Blogs

BlogsTELESHIM, MIXEDKEY & BINDCLOAK: Dissecting the East Asian APT’s Three-Family Toolkit Weaponizing Telegram C2 Against Middle East GovernmentsZscaler ThreatLabz exposed three undocumented malware families targeting Middle East governments. Learn how TELESHIM, MIXEDKEY, and BINDCLOAK chain together using Telegram C2,…Jul 31, 2026 · 19 min readRead →BlogsCVE-2026-56155 Anatomy: Inside the Actively Exploited AD FS Zero-Day That Grants Admin Privileges and How Ransomware Groups Are Chaining It With RCECVE-2026-56155 turns a permissive AD FS DKM container ACL into a full federated-identity compromise via Golden SAML. Learn how ransomware groups chain…Jul 27, 2026 · 17 min readRead →BlogsCVE-2026-57092 Anatomy: Hyper-V VMSwitch Use-After-Free Guest-to-Host Escape, From Low-Privileged VM Tenant to Full Hypervisor CompromiseCVE-2026-57092 is a CVSS 9.9 use-after-free in vmswitch.sys that lets an authenticated guest tenant escape to host ring-0. This teardown covers the…Jul 24, 2026 · 18 min readRead →BlogsGoSerpent Malware Internals: Reversing the Undocumented Go Implant Silently Espionaging Southeast Asian Governments Since Late 2025GoSerpent is a patient Go-based espionage implant targeting Southeast Asian governments since late 2025. This post reverses the binary internals, decrypts the…Jul 22, 2026 · 16 min readRead →BlogsSharePoint CVE-2026-50522 / CVE-2026-58644 Teardown: Pwn2Own-Demonstrated Deserialization-to-RCE and the Authentication-Bypass Chain That Makes It Pre-AuthThree CVSS 9+ SharePoint flaws from Pwn2Own Berlin - two deserialization RCEs and a JWT bypass - combine into a pre-auth kill…Jul 20, 2026 · 18 min readRead →BlogsHelloNet Exposed: Reversing the APT That Weaponized ViPNet’s Trusted Update ChannelHelloNet abused ViPNet's signed updater to sideload a modular implant chain into svchost.exe - no new service, no run key, just a…Jul 20, 2026 · 19 min readRead →BlogsCVE-2026-56190 Anatomy: Uninitialized-Resource RCE in Windows RDP – Pre-Auth Memory Corruption to Remote Code Execution Without a Single Packet of AuthenticationCVE-2026-56190 is a CVSS 9.8 pre-authentication RCE in the Windows RDP server caused by an uninitialized-resource flaw in termsrv.dll. Learn how the…Jul 20, 2026 · 18 min readRead →BlogsLegacyHive Exposed: Dissecting Chaotic Eclipse’s Unpatched Windows Registry Hive-Loading Zero-Day and the Adversarial Pattern Behind Nine Back-to-Back Uncoordinated DisclosuresLegacyHive is an unpatched Windows privilege escalation zero-day abusing a deterministic TOCTOU race in ProfSvc to redirect hive loads via Object Manager…Jul 17, 2026 · 16 min readRead →BlogsPolinRider: North Korea’s 108-Package Open-Source Supply Chain Campaign DissectedPolinRider compromised 108 packages and 1,951 GitHub repos using VS Code auto-run task hijacking, blockchain dead-drop C2, and expired-domain account takeover to…Jul 13, 2026 · 17 min readRead →BlogsUAT-7810 / LapDogs ORB Network Dissected: LONGLEASH Malware, Internet-Facing Device Compromise, and the Architecture of China’s Operational Relay Box EcosystemUAT-7810's LapDogs ORB network weaponizes unpatched Ruckus access points using LONGLEASH, a purpose-built intermediate C2 relay implant. This deep dive covers binary…Jul 12, 2026 · 18 min readRead →BlogsJADEPUFFER Dissected: Inside the World’s First Confirmed Fully-Agentic Ransomware Attack – Langflow RCE, LLM-Driven Lateral Movement, and What It Means for DefendersJADEPUFFER is the first confirmed fully-agentic ransomware attack - an LLM ran recon, credential theft, lateral movement, and encryption with no human…Jul 10, 2026 · 17 min readRead →BlogsCVE-2026-43499 “GhostLock” + IonStack Full-Chain Teardown: Futex Requeue-PI Stack Use-After-Free to Root and Container EscapeCVE-2026-43499 'GhostLock' turns a one-word logic error in Linux's PI futex code into a stack use-after-free, root escalation, and full container escape…Jul 8, 2026 · 20 min readRead →