Blogs
BlogsTELESHIM, MIXEDKEY & BINDCLOAK: Dissecting the East Asian APT’s Three-Family Toolkit Weaponizing Telegram C2 Against Middle East GovernmentsZscaler ThreatLabz exposed three undocumented malware families targeting Middle East governments. Learn how TELESHIM, MIXEDKEY, and BINDCLOAK chain together using Telegram C2,…Read →BlogsCVE-2026-56155 Anatomy: Inside the Actively Exploited AD FS Zero-Day That Grants Admin Privileges and How Ransomware Groups Are Chaining It With RCECVE-2026-56155 turns a permissive AD FS DKM container ACL into a full federated-identity compromise via Golden SAML. Learn how ransomware groups chain…Read →BlogsCVE-2026-57092 Anatomy: Hyper-V VMSwitch Use-After-Free Guest-to-Host Escape, From Low-Privileged VM Tenant to Full Hypervisor CompromiseCVE-2026-57092 is a CVSS 9.9 use-after-free in vmswitch.sys that lets an authenticated guest tenant escape to host ring-0. This teardown covers the…Read →BlogsGoSerpent Malware Internals: Reversing the Undocumented Go Implant Silently Espionaging Southeast Asian Governments Since Late 2025GoSerpent is a patient Go-based espionage implant targeting Southeast Asian governments since late 2025. This post reverses the binary internals, decrypts the…Read →BlogsSharePoint CVE-2026-50522 / CVE-2026-58644 Teardown: Pwn2Own-Demonstrated Deserialization-to-RCE and the Authentication-Bypass Chain That Makes It Pre-AuthThree CVSS 9+ SharePoint flaws from Pwn2Own Berlin - two deserialization RCEs and a JWT bypass - combine into a pre-auth kill…Read →BlogsHelloNet Exposed: Reversing the APT That Weaponized ViPNet’s Trusted Update ChannelHelloNet abused ViPNet's signed updater to sideload a modular implant chain into svchost.exe - no new service, no run key, just a…Read →BlogsCVE-2026-56190 Anatomy: Uninitialized-Resource RCE in Windows RDP – Pre-Auth Memory Corruption to Remote Code Execution Without a Single Packet of AuthenticationCVE-2026-56190 is a CVSS 9.8 pre-authentication RCE in the Windows RDP server caused by an uninitialized-resource flaw in termsrv.dll. Learn how the…Read →BlogsLegacyHive Exposed: Dissecting Chaotic Eclipse’s Unpatched Windows Registry Hive-Loading Zero-Day and the Adversarial Pattern Behind Nine Back-to-Back Uncoordinated DisclosuresLegacyHive is an unpatched Windows privilege escalation zero-day abusing a deterministic TOCTOU race in ProfSvc to redirect hive loads via Object Manager…Read →BlogsPolinRider: North Korea’s 108-Package Open-Source Supply Chain Campaign DissectedPolinRider compromised 108 packages and 1,951 GitHub repos using VS Code auto-run task hijacking, blockchain dead-drop C2, and expired-domain account takeover to…Read →BlogsUAT-7810 / LapDogs ORB Network Dissected: LONGLEASH Malware, Internet-Facing Device Compromise, and the Architecture of China’s Operational Relay Box EcosystemUAT-7810's LapDogs ORB network weaponizes unpatched Ruckus access points using LONGLEASH, a purpose-built intermediate C2 relay implant. This deep dive covers binary…Read →BlogsJADEPUFFER Dissected: Inside the World’s First Confirmed Fully-Agentic Ransomware Attack – Langflow RCE, LLM-Driven Lateral Movement, and What It Means for DefendersJADEPUFFER is the first confirmed fully-agentic ransomware attack - an LLM ran recon, credential theft, lateral movement, and encryption with no human…Read →BlogsCVE-2026-43499 “GhostLock” + IonStack Full-Chain Teardown: Futex Requeue-PI Stack Use-After-Free to Root and Container EscapeCVE-2026-43499 'GhostLock' turns a one-word logic error in Linux's PI futex code into a stack use-after-free, root escalation, and full container escape…Read →