Blogs

BlogsHotel Photo-ZIP Phishing: Anatomy of Microsoft’s Newly Disclosed Node.js Implant Targeting Hospitality Front Desks Across Europe and AsiaMicrosoft disclosed TonRAT in June 2026: a Node.js implant delivered via Calendly authentication laundering that resolves C2 through the TON blockchain. Full…Jun 28, 2026 · 17 min readRead →BlogsmacOS.Gaslight Dissected: How North Korea’s Newest Rust Implant Embeds 38 Prompt Injections to Gaslight Your AI Malware AnalystNorth Korea's macOS.Gaslight Rust implant carries 38 fabricated system messages designed to make AI triage agents abort without issuing a verdict. This…Jun 28, 2026 · 17 min readRead →BlogsCVE-2026-46331 “pedit COW”: Anatomy of the Linux Kernel Page-Cache Poisoning LPE That Spawns a Root Shell While File-Integrity Checks Stay GreenCVE-2026-46331 'pedit COW' exploits a partial copy-on-write failure in act_pedit to corrupt page-cache memory and execute a root shell - without ever…Jun 27, 2026 · 21 min readRead →BlogsMuddyWater’s Chaos Ransomware Masquerade: Dissecting the Iranian APT’s Teams-Based Intrusion Chain, Credential Harvesting, and False-Flag DeploymentMuddyWater used Chaos ransomware branding, a Microsoft Teams IT-support lure, and a trojanized WebView2 backdoor to disguise Iranian state espionage as cybercrime.…Jun 26, 2026 · 18 min readRead →BlogsStrikeShark & SharkLoader Dissected: Inside the Unattributed APT Campaign Hitting Diplomats, Governments, and Software Firms Across 9 CountriesKaspersky's GReAT exposed StrikeShark, an unattributed APT campaign hitting diplomats, governments, and software firms across 9 countries. Dissect SharkLoader's four-stage loading chain,…Jun 25, 2026 · 19 min readRead →BlogsCVE-2026-42985 Deep Dive: Weaponizing the RDP Client Use-After-Free for Rogue-Server RCECVE-2026-42985 flips the RDP threat model: a rogue server exploits a use-after-free in mstscax.dll to achieve RCE on the connecting client. This…Jun 24, 2026 · 15 min readRead →BlogsCVE-2026-47291 Teardown: Inside the HTTP.sys Integer Overflow That Gives Attackers Kernel-Mode RCE on Every Unpatched Windows ServerCVE-2026-47291 is a CVSS 9.8 integer overflow in http.sys that lets unauthenticated attackers execute code in kernel mode on any Windows Server…Jun 23, 2026 · 20 min readRead →BlogsMiasma / Mini Shai-Hulud: Dissecting the Wormable npm Supply Chain Attack That Hit 32 Red Hat PackagesA stolen GitHub session cookie bypassed MFA and triggered a wormable npm supply chain attack across 32 Red Hat packages - each…Jun 22, 2026 · 16 min readRead →BlogsCVE-2026-45657 Teardown: Hunting the Wormable Windows Kernel TCP/IP Use-After-FreeCVE-2026-45657 is a CVSS 9.8 wormable use-after-free in the Windows kernel TCP/IP stack - unauthenticated, no user interaction, network-reachable. This teardown covers…Jun 22, 2026 · 22 min readRead →BlogsNightmare Eclipse vs. Microsoft: Anatomy of the Defender Zero-Day SagaOne architectural flaw in Windows Defender's privileged file-operation model spawned four exploits - BlueHammer, RedSun, UnDefend, and RoguePlanet. Three are patched. One…Jun 22, 2026 · 16 min readRead →BlogsGreenPlasma, MiniPlasma & RoguePlanet: Anatomy of 2026’s Chaotic Eclipse Windows SYSTEM Zero-DaysThree Windows LPE zero-days from the Chaotic Eclipse campaign - GreenPlasma, MiniPlasma, and RoguePlanet - exploit link-following and TOCTOU flaws in CTF,…Jun 20, 2026 · 18 min readRead →BlogsLow-Level Keylogger Architectures: A Deep Dive into Windows Input Capture MechanismsIn this deep dive, we're gonna break down different keylogger implementation techniques, how they actually work under the hood in the Windows…Dec 27, 2025 · 16 min readRead →