Tag index
Generated from page-level ## Tags sections. Each tag below links to the pages that currently use it.
All tags
- .NET (8)
- .NET malware (7)
- .pth (1)
- /accessv2 (1)
- /dev/kvm (1)
- 146.70.139.154 (1)
- 192.42.116.105 (1)
- 192.42.116.58 (1)
- 2FA recovery codes (1)
- 3CX (1)
- 404 TDS (1)
- 43.228.157.68 (1)
- 4sync (1)
- @marketfront (1)
- @tqm-mfe (1)
.bin(1)<all_urls>(1)- Ababil of Minab (1)
- abuse response (1)
- academic research (1)
- academic sector (1)
- Accellion (1)
- access broker (2)
- access brokers (1)
- access optionality (1)
- access token abuse (1)
- account lockout (1)
- account takeover (3)
- account-takeover (1)
- ACR Stealer (1)
- act_pedit (1)
- ACTINIUM (1)
- Active Directory (1)
- active exploitation (52)
- active probing (1)
- active threat (2)
- active-exploitation (1)
- ActiveX (1)
- actor (5)
- actors (10)
- ad blocker (1)
- ad fraud (1)
- Adaptix C2 (1)
- ADB TCP/5555 (1)
- Adblock for YouTube (1)
- ADFS (1)
- Admin API key theft (1)
- administrator account creation (2)
- Adobe ColdFusion (1)
- Adobe Commerce (1)
- Adspect (1)
- Advanced IP Scanner (1)
- Adversa AI (1)
- adversary-in-the-middle (5)
- adware (5)
- adware history (1)
- AES-128-CBC (1)
- AES-256-CTR (1)
- AES-256-GCM (2)
- AES-CTR (1)
- AES-GCM (3)
- AES-GCM C2 (1)
- affiliate hijacking (1)
- Afghanistan (3)
- Africa (2)
- agent frameworks (3)
- agent memory (1)
- agent skills (2)
- agent state (1)
- AgentBaiting (1)
- agentic AI (3)
- agentic botnets (1)
- agentic browser (1)
- agentic browsers (1)
- agentic malware (1)
- agentic ransomware (1)
- agentic threat actor (2)
- Agentjacking (1)
- AGENTPSD (2)
- AI (5)
- AI agent (1)
- AI agents (17)
- AI anti-analysis (1)
- AI application infrastructure (4)
- AI assistant credentials (2)
- AI assistants (4)
- AI brand impersonation (2)
- AI browsers (2)
- AI chatbot abuse (1)
- AI coding agents (1)
- AI credential theft (1)
- AI data exfiltration (1)
- AI developer tooling (2)
- AI framework (1)
- AI gateway (1)
- AI infrastructure (1)
- AI model encryption (1)
- AI model evaluation (1)
- AI Now Institute (1)
- AI search poisoning (1)
- AI security (1)
- AI services (1)
- AI tooling (16)
- AI vulnerability discovery (1)
- AI workflow (1)
- ai-abuse (1)
- ai-agent (1)
- AI-assisted development (2)
- AI-assisted intrusion (1)
- AI-assisted malware (3)
- AI-assisted malware development (4)
- AI-assisted phishing (1)
- AI-assisted vulnerability discovery (1)
- AI-augmented operations (2)
- AI-generated malware (1)
- AI-generated narrator (1)
- Aider (1)
- AISURU (1)
- AiTM (3)
- Albania (1)
- Amadey (1)
- Amatera Stealer (1)
- Amazon Q Developer (1)
- Amazon SES (2)
- AMOS (1)
- AMSI bypass (4)
- AmsiScanBuffer (1)
- Android (8)
- Android Accessibility Service (2)
- Android ADB (3)
- Android Debug Bridge (1)
- Android malware (2)
- Android spyware (3)
- Anthropic (1)
- anti-analysis (6)
- anti-bot (1)
- anti-forensics (2)
- Anubis ransomware (1)
- ANY.RUN (1)
- AnyDesk (1)
- Apex One (1)
- API abuse (1)
- API enumeration (1)
- API exposure (1)
- API key exposure (1)
- API keys (1)
- API-driven payloads (1)
- apintergrationpost (1)
- App-Bound Encryption bypass (1)
- AppDomainManager (1)
- AppDomainManager injection (2)
- AppleJeus (1)
- AppleScript (1)
- AppleSeed (1)
- appliance (1)
- application delivery controller (1)
- application token (1)
- APSB26-68 (1)
- APT (8)
- APT-C-08 (1)
- APT27 (1)
- APT28 (1)
- APT29 (1)
- APT32 (1)
- APT36 (2)
- APT37 (1)
- APT42 (1)
- APT43 (1)
- APT44 (2)
- APT45 (1)
- Aptos (2)
- Aquatic Panda (2)
- AquilaRAT (1)
- arbitrary code execution (1)
- arbitrary file disclosure (1)
- arbitrary file read (2)
- arbitrary file upload (1)
- arbitrary file write (3)
- arbitrary JavaScript (1)
- Arch Linux (1)
- Arctic Wolf (1)
- ArduPilot (1)
- Argo CD (1)
- ArgoCD (1)
- Arista EOS (1)
- ARL (1)
- Armageddon (1)
- ArmCorp (1)
- Armored Likho (3)
- Artifact Signing (1)
- AryStinger (1)
- AS32167 (1)
- Asia targeting (1)
- ASLR bypass (1)
- ASNs (1)
- ASP.NET (2)
- ASP.NET machineKey (1)
- ASPX web shells (2)
- Astro (1)
- ASUS AiCloud routers (1)
- ASUS router (1)
- AsyncAPI (1)
- AsyncRAT (3)
- Atlas RAT (1)
- Atomic Stealer (1)
- AUDIOFIX (2)
- audit logging (1)
- AUR (1)
- authenticated RCE (1)
- authenticated remote code execution (1)
- authentication bypass (15)
- authentication laundering (1)
- authentication stack (2)
- authentication-coercion (1)
- Authenticode impersonation (1)
- authorization bypass (1)
- auto-execution (1)
- AUTODYN (1)
- AutoGen Studio (1)
- AutoHotKey (1)
- AutoJack (1)
- autonomous agents (2)
- autonomous scanning (1)
- Avalon (2)
- AWS (6)
- AWS CloudTrail (1)
- AWS S3 (2)
- AWS Secrets Manager (1)
- axios (1)
- Azure (3)
- Azure CLI (1)
- Azure DevOps (1)
- Azure Storage (1)
- Backblaze (1)
- backdoor (16)
- Backdoor.Mistic (1)
- Backstage (1)
- backup disruption (1)
- backup recovery keys (1)
- backup targeting (1)
- backups (1)
- Bad Epoll (1)
- BadBlocker (1)
- Badbox 2.0 (1)
- Balbooa Forms (1)
- Balochistan Police (1)
- Banana RAT (1)
- bandcampro (1)
- banking (1)
- banking malware (3)
- banking trojan (3)
- Barracuda (1)
- Base64 (1)
- BaseZipInstaller (1)
- Bash Uploader (1)
- batch loader (1)
- BCU key (1)
- Beast ransomware (1)
- BeaverTail (1)
- Bedrock (1)
- behavioral integrity verification (1)
- Behinder (1)
- Belarus (2)
- BELQI (1)
- BeyondTrust (1)
- Binance Smart Chain (1)
- binary execution (1)
- BinaryFormatter (1)
- BINDCLOAK (3)
- binding.gyp (2)
- biometric records (1)
- BIOPASS RAT (1)
- BioShocking (1)
- BirdCall (1)
- Bitbucket (1)
- Bitcoin (1)
- BitMiner (1)
- bitsadmin (1)
- Bitter (1)
- Bitwarden (1)
- BKA (1)
- BlackFile (1)
- Blackpoint Cyber (6)
- Bleacher Report (1)
- blockchain C2 (4)
- blockchain dead drop (3)
- blockchain RPC (1)
- blockchain-dead-drop (1)
- Blogger abuse (1)
- blogspot staging (1)
- BLUEBEAM (1)
- botnet (10)
- botnet framework (1)
- Braintree (1)
- branch-compromise (1)
- branch-name-injection (1)
- brand impersonation (3)
- brand-impersonation (1)
- Brazil (4)
- Brazilian banking malware (1)
- BreachForums (1)
- Breeze Cache Cleaner (1)
- BRICKSTORM (2)
- Broadcom (2)
- browser assembly (1)
- browser automation (1)
- browser cookie theft (1)
- browser credential theft (22)
- browser data theft (1)
- browser extension (9)
- browser extension loader (1)
- browser hijacking (2)
- browser malware (1)
- browser security (2)
- browser session abuse (2)
- browser session risk (3)
- browser zero-day (1)
- browser-credential-theft (1)
- browser-extensions (2)
- browser-resident malware (1)
- browser-security (1)
- browser-session risk (1)
- browsing history (1)
- brute-force credentials (1)
- BSC (1)
- BTMOB (1)
- bucket hijacking (1)
- bucket squatting (1)
- build-time compromise (1)
- building automation (1)
- bulletproof hosting (1)
- Bun (3)
- Bun runtime abuse (1)
- business email compromise (2)
- BusySnake Stealer (3)
- Bybit (1)
- BYOVD (3)
- bypass2fa (1)
- C# (1)
- C++ (2)
- C++/CLI (1)
- C0XMO (1)
- C2 (12)
- C2 framework (2)
- C2 tasking (1)
- CageFS (1)
- calendar dead drop (1)
- calendar invitation (1)
- Calendly abuse (1)
- call forwarding (2)
- Cambodia (1)
- campaign (2)
- Canada (1)
- CANFAIL (1)
- CAP_NET_ADMIN (2)
- Casbaneiro (1)
- CastleStealer (1)
- Catalyst SD-WAN Manager (1)
- Catcher (1)
- Cav3rn (1)
- Cavern (2)
- Cavern Manticore (3)
- CCleaner (1)
- CDN (1)
- CERT-In (1)
- CERT/CC (1)
- Certbot (1)
- certificate pinning (1)
- certificate theft (1)
- certutil (1)
- CFIDE (1)
- ChaCha20 (1)
- ChainVeil (1)
- ChatGPT (1)
- chattr (1)
- Chatty Spider (1)
- CHAVECLOAK (1)
- Check Point (2)
- Check Point Research (1)
- Checkmarx (2)
- checkpointers (1)
- China (2)
- China-linked (8)
- China-nexus (13)
- China-speaking ecosystem (1)
- Chinese-language cybercrime (1)
- Chinese-language fraud ecosystem (1)
- Chinese-speaking (4)
- Chinese-speaking cybercrime (1)
- Chinese-speaking operator (1)
- Chisel (3)
- ChocoPoC (1)
- Chrome (2)
- Chrome App-Bound Encryption (1)
- Chrome DevTools Protocol (1)
- Chrome extension (2)
- Chrome renderer sandbox (1)
- Chrome Web Store (5)
- chrome_settings_overrides (1)
- ChromElevator (1)
- Chromium (5)
- Chromium extension (1)
- CI secrets (1)
- CI-CD (2)
- CI/CD (37)
- CI/CD abuse (1)
- CircleCI (1)
- CIS (2)
- CISA (3)
- CISA KEV (25)
- Cisco (3)
- Cisco IOS (1)
- Cisco IOS 12.4 (1)
- Cisco Nexus (1)
- Cisco Talos (2)
- Cisco Unified CM (1)
- Cisco Unified Communications Manager (1)
- citizen portal compromise (1)
- Citrine Sleet (1)
- Citrix (2)
- Citrix NetScaler (1)
- CitrixBleed (1)
- CitrixBleed 2 (1)
- CKEditor file manager (1)
- CL-CRI-1089 (1)
- CL-CRI-1147 (1)
- CL-STA-1062 (3)
- CL-STA-1114 (3)
- Claude (2)
- Claude Code (6)
- Claude for Chrome (1)
- Clever Cloud (1)
- ClickFix (17)
- ClickOnce (1)
- ClickUp (1)
- client-side exploitation (1)
- Cline (1)
- clipboard hijacker (1)
- clipboard injection (1)
- clipboard manipulation (2)
- clipboard stealer (1)
- clipboard theft (6)
- clipper (2)
- Cloaked Ursa (1)
- cloaking (2)
- cloud (6)
- cloud C2 (2)
- cloud compromise (1)
- cloud credential hunting (1)
- cloud credential risk (1)
- cloud credential theft (8)
- cloud credentials (3)
- Cloud Files Mini Filter Driver (1)
- Cloud Filter driver (1)
- cloud IAM (1)
- cloud identity (2)
- cloud identity abuse (1)
- cloud infrastructure (1)
- cloud logging (1)
- cloud secrets (4)
- cloud security (3)
- cloud service abuse (4)
- cloud storage (1)
- cloud storage exfiltration (1)
- cloud transcoding (1)
- Cloudflare (4)
- Cloudflare Tunnel (3)
- Cloudflare tunnels (2)
- Cloudflare Turnstile (1)
- Cloudflare Workers (5)
- cloudflared (1)
- CloudLinux (1)
- cluster compromise (1)
- CMS (7)
- CMS exploitation (1)
- Cobalt Strike (6)
- code execution (1)
- code injection (1)
- code sandbox scraping (1)
- code signing (3)
- Codecov (1)
- codemado (1)
- CodeQL (1)
- Codex (2)
- Codex CLI (1)
- coding agents (1)
- coding challenge (1)
- Coinbase (1)
- ColdFusion (1)
- collaboration platforms (1)
- collaboration-tool phishing (1)
- COM-hijacking (1)
- ComfyUI (1)
- command and control (2)
- command execution (7)
- command injection (7)
- command-execution (1)
- command-injection (1)
- commercial messaging applications (1)
- commit farming (1)
- communications infrastructure (1)
- Composer (5)
- compromised accounts (2)
- compromised credentials (1)
- compromised infrastructure (1)
- compromised websites (2)
- compromised WordPress (2)
- computer vision (1)
- Conditional Access (1)
- configuration exposure (1)
- configuration theft (2)
- confused deputy (3)
- ConfuserEx (2)
- conhost (1)
- connected apps (1)
- ConnectWise (1)
- ConnectWise ScreenConnect (1)
- consumer devices (1)
- consumer IoT (1)
- Contagious Interview (4)
- container (1)
- container escape (5)
- container escape pre-check (1)
- content compliance rules (1)
- context flooding (1)
- Continue (1)
- continuous visibility (1)
- control flow flattening (3)
- control panel compromise (1)
- control plane (1)
- cookie theft (4)
- Copilot (1)
- Copilot CLI (1)
- Copy-on-Write (1)
- Corepack (1)
- Coruna (1)
- counterfeit software (1)
- COW (1)
- COWARDDUCK (1)
- CPaaS (1)
- cPanel (4)
- CPUID (1)
- cracked software (1)
- CrackMapExec (1)
- CrashStealer (1)
- Crates.io (1)
- credential attacks (3)
- credential dumping (1)
- credential exposure (3)
- credential harvesting (4)
- credential spraying (1)
- credential stuffing (2)
- credential theft (58)
- credential-theft (52)
- credit card theft (1)
- criminal infrastructure (1)
- critical infrastructure (5)
- critical-infrastructure (2)
- CRM data theft (1)
- cron (2)
- cron persistence (3)
- cross-platform (1)
- cross-platform malware (1)
- cross-project access (1)
- cross-site request forgery (1)
- cross-tenant isolation (1)
- CrownX (2)
- Crucio (1)
- crypto (2)
- crypto clipper (1)
- crypto wallets (2)
- crypto-wallets (1)
- cryptocurrency (13)
- cryptocurrency scam (1)
- cryptocurrency theft (10)
- cryptocurrency wallet theft (5)
- cryptocurrency wallets (4)
- cryptojacking (1)
- cryptominer (2)
- cryptomining (1)
- CSRF (1)
- CSRF token theft (1)
- Curious Serpens (1)
- CURP (1)
- Cursor (4)
- Curve25519 (1)
- custody APIs (1)
- CVE-2008-4128 (1)
- CVE-2013-3307 (1)
- CVE-2016-5681 (1)
- CVE-2020-17103 (1)
- CVE-2020-22653 (1)
- CVE-2020-22658 (1)
- CVE-2021-27137 (1)
- CVE-2021-29441 (1)
- CVE-2022-0492 (1)
- CVE-2023-24932 (1)
- CVE-2023-25717 (1)
- CVE-2023-2868 (1)
- CVE-2023-4346 (1)
- CVE-2023-4966 (1)
- CVE-2024-1708 (1)
- CVE-2024-1709 (1)
- CVE-2024-20399 (1)
- CVE-2024-21182 (1)
- CVE-2024-3094 (2)
- CVE-2024-42009 (1)
- CVE-2025-11371 (1)
- CVE-2025-11837 (1)
- CVE-2025-24054 (1)
- CVE-2025-2492 (1)
- CVE-2025-3248 (2)
- CVE-2025-32975 (1)
- CVE-2025-33053 (1)
- CVE-2025-34291 (1)
- CVE-2025-40947 (1)
- CVE-2025-40948 (1)
- CVE-2025-40949 (1)
- CVE-2025-48595 (1)
- CVE-2025-49113 (1)
- CVE-2025-49704 (1)
- CVE-2025-49706 (1)
- CVE-2025-5777 (1)
- CVE-2025-66376 (3)
- CVE-2025-67038 (1)
- CVE-2025-68686 (1)
- CVE-2025-8088 (4)
- CVE-2026-0257 (1)
- CVE-2026-0770 (1)
- CVE-2026-10520 (1)
- CVE-2026-10523 (1)
- CVE-2026-11405 (1)
- CVE-2026-11645 (1)
- CVE-2026-12569 (1)
- CVE-2026-12957 (1)
- CVE-2026-12958 (1)
- CVE-2026-15409 (1)
- CVE-2026-15410 (1)
- CVE-2026-16232 (1)
- CVE-2026-16723 (1)
- CVE-2026-20127 (1)
- CVE-2026-20182 (1)
- CVE-2026-20230 (1)
- CVE-2026-20245 (1)
- CVE-2026-20253 (1)
- CVE-2026-20262 (1)
- CVE-2026-20896 (1)
- CVE-2026-21513 (1)
- CVE-2026-23111 (1)
- CVE-2026-26980 (1)
- CVE-2026-2699 (1)
- CVE-2026-2701 (1)
- CVE-2026-28318 (1)
- CVE-2026-29059 (1)
- CVE-2026-3300 (1)
- CVE-2026-33017 (2)
- CVE-2026-33691 (1)
- CVE-2026-34908 (1)
- CVE-2026-34909 (1)
- CVE-2026-34910 (1)
- CVE-2026-34926 (1)
- CVE-2026-35273 (2)
- CVE-2026-35616 (1)
- CVE-2026-39987 (1)
- CVE-2026-40138 (1)
- CVE-2026-40139 (1)
- CVE-2026-40140 (1)
- CVE-2026-40141 (1)
- CVE-2026-4020 (1)
- CVE-2026-41091 (1)
- CVE-2026-41940 (2)
- CVE-2026-42271 (1)
- CVE-2026-42533 (1)
- CVE-2026-43074 (1)
- CVE-2026-43284 (1)
- CVE-2026-43499 (1)
- CVE-2026-43500 (1)
- CVE-2026-43503 (1)
- CVE-2026-44338 (1)
- CVE-2026-45247 (1)
- CVE-2026-45498 (1)
- CVE-2026-45659 (1)
- CVE-2026-46242 (1)
- CVE-2026-46300 (1)
- CVE-2026-46331 (1)
- CVE-2026-46817 (1)
- CVE-2026-48172 (1)
- CVE-2026-48276 (1)
- CVE-2026-48277 (1)
- CVE-2026-48281 (1)
- CVE-2026-48282 (1)
- CVE-2026-48283 (1)
- CVE-2026-48285 (1)
- CVE-2026-48307 (1)
- CVE-2026-48313 (1)
- CVE-2026-48314 (1)
- CVE-2026-48315 (1)
- CVE-2026-48316 (1)
- CVE-2026-48558 (3)
- CVE-2026-48907 (2)
- CVE-2026-48908 (1)
- CVE-2026-48939 (1)
- CVE-2026-50522 (1)
- CVE-2026-50751 (1)
- CVE-2026-50752 (1)
- CVE-2026-53359 (1)
- CVE-2026-5426 (1)
- CVE-2026-54420 (1)
- CVE-2026-55255 (1)
- CVE-2026-56290 (1)
- CVE-2026-56291 (1)
- CVE-2026-60137 (1)
- CVE-2026-62144 (1)
- CVE-2026-62145 (1)
- CVE-2026-63030 (1)
- CVE-2026-6682 (1)
- CVE-2026-6683 (1)
- CVE-2026-6684 (1)
- CVE-2026-6685 (1)
- CVE-2026-6686 (1)
- CVE-2026-6687 (1)
- CVE-2026-6688 (1)
- CVE-2026-6875 (1)
- CVE-2026-7473 (1)
- CVE-2026-8037 (1)
- CVE-2026-8451 (1)
- CVE-2026-8461 (1)
- CVE-2026-8732 (1)
- CVE-2026-9082 (1)
- CWE-22 (1)
- CWE-352 (1)
- CWE-502 (1)
- CWE-77 (1)
- CWE-78 (1)
- CWE-829 (1)
- cyber-espionage (1)
- CyberAv3ngers (1)
- cybercrime (13)
- cybercrime ecosystem (2)
- cyberespionage (2)
- Cython (1)
- Czech Republic (1)
- D-Link (1)
- dangling resources (1)
- data exfiltration (9)
- data exposure (1)
- data extortion (2)
- data leak site (2)
- data theft (6)
- data-exfiltration (1)
- database extortion (1)
- Datadog Security Labs (1)
- dataset processing (1)
- DAYLIGHT (1)
- DCloud (1)
- DCloud Uni-App (1)
- DcRAT (1)
- DD-WRT (1)
- DDNS (1)
- DDoS (6)
- DDoS botnet (1)
- DDoS-for-hire (2)
- dead drop (1)
- dead drop resolver (4)
- dead-drop resolver (1)
- Debian (1)
- DEBULL (1)
- declarativeNetRequest (1)
- DeepAudit (1)
- DeepSeek (3)
- Defender Advanced Hunting (1)
- Defender evasion (2)
- Defender exclusion (1)
- defense (3)
- defense evasion (6)
- defense targeting (1)
- defense-evasion (1)
- DeFi (4)
- delayed execution (2)
- denial of service (5)
- Deno (2)
- dependency confusion (3)
- deployment_status (1)
- deserialization (6)
- destructive malware (3)
- destructive operations (3)
- detection engineering (1)
- DEV-0206 (1)
- developer credential theft (2)
- developer credentials (1)
- developer endpoints (2)
- Developer ID abuse (1)
- developer identity (1)
- developer infrastructure (1)
- developer machines (9)
- developer mode (1)
- developer platform (1)
- developer targeting (7)
- developer tooling (6)
- developer workstations (3)
- developer-machine-fleet (1)
- developer-targeting (19)
- developer-tools (1)
- developer-workstations (2)
- device lockout (1)
- device registration (1)
- device-code phishing (3)
- DevOps (1)
- DevTools (1)
- DEWMODE (1)
- DGA (1)
- DIAMONDBACK (2)
- Digital Knowledge (1)
- digital wallets (1)
- DigitalOcean (1)
- Dindoor (1)
- diplomatic targeting (3)
- DirtyClone (1)
- DirtyFrag (1)
- Discord (2)
- discovery (1)
- disk wiping (1)
- distributed scanning (1)
- Djinn Stealer (3)
- DLL side-loading (6)
- DLL sideloading (19)
- DNS C2 (2)
- DNS callback (1)
- DNS dead drop (1)
- DNS exfiltration (2)
- DNS threat intelligence (1)
- DNS tunneling (3)
- DNS-over-HTTPS (1)
- Docker (3)
- Docker credentials (1)
- Docker images (1)
- Docker socket (2)
- document collection (1)
- document exfiltration (1)
- document theft (4)
- DOGLEASH (1)
- domain squatting (1)
- domestic espionage (1)
- dormant accounts (2)
- DotNetNuke (1)
- DotnetTool (1)
- double extortion (1)
- downgrade risk (1)
- downloader (1)
- DPAPI (3)
- DPAPILoader (1)
- DPRK (5)
- driver loading (1)
- DroneLink (1)
- Dropbear (1)
- Dropbox (2)
- dropper (1)
- Drupal (1)
- duckdns (1)
- Dutch Police (1)
- DWAgent (1)
- dynamic DNS (1)
- dynamic obfuscation (1)
- Dynu (1)
- e-commerce (1)
- Eagle Werewolf (2)
- Earth Lusca (2)
- East Asia (1)
- East Asia-linked (1)
- eBPF (3)
- Eclipse (1)
- Ed25519 (1)
- edge appliance (13)
- edge appliances (2)
- edge application server (1)
- edge device (3)
- edge devices (4)
- edge exploitation (1)
- Edge extension (1)
- edge service (2)
- edge services (1)
- editor profile import (1)
- EDR evasion (2)
- EDR killer (2)
- EDS5000 (1)
- education (2)
- Egnyte (1)
- EKZ Infostealer (1)
- Elastic Security Labs (5)
- Elasticsearch (1)
- electric power sector (2)
- Electron (1)
- email (1)
- email exfiltration (2)
- email gateway (1)
- email infrastructure abuse (1)
- email theft (3)
- embedded systems (1)
- Emerald Sleet (1)
- ENCFORGE (2)
- encrypted C2 (3)
- endpoint management (1)
- endpoint management abuse (1)
- endpoint response (1)
- endpoint-detection (1)
- endpoint-security (2)
- EndpointDlp.dll (1)
- energy sector (5)
- energy-sector (1)
- engineering (1)
- engineering software (1)
- enterprise application (2)
- enterprise application exploitation (1)
- enterprise applications (1)
- Entra ID (3)
- Environment Management Hub (1)
- environment variable theft (2)
- environment variables (1)
- environmental keying (4)
- epoll (1)
- Epsilon Stealer (1)
- ERP (1)
- eSentire TRU (1)
- ESG (1)
- espionage (52)
- Espressif ESP-IDF (1)
- ESXi (1)
- Ethereum (1)
- EtherHiding (4)
- ETW bypass (1)
- ETW patching (1)
- ETW tampering (1)
- Eurojust (1)
- Europe (3)
- Europe targeting (1)
- European Union (1)
- Europol (2)
- evasion (1)
- event log clearing (1)
- eventpoll (1)
- Everest Forms Pro (1)
- evidence quality (1)
- Evil Corp (1)
- EvilAI (1)
- Evilginx (1)
- excessive agency (1)
- exec_globals (1)
- exFAT (1)
- exfiltration (4)
- exploit chain (1)
- exploit-development (1)
- exploit-kit (1)
- Exploit.in (1)
- exploitation (15)
- exploitation attempts (1)
- ExploitGym (1)
- exposed attacker infrastructure (1)
- extension supply-chain (2)
- external federation (1)
- extortion (7)
- F5 (1)
- F5 BIG-IP (1)
- Factory-v3 (1)
- fake app store (1)
- fake CAPTCHA (5)
- fake certificate (1)
- fake crypto exchange (1)
- fake dating lures (1)
- fake gambling (1)
- fake installers (1)
- fake login screen (1)
- fake Microsoft Store (1)
- fake plugin (1)
- fake PoC (2)
- fake ransomware (1)
- fake recruiting (2)
- fake reputation (1)
- fake update (3)
- FakeCaptcha (1)
- FakeGit (1)
- Fakeset (1)
- faketivism (1)
- FakeUpdates (1)
- FallSpy (1)
- FAMOUS CHOLLIMA (2)
- Famous Chollima (1)
- Fancy Bear (1)
- Fast16 (1)
- FastAPI (1)
- FastCGI (1)
- Fastjson (1)
- fat JAR (1)
- FAT32 (1)
- FatFs (1)
- FBI (2)
- FFmpeg (1)
- FIDO2 (1)
- FIFA (1)
- file encryption (1)
- file exfiltration (1)
- file inflation (1)
- file sharing (1)
- file theft (1)
- File Transmission (1)
- file upload path traversal (1)
- file-system filter (1)
- FileFiend (1)
- FILEIO (1)
- fileless execution (3)
- fileless malware (1)
- filemanager (1)
- filename-injection (1)
- filesystem parser (1)
- finance (2)
- financial fraud (4)
- financial sector (5)
- financial services (3)
- financial theft (3)
- financially motivated (1)
- FireAnt MetaKit (1)
- Firefox Add-ons (1)
- Firefox WebDriver BiDi (1)
- firewall (1)
- firewall management (1)
- firmware (1)
- firmware update (1)
- FishMonger (1)
- FlexPLM (1)
- FlockWiper (1)
- flow execution (1)
- Flowerbed (3)
- FLUIDLEECH (1)
- Flutter (1)
- FlutterShell (1)
- FOFA (1)
- folderOpen (1)
- foreign affairs targeting (1)
- foreign policy targeting (1)
- Forest Blizzard (1)
- Forg365 (1)
- ForgCookie (1)
- Forgejo (1)
- FortiClient EMS (1)
- FortiGate (2)
- Fortinet (4)
- FortiOS (2)
- FortiSandbox (1)
- Fox Tempest (2)
- fraud (2)
- FREAKYPOLL (1)
- FreeBSD (2)
- Freedom365 (1)
- freeware impersonation (1)
- Friendly Fire (1)
- FSB (4)
- FSB Center 16 (2)
- fscan (1)
- FTA (1)
- ftp.exe (1)
- Full Disk Access social engineering (1)
- Funnull (1)
- futex PI (1)
- Gafgyt (1)
- GaiaOS WebUI (1)
- Gamaredon (3)
- Gamaredon collaboration (1)
- gambling (1)
- gambling industry targeting (1)
- game cheats (1)
- GammaLoad (1)
- GammaPhish (1)
- GammaSteel (1)
- GammaWorm (1)
- Garble (2)
- Gardener (1)
- Gatekeeper bypass (1)
- GCS (1)
- Gemini CLI (1)
- GentleKiller (1)
- Germany (1)
- GHETTOVIBE (1)
- Ghost (2)
- ghost accounts (1)
- Ghost CMS (1)
- Ghost Networks (1)
- GhostLock (1)
- GHSA-6rmh-7xcm-cpxj (1)
- GHSA-6v3r-4p5c-mrp5 (1)
- GHSA-qrpv-q767-xqq2 (1)
- GHSA-xhcr-j4j9-3gh7 (1)
- GIFTEDCROOK (1)
- Git (1)
- git.exe (1)
- Gitea (1)
- GitHub (20)
- GitHub abuse (3)
- GitHub Actions (24)
- GitHub API (1)
- GitHub App (1)
- GitHub CLI (1)
- GitHub dead drop (1)
- GitHub issue spam (1)
- GitHub OAuth (1)
- GitHub Pages abuse (2)
- GitHub payload delivery (1)
- GitHub release assets (1)
- GitHub Security Advisories (2)
- GitHub tokens (2)
- GitHub-hosted runners (1)
- GitLab (2)
- gitleaks (1)
- GitOps (1)
- Gleaming Pisces (1)
- gleeze.com (1)
- GlobalProtect (1)
- Gmail (4)
- Go (5)
- Go loader (1)
- Go malware (3)
- Go modules (2)
- Go2Tunnel (1)
- GodDamn ransomware (1)
- Godzilla (1)
- GoEdge (1)
- GoFile (1)
- Golang (2)
- Golang malware (1)
- GOLD PRELUDE (1)
- Google Ads (1)
- Google Analytics telemetry (1)
- Google API (3)
- Google Calendar (1)
- Google Chrome (1)
- Google Cloud (1)
- Google Cloud Logging (1)
- Google Cloud Storage (1)
- Google credential theft (1)
- Google Docs (1)
- Google Drive (1)
- Google Notes (1)
- Google Play (1)
- Google Play Protect (1)
- Google redirect abuse (1)
- Google Sheets (1)
- Google Stitch (1)
- Google Threat Intelligence Group (2)
- Google Workspace (1)
- Goose (1)
- GoSerpent (1)
- government (5)
- government targeting (16)
- government-impersonation (1)
- GPT (1)
- GPT-5.6 Sol (1)
- Gradio (1)
- Grandoreiro (2)
- granular access tokens (1)
- GraphSpy (1)
- Gravity SMTP (1)
- GRE (1)
- GREYVIBE (1)
- group (4)
- groups (15)
- gRPC (1)
- gRPC C2 (2)
- GRU (2)
- gs-netcat (1)
- GS-Netcat (1)
- Gshell (1)
- GTIG (2)
- GUE (1)
- guest-to-host escape (1)
- Guildma (1)
- hack-and-leak (2)
- HackIndex (1)
- hacktivist persona (1)
- Hades (2)
- Hajime (1)
- hallucination (1)
- HalluSquatting (1)
- Handala (1)
- HappyDoor (1)
- HAR files (1)
- hard-coded secrets (1)
- HarmonyLib (1)
- HashiCorp Vault (1)
- HavocKiller (1)
- headless browser (2)
- healthcare (2)
- heap buffer overflow (1)
- heap pointer disclosure (1)
- HelloBackdoor (1)
- HelloCleaner (1)
- HelloDoor (1)
- HelloExecutor (1)
- HelloInjector (1)
- HelloNet (1)
- HelloProxy (1)
- HellsGate (1)
- Helm (1)
- Hermes Agent (1)
- HexKiller (1)
- hidden backdoor (1)
- hidden instructions (1)
- hidden service (1)
- high explosives (1)
- higher education (2)
- HOLLOWGRAPH (1)
- Honduras (2)
- HONESTCUE (1)
- Hong Kong infrastructure (1)
- hospitality targeting (1)
- Host Radar (1)
- host surveillance (1)
- hosting control plane (1)
- hosting provider (1)
- hosting providers (1)
- hotel targeting (1)
- Howling Scorpius (1)
- HPC (1)
- HR lures (1)
- HTA (5)
- HTML comments (1)
- HTML email (1)
- HTML smuggling (1)
- HTTP C2 (1)
- HTTP/2 (1)
- HttpMalice (1)
- HTTPS C2 (1)
- HTTPS exfiltration (1)
- HTTPSpy (1)
- Hugging Face (3)
- Hunt.io (4)
- Huntress (1)
- Hyadina (1)
- hybrid threat actor (1)
- hydropower (2)
- Hydropower Cooperation Project Proposal.zip (1)
- hypervisor escape (1)
- Hyunwoo Kim (1)
- I-SOON (2)
- iCagenda (1)
- ICE (1)
- ICONICSTEALER (1)
- ICS (3)
- IDE extension (1)
- IDE plugins (1)
- ide.cfm (1)
- identity (3)
- identity attacks (1)
- identity compromise (1)
- identity infrastructure (1)
- identity security (1)
- identity-first intrusion (1)
- IDEs (2)
- IFEO persistence (1)
- IIOP (1)
- IIS (1)
- IKEv1 (1)
- image recognition (1)
- iMessage (1)
- Impacket (2)
- impersonation (1)
- implant (1)
- import-time execution (4)
- improper privilege management (1)
- in-memory DLL loading (1)
- in-memory plugins (1)
- incident response (25)
- incident-response (1)
- IndexedDB (1)
- India (3)
- India-nexus (1)
- Indian government (1)
- indirect prompt injection (6)
- indirect syscalls (1)
- Indonesia (1)
- industrial control (1)
- industrial control systems (2)
- industrial targeting (1)
- INFINITERED (1)
- Infoblox Threat Intel (1)
- information disclosure (2)
- infostealer (24)
- InfoTeCS (1)
- infrastructure (5)
- infrastructure disruption (3)
- initial access broker (2)
- initial-access (3)
- Injective Labs (1)
- input capture (1)
- install-time execution (4)
- install-time-execution (1)
- install.res.1033.dll (1)
- Integration Broker (1)
- Intercolo (1)
- internet-facing admin surface (1)
- internet-facing appliance (1)
- internet-facing applications (1)
- investment scam (1)
- InvisibleFerret (1)
- iOS (1)
- IoT (4)
- IoT botnet (5)
- IP cameras (1)
- IP-in-IP (1)
- IPFS (1)
- IPsec (1)
- IPv6 (2)
- ipynbdiff (1)
- Iran (8)
- Iran-nexus (1)
- IRGC (1)
- IronWorm (1)
- ischhfd83 (1)
- Island Security Research (2)
- ISO image (2)
- Israel (4)
- IT providers (1)
- Italian foreign-policy targeting (1)
- Italy targeting (1)
- Ivanti Sentry (1)
- JADEPUFFER (2)
- Jamf Threat Labs (2)
- Januscape (1)
- Japan (1)
- JARLEASH (1)
- Java (1)
- Java malware (1)
- JavaScript (15)
- JavaScript bridge (1)
- JavaScript execution (1)
- JavaScript injection (2)
- JavaScript loader (1)
- JavaScript malware (2)
- JavaScript masquerading (1)
- JavaScript tampering (1)
- JavaScriptCore (1)
- JCE (1)
- JDY (1)
- Jellyfin (1)
- Jenkins (1)
- JetBrains (2)
- JetBrains Marketplace (1)
- JetStream (1)
- JFrog (3)
- JFrog Security Research (3)
- JINX-0164 (2)
- joblib (1)
- Joomla (3)
- Joomla Content Editor (1)
- Joomla JCE (1)
- Joomlack (1)
- JoomShaper (1)
- journalists (1)
- JSCoreRunner (1)
- jscrambler (1)
- Jscrambler (1)
- JScript (1)
- JSON (1)
- JSON:API (1)
- JSONKeeper (1)
- JSONPing (1)
- JSP web shell (1)
- JuicyPotato (2)
- Jupyter Notebook (1)
- JustWatch (1)
- JXA downloader (1)
- K1MORPHER (2)
- Kairos (1)
- Kaitori (1)
- Kali365 (1)
- Kaspersky (2)
- Kaspersky GReAT (3)
- Kaspersky Securelist (2)
- Kazakhstan (1)
- KAZUAR (2)
- KAZUAR overlap (1)
- Keitaro (1)
- Keksec (1)
- Kemp LoadMaster (1)
- kernel driver (3)
- kernel instrumentation (1)
- kernelCTF (2)
- KEV (3)
- Keychain theft (1)
- keychain theft (2)
- KeyHunter (1)
- keylogger (4)
- keylogging (1)
- Kimsuky (1)
- Klue (1)
- KnowledgeDeliver (1)
- KNUCKLEBALL (1)
- KNX (1)
- KNX Association (1)
- KNX Protocol (1)
- KongTuke (1)
- KORKERDS (1)
- Kratos (1)
- Kubernetes (6)
- KV-botnet (1)
- KVM (1)
- KVM escape (1)
- kvmCTF (1)
- L2TP/IPSec (1)
- LA Metro (1)
- LabubaPanel (1)
- LabubaRAT (1)
- LangChain (2)
- Langflow (8)
- LangFlow (1)
- LangGraph (1)
- Language Servers for AWS (1)
- Lantronix (1)
- LapDogs (1)
- Laravel (2)
- Laravel deserialization (1)
- lateral movement (5)
- lateral-movement (1)
- Latin America (2)
- LaunchAgent (3)
- launchctl (1)
- LAUNDRY BEAR (3)
- law enforcement (2)
- law enforcement targeting (1)
- law-enforcement-disruption (1)
- LayerX (1)
- Lazarus (5)
- LD_PRELOAD (2)
- LDAP (1)
- leaked credentials (1)
- LEASHTEST (1)
- least privilege (2)
- Ledger (1)
- legacy botnet hijacking (1)
- legacy infrastructure (1)
- legacy software (1)
- legal sector (1)
- LegionRelay (1)
- Leo Platform (1)
- Level RMM (1)
- LevelBlue (1)
- Lexfo (1)
- libcurl (1)
- liblzma (1)
- libp2p (1)
- libpeconv (1)
- lifecycle hooks (1)
- lifecycle-hooks (1)
- Lightning Shared Scooter Co. (1)
- LinkedIn (2)
- Linksys (1)
- Linux (24)
- Linux kernel (5)
- Linux malware (2)
- Linux networking devices (1)
- LiteLLM (3)
- LiteSpeed (2)
- living off the land (1)
- living-off-the-land (1)
- living-off-the-land binaries (1)
- LLM (4)
- LLM security (1)
- LLM-assisted malware (3)
- LLM-driven intrusion (1)
- LLMjacking (1)
- LMS (1)
- LNK (10)
- LNK files (1)
- load balancer (1)
- loader (5)
- LOADLOOP (1)
- local LLMs (1)
- local privilege escalation (6)
- local-file-inclusion (1)
- localhost (1)
- log poisoning (1)
- logging (1)
- login item persistence (1)
- LOLBins (3)
- long-horizon autonomy (1)
- long-lived tokens (1)
- long-term access (1)
- LONGLEASH (1)
- LONGSTREAM (1)
- LOOKVALJS (1)
- LOOKVALPS (1)
- loopback (1)
- Loophole (1)
- low-confidence attribution (4)
- LPE (1)
- LS-DYNA (1)
- LSASS (1)
- LSHIY (1)
- LSSC (1)
- Lua (1)
- LuaJIT (1)
- Lumen (1)
- Lumen Black Lotus Labs (1)
- Lumma Stealer (1)
- Luna Moth (1)
- Luno (1)
- Lyceum (1)
- M-RED-TEAM (1)
- MaaS (6)
- MAC address (1)
- MacCMS (1)
- Maccy impersonation (1)
- machine-learning (1)
- macOS (13)
- macOS malware (2)
- MaDoO Blaster (1)
- Magento (1)
- MagicYUV (1)
- mail server compromise (1)
- mail-argenta (1)
- mailbox compromise (1)
- mailbox theft (3)
- MAIN world injection (1)
- maintainer compromise (4)
- maintainer persona (1)
- maintainer-compromise (2)
- malicious dataset (1)
- malicious GPO (1)
- malicious packages (1)
- malicious plugin (1)
- malicious releases (2)
- malicious signed driver (1)
- malvertising (9)
- malware (48)
- malware analysis (2)
- malware delivery (7)
- malware framework (2)
- Malware-as-a-Service (1)
- malware-as-a-service (5)
- malware-signing-as-a-service (1)
- MALXMR (1)
- managed file transfer (2)
- managed service provider (1)
- ManageEngine Endpoint Central (1)
- management plane (3)
- Manifest V3 (1)
- Manifold Security (1)
- manufacturing (1)
- Mapbox (2)
- marimo (1)
- MARKETMAKER (1)
- marketplace abuse (2)
- marketplace trust (1)
- MarkiRAT (1)
- Maven Central (1)
- mawesome (1)
- Mbed (1)
- McAfee Labs (1)
- McMx (1)
- MCP (11)
- MCP credentials (1)
- media processing (1)
- medical research (1)
- Mekotio (1)
- memfd (1)
- memory corruption (2)
- memory disclosure (2)
- memory implant (1)
- memory overread (1)
- memory poisoning (1)
- memory-only malware (1)
- merchant credential theft (1)
- MeshAgent (1)
- MeshCentral (2)
- MetaMask (1)
- MEV bot lure (1)
- Mexican banking fraud (2)
- Mexico (3)
- MFA bypass (8)
- MFA fatigue (1)
- MFA-bypass (1)
- Miasma (7)
- MicroPython (1)
- Microsoft (10)
- Microsoft .NET (1)
- Microsoft 365 (8)
- Microsoft 365 Copilot (1)
- Microsoft Authentication Broker (1)
- Microsoft Defender (1)
- Microsoft Defender Security Research (1)
- Microsoft dev tunnels (2)
- Microsoft Digital Crimes Unit (1)
- Microsoft Edge (2)
- Microsoft Edge Add-ons (2)
- Microsoft Edge Extensions Security Team (1)
- Microsoft Entra ID (4)
- Microsoft Graph (3)
- Microsoft Identity Platform (1)
- Microsoft Office SharePoint (1)
- Microsoft Security Blog (1)
- Microsoft SQL Server (1)
- Microsoft Teams (4)
- Microsoft Threat Intelligence (3)
- Microsoft Windows Hardware Compatibility Publisher (1)
- Microsoft-signed binary abuse (1)
- Middle East (4)
- middleware (1)
- Midnight Blizzard (1)
- military logistics (1)
- military research (1)
- Mimikatz (5)
- Minecraft DDoS (1)
- Mini Shai-Hulud (3)
- MiniJunk (1)
- MiniPlasma (1)
- MINIRAT (2)
- MINIRECON (2)
- Ministry of Finance (2)
- MiniUpdate (1)
- MIPS embedded devices (1)
- Mirai (3)
- Mirai-derived botnet (1)
- Mistic (1)
- MITRE ATT&CK T1005 (1)
- MITRE ATT&CK T1562 (1)
- mixed boolean arithmetic (3)
- MIXEDKEY (3)
- MLTBackdoor (1)
- mnemonic theft (1)
- mobile (1)
- Mobile Access (1)
- mobile banking fraud (1)
- mobile device management (1)
- mobile devices (1)
- mobile malware (2)
- MobileIron Sentry (1)
- MODBEACON (2)
- Model Context Protocol (8)
- model poisoning (1)
- model weights (1)
- model-provider abuse (1)
- ModeloRAT (1)
- ModHeader (1)
- modular malware (1)
- module-proxy (1)
- MOIS (6)
- Monero (2)
- Monero mining (1)
- Monster ransomware (1)
- Mozi (1)
- MpClient.dll (1)
- MpExtMs.exe (1)
- MPR network provider (1)
- Mr_Rot13 (1)
- MSBuild (1)
- msgpack (1)
- mshta (5)
- MSI (1)
- MSP (3)
- MSSQL (1)
- mTLS (1)
- Muck and Load (1)
- MuddyWater (4)
- Mullvad VPN (1)
- Multi-Domain Security Management (1)
- multi-tenant cloud (1)
- Mustang Panda (2)
- Mustard Tempest (1)
- mutable tags (2)
- MYRA (1)
- MySQL (1)
- Mysterious Elephant (1)
- Mythos (1)
- n8n (1)
- Nacos (2)
- NadMesh (1)
- named pipes (1)
- namespace recycling (1)
- namespace squatting (1)
- NAS targeting (1)
- nation-state (1)
- national identity records (1)
- native addon (1)
- native extension (3)
- NativeAOT (3)
- NATO (3)
- NATS (1)
- NCSC-NL (1)
- Nebo (1)
- Nebula Security (1)
- negotiation (1)
- Neo-reGeorg (1)
- nested virtualization (1)
- Neteller (1)
- Netherlands (2)
- Netlify abuse (1)
- NetNut (1)
- NetScaler (2)
- NetScaler ADC (2)
- NetScaler Gateway (2)
- network infrastructure (1)
- network infrastructure exploitation (1)
- network policies (1)
- network-share exfiltration (1)
- Nextcloud (1)
- Nextcloud Flow (1)
- nf_tables (1)
- nftables (1)
- NGINX (1)
- Nginx (2)
- Nginx module (1)
- Ngrok C2 (1)
- Nigeria-nexus (1)
- NirSoft (1)
- no attribution (1)
- No-IP (1)
- node-gyp (2)
- node-ipc (1)
- node-pty (1)
- Node.js (4)
- Node.js implant (1)
- Node.js malware (1)
- North Korea (12)
- notarized malware (2)
- notification interception (1)
- npm (51)
- npm lifecycle hook (3)
- npm supply-chain (1)
- npm token theft (1)
- npm tokens (1)
- npm v12 (1)
- npx (1)
- NSecKrnl.sys (1)
- NTDS.dit (2)
- NTFS ADS (2)
- NTLM (1)
- nuclear weapons (1)
- NuGet (4)
- Nuitka (1)
- null-byte padding (1)
- NVGRE (1)
- NVIDIA impersonation (1)
- O-UNC-066 (1)
- OAuth (4)
- OAuth abuse (4)
- OAuth client credentials (1)
- OAuth device authorization grant (2)
- OAuth redirect (1)
- OAuth token abuse (1)
- OAuth token exposure (1)
- OAuth tokens (3)
- OBF networks (1)
- obfuscation (1)
- obfuscator.io (1)
- Oblivion (2)
- obsolete software (1)
- Octopi365 (1)
- OFAC (1)
- official store compromise (1)
- Offshore LC (1)
- OIDC (7)
- OilRig (1)
- Oj (1)
- OkoBot (1)
- Okta (4)
- Okta Threat Intelligence (1)
- OKX (1)
- Ollama (2)
- Oman (1)
- Omnibox (1)
- OneDrive (3)
- OneDrive access (1)
- opaque predicates (2)
- open directory (1)
- Open Interpreter (1)
- Open WebUI (1)
- OpenAI (2)
- OpenAI Codex (1)
- OpenClaw (1)
- opencode (1)
- OpenConnect (1)
- OpenHands (1)
- OpenSearch (1)
- OpenShield (1)
- OpenSSH (2)
- OpenVPN (1)
- OpenVPN-shaped UDP (1)
- OpenVSX (1)
- operation (2)
- Operation BlueDash (1)
- Operation DangerousPassword (1)
- Operation Endgame (1)
- Operation Highland (2)
- operational relay box (1)
- Operational Relay Box (1)
- operational resilience (1)
- operational security (1)
- operational technology (1)
- operations (231)
- OpFauxSign (1)
- ops (259)
- opsec failure (1)
- Oracle (1)
- Oracle E-Business Suite (1)
- Oracle Payments (1)
- Oracle PeopleSoft (2)
- Oracle WebLogic Server (1)
- ORANGETAIL (1)
- ORB network (1)
- OS command injection (1)
- OT (3)
- OT switches (1)
- OTA update (1)
- OTP interception (1)
- OtterCookie (1)
- out-of-bounds write (1)
- Outlook (1)
- overlay attacks (2)
- OX Security (1)
- OxideHarvest (1)
- OYSTERBLUES (1)
- OYSTERFRESH (1)
- OYSTERSHUCK (1)
- P2P (1)
- P2P C2 (1)
- package masquerading (1)
- package registry (8)
- package registry abuse (1)
- package registry credentials (1)
- package registry proxy (1)
- package republishing (1)
- package scanning (1)
- package takedown (1)
- package-cooldowns (1)
- package-manager-hardening (1)
- package-splitting (1)
- package-takeover (1)
- Packagist (5)
- Page Builder CK (1)
- page cache (2)
- page poisoning (1)
- Pakistan (3)
- Pakistan-linked (2)
- Palo Alto Networks (1)
- PAM (2)
- PAM credential validation (1)
- PamStealer (1)
- PAN-OS (1)
- parallel-intrusion (1)
- passkeys (1)
- password manager theft (1)
- password spray (1)
- password spraying (3)
- password-protected archive (2)
- Pastebin (1)
- PAT theft (1)
- patch management (2)
- path hijacking (1)
- path traversal (2)
- Patriot Bait (1)
- patterns (29)
- payload loader (1)
- payload staging (1)
- payload-as-a-service (1)
- payment fraud (1)
- payment SDK (1)
- payment skimmer (1)
- payment workflow exposure (1)
- payment-card theft (2)
- payment-card-theft (2)
- PayPal (1)
- payroll lures (1)
- Paysafe (1)
- pe_to_shellcode (1)
- PebbleDash (1)
- pedit (1)
- pentesting (1)
- people (1)
- PeopleTools (1)
- PerfWatson2.exe (1)
- Perplexity AI (1)
- persistence (29)
- persistent root access (1)
- persona operations (1)
- personal access tokens (2)
- pfSense (1)
- PhaaS (2)
- Phantom Gyp (3)
- PhantomClick (1)
- PhantomMail (1)
- PhantomRelay (1)
- Philippines (1)
- phishing (25)
- phishing-as-a-service (5)
- PHP (2)
- PHP code execution (1)
- PHP code injection (1)
- PHP object injection (1)
- PHP upload (1)
- PHP web shell (1)
- physical systems (1)
- physics (1)
- PicassoLoader (1)
- pickle (1)
- pig butchering (1)
- pig-butchering (1)
- Pink (1)
- pipelines (1)
- piracy (1)
- Piriform (1)
- Pix (1)
- Pixeldrain (1)
- PixelSmash (1)
- PKGBUILD (1)
- plaintext HTTP (1)
- Plandex (1)
- PLENET (2)
- plugin architecture (2)
- PlugX (1)
- poisoned-branch (1)
- PoisonX (1)
- police digital services (1)
- PolinRider (2)
- Poly1305 (1)
- polyfill (1)
- Polygon (1)
- Polygon blockchain dead drop (2)
- Polymarket (1)
- polymorphic loader (1)
- polymorphic payloads (1)
- Popa (1)
- portmap (1)
- Portugal (1)
- post-authentication RCE (1)
- post-exploitation (6)
- post-exploitation framework (1)
- postal-impersonation (1)
- PostCSS (1)
- PostgreSQL (3)
- postinstall (10)
- PowerCloud (1)
- PowerShell (24)
- PowerShell execution (1)
- PowerShell malware (3)
- PowerShower (1)
- PPtP (1)
- PRA (1)
- PraisonAI (1)
- PRC (1)
- PRC-aligned (1)
- PRC-nexus (1)
- pre-auth RCE (1)
- pre-authentication (2)
- pre-authentication RCE (1)
- preinstall (3)
- Primitive Bear (1)
- PrincessClub (1)
- priority inheritance (1)
- privacy (1)
- privacy exposure (1)
- private key theft (1)
- private registry fallback (1)
- private-key theft (1)
- privilege escalation (10)
- Privileged Remote Access (1)
- process doppelgänging (1)
- process environment scraping (1)
- process hollowing (3)
- process injection (6)
- product lifecycle management (1)
- professional services (1)
- profile.d (1)
- Progress Kemp LoadMaster (1)
- Progress Software (1)
- Project Proposal.exe (1)
- prompt injection (8)
- prompt-injection (4)
- PROMPTFLUX (1)
- PROMPTSPY (1)
- promptware (1)
- proof of deletion (1)
- Proofpoint (1)
- protestware (1)
- Protobuf (1)
- provenance (1)
- proxy (8)
- proxy network (2)
- ProxyChains (1)
- proxyjacking (1)
- proxyware (1)
- prt-scan (1)
- PSEMHUB (1)
- PsExec (2)
- PSIGW (1)
- psychological operations (1)
- PTC (1)
- PteroBox (2)
- PteroPaste (2)
- PteroPSDoor (2)
- PteroSetup (2)
- PteroVDoor (2)
- public exploit (3)
- public file-transfer exfiltration (1)
- public proof of concept (1)
- public sector (2)
- public service abuse (1)
- pull requests (2)
- PUP (1)
- PureLogs Stealer (1)
- PureRAT (1)
- pwn-request (1)
- PyArmor (3)
- PyInstaller (1)
- PyPI (12)
- Python (13)
- Python extension modules (1)
- Python malware (2)
- Python stealer (1)
- Qianxin Threat Intelligence Center (2)
- QiAnXin XLab (3)
- Qilin (3)
- QNAP (1)
- QR code (1)
- QR code interception (1)
- quantum computing (1)
- Quasar (1)
- query injection (1)
- Quest KACE SMA (1)
- QuimaRAT (1)
- RaaS (1)
- RabbitMQ (1)
- race condition (1)
- RainbowEx (1)
- RakNet flood (1)
- RAM disk (1)
- Ransom-ISAC (1)
- ransomware (11)
- ransomware access (1)
- ransomware enablement (1)
- ransomware-access (1)
- rapid exploitation (2)
- Rapid7 (1)
- RAR archives (1)
- RAR staging (2)
- RAT (30)
- RC4 (4)
- RC4 C2 (1)
- RCE (6)
- Rclone (1)
- rclone (1)
- RCS (1)
- RDP (1)
- RDP phishing (1)
- RDS (1)
- Reality (1)
- Reaper (1)
- reconnaissance (2)
- recovery denial (2)
- recovery disruption (2)
- recruitment lures (1)
- Red Dev 10 (2)
- Red Hat (1)
- Red Raindrop Team (2)
- REDCap (1)
- Redis (4)
- Redis backdoor (1)
- RediSearch (1)
- reduced cyber refusals (1)
- RedWing (2)
- REF6045 (2)
- REF9403 (1)
- reflective .NET loading (1)
- reflective loading (3)
- refresh token theft (1)
- refresh tokens (1)
- RegAsm process hollowing (1)
- registry persistence (5)
- registry-controls (1)
- release automation (1)
- release tampering (1)
- Remcos (2)
- Remcos RAT (1)
- remote access (6)
- remote access software (1)
- remote access trojan (3)
- Remote Access VPN (1)
- remote code execution (18)
- remote debugging (2)
- remote MCP (1)
- remote monitoring and management (1)
- remote script injection (1)
- Remote Support (1)
- remote support (2)
- Remote Utilities (2)
- remote-access (1)
- Remotely (1)
- RemotePE (1)
- RemotePELoader (1)
- removable media (1)
- Rentry (1)
- replication (1)
- repo-server (1)
- repository compromise (1)
- repository exfiltration (1)
- repository poisoning (3)
- research sector (1)
- residential proxies (1)
- residential proxy (1)
- REST API (1)
- REST C2 (1)
- restart-triggered execution (1)
- retail trading (1)
- reverse proxy (2)
- reverse SSH tunneling (2)
- reverse tunneling (1)
- REVERSE_PROXY_TRUSTED_PROXIES (1)
- ReverseSocks (1)
- reviewdog (1)
- Rilide (1)
- RingH23 (1)
- RMM (3)
- RMM abuse (10)
- ROADrecon (1)
- ROADtools (1)
- roadtx (1)
- Rokarolla (2)
- RokRAT (1)
- Rollup (1)
- RomulusLoader (1)
- Roo-Code (1)
- root (2)
- root access (1)
- root escalation (1)
- root execution (2)
- rootkit (4)
- ROOTRUN (1)
- ROPC (1)
- Rouki obfuscation (1)
- Roundcube (1)
- router (1)
- router compromise (1)
- router malware (1)
- ROX II (1)
- RSA (1)
- RSA-2048 (2)
- RSA-OAEP (1)
- RT-Thread (1)
- RTL819X (1)
- RTLO (1)
- rtmutex (1)
- RubyGems (3)
- Ruckus routers (1)
- RUGGEDCOM (1)
- Run key (1)
- Run key persistence (1)
- rundll32 (2)
- Runner.Worker (1)
- Runspace (1)
- runtime execution (2)
- runtime mutation (1)
- runtime patching (1)
- runZero (1)
- Russia (12)
- Russia-affiliated (2)
- Russia-linked (3)
- Russia-linked cybercrime (1)
- Russia-nexus (2)
- Russia-speaking operator (1)
- Russian Intelligence Services (1)
- Russian intelligence services (1)
- Russian state-supported (3)
- Russian-speaking ecosystem (1)
- Russian-speaking forums (1)
- Rust (8)
- Rust malware (5)
- S3 Browser (1)
- S3-compatible storage (1)
- s5cmd (1)
- SaaS (5)
- SaaS abuse (1)
- SaaS data access (1)
- SaaS exposure (1)
- sabotage (2)
- Safari (1)
- SafeDep (5)
- Salesforce (3)
- SAML IdP (1)
- Samsung TizenRT (1)
- sandbox escape (2)
- sandbox evasion (1)
- sandboxing (1)
- Sandworm (2)
- saroula01 (1)
- scam infrastructure (1)
- scambling (1)
- scanner evasion (1)
- ScarCruft (1)
- scheduled task (6)
- scheduled task persistence (5)
- scheduled tasks (6)
- SCMBANKER (2)
- scope squatting (1)
- scoped package impersonation (1)
- SCOUTCURL (1)
- screen capture (2)
- ScreenConnect (5)
- Screening Serpens (1)
- screenshot capture (1)
- screenshot theft (3)
- script-injection (1)
- SD-WAN (1)
- search hijacking (1)
- search poisoning (1)
- search result poisoning (1)
- search-ms (1)
- Seashell Blizzard (2)
- Secret Blizzard (3)
- secret exposure (1)
- secrets (6)
- secrets management (1)
- Secure Preferences (1)
- Security Management Server (1)
- security platform (1)
- security-tool discovery (1)
- seed phrase theft (2)
- SeedHunter (1)
- Seedworm (3)
- segmented networks (1)
- Sekoia (1)
- self-delete (1)
- self-hosted AI services (1)
- self-hosted media (1)
- self-hosted runner (1)
- self-propagation (1)
- semantic-release (1)
- sendit.sh (1)
- sensitive information exposure (1)
- Sentinel (1)
- SentinelOne (1)
- Sentry (1)
- Sentry abuse (1)
- SEO poisoning (6)
- Seqrite Labs (1)
- Serv-U (1)
- service accounts (1)
- service persistence (1)
- service providers (1)
- service-agent (1)
- ServiceNow (2)
- ServiceNow AI Platform (1)
- ServiceWorker (1)
- session cookie theft (3)
- session hijacking (2)
- session secret exposure (1)
- session theft (2)
- session token theft (1)
- setuid (1)
- shadow copy deletion (2)
- shadow MMU (1)
- SHADOW-AETHER-040 (1)
- SHADOW-AETHER-064 (1)
- SHADOW-EARTH-066 (1)
- SHADOW-WATER-063 (1)
- ShadowPad (3)
- Shai-Hulud (7)
- SHARDLOADER (2)
- share propagation (1)
- shared hosting (3)
- shared secrets (1)
- SharedWorker (1)
- ShareFile (1)
- SharePoint (5)
- SharePoint Server (1)
- SharkLoader (1)
- shell injection (1)
- ShinyHunters (2)
- Shodan (1)
- ShortLeash (1)
- Shuckworm (1)
- SideCopy (1)
- sideloading (1)
- Siemens (1)
- Signal (3)
- Signal interception (1)
- signed malware (1)
- signed updates (1)
- signed-binary (1)
- Silent Ransom Group (1)
- Silent Swap (1)
- SilentCryptoMiner (1)
- SilentRunLoader (1)
- SiliconFlow (1)
- Silver Fox (2)
- SimpleHelp (4)
- SimpleHTTPServer exposure (1)
- simulation tampering (1)
- Site Member permissions (1)
- skb (1)
- SkillCloak (1)
- SkillDetonate (1)
- Skrill (1)
- sleeper packages (1)
- Sliver (2)
- SLSA (1)
- SLSA provenance (1)
- SMA1000 (2)
- smart building (1)
- smart TVs (1)
- SMARTAXE (1)
- SmartConsole (1)
- SmartLoader (1)
- SmartScreen (1)
- SMB (1)
- SMB brute force (1)
- SMB egress (1)
- smishing (4)
- SMS interception (2)
- sms-phishing (1)
- SMTP (1)
- SMTP abuse (1)
- Snake (1)
- Sneaky 2FA (1)
- SNOWLIGHT (1)
- SOAP API abuse (1)
- SocGholish (1)
- social engineering (15)
- social-engineering (2)
- Socket (4)
- Socket Security (3)
- Socket Security Research (2)
- Socket.IO (2)
- SOCKS tunneling (1)
- SOCKS5 (5)
- SOCKS5 proxy (1)
- SOCKS5 tunneling (1)
- SOCRadar (2)
- SoftEther VPN (2)
- software impersonation (1)
- software supply chain (1)
- software-deployment (1)
- SOHO router (1)
- SOHO routers (1)
- Solana (3)
- SolarWinds (1)
- Solid PDF Creator (1)
- SolidPDFCreator.dll (1)
- SolidPDFPcl2Bmp (1)
- SonicWall (2)
- Sophos (1)
- source code (1)
- source control (3)
- source repository compromise (1)
- source-code compromise (1)
- source-control token theft (1)
- source-package drift (1)
- source-package mismatch (2)
- source-repository poisoning (5)
- source-repository reconnaissance (1)
- SourceForge abuse (1)
- SourTrade (1)
- South Africa (1)
- South Asia (1)
- South Korea (2)
- Southeast Asia (6)
- SP Page Builder (1)
- spam (1)
- spear phishing (8)
- spear-phishing (2)
- spearphishing (1)
- SPECTRALVIPER (1)
- Sphinx ransomware (1)
- SpiderLabs (1)
- Spikey Scorpius (1)
- Splunk (1)
- Spring Boot (1)
- SprySOCKS (2)
- spyware (1)
- SQL injection (5)
- SQLite (1)
- SQLite state (1)
- SquareShell (1)
- SSDP (1)
- SSH (3)
- SSH backdoor (1)
- SSH bastion (1)
- SSH brute force (1)
- SSH key exposure (1)
- SSH key persistence (1)
- SSH keys (4)
- SSH lateral movement (1)
- SSH persistence (1)
- SSH tunnel (1)
- SSH tunneling (1)
- SSH tunnels (1)
- SSL VPN (2)
- SSRF (5)
- stack use-after-free (1)
- staged malicious update (1)
- stale access (1)
- stale credentials (1)
- Starland RAT (3)
- Startup folder (1)
- Startup folder persistence (1)
- state-linked (2)
- state-owned enterprise (1)
- Static Kitten (1)
- stdio (3)
- StealC (2)
- stealer (3)
- Steam profile dead drop (2)
- steganography (3)
- StegoAd (1)
- StepSecurity (2)
- STM32Cube (1)
- stock exchange (1)
- STOCKSTAY (3)
- storage deletion (1)
- Storage Zone Controller (1)
- stored XSS (1)
- Storm-2603 (1)
- Storm-2697 (1)
- Storm-3075 (1)
- Stowaway (1)
- STRD (3)
- streaming boxes (1)
- Stripe OLT (1)
- student targeting (1)
- STUN (1)
- Stuxnet lineage (1)
- subject claim (1)
- SuccessKey (1)
- SUMMIT (3)
- Suo5 (1)
- Supabase (1)
- SUPERADMIN_SECRET (1)
- supply chain (14)
- supply chain compromise (1)
- supply-chain (86)
- supply-chain attribution (1)
- supply-chain integrity (1)
- supply-chain-adjacent (1)
- surveillance (1)
- suspected China-aligned (1)
- suspected China-linked (1)
- SVG (2)
- SWE-agent (1)
- SWUpdate (1)
- Symantec Threat Hunter Team (2)
- symbolic link (1)
- symlink following (1)
- Synacktiv (1)
- Synology (1)
- synthetic commits (1)
- Sysdig (2)
- SYSTEM (1)
- SystemBC (1)
- systemd (1)
- systemd-userdbd (1)
- T1204.004 (1)
- T3 (1)
- TA427 (1)
- TA488 (3)
- TA569 (1)
- Tactical RMM (2)
- tag rewrite (1)
- tag tampering (4)
- TAG-124 (1)
- TAG-179 (1)
- TAG-182 (1)
- TAG-22 (2)
- Taiwan (8)
- takedown (3)
- TamperedChef (1)
- targeted malware (1)
- targeted operations (1)
- TartarusGate (1)
- task queue (1)
- task scheduler abuse (1)
- TaskWeaver (3)
- tax-season phishing (1)
- tc (1)
- TCP traffic diversion (1)
- TDS (1)
- TeamPCP (8)
- TeamPCP-adjacent (1)
- Teams access (1)
- TeamViewer (1)
- TEASOUP (1)
- Tebi (1)
- technician session (1)
- telecom (2)
- telecom-impersonation (1)
- telecommunications (1)
- Telegra.ph (1)
- Telegram (10)
- telegram (1)
- Telegram bot (2)
- Telegram C2 (5)
- Telegram dead drop (2)
- Telegram exfiltration (1)
- Telegram notification (1)
- telemetry (1)
- TELEPUZ (1)
- TELESHIM (4)
- Teletype (1)
- Telnet (1)
- Telnet brute force (2)
- Telnyx (1)
- Temp Zagros (1)
- template injection (1)
- tenant-project (1)
- TencShell (1)
- Tenda (1)
- Tenet Security (1)
- Tetrade (1)
- TetrisPhantom (1)
- TeviRAT (1)
- Thailand (4)
- The Gentlemen (1)
- The Hacker News (12)
- The Quarry (1)
- ThemeREX Addons (1)
- third-party integrations (1)
- threat hunting (1)
- threat landscape (1)
- ThrottleBlood (1)
- ThumbcacheService (1)
- thumbnail generation (1)
- TinyGo (1)
- TinyRCT (3)
- tj-actions (1)
- TmcLoader (1)
- TmcPayload (1)
- ToddyCat (3)
- token forgery (1)
- token replay (3)
- token theft (6)
- token-theft (1)
- TONESHELL (2)
- TookPS (1)
- tool (1)
- tool execution (1)
- tool output injection (1)
- tool poisoning (1)
- tool use (1)
- tooling (5)
- tools (35)
- Tor (3)
- Total Software Deployment (1)
- Trading Technologies (1)
- TradingView (1)
- traffic broker (1)
- traffic control (1)
- traffic hijacking (1)
- traffic-distribution-system (1)
- traffic-fraud (1)
- training data (1)
- transaction authority (1)
- transitive dependency (1)
- transnational repression (1)
- Transparent Tribe (2)
- transport (1)
- transportation (2)
- Trend Micro (3)
- TrendAI (1)
- Trezor (1)
- TrickBot (1)
- Trident Ursa (1)
- trojanized installers (3)
- Tron (2)
- trusted extension risk (1)
- trusted publishing (2)
- tunnel decapsulation (1)
- tunnel services (1)
- Turla (4)
- Turla collaboration (1)
- TuxBot (1)
- TuxBot v3 Evolution (1)
- Twilio (1)
- Twilio SendGrid (1)
- Tycoon2FA (1)
- TypeScript (2)
- typosquat (1)
- typosquatting (15)
- UAC (1)
- UAC bypass (1)
- UAC-0002 (2)
- UAC-0010 (3)
- UAC-0098 (1)
- UAC-0145 (2)
- UAC-0194 (3)
- UAC-0226 (1)
- UAT-11795 (3)
- UAT-5918 (1)
- UAT-7237 (3)
- UAT-7810 (1)
- Ubiquiti (1)
- Ubuntu (1)
- Udev persistence (1)
- UDP C2 (1)
- UDP/1900 (1)
- Ukraine (14)
- Ukraine targeting (3)
- Ulej (3)
- UltraVNC (1)
- Umbrij (3)
- unauthenticated access (1)
- unauthenticated HTTP exploitation (1)
- unauthenticated RCE (4)
- UNC1543 (1)
- UNC2814 (1)
- UNC3753 (1)
- UNC4221 (1)
- UNC4736 (1)
- UNC5792 (1)
- UNC6240 (2)
- UNC6508 (1)
- UNC6671 (1)
- UNC6692 (2)
- UNC6780 (1)
- Uni-App (1)
- UniFi OS (1)
- Unified CM SME (1)
- uninitialized heap memory (1)
- Unit 42 (8)
- United States (3)
- university targeting (1)
- UNK_MassTraction (1)
- UNK_PitStop (1)
- unpatched vulnerability (2)
- unsafe deserialization (1)
- unsigned installer (1)
- UpdateFactory (1)
- UPnP (1)
- UPX (1)
- uranium compression (1)
- USB propagation (1)
- USB weaponizer (1)
- USB worm (2)
- use-after-free (2)
- user execution (1)
- user namespaces (2)
- UTA0355 (1)
- UTA0533 (1)
- UTG-Q-1000 (2)
- uTLS (1)
- V2Ray (1)
- V4bel (1)
- V8 (1)
- valid accounts (1)
- ValleyRAT (2)
- VBCloud (1)
- VBE (1)
- VBS (1)
- VBScript (7)
- vector databases (1)
- VEIL#DROP (1)
- Velociraptor (1)
- Velvet Ant (2)
- VELVETSHELL (1)
- vendor compromise (1)
- vendor credentials (1)
- VENOMOUS BEAR (3)
- Vercel (1)
- Vertex AI (1)
- VIDAR (2)
- Vidar Stealer (3)
- Vietnam (2)
- Vietnam-aligned (1)
- Views (1)
- ViewState deserialization (1)
- ViPNet (1)
- virtualization (2)
- VirusTotal sentiment abuse (1)
- vishing (7)
- Visual Studio (1)
- Visual Studio Code Remote SSH (1)
- Vite (1)
- Vitest (1)
- ViteVenom (1)
- VLESS (1)
- vManage (1)
- VMware (2)
- VNC (2)
- VNT (2)
- Void Blizzard (3)
- Void Manticore (1)
- Volt Typhoon (1)
- volume serial number (1)
- VPN (6)
- VPN credentials (2)
- VPN gateway (1)
- VPN Go (1)
- VPN session hijacking (1)
- VS Code (8)
- VS Code tunnels (1)
- Vshell (1)
- VShell (1)
- VSIX (1)
- vSphere (2)
- VU#213560 (1)
- VulnCheck (1)
- vulnerability (22)
- vulnerability exploitation (2)
- vulnerability research (4)
- vulnerability-research (1)
- vulnerable appliances (1)
- VXLAN (1)
- w3wp.exe (1)
- wallet address replacement (1)
- wallet drainer (1)
- wallet infrastructure (1)
- wallet replacement (1)
- wallet theft (6)
- wallet-drainer (1)
- wallet-theft (3)
- Wasabi (2)
- watchdog (1)
- watchTowr (3)
- watchTowr Labs (1)
- watering hole (1)
- watering-hole (2)
- weak credentials (1)
- weak passwords (1)
- weapons shipments (1)
- web application (5)
- web application compromise (1)
- web hosting (2)
- web IDE (1)
- web injection (1)
- web injector (1)
- web management interface (1)
- web proxy (1)
- web RCE (1)
- web server (1)
- web shell (8)
- web shell hunting (1)
- web shells (3)
- web supply chain (1)
- web-shells (1)
- WebAssembly (1)
- WebDAV (2)
- WebKit (1)
- WebLogic (1)
- webmail (3)
- WebRTC (1)
- webshell (1)
- webshells (1)
- website-compromise (1)
- WebSocket (2)
- WebSocket C2 (7)
- websocket-sharp (1)
- WebView (1)
- WebView2 C2 (1)
- Webworm (1)
- Werkbit (1)
- WhatsApp (3)
- WhatsApp phishing (1)
- WHM (4)
- Widget Factory (1)
- wiki (1)
- WILDDAY (2)
- Windchill (1)
- Windchill PDMLink (1)
- WinDirStat (1)
- Windmill (1)
- Windows (32)
- Windows Defender (1)
- Windows Defender exclusions (1)
- Windows Forms (1)
- Windows malware (12)
- Windows persistence (1)
- Windows Run dialog (1)
- Windows Script Host (2)
- Windows servers (1)
- Windows service persistence (1)
- Windows Terminal (1)
- Winnti Group (2)
- WinOS (1)
- Winos4.0 (1)
- WinPython (1)
- WinRAR (4)
- wiper (3)
- wiper-adjacent (1)
- WireGuard (2)
- Wiz Research (1)
- WLDR agent (2)
- WM_COPYDATA IPC (1)
- WMI (1)
- Woodgnat (1)
- WordPress (8)
- WordPress credential theft (1)
- workflow backdoor (1)
- working-directory hijacking (1)
- workspace trust (2)
- World Cup (1)
- worm (13)
- WP Maps Pro (1)
- WP-SHELLSTORM (1)
- wp2shell (1)
- WScript (1)
- X-Secret (1)
- X-WEBAUTH-USER (1)
- X25519 (1)
- X3D MINER (1)
- X_TRADER (1)
- XChaCha20 (1)
- XenoRAT (2)
- XFRM (1)
- xlabs_v1 (1)
- XMLDecoder (1)
- XMRig (6)
- XOR (2)
- XOR obfuscation (1)
- Xray (1)
- XSLT SSRF (1)
- XSS (1)
- XSS.is (1)
- XXE (1)
- xz (2)
- Yanbian (1)
- YesWeHack (1)
- YouTube abuse (1)
- Yuechi Shared Technology (1)
- yuze (2)
- ZAPiXDESK (1)
- Zendesk (1)
- Zephyr RTOS (1)
- Zero Trust (1)
- zero-click (1)
- zero-day (5)
- zero-day exploitation (1)
- zero-reputation infrastructure (1)
- ZeroBEC (1)
- Zimbra (3)
- Zimbra Collaboration Suite (1)
- Zimperium (2)
- zLabs (2)
- Zoho Assist (2)
- Zoho WorkDrive (2)
- ZOHOMURK (2)
- Zoom (1)
.NET
- Braintree.Net NuGet payment skimmer
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Sicoob.Sdk NuGet banking certificate stealer
- STOCKSTAY
- TinyRCT
- Umbrij
.NET malware
- Avalon / CrownX malware framework
- Cavern
- Cavern Manticore
- HOLLOWGRAPH
- Silent Swap Google Notes crypto clipper
- ToddyCat Umbrij Gmail OAuth operation
- Turla STOCKSTAY backdoor operations
.pth
/accessv2
/dev/kvm
146.70.139.154
192.42.116.105
192.42.116.58
2FA recovery codes
3CX
404 TDS
43.228.157.68
4sync
@marketfront
@tqm-mfe
.bin
<all_urls>
Ababil of Minab
abuse response
academic research
academic sector
Accellion
access broker
access brokers
access optionality
access token abuse
account lockout
account takeover
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- O-UNC-066 Entra passkey vishing
- Russian intelligence commercial-messaging backup-key phishing
account-takeover
ACR Stealer
act_pedit
ACTINIUM
Active Directory
active exploitation
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- C0XMO Gafgyt DD-WRT botnet
- Check Point VPN CVE-2026-50751 exploitation
- Chrome V8 CVE-2026-11645 exploitation
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- CL-STA-1114 Zimbra webmail espionage
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Gitea Docker CVE-2026-20896 probing
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Gravity SMTP CVE-2026-4020 exploitation
- Ivanti Sentry CVE-2026-10520 exploitation
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
- Windmill CVE-2026-29059 active exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
active probing
active threat
- OkoBot cryptocurrency-wallet malware framework
- Progress ShareFile Storage Zone Controller security threat
active-exploitation
ActiveX
actor
actors
- Armored Likho
- Cavern Manticore
- Fox Tempest
- JINX-0164
- Mustang Panda
- OP-512
- TA4922
- ToddyCat
- UAT-11795
- Webworm
ad blocker
ad fraud
Adaptix C2
ADB TCP/5555
Adblock for YouTube
ADFS
Admin API key theft
administrator account creation
Adobe ColdFusion
Adobe Commerce
Adspect
Advanced IP Scanner
Adversa AI
adversary-in-the-middle
- AI-brand impersonation phishing and malvertising
- Chinese-language PhaaS wallet-tokenization ecosystem
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
adware
- Chrome live-wallpaper extension ad-fraud network
- Fake Corepack site infostealer and proxyware campaign
- ModHeader browser-extension surveillance capability
- Operation FlutterBridge FlutterShell macOS malvertising
- TamperedChef-style productivity malware clusters
adware history
AES-128-CBC
AES-256-CTR
AES-256-GCM
AES-CTR
AES-GCM
- CrashStealer macOS notarized-dropper campaign
- macOS.Gaslight Rust backdoor
- ModHeader browser-extension surveillance capability
AES-GCM C2
affiliate hijacking
Afghanistan
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Africa
agent frameworks
- Agent localhost control-plane RCE
- MCP stdio command-execution boundary
- PraisonAI CVE-2026-44338 rapid exploitation
agent memory
agent skills
agent state
AgentBaiting
agentic AI
- Patriot Bait AI-assisted C2 botnet
- SHADOW-AETHER AI-augmented Latin America intrusions
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
agentic botnets
agentic browser
agentic browsers
agentic malware
agentic ransomware
agentic threat actor
Agentjacking
AGENTPSD
AI
- AI-augmented adversary operations
- GREYVIBE
- Patriot Bait AI-assisted C2 botnet
- Vertex AI staging-bucket squatting
- Xinference PyPI compromise
AI agent
AI agents
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI browser-extension confused deputy
- AI-agent memory poisoning
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- GuardFall AI-agent shell-guard bypass
- Langflow CVE-2025-34291 exploitation
- LangGraph checkpointer injection and unsafe deserialization
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NATS-as-C2 KeyHunter credential-harvesting operation
- Phantom squatting: AI-hallucinated domains
- PraisonAI CVE-2026-44338 rapid exploitation
- Sentry MCP Agentjacking
AI anti-analysis
AI application infrastructure
- Hugging Face autonomous-agent production intrusion
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- ServiceNow AI Platform CVE-2026-6875 exploitation
AI assistant credentials
AI assistants
- binding.gyp npm CI/CD worm
- Claude Code GitHub Action prompt-injection boundary
- Developer-tool config auto-execution
- Immobiliare Labs Backstage plugins npm compromise
AI brand impersonation
- AI-brand impersonation phishing and malvertising
- Perplexity AI-spoofing Chromium extension search hijacker
AI browsers
AI chatbot abuse
AI coding agents
AI credential theft
AI data exfiltration
AI developer tooling
AI framework
AI gateway
AI infrastructure
AI model encryption
AI model evaluation
AI Now Institute
AI search poisoning
AI security
AI services
AI tooling
- @withgoogle/stitch-sdk scope squat
- Amazon Q CVE-2026-12957 MCP auto-execution
- AsyncAPI generator / specs Miasma compromise
- codexui-android OpenAI token stealer
- JetBrains AI plugin API-key theft
- LangGraph checkpointer injection and unsafe deserialization
- Malware-Slop Claude user-data npm infostealer
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- Ollama P2P cryptominer RAT campaign
- Phantom squatting: AI-hallucinated domains
- Polymarket npm wallet-drainer packages
- PraisonAI CVE-2026-44338 rapid exploitation
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- TrapDoor crypto-stealer cross-ecosystem campaign
AI vulnerability discovery
AI workflow
ai-abuse
ai-agent
AI-assisted development
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
AI-assisted intrusion
AI-assisted malware
- Avalon / CrownX malware framework
- Evilginx and device-code phishing open-directory cluster
- Patriot Bait AI-assisted C2 botnet
AI-assisted malware development
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- TuxBot v3 Evolution IoT botnet framework
- Ulej / Flowerbed
AI-assisted phishing
AI-assisted vulnerability discovery
AI-augmented operations
- Hugging Face autonomous-agent production intrusion
- SHADOW-AETHER AI-augmented Latin America intrusions
AI-generated malware
AI-generated narrator
Aider
AISURU
AiTM
- BlackFile / UNC6671 vishing extortion operation
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
Albania
Amadey
Amatera Stealer
Amazon Q Developer
Amazon SES
AMOS
AMSI bypass
- ClickFix CPaaS API-driven payload delivery
- Operation DragonReturn India tax-season DcRAT campaign
- TELEPUZ
- Vidar / XMRig Factory-v3 malvertising campaign
AmsiScanBuffer
Android
- Android Framework CVE-2025-48595 exploitation
- codexui-android OpenAI token stealer
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- NetNut / Popa residential proxy network disruption
- ScarCruft Yanbian game-platform supply-chain attack
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Android Accessibility Service
Android ADB
Android Debug Bridge
Android malware
Android spyware
Anthropic
anti-analysis
- AI scanner anti-analysis
- CrashStealer macOS notarized-dropper campaign
- jscrambler npm preinstall stealer
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- TELESHIM
- TELESHIM Middle East government espionage campaign
anti-bot
anti-forensics
Anubis ransomware
ANY.RUN
AnyDesk
Apex One
API abuse
API enumeration
API exposure
API key exposure
API keys
API-driven payloads
apintergrationpost
App-Bound Encryption bypass
AppDomainManager
AppDomainManager injection
AppleJeus
AppleScript
AppleSeed
appliance
application delivery controller
application token
APSB26-68
APT
- Armored Likho
- Armored Likho BusySnake campaign
- Cloud Atlas
- Gamaredon
- Ghostwriter
- HelloNet ViPNet update-system campaign
- Screening Serpens
- ToddyCat
APT-C-08
APT27
APT28
APT29
APT32
APT36
APT37
APT42
APT43
APT44
APT45
Aptos
Aquatic Panda
AquilaRAT
arbitrary code execution
arbitrary file disclosure
arbitrary file read
arbitrary file upload
arbitrary file write
- Adobe ColdFusion APSB26-68 CVE bonanza
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
arbitrary JavaScript
Arch Linux
Arctic Wolf
ArduPilot
Argo CD
ArgoCD
Arista EOS
ARL
Armageddon
ArmCorp
Armored Likho
Artifact Signing
AryStinger
AS32167
Asia targeting
ASLR bypass
ASNs
ASP.NET
ASP.NET machineKey
ASPX web shells
Astro
ASUS AiCloud routers
ASUS router
AsyncAPI
AsyncRAT
- Operation Muck and Load GitHub lure network
- Pakistani law enforcement espionage convergence
- ScreenConnect freeware / AsyncRAT SEO campaign
Atlas RAT
Atomic Stealer
AUDIOFIX
audit logging
AUR
authenticated RCE
authenticated remote code execution
authentication bypass
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Gitea Docker CVE-2026-20896 probing
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Progress ShareFile Storage Zone Controller security threat
- ServiceNow AI Platform CVE-2026-6875 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
authentication laundering
authentication stack
authentication-coercion
Authenticode impersonation
authorization bypass
auto-execution
AUTODYN
AutoGen Studio
AutoHotKey
AutoJack
autonomous agents
autonomous scanning
Avalon
AWS
- @copilot-mcp/apex macOS infostealer campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- CircleCI 2023 customer secret exposure incident
- MrMustard PyPI credential-stealer compromise
- NATS-as-C2 KeyHunter credential-harvesting operation
- vpmdhaj OpenSearch npm cloud-secret stealer
AWS CloudTrail
AWS S3
AWS Secrets Manager
axios
Azure
Azure CLI
Azure DevOps
Azure Storage
Backblaze
backdoor
- BINDCLOAK
- DAEMON Tools Lite supply-chain compromise
- GigaWiper
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- macOS.Gaslight Rust backdoor
- MODBEACON
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- Ollama P2P cryptominer RAT campaign
- Operation FlutterBridge FlutterShell macOS malvertising
- shopsprint/decimal Go typosquat DNS backdoor
- Showboat
- SprySOCKS
- STOCKSTAY
- TELESHIM
- Telnyx PyPI TeamPCP compromise
- TinyRCT
Backdoor.Mistic
Backstage
backup disruption
backup recovery keys
backup targeting
backups
Bad Epoll
BadBlocker
Badbox 2.0
Balbooa Forms
Balochistan Police
Banana RAT
bandcampro
banking
banking malware
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
banking trojan
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
Barracuda
Base64
BaseZipInstaller
Bash Uploader
batch loader
BCU key
Beast ransomware
BeaverTail
Bedrock
behavioral integrity verification
Behinder
Belarus
BELQI
BeyondTrust
Binance Smart Chain
binary execution
BinaryFormatter
BINDCLOAK
binding.gyp
biometric records
BIOPASS RAT
BioShocking
BirdCall
Bitbucket
Bitcoin
BitMiner
bitsadmin
Bitter
Bitwarden
BKA
BlackFile
Blackpoint Cyber
- Avalon / CrownX malware framework
- CrownX
- Djinn Stealer
- LabubaRAT
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- TaskWeaver
Bleacher Report
blockchain C2
- Astro config blockchain C2 PR injection
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- PolinRider cross-ecosystem supply-chain campaign
- ViteVenom / ChainVeil npm campaign
blockchain dead drop
blockchain RPC
blockchain-dead-drop
Blogger abuse
blogspot staging
BLUEBEAM
botnet
- C0XMO Gafgyt DD-WRT botnet
- Dutch Police / NCSC 17-million-device botnet disruption
- Glassworm developer supply-chain botnet
- JDY SOHO / IoT reconnaissance botnet
- Lucide Proxy npm browser DDoS botnet
- NadMesh AI-service and cloud-credential botnet
- NetNut / Popa residential proxy network disruption
- Patriot Bait AI-assisted C2 botnet
- RustDuck
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
botnet framework
Braintree
branch-compromise
branch-name-injection
brand impersonation
- DCloud Uni-App scam infrastructure ecosystem
- Fake Corepack site infostealer and proxyware campaign
- GHOST STADIUM FIFA World Cup ticket phishing
brand-impersonation
Brazil
- Armored Likho
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- SHADOW-AETHER AI-augmented Latin America intrusions
Brazilian banking malware
BreachForums
Breeze Cache Cleaner
BRICKSTORM
Broadcom
browser assembly
browser automation
browser cookie theft
browser credential theft
- @copilot-mcp/apex macOS infostealer campaign
- ACR Stealer
- Armored Likho BusySnake campaign
- Avalon / CrownX malware framework
- BusySnake Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- GREYVIBE
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- macOS.Gaslight Rust backdoor
- PamStealer
- Seedworm / MuddyWater
- Silent Swap Google Notes crypto clipper
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0226 / SHADOW-EARTH-066
- Vidar / XMRig Factory-v3 malvertising campaign
- Void Dokkaebi
- VPN Go browser-extension clipboard stealer
browser data theft
browser extension
- Adblock for YouTube BadBlocker remote-script injection risk
- AI browser-extension confused deputy
- Forg365 Microsoft 365 PhaaS
- ModHeader browser-extension surveillance capability
- Perplexity AI-spoofing Chromium extension search hijacker
- Silent Swap Google Notes crypto clipper
- StegoAd Edge extension steganography campaign
- UNC6692 SNOW malware social-engineering campaign
- VPN Go browser-extension clipboard stealer
browser extension loader
browser hijacking
- Operation FlutterBridge FlutterShell macOS malvertising
- Perplexity AI-spoofing Chromium extension search hijacker
browser malware
browser security
browser session abuse
browser session risk
- Adblock for YouTube BadBlocker remote-script injection risk
- Perplexity AI-spoofing Chromium extension search hijacker
- VPN Go browser-extension clipboard stealer
browser zero-day
browser-credential-theft
browser-extensions
browser-resident malware
browser-security
browser-session risk
browsing history
brute-force credentials
BSC
BTMOB
bucket hijacking
bucket squatting
build-time compromise
building automation
bulletproof hosting
Bun
- actions-cool GitHub Actions tag compromise
- codfish semantic-release-action tag compromise
- SourTrade browser-assembled malware malvertising
Bun runtime abuse
business email compromise
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Microsoft Q2 2026 email and Teams phishing landscape
BusySnake Stealer
Bybit
BYOVD
- GodDamn ransomware PoisonX BYOVD activity
- Storm-2603 parallel SharePoint ransomware intrusion
- The Gentlemen ransomware
bypass2fa
C
C++
C++/CLI
C0XMO
C2
- BINDCLOAK
- DAEMON Tools Lite supply-chain compromise
- Glassworm developer supply-chain botnet
- Malicious infrastructure provider concentration
- NATS-as-C2 KeyHunter credential-harvesting operation
- Oman government Iranian-nexus webshell C2
- Patriot Bait AI-assisted C2 botnet
- Quest KACE SMA CVE-2025-32975 exploitation
- QuimaRAT
- RemotePE
- Showboat
- WLDR agent
C2 framework
C2 tasking
CageFS
calendar dead drop
calendar invitation
Calendly abuse
call forwarding
Cambodia
campaign
Canada
CANFAIL
CAP_NET_ADMIN
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
Casbaneiro
CastleStealer
Catalyst SD-WAN Manager
Catcher
Cav3rn
Cavern
Cavern Manticore
CCleaner
CDN
CERT-In
CERT/CC
Certbot
certificate pinning
certificate theft
certutil
CFIDE
ChaCha20
ChainVeil
ChatGPT
chattr
Chatty Spider
CHAVECLOAK
Check Point
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
Check Point Research
Checkmarx
checkpointers
China
China-linked
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- FishMonger
- GHOST STADIUM FIFA World Cup ticket phishing
- OP-512
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- SprySOCKS
China-nexus
- JDY SOHO / IoT reconnaissance botnet
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Pakistani law enforcement espionage convergence
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UAT-7810 LONGLEASH ORB network expansion
- UNC6508
- UNK_MassTraction Roundcube university mailserver campaign
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
China-speaking ecosystem
Chinese-language cybercrime
Chinese-language fraud ecosystem
Chinese-speaking
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GHOST STADIUM FIFA World Cup ticket phishing
- HelloNet ViPNet update-system campaign
Chinese-speaking cybercrime
Chinese-speaking operator
Chisel
- Oman government Iranian-nexus webshell C2
- PCPJack cloud SMTP relay network
- SHADOW-AETHER AI-augmented Latin America intrusions
ChocoPoC
Chrome
Chrome App-Bound Encryption
Chrome DevTools Protocol
Chrome extension
- ModHeader browser-extension surveillance capability
- PolinRider cross-ecosystem supply-chain campaign
Chrome renderer sandbox
Chrome Web Store
- Adblock for YouTube BadBlocker remote-script injection risk
- Chrome live-wallpaper extension ad-fraud network
- ModHeader browser-extension surveillance capability
- Perplexity AI-spoofing Chromium extension search hijacker
- VPN Go browser-extension clipboard stealer
chrome_settings_overrides
ChromElevator
Chromium
- Chrome V8 CVE-2026-11645 exploitation
- Perplexity AI-spoofing Chromium extension search hijacker
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
Chromium extension
CI secrets
CI-CD
CI/CD
- @marketfront / @tqm-mfe dependency-confusion stealer
- actions-cool GitHub Actions tag compromise
- Argo CD repo-server unauthenticated RCE
- Astro config blockchain C2 PR injection
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- CircleCI 2023 customer secret exposure incident
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- codfish semantic-release-action tag compromise
- Crypto supply-chain path to transaction authority
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- GuardFall AI-agent shell-guard bypass
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Immobiliare Labs Backstage plugins npm compromise
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Laravel-Lang Composer tag-rewrite compromise
- Leo Platform npm Miasma-style compromise
- LiteLLM compromise
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- SANDWORM_MODE AI-toolchain npm worm
- simonecorsi/mawesome GitHub Action compromise
- TeamPCP
- Telnyx PyPI TeamPCP compromise
- tj-actions and reviewdog compromise
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- vpmdhaj OpenSearch npm cloud-secret stealer
CI/CD abuse
CircleCI
CIS
CISA
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- FortiBleed Fortinet credential exposure
CISA KEV
- Android Framework CVE-2025-48595 exploitation
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- C0XMO Gafgyt DD-WRT botnet
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ivanti Sentry CVE-2026-10520 exploitation
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Trend Micro Apex One CVE-2026-34926 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Cisco
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
Cisco IOS
Cisco IOS 12.4
Cisco Nexus
Cisco Talos
Cisco Unified CM
Cisco Unified Communications Manager
citizen portal compromise
Citrine Sleet
Citrix
Citrix NetScaler
CitrixBleed
CitrixBleed 2
CKEditor file manager
CL-CRI-1089
CL-CRI-1147
CL-STA-1062
CL-STA-1114
Claude
Claude Code
- @withgoogle/stitch-sdk scope squat
- Azure DevOps MCP pull-request prompt injection
- Claude Code GitHub Action prompt-injection boundary
- GuardFall AI-agent shell-guard bypass
- Sentry MCP Agentjacking
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Claude for Chrome
Clever Cloud
ClickFix
- ACR Stealer
- Backdoor.Mistic / KongTuke ModeloRAT activity
- ClickFix CPaaS API-driven payload delivery
- Exposed WebDAV malware delivery lab and CURP campaign
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GREYVIBE
- JINX-0164 crypto developer infrastructure campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- Starland RAT
- StealC / Amadey infrastructure disruption
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795
- UAT-11795 Starland / WLDR campaign
ClickOnce
ClickUp
client-side exploitation
Cline
clipboard hijacker
clipboard injection
clipboard manipulation
clipboard stealer
clipboard theft
- BusySnake Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto Clipper Tor / USB worm
- PamStealer
- Silent Swap Google Notes crypto clipper
- VPN Go browser-extension clipboard stealer
clipper
Cloaked Ursa
cloaking
cloud
- APT29
- PCPJack cloud SMTP relay network
- ROADtools
- Vertex AI staging-bucket squatting
- Webworm
- Xinference PyPI compromise
cloud C2
cloud compromise
cloud credential hunting
cloud credential risk
cloud credential theft
- AI-augmented adversary operations
- Djinn Stealer
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Hugging Face autonomous-agent production intrusion
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
cloud credentials
- Amazon Q CVE-2026-12957 MCP auto-execution
- jscrambler npm preinstall stealer
- wshu.net npm credential-stealer campaign
Cloud Files Mini Filter Driver
Cloud Filter driver
cloud IAM
cloud identity
cloud identity abuse
cloud infrastructure
cloud logging
cloud secrets
- @marketfront / @tqm-mfe dependency-confusion stealer
- JINX-0164 crypto developer infrastructure campaign
- oob.moika.tech dependency-confusion environment stealer
- vpmdhaj OpenSearch npm cloud-secret stealer
cloud security
- Cloud bucket namespace hijacking
- Cloud logging control-plane tampering
- PraisonAI CVE-2026-44338 rapid exploitation
cloud service abuse
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Stock exchange executive mailbox espionage
cloud storage
cloud storage exfiltration
cloud transcoding
Cloudflare
- Forg365 Microsoft 365 PhaaS
- GHOST STADIUM FIFA World Cup ticket phishing
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Okta support-system compromise
Cloudflare Tunnel
- Evilginx and device-code phishing open-directory cluster
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Storm-2603 parallel SharePoint ransomware intrusion
Cloudflare tunnels
Cloudflare Turnstile
Cloudflare Workers
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Polymarket npm wallet-drainer packages
- StegoAd Edge extension steganography campaign
cloudflared
CloudLinux
cluster compromise
CMS
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Gravity SMTP CVE-2026-4020 exploitation
- Joomla JCE CVE-2026-48907 exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
CMS exploitation
Cobalt Strike
- FishMonger
- Ghostwriter
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Malicious infrastructure provider concentration
- Pakistani law enforcement espionage convergence
- StrikeShark SharkLoader / Cobalt Strike campaign
code execution
code injection
code sandbox scraping
code signing
- AI-brand impersonation phishing and malvertising
- Fox Tempest
- TamperedChef-style productivity malware clusters
Codecov
codemado
CodeQL
Codex
Codex CLI
coding agents
coding challenge
Coinbase
ColdFusion
collaboration platforms
collaboration-tool phishing
COM-hijacking
ComfyUI
command and control
command execution
- Agent localhost control-plane RCE
- Argo CD repo-server unauthenticated RCE
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Fake Corepack site infostealer and proxyware campaign
- GuardFall AI-agent shell-guard bypass
- MCP stdio command-execution boundary
- Ollama P2P cryptominer RAT campaign
command injection
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Ivanti Sentry CVE-2026-10520 exploitation
- Lantronix EDS5000 CVE-2025-67038 exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Siemens ROX II zero-day exploit chain
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
command-execution
command-injection
commercial messaging applications
commit farming
communications infrastructure
Composer
- Famous Chollima Packagist dev-branch loader
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Laravel-Lang Composer tag-rewrite compromise
- PolinRider cross-ecosystem supply-chain campaign
compromised accounts
compromised credentials
compromised infrastructure
compromised websites
compromised WordPress
computer vision
Conditional Access
configuration exposure
configuration theft
confused deputy
- Agent localhost control-plane RCE
- AI browser-extension confused deputy
- Azure DevOps MCP pull-request prompt injection
ConfuserEx
conhost
connected apps
ConnectWise
ConnectWise ScreenConnect
consumer devices
consumer IoT
Contagious Interview
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- PolinRider cross-ecosystem supply-chain campaign
- StegaBin Pastebin-steganography npm campaign
container
container escape
- ENCFORGE
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
container escape pre-check
content compliance rules
context flooding
Continue
continuous visibility
control flow flattening
control panel compromise
control plane
cookie theft
- Armored Likho BusySnake campaign
- BusySnake Stealer
- StegoAd Edge extension steganography campaign
- Vidar / XMRig Factory-v3 malvertising campaign
Copilot
Copilot CLI
Copy-on-Write
Corepack
Coruna
counterfeit software
COW
COWARDDUCK
CPaaS
cPanel
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
CPUID
cracked software
CrackMapExec
CrashStealer
Crates.io
credential attacks
- Kairos data-extortion government payment
- NetNut / Popa residential proxy network disruption
- Patriot Bait AI-assisted C2 botnet
credential dumping
credential exposure
- FortiBleed Fortinet credential exposure
- Progress ShareFile Storage Zone Controller security threat
- Sentry MCP Agentjacking
credential harvesting
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GodDamn ransomware PoisonX BYOVD activity
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC6508
credential spraying
credential stuffing
credential theft
- @copilot-mcp/apex macOS infostealer campaign
- @withgoogle/stitch-sdk scope squat
- Agent skill marketplace poisoning
- AI-brand impersonation phishing and malvertising
- Amazon Q CVE-2026-12957 MCP auto-execution
- AsyncAPI generator / specs Miasma compromise
- Avalon / CrownX malware framework
- Braintree.Net NuGet payment skimmer
- Browser-based developer IDE OAuth token theft
- Chinese-language PhaaS wallet-tokenization ecosystem
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Cursor Windows workspace-path binary hijack
- Exposed WebDAV malware delivery lab and CURP campaign
- FakeGit AgentBaiting and SmartLoader campaign
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- GHOST STADIUM FIFA World Cup ticket phishing
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Lazarus-linked Rollup polyfill npm malware
- LiteLLM compromise
- Microsoft Q2 2026 email and Teams phishing landscape
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- NadMesh AI-service and cloud-credential botnet
- nodemon-sudo / tslint-conf runtime npm backdoor
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation Highland Velvet Ant authentication-stack backdoors
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- PCPJack cloud SMTP relay network
- PolinRider cross-ecosystem supply-chain campaign
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- ScreenConnect freeware / AsyncRAT SEO campaign
- Seedworm / MuddyWater
- Solana FakeFix npm / PyPI developer stealer
- Starland RAT
- StealC / Amadey infrastructure disruption
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
- UAT-11795
- UAT-11795 Starland / WLDR campaign
- Umbrij
- UNC6692 SNOW malware social-engineering campaign
- UNK_MassTraction Roundcube university mailserver campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- ViteVenom / ChainVeil npm campaign
credential-theft
- @marketfront / @tqm-mfe dependency-confusion stealer
- actions-cool GitHub Actions tag compromise
- APT29
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- DAEMON Tools Lite supply-chain compromise
- Developer-tool config auto-execution
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- forge-jsxy
- GitHub / Packagist postinstall hook campaign
- Glassworm developer supply-chain botnet
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hunt.io global smishing infrastructure campaign
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- JetBrains AI plugin API-key theft
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- Kali365 device-code phishing expansion
- Laravel-Lang Composer tag-rewrite compromise
- Leo Platform npm Miasma-style compromise
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- node-ipc 2026 npm maintainer-account compromise
- Nx Console VS Code extension compromise
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Operation GriefLure Southeast Asia LNK dropper
- Outsider Enterprise smishing PhaaS
- postcss-minify-selector-parser npm RAT
- SANDWORM_MODE AI-toolchain npm worm
- Sicoob.Sdk NuGet banking certificate stealer
- simonecorsi/mawesome GitHub Action compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- Storm-2603 parallel SharePoint ransomware intrusion
- TA4922
- TrapDoor crypto-stealer cross-ecosystem campaign
- UNK_DeadDrop developer repository phishing
- vpmdhaj OpenSearch npm cloud-secret stealer
- wshu.net npm credential-stealer campaign
- Xinference PyPI compromise
credit card theft
criminal infrastructure
critical infrastructure
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Operation Highland Velvet Ant authentication-stack backdoors
- Siemens ROX II zero-day exploit chain
- Velvet Ant
critical-infrastructure
CRM data theft
cron
cron persistence
- C0XMO Gafgyt DD-WRT botnet
- Langflow CVE-2026-33017 cryptominer SSH worm
- NadMesh AI-service and cloud-credential botnet
cross-platform
cross-platform malware
cross-project access
cross-site request forgery
cross-tenant isolation
CrownX
Crucio
crypto
crypto clipper
crypto wallets
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- wshu.net npm credential-stealer campaign
crypto-wallets
cryptocurrency
- Crypto Clipper Tor / USB worm
- Crypto supply-chain path to transaction authority
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Mastra
easy-day-jsnpm scope compromise - Polymarket npm wallet-drainer packages
- RemotePE
- SANDWORM_MODE AI-toolchain npm worm
- Solana FakeFix npm / PyPI developer stealer
- SourTrade browser-assembled malware malvertising
- UNK_DeadDrop developer repository phishing
cryptocurrency scam
cryptocurrency theft
- @copilot-mcp/apex macOS infostealer campaign
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake-reputation crypto clipboard hijacker
- Funnull RingH23 and MacCMS supply-chain attacks
- OkoBot cryptocurrency-wallet malware framework
- Silent Swap Google Notes crypto clipper
- Starland RAT
- UAT-11795
- UAT-11795 Starland / WLDR campaign
- Void Dokkaebi
cryptocurrency wallet theft
- Avalon / CrownX malware framework
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- jscrambler npm preinstall stealer
- Vidar / XMRig Factory-v3 malvertising campaign
cryptocurrency wallets
- Djinn Stealer
- Lazarus-linked Rollup polyfill npm malware
- OkoBot cryptocurrency-wallet malware framework
- PamStealer
cryptojacking
cryptominer
cryptomining
CSRF
CSRF token theft
Curious Serpens
CURP
Cursor
- Cursor Windows workspace-path binary hijack
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Sentry MCP Agentjacking
- UNK_DeadDrop developer repository phishing
Curve25519
custody APIs
CVE-2008-4128
CVE-2013-3307
CVE-2016-5681
CVE-2020-17103
CVE-2020-22653
CVE-2020-22658
CVE-2021-27137
CVE-2021-29441
CVE-2022-0492
CVE-2023-24932
CVE-2023-25717
CVE-2023-2868
CVE-2023-4346
CVE-2023-4966
CVE-2024-1708
CVE-2024-1709
CVE-2024-20399
CVE-2024-21182
CVE-2024-3094
CVE-2024-42009
CVE-2025-11371
CVE-2025-11837
CVE-2025-24054
CVE-2025-2492
CVE-2025-3248
CVE-2025-32975
CVE-2025-33053
CVE-2025-34291
CVE-2025-40947
CVE-2025-40948
CVE-2025-40949
CVE-2025-48595
CVE-2025-49113
CVE-2025-49704
CVE-2025-49706
CVE-2025-5777
CVE-2025-66376
CVE-2025-67038
CVE-2025-68686
CVE-2025-8088
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
CVE-2026-0257
CVE-2026-0770
CVE-2026-10520
CVE-2026-10523
CVE-2026-11405
CVE-2026-11645
CVE-2026-12569
CVE-2026-12957
CVE-2026-12958
CVE-2026-15409
CVE-2026-15410
CVE-2026-16232
CVE-2026-16723
CVE-2026-20127
CVE-2026-20182
CVE-2026-20230
CVE-2026-20245
CVE-2026-20253
CVE-2026-20262
CVE-2026-20896
CVE-2026-21513
CVE-2026-23111
CVE-2026-26980
CVE-2026-2699
CVE-2026-2701
CVE-2026-28318
CVE-2026-29059
CVE-2026-3300
CVE-2026-33017
CVE-2026-33691
CVE-2026-34908
CVE-2026-34909
CVE-2026-34910
CVE-2026-34926
CVE-2026-35273
CVE-2026-35616
CVE-2026-39987
CVE-2026-40138
CVE-2026-40139
CVE-2026-40140
CVE-2026-40141
CVE-2026-4020
CVE-2026-41091
CVE-2026-41940
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
CVE-2026-42271
CVE-2026-42533
CVE-2026-43074
CVE-2026-43284
CVE-2026-43499
CVE-2026-43500
CVE-2026-43503
CVE-2026-44338
CVE-2026-45247
CVE-2026-45498
CVE-2026-45659
CVE-2026-46242
CVE-2026-46300
CVE-2026-46331
CVE-2026-46817
CVE-2026-48172
CVE-2026-48276
CVE-2026-48277
CVE-2026-48281
CVE-2026-48282
CVE-2026-48283
CVE-2026-48285
CVE-2026-48307
CVE-2026-48313
CVE-2026-48314
CVE-2026-48315
CVE-2026-48316
CVE-2026-48558
CVE-2026-48907
CVE-2026-48908
CVE-2026-48939
CVE-2026-50522
CVE-2026-50751
CVE-2026-50752
CVE-2026-53359
CVE-2026-5426
CVE-2026-54420
CVE-2026-55255
CVE-2026-56290
CVE-2026-56291
CVE-2026-60137
CVE-2026-62144
CVE-2026-62145
CVE-2026-63030
CVE-2026-6682
CVE-2026-6683
CVE-2026-6684
CVE-2026-6685
CVE-2026-6686
CVE-2026-6687
CVE-2026-6688
CVE-2026-6875
CVE-2026-7473
CVE-2026-8037
CVE-2026-8451
CVE-2026-8461
CVE-2026-8732
CVE-2026-9082
CWE-22
CWE-352
CWE-502
CWE-77
CWE-78
CWE-829
cyber-espionage
CyberAv3ngers
cybercrime
- Dutch Police / NCSC 17-million-device botnet disruption
- First VPN
- Fox Tempest
- Funnull RingH23 and MacCMS supply-chain attacks
- Hunt.io global smishing infrastructure campaign
- JINX-0164
- Operation FlutterBridge FlutterShell macOS malvertising
- Outsider Enterprise smishing PhaaS
- Pirated media SilentCryptoMiner RAT campaign
- TA4922
- The Gentlemen ransomware
- UAT-11795
- UAT-11795 Starland / WLDR campaign
cybercrime ecosystem
cyberespionage
Cython
Czech Republic
D-Link
dangling resources
data exfiltration
- Ababil of Minab MOIS-linked recovery-destruction campaign
- AI-agent memory poisoning
- Cloud bucket namespace hijacking
- HOLLOWGRAPH
- MCP tool-description poisoning
- ModHeader browser-extension surveillance capability
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- SHADOW-AETHER AI-augmented Latin America intrusions
data exposure
data extortion
data leak site
data theft
- Accellion FTA exploitation campaign
- GoSerpent Southeast Asia espionage campaign
- Kairos data-extortion government payment
- Malware-Slop Claude user-data npm infostealer
- ShinyHunters
- UNC3753
data-exfiltration
database extortion
Datadog Security Labs
dataset processing
DAYLIGHT
DCloud
DCloud Uni-App
DcRAT
DD-WRT
DDNS
DDoS
- C0XMO Gafgyt DD-WRT botnet
- Dutch Police / NCSC 17-million-device botnet disruption
- Lucide Proxy npm browser DDoS botnet
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- RustDuck
DDoS botnet
DDoS-for-hire
dead drop
dead drop resolver
- ChocoPoC
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
dead-drop resolver
Debian
DEBULL
declarativeNetRequest
DeepAudit
DeepSeek
- AI-brand impersonation phishing and malvertising
- JetBrains AI plugin API-key theft
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Defender Advanced Hunting
Defender evasion
Defender exclusion
defense
defense evasion
- Cloud logging control-plane tampering
- GodDamn ransomware PoisonX BYOVD activity
- Ollama P2P cryptominer RAT campaign
- Pirated media SilentCryptoMiner RAT campaign
- ROADtools
- SourTrade browser-assembled malware malvertising
defense targeting
defense-evasion
DeFi
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- RemotePE
- TrapDoor crypto-stealer cross-ecosystem campaign
delayed execution
denial of service
- Citrix NetScaler CVE-2026-8451 memory overread
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- SolarWinds Serv-U CVE-2026-28318 exploitation
Deno
dependency confusion
- @marketfront / @tqm-mfe dependency-confusion stealer
- nodemon-sudo / tslint-conf runtime npm backdoor
- oob.moika.tech dependency-confusion environment stealer
deployment_status
deserialization
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Fastjson CVE-2026-16723 active exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Vertex AI staging-bucket squatting
destructive malware
destructive operations
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Iran-linked threat landscape: access optionality and evidence quality
- UAC-0145
detection engineering
DEV-0206
developer credential theft
developer credentials
developer endpoints
Developer ID abuse
developer identity
developer infrastructure
developer machines
- Agent localhost control-plane RCE
- Astro config blockchain C2 PR injection
- BufferZoneCorp RubyGems / Go module CI poisoning
- GuardFall AI-agent shell-guard bypass
- MCP stdio command-execution boundary
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
developer mode
developer platform
developer targeting
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Fake Corepack site infostealer and proxyware campaign
- FakeGit AgentBaiting and SmartLoader campaign
- Solana FakeFix npm / PyPI developer stealer
- ViteVenom / ChainVeil npm campaign
- Void Dokkaebi
developer tooling
- AsyncAPI generator / specs Miasma compromise
- Browser-based developer IDE OAuth token theft
- Cursor Windows workspace-path binary hijack
- Fake Corepack site infostealer and proxyware campaign
- ModHeader browser-extension surveillance capability
- Phantom squatting: AI-hallucinated domains
developer workstations
- Lazarus-linked Rollup polyfill npm malware
- Sentry MCP Agentjacking
- SleeperGem RubyGems maintainer-account compromise
developer-machine-fleet
developer-targeting
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- codexui-android OpenAI token stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- JetBrains AI plugin API-key theft
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- procwire / routecraft npm Windows dropper
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- UNK_DeadDrop developer repository phishing
- wshu.net npm credential-stealer campaign
developer-tools
developer-workstations
device lockout
device registration
device-code phishing
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kali365 device-code phishing expansion
DevOps
DevTools
DEWMODE
DGA
DIAMONDBACK
Digital Knowledge
digital wallets
DigitalOcean
Dindoor
diplomatic targeting
DirtyClone
DirtyFrag
Discord
discovery
disk wiping
distributed scanning
Djinn Stealer
DLL side-loading
- MIXEDKEY
- OceanLotus
- Pirated media SilentCryptoMiner RAT campaign
- SprySOCKS
- TELESHIM
- TELESHIM Middle East government espionage campaign
DLL sideloading
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Cavern
- Exposed WebDAV malware delivery lab and CURP campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- HelloNet ViPNet update-system campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation Dragon Weave Azure Blob C2 campaign
- Operation GriefLure Southeast Asia LNK dropper
- ScreenConnect freeware / AsyncRAT SEO campaign
- Screening Serpens
- Seedworm / MuddyWater
- Storm-2603 parallel SharePoint ransomware intrusion
- StrikeShark SharkLoader / Cobalt Strike campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
- Vidar / XMRig Factory-v3 malvertising campaign
DNS C2
DNS callback
DNS dead drop
DNS exfiltration
DNS threat intelligence
DNS tunneling
DNS-over-HTTPS
Docker
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- NadMesh AI-service and cloud-credential botnet
- Ulej / Flowerbed
Docker credentials
Docker images
Docker socket
document collection
document exfiltration
document theft
- ACR Stealer
- Gamaredon
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
DOGLEASH
domain squatting
domestic espionage
dormant accounts
DotNetNuke
DotnetTool
double extortion
downgrade risk
downloader
DPAPI
DPAPILoader
DPRK
- AI-augmented adversary operations
- Astro config blockchain C2 PR injection
- Contagious Interview SVG-steganography OtterCookie campaign
- macOS.Gaslight Rust backdoor
- PolinRider cross-ecosystem supply-chain campaign
driver loading
DroneLink
Dropbear
Dropbox
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Stock exchange executive mailbox espionage
dropper
Drupal
duckdns
Dutch Police
DWAgent
dynamic DNS
dynamic obfuscation
Dynu
e-commerce
Eagle Werewolf
Earth Lusca
East Asia
East Asia-linked
eBPF
- Atomic Arch AUR package hijack
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
Eclipse
Ed25519
edge appliance
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- CitrixBleed session-hijack wave
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ivanti Sentry CVE-2026-10520 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Quest KACE SMA CVE-2025-32975 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
edge appliances
edge application server
edge device
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- FortiBleed Fortinet credential exposure
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
edge devices
- Dutch Police / NCSC 17-million-device botnet disruption
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Russian state IP-camera military-logistics espionage
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
edge exploitation
Edge extension
edge service
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
edge services
editor profile import
EDR evasion
EDR killer
EDS5000
education
Egnyte
EKZ Infostealer
Elastic Security Labs
- Contagious Interview SVG-steganography OtterCookie campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
Elasticsearch
electric power sector
Electron
email exfiltration
email gateway
email infrastructure abuse
email theft
embedded systems
Emerald Sleet
ENCFORGE
encrypted C2
endpoint management
endpoint management abuse
endpoint response
endpoint-detection
endpoint-security
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
EndpointDlp.dll
energy sector
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- HelloNet ViPNet update-system campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
energy-sector
engineering
engineering software
enterprise application
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform CVE-2026-6875 exploitation
enterprise application exploitation
enterprise applications
Entra ID
Environment Management Hub
environment variable theft
- Braintree.Net NuGet payment skimmer
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
environment variables
environmental keying
epoll
Epsilon Stealer
ERP
eSentire TRU
ESG
espionage
- APT29
- Barracuda ESG zero-day backdoor campaign
- Cavern Manticore
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Cloud Atlas
- Dragonfly
- FishMonger
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghostwriter
- GoSerpent Southeast Asia espionage campaign
- GREYVIBE
- HelloNet ViPNet update-system campaign
- HOLLOWGRAPH
- Iran-linked threat landscape: access optionality and evidence quality
- Kimsuky / Emerald Sleet / TA427
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- OceanLotus
- Oman government Iranian-nexus webshell C2
- OP-512
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Pakistani law enforcement espionage convergence
- RemotePE
- ROADtools
- Russian state IP-camera military-logistics espionage
- ScarCruft Yanbian game-platform supply-chain attack
- Screening Serpens
- Seedworm / MuddyWater
- Showboat
- SideCopy
- SprySOCKS
- Stock exchange executive mailbox espionage
- TELESHIM Middle East government espionage campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Turla
- Turla STOCKSTAY backdoor operations
- UAC-0145
- Ulej / Flowerbed
- UNC6508
- UNC6692 SNOW malware social-engineering campaign
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- Webworm
Espressif ESP-IDF
ESXi
Ethereum
EtherHiding
- ACR Stealer
- Silent Swap Google Notes crypto clipper
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
ETW bypass
ETW patching
ETW tampering
Eurojust
Europe
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Webworm
Europe targeting
European Union
Europol
evasion
event log clearing
eventpoll
Everest Forms Pro
evidence quality
Evil Corp
EvilAI
Evilginx
excessive agency
exec_globals
exFAT
exfiltration
- codexui-android OpenAI token stealer
- JetBrains AI plugin API-key theft
- js-logger-pack Hugging Face exfiltration campaign
- Malware-Slop Claude user-data npm infostealer
exploit chain
exploit-development
exploit-kit
Exploit.in
exploitation
- Android Framework CVE-2025-48595 exploitation
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Langflow CVE-2025-34291 exploitation
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
exploitation attempts
ExploitGym
exposed attacker infrastructure
extension supply-chain
- Adblock for YouTube BadBlocker remote-script injection risk
- StegoAd Edge extension steganography campaign
external federation
extortion
- Accellion FTA exploitation campaign
- BlackFile / UNC6671 vishing extortion operation
- CrownX
- Klue Salesforce OAuth token abuse
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- ShinyHunters
- UNC3753
F5
F5 BIG-IP
Factory-v3
fake app store
fake CAPTCHA
- ClickFix CPaaS API-driven payload delivery
- GREYVIBE
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
fake certificate
fake crypto exchange
fake dating lures
fake gambling
fake installers
fake login screen
fake Microsoft Store
fake plugin
fake PoC
fake ransomware
fake recruiting
fake reputation
fake update
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Operation BlueDash multi-RMM workplace phishing
- Pirated media SilentCryptoMiner RAT campaign
FakeCaptcha
FakeGit
Fakeset
faketivism
FakeUpdates
FallSpy
FAMOUS CHOLLIMA
Famous Chollima
Fancy Bear
Fast16
FastAPI
FastCGI
Fastjson
fat JAR
FAT32
FatFs
FBI
FFmpeg
FIDO2
FIFA
file encryption
file exfiltration
file inflation
file sharing
file theft
File Transmission
file upload path traversal
file-system filter
FileFiend
FILEIO
fileless execution
fileless malware
filemanager
filename-injection
filesystem parser
finance
- oob.moika.tech dependency-confusion environment stealer
- Sicoob.Sdk NuGet banking certificate stealer
financial fraud
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- REF6045 / SCMBANKER Mexican banking fraud
financial sector
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- RemotePE
- SHADOW-AETHER AI-augmented Latin America intrusions
- Stock exchange executive mailbox espionage
financial services
- Seedworm / MuddyWater
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC3753
financial theft
financially motivated
FireAnt MetaKit
Firefox Add-ons
Firefox WebDriver BiDi
firewall
firewall management
firmware
firmware update
FishMonger
FlexPLM
FlockWiper
flow execution
Flowerbed
FLUIDLEECH
Flutter
FlutterShell
FOFA
folderOpen
foreign affairs targeting
foreign policy targeting
Forest Blizzard
Forg365
ForgCookie
Forgejo
FortiClient EMS
FortiGate
Fortinet
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
FortiOS
FortiSandbox
Fox Tempest
fraud
FREAKYPOLL
FreeBSD
Freedom365
freeware impersonation
Friendly Fire
FSB
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Russian intelligence commercial-messaging backup-key phishing
FSB Center 16
fscan
FTA
ftp.exe
Full Disk Access social engineering
Funnull
futex PI
Gafgyt
GaiaOS WebUI
Gamaredon
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
Gamaredon collaboration
gambling
gambling industry targeting
game cheats
GammaLoad
GammaPhish
GammaSteel
GammaWorm
Garble
Gardener
Gatekeeper bypass
GCS
Gemini CLI
GentleKiller
Germany
GHETTOVIBE
Ghost
ghost accounts
Ghost CMS
Ghost Networks
GhostLock
GHSA-6rmh-7xcm-cpxj
GHSA-6v3r-4p5c-mrp5
GHSA-qrpv-q767-xqq2
GHSA-xhcr-j4j9-3gh7
GIFTEDCROOK
Git
git.exe
Gitea
GitHub
- Astro config blockchain C2 PR injection
- Browser-based developer IDE OAuth token theft
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChocoPoC fake PoC supply-chain campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto supply-chain path to transaction authority
- Developer-tool config auto-execution
- FakeGit AgentBaiting and SmartLoader campaign
- GitHub / Packagist postinstall hook campaign
- GitHub API enumeration and access-token abuse
- Glassworm developer supply-chain botnet
- IronWorm npm Rust infostealer campaign
- JiaT75
- JINX-0164 crypto developer infrastructure campaign
- Malware-Slop Claude user-data npm infostealer
- Nx Console VS Code extension compromise
- Operation Muck and Load GitHub lure network
- PolinRider cross-ecosystem supply-chain campaign
- UNK_DeadDrop developer repository phishing
- Webworm
GitHub abuse
- AI-brand impersonation phishing and malvertising
- Armored Likho BusySnake campaign
- Fake-reputation crypto clipboard hijacker
GitHub Actions
- actions-cool GitHub Actions tag compromise
- AsyncAPI generator / specs Miasma compromise
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- Claude Code GitHub Action prompt-injection boundary
- codfish semantic-release-action tag compromise
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- Operation Muck and Load GitHub lure network
- SANDWORM_MODE AI-toolchain npm worm
- simonecorsi/mawesome GitHub Action compromise
- TeamPCP
- tj-actions and reviewdog compromise
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
GitHub API
GitHub App
GitHub CLI
GitHub dead drop
GitHub issue spam
GitHub OAuth
GitHub Pages abuse
GitHub payload delivery
GitHub release assets
GitHub Security Advisories
GitHub tokens
GitHub-hosted runners
GitLab
gitleaks
GitOps
Gleaming Pisces
gleeze.com
GlobalProtect
Gmail
Go
- BufferZoneCorp RubyGems / Go module CI poisoning
- Ollama P2P cryptominer RAT campaign
- Operation Muck and Load GitHub lure network
- shopsprint/decimal Go typosquat DNS backdoor
- The Gentlemen ransomware
Go loader
Go malware
- GoSerpent Southeast Asia espionage campaign
- NadMesh AI-service and cloud-credential botnet
- Vidar / XMRig Factory-v3 malvertising campaign
Go modules
Go2Tunnel
GodDamn ransomware
Godzilla
GoEdge
GoFile
Golang
Golang malware
GOLD PRELUDE
Google Ads
Google Analytics telemetry
Google API
Google Calendar
Google Chrome
Google Cloud
Google Cloud Logging
Google Cloud Storage
Google credential theft
Google Docs
Google Drive
Google Notes
Google Play
Google Play Protect
Google redirect abuse
Google Sheets
Google Stitch
Google Threat Intelligence Group
Google Workspace
Goose
GoSerpent
government
- Cavern Manticore
- HelloNet ViPNet update-system campaign
- Kairos data-extortion government payment
- Kimsuky / Emerald Sleet / TA427
- Oman government Iranian-nexus webshell C2
government targeting
- Armored Likho
- Armored Likho BusySnake campaign
- BINDCLOAK
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Cloud Atlas
- FishMonger
- GoSerpent Southeast Asia espionage campaign
- Mustang Panda
- Russian intelligence commercial-messaging backup-key phishing
- SHADOW-AETHER AI-augmented Latin America intrusions
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TELESHIM Middle East government espionage campaign
government-impersonation
GPT
GPT-5.6 Sol
Gradio
Grandoreiro
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
granular access tokens
GraphSpy
Gravity SMTP
GRE
GREYVIBE
group
groups
- APT29
- CL-STA-1062
- CL-STA-1114 / Void Blizzard
- Dragonfly
- Fox Tempest
- JINX-0164
- OP-512
- TA4922
- Turla
- UAT-11795
- UNC3753
- UNC6508
- VerdantBamboo
- Void Dokkaebi
- Webworm
gRPC
gRPC C2
GRU
gs-netcat
GS-Netcat
Gshell
GTIG
GUE
guest-to-host escape
Guildma
hack-and-leak
HackIndex
hacktivist persona
Hades
Hajime
hallucination
HalluSquatting
Handala
HappyDoor
HAR files
hard-coded secrets
HarmonyLib
HashiCorp Vault
HavocKiller
headless browser
healthcare
heap buffer overflow
heap pointer disclosure
HelloBackdoor
HelloCleaner
HelloDoor
HelloExecutor
HelloInjector
HelloNet
HelloProxy
HellsGate
Helm
Hermes Agent
HexKiller
hidden backdoor
hidden instructions
hidden service
high explosives
higher education
HOLLOWGRAPH
Honduras
HONESTCUE
Hong Kong infrastructure
hospitality targeting
Host Radar
host surveillance
hosting control plane
hosting provider
hosting providers
hotel targeting
Howling Scorpius
HPC
HR lures
HTA
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- UAT-11795 Starland / WLDR campaign
HTML comments
HTML email
HTML smuggling
HTTP C2
HTTP/2
HttpMalice
HTTPS C2
HTTPS exfiltration
HTTPSpy
Hugging Face
- forge-jsxy
- Hugging Face autonomous-agent production intrusion
- js-logger-pack Hugging Face exfiltration campaign
Hunt.io
- GHOST STADIUM FIFA World Cup ticket phishing
- Malicious infrastructure provider concentration
- Quest KACE SMA CVE-2025-32975 exploitation
- xlabs_v1 DDoS-for-hire IoT botnet
Huntress
Hyadina
hybrid threat actor
hydropower
Hydropower Cooperation Project Proposal.zip
hypervisor escape
Hyunwoo Kim
I-SOON
iCagenda
ICE
ICONICSTEALER
ICS
- Dragonfly
- Iran-linked threat landscape: access optionality and evidence quality
- KNX Protocol CVE-2023-4346 KEV exploitation
IDE extension
IDE plugins
ide.cfm
identity
identity attacks
identity compromise
identity infrastructure
identity security
identity-first intrusion
IDEs
IFEO persistence
IIOP
IIS
IKEv1
image recognition
iMessage
Impacket
impersonation
implant
import-time execution
- Lazarus-linked Rollup polyfill npm malware
- MrMustard PyPI credential-stealer compromise
- Solana FakeFix npm / PyPI developer stealer
- ViteVenom / ChainVeil npm campaign
improper privilege management
in-memory DLL loading
in-memory plugins
incident response
- Check Point VPN CVE-2026-50751 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Hugging Face autonomous-agent production intrusion
- Iran-linked threat landscape: access optionality and evidence quality
- Klue Salesforce OAuth token abuse
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Malicious infrastructure provider concentration
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
incident-response
IndexedDB
India
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation DragonReturn India tax-season DcRAT campaign
India-nexus
Indian government
indirect prompt injection
- AI browser-extension confused deputy
- AI-agent memory poisoning
- AI-augmented adversary operations
- Azure DevOps MCP pull-request prompt injection
- MCP tool-description poisoning
- Sentry MCP Agentjacking
indirect syscalls
Indonesia
industrial control
industrial control systems
industrial targeting
INFINITERED
Infoblox Threat Intel
information disclosure
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FortiOS CVE-2025-68686 symlink-persistence bypass
infostealer
- @copilot-mcp/apex macOS infostealer campaign
- ACR Stealer
- Armored Likho
- Armored Likho BusySnake campaign
- BusySnake Stealer
- codexui-android OpenAI token stealer
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- Fake Corepack site infostealer and proxyware campaign
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164 crypto developer infrastructure campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Operation Muck and Load GitHub lure network
- PamStealer
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- TamperedChef-style productivity malware clusters
- Telnyx PyPI TeamPCP compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- wshu.net npm credential-stealer campaign
InfoTeCS
infrastructure
- First VPN
- Funnull RingH23 and MacCMS supply-chain attacks
- GHOST STADIUM FIFA World Cup ticket phishing
- Hunt.io global smishing infrastructure campaign
- Malicious infrastructure provider concentration
infrastructure disruption
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NetNut / Popa residential proxy network disruption
- StealC / Amadey infrastructure disruption
initial access broker
initial-access
- AI-augmented adversary operations
- ClickOnce COM hijacking abuse
- Operation Endgame SocGholish disruption
Injective Labs
input capture
install-time execution
- @copilot-mcp/apex macOS infostealer campaign
- jscrambler npm preinstall stealer
- MYRA RAT
- Solana FakeFix npm / PyPI developer stealer
install-time-execution
install.res.1033.dll
Integration Broker
Intercolo
internet-facing admin surface
internet-facing appliance
internet-facing applications
investment scam
InvisibleFerret
iOS
IoT
- Dutch Police / NCSC 17-million-device botnet disruption
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- JDY SOHO / IoT reconnaissance botnet
- Russian state IP-camera military-logistics espionage
IoT botnet
- AryStinger legacy-router recon proxy network
- C0XMO Gafgyt DD-WRT botnet
- RustDuck
- TuxBot v3 Evolution IoT botnet framework
- xlabs_v1 DDoS-for-hire IoT botnet
IP cameras
IP-in-IP
IPFS
IPsec
IPv6
ipynbdiff
Iran
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Cavern
- Cavern Manticore
- Handala
- Iran-linked threat landscape: access optionality and evidence quality
- Langflow CVE-2025-34291 exploitation
- Screening Serpens
- Seedworm / MuddyWater
Iran-nexus
IRGC
IronWorm
ischhfd83
Island Security Research
- Adblock for YouTube BadBlocker remote-script injection risk
- FakeGit AgentBaiting and SmartLoader campaign
ISO image
Israel
IT providers
Italian foreign-policy targeting
Italy targeting
Ivanti Sentry
JADEPUFFER
Jamf Threat Labs
Januscape
Japan
JARLEASH
Java
Java malware
JavaScript
- Astro config blockchain C2 PR injection
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Mastra
easy-day-jsnpm scope compromise - nodemon-sudo / tslint-conf runtime npm backdoor
- npm install explicit-trust controls
- Operation DangerousPassword axios npm compromise
- Operation XENOFISCAL SideCopy XenoRAT campaign
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- TaskWeaver
- Ulej / Flowerbed
- wshu.net npm credential-stealer campaign
JavaScript bridge
JavaScript execution
JavaScript injection
JavaScript loader
JavaScript malware
JavaScript masquerading
JavaScript tampering
JavaScriptCore
JCE
JDY
Jellyfin
Jenkins
JetBrains
JetBrains Marketplace
JetStream
JFrog
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Lucide Proxy npm browser DDoS botnet
JFrog Security Research
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- Solana FakeFix npm / PyPI developer stealer
JINX-0164
joblib
Joomla
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- WP-SHELLSTORM webshell access brokerage
Joomla Content Editor
Joomla JCE
Joomlack
JoomShaper
journalists
JSCoreRunner
jscrambler
Jscrambler
JScript
JSON
JSON:API
JSONKeeper
JSONPing
JSP web shell
JuicyPotato
Jupyter Notebook
JustWatch
JXA downloader
K1MORPHER
Kairos
Kaitori
Kali365
Kaspersky
Kaspersky GReAT
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- OkoBot cryptocurrency-wallet malware framework
Kaspersky Securelist
Kazakhstan
KAZUAR
KAZUAR overlap
Keitaro
Keksec
Kemp LoadMaster
kernel driver
kernel instrumentation
kernelCTF
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
KEV
- Drupal Core CVE-2026-9082 exploitation
- Langflow CVE-2025-34291 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
Keychain theft
keychain theft
KeyHunter
keylogger
- forge-jsxy
- js-logger-pack Hugging Face exfiltration campaign
- OkoBot cryptocurrency-wallet malware framework
- TELEPUZ
keylogging
Kimsuky
Klue
KnowledgeDeliver
KNUCKLEBALL
KNX
KNX Association
KNX Protocol
KongTuke
KORKERDS
Kratos
Kubernetes
- @copilot-mcp/apex macOS infostealer campaign
- Argo CD repo-server unauthenticated RCE
- Crypto supply-chain path to transaction authority
- Hugging Face autonomous-agent production intrusion
- MrMustard PyPI credential-stealer compromise
- NadMesh AI-service and cloud-credential botnet
KV-botnet
KVM
KVM escape
kvmCTF
L2TP/IPSec
LA Metro
LabubaPanel
LabubaRAT
LangChain
Langflow
- ENCFORGE
- JADEPUFFER Langflow agentic ransomware
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
LangFlow
LangGraph
Language Servers for AWS
Lantronix
LapDogs
Laravel
Laravel deserialization
lateral movement
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- GodDamn ransomware PoisonX BYOVD activity
- Hugging Face autonomous-agent production intrusion
- Quest KACE SMA CVE-2025-32975 exploitation
- The Gentlemen ransomware
lateral-movement
Latin America
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- SHADOW-AETHER AI-augmented Latin America intrusions
LaunchAgent
- @copilot-mcp/apex macOS infostealer campaign
- CrashStealer macOS notarized-dropper campaign
- macOS.Gaslight Rust backdoor
launchctl
LAUNDRY BEAR
law enforcement
- Dutch Police / NCSC 17-million-device botnet disruption
- Kratos Microsoft 365 PhaaS and infrastructure disruption
law enforcement targeting
law-enforcement-disruption
LayerX
Lazarus
- Famous Chollima Packagist dev-branch loader
- Lazarus-linked Rollup polyfill npm malware
- Operation DangerousPassword axios npm compromise
- RemotePE
- StegaBin Pastebin-steganography npm campaign
LD_PRELOAD
LDAP
leaked credentials
LEASHTEST
least privilege
Ledger
legacy botnet hijacking
legacy infrastructure
legacy software
legal sector
LegionRelay
Leo Platform
Level RMM
LevelBlue
Lexfo
libcurl
liblzma
libp2p
libpeconv
lifecycle hooks
lifecycle-hooks
Lightning Shared Scooter Co.
Linksys
Linux
- Atomic Arch AUR package hijack
- Djinn Stealer
- ENCFORGE
- GitHub / Packagist postinstall hook campaign
- IronWorm npm Rust infostealer campaign
- Januscape KVM CVE-2026-53359 guest-to-host escape
- js-logger-pack Hugging Face exfiltration campaign
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- MYRA RAT
- Ollama P2P cryptominer RAT campaign
- Operation DangerousPassword axios npm compromise
- Operation Highland Velvet Ant authentication-stack backdoors
- PCPJack cloud SMTP relay network
- QuimaRAT
- Showboat
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- XZ Utils backdoor
Linux kernel
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux pedit COW CVE-2026-46331 local privilege escalation
Linux malware
Linux networking devices
LiteLLM
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- Telnyx PyPI TeamPCP compromise
LiteSpeed
living off the land
living-off-the-land
living-off-the-land binaries
LLM
- AI-augmented adversary operations
- GREYVIBE
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Ollama P2P cryptominer RAT campaign
LLM security
LLM-assisted malware
- Exposed WebDAV malware delivery lab and CURP campaign
- REF6045 / SCMBANKER Mexican banking fraud
- TuxBot v3 Evolution IoT botnet framework
LLM-driven intrusion
LLMjacking
LMS
LNK
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Armored Likho BusySnake campaign
- Avalon / CrownX malware framework
- Crypto Clipper Tor / USB worm
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation GriefLure Southeast Asia LNK dropper
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Photo ZIP hospitality Node.js implant campaign
- SideCopy
- UAC-0226 / SHADOW-EARTH-066
LNK files
load balancer
loader
- Famous Chollima Packagist dev-branch loader
- MIXEDKEY
- RustDuck
- StealC / Amadey infrastructure disruption
- TaskWeaver
LOADLOOP
local LLMs
local privilege escalation
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux pedit COW CVE-2026-46331 local privilege escalation
- MiniPlasma Windows Cloud Filter LPE exploitation
local-file-inclusion
localhost
log poisoning
logging
login item persistence
LOLBins
- ClickFix CPaaS API-driven payload delivery
- Exposed WebDAV malware delivery lab and CURP campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
long-horizon autonomy
long-lived tokens
long-term access
LONGLEASH
LONGSTREAM
LOOKVALJS
LOOKVALPS
loopback
Loophole
low-confidence attribution
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- HOLLOWGRAPH
- WhatsApp VBScript ManageEngine RMM campaign
LPE
LS-DYNA
LSASS
LSHIY
LSSC
Lua
LuaJIT
Lumen
Lumen Black Lotus Labs
Lumma Stealer
Luna Moth
Luno
Lyceum
M-RED-TEAM
MaaS
- ACR Stealer
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
MAC address
MacCMS
Maccy impersonation
machine-learning
macOS
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- macOS.Gaslight Rust backdoor
- Operation DangerousPassword axios npm compromise
- Operation FlutterBridge FlutterShell macOS malvertising
- PamStealer
- QuimaRAT
macOS malware
MaDoO Blaster
Magento
MagicYUV
mail server compromise
mail-argenta
mailbox compromise
mailbox theft
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Stock exchange executive mailbox espionage
MAIN world injection
maintainer compromise
- Injective SDK npm wallet stealer
- Mastra
easy-day-jsnpm scope compromise - MrMustard PyPI credential-stealer compromise
- Operation DangerousPassword axios npm compromise
maintainer persona
maintainer-compromise
malicious dataset
malicious GPO
malicious packages
malicious plugin
malicious releases
malicious signed driver
malvertising
- ACR Stealer
- AI-brand impersonation phishing and malvertising
- Fake Corepack site infostealer and proxyware campaign
- Lucide Proxy npm browser DDoS botnet
- Operation FlutterBridge FlutterShell macOS malvertising
- SourTrade browser-assembled malware malvertising
- StealC / Amadey infrastructure disruption
- TamperedChef-style productivity malware clusters
- Vidar / XMRig Factory-v3 malvertising campaign
malware
- ACR Stealer
- AI-augmented adversary operations
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BINDCLOAK
- binding.gyp npm CI/CD worm
- BusySnake Stealer
- CanisterWorm
- Cavern
- ChocoPoC
- CrownX
- Crypto Clipper Tor / USB worm
- Djinn Stealer
- ENCFORGE
- Fast16
- forge-jsxy
- GigaWiper
- HOLLOWGRAPH
- IronWorm npm Rust infostealer campaign
- LabubaRAT
- macOS.Gaslight Rust backdoor
- MIXEDKEY
- MODBEACON
- MYRA RAT
- Operation Endgame SocGholish disruption
- PamStealer
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- RedWing
- RemotePE
- RustDuck
- SCMBANKER
- Showboat
- SprySOCKS
- Starland RAT
- StealC / Amadey infrastructure disruption
- STOCKSTAY
- StrikeShark SharkLoader / Cobalt Strike campaign
- TA4922
- TamperedChef-style productivity malware clusters
- TaskWeaver
- TeamPCP
- TELEPUZ
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Umbrij
- UNC6692 SNOW malware social-engineering campaign
- WLDR agent
malware analysis
malware delivery
- ClickFix CPaaS API-driven payload delivery
- Fake Corepack site infostealer and proxyware campaign
- FakeGit AgentBaiting and SmartLoader campaign
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Microsoft Q2 2026 email and Teams phishing landscape
- TELEPUZ ClickFix / VIDAR campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
malware framework
Malware-as-a-Service
malware-as-a-service
- LabubaRAT
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- StealC / Amadey infrastructure disruption
malware-signing-as-a-service
MALXMR
managed file transfer
- Progress ShareFile Storage Zone Controller security threat
- SolarWinds Serv-U CVE-2026-28318 exploitation
managed service provider
ManageEngine Endpoint Central
management plane
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Manifest V3
Manifold Security
manufacturing
Mapbox
marimo
MARKETMAKER
marketplace abuse
marketplace trust
MarkiRAT
Maven Central
mawesome
Mbed
McAfee Labs
McMx
MCP
- @copilot-mcp/apex macOS infostealer campaign
- Agent localhost control-plane RCE
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NadMesh AI-service and cloud-credential botnet
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
MCP credentials
media processing
medical research
Mekotio
memfd
memory corruption
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- GitLab Oj notebook-diff authenticated RCE chain
memory disclosure
- Citrix NetScaler CVE-2026-8451 memory overread
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
memory implant
memory overread
memory poisoning
memory-only malware
merchant credential theft
MeshAgent
MeshCentral
MetaMask
MEV bot lure
Mexican banking fraud
Mexico
- Exposed WebDAV malware delivery lab and CURP campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SHADOW-AETHER AI-augmented Latin America intrusions
MFA bypass
- 0ktapus phishing campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Azure CLI LSHIY password-spray campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- CitrixBleed session-hijack wave
- Evilginx and device-code phishing open-directory cluster
- ROADtools
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
MFA fatigue
MFA-bypass
Miasma
- AI scanner anti-analysis
- AsyncAPI generator / specs Miasma compromise
- binding.gyp npm CI/CD worm
- Developer-tool config auto-execution
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- npm install explicit-trust controls
MicroPython
Microsoft
- Agent localhost control-plane RCE
- AI-agent memory poisoning
- AI-brand impersonation phishing and malvertising
- Azure DevOps MCP pull-request prompt injection
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- CL-STA-1114 / Void Blizzard
- Fox Tempest
- MCP tool-description poisoning
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
Microsoft .NET
Microsoft 365
- Azure CLI LSHIY password-spray campaign
- BlackFile / UNC6671 vishing extortion operation
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- HOLLOWGRAPH
- Kali365 device-code phishing expansion
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- O-UNC-066 Entra passkey vishing
Microsoft 365 Copilot
Microsoft Authentication Broker
Microsoft Defender
Microsoft Defender Security Research
Microsoft dev tunnels
Microsoft Digital Crimes Unit
Microsoft Edge
Microsoft Edge Add-ons
Microsoft Edge Extensions Security Team
Microsoft Entra ID
- Azure CLI LSHIY password-spray campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- O-UNC-066 Entra passkey vishing
Microsoft Graph
Microsoft Identity Platform
Microsoft Office SharePoint
Microsoft Security Blog
Microsoft SQL Server
Microsoft Teams
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft Teams external-chat phishing
- Operation BlueDash multi-RMM workplace phishing
- UNC6692 SNOW malware social-engineering campaign
Microsoft Threat Intelligence
Microsoft Windows Hardware Compatibility Publisher
Microsoft-signed binary abuse
Middle East
- BINDCLOAK
- Malicious infrastructure provider concentration
- Showboat
- TELESHIM Middle East government espionage campaign
middleware
Midnight Blizzard
military logistics
military research
Mimikatz
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
Minecraft DDoS
Mini Shai-Hulud
- AsyncAPI generator / specs Miasma compromise
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
MiniJunk
MiniPlasma
MINIRAT
MINIRECON
Ministry of Finance
- Operation DragonReturn India tax-season DcRAT campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
MiniUpdate
MIPS embedded devices
Mirai
- Malicious infrastructure provider concentration
- NetNut / Popa residential proxy network disruption
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Mirai-derived botnet
Mistic
MITRE ATT&CK T1005
MITRE ATT&CK T1562
mixed boolean arithmetic
MIXEDKEY
MLTBackdoor
mnemonic theft
mobile
Mobile Access
mobile banking fraud
mobile device management
mobile devices
mobile malware
MobileIron Sentry
MODBEACON
Model Context Protocol
- Agent localhost control-plane RCE
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NadMesh AI-service and cloud-credential botnet
model poisoning
model weights
model-provider abuse
ModeloRAT
ModHeader
modular malware
module-proxy
MOIS
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Cavern
- Cavern Manticore
- Handala
- Iran-linked threat landscape: access optionality and evidence quality
- Seedworm / MuddyWater
Monero
Monero mining
Monster ransomware
Mozi
MpClient.dll
MpExtMs.exe
MPR network provider
Mr_Rot13
MSBuild
msgpack
mshta
- ACR Stealer
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- UAT-11795 Starland / WLDR campaign
MSI
MSP
- ConnectWise ScreenConnect exploitation wave
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
MSSQL
mTLS
Muck and Load
MuddyWater
- Cavern Manticore
- Iran-linked threat landscape: access optionality and evidence quality
- Langflow CVE-2025-34291 exploitation
- Seedworm / MuddyWater
Mullvad VPN
Multi-Domain Security Management
multi-tenant cloud
Mustang Panda
Mustard Tempest
mutable tags
MYRA
MySQL
Mysterious Elephant
Mythos
n8n
Nacos
NadMesh
named pipes
namespace recycling
namespace squatting
NAS targeting
nation-state
national identity records
native addon
native extension
NativeAOT
NATO
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Russian state IP-camera military-logistics espionage
NATS
NCSC-NL
Nebo
Nebula Security
negotiation
Neo-reGeorg
nested virtualization
Neteller
Netherlands
- Dutch Police / NCSC 17-million-device botnet disruption
- Russian state IP-camera military-logistics espionage
Netlify abuse
NetNut
NetScaler
NetScaler ADC
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Citrix NetScaler CVE-2026-8451 memory overread
NetScaler Gateway
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Citrix NetScaler CVE-2026-8451 memory overread
network infrastructure
network infrastructure exploitation
network policies
network-share exfiltration
Nextcloud
Nextcloud Flow
nf_tables
nftables
NGINX
Nginx
Nginx module
Ngrok C2
Nigeria-nexus
NirSoft
no attribution
No-IP
node-gyp
node-ipc
node-pty
Node.js
- Fake Corepack site infostealer and proxyware campaign
- nodemon-sudo / tslint-conf runtime npm backdoor
- Seedworm / MuddyWater
- TaskWeaver
Node.js implant
Node.js malware
North Korea
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- Kimsuky / Emerald Sleet / TA427
- Lazarus-linked Rollup polyfill npm malware
- macOS.Gaslight Rust backdoor
- Operation DangerousPassword axios npm compromise
- PolinRider cross-ecosystem supply-chain campaign
- RemotePE
- ScarCruft Yanbian game-platform supply-chain attack
- StegaBin Pastebin-steganography npm campaign
- UNK_DeadDrop developer repository phishing
- Void Dokkaebi
notarized malware
- CrashStealer macOS notarized-dropper campaign
- Operation FlutterBridge FlutterShell macOS malvertising
notification interception
npm
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- AI scanner anti-analysis
- art-template Coruna-style iOS watering-hole compromise
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- codexui-android OpenAI token stealer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- forge-jsxy
- GitHub / Packagist postinstall hook campaign
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Immobiliare Labs Backstage plugins npm compromise
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Lucide Proxy npm browser DDoS botnet
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MYRA RAT
- node-ipc 2026 npm maintainer-account compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- npm install explicit-trust controls
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- Solana FakeFix npm / PyPI developer stealer
- StegaBin Pastebin-steganography npm campaign
- TeamPCP
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- ViteVenom / ChainVeil npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
- wshu.net npm credential-stealer campaign
npm lifecycle hook
- Mastra
easy-day-jsnpm scope compromise - Operation DangerousPassword axios npm compromise
- procwire / routecraft npm Windows dropper
npm supply-chain
npm token theft
npm tokens
npm v12
npx
NSecKrnl.sys
NTDS.dit
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Storm-2603 parallel SharePoint ransomware intrusion
NTFS ADS
NTLM
nuclear weapons
NuGet
- Braintree.Net NuGet payment skimmer
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Sicoob.Sdk NuGet banking certificate stealer
Nuitka
null-byte padding
NVGRE
NVIDIA impersonation
O-UNC-066
OAuth
- Azure CLI LSHIY password-spray campaign
- Browser-based developer IDE OAuth token theft
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
OAuth abuse
OAuth client credentials
OAuth device authorization grant
OAuth redirect
OAuth token abuse
OAuth token exposure
OAuth tokens
- codexui-android OpenAI token stealer
- GitHub API enumeration and access-token abuse
- Klue Salesforce OAuth token abuse
OBF networks
obfuscation
obfuscator.io
Oblivion
obsolete software
Octopi365
OFAC
official store compromise
Offshore LC
OIDC
- AsyncAPI generator / specs Miasma compromise
- Claude Code GitHub Action prompt-injection boundary
- codfish semantic-release-action tag compromise
- GitHub Actions OIDC subject-claim collisions
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
OilRig
Oj
OkoBot
Okta
- 0ktapus phishing campaign
- BlackFile / UNC6671 vishing extortion operation
- Kali365 device-code phishing expansion
- Okta support-system compromise
Okta Threat Intelligence
OKX
Ollama
Oman
Omnibox
OneDrive
OneDrive access
opaque predicates
open directory
Open Interpreter
Open WebUI
OpenAI
OpenAI Codex
OpenClaw
opencode
OpenConnect
OpenHands
OpenSearch
OpenShield
OpenSSH
OpenVPN
OpenVPN-shaped UDP
OpenVSX
operation
Operation BlueDash
Operation DangerousPassword
Operation Endgame
Operation Highland
operational relay box
Operational Relay Box
operational resilience
operational security
operational technology
operations
- 0ktapus phishing campaign
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Accellion FTA exploitation campaign
- actions-cool GitHub Actions tag compromise
- Adblock for YouTube BadBlocker remote-script injection risk
- Adobe ColdFusion APSB26-68 CVE bonanza
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Argo CD repo-server unauthenticated RCE
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Armored Likho BusySnake campaign
- art-template Coruna-style iOS watering-hole compromise
- AryStinger legacy-router recon proxy network
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Avalon / CrownX malware framework
- Azure CLI LSHIY password-spray campaign
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Barracuda ESG zero-day backdoor campaign
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BlackFile / UNC6671 vishing extortion operation
- BufferZoneCorp RubyGems / Go module CI poisoning
- C0XMO Gafgyt DD-WRT botnet
- CanisterWorm
- CCleaner signed-update compromise
- Check Point VPN CVE-2026-50751 exploitation
- Chinese-language PhaaS wallet-tokenization ecosystem
- Chrome live-wallpaper extension ad-fraud network
- Chrome V8 CVE-2026-11645 exploitation
- CircleCI 2023 customer secret exposure incident
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- CitrixBleed session-hijack wave
- CL-STA-1062 Southeast Asia government and energy intrusions
- ClickFix CPaaS API-driven payload delivery
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- ConnectWise ScreenConnect exploitation wave
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto Clipper Tor / USB worm
- DAEMON Tools Lite supply-chain compromise
- DCloud Uni-App scam infrastructure ecosystem
- Drupal Core CVE-2026-9082 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Everest Forms Pro CVE-2026-3300 exploitation
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Fastjson CVE-2026-16723 active exploitation
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GHOST STADIUM FIFA World Cup ticket phishing
- Gitea Docker CVE-2026-20896 probing
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitLab Oj notebook-diff authenticated RCE chain
- Glassworm developer supply-chain botnet
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Gravity SMTP CVE-2026-4020 exploitation
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- HelloNet ViPNet update-system campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hugging Face autonomous-agent production intrusion
- Hunt.io global smishing infrastructure campaign
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JADEPUFFER Langflow agentic ransomware
- Januscape KVM CVE-2026-53359 guest-to-host escape
- JDY SOHO / IoT reconnaissance botnet
- JetBrains AI plugin API-key theft
- JINX-0164 crypto developer infrastructure campaign
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- js-logger-pack Hugging Face exfiltration campaign
- Kairos data-extortion government payment
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- LiteLLM compromise
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Lucide Proxy npm browser DDoS botnet
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mini Shai-Hulud npm/PyPI worm campaign
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- node-ipc 2026 npm maintainer-account compromise
- Nx Console VS Code extension compromise
- Okta support-system compromise
- Ollama P2P cryptominer RAT campaign
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Operation BlueDash multi-RMM workplace phishing
- Operation DangerousPassword axios npm compromise
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation Endgame SocGholish disruption
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation Muck and Load GitHub lure network
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Outsider Enterprise smishing PhaaS
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Patriot Bait AI-assisted C2 botnet
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Perplexity AI-spoofing Chromium extension search hijacker
- Photo ZIP hospitality Node.js implant campaign
- Pirated media SilentCryptoMiner RAT campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- PraisonAI CVE-2026-44338 rapid exploitation
- procwire / routecraft npm Windows dropper
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- REF6045 / SCMBANKER Mexican banking fraud
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- ScreenConnect freeware / AsyncRAT SEO campaign
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- Siemens ROX II zero-day exploit chain
- Silent Swap Google Notes crypto clipper
- simonecorsi/mawesome GitHub Action compromise
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SleeperGem RubyGems maintainer-account compromise
- SolarWinds Serv-U CVE-2026-28318 exploitation
- SourTrade browser-assembled malware malvertising
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Storm-2603 parallel SharePoint ransomware intrusion
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TamperedChef-style productivity malware clusters
- TeamPCP
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Telnyx PyPI TeamPCP compromise
- Thailand healthcare RAR / Python stealer campaign
- tj-actions and reviewdog compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trend Micro Apex One CVE-2026-34926 exploitation
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Turla STOCKSTAY backdoor operations
- TuxBot v3 Evolution IoT botnet framework
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795 Starland / WLDR campaign
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UNK_DeadDrop developer repository phishing
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- VerdantBamboo appliance BRICKSTORM operation
- ViteVenom / ChainVeil npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- WhatsApp VBScript ManageEngine RMM campaign
- Windmill CVE-2026-29059 active exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- wshu.net npm credential-stealer campaign
- Xinference PyPI compromise
- XZ Utils backdoor
OpFauxSign
ops
- 0ktapus phishing campaign
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Accellion FTA exploitation campaign
- actions-cool GitHub Actions tag compromise
- Adblock for YouTube BadBlocker remote-script injection risk
- Adobe ColdFusion APSB26-68 CVE bonanza
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Argo CD repo-server unauthenticated RCE
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Armored Likho BusySnake campaign
- art-template Coruna-style iOS watering-hole compromise
- AryStinger legacy-router recon proxy network
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Avalon / CrownX malware framework
- Azure CLI LSHIY password-spray campaign
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Barracuda ESG zero-day backdoor campaign
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BlackFile / UNC6671 vishing extortion operation
- Braintree.Net NuGet payment skimmer
- BufferZoneCorp RubyGems / Go module CI poisoning
- C0XMO Gafgyt DD-WRT botnet
- CCleaner signed-update compromise
- Check Point VPN CVE-2026-50751 exploitation
- Chinese-language PhaaS wallet-tokenization ecosystem
- ChocoPoC fake PoC supply-chain campaign
- Chrome live-wallpaper extension ad-fraud network
- Chrome V8 CVE-2026-11645 exploitation
- CircleCI 2023 customer secret exposure incident
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- CitrixBleed session-hijack wave
- CL-STA-1062 Southeast Asia government and energy intrusions
- CL-STA-1114 Zimbra webmail espionage
- ClickFix CPaaS API-driven payload delivery
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- ConnectWise ScreenConnect exploitation wave
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Crypto Clipper Tor / USB worm
- DAEMON Tools Lite supply-chain compromise
- DCloud Uni-App scam infrastructure ecosystem
- Drupal Core CVE-2026-9082 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Everest Forms Pro CVE-2026-3300 exploitation
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Fastjson CVE-2026-16723 active exploitation
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Forg365 Microsoft 365 PhaaS
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GHOST STADIUM FIFA World Cup ticket phishing
- Gitea Docker CVE-2026-20896 probing
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitLab Oj notebook-diff authenticated RCE chain
- Glassworm developer supply-chain botnet
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Gravity SMTP CVE-2026-4020 exploitation
- HackerBot Claw GitHub Actions exploitation campaign
- HelloNet ViPNet update-system campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hugging Face autonomous-agent production intrusion
- Hunt.io global smishing infrastructure campaign
- Immobiliare Labs Backstage plugins npm compromise
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JADEPUFFER Langflow agentic ransomware
- Januscape KVM CVE-2026-53359 guest-to-host escape
- JDY SOHO / IoT reconnaissance botnet
- JetBrains AI plugin API-key theft
- JINX-0164 crypto developer infrastructure campaign
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- js-logger-pack Hugging Face exfiltration campaign
- jscrambler npm preinstall stealer
- Kairos data-extortion government payment
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- LiteLLM compromise
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Lucide Proxy npm browser DDoS botnet
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mini Shai-Hulud npm/PyPI worm campaign
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- ModHeader browser-extension surveillance capability
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- node-ipc 2026 npm maintainer-account compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- NuGet game-cheat DotnetTool pepesoft campaign
- Nx Console VS Code extension compromise
- O-UNC-066 Entra passkey vishing
- OkoBot cryptocurrency-wallet malware framework
- Okta support-system compromise
- Ollama P2P cryptominer RAT campaign
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Operation BlueDash multi-RMM workplace phishing
- Operation DangerousPassword axios npm compromise
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation Endgame SocGholish disruption
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation Muck and Load GitHub lure network
- Operation Phnom Penh MODBEACON activity
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Outsider Enterprise smishing PhaaS
- Pakistani law enforcement espionage convergence
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Patriot Bait AI-assisted C2 botnet
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Perplexity AI-spoofing Chromium extension search hijacker
- Photo ZIP hospitality Node.js implant campaign
- Pirated media SilentCryptoMiner RAT campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- PraisonAI CVE-2026-44338 rapid exploitation
- procwire / routecraft npm Windows dropper
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- RedWing mobile MaaS Android bank-fraud operation
- REF6045 / SCMBANKER Mexican banking fraud
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- ScreenConnect freeware / AsyncRAT SEO campaign
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- Siemens ROX II zero-day exploit chain
- Silent Swap Google Notes crypto clipper
- simonecorsi/mawesome GitHub Action compromise
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SleeperGem RubyGems maintainer-account compromise
- Solana FakeFix npm / PyPI developer stealer
- SolarWinds Serv-U CVE-2026-28318 exploitation
- SourTrade browser-assembled malware malvertising
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Storm-2603 parallel SharePoint ransomware intrusion
- StrikeShark SharkLoader / Cobalt Strike campaign
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TamperedChef-style productivity malware clusters
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Telnyx PyPI TeamPCP compromise
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- Thailand healthcare RAR / Python stealer campaign
- tj-actions and reviewdog compromise
- ToddyCat Umbrij Gmail OAuth operation
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trend Micro Apex One CVE-2026-34926 exploitation
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Turla STOCKSTAY backdoor operations
- TuxBot v3 Evolution IoT botnet framework
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795 Starland / WLDR campaign
- UAT-7810 LONGLEASH ORB network expansion
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UNC6692 SNOW malware social-engineering campaign
- UNK_DeadDrop developer repository phishing
- UNK_MassTraction Roundcube university mailserver campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- VerdantBamboo appliance BRICKSTORM operation
- Vidar / XMRig Factory-v3 malvertising campaign
- ViteVenom / ChainVeil npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- WhatsApp VBScript ManageEngine RMM campaign
- Windmill CVE-2026-29059 active exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- WP-SHELLSTORM webshell access brokerage
- wshu.net npm credential-stealer campaign
- Xinference PyPI compromise
- XZ Utils backdoor
opsec failure
Oracle
Oracle E-Business Suite
Oracle Payments
Oracle PeopleSoft
Oracle WebLogic Server
ORANGETAIL
ORB network
OS command injection
OT
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Iran-linked threat landscape: access optionality and evidence quality
- KNX Protocol CVE-2023-4346 KEV exploitation
OT switches
OTA update
OTP interception
OtterCookie
out-of-bounds write
Outlook
overlay attacks
OX Security
OxideHarvest
OYSTERBLUES
OYSTERFRESH
OYSTERSHUCK
P2P
P2P C2
package masquerading
package registry
- Braintree.Net NuGet payment skimmer
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- Mastra
easy-day-jsnpm scope compromise - Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Operation DangerousPassword axios npm compromise
- Telnyx PyPI TeamPCP compromise
package registry abuse
package registry credentials
package registry proxy
package republishing
package scanning
package takedown
package-cooldowns
package-manager-hardening
package-splitting
package-takeover
Packagist
- Famous Chollima Packagist dev-branch loader
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Laravel-Lang Composer tag-rewrite compromise
- PolinRider cross-ecosystem supply-chain campaign
Page Builder CK
page cache
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
page poisoning
Pakistan
Pakistan-linked
Palo Alto Networks
PAM
PAM credential validation
PamStealer
PAN-OS
parallel-intrusion
passkeys
password manager theft
password spray
password spraying
- Azure CLI LSHIY password-spray campaign
- FortiBleed Fortinet credential exposure
- Patriot Bait AI-assisted C2 botnet
password-protected archive
Pastebin
PAT theft
patch management
path hijacking
path traversal
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- Windmill CVE-2026-29059 active exploitation
Patriot Bait
patterns
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI browser-extension confused deputy
- AI scanner anti-analysis
- AI-agent memory poisoning
- AI-augmented adversary operations
- AI-brand impersonation phishing and malvertising
- Azure DevOps MCP pull-request prompt injection
- Browser-based developer IDE OAuth token theft
- Claude Code GitHub Action prompt-injection boundary
- ClickOnce COM hijacking abuse
- Cloud bucket namespace hijacking
- Cloud logging control-plane tampering
- Crypto supply-chain path to transaction authority
- Cursor Windows workspace-path binary hijack
- Developer-tool config auto-execution
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- GitHub API enumeration and access-token abuse
- GuardFall AI-agent shell-guard bypass
- LangGraph checkpointer injection and unsafe deserialization
- Malicious infrastructure provider concentration
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- Microsoft Teams external-chat phishing
- npm install explicit-trust controls
- Phantom squatting: AI-hallucinated domains
- Sentry MCP Agentjacking
- Vertex AI staging-bucket squatting
payload loader
payload staging
payload-as-a-service
payment fraud
payment SDK
payment skimmer
payment workflow exposure
payment-card theft
payment-card-theft
PayPal
payroll lures
Paysafe
pe_to_shellcode
PebbleDash
pedit
pentesting
people
PeopleTools
PerfWatson2.exe
Perplexity AI
persistence
- @copilot-mcp/apex macOS infostealer campaign
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- ClickOnce COM hijacking abuse
- forge-jsxy
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Mastra
easy-day-jsnpm scope compromise - MrMustard PyPI credential-stealer compromise
- MYRA RAT
- Nx Console VS Code extension compromise
- Ollama P2P cryptominer RAT campaign
- Operation Highland Velvet Ant authentication-stack backdoors
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- ROADtools
- Showboat
- SleeperGem RubyGems maintainer-account compromise
- Stock exchange executive mailbox espionage
- TamperedChef-style productivity malware clusters
- TeamPCP
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Velvet Ant
- Vidar / XMRig Factory-v3 malvertising campaign
- wshu.net npm credential-stealer campaign
persistent root access
persona operations
personal access tokens
pfSense
PhaaS
Phantom Gyp
- binding.gyp npm CI/CD worm
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
PhantomClick
PhantomMail
PhantomRelay
Philippines
phishing
- AI-brand impersonation phishing and malvertising
- Avalon / CrownX malware framework
- Chinese-language PhaaS wallet-tokenization ecosystem
- Cloud Atlas
- Dutch Police / NCSC 17-million-device botnet disruption
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Forg365 Microsoft 365 PhaaS
- GHOST STADIUM FIFA World Cup ticket phishing
- Ghostwriter
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Hunt.io global smishing infrastructure campaign
- Kali365 device-code phishing expansion
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Microsoft Q2 2026 email and Teams phishing landscape
- O-UNC-066 Entra passkey vishing
- Operation BlueDash multi-RMM workplace phishing
- Outsider Enterprise smishing PhaaS
- Phantom squatting: AI-hallucinated domains
- Photo ZIP hospitality Node.js implant campaign
- RedWing mobile MaaS Android bank-fraud operation
- Russian intelligence commercial-messaging backup-key phishing
- TA4922
- UNK_DeadDrop developer repository phishing
phishing-as-a-service
- Chinese-language PhaaS wallet-tokenization ecosystem
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Outsider Enterprise smishing PhaaS
PHP
PHP code execution
PHP code injection
PHP object injection
PHP upload
PHP web shell
physical systems
physics
PicassoLoader
pickle
pig butchering
pig-butchering
Pink
pipelines
piracy
Piriform
Pix
Pixeldrain
PixelSmash
PKGBUILD
plaintext HTTP
Plandex
PLENET
plugin architecture
PlugX
poisoned-branch
PoisonX
police digital services
PolinRider
Poly1305
polyfill
Polygon
Polygon blockchain dead drop
Polymarket
polymorphic loader
polymorphic payloads
Popa
portmap
Portugal
post-authentication RCE
post-exploitation
- AI-augmented adversary operations
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Showboat
- TaskWeaver
- WLDR agent
post-exploitation framework
postal-impersonation
PostCSS
PostgreSQL
- Drupal Core CVE-2026-9082 exploitation
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
postinstall
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - MYRA RAT
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Polymarket npm wallet-drainer packages
- wshu.net npm credential-stealer campaign
PowerCloud
PowerShell
- ACR Stealer
- Armored Likho BusySnake campaign
- ClickFix CPaaS API-driven payload delivery
- Cloud Atlas
- Fake Corepack site infostealer and proxyware campaign
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- GREYVIBE
- Oman government Iranian-nexus webshell C2
- Operation BlueDash multi-RMM workplace phishing
- Operation Muck and Load GitHub lure network
- Patriot Bait AI-assisted C2 botnet
- Photo ZIP hospitality Node.js implant campaign
- postcss-minify-selector-parser npm RAT
- Seedworm / MuddyWater
- StealC / Amadey infrastructure disruption
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
- UAT-11795 Starland / WLDR campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- WLDR agent
PowerShell execution
PowerShell malware
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
PowerShower
PPtP
PRA
PraisonAI
PRC
PRC-aligned
PRC-nexus
pre-auth RCE
pre-authentication
- Citrix NetScaler CVE-2026-8451 memory overread
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
pre-authentication RCE
preinstall
- @withgoogle/stitch-sdk scope squat
- jscrambler npm preinstall stealer
- procwire / routecraft npm Windows dropper
Primitive Bear
PrincessClub
priority inheritance
privacy
privacy exposure
private key theft
private registry fallback
private-key theft
privilege escalation
- Android Framework CVE-2025-48595 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Drupal Core CVE-2026-9082 exploitation
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Siemens ROX II zero-day exploit chain
- UTA0533 SonicWall SMA1000 zero-day compromise
- WP Maps Pro CVE-2026-8732 exploitation
Privileged Remote Access
process doppelgänging
process environment scraping
process hollowing
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Exposed WebDAV malware delivery lab and CURP campaign
- Pirated media SilentCryptoMiner RAT campaign
process injection
- HelloNet ViPNet update-system campaign
- OceanLotus
- OkoBot cryptocurrency-wallet malware framework
- Operation DragonReturn India tax-season DcRAT campaign
- Operation GriefLure Southeast Asia LNK dropper
- Starland RAT
product lifecycle management
professional services
profile.d
Progress Kemp LoadMaster
Progress Software
Project Proposal.exe
prompt injection
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI scanner anti-analysis
- AI-agent memory poisoning
- Claude Code GitHub Action prompt-injection boundary
- GuardFall AI-agent shell-guard bypass
- macOS.Gaslight Rust backdoor
- MCP tool-description poisoning
prompt-injection
- AI-augmented adversary operations
- HackerBot Claw GitHub Actions exploitation campaign
- SANDWORM_MODE AI-toolchain npm worm
- TrapDoor crypto-stealer cross-ecosystem campaign
PROMPTFLUX
PROMPTSPY
promptware
proof of deletion
Proofpoint
protestware
Protobuf
provenance
proxy
- First VPN
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- PCPJack cloud SMTP relay network
- Showboat
- TamperedChef-style productivity malware clusters
- VPN Go browser-extension clipboard stealer
- Webworm
proxy network
ProxyChains
proxyjacking
proxyware
prt-scan
PSEMHUB
PsExec
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- GodDamn ransomware PoisonX BYOVD activity
PSIGW
psychological operations
PTC
PteroBox
PteroPaste
PteroPSDoor
PteroSetup
PteroVDoor
public exploit
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- MiniPlasma Windows Cloud Filter LPE exploitation
public file-transfer exfiltration
public proof of concept
public sector
public service abuse
pull requests
PUP
PureLogs Stealer
PureRAT
pwn-request
PyArmor
PyInstaller
PyPI
- binding.gyp npm CI/CD worm
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Glassworm developer supply-chain botnet
- LiteLLM compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Solana FakeFix npm / PyPI developer stealer
- Telnyx PyPI TeamPCP compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Xinference PyPI compromise
Python
- ACR Stealer
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- macOS.Gaslight Rust backdoor
- MrMustard PyPI credential-stealer compromise
- postcss-minify-selector-parser npm RAT
- Seedworm / MuddyWater
- Starland RAT
- Telnyx PyPI TeamPCP compromise
- UAT-11795 Starland / WLDR campaign
- Ulej / Flowerbed
- Xinference PyPI compromise
Python extension modules
Python malware
Python stealer
Qianxin Threat Intelligence Center
QiAnXin XLab
- AryStinger legacy-router recon proxy network
- NadMesh AI-service and cloud-credential botnet
- RustDuck
Qilin
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Check Point VPN CVE-2026-50751 exploitation
- The Gentlemen ransomware
QNAP
QR code
QR code interception
quantum computing
Quasar
query injection
Quest KACE SMA
QuimaRAT
RaaS
RabbitMQ
race condition
RainbowEx
RakNet flood
RAM disk
Ransom-ISAC
ransomware
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Avalon / CrownX malware framework
- Check Point VPN CVE-2026-50751 exploitation
- CrownX
- ENCFORGE
- First VPN
- Fox Tempest
- GodDamn ransomware PoisonX BYOVD activity
- Kairos data-extortion government payment
- Storm-2603 parallel SharePoint ransomware intrusion
- The Gentlemen ransomware
ransomware access
ransomware enablement
ransomware-access
rapid exploitation
Rapid7
RAR archives
RAR staging
RAT
- Armored Likho
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- DAEMON Tools Lite supply-chain compromise
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- forge-jsxy
- Glassworm developer supply-chain botnet
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- GREYVIBE
- JINX-0164 crypto developer infrastructure campaign
- LabubaRAT
- Mastra
easy-day-jsnpm scope compromise - MYRA RAT
- Ollama P2P cryptominer RAT campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- RemotePE
- Screening Serpens
- SprySOCKS
- Starland RAT
- StegaBin Pastebin-steganography npm campaign
- STOCKSTAY
- TamperedChef-style productivity malware clusters
- TinyRCT
- UAT-11795 Starland / WLDR campaign
RC4
- @marketfront / @tqm-mfe dependency-confusion stealer
- OP-512
- StealC / Amadey infrastructure disruption
- UAC-0226 / SHADOW-EARTH-066
RC4 C2
RCE
- Agent localhost control-plane RCE
- LangGraph checkpointer injection and unsafe deserialization
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Vertex AI staging-bucket squatting
Rclone
rclone
RCS
RDP
RDP phishing
RDS
Reality
Reaper
reconnaissance
recovery denial
recovery disruption
recruitment lures
Red Dev 10
Red Hat
Red Raindrop Team
REDCap
Redis
- Argo CD repo-server unauthenticated RCE
- GigaWiper
- LangGraph checkpointer injection and unsafe deserialization
- NadMesh AI-service and cloud-credential botnet
Redis backdoor
RediSearch
reduced cyber refusals
RedWing
REF6045
REF9403
reflective .NET loading
reflective loading
refresh token theft
refresh tokens
RegAsm process hollowing
registry persistence
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Photo ZIP hospitality Node.js implant campaign
- SideCopy
- The Gentlemen ransomware
- Turla STOCKSTAY backdoor operations
registry-controls
release automation
release tampering
Remcos
Remcos RAT
remote access
- Citrix NetScaler CVE-2026-8451 memory overread
- ConnectWise ScreenConnect exploitation wave
- FortiBleed Fortinet credential exposure
- Lazarus-linked Rollup polyfill npm malware
- Pirated media SilentCryptoMiner RAT campaign
- WhatsApp VBScript ManageEngine RMM campaign
remote access software
remote access trojan
Remote Access VPN
remote code execution
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Crypto Clipper Tor / USB worm
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Hugging Face autonomous-agent production intrusion
- Ivanti Sentry CVE-2026-10520 exploitation
- Joomla JCE CVE-2026-48907 exploitation
- Langflow CVE-2026-0770 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- nodemon-sudo / tslint-conf runtime npm backdoor
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform CVE-2026-6875 exploitation
- StegoAd Edge extension steganography campaign
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
remote debugging
remote MCP
remote monitoring and management
remote script injection
Remote Support
remote support
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
Remote Utilities
remote-access
Remotely
RemotePE
RemotePELoader
removable media
Rentry
replication
repo-server
repository compromise
repository exfiltration
repository poisoning
- Amazon Q CVE-2026-12957 MCP auto-execution
- Claude Code GitHub Action prompt-injection boundary
- FakeGit AgentBaiting and SmartLoader campaign
research sector
residential proxies
residential proxy
REST API
REST C2
restart-triggered execution
retail trading
reverse proxy
reverse SSH tunneling
reverse tunneling
REVERSE_PROXY_TRUSTED_PROXIES
ReverseSocks
reviewdog
Rilide
RingH23
RMM
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- UNC3753
RMM abuse
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Cavern
- Cavern Manticore
- Evilginx and device-code phishing open-directory cluster
- Iran-linked threat landscape: access optionality and evidence quality
- Operation BlueDash multi-RMM workplace phishing
- ScreenConnect freeware / AsyncRAT SEO campaign
- TaskWeaver
- WhatsApp VBScript ManageEngine RMM campaign
ROADrecon
ROADtools
roadtx
Rokarolla
RokRAT
Rollup
RomulusLoader
Roo-Code
root
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
root access
root escalation
root execution
rootkit
- Atomic Arch AUR package hijack
- Funnull RingH23 and MacCMS supply-chain attacks
- IronWorm npm Rust infostealer campaign
- MYRA RAT
ROOTRUN
ROPC
Rouki obfuscation
Roundcube
router
router compromise
router malware
ROX II
RSA
RSA-2048
RSA-OAEP
RT-Thread
RTL819X
RTLO
rtmutex
RubyGems
- binding.gyp npm CI/CD worm
- BufferZoneCorp RubyGems / Go module CI poisoning
- SleeperGem RubyGems maintainer-account compromise
Ruckus routers
RUGGEDCOM
Run key
Run key persistence
rundll32
Runner.Worker
Runspace
runtime execution
runtime mutation
runtime patching
runZero
Russia
- APT29
- Armored Likho
- Cloud Atlas
- Dragonfly
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- HelloNet ViPNet update-system campaign
- Russian state IP-camera military-logistics espionage
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
Russia-affiliated
Russia-linked
Russia-linked cybercrime
Russia-nexus
Russia-speaking operator
Russian Intelligence Services
Russian intelligence services
Russian state-supported
Russian-speaking ecosystem
Russian-speaking forums
Rust
- Atomic Arch AUR package hijack
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
- macOS.Gaslight Rust backdoor
- Operation Dragon Weave Azure Blob C2 campaign
- RustDuck
- TrapDoor crypto-stealer cross-ecosystem campaign
- wshu.net npm credential-stealer campaign
Rust malware
- Fake-reputation crypto clipboard hijacker
- HelloNet ViPNet update-system campaign
- LabubaRAT
- MODBEACON
- PamStealer
S3 Browser
S3-compatible storage
s5cmd
SaaS
- BlackFile / UNC6671 vishing extortion operation
- Klue Salesforce OAuth token abuse
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- ShinyHunters
SaaS abuse
SaaS data access
SaaS exposure
sabotage
Safari
SafeDep
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- MYRA RAT
- nodemon-sudo / tslint-conf runtime npm backdoor
Salesforce
SAML IdP
Samsung TizenRT
sandbox escape
- Hugging Face autonomous-agent production intrusion
- ServiceNow AI Platform CVE-2026-6875 exploitation
sandbox evasion
sandboxing
Sandworm
saroula01
scam infrastructure
scambling
scanner evasion
ScarCruft
scheduled task
- Crypto Clipper Tor / USB worm
- StealC / Amadey infrastructure disruption
- TELESHIM
- TELESHIM Middle East government espionage campaign
- TinyRCT
- Vidar / XMRig Factory-v3 malvertising campaign
scheduled task persistence
- Armored Likho BusySnake campaign
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- BusySnake Stealer
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- ScreenConnect freeware / AsyncRAT SEO campaign
scheduled tasks
- ACR Stealer
- GigaWiper
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Stock exchange executive mailbox espionage
- StrikeShark SharkLoader / Cobalt Strike campaign
- The Gentlemen ransomware
SCMBANKER
scope squatting
scoped package impersonation
SCOUTCURL
screen capture
ScreenConnect
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- ConnectWise ScreenConnect exploitation wave
- Operation BlueDash multi-RMM workplace phishing
- ScreenConnect freeware / AsyncRAT SEO campaign
Screening Serpens
screenshot capture
screenshot theft
script-injection
SD-WAN
search hijacking
search poisoning
search result poisoning
search-ms
Seashell Blizzard
Secret Blizzard
secret exposure
secrets
- Azure DevOps MCP pull-request prompt injection
- binding.gyp npm CI/CD worm
- CircleCI 2023 customer secret exposure incident
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- GitHub Actions deployment poisoning
secrets management
Secure Preferences
Security Management Server
security platform
security-tool discovery
seed phrase theft
SeedHunter
Seedworm
- Cavern Manticore
- Iran-linked threat landscape: access optionality and evidence quality
- Seedworm / MuddyWater
segmented networks
Sekoia
self-delete
self-hosted AI services
self-hosted media
self-hosted runner
self-propagation
semantic-release
sendit.sh
sensitive information exposure
Sentinel
SentinelOne
Sentry
Sentry abuse
SEO poisoning
- ACR Stealer
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI-brand impersonation phishing and malvertising
- Operation Phnom Penh MODBEACON activity
- ScreenConnect freeware / AsyncRAT SEO campaign
- StealC / Amadey infrastructure disruption
Seqrite Labs
Serv-U
service accounts
service persistence
service providers
service-agent
ServiceNow
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
ServiceNow AI Platform
ServiceWorker
session cookie theft
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
session hijacking
session secret exposure
session theft
session token theft
setuid
shadow copy deletion
shadow MMU
SHADOW-AETHER-040
SHADOW-AETHER-064
SHADOW-EARTH-066
SHADOW-WATER-063
ShadowPad
Shai-Hulud
- AI scanner anti-analysis
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Developer-tool config auto-execution
- Mini Shai-Hulud npm/PyPI worm campaign
- npm install explicit-trust controls
- SANDWORM_MODE AI-toolchain npm worm
SHARDLOADER
share propagation
shared hosting
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
shared secrets
SharedWorker
ShareFile
SharePoint
- BlackFile / UNC6671 vishing extortion operation
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Storm-2603 parallel SharePoint ransomware intrusion
SharePoint Server
SharkLoader
shell injection
ShinyHunters
Shodan
ShortLeash
Shuckworm
SideCopy
sideloading
Siemens
Signal
- Russian intelligence commercial-messaging backup-key phishing
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Signal interception
signed malware
signed updates
signed-binary
Silent Ransom Group
Silent Swap
SilentCryptoMiner
SilentRunLoader
SiliconFlow
Silver Fox
SimpleHelp
- Djinn Stealer
- Evilginx and device-code phishing open-directory cluster
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- TaskWeaver
SimpleHTTPServer exposure
simulation tampering
Site Member permissions
skb
SkillCloak
SkillDetonate
Skrill
sleeper packages
Sliver
SLSA
SLSA provenance
SMA1000
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- UTA0533 SonicWall SMA1000 zero-day compromise
smart building
smart TVs
SMARTAXE
SmartConsole
SmartLoader
SmartScreen
SMB
SMB brute force
SMB egress
smishing
- 0ktapus phishing campaign
- Crypto supply-chain path to transaction authority
- Hunt.io global smishing infrastructure campaign
- Outsider Enterprise smishing PhaaS
SMS interception
sms-phishing
SMTP
SMTP abuse
Snake
Sneaky 2FA
SNOWLIGHT
SOAP API abuse
SocGholish
social engineering
- AI-brand impersonation phishing and malvertising
- Chinese-language PhaaS wallet-tokenization ecosystem
- ClickFix CPaaS API-driven payload delivery
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Microsoft Teams external-chat phishing
- Polymarket npm wallet-drainer packages
- Russian intelligence commercial-messaging backup-key phishing
- Screening Serpens
- UNC3753
- UNC6692 SNOW malware social-engineering campaign
- Void Dokkaebi
- WhatsApp VBScript ManageEngine RMM campaign
social-engineering
Socket
- jscrambler npm preinstall stealer
- Operation Muck and Load GitHub lure network
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- VPN Go browser-extension clipboard stealer
Socket Security
- Braintree.Net NuGet payment skimmer
- Injective SDK npm wallet stealer
- NuGet game-cheat DotnetTool pepesoft campaign
Socket Security Research
- Chrome live-wallpaper extension ad-fraud network
- Fake Corepack site infostealer and proxyware campaign
Socket.IO
- Contagious Interview SVG-steganography OtterCookie campaign
- Lazarus-linked Rollup polyfill npm malware
SOCKS tunneling
SOCKS5
- Cavern
- GoSerpent Southeast Asia espionage campaign
- Operation Highland Velvet Ant authentication-stack backdoors
- Seedworm / MuddyWater
- Showboat
SOCKS5 proxy
SOCKS5 tunneling
SOCRadar
SoftEther VPN
software impersonation
software supply chain
software-deployment
SOHO router
SOHO routers
Solana
- Glassworm developer supply-chain botnet
- Solana FakeFix npm / PyPI developer stealer
- SourTrade browser-assembled malware malvertising
SolarWinds
Solid PDF Creator
SolidPDFCreator.dll
SolidPDFPcl2Bmp
SonicWall
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- UTA0533 SonicWall SMA1000 zero-day compromise
Sophos
source code
source control
- Gitea Docker CVE-2026-20896 probing
- GitHub API enumeration and access-token abuse
- GitLab Oj notebook-diff authenticated RCE chain
source repository compromise
source-code compromise
source-control token theft
source-package drift
source-package mismatch
source-repository poisoning
- Astro config blockchain C2 PR injection
- Cursor Windows workspace-path binary hijack
- Developer-tool config auto-execution
- Operation Muck and Load GitHub lure network
- PolinRider cross-ecosystem supply-chain campaign
source-repository reconnaissance
SourceForge abuse
SourTrade
South Africa
South Asia
South Korea
Southeast Asia
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GoSerpent Southeast Asia espionage campaign
- OceanLotus
- Operation GriefLure Southeast Asia LNK dropper
- Showboat
SP Page Builder
spam
spear phishing
- Armored Likho
- Armored Likho BusySnake campaign
- Kimsuky / Emerald Sleet / TA427
- Operation DragonReturn India tax-season DcRAT campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- Thailand healthcare RAR / Python stealer campaign
- UAC-0226 / SHADOW-EARTH-066
spear-phishing
spearphishing
SPECTRALVIPER
Sphinx ransomware
SpiderLabs
Spikey Scorpius
Splunk
Spring Boot
SprySOCKS
spyware
SQL injection
- Drupal Core CVE-2026-9082 exploitation
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- LangGraph checkpointer injection and unsafe deserialization
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
SQLite
SQLite state
SquareShell
SSDP
SSH
SSH backdoor
SSH bastion
SSH brute force
SSH key exposure
SSH key persistence
SSH keys
- @copilot-mcp/apex macOS infostealer campaign
- Djinn Stealer
- Fake Corepack site infostealer and proxyware campaign
- MrMustard PyPI credential-stealer compromise
SSH lateral movement
SSH persistence
SSH tunnel
SSH tunneling
SSH tunnels
SSL VPN
SSRF
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- GitHub Actions deployment poisoning
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
stack use-after-free
staged malicious update
stale access
stale credentials
Starland RAT
Startup folder
Startup folder persistence
state-linked
state-owned enterprise
Static Kitten
stdio
- Agent localhost control-plane RCE
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
StealC
stealer
Steam profile dead drop
steganography
- ACR Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- StegoAd Edge extension steganography campaign
StegoAd
StepSecurity
STM32Cube
stock exchange
STOCKSTAY
storage deletion
Storage Zone Controller
stored XSS
Storm-2603
Storm-2697
Storm-3075
Stowaway
STRD
streaming boxes
Stripe OLT
student targeting
STUN
Stuxnet lineage
subject claim
SuccessKey
SUMMIT
Suo5
Supabase
SUPERADMIN_SECRET
supply chain
- Braintree.Net NuGet payment skimmer
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub API enumeration and access-token abuse
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- MYRA RAT
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- nodemon-sudo / tslint-conf runtime npm backdoor
- NuGet game-cheat DotnetTool pepesoft campaign
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Solana FakeFix npm / PyPI developer stealer
supply chain compromise
supply-chain
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- actions-cool GitHub Actions tag compromise
- Agent skill marketplace poisoning
- AI scanner anti-analysis
- AI-augmented adversary operations
- APT29
- art-template Coruna-style iOS watering-hole compromise
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Browser-based developer IDE OAuth token theft
- BufferZoneCorp RubyGems / Go module CI poisoning
- CanisterWorm
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- Crypto supply-chain path to transaction authority
- DAEMON Tools Lite supply-chain compromise
- Developer-tool config auto-execution
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- forge-jsxy
- Funnull RingH23 and MacCMS supply-chain attacks
- GitHub / Packagist postinstall hook campaign
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- Glassworm developer supply-chain botnet
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- JetBrains AI plugin API-key theft
- JiaT75
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- Klue Salesforce OAuth token abuse
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- LiteLLM compromise
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - MCP stdio command-execution boundary
- MCP tool-description poisoning
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- node-ipc 2026 npm maintainer-account compromise
- npm install explicit-trust controls
- Nx Console VS Code extension compromise
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- Phantom squatting: AI-hallucinated domains
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- simonecorsi/mawesome GitHub Action compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- TeamPCP
- Telnyx PyPI TeamPCP compromise
- tj-actions and reviewdog compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Vertex AI staging-bucket squatting
- Void Dokkaebi
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- wshu.net npm credential-stealer campaign
- Xinference PyPI compromise
- XZ Utils backdoor
supply-chain attribution
supply-chain integrity
supply-chain-adjacent
surveillance
suspected China-aligned
suspected China-linked
SVG
SWE-agent
SWUpdate
Symantec Threat Hunter Team
symbolic link
symlink following
Synacktiv
Synology
synthetic commits
Sysdig
SYSTEM
SystemBC
systemd
systemd-userdbd
T1204.004
T3
TA427
TA488
TA569
Tactical RMM
tag rewrite
tag tampering
- actions-cool GitHub Actions tag compromise
- codfish semantic-release-action tag compromise
- simonecorsi/mawesome GitHub Action compromise
- tj-actions and reviewdog compromise
TAG-124
TAG-179
TAG-182
TAG-22
Taiwan
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- FishMonger
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation Dragon Weave Azure Blob C2 campaign
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
takedown
- Dutch Police / NCSC 17-million-device botnet disruption
- First VPN
- Glassworm developer supply-chain botnet
TamperedChef
targeted malware
targeted operations
TartarusGate
task queue
task scheduler abuse
TaskWeaver
tax-season phishing
tc
TCP traffic diversion
TDS
TeamPCP
- actions-cool GitHub Actions tag compromise
- AI-augmented adversary operations
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Mini Shai-Hulud npm/PyPI worm campaign
- Nx Console VS Code extension compromise
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
- Xinference PyPI compromise
TeamPCP-adjacent
Teams access
TeamViewer
TEASOUP
Tebi
technician session
telecom
telecom-impersonation
telecommunications
Telegra.ph
Telegram
- 0ktapus phishing campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- Forg365 Microsoft 365 PhaaS
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- GREYVIBE
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NuGet game-cheat DotnetTool pepesoft campaign
- Starland RAT
- UAC-0226 / SHADOW-EARTH-066
telegram
Telegram bot
Telegram C2
- macOS.Gaslight Rust backdoor
- Solana FakeFix npm / PyPI developer stealer
- TELESHIM
- TELESHIM Middle East government espionage campaign
- wshu.net npm credential-stealer campaign
Telegram dead drop
Telegram exfiltration
Telegram notification
telemetry
TELEPUZ
TELESHIM
Teletype
Telnet
Telnet brute force
Telnyx
Temp Zagros
template injection
tenant-project
TencShell
Tenda
Tenet Security
Tetrade
TetrisPhantom
TeviRAT
Thailand
- FishMonger
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- Thailand healthcare RAR / Python stealer campaign
The Gentlemen
The Hacker News
- Azure CLI LSHIY password-spray campaign
- CrashStealer macOS notarized-dropper campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Gitea Docker CVE-2026-20896 probing
- ModHeader browser-extension surveillance capability
- O-UNC-066 Entra passkey vishing
- OkoBot cryptocurrency-wallet malware framework
- Progress ShareFile Storage Zone Controller security threat
- StegoAd Edge extension steganography campaign
- UAT-7810 LONGLEASH ORB network expansion
- WP-SHELLSTORM webshell access brokerage
The Quarry
ThemeREX Addons
third-party integrations
threat hunting
threat landscape
ThrottleBlood
ThumbcacheService
thumbnail generation
TinyGo
TinyRCT
tj-actions
TmcLoader
TmcPayload
ToddyCat
token forgery
token replay
token theft
- ACR Stealer
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- MrMustard PyPI credential-stealer compromise
- Okta support-system compromise
- ROADtools
token-theft
TONESHELL
TookPS
tool
tool execution
tool output injection
tool poisoning
tool use
tooling
- CanisterWorm
- HackerBot Claw
- LiteLLM compromise
- TeamPCP
- Trivy → TeamPCP → CanisterWorm: compromise timeline
tools
- ACR Stealer
- BINDCLOAK
- BusySnake Stealer
- Cavern
- CrownX
- Djinn Stealer
- ENCFORGE
- Fast16
- First VPN
- forge-jsxy
- GigaWiper
- HOLLOWGRAPH
- LabubaRAT
- MIXEDKEY
- MODBEACON
- MYRA RAT
- PamStealer
- QuimaRAT
- RedWing
- RemotePE
- ROADtools
- RustDuck
- SCMBANKER
- Showboat
- SprySOCKS
- Starland RAT
- STOCKSTAY
- TaskWeaver
- TELEPUZ
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Ulej / Flowerbed
- Umbrij
- WLDR agent
Tor
Total Software Deployment
Trading Technologies
TradingView
traffic broker
traffic control
traffic hijacking
traffic-distribution-system
traffic-fraud
training data
transaction authority
transitive dependency
transnational repression
Transparent Tribe
transport
transportation
Trend Micro
- Langflow CVE-2026-33017 cryptominer SSH worm
- SHADOW-AETHER AI-augmented Latin America intrusions
- Trend Micro Apex One CVE-2026-34926 exploitation
TrendAI
Trezor
TrickBot
Trident Ursa
trojanized installers
Tron
trusted extension risk
trusted publishing
tunnel decapsulation
tunnel services
Turla
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- STOCKSTAY
- Turla
- Turla STOCKSTAY backdoor operations
Turla collaboration
TuxBot
TuxBot v3 Evolution
Twilio
Twilio SendGrid
Tycoon2FA
TypeScript
typosquat
typosquatting
- @withgoogle/stitch-sdk scope squat
- Braintree.Net NuGet payment skimmer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Funnull RingH23 and MacCMS supply-chain attacks
- Hunt.io global smishing infrastructure campaign
- Lazarus-linked Rollup polyfill npm malware
- Microsoft Teams external-chat phishing
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- nodemon-sudo / tslint-conf runtime npm backdoor
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- SANDWORM_MODE AI-toolchain npm worm
- ScreenConnect freeware / AsyncRAT SEO campaign
- shopsprint/decimal Go typosquat DNS backdoor
- StegaBin Pastebin-steganography npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
UAC
UAC bypass
UAC-0002
UAC-0010
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
UAC-0098
UAC-0145
UAC-0194
UAC-0226
UAT-11795
UAT-5918
UAT-7237
UAT-7810
Ubiquiti
Ubuntu
Udev persistence
UDP C2
UDP/1900
Ukraine
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghostwriter
- GREYVIBE
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- Showboat
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
Ukraine targeting
Ulej
UltraVNC
Umbrij
unauthenticated access
unauthenticated HTTP exploitation
unauthenticated RCE
- Argo CD repo-server unauthenticated RCE
- Fastjson CVE-2026-16723 active exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
UNC1543
UNC2814
UNC3753
UNC4221
UNC4736
UNC5792
UNC6240
UNC6508
UNC6671
UNC6692
UNC6780
Uni-App
UniFi OS
Unified CM SME
uninitialized heap memory
Unit 42
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- FortiBleed Fortinet credential exposure
- Operation FlutterBridge FlutterShell macOS malvertising
- Phantom squatting: AI-hallucinated domains
- Siemens ROX II zero-day exploit chain
- TuxBot v3 Evolution IoT botnet framework
- Vidar / XMRig Factory-v3 malvertising campaign
United States
- Seedworm / MuddyWater
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC3753
university targeting
UNK_MassTraction
UNK_PitStop
unpatched vulnerability
unsafe deserialization
unsigned installer
UpdateFactory
UPnP
UPX
uranium compression
USB propagation
USB weaponizer
USB worm
use-after-free
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
user execution
user namespaces
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
UTA0355
UTA0533
UTG-Q-1000
uTLS
V2Ray
V4bel
V8
valid accounts
ValleyRAT
VBCloud
VBE
VBS
VBScript
- BusySnake Stealer
- Cloud Atlas
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- WhatsApp VBScript ManageEngine RMM campaign
vector databases
VEIL#DROP
Velociraptor
Velvet Ant
VELVETSHELL
vendor compromise
vendor credentials
VENOMOUS BEAR
Vercel
Vertex AI
VIDAR
Vidar Stealer
- AI-brand impersonation phishing and malvertising
- Operation Muck and Load GitHub lure network
- Vidar / XMRig Factory-v3 malvertising campaign
Vietnam
Vietnam-aligned
Views
ViewState deserialization
ViPNet
virtualization
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Januscape KVM CVE-2026-53359 guest-to-host escape
VirusTotal sentiment abuse
vishing
- BlackFile / UNC6671 vishing extortion operation
- Microsoft Q2 2026 email and Teams phishing landscape
- O-UNC-066 Entra passkey vishing
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- ShinyHunters
- UNC3753
Visual Studio
Visual Studio Code Remote SSH
Vite
Vitest
ViteVenom
VLESS
vManage
VMware
VNC
VNT
Void Blizzard
Void Manticore
Volt Typhoon
volume serial number
VPN
- Check Point VPN CVE-2026-50751 exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- First VPN
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
- VPN Go browser-extension clipboard stealer
VPN credentials
VPN gateway
VPN Go
VPN session hijacking
VS Code
- Amazon Q CVE-2026-12957 MCP auto-execution
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Browser-based developer IDE OAuth token theft
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Nx Console VS Code extension compromise
- PolinRider cross-ecosystem supply-chain campaign
- UNK_DeadDrop developer repository phishing
VS Code tunnels
Vshell
VShell
VSIX
vSphere
VU#213560
VulnCheck
vulnerability
- Adobe ColdFusion APSB26-68 CVE bonanza
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Joomla extension KEV exploitation cluster
- Langflow CVE-2026-55255 flow authorization bypass
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Quest KACE SMA CVE-2025-32975 exploitation
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- Trend Micro Apex One CVE-2026-34926 exploitation
vulnerability exploitation
vulnerability research
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- GitLab Oj notebook-diff authenticated RCE chain
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
vulnerability-research
vulnerable appliances
VXLAN
w3wp.exe
wallet address replacement
wallet drainer
wallet infrastructure
wallet replacement
wallet theft
- @copilot-mcp/apex macOS infostealer campaign
- Fake-reputation crypto clipboard hijacker
- Injective SDK npm wallet stealer
- Mastra
easy-day-jsnpm scope compromise - Solana FakeFix npm / PyPI developer stealer
- Void Dokkaebi
wallet-drainer
wallet-theft
Wasabi
watchdog
watchTowr
- Adobe ColdFusion APSB26-68 CVE bonanza
- Citrix NetScaler CVE-2026-8451 memory overread
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
watchTowr Labs
watering hole
watering-hole
weak credentials
weak passwords
weapons shipments
web application
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- Gravity SMTP CVE-2026-4020 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
web application compromise
web hosting
web IDE
web injection
web injector
web management interface
web proxy
web RCE
web server
web shell
- Everest Forms Pro CVE-2026-3300 exploitation
- Joomla extension KEV exploitation cluster
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Oman government Iranian-nexus webshell C2
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC6508
- UTA0533 SonicWall SMA1000 zero-day compromise
web shell hunting
web shells
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- StrikeShark SharkLoader / Cobalt Strike campaign
web supply chain
web-shells
WebAssembly
WebDAV
WebKit
WebLogic
webmail
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- UNK_MassTraction Roundcube university mailserver campaign
WebRTC
webshell
webshells
website-compromise
WebSocket
WebSocket C2
- Cavern
- GREYVIBE
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- SprySOCKS
- STOCKSTAY
- TELEPUZ
- Turla STOCKSTAY backdoor operations
websocket-sharp
WebView
WebView2 C2
Webworm
Werkbit
WhatsApp phishing
WHM
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
Widget Factory
wiki
WILDDAY
Windchill
Windchill PDMLink
WinDirStat
Windmill
Windows
- 3CX desktop app compromise
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BINDCLOAK
- BusySnake Stealer
- CCleaner signed-update compromise
- ClickOnce COM hijacking abuse
- Crypto Clipper Tor / USB worm
- Cursor Windows workspace-path binary hijack
- DAEMON Tools Lite supply-chain compromise
- Djinn Stealer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- GigaWiper
- GodDamn ransomware PoisonX BYOVD activity
- IronWorm npm Rust infostealer campaign
- js-logger-pack Hugging Face exfiltration campaign
- LabubaRAT
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- MiniPlasma Windows Cloud Filter LPE exploitation
- MIXEDKEY
- Operation DangerousPassword axios npm compromise
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuimaRAT
- ScarCruft Yanbian game-platform supply-chain attack
- Starland RAT
- StrikeShark SharkLoader / Cobalt Strike campaign
- TamperedChef-style productivity malware clusters
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
Windows Defender
Windows Defender exclusions
Windows Forms
Windows malware
- Armored Likho BusySnake campaign
- CrownX
- Fake-reputation crypto clipboard hijacker
- MODBEACON
- NuGet game-cheat DotnetTool pepesoft campaign
- OkoBot cryptocurrency-wallet malware framework
- SourTrade browser-assembled malware malvertising
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Thailand healthcare RAR / Python stealer campaign
- WhatsApp VBScript ManageEngine RMM campaign
Windows persistence
Windows Run dialog
Windows Script Host
Windows servers
Windows service persistence
Windows Terminal
Winnti Group
WinOS
Winos4.0
WinPython
WinRAR
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
wiper
wiper-adjacent
WireGuard
Wiz Research
WLDR agent
WM_COPYDATA IPC
WMI
Woodgnat
WordPress
- Everest Forms Pro CVE-2026-3300 exploitation
- Gravity SMTP CVE-2026-4020 exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Operation Endgame SocGholish disruption
- Patriot Bait AI-assisted C2 botnet
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- WP-SHELLSTORM webshell access brokerage
WordPress credential theft
workflow backdoor
working-directory hijacking
workspace trust
World Cup
worm
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- Crypto Clipper Tor / USB worm
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
- Leo Platform npm Miasma-style compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- PCPJack cloud SMTP relay network
- SANDWORM_MODE AI-toolchain npm worm
- TeamPCP
- Trivy → TeamPCP → CanisterWorm: compromise timeline
WP Maps Pro
WP-SHELLSTORM
wp2shell
WScript
X-Secret
X-WEBAUTH-USER
X25519
X3D MINER
X_TRADER
XChaCha20
XenoRAT
XFRM
xlabs_v1
XMLDecoder
XMRig
- GREYVIBE
- Langflow CVE-2026-33017 cryptominer SSH worm
- Ollama P2P cryptominer RAT campaign
- Operation Muck and Load GitHub lure network
- Pirated media SilentCryptoMiner RAT campaign
- Vidar / XMRig Factory-v3 malvertising campaign
XOR
XOR obfuscation
Xray
XSLT SSRF
XSS
XSS.is
XXE
xz
Yanbian
YesWeHack
YouTube abuse
Yuechi Shared Technology
yuze
ZAPiXDESK
Zendesk
Zephyr RTOS
Zero Trust
zero-click
zero-day
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- MiniPlasma Windows Cloud Filter LPE exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Siemens ROX II zero-day exploit chain
- UTA0533 SonicWall SMA1000 zero-day compromise
zero-day exploitation
zero-reputation infrastructure
ZeroBEC
Zimbra
Zimbra Collaboration Suite
Zimperium
zLabs
Zoho Assist
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Storm-2603 parallel SharePoint ransomware intrusion