Blogs

BlogsSilkParasite Dissected: Seven-RAT China-Nexus Toolkit, Google Drive C2 via ETag Headers, and AI-Assisted Development Against Central Asian GovernmentsBitdefender's SilkParasite disclosure reveals a seven-family China-nexus toolkit using Google Drive as C2, HTTP ETag/Cookie covert channels, HalosGate syscall evasion, and AI-assisted…Aug 28, 2026 · 19 min readRead →BlogsDeadLock Ransomware’s Blockchain C2: How Polygon Smart Contracts Replace Traditional Infrastructure and Why Takedowns No Longer WorkDeadLock ransomware replaced traditional C2 infrastructure with Polygon smart contracts, making server seizures and domain takedowns structurally obsolete. Learn the architecture, the…Aug 24, 2026 · 18 min readRead →BlogsCVE-2026-59310 and CVE-2026-59309 Teardown: How a China-Nexus APT Turned vCenter’s Log Collector Into an Unauthenticated Root ShellA China-nexus APT exploited CVE-2026-59310 within five days of disclosure, turning vCenter's syslog handler into an unauthenticated root shell across 361 victims.…Aug 21, 2026 · 17 min readRead →BlogsCVE-2026-62815 Teardown: Zero-Auth Use-After-Free in Microsoft QUIC’s msquic Stack, One Malformed UDP Packet to RCE on Every Unpatched Windows Server 2022/2025CVE-2026-62815 is a CVSS 9.8 use-after-free in Microsoft's msquic stack - one unauthenticated UDP packet can achieve RCE on unpatched Windows Server…Aug 17, 2026 · 20 min readRead →BlogsCVE-2026-68820 Anatomy: How Lazarus Group’s afd.sys Use-After-Free Race Condition Became a SYSTEM-Level Zero-Day Paired With FudModule Rootkit and ForestTiger BackdoorCVE-2026-68820 is Lazarus Group's fourth afd.sys zero-day since 2024 - a race-triggered use-after-free that escalates to SYSTEM, blinds ETW-based sensors with FudModule…Aug 14, 2026 · 18 min readRead →BlogsAPT-C-60 / SpyGlace 2026: LNK-to-mshta Execution, Developer-Platform Abuse as CDN, and How Japan’s Most-Targeted Espionage Group Turned GitHub, GitLab, and jsDelivr Into a Malware Distribution NetworkAPT-C-60's 2026 SpyGlace campaign bypasses reputation-based defenses by staging payloads on GitHub, GitLab, jsDelivr, and Codeberg. Learn how the LNK-to-mshta chain works…Aug 10, 2026 · 19 min readRead →BlogsCVE-2026-18577 Teardown: How an Incomplete N-able N-central Auth-Bypass Patch Became a God-Mode MSP Supply Chain WeaponCVE-2026-18577 exposed a critical flaw in N-able N-central: the first patch left an alternate auth bypass open, giving attackers god-mode console access…Aug 7, 2026 · 16 min readRead →BlogsAPT-C-20 / Fancy Bear’s PNG Steganography Campaign: LSB Payload Concealment, PBKDF2-Derived AES-256, and Reflective C# Loading Against Defense MinistriesAPT-C-20 (Fancy Bear) stacked LSB steganography, PBKDF2-derived AES-256-CBC, and reflective CLR loading to compromise defense ministries without writing a payload to disk.…Aug 3, 2026 · 17 min readRead →BlogsEggStreme Fileless Framework: Dissecting the China-Nexus APT Targeting Philippine Military Organizations With a Zero-Footprint ImplantEggStreme is a China-nexus, six-component fileless framework that injects a gRPC/mTLS backdoor into winlogon.exe without ever writing decrypted code to disk. Dissect…Aug 3, 2026 · 17 min readRead →BlogsCVE-2026-63077 Teardown: Weaponizing JetBrains TeamCity’s Agent Polling Protocol for Zero-Click CI/CD Pipeline TakeoverCVE-2026-63077 is a CVSS 9.8 unauthenticated deserialization flaw in JetBrains TeamCity's agent polling protocol. This teardown covers root cause, a lab exploit…Aug 3, 2026 · 18 min readRead →BlogsGolden Chickens 2026: Four New Malware Families, Modular MaaS Architecture, and Why the Most Resilient Crimeware Ecosystem Keeps Reinventing ItselfTAG-195 refactored Golden Chickens into a modular MaaS framework: four new families, WebSocket C2, and a Chrome ABE bypass. Here's the full…Jul 31, 2026 · 20 min readRead →BlogsLAUNDRY BEAR Exposed: Dissecting Russia’s Zimbra-Targeting APTLAUNDRY BEAR turned a CVSS 6.1 Zimbra stored XSS into a five-month state espionage campaign. Dissect the CVE-2025-66376 exploit chain, Ulej SOAP…Jul 31, 2026 · 19 min readRead →