How to correlate Kubernetes audit logs with container runtime data

The article explains how to correlate Kubernetes audit logs with Elastic Defend for Containers data to investigate suspicious service account activity, pod creation, and attempted container escape behavior. It highlights two main join methods—pod caller identity and service account plus objectRef pod names—using an EKS lab scenario that includes a breakout pod, nsenter, chroot, and decoded exec requestURIs. #ElasticDefendforContainers #Kubernetes #EKS #nsenter #chroot

Read More
Linux Detection Engineering – Local Privilege Escalation

The article describes a layered Linux privilege escalation detection framework that combines general root-transition logic with technique-specific rules for SUID abuse, unshare, Python-driven exploits, and kernel page-cache corruption. It also reviews 2026 Linux LPE cases such as Copy Fail, DirtyFrag, Fragnesia, DirtyDecrypt, pedit COW, DirtyClone, CIFSwitch, OVSwrap, and CVE-2026-46333, showing how Elastic Defend and Auditd can catch them in practice. #CopyFail #DirtyFrag #Fragnesia #DirtyDecrypt #peditCOW #DirtyClone #CIFSwitch #OVSwrap #CVE-2026-46333

Read More
The sparrow that chirped too loud: FamousSparrow attacks using updated SparrowDoor and the new SquawkDoor backdoor

The SquawkDoor backdoor uses browser-waiting and a one-time POST to /register-ip as anti-analysis and execution confirmation, then connects to its command-and-control server over TLS with a custom SQD1 protocol. After the handshake, it collects basic host information and awaits further commands from the C2 server. #SquawkDoor #register-ip #SQD1

Read More
DragonDoll: the spyware hiding behind a Google Chrome update

DragonDoll uses hybrid encryption with AES-256-CBC for data and RSA-OAEP for key exchange, then sends extensive device information after registration. Its NetworkUtils and bgs components support C2 messaging, overlay file retrieval for ENABLE_INJECT, and persistent Socket.IO-based handling of incoming connections. #DragonDoll #NetworkUtils #bgs #Socket.IO

Read More
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers

FortiGuard Labs observed a Casbaneiro campaign targeting Windows users in Latin America through phishing emails and PDF lures themed as fake invoices and legal notices. The attack used a multi-stage chain with HTA and AutoIt loaders, stealthy environment checks, and selective C2 behavior to steal data and evade analysis. #Casbaneiro #FortiGuardLabs #MicrosoftWindows #MicrosoftOutlook

Read More
Detecting Windows attacks with Microsoft Defender ASR and Wazuh 

The article explains how Microsoft Defender Attack Surface Reduction (ASR) rules can block suspicious Windows behaviors such as WMI-based process creation, persistence, copied system tools, and malicious Office activity, while also logging configuration changes. It also shows how Wazuh collects ASR telemetry and uses custom rules to detect and visualize blocked…

Read More
Fake Tax-Themed Phishing Campaign Delivers Malware

CYFIRMA reports a multi-domain campaign that impersonates the Indian Income Tax Department to lure victims into downloading a malicious VHDX file that delivers a loader and DLL payload. The operation uses ten disposable .shop domains, process injection into Runtimebroke.exe, and an attempted connection to xvcbvgfr.com, with infrastructure and artifacts tied to Common_Offline_Utility_ITR-1_to_4_AY2026-07-27.vhdx, Common_Offline_Utility_ITR-1_to_4_AY2026-27.exe, and tedutil.dll. #IncomeTaxDepartment #Runtimebroke.exe #tedutil.dll #xvcbvgfr.com

Read More
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Socket’s Threat Research Team found that the cross-store browser extension “Twitch Enhanced Viewer | JeetBot” forwards users’ live Twitch OAuth session tokens to operator-controlled proxy infrastructure, exposing account-scoped credentials across Chrome and Firefox. Earlier versions even POSTed the token to a dedicated set-token endpoint, and the operator’s infrastructure is tied to the JeetBot commercial Twitch, Kick, and VK-Live bot service. #TwitchEnhancedViewer #JeetBot #ChromeWebStore #FirefoxAddons

Read More
Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit

Sysdig TRT observed a skilled threat actor exploit CVE-2026-39987 in marimo to move from an unauthenticated WebSocket terminal to SSH access on a bastion host in eight seconds, using hand-built Python tooling rather than LLM-generated scripts. The campaign involved AWS credential harvesting, Secrets Manager access, EC2 enumeration, and direct SSH pivoting, with infrastructure tied to Akamai Connected Cloud/Linode. #CVE-2026-39987 #marimo #AWSSecretsManager #Linode

Read More
DNS Footprinting: SourTrade Distributes Unfinished Malware through Malvertising

Confiant reported that SourTrade used malvertisements to spread unfinished malware while impersonating TradingView, Solana, and Luno to target retail traders and crypto investors. The investigation uncovered extensive malicious infrastructure, including typosquatting domains, email-connected domains, and IP addresses linked to the campaign, with many already flagged as malicious. #SourTrade #Confiant #TradingView #Solana #Luno

Read More
SloppyRAT: A New Tool For Ransomware Attacks

Zscaler ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware-related attacks and delivered through a multi-stage ClickFix infection chain. It combines anti-analysis features, EtherHiding-based C2 resolution, certificate pinning, and extensive remote command execution capabilities, while also showing signs of ongoing development and coding flaws. #SloppyRAT #ClickFix #CastleLoader #CastleRAT #EtherHiding

Read More
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

Researchers introduced a plain-English prompt-crafting method that hides a policy-violating payload inside an obfuscated prose wrapper, allowing quick LLM gatekeepers to miss it while a stronger target model can recover and act on the embedded request. In tests against gpt-4o-mini-2024-07-18, gpt-oss-safeguard:20b, claude-3-haiku-20240307, and llama-guard3, the crafted prompts bypassed gatekeepers in all trials, and gpt-5-thinking-high recovered and executed the payload in most target tests. #gpt-4o-mini-2024-07-18 #gpt-oss-safeguard:20b #claude-3-haiku-20240307 #llama-guard3 #gpt-5-thinking-high

Read More
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

Socket uncovered a cross-browser extension campaign using malicious Chrome and Firefox add-ons to steal authenticated Axiom Trade and Padre session data, wallet-related state, tokens, and cookies from cryptocurrency traders. The operation spans J7Tracker, VREO, Orbit Tracker, GhostApe, and GhostApe Color, with exfiltration sent to threat actor-controlled Vercel and other infrastructure. #J7Tracker #VREO #OrbitTracker #GhostApe #AxiomTrade #Padre #Vercel

Read More
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

Volexity uncovered spear-phishing campaigns by UTA0560 and JungleBamboo that abused a Chrome zero-day exploit chain to target NGOs and other victims through malicious links and patched-but-unreleased Chromium flaws. UTA0560 used the chain to deploy GRIMWEDGE, while JungleBamboo used it to install SUPERSTOMP and the LONGTALE Chrome extension for credential theft and surveillance. #UTA0560 #JungleBamboo #GRIMWEDGE #SUPERSTOMP #LONGTALE #CVE-2026-85046 #CVE-2026-85880 #CVE-2026-87491

Read More