Blogs
BlogsHotel Photo-ZIP Phishing: Anatomy of Microsoft’s Newly Disclosed Node.js Implant Targeting Hospitality Front Desks Across Europe and AsiaMicrosoft disclosed TonRAT in June 2026: a Node.js implant delivered via Calendly authentication laundering that resolves C2 through the TON blockchain. Full…Read →BlogsmacOS.Gaslight Dissected: How North Korea’s Newest Rust Implant Embeds 38 Prompt Injections to Gaslight Your AI Malware AnalystNorth Korea's macOS.Gaslight Rust implant carries 38 fabricated system messages designed to make AI triage agents abort without issuing a verdict. This…Read →BlogsCVE-2026-46331 “pedit COW”: Anatomy of the Linux Kernel Page-Cache Poisoning LPE That Spawns a Root Shell While File-Integrity Checks Stay GreenCVE-2026-46331 'pedit COW' exploits a partial copy-on-write failure in act_pedit to corrupt page-cache memory and execute a root shell - without ever…Read →BlogsMuddyWater’s Chaos Ransomware Masquerade: Dissecting the Iranian APT’s Teams-Based Intrusion Chain, Credential Harvesting, and False-Flag DeploymentMuddyWater used Chaos ransomware branding, a Microsoft Teams IT-support lure, and a trojanized WebView2 backdoor to disguise Iranian state espionage as cybercrime.…Read →BlogsStrikeShark & SharkLoader Dissected: Inside the Unattributed APT Campaign Hitting Diplomats, Governments, and Software Firms Across 9 CountriesKaspersky's GReAT exposed StrikeShark, an unattributed APT campaign hitting diplomats, governments, and software firms across 9 countries. Dissect SharkLoader's four-stage loading chain,…Read →BlogsCVE-2026-42985 Deep Dive: Weaponizing the RDP Client Use-After-Free for Rogue-Server RCECVE-2026-42985 flips the RDP threat model: a rogue server exploits a use-after-free in mstscax.dll to achieve RCE on the connecting client. This…Read →BlogsCVE-2026-47291 Teardown: Inside the HTTP.sys Integer Overflow That Gives Attackers Kernel-Mode RCE on Every Unpatched Windows ServerCVE-2026-47291 is a CVSS 9.8 integer overflow in http.sys that lets unauthenticated attackers execute code in kernel mode on any Windows Server…Read →BlogsMiasma / Mini Shai-Hulud: Dissecting the Wormable npm Supply Chain Attack That Hit 32 Red Hat PackagesA stolen GitHub session cookie bypassed MFA and triggered a wormable npm supply chain attack across 32 Red Hat packages - each…Read →BlogsCVE-2026-45657 Teardown: Hunting the Wormable Windows Kernel TCP/IP Use-After-FreeCVE-2026-45657 is a CVSS 9.8 wormable use-after-free in the Windows kernel TCP/IP stack - unauthenticated, no user interaction, network-reachable. This teardown covers…Read →BlogsNightmare Eclipse vs. Microsoft: Anatomy of the Defender Zero-Day SagaOne architectural flaw in Windows Defender's privileged file-operation model spawned four exploits - BlueHammer, RedSun, UnDefend, and RoguePlanet. Three are patched. One…Read →BlogsGreenPlasma, MiniPlasma & RoguePlanet: Anatomy of 2026’s Chaotic Eclipse Windows SYSTEM Zero-DaysThree Windows LPE zero-days from the Chaotic Eclipse campaign - GreenPlasma, MiniPlasma, and RoguePlanet - exploit link-following and TOCTOU flaws in CTF,…Read →BlogsLow-Level Keylogger Architectures: A Deep Dive into Windows Input Capture MechanismsIn this deep dive, we're gonna break down different keylogger implementation techniques, how they actually work under the hood in the Windows…Read →