Skip to content

Tag index

Generated from page-level ## Tags sections. Each tag below links to the pages that currently use it.

All tags

.NET

.NET malware

.pth

/accessv2

/dev/kvm

146.70.139.154

192.42.116.105

192.42.116.58

2FA recovery codes

3CX

404 TDS

43.228.157.68

4sync

@marketfront

@tqm-mfe

.bin

<all_urls>

Ababil of Minab

abuse response

academic research

academic sector

Accellion

access broker

access brokers

access optionality

access token abuse

account lockout

account takeover

account-takeover

ACR Stealer

act_pedit

ACTINIUM

Active Directory

active exploitation

active probing

active threat

active-exploitation

ActiveX

actor

actors

ad blocker

ad fraud

Adaptix C2

ADB TCP/5555

Adblock for YouTube

ADFS

Admin API key theft

administrator account creation

Adobe ColdFusion

Adobe Commerce

Adspect

Advanced IP Scanner

Adversa AI

adversary-in-the-middle

adware

adware history

AES-128-CBC

AES-256-CTR

AES-256-GCM

AES-CTR

AES-GCM

AES-GCM C2

affiliate hijacking

Afghanistan

Africa

agent frameworks

agent memory

agent skills

agent state

AgentBaiting

agentic AI

agentic botnets

agentic browser

agentic browsers

agentic malware

agentic ransomware

agentic threat actor

Agentjacking

AGENTPSD

AI

AI agent

AI agents

AI anti-analysis

AI application infrastructure

AI assistant credentials

AI assistants

AI brand impersonation

AI browsers

AI chatbot abuse

AI coding agents

AI credential theft

AI data exfiltration

AI developer tooling

AI framework

AI gateway

AI infrastructure

AI model encryption

AI model evaluation

AI Now Institute

AI search poisoning

AI security

AI services

AI tooling

AI vulnerability discovery

AI workflow

ai-abuse

ai-agent

AI-assisted development

AI-assisted intrusion

AI-assisted malware

AI-assisted malware development

AI-assisted phishing

AI-assisted vulnerability discovery

AI-augmented operations

AI-generated malware

AI-generated narrator

Aider

AISURU

AiTM

Albania

Amadey

Amatera Stealer

Amazon Q Developer

Amazon SES

AMOS

AMSI bypass

AmsiScanBuffer

Android

Android Accessibility Service

Android ADB

Android Debug Bridge

Android malware

Android spyware

Anthropic

anti-analysis

anti-bot

anti-forensics

Anubis ransomware

ANY.RUN

AnyDesk

Apex One

API abuse

API enumeration

API exposure

API key exposure

API keys

API-driven payloads

apintergrationpost

App-Bound Encryption bypass

AppDomainManager

AppDomainManager injection

AppleJeus

AppleScript

AppleSeed

appliance

application delivery controller

application token

APSB26-68

APT

APT-C-08

APT27

APT28

APT29

APT32

APT36

APT37

APT42

APT43

APT44

APT45

Aptos

Aquatic Panda

AquilaRAT

arbitrary code execution

arbitrary file disclosure

arbitrary file read

arbitrary file upload

arbitrary file write

arbitrary JavaScript

Arch Linux

Arctic Wolf

ArduPilot

Argo CD

ArgoCD

Arista EOS

ARL

Armageddon

ArmCorp

Armored Likho

Artifact Signing

AryStinger

AS32167

Asia targeting

ASLR bypass

ASNs

ASP.NET

ASP.NET machineKey

ASPX web shells

Astro

ASUS AiCloud routers

ASUS router

AsyncAPI

AsyncRAT

Atlas RAT

Atomic Stealer

AUDIOFIX

audit logging

AUR

authenticated RCE

authenticated remote code execution

authentication bypass

authentication laundering

authentication stack

authentication-coercion

Authenticode impersonation

authorization bypass

auto-execution

AUTODYN

AutoGen Studio

AutoHotKey

AutoJack

autonomous agents

autonomous scanning

Avalon

AWS

AWS CloudTrail

AWS S3

AWS Secrets Manager

axios

Azure

Azure CLI

Azure DevOps

Azure Storage

Backblaze

backdoor

Backdoor.Mistic

Backstage

backup disruption

backup recovery keys

backup targeting

backups

Bad Epoll

BadBlocker

Badbox 2.0

Balbooa Forms

Balochistan Police

Banana RAT

bandcampro

banking

banking malware

banking trojan

Barracuda

Base64

BaseZipInstaller

Bash Uploader

batch loader

BCU key

Beast ransomware

BeaverTail

Bedrock

behavioral integrity verification

Behinder

Belarus

BELQI

BeyondTrust

Binance Smart Chain

binary execution

BinaryFormatter

BINDCLOAK

binding.gyp

biometric records

BIOPASS RAT

BioShocking

BirdCall

Bitbucket

Bitcoin

BitMiner

bitsadmin

Bitter

Bitwarden

BKA

BlackFile

Blackpoint Cyber

Bleacher Report

blockchain C2

blockchain dead drop

blockchain RPC

blockchain-dead-drop

Blogger abuse

blogspot staging

BLUEBEAM

botnet

botnet framework

Braintree

branch-compromise

branch-name-injection

brand impersonation

brand-impersonation

Brazil

Brazilian banking malware

BreachForums

Breeze Cache Cleaner

BRICKSTORM

Broadcom

browser assembly

browser automation

browser credential theft

browser data theft

browser extension

browser extension loader

browser hijacking

browser malware

browser security

browser session abuse

browser session risk

browser zero-day

browser-credential-theft

browser-extensions

browser-resident malware

browser-security

browser-session risk

browsing history

brute-force credentials

BSC

BTMOB

bucket hijacking

bucket squatting

build-time compromise

building automation

bulletproof hosting

Bun

Bun runtime abuse

business email compromise

BusySnake Stealer

Bybit

BYOVD

bypass2fa

C

C++

C++/CLI

C0XMO

C2

C2 framework

C2 tasking

CageFS

calendar dead drop

calendar invitation

Calendly abuse

call forwarding

Cambodia

campaign

Canada

CANFAIL

CAP_NET_ADMIN

Casbaneiro

CastleStealer

Catalyst SD-WAN Manager

Catcher

Cav3rn

Cavern

Cavern Manticore

CCleaner

CDN

CERT-In

CERT/CC

Certbot

certificate pinning

certificate theft

certutil

CFIDE

ChaCha20

ChainVeil

ChatGPT

chattr

Chatty Spider

CHAVECLOAK

Check Point

Check Point Research

Checkmarx

checkpointers

China

China-linked

China-nexus

China-speaking ecosystem

Chinese-language cybercrime

Chinese-language fraud ecosystem

Chinese-speaking

Chinese-speaking cybercrime

Chinese-speaking operator

Chisel

ChocoPoC

Chrome

Chrome App-Bound Encryption

Chrome DevTools Protocol

Chrome extension

Chrome renderer sandbox

Chrome Web Store

chrome_settings_overrides

ChromElevator

Chromium

Chromium extension

CI secrets

CI-CD

CI/CD

CI/CD abuse

CircleCI

CIS

CISA

CISA KEV

Cisco

Cisco IOS

Cisco IOS 12.4

Cisco Nexus

Cisco Talos

Cisco Unified CM

Cisco Unified Communications Manager

citizen portal compromise

Citrine Sleet

Citrix

Citrix NetScaler

CitrixBleed

CitrixBleed 2

CKEditor file manager

CL-CRI-1089

CL-CRI-1147

CL-STA-1062

CL-STA-1114

Claude

Claude Code

Claude for Chrome

Clever Cloud

ClickFix

ClickOnce

ClickUp

client-side exploitation

Cline

clipboard hijacker

clipboard injection

clipboard manipulation

clipboard stealer

clipboard theft

clipper

Cloaked Ursa

cloaking

cloud

cloud C2

cloud compromise

cloud credential hunting

cloud credential risk

cloud credential theft

cloud credentials

Cloud Files Mini Filter Driver

Cloud Filter driver

cloud IAM

cloud identity

cloud identity abuse

cloud infrastructure

cloud logging

cloud secrets

cloud security

cloud service abuse

cloud storage

cloud storage exfiltration

cloud transcoding

Cloudflare

Cloudflare Tunnel

Cloudflare tunnels

Cloudflare Turnstile

Cloudflare Workers

cloudflared

CloudLinux

cluster compromise

CMS

CMS exploitation

Cobalt Strike

code execution

code injection

code sandbox scraping

code signing

Codecov

codemado

CodeQL

Codex

Codex CLI

coding agents

coding challenge

Coinbase

ColdFusion

collaboration platforms

collaboration-tool phishing

COM-hijacking

ComfyUI

command and control

command execution

command injection

command-execution

command-injection

commercial messaging applications

commit farming

communications infrastructure

Composer

compromised accounts

compromised credentials

compromised infrastructure

compromised websites

compromised WordPress

computer vision

Conditional Access

configuration exposure

configuration theft

confused deputy

ConfuserEx

conhost

connected apps

ConnectWise

ConnectWise ScreenConnect

consumer devices

consumer IoT

Contagious Interview

container

container escape

container escape pre-check

content compliance rules

context flooding

Continue

continuous visibility

control flow flattening

control panel compromise

control plane

Copilot

Copilot CLI

Copy-on-Write

Corepack

Coruna

counterfeit software

COW

COWARDDUCK

CPaaS

cPanel

CPUID

cracked software

CrackMapExec

CrashStealer

Crates.io

credential attacks

credential dumping

credential exposure

credential harvesting

credential spraying

credential stuffing

credential theft

credential-theft

credit card theft

criminal infrastructure

critical infrastructure

critical-infrastructure

CRM data theft

cron

cron persistence

cross-platform

cross-platform malware

cross-project access

cross-site request forgery

cross-tenant isolation

CrownX

Crucio

crypto

crypto clipper

crypto wallets

crypto-wallets

cryptocurrency

cryptocurrency scam

cryptocurrency theft

cryptocurrency wallet theft

cryptocurrency wallets

cryptojacking

cryptominer

cryptomining

CSRF

CSRF token theft

Curious Serpens

CURP

Cursor

Curve25519

custody APIs

CVE-2008-4128

CVE-2013-3307

CVE-2016-5681

CVE-2020-17103

CVE-2020-22653

CVE-2020-22658

CVE-2021-27137

CVE-2021-29441

CVE-2022-0492

CVE-2023-24932

CVE-2023-25717

CVE-2023-2868

CVE-2023-4346

CVE-2023-4966

CVE-2024-1708

CVE-2024-1709

CVE-2024-20399

CVE-2024-21182

CVE-2024-3094

CVE-2024-42009

CVE-2025-11371

CVE-2025-11837

CVE-2025-24054

CVE-2025-2492

CVE-2025-3248

CVE-2025-32975

CVE-2025-33053

CVE-2025-34291

CVE-2025-40947

CVE-2025-40948

CVE-2025-40949

CVE-2025-48595

CVE-2025-49113

CVE-2025-49704

CVE-2025-49706

CVE-2025-5777

CVE-2025-66376

CVE-2025-67038

CVE-2025-68686

CVE-2025-8088

CVE-2026-0257

CVE-2026-0770

CVE-2026-10520

CVE-2026-10523

CVE-2026-11405

CVE-2026-11645

CVE-2026-12569

CVE-2026-12957

CVE-2026-12958

CVE-2026-15409

CVE-2026-15410

CVE-2026-16232

CVE-2026-16723

CVE-2026-20127

CVE-2026-20182

CVE-2026-20230

CVE-2026-20245

CVE-2026-20253

CVE-2026-20262

CVE-2026-20896

CVE-2026-21513

CVE-2026-23111

CVE-2026-26980

CVE-2026-2699

CVE-2026-2701

CVE-2026-28318

CVE-2026-29059

CVE-2026-3300

CVE-2026-33017

CVE-2026-33691

CVE-2026-34908

CVE-2026-34909

CVE-2026-34910

CVE-2026-34926

CVE-2026-35273

CVE-2026-35616

CVE-2026-39987

CVE-2026-40138

CVE-2026-40139

CVE-2026-40140

CVE-2026-40141

CVE-2026-4020

CVE-2026-41091

CVE-2026-41940

CVE-2026-42271

CVE-2026-42533

CVE-2026-43074

CVE-2026-43284

CVE-2026-43499

CVE-2026-43500

CVE-2026-43503

CVE-2026-44338

CVE-2026-45247

CVE-2026-45498

CVE-2026-45659

CVE-2026-46242

CVE-2026-46300

CVE-2026-46331

CVE-2026-46817

CVE-2026-48172

CVE-2026-48276

CVE-2026-48277

CVE-2026-48281

CVE-2026-48282

CVE-2026-48283

CVE-2026-48285

CVE-2026-48307

CVE-2026-48313

CVE-2026-48314

CVE-2026-48315

CVE-2026-48316

CVE-2026-48558

CVE-2026-48907

CVE-2026-48908

CVE-2026-48939

CVE-2026-50522

CVE-2026-50751

CVE-2026-50752

CVE-2026-53359

CVE-2026-5426

CVE-2026-54420

CVE-2026-55255

CVE-2026-56290

CVE-2026-56291

CVE-2026-60137

CVE-2026-62144

CVE-2026-62145

CVE-2026-63030

CVE-2026-6682

CVE-2026-6683

CVE-2026-6684

CVE-2026-6685

CVE-2026-6686

CVE-2026-6687

CVE-2026-6688

CVE-2026-6875

CVE-2026-7473

CVE-2026-8037

CVE-2026-8451

CVE-2026-8461

CVE-2026-8732

CVE-2026-9082

CWE-22

CWE-352

CWE-502

CWE-77

CWE-78

CWE-829

cyber-espionage

CyberAv3ngers

cybercrime

cybercrime ecosystem

cyberespionage

Cython

Czech Republic

dangling resources

data exfiltration

data exposure

data extortion

data leak site

data theft

data-exfiltration

database extortion

Datadog Security Labs

dataset processing

DAYLIGHT

DCloud

DCloud Uni-App

DcRAT

DD-WRT

DDNS

DDoS

DDoS botnet

DDoS-for-hire

dead drop

dead drop resolver

dead-drop resolver

Debian

DEBULL

declarativeNetRequest

DeepAudit

DeepSeek

Defender Advanced Hunting

Defender evasion

Defender exclusion

defense

defense evasion

defense targeting

defense-evasion

DeFi

delayed execution

denial of service

Deno

dependency confusion

deployment_status

deserialization

destructive malware

destructive operations

detection engineering

DEV-0206

developer credential theft

developer credentials

developer endpoints

Developer ID abuse

developer identity

developer infrastructure

developer machines

developer mode

developer platform

developer targeting

developer tooling

developer workstations

developer-machine-fleet

developer-targeting

developer-tools

developer-workstations

device lockout

device registration

device-code phishing

DevOps

DevTools

DEWMODE

DGA

DIAMONDBACK

Digital Knowledge

digital wallets

DigitalOcean

Dindoor

diplomatic targeting

DirtyClone

DirtyFrag

Discord

discovery

disk wiping

distributed scanning

Djinn Stealer

DLL side-loading

DLL sideloading

DNS C2

DNS callback

DNS dead drop

DNS exfiltration

DNS threat intelligence

DNS tunneling

DNS-over-HTTPS

Docker

Docker credentials

Docker images

Docker socket

document collection

document exfiltration

document theft

DOGLEASH

domain squatting

domestic espionage

dormant accounts

DotNetNuke

DotnetTool

double extortion

downgrade risk

downloader

DPAPI

DPAPILoader

DPRK

driver loading

Dropbear

Dropbox

dropper

Drupal

duckdns

Dutch Police

DWAgent

dynamic DNS

dynamic obfuscation

Dynu

e-commerce

Eagle Werewolf

Earth Lusca

East Asia

East Asia-linked

eBPF

Eclipse

Ed25519

edge appliance

edge appliances

edge application server

edge device

edge devices

edge exploitation

Edge extension

edge service

edge services

editor profile import

EDR evasion

EDR killer

EDS5000

education

Egnyte

EKZ Infostealer

Elastic Security Labs

Elasticsearch

electric power sector

Electron

email

email exfiltration

email gateway

email infrastructure abuse

email theft

embedded systems

Emerald Sleet

ENCFORGE

encrypted C2

endpoint management

endpoint management abuse

endpoint response

endpoint-detection

endpoint-security

EndpointDlp.dll

energy sector

energy-sector

engineering

engineering software

enterprise application

enterprise application exploitation

enterprise applications

Entra ID

Environment Management Hub

environment variable theft

environment variables

environmental keying

epoll

Epsilon Stealer

ERP

eSentire TRU

ESG

espionage

Espressif ESP-IDF

ESXi

Ethereum

EtherHiding

ETW bypass

ETW patching

ETW tampering

Eurojust

Europe

Europe targeting

European Union

Europol

evasion

event log clearing

eventpoll

Everest Forms Pro

evidence quality

Evil Corp

EvilAI

Evilginx

excessive agency

exec_globals

exFAT

exfiltration

exploit chain

exploit-development

exploit-kit

Exploit.in

exploitation

exploitation attempts

ExploitGym

exposed attacker infrastructure

extension supply-chain

external federation

extortion

F5

F5 BIG-IP

Factory-v3

fake app store

fake CAPTCHA

fake certificate

fake crypto exchange

fake dating lures

fake gambling

fake installers

fake login screen

fake Microsoft Store

fake plugin

fake PoC

fake ransomware

fake recruiting

fake reputation

fake update

FakeCaptcha

FakeGit

Fakeset

faketivism

FakeUpdates

FallSpy

FAMOUS CHOLLIMA

Famous Chollima

Fancy Bear

Fast16

FastAPI

FastCGI

Fastjson

fat JAR

FAT32

FatFs

FBI

FFmpeg

FIDO2

FIFA

file encryption

file exfiltration

file inflation

file sharing

file theft

File Transmission

file upload path traversal

file-system filter

FileFiend

FILEIO

fileless execution

fileless malware

filemanager

filename-injection

filesystem parser

finance

financial fraud

financial sector

financial services

financial theft

financially motivated

FireAnt MetaKit

Firefox Add-ons

Firefox WebDriver BiDi

firewall

firewall management

firmware

firmware update

FishMonger

FlexPLM

FlockWiper

flow execution

Flowerbed

FLUIDLEECH

Flutter

FlutterShell

FOFA

folderOpen

foreign affairs targeting

foreign policy targeting

Forest Blizzard

Forg365

ForgCookie

Forgejo

FortiClient EMS

FortiGate

Fortinet

FortiOS

FortiSandbox

Fox Tempest

fraud

FREAKYPOLL

FreeBSD

Freedom365

freeware impersonation

Friendly Fire

FSB

FSB Center 16

fscan

FTA

ftp.exe

Full Disk Access social engineering

Funnull

futex PI

Gafgyt

GaiaOS WebUI

Gamaredon

Gamaredon collaboration

gambling

gambling industry targeting

game cheats

GammaLoad

GammaPhish

GammaSteel

GammaWorm

Garble

Gardener

Gatekeeper bypass

GCS

Gemini CLI

GentleKiller

Germany

GHETTOVIBE

Ghost

ghost accounts

Ghost CMS

Ghost Networks

GhostLock

GHSA-6rmh-7xcm-cpxj

GHSA-6v3r-4p5c-mrp5

GHSA-qrpv-q767-xqq2

GHSA-xhcr-j4j9-3gh7

GIFTEDCROOK

Git

git.exe

Gitea

GitHub

GitHub abuse

GitHub Actions

GitHub API

GitHub App

GitHub CLI

GitHub dead drop

GitHub issue spam

GitHub OAuth

GitHub Pages abuse

GitHub payload delivery

GitHub release assets

GitHub Security Advisories

GitHub tokens

GitHub-hosted runners

GitLab

gitleaks

GitOps

Gleaming Pisces

gleeze.com

GlobalProtect

Gmail

Go

Go loader

Go malware

Go modules

Go2Tunnel

GodDamn ransomware

Godzilla

GoEdge

GoFile

Golang

Golang malware

GOLD PRELUDE

Google Analytics telemetry

Google API

Google Calendar

Google Chrome

Google Cloud

Google Cloud Logging

Google Cloud Storage

Google credential theft

Google Docs

Google Drive

Google Notes

Google Play

Google Play Protect

Google redirect abuse

Google Sheets

Google Stitch

Google Threat Intelligence Group

Google Workspace

Goose

GoSerpent

government

government targeting

government-impersonation

GPT

GPT-5.6 Sol

Gradio

Grandoreiro

granular access tokens

GraphSpy

Gravity SMTP

GRE

GREYVIBE

group

groups

gRPC

gRPC C2

GRU

gs-netcat

GS-Netcat

Gshell

GTIG

GUE

guest-to-host escape

Guildma

hack-and-leak

HackIndex

hacktivist persona

Hades

Hajime

hallucination

HalluSquatting

Handala

HappyDoor

HAR files

hard-coded secrets

HarmonyLib

HashiCorp Vault

HavocKiller

headless browser

healthcare

heap buffer overflow

heap pointer disclosure

HelloBackdoor

HelloCleaner

HelloDoor

HelloExecutor

HelloInjector

HelloNet

HelloProxy

HellsGate

Helm

Hermes Agent

HexKiller

hidden backdoor

hidden instructions

hidden service

high explosives

higher education

HOLLOWGRAPH

Honduras

HONESTCUE

Hong Kong infrastructure

hospitality targeting

Host Radar

host surveillance

hosting control plane

hosting provider

hosting providers

hotel targeting

Howling Scorpius

HPC

HR lures

HTA

HTML comments

HTML email

HTML smuggling

HTTP C2

HTTP/2

HttpMalice

HTTPS C2

HTTPS exfiltration

HTTPSpy

Hugging Face

Hunt.io

Huntress

Hyadina

hybrid threat actor

hydropower

Hydropower Cooperation Project Proposal.zip

hypervisor escape

Hyunwoo Kim

I-SOON

iCagenda

ICE

ICONICSTEALER

ICS

IDE extension

IDE plugins

ide.cfm

identity

identity attacks

identity compromise

identity infrastructure

identity security

identity-first intrusion

IDEs

IFEO persistence

IIOP

IIS

IKEv1

image recognition

iMessage

Impacket

impersonation

implant

import-time execution

improper privilege management

in-memory DLL loading

in-memory plugins

incident response

incident-response

IndexedDB

India

India-nexus

Indian government

indirect prompt injection

indirect syscalls

Indonesia

industrial control

industrial control systems

industrial targeting

INFINITERED

Infoblox Threat Intel

information disclosure

infostealer

InfoTeCS

infrastructure

infrastructure disruption

initial access broker

initial-access

Injective Labs

input capture

install-time execution

install-time-execution

install.res.1033.dll

Integration Broker

Intercolo

internet-facing admin surface

internet-facing appliance

internet-facing applications

investment scam

InvisibleFerret

iOS

IoT

IoT botnet

IP cameras

IP-in-IP

IPFS

IPsec

IPv6

ipynbdiff

Iran

Iran-nexus

IRGC

IronWorm

ischhfd83

Island Security Research

ISO image

Israel

IT providers

Italian foreign-policy targeting

Italy targeting

Ivanti Sentry

JADEPUFFER

Jamf Threat Labs

Januscape

Japan

JARLEASH

Java

Java malware

JavaScript

JavaScript bridge

JavaScript execution

JavaScript injection

JavaScript loader

JavaScript malware

JavaScript masquerading

JavaScript tampering

JavaScriptCore

JCE

JDY

Jellyfin

Jenkins

JetBrains

JetBrains Marketplace

JetStream

JFrog

JFrog Security Research

JINX-0164

joblib

Joomla

Joomla Content Editor

Joomla JCE

Joomlack

JoomShaper

journalists

JSCoreRunner

jscrambler

Jscrambler

JScript

JSON

JSON:API

JSONKeeper

JSONPing

JSP web shell

JuicyPotato

Jupyter Notebook

JustWatch

JXA downloader

K1MORPHER

Kairos

Kaitori

Kali365

Kaspersky

Kaspersky GReAT

Kaspersky Securelist

Kazakhstan

KAZUAR

KAZUAR overlap

Keitaro

Keksec

Kemp LoadMaster

kernel driver

kernel instrumentation

kernelCTF

KEV

Keychain theft

keychain theft

KeyHunter

keylogger

keylogging

Kimsuky

Klue

KnowledgeDeliver

KNUCKLEBALL

KNX

KNX Association

KNX Protocol

KongTuke

KORKERDS

Kratos

Kubernetes

KV-botnet

KVM

KVM escape

kvmCTF

L2TP/IPSec

LA Metro

LabubaPanel

LabubaRAT

LangChain

Langflow

LangFlow

LangGraph

Language Servers for AWS

Lantronix

LapDogs

Laravel

Laravel deserialization

lateral movement

lateral-movement

Latin America

LaunchAgent

launchctl

LAUNDRY BEAR

law enforcement

law enforcement targeting

law-enforcement-disruption

LayerX

Lazarus

LD_PRELOAD

LDAP

leaked credentials

LEASHTEST

least privilege

Ledger

legacy botnet hijacking

legacy infrastructure

legacy software

LegionRelay

Leo Platform

Level RMM

LevelBlue

Lexfo

libcurl

liblzma

libp2p

libpeconv

lifecycle hooks

lifecycle-hooks

Lightning Shared Scooter Co.

LinkedIn

Linksys

Linux

Linux kernel

Linux malware

Linux networking devices

LiteLLM

LiteSpeed

living off the land

living-off-the-land

living-off-the-land binaries

LLM

LLM security

LLM-assisted malware

LLM-driven intrusion

LLMjacking

LMS

LNK

LNK files

load balancer

loader

LOADLOOP

local LLMs

local privilege escalation

local-file-inclusion

localhost

log poisoning

logging

login item persistence

LOLBins

long-horizon autonomy

long-lived tokens

long-term access

LONGLEASH

LONGSTREAM

LOOKVALJS

LOOKVALPS

loopback

Loophole

low-confidence attribution

LPE

LS-DYNA

LSASS

LSHIY

LSSC

Lua

LuaJIT

Lumen

Lumen Black Lotus Labs

Lumma Stealer

Luna Moth

Luno

Lyceum

M-RED-TEAM

MaaS

MAC address

MacCMS

Maccy impersonation

machine-learning

macOS

macOS malware

MaDoO Blaster

Magento

MagicYUV

mail server compromise

mail-argenta

mailbox compromise

mailbox theft

MAIN world injection

maintainer compromise

maintainer persona

maintainer-compromise

malicious dataset

malicious GPO

malicious packages

malicious plugin

malicious releases

malicious signed driver

malvertising

malware

malware analysis

malware delivery

malware framework

Malware-as-a-Service

malware-as-a-service

malware-signing-as-a-service

MALXMR

managed file transfer

managed service provider

ManageEngine Endpoint Central

management plane

Manifest V3

Manifold Security

manufacturing

Mapbox

marimo

MARKETMAKER

marketplace abuse

marketplace trust

MarkiRAT

Maven Central

mawesome

Mbed

McAfee Labs

McMx

MCP

MCP credentials

media processing

medical research

Mekotio

memfd

memory corruption

memory disclosure

memory implant

memory overread

memory poisoning

memory-only malware

merchant credential theft

MeshAgent

MeshCentral

MetaMask

MEV bot lure

Mexican banking fraud

Mexico

MFA bypass

MFA fatigue

MFA-bypass

Miasma

MicroPython

Microsoft

Microsoft .NET

Microsoft 365

Microsoft 365 Copilot

Microsoft Authentication Broker

Microsoft Defender

Microsoft Defender Security Research

Microsoft dev tunnels

Microsoft Digital Crimes Unit

Microsoft Edge

Microsoft Edge Add-ons

Microsoft Edge Extensions Security Team

Microsoft Entra ID

Microsoft Graph

Microsoft Identity Platform

Microsoft Office SharePoint

Microsoft Security Blog

Microsoft SQL Server

Microsoft Teams

Microsoft Threat Intelligence

Microsoft Windows Hardware Compatibility Publisher

Microsoft-signed binary abuse

Middle East

middleware

Midnight Blizzard

military logistics

military research

Mimikatz

Minecraft DDoS

Mini Shai-Hulud

MiniJunk

MiniPlasma

MINIRAT

MINIRECON

Ministry of Finance

MiniUpdate

MIPS embedded devices

Mirai

Mirai-derived botnet

Mistic

MITRE ATT&CK T1005

MITRE ATT&CK T1562

mixed boolean arithmetic

MIXEDKEY

MLTBackdoor

mnemonic theft

mobile

Mobile Access

mobile banking fraud

mobile device management

mobile devices

mobile malware

MobileIron Sentry

MODBEACON

Model Context Protocol

model poisoning

model weights

model-provider abuse

ModeloRAT

ModHeader

modular malware

module-proxy

MOIS

Monero

Monero mining

Monster ransomware

Mozi

MpClient.dll

MpExtMs.exe

MPR network provider

Mr_Rot13

MSBuild

msgpack

mshta

MSI

MSP

MSSQL

mTLS

Muck and Load

MuddyWater

Mullvad VPN

Multi-Domain Security Management

multi-tenant cloud

Mustang Panda

Mustard Tempest

mutable tags

MYRA

MySQL

Mysterious Elephant

Mythos

n8n

Nacos

NadMesh

named pipes

namespace recycling

namespace squatting

NAS targeting

nation-state

national identity records

native addon

native extension

NativeAOT

NATO

NATS

NCSC-NL

Nebo

Nebula Security

negotiation

Neo-reGeorg

nested virtualization

Neteller

Netherlands

Netlify abuse

NetNut

NetScaler

NetScaler ADC

NetScaler Gateway

network infrastructure

network infrastructure exploitation

network policies

network-share exfiltration

Nextcloud

Nextcloud Flow

nf_tables

nftables

NGINX

Nginx

Nginx module

Ngrok C2

Nigeria-nexus

NirSoft

no attribution

No-IP

node-gyp

node-ipc

node-pty

Node.js

Node.js implant

Node.js malware

North Korea

notarized malware

notification interception

npm

npm lifecycle hook

npm supply-chain

npm token theft

npm tokens

npm v12

npx

NSecKrnl.sys

NTDS.dit

NTFS ADS

NTLM

nuclear weapons

NuGet

Nuitka

null-byte padding

NVGRE

NVIDIA impersonation

O-UNC-066

OAuth

OAuth abuse

OAuth client credentials

OAuth device authorization grant

OAuth redirect

OAuth token abuse

OAuth token exposure

OAuth tokens

OBF networks

obfuscation

obfuscator.io

Oblivion

obsolete software

Octopi365

OFAC

official store compromise

Offshore LC

OIDC

OilRig

Oj

OkoBot

Okta

Okta Threat Intelligence

OKX

Ollama

Oman

Omnibox

OneDrive

OneDrive access

opaque predicates

open directory

Open Interpreter

Open WebUI

OpenAI

OpenAI Codex

OpenClaw

opencode

OpenConnect

OpenHands

OpenSearch

OpenShield

OpenSSH

OpenVPN

OpenVPN-shaped UDP

OpenVSX

operation

Operation BlueDash

Operation DangerousPassword

Operation Endgame

Operation Highland

operational relay box

Operational Relay Box

operational resilience

operational security

operational technology

operations

OpFauxSign

ops

opsec failure

Oracle

Oracle E-Business Suite

Oracle Payments

Oracle PeopleSoft

Oracle WebLogic Server

ORANGETAIL

ORB network

OS command injection

OT

OT switches

OTA update

OTP interception

OtterCookie

out-of-bounds write

Outlook

overlay attacks

OX Security

OxideHarvest

OYSTERBLUES

OYSTERFRESH

OYSTERSHUCK

P2P

P2P C2

package masquerading

package registry

package registry abuse

package registry credentials

package registry proxy

package republishing

package scanning

package takedown

package-cooldowns

package-manager-hardening

package-splitting

package-takeover

Packagist

Page Builder CK

page cache

page poisoning

Pakistan

Pakistan-linked

Palo Alto Networks

PAM

PAM credential validation

PamStealer

PAN-OS

parallel-intrusion

passkeys

password manager theft

password spray

password spraying

password-protected archive

Pastebin

PAT theft

patch management

path hijacking

path traversal

Patriot Bait

patterns

payload loader

payload staging

payload-as-a-service

payment fraud

payment SDK

payment skimmer

payment workflow exposure

payment-card theft

payment-card-theft

PayPal

payroll lures

Paysafe

pe_to_shellcode

PebbleDash

pedit

pentesting

people

PeopleTools

PerfWatson2.exe

Perplexity AI

persistence

persistent root access

persona operations

personal access tokens

pfSense

PhaaS

Phantom Gyp

PhantomClick

PhantomMail

PhantomRelay

Philippines

phishing

phishing-as-a-service

PHP

PHP code execution

PHP code injection

PHP object injection

PHP upload

PHP web shell

physical systems

physics

PicassoLoader

pickle

pig butchering

pig-butchering

Pink

pipelines

piracy

Piriform

Pix

Pixeldrain

PixelSmash

PKGBUILD

plaintext HTTP

Plandex

PLENET

plugin architecture

PlugX

poisoned-branch

PoisonX

police digital services

PolinRider

Poly1305

polyfill

Polygon

Polygon blockchain dead drop

Polymarket

polymorphic loader

polymorphic payloads

Popa

portmap

Portugal

post-authentication RCE

post-exploitation

post-exploitation framework

postal-impersonation

PostCSS

PostgreSQL

postinstall

PowerCloud

PowerShell

PowerShell execution

PowerShell malware

PowerShower

PPtP

PRA

PraisonAI

PRC

PRC-aligned

PRC-nexus

pre-auth RCE

pre-authentication

pre-authentication RCE

preinstall

Primitive Bear

PrincessClub

priority inheritance

privacy

privacy exposure

private key theft

private registry fallback

private-key theft

privilege escalation

Privileged Remote Access

process doppelgänging

process environment scraping

process hollowing

process injection

product lifecycle management

professional services

profile.d

Progress Kemp LoadMaster

Progress Software

Project Proposal.exe

prompt injection

prompt-injection

PROMPTFLUX

PROMPTSPY

promptware

proof of deletion

Proofpoint

protestware

Protobuf

provenance

proxy

proxy network

ProxyChains

proxyjacking

proxyware

prt-scan

PSEMHUB

PsExec

PSIGW

psychological operations

PTC

PteroBox

PteroPaste

PteroPSDoor

PteroSetup

PteroVDoor

public exploit

public file-transfer exfiltration

public proof of concept

public sector

public service abuse

pull requests

PUP

PureLogs Stealer

PureRAT

pwn-request

PyArmor

PyInstaller

PyPI

Python

Python extension modules

Python malware

Python stealer

Qianxin Threat Intelligence Center

QiAnXin XLab

Qilin

QNAP

QR code

QR code interception

quantum computing

Quasar

query injection

Quest KACE SMA

QuimaRAT

RaaS

RabbitMQ

race condition

RainbowEx

RakNet flood

RAM disk

Ransom-ISAC

ransomware

ransomware access

ransomware enablement

ransomware-access

rapid exploitation

Rapid7

RAR archives

RAR staging

RAT

RC4

RC4 C2

RCE

Rclone

rclone

RCS

RDP

RDP phishing

RDS

Reality

Reaper

reconnaissance

recovery denial

recovery disruption

recruitment lures

Red Dev 10

Red Hat

Red Raindrop Team

REDCap

Redis

Redis backdoor

RediSearch

reduced cyber refusals

RedWing

REF6045

REF9403

reflective .NET loading

reflective loading

refresh token theft

refresh tokens

RegAsm process hollowing

registry persistence

registry-controls

release automation

release tampering

Remcos

Remcos RAT

remote access

remote access software

remote access trojan

Remote Access VPN

remote code execution

remote debugging

remote MCP

remote monitoring and management

remote script injection

Remote Support

remote support

Remote Utilities

remote-access

Remotely

RemotePE

RemotePELoader

removable media

Rentry

replication

repo-server

repository compromise

repository exfiltration

repository poisoning

research sector

residential proxies

residential proxy

REST API

REST C2

restart-triggered execution

retail trading

reverse proxy

reverse SSH tunneling

reverse tunneling

REVERSE_PROXY_TRUSTED_PROXIES

ReverseSocks

reviewdog

Rilide

RingH23

RMM

RMM abuse

ROADrecon

ROADtools

roadtx

Rokarolla

RokRAT

Rollup

RomulusLoader

Roo-Code

root

root access

root escalation

root execution

rootkit

ROOTRUN

ROPC

Rouki obfuscation

Roundcube

router

router compromise

router malware

ROX II

RSA

RSA-2048

RSA-OAEP

RT-Thread

RTL819X

RTLO

rtmutex

RubyGems

Ruckus routers

RUGGEDCOM

Run key

Run key persistence

rundll32

Runner.Worker

Runspace

runtime execution

runtime mutation

runtime patching

runZero

Russia

Russia-affiliated

Russia-linked

Russia-linked cybercrime

Russia-nexus

Russia-speaking operator

Russian Intelligence Services

Russian intelligence services

Russian state-supported

Russian-speaking ecosystem

Russian-speaking forums

Rust

Rust malware

S3 Browser

S3-compatible storage

s5cmd

SaaS

SaaS abuse

SaaS data access

SaaS exposure

sabotage

Safari

SafeDep

Salesforce

SAML IdP

Samsung TizenRT

sandbox escape

sandbox evasion

sandboxing

Sandworm

saroula01

scam infrastructure

scambling

scanner evasion

ScarCruft

scheduled task

scheduled task persistence

scheduled tasks

SCMBANKER

scope squatting

scoped package impersonation

SCOUTCURL

screen capture

ScreenConnect

Screening Serpens

screenshot capture

screenshot theft

script-injection

SD-WAN

search hijacking

search poisoning

search result poisoning

search-ms

Seashell Blizzard

Secret Blizzard

secret exposure

secrets

secrets management

Secure Preferences

Security Management Server

security platform

security-tool discovery

seed phrase theft

SeedHunter

Seedworm

segmented networks

Sekoia

self-delete

self-hosted AI services

self-hosted media

self-hosted runner

self-propagation

semantic-release

sendit.sh

sensitive information exposure

Sentinel

SentinelOne

Sentry

Sentry abuse

SEO poisoning

Seqrite Labs

Serv-U

service accounts

service persistence

service providers

service-agent

ServiceNow

ServiceNow AI Platform

ServiceWorker

session hijacking

session secret exposure

session theft

session token theft

setuid

shadow copy deletion

shadow MMU

SHADOW-AETHER-040

SHADOW-AETHER-064

SHADOW-EARTH-066

SHADOW-WATER-063

ShadowPad

Shai-Hulud

SHARDLOADER

share propagation

shared hosting

shared secrets

SharedWorker

ShareFile

SharePoint

SharePoint Server

SharkLoader

shell injection

ShinyHunters

Shodan

ShortLeash

Shuckworm

SideCopy

sideloading

Siemens

Signal

Signal interception

signed malware

signed updates

signed-binary

Silent Ransom Group

Silent Swap

SilentCryptoMiner

SilentRunLoader

SiliconFlow

Silver Fox

SimpleHelp

SimpleHTTPServer exposure

simulation tampering

Site Member permissions

skb

SkillCloak

SkillDetonate

Skrill

sleeper packages

Sliver

SLSA

SLSA provenance

SMA1000

smart building

smart TVs

SMARTAXE

SmartConsole

SmartLoader

SmartScreen

SMB

SMB brute force

SMB egress

smishing

SMS interception

sms-phishing

SMTP

SMTP abuse

Snake

Sneaky 2FA

SNOWLIGHT

SOAP API abuse

SocGholish

social engineering

social-engineering

Socket

Socket Security

Socket Security Research

Socket.IO

SOCKS tunneling

SOCKS5

SOCKS5 proxy

SOCKS5 tunneling

SOCRadar

SoftEther VPN

software impersonation

software supply chain

software-deployment

SOHO router

SOHO routers

Solana

SolarWinds

Solid PDF Creator

SolidPDFCreator.dll

SolidPDFPcl2Bmp

SonicWall

Sophos

source code

source control

source repository compromise

source-code compromise

source-control token theft

source-package drift

source-package mismatch

source-repository poisoning

source-repository reconnaissance

SourceForge abuse

SourTrade

South Africa

South Asia

South Korea

Southeast Asia

SP Page Builder

spam

spear phishing

spear-phishing

spearphishing

SPECTRALVIPER

Sphinx ransomware

SpiderLabs

Spikey Scorpius

Splunk

Spring Boot

SprySOCKS

spyware

SQL injection

SQLite

SQLite state

SquareShell

SSDP

SSH

SSH backdoor

SSH bastion

SSH brute force

SSH key exposure

SSH key persistence

SSH keys

SSH lateral movement

SSH persistence

SSH tunnel

SSH tunneling

SSH tunnels

SSL VPN

SSRF

stack use-after-free

staged malicious update

stale access

stale credentials

Starland RAT

Startup folder

Startup folder persistence

state-linked

state-owned enterprise

Static Kitten

stdio

StealC

stealer

Steam profile dead drop

steganography

StegoAd

StepSecurity

STM32Cube

stock exchange

STOCKSTAY

storage deletion

Storage Zone Controller

stored XSS

Storm-2603

Storm-2697

Storm-3075

Stowaway

STRD

streaming boxes

Stripe OLT

student targeting

STUN

Stuxnet lineage

subject claim

SuccessKey

SUMMIT

Suo5

Supabase

SUPERADMIN_SECRET

supply chain

supply chain compromise

supply-chain

supply-chain attribution

supply-chain integrity

supply-chain-adjacent

surveillance

suspected China-aligned

suspected China-linked

SVG

SWE-agent

SWUpdate

Symantec Threat Hunter Team

Synacktiv

Synology

synthetic commits

Sysdig

SYSTEM

SystemBC

systemd

systemd-userdbd

T1204.004

T3

TA427

TA488

TA569

Tactical RMM

tag rewrite

tag tampering

TAG-124

TAG-179

TAG-182

TAG-22

Taiwan

takedown

TamperedChef

targeted malware

targeted operations

TartarusGate

task queue

task scheduler abuse

TaskWeaver

tax-season phishing

tc

TCP traffic diversion

TDS

TeamPCP

TeamPCP-adjacent

Teams access

TeamViewer

TEASOUP

Tebi

technician session

telecom

telecom-impersonation

telecommunications

Telegra.ph

Telegram

telegram

Telegram bot

Telegram C2

Telegram dead drop

Telegram exfiltration

Telegram notification

telemetry

TELEPUZ

TELESHIM

Teletype

Telnet

Telnet brute force

Telnyx

Temp Zagros

template injection

tenant-project

TencShell

Tenda

Tenet Security

Tetrade

TetrisPhantom

TeviRAT

Thailand

The Gentlemen

The Hacker News

The Quarry

ThemeREX Addons

third-party integrations

threat hunting

threat landscape

ThrottleBlood

ThumbcacheService

thumbnail generation

TinyGo

TinyRCT

tj-actions

TmcLoader

TmcPayload

ToddyCat

token forgery

token replay

token theft

token-theft

TONESHELL

TookPS

tool

tool execution

tool output injection

tool poisoning

tool use

tooling

tools

Tor

Total Software Deployment

Trading Technologies

TradingView

traffic broker

traffic control

traffic hijacking

traffic-distribution-system

traffic-fraud

training data

transaction authority

transitive dependency

transnational repression

Transparent Tribe

transport

transportation

Trend Micro

TrendAI

Trezor

TrickBot

Trident Ursa

trojanized installers

Tron

trusted extension risk

trusted publishing

tunnel decapsulation

tunnel services

Turla

Turla collaboration

TuxBot

TuxBot v3 Evolution

Twilio

Twilio SendGrid

Tycoon2FA

TypeScript

typosquat

typosquatting

UAC

UAC bypass

UAC-0002

UAC-0010

UAC-0098

UAC-0145

UAC-0194

UAC-0226

UAT-11795

UAT-5918

UAT-7237

UAT-7810

Ubiquiti

Ubuntu

Udev persistence

UDP C2

UDP/1900

Ukraine

Ukraine targeting

Ulej

UltraVNC

Umbrij

unauthenticated access

unauthenticated HTTP exploitation

unauthenticated RCE

UNC1543

UNC2814

UNC3753

UNC4221

UNC4736

UNC5792

UNC6240

UNC6508

UNC6671

UNC6692

UNC6780

Uni-App

UniFi OS

Unified CM SME

uninitialized heap memory

Unit 42

United States

university targeting

UNK_MassTraction

UNK_PitStop

unpatched vulnerability

unsafe deserialization

unsigned installer

UpdateFactory

UPnP

UPX

uranium compression

USB propagation

USB weaponizer

USB worm

use-after-free

user execution

user namespaces

UTA0355

UTA0533

UTG-Q-1000

uTLS

V2Ray

V4bel

V8

valid accounts

ValleyRAT

VBCloud

VBE

VBS

VBScript

vector databases

VEIL#DROP

Velociraptor

Velvet Ant

VELVETSHELL

vendor compromise

vendor credentials

VENOMOUS BEAR

Vercel

Vertex AI

VIDAR

Vidar Stealer

Vietnam

Vietnam-aligned

Views

ViewState deserialization

ViPNet

virtualization

VirusTotal sentiment abuse

vishing

Visual Studio

Visual Studio Code Remote SSH

Vite

Vitest

ViteVenom

VLESS

vManage

VMware

VNC

VNT

Void Blizzard

Void Manticore

Volt Typhoon

volume serial number

VPN

VPN credentials

VPN gateway

VPN Go

VPN session hijacking

VS Code

VS Code tunnels

Vshell

VShell

VSIX

vSphere

VU#213560

VulnCheck

vulnerability

vulnerability exploitation

vulnerability research

vulnerability-research

vulnerable appliances

VXLAN

w3wp.exe

wallet address replacement

wallet drainer

wallet infrastructure

wallet replacement

wallet theft

wallet-drainer

wallet-theft

Wasabi

watchdog

watchTowr

watchTowr Labs

watering hole

watering-hole

weak credentials

weak passwords

weapons shipments

web application

web application compromise

web hosting

web IDE

web injection

web injector

web management interface

web proxy

web RCE

web server

web shell

web shell hunting

web shells

web supply chain

web-shells

WebAssembly

WebDAV

WebKit

WebLogic

webmail

WebRTC

webshell

webshells

website-compromise

WebSocket

WebSocket C2

websocket-sharp

WebView

WebView2 C2

Webworm

Werkbit

WhatsApp

WhatsApp phishing

WHM

Widget Factory

wiki

WILDDAY

Windchill

WinDirStat

Windmill

Windows

Windows Defender

Windows Defender exclusions

Windows Forms

Windows malware

Windows persistence

Windows Run dialog

Windows Script Host

Windows servers

Windows service persistence

Windows Terminal

Winnti Group

WinOS

Winos4.0

WinPython

WinRAR

wiper

wiper-adjacent

WireGuard

Wiz Research

WLDR agent

WM_COPYDATA IPC

WMI

Woodgnat

WordPress

WordPress credential theft

workflow backdoor

working-directory hijacking

workspace trust

World Cup

worm

WP Maps Pro

WP-SHELLSTORM

wp2shell

WScript

X-Secret

X-WEBAUTH-USER

X25519

X3D MINER

X_TRADER

XChaCha20

XenoRAT

XFRM

xlabs_v1

XMLDecoder

XMRig

XOR

XOR obfuscation

Xray

XSLT SSRF

XSS

XSS.is

XXE

xz

Yanbian

YesWeHack

YouTube abuse

Yuechi Shared Technology

yuze

ZAPiXDESK

Zendesk

Zephyr RTOS

Zero Trust

zero-click

zero-day

zero-day exploitation

zero-reputation infrastructure

ZeroBEC

Zimbra

Zimbra Collaboration Suite

Zimperium

zLabs

Zoho Assist

Zoho WorkDrive

ZOHOMURK

Zoom