Blogs

BlogsToddyCat’s Umbrij Dissected: Shadow Token via Remote Debug, OAuth Code Theft, and the DLL Side-Loading Chain Emptying Corporate Gmail InboxesToddyCat's Umbrij malware skips credential theft entirely - it hijacks the OAuth consent flow from inside your browser using headless Chrome and…Jul 6, 2026 · 22 min readRead →BlogsAnubis RaaS Deep Dive: Citrix Bleed 2, /WIPEMODE Irreversible Destruction, and the Supply Chain Credential Pipeline Feeding Its AffiliatesAnubis RaaS (formerly Sphinx) chains Citrix Bleed 2 session hijacking with a /WIPEMODE wiper and a 300 GB supply-chain credential pipeline to…Jul 3, 2026 · 25 min readRead →BlogsShadowGuard Exposed: Inside the eBPF Rootkit That Made 70 Organizations Blind to Their Own KernelShadowGuard is the eBPF rootkit behind TGR-STA-1030's compromise of 70 organizations across 37 countries. Learn exactly how it rewrites d_reclen to hide…Jul 3, 2026 · 15 min readRead →BlogsCVE-2026-50656 (RoguePlanet): Dissecting the Defender Race Condition That Hands You a SYSTEM ShellRoguePlanet (CVE-2026-50656) exploits a TOCTOU race in Microsoft Defender's remediation pipeline, using NTFS opportunistic locks and VSS timing to deterministically land a…Jul 3, 2026 · 20 min readRead →BlogsAI-Assisted Ransomware Engineering in 2026: A Red-Teamer’s Technical Dissection of the Sophos-Documented Toolkit That Used Cursor and Claude to Automate AD Discovery and EDR EvasionSophos X-Ops documented a real agentic ransomware toolkit using Claude Opus 4.5 and Cursor to automate Active Directory enumeration and iterate EDR…Jun 29, 2026 · 17 min readRead →BlogsCVE-2026-20230 Anatomy: How Cisco Unified CM’s Improper Input Validation Became an Unauthenticated File-Write-to-Root Chain Within Days of PoC DropCVE-2026-20230 chains an unauthenticated SSRF file-write in Cisco Unified CM's WebDialer into root-level JSP webshell deployment in three HTTP requests. Here's the…Jun 29, 2026 · 14 min readRead →BlogsSecret Blizzard’s Kazuar P2P Botnet: Dissecting the FSB Implant That Replaced Traditional C2 With Leaderless Mesh InfrastructureSecret Blizzard's Kazuar is no longer a simple beacon-to-C2 backdoor. The 2026 variant runs a three-process IPC mesh where most infected hosts…Jun 29, 2026 · 20 min readRead →BlogsBYOVD in 2026 Is Eating EDR Alive: A Systematic Teardown of DragonForce’s Five-Driver Kill ChainDragonForce dropped five kernel drivers and silenced Defender, SentinelOne, and Kaspersky before encrypting a single file. This teardown breaks each driver apart…Jun 28, 2026 · 16 min readRead →BlogsHotel Photo-ZIP Phishing: Anatomy of Microsoft’s Newly Disclosed Node.js Implant Targeting Hospitality Front Desks Across Europe and AsiaMicrosoft disclosed TonRAT in June 2026: a Node.js implant delivered via Calendly authentication laundering that resolves C2 through the TON blockchain. Full…Jun 28, 2026 · 17 min readRead →BlogsmacOS.Gaslight Dissected: How North Korea’s Newest Rust Implant Embeds 38 Prompt Injections to Gaslight Your AI Malware AnalystNorth Korea's macOS.Gaslight Rust implant carries 38 fabricated system messages designed to make AI triage agents abort without issuing a verdict. This…Jun 28, 2026 · 17 min readRead →BlogsCVE-2026-46331 “pedit COW”: Anatomy of the Linux Kernel Page-Cache Poisoning LPE That Spawns a Root Shell While File-Integrity Checks Stay GreenCVE-2026-46331 'pedit COW' exploits a partial copy-on-write failure in act_pedit to corrupt page-cache memory and execute a root shell - without ever…Jun 27, 2026 · 21 min readRead →BlogsMuddyWater’s Chaos Ransomware Masquerade: Dissecting the Iranian APT’s Teams-Based Intrusion Chain, Credential Harvesting, and False-Flag DeploymentMuddyWater used Chaos ransomware branding, a Microsoft Teams IT-support lure, and a trojanized WebView2 backdoor to disguise Iranian state espionage as cybercrime.…Jun 26, 2026 · 18 min readRead →