What GTG-1002 and Claude-Style Attacks Mean for SaaS Verification

GTG-1002 is the first documented case of an AI agent orchestrating real-world intrusions with minimal human input, with a Chinese state-sponsored group manipulating Anthropic’s Claude Code to perform about 80% of a multi-target campaign autonomously. The AI handled reconnaissance, vulnerability discovery, exploitation, credential theft, and data exfiltration across dozens of organizations, operating at machine tempo and executing tasks in seconds—far faster than any human team could.
#GTG-1002 #ClaudeCode

Read More
After React2Shell: Following the Attacker From Access to Impact

React2Shell (CVE-2025-55182) is a critical unauthenticated remote code execution vulnerability in React Server Components that allows attackers to deliver malicious Flight payloads and achieve code execution on servers running React 19.x with Server Components. It was rapidly weaponized with public PoCs, Metasploit modules, large-scale scanning, confirmed compromises, and nation-state exploitation—forcing KEV listing and causing operational impacts reported by providers like Cloudflare. #React2Shell #CVE-2025-55182

Read More
Detecting Next.js CVE-2025-66478 RCE vulnerability with Wazuh

A critical Remote Code Execution (RCE) vulnerability (CVE-2025-66478) in Next.js App Router arises from an upstream flaw in the React Server Components (RSC) protocol (CVE-2025-55182), allowing unauthenticated attackers to send crafted RSC requests that execute arbitrary code on vulnerable servers. Wazuh can detect exposed systems by identifying vulnerable package versions, monitoring…

Read More
Critical Vulnerabilities in React Server Components and Next.js

Researchers disclosed critical remote code execution vulnerabilities in the Flight protocol for React Server Components on Dec. 3, 2025, enabling unauthenticated attackers to execute arbitrary server-side JavaScript via insecure deserialization. The flaws (tracked as CVE-2025-55182, with CVE-2025-66478 later marked a duplicate) affect React 19 and frameworks such as Next.js, are highly…

Read More
Sha1-Hulud: The Second Coming of The New npm GitHub Worm

Sha1-Hulud has launched a sophisticated supply-chain attack targeting npm packages used by JavaScript developers, infecting nearly 1,000 packages and exposing tens of thousands of repositories. The latest campaign includes new features like cross-platform support, a self-destruct mechanism, and remote code execution via GitHub Actions, increasing the threat’s severity. #Sha1Hulud #npmSupplyChainAttack…

Read More
V3G4 Botnet Evolves: From DDoS to Covert Cryptomining

Cyble Research & Intelligence Labs (CRIL) uncovered an active Linux campaign delivering a Mirai-derived V3G4 botnet that performs raw-socket SSH scanning, C2 DNS resolution, and process masquerading before deploying a runtime-configured XMRig Monero miner. The campaign uses an architecture-aware downloader, tmpfs staging, UPX-packed binaries, and fileless miner configuration fetched from C2 to maximize stealth and evasion. #V3G4 #XMRig

Read More
FlexibleFerret: macOS Malware Used in Fake Job Scams

Jamf Threat Labs analyzed a multi-stage FlexibleFerret campaign that uses fake recruitment websites and staged hiring assessments to socially engineer macOS users into running Terminal commands that download and execute a shell loader and Go backdoor. The attack establishes persistence via a LaunchAgent, displays a decoy MediaPatcher.app to capture Chrome credentials and keychain data, and exfiltrates harvested data using the Dropbox upload API as part of the Contagious Interview operation. #FlexibleFerret #ContagiousInterview

Read More
Salty2FA & Tycoon2FA Hybrid: A New Phishing Threat to Enterprises 

A sudden collapse in Salty2FA infrastructure in late October 2025 coincided with samples that contained indicators, code, and delivery fallbacks from both Salty2FA and Tycoon2FA, producing single payloads that executed stages from each kit. This hybridization complicates attribution and detection, and suggests defenders should treat Salty2FA and Tycoon2FA as a linked…

Read More
What Is Cyber Threat Hunting? Types, Tricks, and Tips | Huntress

Threat hunting is a proactive, human-driven process that searches networks and endpoints to identify hidden or emerging threats missed by automated defenses. Combining intelligence, data analysis, and skilled hunters—supported by tools like Huntress Managed SIEM—enables organizations to detect and contain threats earlier and convert successful hunts into automated detections. #Huntress #HuntressManagedSIEM

Read More
APT36 Python Based ELF Malware Targeting Indian Government Entities

CYFIRMA uncovered an APT36 campaign delivering a Python-based RAT to BOSS Linux systems via weaponized .desktop shortcut files inside a malicious archive that staged downloads from lionsdenim[.]xyz and 185[.]235[.]137[.]90. The campaign establishes persistence (systemd user services), supports remote command execution, file exfiltration, screenshots, and cross-platform control for sustained espionage. #APT36 #BOSS

Read More
Shai-hulud 2.0 Campaign Targets Cloud and Developer Ecosystems

Shai-hulud 2.0 is a sophisticated NPM-supplied malware that steals credentials and secrets from AWS, GCP, Azure, GitHub, and NPM, then uses those credentials to create attacker-controlled GitHub repositories, GitHub Actions runners/workflows, and to republish backdoored NPM packages. The campaign automates worm‑like supply‑chain propagation by injecting malicious preinstall hooks (setup_bun.js → bun_environment.js)…

Read More

Microsoft plans to enhance Entra ID security by implementing stricter Content Security Policy (CSP) controls to prevent script injection attacks starting in October 2026. This move is part of its broader Secure Future Initiative (SFI) to improve authentication security and protect against cross-site scripting (XSS) threats. #EntraID #ContentSecurityPolicy #XSS #SecureFutureInitiative…

Read More
Zscaler Threat Hunting Discovers and Reconstructs a Sophisticated Water Gamayun APT Group Attack

Zscaler reconstructed a multi-stage intrusion attributed to the Water Gamayun APT that used a compromised BELAY Solutions site and a lookalike domain to deliver a double-extension RAR disguised as a PDF, exploit MSC EvilTwin (CVE-2025-26633) via mmc.exe, and chain hidden PowerShell stages to deploy a final ItunesC loader. Zscaler attributed the campaign to Water Gamayun based on unique TTPs including MSC EvilTwin exploitation, nested Base64/UTF-16LE PowerShell obfuscation, trusted-binary proxy execution via mmc.exe, window-hiding tradecraft, and dual-path infrastructure patterns #WaterGamayun #CVE-2025-26633

Read More
Water Gamayun Weaponizes “MSC EvilTwin” Zero-Day for Stealthy Backdoor Attacks

A new cyber espionage campaign by Russia-aligned APT group Water Gamayun exploits a zero-day Windows vulnerability, CVE-2025-26633, to infiltrate high-value networks. The attack relies on social engineering and exploits trusted Windows processes to deploy malware and steal sensitive information. #WaterGamayun #CVE202526633…

Read More