Data access: the hidden cost of security vendor lock-in

The article argues that SOC teams should treat security telemetry as their most valuable asset and demand open data access that is free, complete, and real time. It warns that vendors who charge for export, delay delivery, or only provide partial data create lock-in and weaken incident response, with references to CrowdStrike’s 2026 Global Threat Report and Elastic’s own stance on live access. #CrowdStrike #Elastic #SIEM #SOC

Read More
Angry Birds: Toy Ghouls’ new toys

Toy Ghouls, also tracked as Bearlyfy, Laboo.boo, and Feral Wolf, is using custom backdoors that communicate through HiveMQ MQTT and the Element/Matrix platform after previously relying on public tools and leaked ransomware builders. The campaign targets Russian organizations and has been linked to GenieLocker, with infrastructure and artifacts including #ToyGhouls #GenieLocker #broker.hivemq.com #meet.element.tw.

Read More
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

ASEC found attack cases where threat actors used Radmin and UltraVNC to take over infected systems, then deployed Netch, CCProxy, and SoftEther VPN to turn them into proxy nodes and VPN servers. The activity involved downloads from 103.86.86[.]244 and used Chinese-language scripts and configuration files, suggesting a Chinese-speaking operator. #Radmin #UltraVNC…

Read More
Node.js: Old Technique Makes a Comeback

Symantec reports that attackers have revived abuse of Node.js since February 2026, using the trusted node.exe runtime for persistence and execution against victims including government departments, technology companies, and hotels. In the observed campaigns, actors tied to Woodgnat/KongTuke and other threats used ClickFix, AdaptixC2, Cobalt Strike, ModeloRAT, Backdoor.Mistic, C2Looper, and EtherHiding-style Ethereum blockchain lookups to maintain access and evade defenses. #Node.js #AdaptixC2 #CobaltStrike #ModeloRAT #BackdoorMistic #C2Looper #EtherHiding #Woodgnat #KongTuke

Read More

DFIR Report identified BengalSEO, a Rajasthan-based scam operation that has used SEO poisoning, malicious lure pages, and a traffic distribution system to deliver the MayaBot malware and drive tech support fraud since at least 2015. The campaign relies on companies such as WeConnect Solutions LLC and Garage2Global, along with infrastructure spanning GitHub, Hostmaza, Cloudflare, Matomo, and numerous redirector and payload domains. #BengalSEO #MayaBot #WeConnectSolutionsLLC #Garage2Global #Hostmaza #Cloudflare #Matomo

Read More
Remote access hardening playbook: Reducing RMM tool risk for SMBs

This article turns telemetry from over 1.8 million endpoints into a practical hardening guide for remote access tools most often abused by attackers, including RDP, ScreenConnect, MeshAgent, and VNC. It recommends a tiered defense strategy of blocking, monitoring, and tightly auditing remote tools to reduce attack surface and detect attacker-deployed access quickly. #RDP #ScreenConnect #MeshAgent #VNC #AmmyyAdmin #UltraVNC #RDPWrap

Read More
H1 2026 Malware Vulnerability Trends

H1 2026 threat activity was dominated by abuse of legitimate tools, trusted platforms, and routine workflows, while AI mainly augmented existing intrusion tradecraft rather than replacing it. The report also highlights widespread exploitation of exposed CVEs, persistent RAT and stealware activity, evolving supply-chain compromises, NFC-based mobile fraud, and Magecart campaigns that leveraged trusted third-party services. #AsyncRAT #CobaltStrike #XWorm #Stealc #REMCOSRAT #PromptSpy #NGate #NFCShare #Magecart #ShaiHulud #TeamPCP

Read More
Malware on the Blockchain: An Ongoing Campaign’s New WebRTC Twist

EtherHiding has been used on more than 5,400 compromised small-business websites to fetch payloads from BNB Smart Chain testnet smart contracts, enabling takedown-resistant delivery of ClickFix lures or a covert WebRTC command channel. Netskope says the campaign spans over 2,200 organizations worldwide and continues to grow as operators rewrite a single on-chain contract to change what victims receive. #EtherHiding #BNBSmartChain #ClickFix #WebRTC

Read More
Modern Adventures in Azure Privilege Escalation

The article explains how Azure RBAC and ABAC can be analyzed at the permission level to uncover privilege escalation paths, including a built-in role that once allowed arbitrary escalation to Owner. It also describes an undocumented ARM API for mapping permissions to roles, the discovery and remediation of the Anyscale Platform Administrator Role issue, and recommendations for reducing attack surface in Azure. #AzureRBAC #ABAC #AnyscalePlatformAdministratorRole

Read More
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

This report details two AI-assisted intrusion campaigns in Latin America: CL-CRI-1131 against Mexican transportation and government-related targets, and CL-CRI-1163 against Brazil’s financial sector. Attackers used living-off-the-land techniques, custom RATs, SOCKS5 tunneling tools, and exposed NextChat/LLM infrastructure to troubleshoot failures, stage scripts, and exfiltrate data. #CL-CRI-1131 #CL-CRI-1163 #NextChat #SockTz #Claude #GPT-4.1…

Read More
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point Research describes Gambling Goblin, a Chinese-speaking cybercrime group linked to Earth Berberoka, as running a sustained campaign against Brazilian government and educational organizations since mid-2025. The operation uses malicious Apache modules, SEO manipulation, and a large Linux toolkit to hijack traffic, serve phishing pages that impersonate Google Play, Microsoft Store, and Amazon, and scale into Vietnamese, Spanish, and English targeting. #GamblingGoblin #EarthBerberoka #Apache #GooglePlay #MicrosoftStore #Amazon

Read More
Kim Sooki again? This time, it was disguised as a request for seafood ingredients

A malicious LNK file disguised as a seafood ingredient purchase request was used to deliver a decoy HWP document while PowerShell, scheduled tasks, and external communications ran in the background. The attack exfiltrated system information, fetched additional commands from Backblaze B2, and was linked by AhnLab to Kimsuky. #Kimsuky #BackblazeB2 #AhnLab…

Read More
Python NodeStealer: AI-Assisted to Full Spyware

Netskope Threat Labs reports that Python-based NodeStealer has evolved from a Facebook credential stealer into a spyware-capable tool with keylogging, clipboard monitoring, screenshot capture, and a split Telegram C2 design. The new variant also expands Facebook Graph API collection to more than 20 endpoints, suggesting AI-assisted development and broader abuse of Facebook and Ads Manager data. #NodeStealer #NetskopeThreatLabs #Facebook #AdsManager #Telegram

Read More
“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing

MoiClient is an evasive backdoor distributed as an invoice-lure VHDX file that uses DLL side-loading, process injection, RPC-based UAC bypass, and BYOVD to evade defenses and maintain persistence. It repeatedly reappears through Task Scheduler and ultimately delivers MoiXD Stealer to steal browser information. #MoiClient #MoiXDStealer #BootRepairSys #LenovoPCManager #SumatraPDF…

Read More