarized dropper that's pulling its second stage payload down through GitHub. The payload is a native C++ stealer with client-side AES-GCM encryption and layered anti-analysis. Check out our writeup for additional details and indicators of compromise. https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/ #infostealer #malware #macos #threatresearch
1107
0
20
AA @AAKL@infosec.exchange · Jul 16, 2026
0
1
1
AA @AAKL@infosec.exchange · Jul 16, 2026
New. Any.Run: Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware https://any.run/cybersecurity-blog/phantomenigma-research/ @anyrun_app@infosec.exchange #infosec #phishing #threatresearch
0
0
0
AA @AAKL@infosec.exchange · Jul 16, 2026
New. "Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025." Cisco: UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ @TalosSecurity@mstdn.social #infosec #threatresearch #Python
0
0
0
AA @AAKL@infosec.exchange · Jul 16, 2026
New. Binerly: Fit for Detection: Hunting U-Boot Vulnerabilities at Scale https://www.binarly.io/blog/hunting-u-boot-at-scale #infosec #threatresearch #vulnerability
0
0
0
AA @AAKL@infosec.exchange · Jul 16, 2026
The original research comes from Cato Networks: https://go.catonetworks.com/rs/245-RJK-441/images/The_Agentic_Attacker_the_long_blog.pdf More: Infosecurity-Magazine: Researchers Claim Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain https://www.infosecurity-magazine.com/news/chatgpt55-to-execute-full/ @dannyjpalmer@infosec.exchange #infosec #vulnerability #Chatgpt #threatresearch
0
0
0
AA @AAKL@infosec.exchange · Jul 15, 2026
0
0
0
AA @AAKL@infosec.exchange · Jul 15, 2026
New. This starts with a phone call. "Business owners, professionals, retirees, government employees, and experienced executives continue to fall for variations of the same operation across different cities, different stories, and different backgrounds. The alarming part is that the mechanics barely change." Securonix: Digital Arrest Scams: One of India's Most Heinous Cybercrime Stories https://www.securonix.com/blog/digital-arrest-scams-india-social-engineering/ #infosec #scam #threatresearch #cybercrime
0
0
0
AA @AAKL@infosec.exchange · Jul 15, 2026
0
0
0
AA @AAKL@infosec.exchange · Jul 14, 2026
New. This quote is just the tip of the iceberg: "AI has crossed from development aid to live attack operator. It now does the hands-on work inside live intrusions, from China-nexus espionage campaigns to a criminal breach of multiple Mexican government agencies and has spread from nation states to ordinary cyber criminals." Check Point: AI Security Report 2026 https://research.checkpoint.com/2026/ai-security-report-2026/ Also: Rapid7: CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/ @Rapid7Official@infosec.exchange Vulncheck: Monsta FTP: An SSRF Blocklist That Forgot IPv6 Exists https://www.vulncheck.com/blog/monsta-ftp-ssrf-ipv6-blocklist-bypass @vulncheck@infosec.exchange Any.Run: ​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​ https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/ @anyrun_app@infosec.exchange Scam alert: Group-IB: The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets https://www.group-ib.com/blog/fake-concert-ticket-scam-celine-dion/ #phishing #scam #infosec #threatresearch #cybercrime #Microsoft #vulnerability #threatintel #threatintelligence #Microsoft #malware
0
0
0
AA @AAKL@infosec.exchange · Jul 14, 2026
New. "LabubaRAT creates a reusable foothold for hands-on activity. Once deployed, it can profile the host, identify security tools, receive operator commands, move files, capture screenshots, and proxy traffic through the affected system." Blackpoint Cyber: LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software https://blackpointcyber.com/blog/labubarat-a-rust-based-remote-access-tool-masquerading-as-nvidia-software/ #infosec #threatresearch #malware #Rust #Nvidia
0
0
0
AA @AAKL@infosec.exchange · Jul 14, 2026
Who asked for Tuesday? New. ESET: Forgotten UEFI shims undermining Secure Boot https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/ @ESETresearch@infosec.exchange More: The Hacker News: 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html @thehackernews@social.tchncs.de #Microsoft #infosec #threatresearch #vulnerability
0
0
0
AA @AAKL@infosec.exchange · Jul 09, 2026
New. Huntress: Seven Steps to Ransomware: CitrixBleed 2 Weaponized by Initial Access Brokers https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware @huntress@infosec.exchange #infosec #threatresearch #ransomware #vulnerability
0
0
0
AA @AAKL@infosec.exchange · Jul 09, 2026
New. Socket: Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics https://socket.dev/blog/compromised-injective-sdk-npm-package @SocketSecurity@fosstodon.org #infosec #threatresearch #npm #GitHub
0
0
0
Censys @censys@infosec.exchange · Jul 07, 2026
Replying to @censys@infosec.exchange
All of this was measured using Censys Internet intelligence to help defenders better understand an ecosystem that isn't well covered by traditional threat intelligence. Read Alex Gartner's full research: https://censys.com/blog/roblox-minecraft-and-the-insidious-internet-for-children/ #InternetIntelligence #ThreatResearch #InfoSec #OSINT
0
0
0
AA @AAKL@infosec.exchange · Jul 07, 2026
0
0
0