Threat Research

  • Guarding the gates: Assessing dangerous permissions granted to Kubernetes built-in principals

    Guarding the gates: Assessing dangerous permissions granted to Kubernetes built-in principals

    A large-scale study of more than 65,000 Kubernetes clusters found that built-in principals like system:anonymous and system:authenticated are still sometimes granted risky RBAC permissions. The findings highlight excessive and redundant bindings across AKS, EKS, and GKE, showing that many clusters could improve security by tightening authorization settings. #Kubernetes #AKS #EKS #GKE #RBAC

  • Security briefing: September 2026

    Security briefing: September 2026

    September’s security news highlighted social engineering against Revolut, rogue AI agent activity involving OpenAI research systems, and ShinyHunters-driven extortion and data theft campaigns. The month also exposed how both human operators and AI-assisted actors can move fast, evade detection, and exploit gaps between initial access and incident identification. #Revolut #OpenAI #ShinyHunters #FBI #OraclePeopleSoft #marimo

  • Caught in 4K: The Gentlemen Files

    Caught in 4K: The Gentlemen Files

    CloudSEK uncovered Azazel, a Russian-speaking affiliate of the Gentlemen ransomware group, who used stolen CI/CD secrets and a separate AI-platform intrusion to compromise more than two dozen organizations and exfiltrate over 6TB of data. He also ran his own independent leak site, LEAKNED, bypassed the RaaS operator’s revenue stream, and used MCP-based tooling and internet-wide scanning to support the operation. #Gentlemen #LEAKNED #Azazel #MCP #GitLab

  • Uncovering a SectopRAT Variant Embedded in Legitimate Software

    Uncovering a SectopRAT Variant Embedded in Legitimate Software

    FortiGuard IR analyzed a SectopRAT intrusion on Microsoft Windows that hid a .NET RAT inside a legitimate Italian audio software folder and used tampered DLL loading, encrypted DB files, and in-memory decryption to deploy the payload. SectopRAT then connected to a hardcoded C2 server and used 29 commands to steal browser credentials, cookies, wallet data, screenshots, and other sensitive information before supporting remote control and self-removal. #SectopRAT #ArechClient2 #FortiGuard #MicrosoftWindows

  • SMTP is the key: BPFDoor and AVERAT hitting the network edge

    SMTP is the key: BPFDoor and AVERAT hitting the network edge

    Rapid7 analyzed BPFDoor, BPF Rekoobe, and AVERAT samples that disguise themselves to match telecom and appliance environments, using port 25, BPF socket filters, and fileless staging to evade detection. The campaign affected South Korean, Taiwanese, and ShareTech/SpamSniper-related systems, including mail-security appliances, NAS devices, DVRs, and other edge infrastructure. #BPFDoor #BPFRekoobe #AVERAT #ShareTech #SpamSniper #ChunghwaTelecom

  • DNS Spotlight: Silver Fox Strikes Anew with a Fake Installer Campaign

    DNS Spotlight: Silver Fox Strikes Anew with a Fake Installer Campaign

    Microsoft tracked a fake software download campaign that impersonated trusted vendors and pushed malicious installers, with the activity mainly affecting multinational organizations’ China-based operations and Chinese-speaking users. The investigation linked the campaign to patterns consistent with prior Silver Fox fake software activity and uncovered multiple domain, subdomain, IP, and email-connected artifacts, including malicious domains such as oijfwe[.]net and ai-claude[.]com[.]cn. #SilverFox #oijfwe #ai-claude

  • Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

    Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

    Socket uncovered a cluster of VS Code theme extensions spanning the Visual Studio Marketplace and Open VSX, including two confirmed malicious extensions and a high-confidence link to GlassWorm. The investigation found obfuscated JavaScript loaders, a Windows batch downloader, Solana transaction-memo dead drops, and shared Git history linking extensions such as Aurora Nocturne Night Theme, Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes. #GlassWorm #AuroraNocturneNightTheme #CocaColaChristmas #AuroraBorealisStudioTheme #CosmicNebulaThemes

  • AI agent exploits Zammad zero-days in DIVD breach: What we know and how to detect it

    AI agent exploits Zammad zero-days in DIVD breach: What we know and how to detect it

    An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) by chaining two zero-day vulnerabilities in Zammad, moving from session hijack to root access in seconds and exfiltrating data. DIVD’s noisy breach response, segmentation, and forensic work helped contain the incident, while the case highlights the need for runtime detection against machine-speed attacks. #DIVD #Zammad #CVE-2026-102489 #CVE-2026-102490 #MerlonSecurity #Sysdig #JADEPUFFER

  • Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem

    Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem

    The Spetsvuzavtomatika leak exposes a broad Russian cyber R&D program with projects for reconnaissance, credential theft, cloud-based control, Android collection, covert storage, and anonymous procurement. The material strongly suggests the institute functions as a developer of automated espionage capabilities rather than a conventional front-line intrusion group, with authentic samples linked to the sale but the original breach still unconfirmed. #Spetsvuzavtomatika #SVA2027 #Felix-23 #HAD #Putnik #Initiative-24 #Botany #Blik #Glare #Chain-24

  • GitHub Credentials Also Exposed in Datasets for AI Training

    GitHub Credentials Also Exposed in Datasets for AI Training

    Truffle Security found 543,699 still-valid credentials inside code from public GitHub repositories after analyzing The Stack v3 dataset, which was built from about 224 million repositories. The research showed exposed API keys, access tokens, database credentials, and service accounts, and recommends revoking or rotating any leaked credentials because they may already exist in forks or copies of the repository. #Truffle Security #GitHub #The Stack v3 #Hugging Face #TruffleHog

  • SLTT C2 Traffic Tied to Remus Malware Distribution Operation

    SLTT C2 Traffic Tied to Remus Malware Distribution Operation

    CIS CTI tracked Remus infostealer distribution from March to September 2026, showing how the MaaS operation uses browser-session theft, EtherHiding C2 rotation, and multiple delivery chains to spread the payload. The investigation tied Remus to Lumma Stealer lineage and highlighted activity involving ClickFix, PLYCHIP, DonutLoader, GoFlateLoader, LandUpdate808, and domains such as…

  • $100k in Crypto Drained by the Underground Operation

    0k in Crypto Drained by the Underground Operation

    Netskope Threat Labs uncovered the Underground builder, an Aotera/Tedy-based operation that injects a Vidar-class stealer into Windows processes and uses browser-session injection to drain cryptocurrency exchange accounts. The campaign rotates Cloudflare-fronted gates, abuses Chrome or Edge sessions, and has generated about $100,000 in on-chain proceeds from at least 350 to 430 victims. #Underground #Aotera #Tedy #Vidar #Binance #Cloudflare

  • Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

    Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

    Proofpoint reports that China-aligned TA419 ran credential phishing campaigns in July 2026 by impersonating economists and AI policymakers to target AI experts at US think tanks, universities, and law firms. The operation used multi-stage redirects and a customized Frameless BitB AitM kit to steal Microsoft 365 / Entra ID credentials and…

  • Warlock Ransomware Attackers Hit Water and Telecom Operators

    Warlock Ransomware Attackers Hit Water and Telecom Operators

    Longlegs, a China-nexus threat actor tracked by Symantec, is using Microsoft SharePoint vulnerabilities and the Warlock ransomware to compromise organizations across multiple regions. The campaign has hit critical infrastructure, government, and university victims, while also abusing a vulnerable driver, Visual Studio Code tunneling, and SYSVOL to disable defenses and deploy payloads at scale. #Warlock #Longlegs #Storm2603 #ToolShell #K7RKScan #SharePoint #SYSVOL

  • TIKTOUK: Tracing a WordPress Credential Collection Toolkit

    TIKTOUK: Tracing a WordPress Credential Collection Toolkit

    TIKTOUK combines WordPress probing, exposed configuration harvesting, encrypted email credential recovery, and JavaScript secret scanning through three coordinated components that report to a central hub. The campaign also operated at scale with a leaked panel showing tens of thousands of credentials and included related infrastructure such as 31.56.58.59, 193.32.162.134, and 195.178.110.209. #TIKTOUK #LevelBlue #WordPress #SendGrid #Anthropic #Bedrock #AWS

  • Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

    Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

    Researchers found 70 fake websites impersonating crypto projects such as Kraken’s xStocks, Pendle, Zama, Kinetiq, Yield Basis, and Firelight to lure visitors into clicking a bogus rewards vote. The pages lead to wallet connection prompts that can pave the way for malicious approvals or signatures that drain tokens, and they share…

  • Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

    Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

    LevelBlue THOR identified active exploitation of CVE-2026-88771 against Citrix NetScaler ADC and NetScaler Gateway, with attacker-controlled authentication data used to execute commands, retrieve payloads, and stage configuration data. The activity progressed to reverse-shell deployment, privileged account creation, and web-shell installation using infrastructure and artifacts including main.py, update_c08937.pl, and sec_monitor. #CVE-2026-88771 #CitrixNetScaler #main.py #update_c08937.pl #sec_monitor

  • Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

    Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

    Unit 42 reports possible zero-day exploitation of Citrix NetScaler devices through CVE-2026-88771 and CVE-2026-88772, with attackers using the flaws to deploy web shells and gain persistence. The activity involved infrastructure linked to fingerprinting, DTLS exploitation, and a three-stage command-injection chain, while Citrix and Palo Alto Networks observed widespread exposure and post-disclosure…

  • SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor

    SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor

    SC is a WordPress backdoor ecosystem that survives by regenerating itself across files, the database, shared memory, and scheduled tasks, making simple file deletion ineffective. Its payload hides from admin views, communicates through public Ethereum RPC gateways, and can recreate privileged access, security changes, and even checkout-skimming code on demand. #SC #WordPress #EthereumRPC

  • 2CLoader: A New Malware Loader Delivering Vidar and Remus

    2CLoader: A New Malware Loader Delivering Vidar and Remus

    Zscaler ThreatLabz tracked 2CLoader, a new Windows loader that uses extensive anti-analysis, evasion, and configuration-based execution features to deliver Vidar, Remus, and XWorm. The loader decrypts and launches payloads through multiple paths, uses HTTP-based C2 with XOR-encrypted JSON, and is associated with indicators such as aware-cr1.com, 62.60.226.185, and the threat name Win64.Loader.2CLoader. #2CLoader #Vidar #Remus #XWorm #aware-cr1.com #62.60.226.185

For the sites below, automatic FETCH cannot be performed
(i need to monitor it manual, will be delay 3-7 days)

Bellow are other reference, but for some reason i’m not fetching it automatically
(i need to review the article manually, will be delay 3-5 days)

  • cleafy.com/labs (update 1-2 months)
  • guidepointsecurity.com/blog/ > category: threat advisory
  • research.openanalysis.net
  • blog.phylum.io/tag/research/
  • shadowstackre.com/analysis/
  • mssplab.github.io
  • farghlymal.github.io
  • asec.ahnlab.com/ko/
  • blog.bushidotoken.net
  • kroll.com/en/insights/publications/cyber
  • Sentinelone.com
  • blog.lumen.com

Update

Update January, 2025

“Due to copyright reasons, starting January 2025, this site will no longer display the full content of sourced articles. Only Summaries, Key Points, MITRE Tactics for Threat Research, and selected IoCs will be provided. To read the full article, please click on the ‘source’ link to view it on the original website.”