Tag index
Generated from page-level ## Tags sections. Each tag below links to the pages that currently use it.
All tags
- .NET (10)
- .NET deserialization (1)
- .NET downloaders (1)
- .NET malware (7)
- .NET reflection (1)
- .pth (2)
- .vu TLD (1)
- /accessv2 (1)
- /api/session/reset_password (1)
- /dev/kvm (1)
- /proc/1/environ (1)
- 0-day (1)
- 0.14.3 (1)
- 0x50594d (1)
- 146.70.139.154 (1)
- 158.220.87.79 (1)
- 192.42.116.105 (1)
- 192.42.116.58 (1)
- 1H 2026 State of Exploitation (1)
- 2FA bypass (2)
- 2FA harvesting (1)
- 2FA recovery codes (1)
- 3CX (1)
- 404 TDS (1)
- 43.228.157.68 (1)
- 4sync (1)
- @gl_introduced (1)
- @marketfront (1)
- @tqm-mfe (1)
.bin(1)<all_urls>(1)- AA26-231A (1)
- AA26-237A (1)
- AAA virtual server (2)
- Ababil of Minab (1)
- ABRT (1)
- abuse response (1)
- academia (1)
- academic research (1)
- academic sector (2)
- Accellion (1)
- access as a service (2)
- access broker (2)
- access brokers (2)
- access control (1)
- access control bypass (1)
- access keys (1)
- access optionality (1)
- access token abuse (1)
- access token theft (1)
- Accessibility Service (1)
- account abuse (1)
- account hijacking (1)
- account lockout (1)
- account takeover (7)
- account-takeover (1)
- ACR Stealer (2)
- AcridRain (1)
- Acronis (1)
- Acronis TRU (1)
- act_pedit (1)
- ACTINIUM (1)
- Activator.CreateInstance (1)
- Active Directory (3)
- active exploitation (77)
- active probing (1)
- active threat (3)
- active-exploitation (1)
- ActiveCampaign (1)
- actively-exploited (1)
- ActiveX (1)
- activism (1)
- actor (6)
- actors (13)
- ad blocker (1)
- AD CS (1)
- ad fraud (2)
- adaptive identity management (1)
- adaptive identity phishing (1)
- Adaptix C2 (1)
- AdaptixC2 (1)
- ADB TCP/5555 (2)
- Adblock for YouTube (1)
- add/add collision (1)
- addon domain (1)
- Adform (1)
- ADFS (1)
- Admin API key theft (1)
- admin takeover (1)
- administrator account creation (2)
- Adobe ColdFusion (1)
- Adobe Commerce (1)
- ADP vs vendor CVSS divergence (1)
- ADS (1)
- Adspect (1)
- Advanced IP Scanner (1)
- advanced persistent threat (1)
- Advanced Protection (1)
- Adversa (1)
- Adversa AI (1)
- adversary-in-the-middle (7)
- advertising technology (1)
- adware (6)
- adware history (1)
- aerospace (3)
- AES encrypted payload (1)
- AES-128-CBC (1)
- AES-256-CTR (1)
- AES-256-GCM (2)
- AES-CTR (1)
- AES-GCM (3)
- AES-GCM C2 (1)
- Aeternum (1)
- AFD.sys (1)
- affiliate hijacking (1)
- Afghan telecom (1)
- Afghanistan (4)
- AFP (1)
- Africa (4)
- agent containment (1)
- agent frameworks (3)
- agent hooks (1)
- agent logs (1)
- agent memory (1)
- agent monitoring (1)
- agent platforms (1)
- agent polling protocol (1)
- agent skills (2)
- agent state (1)
- agent-to-agent (1)
- AgentBaiting (1)
- agentic AI (10)
- agentic botnets (1)
- agentic browser (1)
- agentic browsers (1)
- agentic evaluation (1)
- agentic execution (1)
- agentic IDE (1)
- agentic malware (1)
- agentic pipeline (1)
- agentic ransomware (1)
- agentic threat actor (2)
- Agentjacking (1)
- AGENTPSD (2)
- AgentWorm (1)
- agetty (1)
- AI (7)
- AI agent (3)
- AI agent security (3)
- AI agent tooling (1)
- AI agents (25)
- AI anti-analysis (1)
- AI application infrastructure (7)
- AI assistant credentials (2)
- AI assistants (4)
- AI benchmarks (1)
- AI brand impersonation (2)
- AI browsers (2)
- AI chatbot abuse (1)
- AI coding agents (3)
- AI credential theft (1)
- AI data exfiltration (1)
- AI developer tooling (3)
- AI framework (1)
- AI gateway (1)
- AI IDE (1)
- AI infrastructure (3)
- AI infrastructure hijacking (1)
- AI memory poisoning (1)
- AI model encryption (1)
- AI model evaluation (2)
- AI Now Institute (1)
- AI pentesting (1)
- AI search poisoning (1)
- AI security (3)
- AI services (1)
- AI supply chain (1)
- AI tooling (17)
- AI tools (1)
- AI trust boundary (1)
- AI vishing (1)
- AI vulnerability consumption (1)
- AI vulnerability discovery (1)
- AI website builder (1)
- AI workflow (1)
- ai-abuse (1)
- ai-agent (1)
- AI-assisted (1)
- AI-assisted C2 (1)
- AI-assisted development (3)
- AI-assisted exploit (1)
- AI-assisted intrusion (1)
- AI-assisted malware (3)
- AI-assisted malware development (4)
- AI-assisted phishing (1)
- AI-assisted vulnerability discovery (1)
- AI-augmented operations (4)
- AI-enabled malware (1)
- AI-enhanced malware (1)
- AI-generated advisory (1)
- AI-generated exploit (1)
- AI-generated finding (1)
- AI-generated malware (1)
- AI-generated narrator (1)
- Aider (1)
- Aikido (2)
- AISURU (2)
- AiTM (4)
- AitM (1)
- Ajax.NET Professional (1)
- AjaxPro (1)
- Albania (1)
- alert fatigue (1)
- algorithm confusion (1)
- Alibaba (1)
- Alibaba OSS (1)
- Allen-Bradley (1)
- allowed_classes (1)
- Alternate Data Stream (1)
- Amadey (1)
- Amatera Stealer (2)
- Amazon Kiro (1)
- Amazon Q Developer (1)
- Amazon S3 (1)
- Amazon SES (2)
- Amcache (1)
- AMOS (3)
- AMSI bypass (6)
- AMSI patch (1)
- AmsiScanBuffer (1)
- Ancillary Function Driver (1)
- Android (11)
- Android Accessibility Service (2)
- Android ADB (3)
- Android automotive (1)
- Android Debug Bridge (2)
- Android kernel (1)
- Android malware (3)
- Android RAT (2)
- Android spyware (3)
- Android TV (1)
- Anthropic (4)
- anthropickit (1)
- anti-analysis (9)
- anti-bot (1)
- anti-distillation (1)
- anti-forensics (2)
- anti-sandbox (2)
- Anubis ransomware (1)
- ANY.RUN (3)
- AnyDesk (2)
- AOL Mail (1)
- Aone (1)
- Apache Tomcat (1)
- Apache Zeppelin (1)
- APC EarlyBird (1)
- Apex One (1)
- API abuse (1)
- API enumeration (1)
- API exposure (1)
- API key exposure (1)
- API key theft (1)
- API keys (2)
- API-driven payloads (1)
- apintergrationpost (1)
- app-bound encryption (1)
- App-Bound Encryption bypass (1)
- AppDomainManager (1)
- AppDomainManager injection (2)
- Apple (1)
- Apple Sign-In (1)
- Apple threat notification (1)
- AppleJeus (1)
- AppleScript (1)
- AppleSeed (1)
- appliance (1)
- application database (1)
- application delivery controller (1)
- application token (1)
- AppRemover (1)
- APSB26-68 (1)
- APT (9)
- APT simulation (1)
- APT-C-08 (1)
- APT27 (1)
- APT28 (2)
- APT29 (3)
- APT32 (1)
- APT36 (3)
- APT37 (2)
- APT42 (1)
- APT43 (1)
- APT44 (2)
- APT45 (1)
- Aptos (2)
- Aquatic Panda (2)
- AquilaRAT (1)
- arbitrary code execution (1)
- arbitrary file deletion (1)
- arbitrary file disclosure (1)
- arbitrary file read (3)
- arbitrary file upload (2)
- arbitrary file write (6)
- arbitrary JavaScript (1)
- arbitrary SQL execution (1)
- ArcBridge (2)
- Arch Linux (1)
- Arctic Wolf (3)
- ardrv.sys (1)
- ArduPilot (1)
- Argo CD (2)
- ArgoCD (1)
- argocd-mcp (1)
- Arista (1)
- Arista EOS (1)
- ARL (1)
- Armageddon (1)
- ArmCorp (1)
- Armored Likho (4)
- arrayref (1)
- arrest (1)
- Artem Dinaburg (1)
- Artifact Signing (1)
- Artifactory (2)
- arXiv (1)
- AryStinger (1)
- AS32167 (1)
- ASA (1)
- ASCII smuggling (1)
- ASHX (1)
- Asia targeting (1)
- ASLR bypass (1)
- ASNs (1)
- ASP.NET (2)
- ASP.NET machineKey (1)
- ASPX web shells (2)
- assume-breach (1)
- Astra (1)
- Astro (1)
- ASUS AiCloud routers (1)
- ASUS router (1)
- AsyncAPI (1)
- AsyncRAT (3)
- atd (1)
- Atlas RAT (1)
- Atlassian (1)
- Atomic Stealer (2)
- attack-rate (1)
- attribution (1)
- audio surveillance (1)
- AUDIOFIX (2)
- audit logging (1)
- audit telemetry (1)
- auditd disabling (1)
- AUR (1)
- Aura (1)
- Australia (1)
- authenticated RCE (1)
- authenticated remote code execution (1)
- authentication bypass (29)
- authentication coercion (1)
- authentication laundering (1)
- authentication stack (2)
- authentication-coercion (1)
- Authenticode impersonation (1)
- authorization (1)
- authorization bypass (1)
- auto-execution (1)
- AUTODYN (1)
- AutoGen Studio (1)
- AutoHotKey (1)
- AutoJack (1)
- automotive (1)
- automotive sector (1)
- autonomous agents (3)
- autonomous AI (1)
- autonomous attack (2)
- autonomous attacks (1)
- autonomous exploitation (1)
- autonomous scanning (1)
- autonomous vulnerability discovery (1)
- autorun=1 (1)
- AV killer (1)
- Avada (1)
- Avalon (2)
- aviation (2)
- AVIF (1)
- AWS (7)
- AWS CloudTrail (1)
- AWS S3 (2)
- AWS Secrets Manager (1)
- axios (1)
- Azure (4)
- Azure Active Directory (1)
- Azure CLI (1)
- Azure Cosmos DB (1)
- Azure DevOps (1)
- Azure Storage (1)
- Babuk (1)
- back-end (1)
- Backblaze (1)
- backdoor (25)
- Backdoor.Mistic (1)
- Backdoor.Turn (1)
- Backstage (1)
- backup disruption (3)
- backup recovery keys (1)
- backup targeting (1)
- backups (1)
- Bad Epoll (1)
- BadBlocker (1)
- BADBOX (1)
- Badbox 2.0 (1)
- BadIIS (4)
- BadPotato (1)
- Baileys (1)
- balance-overflow (1)
- Balbooa Forms (1)
- Balochistan Police (1)
- Balonx (1)
- Balonx Sistema (1)
- Banana RAT (1)
- Banco de Infects (2)
- bandcampro (1)
- Bandook (1)
- banking (2)
- banking fraud (1)
- banking malware (4)
- banking trojan (4)
- Baron Samedit (1)
- Barracuda (1)
- Base64 (1)
- BaseZipInstaller (1)
- Bash Uploader (1)
- batch loader (1)
- batch script (1)
- Bayesian scoring (1)
- BCS (1)
- BCSAllowedTypeNames (1)
- BCU key (1)
- BDC (1)
- BDCM (1)
- Bearlyfy (2)
- Beast ransomware (1)
- BeaverTail (1)
- Bedrock (1)
- behavioral detection (2)
- behavioral integrity verification (1)
- Behinder (1)
- Belarus (2)
- BELQI (1)
- benchmark integrity (1)
- Berlin (1)
- better-auth (1)
- Bexo Wallet (1)
- BeyondTrust (1)
- bin entry (1)
- Binance Smart Chain (1)
- binary execution (1)
- binary squatting (1)
- BinaryFormatter (1)
- BINDCLOAK (3)
- binding.gyp (3)
- biometric records (1)
- BIOPASS RAT (1)
- BioShocking (1)
- BIP-39 (2)
- BirdCall (1)
- Bitbucket (1)
- Bitcoin (4)
- Bitcoin Libre (1)
- BitMiner (1)
- bitsadmin (1)
- Bitter (1)
- Bitwarden (1)
- BKA (1)
- Black Hat USA 2026 (1)
- BlackFile (1)
- Blackpoint Cyber (6)
- Bleacher Report (1)
- blind prompt injection (1)
- blockchain (2)
- blockchain C2 (9)
- blockchain dead drop (6)
- blockchain RPC (1)
- blockchain-dead-drop (1)
- Blogger abuse (1)
- blogspot staging (1)
- BLOODALCHEMY (1)
- BLUEBEAM (1)
- BlueDelta (1)
- bluemonday (1)
- Blueprints (1)
- Bluetooth LE (1)
- Boatnet (1)
- BOD 26-04 (10)
- body hash (1)
- BOF (1)
- BookStack (1)
- Boot Bus Extender (1)
- Boot Time Removal Tool (1)
- botnet (14)
- botnet framework (1)
- BPFDoor (1)
- Braintree (1)
- branch-compromise (1)
- branch-name-injection (1)
- brand impersonation (4)
- brand-impersonation (2)
- BraZetsu (2)
- Brazil (7)
- Brazilian banking malware (1)
- BreachForums (1)
- Breeze Cache Cleaner (1)
- Brian Fox (1)
- BRICKSTORM (2)
- BridgeHead (2)
- Broadcom (5)
- browser assembly (1)
- browser automation (1)
- browser cookie theft (1)
- browser credential theft (24)
- browser data theft (2)
- browser extension (9)
- browser extension loader (1)
- browser extension malware (1)
- browser extension sideloading (1)
- browser fingerprint spoofing (1)
- browser fingerprinting (1)
- browser hijacking (4)
- browser malware (1)
- browser memory (1)
- browser security (3)
- browser session abuse (2)
- browser session hijacking (1)
- browser session risk (3)
- browser zero-day (2)
- browser-based attack (1)
- browser-credential-theft (1)
- browser-extensions (2)
- browser-resident malware (3)
- browser-security (1)
- browser-session risk (1)
- browsing history (1)
- brute-force credentials (1)
- BSC (1)
- BTMOB (1)
- BTR Reforged (1)
- BTR.sys (1)
- BTR_CLI (1)
- bucket hijacking (1)
- bucket squatting (1)
- buffer overflow (2)
- bug bounty (1)
- Bugcrowd (1)
- build pipeline (1)
- build server (1)
- build-time compromise (2)
- build-time execution (1)
- build.rs (1)
- building automation (1)
- builtin wildcard (1)
- bulletproof hosting (1)
- Bun (6)
- Bun runtime abuse (1)
- Burkina Faso (1)
- business email compromise (2)
- business intelligence (1)
- BusinessDataCatalog (1)
- BusySnake Stealer (3)
- Bybit (1)
- BYOVD (5)
- BYOVD alternative (1)
- bypass2fa (1)
- bytecode (1)
- C backdoor (1)
- C# (1)
- C++ (4)
- C++/CLI (1)
- C0XMO (1)
- C2 (17)
- C2 fallback (1)
- C2 framework (2)
- C2 panel (1)
- C2 tasking (1)
- C2Looper (1)
- CageFS (1)
- Caixa Entradas (1)
- calendar dead drop (1)
- calendar invitation (1)
- Calendly abuse (1)
- call forwarding (2)
- callback URL (1)
- CallFlow (1)
- Cambodia (2)
- campaign (7)
- Canada (1)
- canary (1)
- CANFAIL (1)
- CanisterWorm (1)
- canonicalization (1)
- CAP_NET_ADMIN (2)
- CAPTCHA OCR (1)
- captive portal (2)
- CaptiveCrunch (1)
- capture the flag (1)
- cargo (1)
- Casbaneiro (1)
- CastleStealer (1)
- Catalyst SD-WAN Manager (1)
- Catcher (1)
- Cav3rn (1)
- Cavern (2)
- Cavern Manticore (3)
- CCleaner (1)
- CCTV (1)
- CDN (1)
- CDN abuse (1)
- cdn.jsdelivr.net (1)
- CDP (1)
- Cellebrite (1)
- cellular modem (1)
- census (1)
- Censys (1)
- Censys ARC (1)
- Central Asia (2)
- CERT Polska (1)
- CERT-In (1)
- CERT/CC (2)
- Certbot (1)
- certificate pinning (1)
- certificate template (1)
- certificate theft (1)
- Certighost (1)
- certutil (1)
- CFIDE (1)
- ChaCha20 (1)
- chain-of-thought (1)
- ChainDrop (2)
- chainlit (1)
- ChainVeil (1)
- Chaos ransomware (1)
- Chaotic Eclipse (2)
- charging (1)
- Charming Kitten (2)
- chat-template poisoning (1)
- ChatGPT (1)
- chattr (1)
- Chatty Spider (1)
- CHAVECLOAK (1)
- Check Point (2)
- Check Point Research (5)
- Checkmarx (2)
- Checkmarx KICS (1)
- checkpointers (1)
- China (3)
- China nexus (1)
- China-linked (8)
- China-nexus (18)
- China-speaking ecosystem (1)
- Chinese-language cybercrime (2)
- Chinese-language fraud ecosystem (1)
- Chinese-speaking (10)
- Chinese-speaking cybercrime (1)
- Chinese-speaking operator (2)
- Chisel (4)
- ChocoPoC (1)
- ChocoShell (1)
- ChromaDB (1)
- Chrome (3)
- Chrome App-Bound Encryption (1)
- Chrome DevTools Protocol (1)
- Chrome extension (3)
- Chrome renderer sandbox (1)
- Chrome Web Store (5)
- chrome_settings_overrides (1)
- ChromElevator (1)
- Chromium (6)
- Chromium extension (1)
- chunked exfiltration (1)
- CI secrets (1)
- CI-CD (4)
- CI/CD (45)
- CI/CD abuse (1)
- CI/CD credential theft (1)
- CI/CD pipeline abuse (1)
- CircleCI (1)
- CIS (2)
- CISA (17)
- CISA ADP (2)
- CISA KEV (44)
- Cisco (7)
- Cisco IOS (1)
- Cisco IOS 12.4 (1)
- Cisco Nexus (1)
- Cisco Talos (2)
- Cisco Unified CM (1)
- Cisco Unified Communications Manager (1)
- Citizen Lab (1)
- citizen portal compromise (1)
- Citrine Sleet (1)
- Citrix (5)
- Citrix NetScaler (2)
- CitrixBleed (1)
- CitrixBleed 2 (1)
- City Forum (1)
- CKEditor file manager (1)
- CL-CRI-1089 (1)
- CL-CRI-1131 (1)
- CL-CRI-1147 (1)
- CL-CRI-1163 (1)
- CL-STA-1062 (3)
- CL-STA-1114 (4)
- Clash proxy (1)
- Claude (3)
- Claude Code (8)
- Claude for Chrome (1)
- Claude Mythos 5 (1)
- Claude Opus 4.7 (1)
- Clawdbot (1)
- ClawWorm (1)
- ClearFake (2)
- cleartext credentials (1)
- Clever Cloud (1)
- click interception (1)
- clicker (1)
- ClickFake (1)
- ClickFix (26)
- ClickFix social engineering (1)
- ClickOnce (1)
- ClickUp (1)
- client installer poisoning (1)
- client-side exploitation (2)
- Cline (1)
- clipboard hijacker (1)
- clipboard hijacking (1)
- clipboard injection (1)
- clipboard manipulation (2)
- clipboard stealer (1)
- clipboard theft (6)
- clipjacking (1)
- clipper (2)
- Cloaked Ursa (2)
- cloaking (3)
- ClOd-ViEw (1)
- cloud (7)
- cloud C2 (2)
- cloud compromise (1)
- cloud credential hunting (1)
- cloud credential risk (1)
- cloud credential theft (8)
- cloud credentials (4)
- cloud exploitation (1)
- Cloud Files Mini Filter Driver (1)
- Cloud Filter driver (1)
- Cloud Foundation (1)
- cloud IAM (1)
- cloud identity (2)
- cloud identity abuse (1)
- cloud infrastructure (1)
- cloud keys exfiltration (1)
- cloud logging (1)
- cloud metadata (1)
- cloud metadata service (1)
- cloud secrets (4)
- cloud security (4)
- cloud service abuse (4)
- cloud storage (1)
- cloud storage exfiltration (1)
- cloud transcoding (1)
- Cloudflare (5)
- Cloudflare gate (1)
- Cloudflare R2 (1)
- Cloudflare Tunnel (5)
- Cloudflare tunnels (2)
- Cloudflare Turnstile (1)
- Cloudflare Workers (9)
- cloudflared (2)
- CloudLinux (1)
- CloudSEK (1)
- cluster compromise (1)
- CMS (8)
- CMS exploitation (1)
- CNAB (2)
- CNABHunter (2)
- CNCERT (1)
- Cobalt Strike (7)
- code execution (4)
- code generation (1)
- code injection (7)
- Code Mode (1)
- code sandbox scraping (1)
- code signing (3)
- code signing abuse (1)
- Codecov (1)
- codegen injection (1)
- codemado (1)
- CodeQL (1)
- Codex (2)
- Codex CLI (1)
- coding agents (1)
- coding challenge (1)
- Coinbase (1)
- Coinkite (1)
- COLDCARD (1)
- ColdFusion (1)
- collaboration platforms (2)
- collaboration-tool phishing (2)
- COM-hijacking (1)
- ComfyUI (1)
- command and control (6)
- command execution (9)
- command injection (10)
- command-execution (1)
- command-injection (1)
- commercial LLM abuse (1)
- commercial messaging applications (1)
- commit farming (1)
- communications infrastructure (1)
- Composer (6)
- compromised accounts (2)
- compromised credentials (1)
- compromised infrastructure (1)
- compromised websites (2)
- compromised WordPress (2)
- computer name (1)
- computer vision (1)
- Conditional Access (1)
- configuration exposure (1)
- configuration tampering (1)
- configuration theft (2)
- Confluence (1)
- confused deputy (4)
- ConfuserEx (2)
- conhost (2)
- connected apps (2)
- ConnectWise (2)
- ConnectWise advisory (1)
- ConnectWise ScreenConnect (2)
- construction (2)
- consumer devices (1)
- consumer IoT (1)
- consumer software (1)
- Contagious Interview (6)
- container (1)
- container escape (5)
- container escape pre-check (1)
- content compliance rules (1)
- contentPolicy (1)
- context flooding (1)
- Continue (1)
- continuous visibility (1)
- control flow flattening (3)
- control panel compromise (1)
- control plane (4)
- control-flow hijacking (1)
- conversation theft (1)
- cookie theft (4)
- CookiETagRAT (1)
- Copilot (1)
- Copilot CLI (1)
- Copy-on-Write (1)
- copycat (1)
- Corepack (1)
- CornFlake (1)
- CORS (1)
- CORS bypass (1)
- Cortex XDR (1)
- Coruna (2)
- cosign (1)
- Cosmos (1)
- Cosmos EVM (1)
- Cosmos SDK (1)
- CosmosEscape (1)
- CoSnitch (1)
- counterfeit software (2)
- COW (1)
- COWARDDUCK (1)
- CPaaS (1)
- cPanel (5)
- CPUID (1)
- CRA (1)
- cracked software (1)
- CrackMapExec (1)
- CrashFix (1)
- CrashStealer (1)
- crates.io (2)
- Crates.io (1)
- credential attack (1)
- credential attacks (3)
- credential cracking (1)
- credential dumping (1)
- credential exfiltration (1)
- credential exposure (5)
- credential harvesting (7)
- credential interception (1)
- credential leakage (1)
- credential rotation (1)
- credential spraying (1)
- credential stealer (1)
- credential stuffing (2)
- credential theft (86)
- credential-theft (56)
- credit card theft (1)
- criminal infrastructure (1)
- critical (1)
- Critical cyber capability (1)
- critical framing (1)
- critical infrastructure (12)
- critical vulnerability (6)
- critical-infrastructure (2)
- CRM data theft (1)
- cron (2)
- cron persistence (3)
- crond (1)
- cross-ecosystem (1)
- cross-origin requests (1)
- cross-platform (4)
- cross-platform malware (2)
- cross-project access (1)
- cross-session (1)
- cross-site request forgery (1)
- cross-tenant (1)
- cross-tenant access (1)
- cross-tenant isolation (1)
- cross-tenant leakage (1)
- Crossplane (1)
- crossplane-runtime (1)
- Crosswork (1)
- Crosswork Data Gateway (1)
- Crosswork Network Controller (1)
- Crosswork Planning (1)
- CrowdStrike (1)
- CrowdStrike Counter Adversary Operations (1)
- CrowdStrike Falcon (1)
- CrownX (2)
- Crucio (1)
- crypto (2)
- crypto clipboard theft (1)
- crypto clipper (2)
- crypto draining (1)
- crypto wallets (2)
- crypto-js (1)
- crypto-wallets (1)
- cryptocurrency (15)
- cryptocurrency miner (1)
- cryptocurrency mining (1)
- cryptocurrency scam (1)
- cryptocurrency theft (14)
- cryptocurrency wallet theft (8)
- cryptocurrency wallets (4)
- cryptographic context injection (1)
- cryptojacking (2)
- CryptoJS (1)
- cryptominer (3)
- cryptomining (4)
- CSCwt95997 (1)
- CSI token theft (1)
- CSP stripping (1)
- CSRF (3)
- CSRF token theft (1)
- CSS (1)
- CSS sanitization (1)
- CSSOM (1)
- ctfmon.exe (1)
- Curious Serpens (1)
- CurlRAT (1)
- CURP (1)
- Cursor (6)
- Curve25519 (2)
- Curve25519-XSalsa20-Poly1305 (1)
- custody APIs (1)
- custom instruction set (1)
- custom map (1)
- CVE (2)
- CVE-2008-4128 (1)
- CVE-2013-3307 (1)
- CVE-2015-3246 (1)
- CVE-2015-5287 (1)
- CVE-2016-5681 (1)
- CVE-2019-1068 (1)
- CVE-2020-17103 (1)
- CVE-2020-22653 (1)
- CVE-2020-22658 (1)
- CVE-2021-23758 (1)
- CVE-2021-27137 (1)
- CVE-2021-29441 (1)
- CVE-2021-33044 (1)
- CVE-2021-33045 (1)
- CVE-2022-0492 (1)
- CVE-2022-0995 (1)
- CVE-2023-24932 (1)
- CVE-2023-25717 (1)
- CVE-2023-2868 (1)
- CVE-2023-4346 (1)
- CVE-2023-49105 (2)
- CVE-2023-4966 (1)
- CVE-2024-1708 (1)
- CVE-2024-1709 (1)
- CVE-2024-20399 (1)
- CVE-2024-21182 (1)
- CVE-2024-28000 (1)
- CVE-2024-3094 (2)
- CVE-2024-37014 (1)
- CVE-2024-42009 (1)
- CVE-2025-11371 (1)
- CVE-2025-11837 (1)
- CVE-2025-24054 (1)
- CVE-2025-2492 (1)
- CVE-2025-3248 (3)
- CVE-2025-32975 (1)
- CVE-2025-33053 (1)
- CVE-2025-34291 (2)
- CVE-2025-40947 (1)
- CVE-2025-40948 (1)
- CVE-2025-40949 (1)
- CVE-2025-48595 (1)
- CVE-2025-49113 (2)
- CVE-2025-49704 (1)
- CVE-2025-49706 (1)
- CVE-2025-5777 (1)
- CVE-2025-62593 (1)
- CVE-2025-66376 (3)
- CVE-2025-67038 (1)
- CVE-2025-68613 (1)
- CVE-2025-68686 (1)
- CVE-2025-8088 (4)
- CVE-2026-0257 (1)
- CVE-2026-0300 (1)
- CVE-2026-0769 (1)
- CVE-2026-0770 (2)
- CVE-2026-10520 (1)
- CVE-2026-10523 (1)
- CVE-2026-11405 (1)
- CVE-2026-11645 (1)
- CVE-2026-12569 (1)
- CVE-2026-12957 (1)
- CVE-2026-12958 (1)
- CVE-2026-14494 (1)
- CVE-2026-14894 (1)
- CVE-2026-15409 (1)
- CVE-2026-15410 (1)
- CVE-2026-15583 (1)
- CVE-2026-15981 (1)
- CVE-2026-16232 (1)
- CVE-2026-16723 (1)
- CVE-2026-16812 (1)
- CVE-2026-18431 (1)
- CVE-2026-18556 (2)
- CVE-2026-18577 (1)
- CVE-2026-18885 (1)
- CVE-2026-18886 (1)
- CVE-2026-18963 (1)
- CVE-2026-19478 (1)
- CVE-2026-19489 (1)
- CVE-2026-19490 (1)
- CVE-2026-19516 (1)
- CVE-2026-19598 (1)
- CVE-2026-19632 (1)
- CVE-2026-19650 (1)
- CVE-2026-19912 (1)
- CVE-2026-19913 (1)
- CVE-2026-20127 (1)
- CVE-2026-20182 (1)
- CVE-2026-20212 (1)
- CVE-2026-20230 (1)
- CVE-2026-20245 (1)
- CVE-2026-20253 (1)
- CVE-2026-20262 (1)
- CVE-2026-20274 (1)
- CVE-2026-20279 (1)
- CVE-2026-20316 (1)
- CVE-2026-20349 (1)
- CVE-2026-20896 (1)
- CVE-2026-21445 (1)
- CVE-2026-21513 (1)
- CVE-2026-21858 (1)
- CVE-2026-21962 (1)
- CVE-2026-23111 (1)
- CVE-2026-24301 (1)
- CVE-2026-25895 (1)
- CVE-2026-26980 (1)
- CVE-2026-2699 (1)
- CVE-2026-2701 (1)
- CVE-2026-28318 (1)
- CVE-2026-29059 (1)
- CVE-2026-3055 (1)
- CVE-2026-32475 (2)
- CVE-2026-3300 (1)
- CVE-2026-33017 (4)
- CVE-2026-33497 (1)
- CVE-2026-33691 (1)
- CVE-2026-33824 (2)
- CVE-2026-34486 (2)
- CVE-2026-34908 (1)
- CVE-2026-34909 (1)
- CVE-2026-34910 (1)
- CVE-2026-34926 (1)
- CVE-2026-35273 (2)
- CVE-2026-35616 (1)
- CVE-2026-36425 (1)
- CVE-2026-39987 (2)
- CVE-2026-40138 (1)
- CVE-2026-40139 (1)
- CVE-2026-40140 (1)
- CVE-2026-40141 (1)
- CVE-2026-4020 (1)
- CVE-2026-41091 (1)
- CVE-2026-41703 (1)
- CVE-2026-41709 (1)
- CVE-2026-41940 (2)
- CVE-2026-42271 (2)
- CVE-2026-42533 (1)
- CVE-2026-42897 (2)
- CVE-2026-43074 (1)
- CVE-2026-43284 (1)
- CVE-2026-43499 (1)
- CVE-2026-43500 (1)
- CVE-2026-43503 (1)
- CVE-2026-44338 (1)
- CVE-2026-44613 (1)
- CVE-2026-45018 (1)
- CVE-2026-45019 (1)
- CVE-2026-45247 (1)
- CVE-2026-45498 (1)
- CVE-2026-45659 (1)
- CVE-2026-46242 (1)
- CVE-2026-46300 (1)
- CVE-2026-46331 (1)
- CVE-2026-46817 (1)
- CVE-2026-47876 (1)
- CVE-2026-47884 (1)
- CVE-2026-47890 (1)
- CVE-2026-47891 (1)
- CVE-2026-47892 (1)
- CVE-2026-48172 (1)
- CVE-2026-48276 (1)
- CVE-2026-48277 (1)
- CVE-2026-48281 (1)
- CVE-2026-48282 (1)
- CVE-2026-48283 (1)
- CVE-2026-48285 (1)
- CVE-2026-48307 (1)
- CVE-2026-48313 (1)
- CVE-2026-48314 (1)
- CVE-2026-48315 (1)
- CVE-2026-48316 (1)
- CVE-2026-48558 (3)
- CVE-2026-48710 (2)
- CVE-2026-48907 (2)
- CVE-2026-48908 (1)
- CVE-2026-48939 (1)
- CVE-2026-49869 (1)
- CVE-2026-5027 (1)
- CVE-2026-50522 (1)
- CVE-2026-50656 (2)
- CVE-2026-50751 (1)
- CVE-2026-50752 (1)
- CVE-2026-51296 (1)
- CVE-2026-51297 (1)
- CVE-2026-51300 (1)
- CVE-2026-51302 (1)
- CVE-2026-51303 (1)
- CVE-2026-51304 (1)
- CVE-2026-52810 (1)
- CVE-2026-52813 (1)
- CVE-2026-53359 (2)
- CVE-2026-53362 (1)
- CVE-2026-5426 (1)
- CVE-2026-54420 (1)
- CVE-2026-54718 (1)
- CVE-2026-54720 (1)
- CVE-2026-54721 (1)
- CVE-2026-55040 (2)
- CVE-2026-55207 (1)
- CVE-2026-55208 (1)
- CVE-2026-55212 (1)
- CVE-2026-55220 (1)
- CVE-2026-55255 (2)
- CVE-2026-55450 (1)
- CVE-2026-55634 (1)
- CVE-2026-56290 (1)
- CVE-2026-56291 (1)
- CVE-2026-59283 (1)
- CVE-2026-59285 (1)
- CVE-2026-59309 (1)
- CVE-2026-59310 (2)
- CVE-2026-59313 (1)
- CVE-2026-59318 (1)
- CVE-2026-59726 (1)
- CVE-2026-59822 (2)
- CVE-2026-60004 (1)
- CVE-2026-60137 (1)
- CVE-2026-61539 (1)
- CVE-2026-61979 (1)
- CVE-2026-62144 (1)
- CVE-2026-62145 (1)
- CVE-2026-63030 (1)
- CVE-2026-63077 (1)
- CVE-2026-63520 (1)
- CVE-2026-6471 (1)
- CVE-2026-64849 (1)
- CVE-2026-65400 (1)
- CVE-2026-65640 (1)
- CVE-2026-65643 (1)
- CVE-2026-66384 (1)
- CVE-2026-66747 (1)
- CVE-2026-6682 (1)
- CVE-2026-6683 (1)
- CVE-2026-6684 (1)
- CVE-2026-6685 (1)
- CVE-2026-6686 (1)
- CVE-2026-6687 (1)
- CVE-2026-6688 (1)
- CVE-2026-67426 (1)
- CVE-2026-6875 (1)
- CVE-2026-6876 (1)
- CVE-2026-68820 (2)
- CVE-2026-69414 (1)
- CVE-2026-69836 (1)
- CVE-2026-72529 (1)
- CVE-2026-72530 (1)
- CVE-2026-72898 (2)
- CVE-2026-73570 (1)
- CVE-2026-7473 (1)
- CVE-2026-74820 (1)
- CVE-2026-75149 (1)
- CVE-2026-75604 (1)
- CVE-2026-76581 (1)
- CVE-2026-76639 (1)
- CVE-2026-76640 (1)
- CVE-2026-77413 (1)
- CVE-2026-77414 (1)
- CVE-2026-77415 (1)
- CVE-2026-80192 (1)
- CVE-2026-8037 (1)
- CVE-2026-81578 (1)
- CVE-2026-82078 (1)
- CVE-2026-82222 (1)
- CVE-2026-82329 (1)
- CVE-2026-82447 (1)
- CVE-2026-82448 (1)
- CVE-2026-82450 (1)
- CVE-2026-82452 (1)
- CVE-2026-82454 (1)
- CVE-2026-82456 (1)
- CVE-2026-83548 (1)
- CVE-2026-83549 (1)
- CVE-2026-8451 (1)
- CVE-2026-8452 (2)
- CVE-2026-8461 (1)
- CVE-2026-85046 (1)
- CVE-2026-8732 (1)
- CVE-2026-9082 (1)
- CVE-2026-9198 (2)
- CVE-2026-9539 (1)
- CVE-2026-9586 (1)
- CVSS (1)
- CVSS 10.0 (2)
- CVSS 9.0 (1)
- cvvform (1)
- CWE-22 (1)
- CWE-259 (1)
- CWE-284 (1)
- CWE-287 (1)
- CWE-306 (2)
- CWE-352 (2)
- CWE-470 (1)
- CWE-502 (2)
- CWE-640 (1)
- CWE-77 (1)
- CWE-78 (2)
- CWE-829 (1)
- CWE-94 (1)
- Cybench (1)
- cyber AI (1)
- cyber evaluation (1)
- cyber sanctions (1)
- cyber-espionage (6)
- CyberAv3ngers (1)
- cybercrime (18)
- cybercrime ecosystem (2)
- cyberespionage (7)
- Cyera (1)
- Cython (1)
- Czech Republic (1)
- D-Link (1)
- D2IP (1)
- Dahua (1)
- dangling resources (1)
- Dark Caracal (1)
- DARKLANTERN (1)
- DarkSword (1)
- data analytics (1)
- data breach (1)
- data center (1)
- data contamination (1)
- data exfiltration (18)
- data exposure (3)
- data extortion (2)
- data leak site (3)
- data scraping (1)
- data theft (11)
- data-exfiltration (1)
- database (1)
- database extortion (1)
- Datadog Security Labs (1)
- DataObject (1)
- dataset dead drop (1)
- dataset processing (1)
- DAYLIGHT (1)
- DCIS (1)
- DCloud (1)
- DCloud Uni-App (1)
- DcRAT (1)
- DCSync (1)
- DD-WRT (1)
- DDNS (1)
- DDoS (10)
- DDoS botnet (1)
- DDoS-for-hire (3)
- DDR (1)
- DDS (1)
- dead drop (1)
- dead drop resolver (5)
- dead-drop (1)
- dead-drop resolver (2)
- DeadLock (1)
- Debian (1)
- debugger evasion (1)
- debugging detection (1)
- DEBULL (1)
- declarativeNetRequest (1)
- Deed (1)
- DeepAudit (1)
- DeepSeek (5)
- Defender Advanced Hunting (1)
- Defender evasion (2)
- Defender exclusion (1)
- defense (6)
- defense evasion (10)
- defense impairment (1)
- defense sector (1)
- defense targeting (1)
- defense-evasion (1)
- DeFi (4)
- delayed execution (3)
- denial of service (10)
- Deno (2)
- Denys Pakizh (1)
- Dependabot (1)
- dependency confusion (5)
- deployment_status (1)
- deserialization (13)
- destructive actions (1)
- destructive malware (3)
- destructive operations (3)
- detached execution (1)
- detached process (1)
- detection (1)
- detection engineering (2)
- detection failure (1)
- DEV#POPPER (1)
- DEV-0206 (1)
- developer credential theft (2)
- developer credentials (1)
- developer endpoints (3)
- Developer ID abuse (1)
- developer identity (1)
- developer infrastructure (1)
- developer machines (9)
- developer mode (1)
- developer platform (1)
- developer targeting (12)
- developer tooling (7)
- developer workstations (3)
- developer-machine-fleet (1)
- developer-targeting (22)
- developer-tools (1)
- developer-workstations (5)
- device identity (1)
- device linking (1)
- device lockout (1)
- device registration (1)
- device-code phishing (6)
- DevOps (1)
- DevTools (1)
- DEWMODE (1)
- DGA (1)
- DIAMONDBACK (2)
- diffpatch (1)
- digital forensics (1)
- Digital Knowledge (1)
- digital wallets (1)
- DigitalOcean (2)
- DigitalOcean Spaces (1)
- Dindoor (1)
- DingTalk (1)
- diplomatic (1)
- diplomatic targeting (3)
- direct-to-IP (1)
- directory traversal (1)
- Dirty Pipe (1)
- DirtyClone (1)
- DirtyFrag (1)
- DISCLOSURE (1)
- Discord (2)
- Discord link abuse (1)
- Discord masquerade (1)
- discovery (1)
- disk wiping (1)
- disposable infrastructure (1)
- disruption (1)
- distributed malware infrastructure (1)
- distributed scanning (1)
- Djinn Stealer (3)
- DLL search-order hijacking (2)
- DLL side-loading (8)
- DLL sideloading (28)
- dlopen (1)
- DMTP (1)
- DNS (1)
- DNS C2 (3)
- DNS callback (1)
- DNS dead drop (2)
- DNS exfiltration (4)
- DNS hijack (1)
- DNS hijacking (1)
- DNS rebinding (4)
- DNS resolution (1)
- DNS threat intelligence (1)
- DNS tunneling (3)
- DNS-over-HTTPS (1)
- Docker (3)
- Docker cache (1)
- Docker Compose (1)
- Docker credentials (1)
- Docker Hub (1)
- Docker images (1)
- Docker socket (3)
- document collection (1)
- document exfiltration (1)
- document theft (4)
- document-share lure (1)
- Docusign (1)
- DOE (1)
- DoFun (1)
- DOGLEASH (1)
- DOJ (2)
- domain squatting (1)
- domain verification (1)
- DomainTools (1)
- domestic espionage (1)
- dormant accounts (2)
- DotNetNuke (1)
- DotnetTool (1)
- double extortion (3)
- double free (1)
- downgrade risk (1)
- downloader (1)
- downstream blast radius (1)
- DPAPI (3)
- dpapi.dll (1)
- DPAPILoader (1)
- DPRK (8)
- DPRK APT (1)
- DragonForce (1)
- drive serial number (1)
- driver loading (1)
- DriveSilkRAT (1)
- DroneLink (1)
- Dropbear (1)
- Dropbox (3)
- dropper (1)
- Drupal (1)
- dual-function malware (1)
- dual-use (1)
- dual-use tooling (1)
- duckdns (1)
- Durable Objects (1)
- Dutch Police (1)
- DWAgent (1)
- dynamic DNS (1)
- dynamic obfuscation (1)
- Dynu (1)
- DyPrIs (1)
- Dysphoria (1)
- e-commerce (1)
- E.O. 13224 (1)
- E.O. 13382 (1)
- E.O. 13694 (1)
- E.O. 13902 (1)
- E4del (1)
- Eagle Werewolf (3)
- Early Bird APC injection (1)
- Earth Lusca (2)
- East Asia (1)
- East Asia-linked (1)
- Easy4IP (1)
- eBPF (3)
- Eclipse (1)
- Economic D-Day (1)
- Ecuador (1)
- Ed25519 (1)
- edge appliance (15)
- edge appliances (2)
- edge application server (1)
- edge device (3)
- edge devices (5)
- edge exploitation (1)
- Edge extension (2)
- edge service (2)
- edge services (1)
- edge-service denial of service (1)
- editor profile import (1)
- EDR (1)
- EDR bypass (1)
- EDR evasion (3)
- EDR killer (2)
- EDR/AV bypass (1)
- EDR/AV tampering (1)
- EDS5000 (1)
- education (4)
- EfsPotato (1)
- EggJagger (1)
- Egnyte (1)
- Egypt (1)
- EKZ Infostealer (1)
- Elastic Agent (1)
- Elastic Security Labs (5)
- Elasticsearch (1)
- elections (1)
- electric power sector (2)
- Electron (3)
- Elementor Pro (2)
- email (1)
- email exfiltration (2)
- email gateway (1)
- email infrastructure abuse (1)
- email normalization (1)
- email security (1)
- email subject (1)
- email template (1)
- email theft (4)
- EmailEvents (1)
- embedded configuration (1)
- embedded Linux (2)
- embedded systems (1)
- Emerald Sleet (1)
- emergency patch (1)
- ENCFORGE (2)
- encrypted C2 (4)
- encrypted reasoning (1)
- EncryptInterceptor (1)
- ENDLESSDOORS (2)
- Endor Labs (1)
- endpoint compromise (1)
- endpoint detection (1)
- endpoint management (2)
- endpoint management abuse (1)
- endpoint response (2)
- endpoint security (1)
- endpoint-detection (1)
- endpoint-security (2)
- EndpointDlp.dll (1)
- energy (1)
- energy sector (5)
- energy-sector (1)
- engineering (1)
- engineering software (1)
- enterprise AI (1)
- enterprise application (3)
- enterprise application exploitation (1)
- enterprise applications (1)
- enterprise identity (1)
- enterprise intrusion (1)
- enterprise proxy (1)
- enterprise security (1)
- Entra ID (5)
- Environment Management Hub (1)
- environment variable theft (2)
- environment variables (1)
- environmental keying (9)
- EPA (1)
- EPFL (1)
- epoll (1)
- Epsilon Stealer (1)
- ERAAgent (1)
- ERP (1)
- error-message disclosure (1)
- ESC1 (1)
- Escalate with Certify (1)
- escrow (1)
- eSentire TRU (1)
- ESET (1)
- ESG (1)
- espionage (62)
- Espressif ESP-IDF (1)
- ESX (1)
- ESXi (3)
- ES|QL (1)
- eth_getStorageAt (1)
- Ethereum (6)
- Ethereum C2 (1)
- Ethereum Name Service (2)
- EtherHiding (8)
- Ethiopia (1)
- ETW (1)
- ETW bypass (1)
- ETW patching (2)
- ETW tampering (1)
- Eurojust (2)
- Europe (3)
- Europe targeting (1)
- European Union (1)
- Europol (3)
- eval injection (1)
- evaluation cheating (1)
- evaluation containment (1)
- evasion (1)
- event log clearing (2)
- eventpoll (1)
- Everest Forms Pro (1)
- EveryoneIncludesAnonymous (1)
- evidence quality (1)
- Evil Corp (1)
- EvilAI (1)
- Evilginx (1)
- EVM (1)
- evolutionary optimization (1)
- EWS (1)
- excessive agency (1)
- exec_globals (1)
- execution guardrails (1)
- exFAT (1)
- exfiltration (7)
- Exilware (2)
- Experience Cloud (1)
- exploit chain (2)
- exploit kit (1)
- exploit noise (1)
- exploit-development (1)
- exploit-kit (1)
- Exploit.in (1)
- exploitation (15)
- exploitation attempts (1)
- exploitation telemetry (1)
- ExploitBench (1)
- ExploitGym (1)
- exposed applications (1)
- exposed attacker infrastructure (1)
- exposed debug page (1)
- exposed staging (1)
- exposure window (1)
- extconf.rb (1)
- extension supply-chain (2)
- extension takeover (1)
- external federation (1)
- extortion (11)
- F5 (1)
- F5 BIG-IP (1)
- Factory-v3 (1)
- fail-closed (1)
- fake app store (1)
- fake CAPTCHA (8)
- fake certificate (1)
- fake Cloudflare (1)
- fake crypto exchange (1)
- fake dating lures (1)
- fake documents (1)
- fake gambling (1)
- fake graduation invite (1)
- fake installers (2)
- fake lock screen (1)
- fake login (1)
- fake login screen (1)
- fake Microsoft Store (1)
- fake Minecraft client (1)
- fake plugin (1)
- fake PoC (3)
- fake ransomware (1)
- fake recruiting (4)
- fake reputation (1)
- fake update (4)
- fake VPN (1)
- FakeCaptcha (1)
- FakeGit (1)
- Fakeset (1)
- faketivism (1)
- FakeUpdates (1)
- FALCON (1)
- Falcon Sensor (1)
- FallSpy (1)
- false positive (2)
- false positives (1)
- FAMOUS CHOLLIMA (3)
- Famous Chollima (2)
- Fancy Bear (2)
- Fast16 (1)
- FastAPI (1)
- FastCGI (1)
- Fastjson (1)
- Fastmail (1)
- fat JAR (1)
- FAT32 (1)
- FatFs (1)
- FBI (8)
- FBI indictment (1)
- fbot (1)
- FDMTP (2)
- Feiying (1)
- FFmpeg (1)
- FIDO2 (2)
- field-level security (1)
- FIFA (1)
- file encryption (1)
- file exfiltration (1)
- file infector (1)
- file inflation (1)
- file operations (1)
- file sharing (1)
- file theft (1)
- File Transmission (1)
- file upload (1)
- file upload path traversal (1)
- file-system filter (1)
- FileFiend (1)
- FILEIO (1)
- fileless execution (3)
- fileless malware (1)
- filemanager (1)
- filename-injection (1)
- filestream (1)
- filesystem parser (1)
- filter API (1)
- FilteredObjectInputStream (1)
- finance (2)
- finance phishing (1)
- financial (1)
- financial fraud (8)
- financial institutions (1)
- financial motivation (1)
- financial sector (8)
- financial services (5)
- financial theft (3)
- financially motivated (3)
- FireAnt MetaKit (1)
- Firebase (1)
- Firecracker (1)
- Firefox (1)
- Firefox Add-ons (1)
- Firefox WebDriver BiDi (1)
- Firepower Management Center (1)
- firewall (1)
- firewall management (2)
- firmware (3)
- firmware backdoor (2)
- firmware supply chain (1)
- firmware update (1)
- FishMonger (1)
- FlatBuffers (1)
- FlexPLM (1)
- flight recorder (1)
- FlockWiper (1)
- Flooding Dropper (1)
- flow execution (1)
- Flowerbed (3)
- Flowise (1)
- FLUIDLEECH (1)
- Flutter (1)
- FlutterShell (1)
- Flying Eagle (1)
- Flyto2 Core (1)
- FMC (1)
- FOFA (2)
- FofaMap (1)
- folderOpen (1)
- font1.woff2 (1)
- forced channel follow (1)
- fordmotbvmorcompany.vu (1)
- foreign affairs targeting (2)
- foreign policy targeting (1)
- Forest Blizzard (2)
- ForestTiger (1)
- Forg365 (1)
- ForgCookie (1)
- Forgejo (1)
- forgot password (1)
- FormDigestValue (1)
- Forms Authentication (1)
- FortiClient EMS (1)
- FortiGate (3)
- Fortinet (4)
- FortiOS (3)
- FortiSandbox (1)
- Fox Tempest (2)
- fraud (2)
- FREAKYPOLL (1)
- FreeBSD (2)
- Freedom365 (1)
- freeware impersonation (1)
- Friendly Fire (1)
- frontier AI (2)
- FruitStone (1)
- FSB (4)
- FSB Center 16 (2)
- fscan (1)
- Fscan (1)
- FTA (1)
- FTD (1)
- FTP banner (1)
- ftp.exe (2)
- ftrace (1)
- FudModule (1)
- Full Disk Access social engineering (1)
- Funnull (1)
- Fusion Builder (1)
- futex PI (1)
- FUXA (1)
- G1 EDU (1)
- gadget chain (1)
- Gafgyt (1)
- GaiaOS WebUI (1)
- GalaxyGato (2)
- Gamaredon (3)
- Gamaredon collaboration (1)
- gambling (1)
- gambling industry targeting (1)
- game cheats (1)
- game exploitation (1)
- gaming malware (1)
- GammaLoad (1)
- GammaPhish (1)
- GammaSteel (1)
- GammaWorm (1)
- Garble (2)
- Gardener (1)
- GateKeeper (1)
- Gatekeeper bypass (1)
- GCP (1)
- GCS (1)
- Gemini CLI (1)
- Gen Digital (1)
- generative AI (2)
- GenieLocker (3)
- GentleKiller (1)
- Germany (2)
- GHETTOVIBE (1)
- Ghost (3)
- ghost accounts (1)
- Ghost Calls (1)
- Ghost CMS (1)
- Ghost Networks (1)
- GHOSTBLADE (1)
- GhostLock (1)
- GHSA-2679-6mx9-h9xc (1)
- GHSA-2943-5xfg-gq5f (1)
- GHSA-2xp9-vwfh-vxw4 (1)
- GHSA-66mm-25pp-rfff (1)
- GHSA-6rmh-7xcm-cpxj (1)
- GHSA-6v3r-4p5c-mrp5 (1)
- GHSA-6vxv-wg6j-5qwp (1)
- GHSA-6whr-xjjm-6pf8 (1)
- GHSA-78mw-f4q2-924q (1)
- GHSA-7g4w-cg88-2cq2 (1)
- GHSA-864f-rcv7-6rh4 (1)
- GHSA-8gq3-vp5j-2grp (1)
- GHSA-c39w-43gm-34h5 (1)
- GHSA-c4hm-4h84-2cf3 (1)
- GHSA-g89c-p67h-r497 (1)
- GHSA-hvfh-5mj3-5f3j (1)
- GHSA-m5w8-4gq2-6f8x (1)
- GHSA-mf7q-r4rv-jv94 (1)
- GHSA-p293-qw3h-jr36 (1)
- GHSA-qrpv-q767-xqq2 (1)
- GHSA-rcr6-4jqh-j84m (1)
- GHSA-rg76-677x-56q9 (1)
- GHSA-vwf4-m7j8-wcjf (1)
- GHSA-w3fx-mc44-mf6j (1)
- GHSA-x2rj-828p-hx9m (1)
- GHSA-xhcr-j4j9-3gh7 (1)
- GIFTEDCROOK (1)
- Git (1)
- Git hook (1)
- Git hosting (1)
- git.exe (1)
- Gitea (2)
- GitHub (23)
- GitHub abuse (3)
- GitHub Actions (29)
- GitHub Advisory Database (1)
- GitHub API (1)
- GitHub App (1)
- GitHub CLI (1)
- GitHub dead drop (3)
- GitHub issue spam (1)
- GitHub OAuth (1)
- GitHub Pages (1)
- GitHub Pages abuse (2)
- GitHub PAT abuse (1)
- GitHub payload delivery (1)
- GitHub release assets (1)
- GitHub Security Advisories (9)
- GitHub tokens (2)
- GitHub-hosted runners (1)
- GitLab (3)
- gitleaks (1)
- gitnow (1)
- GitOps (1)
- GiveWP (1)
- Gleaming Pisces (1)
- gleeze.com (1)
- GlobalProtect (1)
- Gmail (5)
- Go (9)
- Go backdoor (1)
- Go loader (1)
- Go malware (4)
- Go modules (2)
- Go net/http user agent (1)
- Go stealer (1)
- Go2Tunnel (1)
- GoCaracal (1)
- GoDaddy federation (1)
- GodDamn ransomware (1)
- GodPotato (1)
- Godzilla (1)
- GoEdge (1)
- GoFile (2)
- GoginRAT (1)
- Gogs (1)
- Golang (2)
- Golang malware (1)
- GOLD PRELUDE (1)
- Golden Pass-ta-key (1)
- gomod (1)
- Goodhart's law (1)
- Google (2)
- Google account (1)
- Google Ads (2)
- Google Analytics telemetry (1)
- Google API (3)
- Google Calendar (1)
- Google Chrome (3)
- Google Cloud (2)
- Google Cloud Authenticator (1)
- Google Cloud Logging (1)
- Google Cloud Storage (1)
- Google credential theft (1)
- Google Docs (1)
- Google Drive (1)
- Google Notes (1)
- Google OAuth (1)
- Google Password Manager (1)
- Google Play (1)
- Google Play Protect (1)
- Google redirect abuse (1)
- Google Sheets (1)
- Google Sheets C2 (1)
- Google Stitch (1)
- Google Threat Intelligence Group (3)
- Google Workspace (1)
- Goose (1)
- GoSerpent (1)
- government (9)
- government impersonation (1)
- government offices (1)
- government services and facilities (1)
- government targeting (21)
- government-impersonation (1)
- GPT (1)
- GPT-5.6 Sol (1)
- GPT-5.6-Cyber (1)
- GPT-6 (1)
- Gradio (1)
- Grafana MCP Server (1)
- Grandoreiro (2)
- granular access tokens (1)
- Graph API (1)
- GraphQL (2)
- GraphQL Composite Data API (1)
- GraphSpy (1)
- Gravity SMTP (1)
- gray market (1)
- GRE (1)
- Gremlin API (1)
- GREYVIBE (1)
- Grok (1)
- group (5)
- Group-IB (3)
- groups (18)
- gRPC (2)
- gRPC C2 (2)
- GRU (2)
- gs-netcat (1)
- GS-Netcat (1)
- Gshell (1)
- GTIG (2)
- GUE (1)
- guest access abuse (1)
- guest-to-host escape (2)
- Guildma (1)
- Gunra (1)
- hack-and-leak (2)
- hacked WordPress sites (1)
- HackerOne (1)
- HackIndex (1)
- hacktivist persona (1)
- Hades (3)
- Hajime (1)
- half-click exploit (1)
- hallucination (1)
- HalluSquatting (1)
- Halo's Gate (1)
- Handala (1)
- HappyDoor (1)
- HAProxy (1)
- HAR files (1)
- hard-coded password (1)
- hard-coded secrets (1)
- HardBreacher (1)
- hardcoded key (1)
- hardening gap (1)
- hardware wallet (2)
- HarmonyLib (1)
- HashiCorp Vault (1)
- HavocKiller (1)
- HDF5 (1)
- Head Mare (1)
- head unit (1)
- HEADLACE (1)
- headless browser (3)
- headless Edge (1)
- HEADRUSH (1)
- healthcare (4)
- heap buffer overflow (2)
- heap overflow (1)
- heap pointer disclosure (1)
- HEIC (1)
- HEIF (1)
- HELIX (1)
- HelloBackdoor (1)
- HelloCleaner (1)
- HelloDoor (1)
- HelloExecutor (1)
- HelloInjector (1)
- HelloNet (1)
- HelloProxy (1)
- HellsGate (1)
- Helm (1)
- help desk impersonation (1)
- Hermes (1)
- Hermes Agent (3)
- Hetzner (1)
- HexKiller (1)
- hidden backdoor (1)
- hidden instructions (1)
- hidden service (1)
- high explosives (1)
- higher education (2)
- HMI (1)
- holiday calendar lure (1)
- HOLLOWGRAPH (1)
- homoglyph (1)
- Honduras (2)
- HONESTCUE (1)
- honeypot (2)
- Hong Kong (1)
- Hong Kong infrastructure (1)
- HOOKEDGE (1)
- hospitality (1)
- hospitality targeting (2)
- host DNS hijacking (1)
- Host Radar (1)
- host RCE (2)
- host surveillance (1)
- hosting control plane (1)
- hosting provider (1)
- hosting providers (1)
- Hostwinds (1)
- hotel targeting (1)
- Howling Scorpius (1)
- HPC (1)
- HR lures (1)
- HS256 (1)
- HTA (6)
- HTML comments (1)
- HTML email (2)
- HTML sanitization (1)
- HTML smuggling (1)
- html5lib (1)
- HTTP C2 (1)
- HTTP/2 (2)
- HttpMalice (1)
- HTTPS C2 (2)
- HTTPS exfiltration (1)
- HTTPSpy (1)
- Hugging Face (3)
- HUMAN Satori (1)
- humanoid robot (1)
- Hunt.io (6)
- Huntress (4)
- Huorong (1)
- Hyadina (1)
- hybrid threat actor (1)
- hydropower (2)
- Hydropower Cooperation Project Proposal.zip (1)
- hypervisor escape (2)
- Hyunwoo Kim (1)
- I-SOON (2)
- IAB (2)
- iACL (1)
- IAM (2)
- Iberian (2)
- IBM (1)
- iCagenda (1)
- ICE (1)
- Ice Relic (1)
- iCloud theft (1)
- ICONICSTEALER (1)
- ICS (4)
- IDE extension (2)
- IDE plugins (1)
- IDE trust boundary (1)
- ide.cfm (1)
- identity (5)
- identity attack (1)
- identity attacks (1)
- identity compromise (1)
- identity infrastructure (1)
- identity phishing (1)
- identity security (1)
- identity theft (1)
- identity-first intrusion (1)
- IDEs (2)
- IFEO persistence (1)
- IIOP (1)
- IIS (4)
- IKE (1)
- IKEv1 (1)
- Ill Bloom (1)
- image optimization (1)
- image proxy bypass (1)
- image recognition (1)
- ImageMagick (1)
- iMessage (2)
- Impacket (4)
- Imperial Kitten (1)
- impersonation (2)
- implant (1)
- import-time execution (6)
- improper access control (3)
- improper authentication (1)
- improper authorization (1)
- improper privilege management (1)
- in-memory (1)
- in-memory DLL loading (1)
- in-memory ELF execution (1)
- in-memory malware (3)
- in-memory plugins (1)
- incident response (38)
- incident-response (2)
- incomplete patch (1)
- IndexedDB (3)
- India (3)
- India-nexus (1)
- Indian government (1)
- indirect prompt injection (11)
- indirect syscalls (1)
- Indonesia (1)
- industrial control (1)
- industrial control systems (3)
- industrial espionage (1)
- industrial targeting (1)
- infect[.]online (2)
- Infected Marketplace (2)
- inference server (1)
- INFINITE NIGHTMARE (1)
- INFINITERED (1)
- Infoblox Threat Intel (1)
- information disclosure (5)
- information stealer (1)
- infostealer (28)
- infotainment (1)
- InfoTeCS (1)
- infrastructure (6)
- infrastructure churn (1)
- infrastructure disruption (4)
- infrastructure seizure (1)
- initial access (2)
- initial access broker (4)
- initial-access (3)
- Injective Labs (1)
- Inno Setup (2)
- input capture (1)
- insider threat (1)
- install-time execution (7)
- install-time-execution (1)
- install.res.1033.dll (1)
- integer-overflow (1)
- Integration Broker (1)
- inter-agent communication (1)
- Intercolo (1)
- internal secret exfiltration (1)
- internal security review (1)
- internet exposure (2)
- internet-facing admin surface (1)
- internet-facing appliance (2)
- internet-facing applications (1)
- investment scam (1)
- invisible prompt injection (1)
- InvisibleFerret (1)
- invocation logging (1)
- iOS (3)
- IOS XR (1)
- IoT (9)
- IoT botnet (8)
- IP cameras (2)
- IP-in-IP (1)
- IPFS (1)
- iPhone (1)
- IPMODIFY (1)
- IPsec (1)
- IPv6 (3)
- ipynbdiff (1)
- Iran (9)
- Iran-nexus (3)
- IRC C2 (1)
- IRGC (1)
- IronWorm (1)
- Irregular (1)
- ischhfd83 (1)
- Island Security (1)
- Island Security Research (2)
- ISO image (2)
- isolated-vm (1)
- Israel (4)
- IT providers (1)
- Italian foreign-policy targeting (1)
- Italy targeting (1)
- ITCSD (1)
- ITRES Labs (1)
- Ivanti Sentry (1)
- JackSkid (1)
- Jackson (1)
- JADEPUFFER (2)
- Jamf Threat Labs (2)
- Januscape (2)
- Japan (1)
- JAR payload (1)
- JARLEASH (1)
- JarService (1)
- Java (3)
- Java deserialization (1)
- Java malware (1)
- java.rmi.MarshalledObject (1)
- JavaScript (21)
- JavaScript bridge (1)
- JavaScript execution (1)
- JavaScript implant (1)
- JavaScript injection (2)
- JavaScript loader (1)
- JavaScript malware (5)
- JavaScript masquerading (1)
- JavaScript runtime (1)
- JavaScript tampering (1)
- JavaScriptCore (1)
- JBoss (1)
- JCE (1)
- JDY (1)
- Jellyfin (1)
- Jenkins (1)
- JetBrains (3)
- JetBrains Marketplace (1)
- JetStream (1)
- JFrog (5)
- JFrog Artifactory (1)
- JFrog Security Research (5)
- Jinja (1)
- Jinja2 (1)
- JINX-0164 (2)
- Jira (2)
- Jiří Vinopal (1)
- job-offer phishing (1)
- job-themed phishing (1)
- joblib (1)
- Joomla (3)
- Joomla Content Editor (1)
- Joomla JCE (1)
- Joomlack (1)
- JoomShaper (1)
- Jordan (1)
- journalism (1)
- journalists (1)
- JPMorgan Chase (1)
- JSCEAL (1)
- JSCoreRunner (1)
- jscrambler (1)
- Jscrambler (1)
- JScript (1)
- JSON (1)
- JSON Web Token (1)
- JSON-RPC (2)
- JSON:API (1)
- jsonata (1)
- JSONKeeper (1)
- JSONL (1)
- JSONPing (1)
- JSP web shell (1)
- JuicyPotato (2)
- Jupyter (1)
- Jupyter Notebook (1)
- JustWatch (1)
- JWT (3)
- JWT alg none (1)
- JXA downloader (1)
- K1MORPHER (2)
- Kairos (1)
- Kaitori (1)
- Kali365 (1)
- Kaltura (1)
- Kaspersky (4)
- Kaspersky detection bypass (1)
- Kaspersky GERT (1)
- Kaspersky GReAT (3)
- Kaspersky Securelist (2)
- Kazakhstan (2)
- KAZUAR (2)
- KAZUAR overlap (1)
- KB5002893 (1)
- KeePassXC (1)
- Keitaro (1)
- Keksec (1)
- Kemp LoadMaster (1)
- kernel driver (4)
- kernel instrumentation (1)
- kernel R/W (1)
- kernel rootkit (1)
- kernelCTF (2)
- Kestra (2)
- KEV (4)
- keychain (1)
- Keychain theft (1)
- keychain theft (4)
- Keycloak (1)
- KeyHunter (1)
- keylogger (5)
- keylogging (4)
- keyval.org (1)
- keyword splitting (1)
- Kimi K2.5 (1)
- Kimsuky (1)
- Kimwolf (1)
- Kimwolf v7 (1)
- Kiro Powers (1)
- KLCERT-26-057 (1)
- KLCERT-26-058 (1)
- Klue (1)
- knaithe (2)
- knowledge base (1)
- KnowledgeDeliver (1)
- known exploited vulnerability (1)
- KNUCKLEBALL (1)
- KNX (1)
- KNX Association (1)
- KNX Protocol (1)
- KnYuan (2)
- KongTuke (1)
- KORKERDS (1)
- Kratos (1)
- krbtgt (1)
- Kubernetes (6)
- KV-botnet (1)
- KVM (2)
- KVM escape (1)
- kvmCTF (1)
- Kyrgyzstan (1)
- L2TP/IPSec (1)
- LA Metro (1)
- Laboo.boo (2)
- LabubaPanel (1)
- LabubaRAT (1)
- Labubu (2)
- LangChain (3)
- Langflow (12)
- LangFlow (1)
- LangGraph (1)
- Language Servers for AWS (1)
- Lantronix (1)
- LapDogs (1)
- Laravel (2)
- Laravel deserialization (1)
- LATAM (3)
- lateral movement (10)
- lateral-movement (1)
- Latin America (4)
- LaunchAgent (5)
- launchctl (1)
- LAUNDRY BEAR (4)
- law enforcement (3)
- law enforcement targeting (2)
- law-enforcement-disruption (1)
- LayerX (1)
- Lazarus (7)
- LD_PRELOAD (2)
- LDAP (1)
- leak site (1)
- leaked credentials (1)
- leaked exploit (1)
- leaked repository (1)
- leaked source code (1)
- learning cycles (1)
- LEASHTEST (1)
- least privilege (4)
- Ledger (1)
- legacy botnet hijacking (1)
- legacy infrastructure (1)
- legacy pattern (1)
- legacy software (1)
- legacy systems (1)
- legal sector (1)
- LegionRelay (1)
- Leo Platform (1)
- Level RMM (1)
- LevelBlue (1)
- Lexfo (1)
- libcurl (1)
- libheif (1)
- liblzma (1)
- libmupdf.dll (1)
- libp2p (1)
- libpeconv (1)
- libsignal-node (1)
- libslirp (1)
- libsodium (1)
- libuser (1)
- lifecycle hooks (1)
- lifecycle-hooks (1)
- lighthouse beacon (1)
- Lightning Shared Scooter Co. (1)
- Lightning Web Runtime (1)
- LinkedIn (2)
- Linksys (1)
- Linux (30)
- Linux backdoor (1)
- Linux kernel (7)
- Linux malware (3)
- Linux networking devices (1)
- Linux rootkit (1)
- LiteLLM (7)
- LiteSpeed (2)
- LiteSpeed Cache (1)
- live chat (1)
- Live Protect (1)
- living off the land (1)
- living-off-the-land (1)
- living-off-the-land binaries (1)
- LLM (10)
- LLM command execution (1)
- LLM gateway (1)
- LLM security (1)
- LLM slop (2)
- LLM-assisted malware (4)
- LLM-driven intrusion (1)
- LLMjacking (2)
- LMS (1)
- LNK (11)
- LNK files (1)
- LNK Startup persistence (1)
- load balancer (1)
- loader (7)
- loadlib2 (1)
- LoadLibrary (1)
- LOADLOOP (1)
- local exploit (2)
- local inference (1)
- local LLMs (1)
- local privilege escalation (10)
- local subprocess (1)
- local-file-inclusion (1)
- localhost (2)
- localhost trust bypass (1)
- localhost.run (1)
- localStorage (2)
- LockBit (2)
- LockBit 3.0 (1)
- Lockdown Mode (1)
- LockScreen (1)
- LockScreenContentServer (1)
- log poisoning (1)
- log sanitization (1)
- Log4j (1)
- Log4j 2 (1)
- Log4j 2.26.1 (1)
- logging (1)
- logging impairment (1)
- logical decoding (1)
- login item persistence (1)
- LOLBAS (1)
- LOLBins (3)
- long-horizon autonomy (1)
- long-lived tokens (1)
- long-term access (1)
- long-term surveillance (1)
- LONGLEASH (1)
- LONGSTREAM (1)
- LOOKVALJS (1)
- LOOKVALPS (1)
- loopback (2)
- loopback login (1)
- Loophole (1)
- loose boolean check (1)
- LosFormatter (1)
- Lovable (1)
- low-confidence attribution (4)
- LPE (1)
- LS-DYNA (1)
- LSASS (1)
- LSHIY (1)
- LSN (1)
- LSSC (1)
- Lua (1)
- LuaJIT (1)
- Lumen (1)
- Lumen Black Lotus Labs (2)
- Lumma Stealer (1)
- Luna Moth (1)
- Luno (1)
- LurkProxy (2)
- Lyceum (1)
- M-RED-TEAM (1)
- M365 (1)
- MaaS (8)
- Mabna Institute (1)
- MAC address (1)
- MacCMS (1)
- Maccy impersonation (1)
- Machine Account Quota (1)
- machine-learning (1)
- machine-speed attack chain (1)
- macOS (20)
- macOS malware (2)
- macro (1)
- macro-enabled Word (1)
- MacSync (1)
- MaDoO Blaster (1)
- Magento (1)
- magic packet (1)
- MagicYUV (1)
- mail server compromise (1)
- mail-argenta (1)
- mailbox compromise (1)
- mailbox permission abuse (2)
- mailbox theft (3)
- MAIN world injection (1)
- maintainer compromise (5)
- maintainer persona (1)
- maintainer-account-compromise (1)
- maintainer-compromise (2)
- malformed signature (1)
- malicious dataset (1)
- malicious GPO (1)
- malicious package (1)
- malicious packages (6)
- malicious plugin (1)
- malicious releases (2)
- malicious signed driver (1)
- malvertising (10)
- malware (65)
- malware analysis (2)
- malware delivery (7)
- malware framework (3)
- malware scanning (1)
- Malware-as-a-Service (1)
- malware-as-a-service (5)
- malware-signing-as-a-service (1)
- MALXMR (1)
- man-in-the-middle (1)
- managed database (1)
- managed file transfer (2)
- managed service provider (2)
- ManageEngine Endpoint Central (1)
- management plane (5)
- Manifest V3 (1)
- Manifold Security (1)
- manufacturing (4)
- Mapbox (2)
- marimo (3)
- Markdown image rendering (1)
- marker (1)
- MARKETMAKER (1)
- marketplace abuse (2)
- marketplace trust (1)
- MarkiRAT (1)
- MarlboroMan (1)
- mass disclosure (1)
- mass repository cloning (1)
- mass scanning (1)
- Maven Central (1)
- mawesome (1)
- Mbed (1)
- McAfee Labs (2)
- McMx (1)
- MCP (22)
- MCP configuration (1)
- MCP credentials (1)
- MCP gateway (1)
- MCP stdio command execution (1)
- mcp-grafana (1)
- MECCHA CHAMELEON (1)
- media embed (1)
- media processing (1)
- media sector (1)
- MediaFire (1)
- medical research (1)
- Mekotio (1)
- memfd (1)
- memory corruption (3)
- memory disclosure (2)
- memory implant (1)
- memory overflow (1)
- memory overread (1)
- memory poisoning (2)
- memory protection unit (1)
- memory-only malware (1)
- MEMORY.md (1)
- merchant credential theft (1)
- mesh VPN (1)
- MeshAgent (1)
- MeshCentral (2)
- Meta Ads (1)
- meta-hacking (1)
- Metabase (2)
- MetaMask (1)
- Metasploit (1)
- METR (1)
- MEV bot lure (1)
- Mexican banking fraud (3)
- Mexico (4)
- MFA (1)
- MFA bypass (10)
- MFA fatigue (2)
- MFA-bypass (1)
- MFT (1)
- Miasma (12)
- MicroLogix 1100 (1)
- MicroLogix 1400 (1)
- MicroPython (2)
- Microsoft (15)
- Microsoft .NET (1)
- Microsoft 365 (11)
- Microsoft 365 Copilot (1)
- Microsoft Authentication Broker (1)
- Microsoft Azure (1)
- Microsoft Copilot Personal (1)
- Microsoft Defender (5)
- Microsoft Defender exclusion (1)
- Microsoft Defender Experts (1)
- Microsoft Defender Security Research (1)
- Microsoft dev tunnels (2)
- Microsoft Digital Crimes Unit (1)
- Microsoft Edge (2)
- Microsoft Edge Add-ons (2)
- Microsoft Edge Extensions Security Team (1)
- Microsoft Edge masquerade (1)
- Microsoft Entra ID (5)
- Microsoft Exchange Server (2)
- Microsoft Graph (4)
- Microsoft Identity Platform (1)
- Microsoft Office SharePoint (1)
- Microsoft Security Blog (1)
- Microsoft Security Research (2)
- Microsoft SQL Server (1)
- Microsoft Teams (6)
- Microsoft Threat Intelligence (5)
- Microsoft typosquat (1)
- Microsoft Windows Hardware Compatibility Publisher (1)
- Microsoft-signed binary abuse (1)
- MicrosoftSystem64 (1)
- Middle East (8)
- middleware (1)
- Midnight Blizzard (3)
- military logistics (1)
- military research (1)
- Milo Wallet (1)
- Mimikatz (6)
- mind virus (1)
- Mindgard (1)
- Minecraft (1)
- Minecraft DDoS (1)
- miner dropper (1)
- Mini Shai-Hulud (8)
- MiniJunk (1)
- miniOrange (1)
- MiniPlasma (1)
- MINIRAT (2)
- MINIRECON (2)
- Ministry of Finance (2)
- Ministry of State Security (1)
- Ministry of Transport and Communications (1)
- MiniUpdate (1)
- mint (1)
- MIPS embedded devices (1)
- Mirage Kitten (5)
- Mirage2FA (1)
- Mirai (3)
- Mirai-derived botnet (1)
- missile procurement (1)
- missing authentication (1)
- Mistic (2)
- MISTPEN (1)
- MITRE ATLAS (1)
- MITRE ATT&CK (5)
- MITRE ATT&CK T1005 (1)
- Mitre ATT&CK T1110 (1)
- MITRE ATT&CK T1562 (1)
- mixed boolean arithmetic (3)
- MIXEDKEY (3)
- MLflow (1)
- MLTBackdoor (2)
- mnemonic theft (1)
- mobile (1)
- Mobile Access (1)
- mobile banking fraud (1)
- mobile device management (1)
- mobile devices (1)
- mobile exploitation (1)
- mobile malware (3)
- mobile spyware (1)
- MobileIron Sentry (1)
- MODAFL (1)
- MODBEACON (2)
- Model Context Protocol (13)
- model poisoning (1)
- model registry webhooks (1)
- model weights (1)
- model-level persistence (1)
- model-provider abuse (1)
- ModeloRAT (2)
- modem firmware (1)
- ModHeader (1)
- modular malware (3)
- module-proxy (1)
- MOIS (7)
- Moltbook (1)
- Moltbot (1)
- Monero (2)
- Monero mining (1)
- MongoDB (1)
- Monster ransomware (1)
- monthly security release (1)
- MoreQuick (1)
- Motorola E13 (1)
- MoYu (1)
- Mozi (2)
- MpClient.dll (1)
- mpengine (1)
- MpEngine.dll (1)
- MpExtMs.exe (1)
- MPK (1)
- MPR network provider (1)
- Mr_Rot13 (1)
- MS-ISAC (1)
- Ms36-AcCeSs (1)
- msaRAT (1)
- MSBuild (1)
- msgpack (1)
- mshta (6)
- MSI (2)
- msiexec (1)
- MSNightmare (1)
- MSP (3)
- MSSQL (1)
- MSXML2.XMLHTTP (1)
- mTLS (1)
- MU plugin (1)
- Muck and Load (1)
- MuddyWater (4)
- Mullvad VPN (1)
- multi-agent (1)
- Multi-Domain Security Management (1)
- multi-model ensemble (1)
- multi-organization PAT campaign (1)
- multi-SAN certificate (1)
- multi-tenant cloud (2)
- multi-tenant isolation (2)
- multiplex queries (1)
- Multiply-With-Carry (1)
- Mustang Panda (4)
- Mustard Tempest (1)
- mutable tags (2)
- mutation attacks (1)
- mutex (1)
- mwEmbed (1)
- mwEmbedLoader.php (1)
- Myanmar (1)
- MYRA (1)
- MySQL (1)
- Mysterious Elephant (1)
- Mythos (1)
- N-able (2)
- N-central (2)
- n8n (2)
- Nacos (3)
- NadMesh (1)
- named pipes (1)
- Named Pipes (1)
- namespace recycling (1)
- namespace squatting (2)
- NanChat (1)
- Nanjing Xinjiuwei (1)
- NAS targeting (1)
- nation-state (1)
- national identity records (1)
- native addon (1)
- native extension (3)
- NativeAOT (3)
- NATO (3)
- NATS (1)
- NCSC-NL (1)
- Nebo (1)
- Nebula Security (1)
- Negotiate (1)
- negotiation (1)
- NemoClaw (1)
- Neo-reGeorg (1)
- neocloud (1)
- nested virtualization (1)
- Neteller (1)
- Netherlands (2)
- NetKeyboard (1)
- Netlify (1)
- Netlify abuse (1)
- NetNut (1)
- NetScaler (5)
- NetScaler ADC (5)
- NetScaler Gateway (5)
- NetSetup.log (1)
- network access (1)
- network detection (1)
- network infrastructure (2)
- network infrastructure exploitation (1)
- network isolation bypass (1)
- network policies (1)
- network switch (1)
- network-share exfiltration (1)
- NexShield (1)
- Next.js (1)
- NextChat (1)
- Nextcloud (1)
- Nextcloud Flow (1)
- Nexus 9000 (1)
- nf_tables (1)
- NFS (1)
- nftables (1)
- NGINX (1)
- Nginx (2)
- Nginx module (1)
- ngrok (1)
- Ngrok C2 (1)
- NIC impersonation (1)
- Nigeria-nexus (1)
- Night Dragon (1)
- NightLedger (2)
- Nightmare-Eclipse (1)
- Nim (1)
- Nimbus Manticore (2)
- NirSoft (1)
- no active exploitation (1)
- no attribution (1)
- no C2 (1)
- no credential theft (1)
- no vendor response (1)
- no-install-hook delivery (1)
- No-IP (1)
- node-gyp (2)
- node-ipc (1)
- node-pty (1)
- Node-RED (1)
- node.exe (1)
- Node.js (11)
- Node.js implant (1)
- Node.js malware (1)
- node:zlib (1)
- NodeEdgeRAT (1)
- NomadRAT (1)
- non-standard protocol abuse (1)
- North Korea (13)
- notarized malware (2)
- notebook security (1)
- notebookjs (1)
- notification interception (1)
- NOVA (1)
- NovaCookies (1)
- NoviSpy (1)
- Now Platform (1)
- npm (70)
- npm lifecycle hook (3)
- npm mirrors (1)
- npm supply-chain (1)
- npm token theft (1)
- npm tokens (1)
- npm v12 (1)
- npmmirror (1)
- npx (1)
- npx confusion (1)
- NSA (1)
- NSecKrnl.sys (1)
- NSO Group (1)
- nsppe (1)
- NTDS.dit (2)
- NTFS ADS (3)
- NTLM (2)
- NTLM relay (1)
- nuclear procurement (1)
- nuclear research (1)
- nuclear weapons (1)
- NuGet (4)
- Nuitka (1)
- null byte truncation (1)
- null-byte padding (1)
- NullReceiver (1)
- NullSessionPipes (1)
- NVD (1)
- NVD scoring (1)
- NVGRE (1)
- NVIDIA (1)
- NVIDIA impersonation (1)
- NX-OS (1)
- O-UNC-066 (1)
- OAST (1)
- OAuth (6)
- OAuth 2.1 (1)
- OAuth abuse (4)
- OAuth client credentials (1)
- OAuth device authorization grant (2)
- OAuth error redirect (1)
- OAuth phishing (1)
- OAuth redirect (1)
- OAuth token abuse (1)
- OAuth token exposure (1)
- OAuth token theft (2)
- OAuth tokens (3)
- OBF networks (1)
- obfuscation (1)
- obfuscator.io (1)
- ObjectInputStream (1)
- Oblivion (2)
- obsolete software (1)
- OCI registry (1)
- OCR content analysis (1)
- OctLurk (2)
- Octopi365 (1)
- OFAC (2)
- Office macros (1)
- official store compromise (1)
- Offshore LC (1)
- OIDC (9)
- OilRig (1)
- Oj (1)
- OkoBot (1)
- Okta (6)
- Okta Threat Intelligence (1)
- OKX (1)
- Ollama (4)
- OLLAMA_HOST (1)
- Oman (1)
- Omnibox (1)
- OmniStealer (1)
- Omnivore (1)
- one-click (1)
- OneDrive (3)
- OneDrive access (1)
- OneDrive C2 (2)
- onion routing (1)
- Ontinue (1)
- opaque predicates (2)
- open directory (1)
- Open Interpreter (1)
- open registration (1)
- Open VSX (1)
- Open WebUI (1)
- open-source (1)
- open-source supply chain (1)
- open-source-malware (1)
- OpenAI (3)
- OpenAI API keys (1)
- OpenAI Codex (1)
- OpenAI Daybreak (1)
- OpenClaw (4)
- opencode (1)
- OpenConnect (1)
- OpenHands (1)
- OpenSearch (1)
- OpenShell (1)
- OpenShield (1)
- OpenSourceMalware (1)
- OpenSSF (1)
- OpenSSH (2)
- openssl_verify (1)
- OpenVPN (3)
- OpenVPN-shaped UDP (1)
- OpenVSX (2)
- OpenWebUI (1)
- OpenWrt (2)
- operation (4)
- Operation BlueDash (1)
- Operation CameraSwarm (1)
- Operation DangerousPassword (1)
- Operation Dream Job (1)
- Operation Economic Outcast (1)
- Operation Endgame (1)
- Operation Escaneo (1)
- Operation Highland (2)
- operational relay box (1)
- Operational Relay Box (1)
- operational resilience (1)
- operational security (1)
- operational technology (2)
- operations (332)
- operator lockout (1)
- OpFauxSign (1)
- opportunistic exploitation (1)
- opportunistic scanning (1)
- ops (391)
- OPSEC failure (1)
- opsec failure (1)
- OpSec failure (1)
- OPSWAT (1)
- Oracle (2)
- Oracle E-Business Suite (1)
- Oracle Fusion Middleware (1)
- Oracle HTTP Server (1)
- Oracle Payments (1)
- Oracle PeopleSoft (2)
- Oracle WebLogic Server (2)
- ORANGETAIL (1)
- ORB network (1)
- organization username (1)
- OS command injection (3)
- OT (6)
- OT switches (1)
- OTA update (1)
- OTP interception (1)
- OtterCookie (1)
- Ousaban (2)
- out-of-bounds read (1)
- out-of-bounds write (2)
- outbound C2 (2)
- Outlook (2)
- Outlook Web Access (2)
- Outsider Enterprise (1)
- overfitting (1)
- overlay attacks (2)
- OWA (1)
- OWAReaper (2)
- ownCloud (2)
- OX Security (6)
- OxideHarvest (1)
- OYSTERBLUES (1)
- OYSTERFRESH (1)
- OYSTERSHUCK (1)
- P2P (1)
- P2P botnet (1)
- P2P C2 (1)
- P2P relay (1)
- P2P sinkhole (1)
- p2pwn (1)
- package fork (1)
- package hijacking (1)
- package masquerading (1)
- package name reuse (1)
- package registry (9)
- package registry abuse (1)
- package registry credentials (1)
- package registry proxy (1)
- package republishing (1)
- package scanning (1)
- package takedown (1)
- package-cooldowns (1)
- package-manager-hardening (1)
- package-splitting (1)
- package-takeover (1)
- Packagist (5)
- packet injection (1)
- PAExec (1)
- Page Builder CK (1)
- page cache (2)
- page poisoning (1)
- paired session (1)
- Pakistan (4)
- Pakistan-aligned (1)
- Pakistan-linked (2)
- Palo Alto Networks (2)
- PAM (2)
- PAM credential validation (1)
- PamStealer (1)
- PAN-OS (1)
- Pandora RC (1)
- PaperCut (1)
- PaperCut MF (1)
- PaperCut NG (1)
- parallel agent orchestration (1)
- parallel-intrusion (1)
- parameter-to-prompt (1)
- parked domain (1)
- partial encryption (1)
- Pass-ta-key (1)
- pass-the-cookie (1)
- passive backdoor (1)
- passkeys (2)
- password manager theft (1)
- password reset (1)
- password spray (1)
- password spraying (4)
- password-protected archive (2)
- passwordless authentication (1)
- Pastebin (2)
- pastebin C2 (1)
- PAT theft (1)
- patch bypass (2)
- patch management (6)
- Patch the Planet (1)
- patch window (1)
- patch-now (1)
- PATCHCORD (1)
- patching (4)
- patchstack (1)
- Patchstack (1)
- path hijacking (1)
- path traversal (12)
- Patriot Bait (1)
- patterns (53)
- Paweł Płatek (1)
- payload loader (1)
- payload staging (1)
- payload storage (1)
- payload-as-a-service (1)
- payment fraud (1)
- payment SDK (1)
- payment skimmer (1)
- payment workflow exposure (1)
- payment-card theft (2)
- payment-card-theft (3)
- PayPal (1)
- payroll lures (1)
- Paysafe (1)
- pc-app.exe (1)
- PCM (1)
- pe_to_shellcode (1)
- pearl-miner (1)
- PEB hash (1)
- PebbleDash (1)
- pedit (1)
- peer list (1)
- Pegasus (1)
- pentesting (1)
- people (1)
- people and process (1)
- PeopleTools (1)
- PEP 723 (1)
- PerfWatson2.exe (1)
- Perplexity AI (1)
- persistence (37)
- persistent root access (1)
- persona operations (1)
- personal access tokens (2)
- PetitPotam (1)
- pfSense (1)
- pg_hba.conf (1)
- PhaaS (6)
- Phantom Gyp (3)
- PhantomClick (1)
- PhantomCore (1)
- PhantomGraph (1)
- PhantomMail (1)
- PhantomRelay (1)
- Philippines (2)
- phishing (32)
- phishing evasion (1)
- phishing overlays (1)
- phishing-as-a-service (8)
- Phorpiex (1)
- PHP (3)
- PHP code execution (1)
- PHP code injection (1)
- PHP object injection (3)
- PHP upload (1)
- PHP web shell (2)
- physical systems (1)
- physics (1)
- PicassoLoader (1)
- pickle (1)
- pig butchering (1)
- pig-butchering (1)
- PII (1)
- PII exposure (1)
- PII theft (1)
- Pimcore (1)
- Pimcore Studio (1)
- PINHOLE (1)
- PINK (1)
- Pink (1)
- Pipedream (1)
- pipelines (1)
- piracy (1)
- Piriform (1)
- pitboss (1)
- Pix (1)
- Pixeldrain (1)
- PixelSmash (1)
- PKGBUILD (1)
- PLA (1)
- plaintext HTTP (1)
- Plandex (1)
- PLC (2)
- PLENET (2)
- plugin architecture (3)
- plugin framework (1)
- plugin RCE (1)
- PlugX (4)
- PNG shellcode (1)
- PoC available (1)
- PoC exploit refusal (1)
- PocSuite3 (1)
- Pods (1)
- poisoned-branch (1)
- PoisonX (1)
- police digital services (1)
- policy-setting abuse (1)
- PolinRider (3)
- polkitd (1)
- Poly1305 (1)
- polyfill (1)
- Polygon (4)
- Polygon blockchain dead drop (2)
- Polymarket (1)
- polymorphic (1)
- polymorphic loader (1)
- polymorphic payloads (1)
- Popa (1)
- portmap (1)
- PortSwigger Research (1)
- Portugal (1)
- Portuguese-speaking (1)
- post-authentication RCE (1)
- post-exploitation (6)
- post-exploitation framework (1)
- post-index-change (1)
- post-mortem (1)
- postal-impersonation (1)
- PostCSS (1)
- PostgreSQL (5)
- postinstall (12)
- Potato (1)
- POWER.md (1)
- PowerCloud (1)
- PowerShell (29)
- PowerShell AMSI bypass (1)
- PowerShell execution (1)
- PowerShell malware (3)
- PowerShell RAT (1)
- PowerShower (1)
- PPPoE credential theft (1)
- PPtP (1)
- PRA (1)
- PraisonAI (1)
- PRC (2)
- PRC-aligned (1)
- PRC-nexus (1)
- pre-auth RCE (1)
- pre-authentication (3)
- pre-authentication RCE (1)
- pre-signed URL (2)
- Prefetch (1)
- preinstall (4)
- PreppHint (1)
- presigned URLs (1)
- primary keys (1)
- Primary Refresh Token (1)
- Primitive Bear (1)
- PrincessClub (1)
- priority inheritance (1)
- privacy (2)
- privacy exposure (1)
- private key theft (1)
- private packages (1)
- private registry fallback (1)
- private-key theft (1)
- privilege escalation (17)
- privileged proxy (1)
- Privileged Remote Access (1)
- PRNG (1)
- proc-macro1 (1)
- proc-macro2 (1)
- process discovery (1)
- process doppelgänging (1)
- process environment scraping (1)
- process hollowing (4)
- process injection (6)
- process lineage (1)
- process termination (2)
- procurement (1)
- product lifecycle management (1)
- professional services (1)
- profile.d (1)
- Program Compatibility Assistant (1)
- Progress Kemp LoadMaster (1)
- Progress Software (1)
- Project Lightwell (1)
- Project Proposal.exe (1)
- prompt infection (1)
- prompt injection (18)
- prompt-injection (4)
- prompt-injection guardrail bypass (1)
- PromptArmor (1)
- PROMPTFLUX (1)
- PROMPTSPY (1)
- promptware (1)
- proof of deletion (1)
- Proofpoint (2)
- protestware (1)
- Protobuf (1)
- Proton Mail (1)
- prototype pollution (1)
- provenance (1)
- Provenance (1)
- proxy (12)
- proxy botnet (1)
- proxy infrastructure (1)
- proxy network (2)
- proxy obfuscation (1)
- ProxyChains (1)
- proxyjacking (1)
- proxyware (1)
- prt-scan (1)
- PSEMHUB (1)
- pseudorandom number generator (1)
- PsExec (4)
- PSIGW (1)
- psychological operations (1)
- PTC (1)
- PteroBox (2)
- PteroPaste (2)
- PteroPSDoor (2)
- PteroSetup (2)
- PteroVDoor (2)
- public exploit (3)
- public file-transfer exfiltration (1)
- public proof of concept (1)
- public sector (3)
- Public Security Bureau impersonation (1)
- public service abuse (1)
- public-service C2 (1)
- publication bias (1)
- publish mode (1)
- publish-time scanning (1)
- publishing credentials (1)
- pull requests (2)
- PUP (1)
- PureLogs Stealer (1)
- PureRAT (1)
- pushd (1)
- pwn-request (1)
- PwPt-sHaRe (1)
- PyArmor (4)
- PyInstaller (2)
- PyPI (18)
- Python (17)
- Python extension modules (1)
- Python implant (1)
- Python malware (2)
- Python stealer (1)
- python-snap7 (1)
- pythonw (1)
- QEMU (1)
- Qianxin Threat Intelligence Center (2)
- QiAnXin XLab (4)
- Qihoo 360 (1)
- Qilin (4)
- QNAP (1)
- QR code (1)
- QR code interception (1)
- QScan (1)
- QTBotnet (1)
- QTFY (1)
- QTRouter (1)
- quantum computing (1)
- Quasar (1)
- query injection (1)
- Quest KACE SMA (1)
- QUIC (1)
- QUICAgent (1)
- Quick Assist (1)
- QuickFox (1)
- QUICSILVER (1)
- QuimaRAT (1)
- RaaS (2)
- RabbitMQ (1)
- race condition (1)
- RAGFlow (1)
- RainbowEx (1)
- RakNet flood (1)
- RAM disk (1)
- random number generator (1)
- ransom (1)
- Ransom-ISAC (1)
- ransomware (21)
- ransomware access (1)
- ransomware enablement (1)
- ransomware-access (1)
- rapid exploitation (2)
- Rapid7 (3)
- RAR archives (1)
- RAR staging (2)
- RAT (33)
- raw packet (1)
- Ray (2)
- RC4 (4)
- RC4 C2 (1)
- RC4 encryption (1)
- RCE (13)
- Rclone (1)
- rclone (1)
- RCS (1)
- RDP (3)
- RDP phishing (1)
- RDS (1)
- reachability (1)
- Reactor Core (1)
- Reactor Netty (1)
- readonly proxy (1)
- real-time operator control (1)
- Reality (1)
- Realme C33 (1)
- Reaper (1)
- reasoning replay (1)
- Reco (1)
- reconnaissance (5)
- recovery denial (3)
- recovery disruption (2)
- recovery flow (1)
- recovery phrase (1)
- recruitment lures (1)
- Red Agent (1)
- Red Dev 10 (2)
- Red Hat (2)
- Red Menshen (1)
- Red Offsec (1)
- Red Raindrop Team (2)
- red team (2)
- red teaming (1)
- REDACT (1)
- RedAlert (1)
- RedC2 (1)
- RedC2 4.0 (1)
- REDCap (1)
- Redis (5)
- Redis backdoor (1)
- RediSearch (1)
- RedShell (1)
- reduced cyber refusals (1)
- RedWing (2)
- REF6045 (2)
- REF9403 (1)
- reflective .NET loading (1)
- reflective loading (7)
- refresh token theft (1)
- refresh tokens (1)
- RegAsm process hollowing (1)
- registry controls (1)
- registry manipulation (1)
- registry metadata (1)
- registry persistence (6)
- registry Run key (1)
- registry storage (1)
- registry-controls (1)
- RelayShell (1)
- release automation (1)
- release tampering (1)
- Remcos (2)
- Remcos RAT (1)
- remote access (8)
- remote access software (2)
- remote access trojan (9)
- Remote Access VPN (1)
- remote code execution (30)
- remote debugging (2)
- remote desktop (1)
- remote MCP (1)
- remote monitoring and management (4)
- remote script injection (1)
- remote shell (1)
- Remote Support (1)
- remote support (2)
- Remote Utilities (2)
- remote-access (2)
- Remotely (1)
- RemotePE (1)
- RemotePELoader (1)
- removable media (1)
- Rentry (1)
- replication (1)
- REPLICATION attribute (1)
- repo-server (1)
- repository compromise (1)
- repository exfiltration (1)
- repository poisoning (3)
- request smuggling (1)
- research sector (1)
- reset-credentials (1)
- residential proxies (1)
- residential proxy (2)
- residential proxy abuse (1)
- responsible disclosure (3)
- REST API (1)
- REST C2 (1)
- restart-triggered execution (1)
- retail (2)
- retail trading (1)
- reverse proxy (2)
- reverse SOCKS5 (1)
- reverse SSH tunnel (1)
- reverse SSH tunneling (3)
- reverse tunnel (1)
- reverse tunneling (1)
- reverse tunnels (1)
- REVERSE_PROXY_TRUSTED_PROXIES (1)
- ReverseSocks (1)
- reviewdog (1)
- reward hacking (1)
- Rewards for Justice (1)
- RHBK (1)
- Rhysida (1)
- Rilide (1)
- Ring 0 (1)
- RingH23 (1)
- RMM (8)
- RMM abuse (12)
- ROADrecon (1)
- ROADtools (1)
- roadtx (1)
- Robbe Van Roey (1)
- Rockwell Automation (1)
- RoguePlanet (2)
- Rokarolla (2)
- RokRAT (1)
- rolling deploy (1)
- Rollup (1)
- Romania (1)
- RomulusLoader (1)
- Roo-Code (1)
- root (2)
- root access (1)
- root code execution (2)
- root escalation (1)
- root execution (2)
- root RCE (1)
- root shell (2)
- rootkit (5)
- ROOTRUN (1)
- Rootstock (1)
- ROPC (1)
- Rouki obfuscation (1)
- Roundcube (2)
- router (1)
- router compromise (4)
- router malware (1)
- Rovo (2)
- RovoBlast (1)
- ROX II (1)
- RRWallet (1)
- RSA (1)
- RSA public key (1)
- RSA-2048 (2)
- RSA-OAEP (1)
- RT-Thread (1)
- RTL819X (1)
- RTLO (1)
- rtmutex (1)
- RubyGems (5)
- Ruckus routers (1)
- Ruflo (1)
- RUGGEDCOM (1)
- Run key (1)
- Run key persistence (1)
- rundll32 (3)
- Runner.Worker (1)
- Runspace (1)
- runtime execution (2)
- runtime mutation (1)
- runtime patching (1)
- runZero (1)
- Russia (16)
- Russia targeting (2)
- Russia-affiliated (2)
- Russia-linked (3)
- Russia-linked cybercrime (1)
- Russia-nexus (2)
- Russia-speaking operator (1)
- Russian Intelligence Services (1)
- Russian intelligence services (1)
- Russian state-supported (4)
- Russian-speaking ecosystem (1)
- Russian-speaking forums (1)
- Rust (9)
- Rust loader (1)
- Rust malware (7)
- S3 Browser (1)
- S3-compatible storage (2)
- s5cmd (1)
- S7comm (1)
- SaaS (8)
- SaaS abuse (1)
- SaaS connectors (1)
- SaaS data access (1)
- SaaS exposure (2)
- sabotage (2)
- Safari (1)
- SafeDep (8)
- Salesforce (4)
- Sality (1)
- SAML (3)
- SAML IdP (1)
- Samsung TizenRT (1)
- sanctions (1)
- sandbox escape (10)
- sandbox evasion (2)
- sandboxing (1)
- Sandworm (2)
- Sangoma (1)
- Sapphire Sleet (1)
- saroula01 (1)
- SBA phishing (1)
- SCADA (1)
- scam infrastructure (1)
- scambling (1)
- scanner evasion (1)
- ScarCruft (1)
- SCCM (1)
- scheduled task (9)
- scheduled task persistence (6)
- scheduled tasks (6)
- SCMBANKER (2)
- scope squatting (1)
- scoped package impersonation (1)
- scorer manipulation (1)
- SCOUTCURL (1)
- screen capture (5)
- Screen Sharing (1)
- ScreenConnect (6)
- Screening Serpens (2)
- screenshot capture (2)
- screenshot theft (3)
- script injection (1)
- script-injection (1)
- SD-WAN (2)
- search hijacking (1)
- search poisoning (1)
- search result poisoning (1)
- search-ms (1)
- Seashell Blizzard (2)
- second-order injection (1)
- secondary sanctions (1)
- Secret Blizzard (3)
- secret exfiltration (2)
- secret exposure (1)
- secrets (6)
- secrets harvesting (1)
- secrets management (1)
- secrets manager compromise (1)
- SectopRAT (1)
- Secure Annex (1)
- Secure Firewall (1)
- Secure Firewall Management Center (1)
- Secure Preferences (1)
- Secure Workload (1)
- secure.html (1)
- Security Management Server (1)
- security operations (1)
- security platform (1)
- security tool abuse (1)
- security-tool discovery (1)
- SecurityPDF (1)
- seed phrase (1)
- seed phrase theft (2)
- seed recovery (1)
- SeedHunter (1)
- Seedworm (3)
- segmented networks (1)
- Sekoia (1)
- self-delete (1)
- self-DoS (1)
- self-hosted AI services (1)
- self-hosted applications (1)
- self-hosted Git (1)
- self-hosted media (1)
- self-hosted runner (1)
- self-managed (1)
- self-propagating payload (1)
- self-propagation (1)
- semantic-release (1)
- sendit.sh (1)
- sensitive information exposure (1)
- Sentinel (1)
- SentinelOne (1)
- Sentry (1)
- Sentry abuse (1)
- SEO fraud (3)
- SEO poisoning (9)
- Seqrite (1)
- Seqrite Labs (2)
- Serbia (1)
- serial-number relay (1)
- Serialize::unserialize (1)
- Serv-U (1)
- service accounts (2)
- service binding (1)
- service DLL persistence (1)
- service impairment (1)
- service persistence (1)
- Service Portal (1)
- service providers (1)
- service stop (1)
- service-agent (1)
- ServiceNow (4)
- ServiceNow AI Platform (2)
- ServiceUrl (1)
- ServiceWorker (1)
- Session (1)
- session cookie theft (4)
- session hijacking (2)
- session secret exposure (1)
- session theft (3)
- session token theft (1)
- setuid (1)
- setup.py (1)
- shadow AI (1)
- shadow copy (1)
- shadow copy deletion (2)
- shadow fleet (1)
- shadow MMU (1)
- SHADOW-AETHER (1)
- SHADOW-AETHER-040 (1)
- SHADOW-AETHER-064 (1)
- SHADOW-EARTH-066 (1)
- SHADOW-WATER-063 (1)
- ShadowPad (4)
- Shadowserver Foundation (1)
- Shai-Hulud (14)
- SHARDLOADER (2)
- SHARE Foundation (1)
- share propagation (1)
- shared accounts (1)
- shared hosting (4)
- shared memory (1)
- shared secrets (1)
- shared-module (1)
- shared_preload_libraries (1)
- SharedWorker (1)
- ShareFile (1)
- SharePoint (8)
- SharePoint Server (2)
- SharkLoader (1)
- sharp (1)
- Shattering the Dream (1)
- SHEETCORD (1)
- shell injection (1)
- shellcode (1)
- Shenzhen Zhibotong Electronics (2)
- ShieldBreak (2)
- Shinobi (1)
- ShinyHunters (2)
- ShinyHunters-adjacent (1)
- shipping lures (1)
- Shodan (1)
- ShortLeash (1)
- Shuckworm (1)
- side channel (1)
- side-loading (1)
- SideCopy (1)
- sideloading (1)
- Siemens (1)
- Siemens S7 (1)
- Sigma Forms Pro (1)
- Signal (3)
- Signal interception (1)
- signature evasion (1)
- signature verification (1)
- signed binary abuse (1)
- signed executable (1)
- signed malware (1)
- signed updates (1)
- signed-binary (1)
- signed-binary abuse (1)
- SignedInfo (1)
- Silent Ransom Group (1)
- Silent Swap (1)
- silent-patch (1)
- SilentCryptoMiner (1)
- SilentRunLoader (1)
- Silicon One (1)
- SiliconFlow (1)
- SilkLurk (2)
- SilkParasite (1)
- Silver Fox (4)
- Silver Pass-ta-key (1)
- Silverstripe (1)
- SimpleHelp (4)
- SimpleHelp RAT (1)
- SimpleHTTPServer exposure (1)
- simulation tampering (1)
- sinkhole (1)
- sinkholing (1)
- SIP (1)
- SIP ALG (1)
- Site Member permissions (1)
- SiYuan (1)
- skb (1)
- SkillCloak (1)
- SkillDetonate (1)
- Skrill (1)
- Skyvern (1)
- Slack webhook (1)
- sleep agent (1)
- sleeper packages (1)
- SLEEPWALKER (1)
- Sliver (2)
- SLSA (1)
- SLSA provenance (1)
- SMA1000 (3)
- smart building (1)
- smart contract (2)
- smart contracts (2)
- smart TVs (1)
- SMARTAXE (1)
- SmartConsole (1)
- SmartLoader (1)
- SmartScreen (1)
- SMB (2)
- SMB brute force (1)
- SMB egress (1)
- SMB/USB worm (1)
- smishing (5)
- SMM (1)
- Smoke Sandstorm (2)
- SMS interception (2)
- SMS phishing (1)
- SMS theft (1)
- sms-phishing (1)
- SMTP (1)
- SMTP abuse (1)
- Snake (1)
- snap7 (1)
- Sneaky 2FA (2)
- Sneaky2FA (1)
- SNMP (1)
- Snowflake (2)
- SNOWLIGHT (1)
- SNWLID-2026-0016 (1)
- SOAP API abuse (1)
- SOC (1)
- SoC (1)
- SocGholish (1)
- social abuse (1)
- social engineering (23)
- Social Security Administration (1)
- social-engineering (2)
- Socket (5)
- Socket Security (3)
- Socket Security Research (2)
- Socket.IO (2)
- SOCKS tunneling (1)
- SOCKS5 (11)
- SOCKS5 proxy (2)
- SOCKS5 tunneling (1)
- SockTz (1)
- SOCRadar (3)
- SoftEther VPN (2)
- SoftPerfect Network Scanner (1)
- software impersonation (1)
- software supply chain (2)
- software-deployment (1)
- SOHO router (1)
- SOHO routers (1)
- Solana (3)
- Solana Name Service (1)
- SolarWinds (1)
- Solid PDF Creator (1)
- SolidPDFCreator.dll (1)
- SolidPDFPcl2Bmp (1)
- Sonatype (4)
- Sonatype Guide (2)
- sonatype-2026-005660 (1)
- sonatype-2026-005899 (1)
- sonatype-2026-005901 (1)
- sonatype-2026-006746 (1)
- SonicWall (3)
- Sophos (1)
- SOUL.md (1)
- source code (1)
- source control (3)
- source repository compromise (1)
- source-code compromise (1)
- source-control token theft (1)
- source-package drift (1)
- source-package mismatch (2)
- source-repository abuse (1)
- source-repository poisoning (6)
- source-repository reconnaissance (1)
- SourceForge abuse (1)
- SourTrade (1)
- South Africa (1)
- South Asia (2)
- South Korea (3)
- Southeast Asia (7)
- SP Page Builder (1)
- Spain (1)
- spam (1)
- Spark RAT (1)
- SPEAKINGSTONE (1)
- spear phishing (12)
- spear-phishing (2)
- spearphishing (1)
- Specter (3)
- SPECTRALVIPER (1)
- SPECTRE (4)
- Spectre (1)
- Sphinx ransomware (1)
- SpiceRAT (1)
- SpiderLabs (1)
- Spikey Scorpius (1)
- Splunk (1)
- Spreadtrum (1)
- Spring (1)
- Spring AI (1)
- Spring AMQP (1)
- Spring Batch (1)
- Spring Boot (1)
- Spring Cloud Config (1)
- Spring Data REST (1)
- Spring Framework (1)
- Spring Integration (1)
- Spring Security (1)
- SprySOCKS (2)
- Spyroid (1)
- spyware (1)
- SQL injection (13)
- SQL Server (1)
- SQLite (2)
- SQLite state (1)
- SQLRCE0 (1)
- SquareShell (1)
- SSD Secure Disclosure (1)
- SSDP (1)
- SSH (4)
- SSH backdoor (1)
- SSH bastion (1)
- SSH brute force (2)
- SSH key exposure (1)
- SSH key persistence (1)
- SSH keylogger (1)
- SSH keys (4)
- SSH lateral movement (1)
- SSH persistence (1)
- SSH pivot (1)
- SSH tunnel (1)
- SSH tunneling (1)
- SSH tunnels (1)
- sshd (1)
- SSL VPN (3)
- SSO (4)
- SSRF (10)
- SSRF allow-list (1)
- STAC4749 (1)
- stack use-after-free (1)
- staged malicious update (1)
- staged publishing (1)
- staking-precompile (1)
- stale access (1)
- stale credentials (1)
- stale state (1)
- Starland RAT (3)
- Starlette (1)
- Startup folder (1)
- Startup folder persistence (2)
- state desynchronization (1)
- state divergence (1)
- state-linked (2)
- state-owned enterprise (1)
- static AWS keys (1)
- static credentials (1)
- Static Kitten (1)
- stdio (3)
- StealC (2)
- stealer (3)
- Steam profile dead drop (2)
- Steam Workshop (1)
- steering file (1)
- steganographic PNG (1)
- steganography (4)
- StegoAd (1)
- StepSecurity (3)
- Still Audio (1)
- Still Sync (1)
- Still Toolkit (1)
- STM32Cube (1)
- stock exchange (1)
- STOCKSTAY (3)
- StopAndProtect (1)
- storage deletion (1)
- Storage Zone Controller (1)
- stored XSS (1)
- Storm-2603 (1)
- Storm-2697 (1)
- Storm-2945 (2)
- Storm-3075 (1)
- Stowaway (1)
- STRD (3)
- streaming boxes (1)
- Stripe OLT (1)
- structured Markdown (1)
- StubMaker (1)
- student targeting (1)
- STUN (1)
- Stuxnet lineage (1)
- subject claim (1)
- subscription fraud platform (1)
- subscription PhaaS (1)
- Subtle Snail (2)
- SuccessKey (1)
- summarization (1)
- SUMMIT (3)
- Suo5 (1)
- Supabase (1)
- Super Forms (1)
- super peer (1)
- SUPERADMIN_SECRET (1)
- superuser escalation (1)
- supply chain (24)
- supply chain compromise (1)
- supply-chain (111)
- supply-chain attack (1)
- supply-chain attribution (1)
- supply-chain integrity (1)
- supply-chain risk (3)
- supply-chain-adjacent (1)
- surveillance (1)
- surveillance abuse (1)
- suspected China-aligned (1)
- suspected China-linked (1)
- SVG (3)
- SWE-agent (1)
- SweetPotato (1)
- Switchvox (1)
- SWUpdate (1)
- Symantec (1)
- Symantec Threat Hunter Team (2)
- symbolic link (1)
- symlink following (1)
- Synacktiv (1)
- Synacor (1)
- SynkLoader (1)
- Synology (1)
- synthetic commits (1)
- synthetic voice (1)
- Syria (1)
- Sysdig (2)
- SYSTEM (1)
- system prompt (1)
- SystemBC (1)
- systemd (1)
- systemd-userdbd (1)
- T1059 (1)
- T1078 (1)
- T1102.001 (1)
- T1190 (1)
- T1204.004 (1)
- T1552 (1)
- T1555 (1)
- T1566 (1)
- T1578 (1)
- T3 (1)
- T606 (1)
- T612 (1)
- T7250 (1)
- TA427 (1)
- TA488 (5)
- TA569 (1)
- Tactical RMM (2)
- tag characters (1)
- tag rewrite (1)
- tag tampering (4)
- TAG-124 (1)
- TAG-179 (1)
- TAG-182 (1)
- TAG-22 (2)
- tag-based install (1)
- Taiwan (9)
- Tajikistan (1)
- Take Control (1)
- takedown (3)
- TamperedChef (1)
- Tanzania (1)
- targeted attack (1)
- targeted malware (1)
- targeted operations (2)
- TartarusGate (1)
- task queue (1)
- task scheduler abuse (1)
- TaskWeaver (3)
- Tauri (1)
- tax forms (1)
- tax-season phishing (1)
- tc (1)
- TCP 43210 (1)
- TCP 43211 (1)
- TCP traffic diversion (1)
- tdata (1)
- TDS (2)
- Team PCP (1)
- TeamCity (1)
- TeamPCP (12)
- TeamPCP-adjacent (1)
- Teams access (1)
- Teams TURN relay (1)
- TeamViewer (1)
- TEASOUP (1)
- Tebi (1)
- tech support scam (1)
- technician session (1)
- technique crossover (1)
- technology sector (2)
- ted backdoor (1)
- telecom (2)
- telecom-impersonation (1)
- telecommunications (4)
- Telegra.ph (1)
- Telegram (14)
- telegram (1)
- Telegram bot (2)
- Telegram C2 (5)
- Telegram dead drop (2)
- Telegram exfiltration (1)
- Telegram notification (1)
- Telegram session theft (1)
- telemetry (1)
- TELEPUZ (1)
- Telerik (1)
- TELESHIM (4)
- Teletype (1)
- Telnet (1)
- Telnet brute force (3)
- Telnyx (1)
- Temp Zagros (1)
- template injection (1)
- tenant isolation (1)
- tenant-project (1)
- Tencent (1)
- TencShell (1)
- Tenda (1)
- Tenet Security (1)
- TerminalFix (1)
- Tesseract (1)
- Tetrade (1)
- TetrisPhantom (1)
- TeviRAT (1)
- text/plain request body (1)
- Thailand (4)
- The Gentlemen (1)
- The Hacker News (12)
- The Outsider (1)
- The Quarry (1)
- ThemeREX Addons (1)
- third-party integrations (1)
- third-party JavaScript (1)
- third-party risk (1)
- thought virus (1)
- threat hunting (2)
- threat intelligence (1)
- threat landscape (2)
- threat measurement (1)
- threat research (1)
- threat telemetry (1)
- ThrottleBlood (1)
- ThumbcacheService (1)
- thumbnail generation (1)
- time-of-check time-of-use (1)
- timestomping (1)
- timing attack (1)
- timing check (1)
- TinyGo (1)
- TinyRCT (3)
- tj-actions (1)
- TLS certificates (1)
- TLS interception (1)
- TmcLoader (1)
- TmcPayload (1)
- TOCTOU (2)
- ToddyCat (3)
- token forgery (3)
- token jacking (1)
- token replay (3)
- token revocation (1)
- token theft (10)
- token-theft (1)
- TONESHELL (2)
- TookPS (1)
- tool (4)
- tool calling (1)
- tool execution (1)
- tool output injection (1)
- tool poisoning (1)
- tool use (1)
- tool-call logging (1)
- tooling (5)
- tools (62)
- Tor (4)
- Tortoiseshell (2)
- Total Software Deployment (1)
- TouchSocket (1)
- Toy Ghouls (3)
- TPM (1)
- Trading Technologies (1)
- TradingView (2)
- traffic broker (1)
- traffic control (1)
- traffic hijacking (1)
- traffic manipulation (1)
- traffic-distribution-system (1)
- traffic-fraud (1)
- Trail of Bits (2)
- training data (1)
- transaction authority (1)
- transcript spoofing (1)
- transfer stations (1)
- transitive dependency (2)
- TranslatePress (1)
- translation software (1)
- transnational repression (1)
- transparent proxy (1)
- Transparent Tribe (3)
- transport (1)
- transportation (2)
- transportation sector (1)
- Trend Micro (3)
- TrendAI (2)
- Trezor (1)
- triage (2)
- TrickBot (1)
- Trident Ursa (1)
- Trinitite (1)
- Trivy (1)
- TRM Labs (1)
- trojanized daemons (1)
- trojanized installers (3)
- trojanized npm (1)
- trojanized PDF viewer (1)
- Tron (4)
- Troy (1)
- TrueConf (1)
- trust boundary (1)
- trusted extension risk (2)
- trusted publishing (3)
- trusted relationship abuse (2)
- trusted runtime (1)
- trusted-component weaponization (1)
- trusted-domain abuse (1)
- trusted-publishing (2)
- tunnel decapsulation (1)
- tunnel services (1)
- tunneling (4)
- Turkey (1)
- Turla (4)
- Turla collaboration (1)
- TuxBot (1)
- TuxBot v3 Evolution (1)
- TWCore (1)
- Twilio (1)
- Twilio SendGrid (1)
- Twill Typhoon (2)
- TWINLOOT (1)
- two-factor authentication (1)
- Tycoon2FA (1)
- type confusion (2)
- TypeConfuseDelegate (1)
- TypeScript (2)
- typosquat (4)
- typosquatting (16)
- U+E0000 (1)
- U.S. critical infrastructure (1)
- UAC (1)
- UAC bypass (3)
- UAC-0002 (2)
- UAC-0010 (3)
- UAC-0098 (1)
- UAC-0145 (2)
- UAC-0194 (3)
- UAC-0226 (1)
- UAT-10147 (4)
- UAT-11795 (3)
- UAT-5918 (1)
- UAT-7237 (3)
- UAT-7810 (1)
- Ubiquiti (1)
- Ubuntu (1)
- Udev persistence (1)
- UDP C2 (2)
- UDP/1900 (1)
- UI redressing (1)
- UI-API (1)
- Ukraine (15)
- Ukraine targeting (3)
- Ulej (3)
- UltraViewer (1)
- UltraVNC (1)
- Umbrij (3)
- unattributed (2)
- unauthenticated (10)
- unauthenticated access (4)
- unauthenticated admin access (1)
- unauthenticated API (2)
- unauthenticated HTTP exploitation (1)
- unauthenticated RCE (15)
- unauthenticated-publish (1)
- unauthorized pentest framing (1)
- UNC1069 (1)
- UNC1543 (1)
- UNC1549 (5)
- UNC2814 (1)
- UNC3753 (1)
- UNC4221 (1)
- UNC4736 (1)
- UNC5792 (1)
- UNC5976 (1)
- UNC6240 (2)
- UNC6293 (1)
- UNC6508 (1)
- UNC6671 (1)
- UNC6692 (2)
- UNC6780 (1)
- UNC7005 (1)
- unchecked-subtraction (1)
- unclaimed names (1)
- unfiltered_upload (1)
- unguarded plugin load (1)
- Uni-App (1)
- UniBLEed (1)
- Unicode (1)
- UniFi OS (1)
- Unified CM SME (1)
- uninitialized heap memory (1)
- unintended internet access (1)
- Unisoc (1)
- Unit 42 (14)
- United States (4)
- Unitree (1)
- university targeting (1)
- UNK_MassTraction (1)
- UNK_PitStop (1)
- unpatched (1)
- unpatched transitive library (1)
- unpatched vulnerability (2)
- unpkg (1)
- Unreal Engine (1)
- unrestricted file upload (1)
- unsafe deserialization (2)
- unsafe reflection (1)
- unsanctioned message board (1)
- unsigned installer (1)
- Unyielding Wasp (1)
- UpdateFactory (1)
- UPnP (2)
- UPS (1)
- upstream dependency (1)
- UPX (1)
- uranium compression (1)
- URL pack (1)
- URL parameter (1)
- URL retrieval (1)
- URLPattern (1)
- USB exfiltration (1)
- USB propagation (1)
- USB weaponizer (1)
- USB worm (2)
- use-after-free (4)
- user execution (2)
- user namespaces (2)
- user verification (1)
- UserAssist (1)
- username environmental keying (1)
- UserPath (1)
- USN Journal (1)
- UTA0355 (1)
- UTA0533 (1)
- UTG-Q-1000 (3)
- uTLS (1)
- Uzbekistan (1)
- V2Ray (1)
- V4bel (1)
- V8 (5)
- V8 isolate (1)
- V8 isolates (1)
- valid accounts (4)
- ValleyRAT (3)
- Varonis (1)
- Varonis Threat Labs (1)
- VBCloud (1)
- VBE (1)
- VBS (1)
- VBS loader (1)
- VBS spreader (1)
- VBScript (7)
- VBScript loader (1)
- vCenter (2)
- vector databases (1)
- VEIL#DROP (1)
- Velociraptor (1)
- VeloCloud (1)
- VeloCloud Orchestrator (1)
- Velvet Ant (2)
- VELVETSHELL (1)
- vendor compromise (1)
- vendor credentials (1)
- Venezuela (1)
- VENOMOUS BEAR (3)
- Vercel (3)
- Vertex AI (1)
- vesting-account (1)
- VHD (1)
- victim-owned relay infrastructure (1)
- Vidar (1)
- VIDAR (2)
- Vidar Stealer (3)
- video conferencing (1)
- video platform (1)
- Vietnam (2)
- Vietnam-aligned (1)
- Views (1)
- ViewState (1)
- ViewState deserialization (1)
- ViPNet (1)
- virtual machine escape (1)
- virtual patching (1)
- virtualization (2)
- virtualization targeting (2)
- VirusTotal sentiment abuse (1)
- vishing (10)
- Visual Studio (1)
- Visual Studio Code Remote SSH (1)
- Vite (1)
- Vitest (1)
- ViteVenom (1)
- VLESS (1)
- VM escape (1)
- vm2 (1)
- vManage (1)
- VMCI (1)
- VMSA-2026-0006 (1)
- VMware (4)
- VMware ESXi (2)
- VMXNET3 (1)
- VNC (2)
- VNT (2)
- VOD (1)
- voice phishing (1)
- Void Blizzard (4)
- Void Manticore (1)
- Volt Typhoon (1)
- VoLTE (1)
- volume serial number (1)
- VPN (9)
- VPN credentials (2)
- VPN gateway (1)
- VPN Go (1)
- VPN session hijacking (1)
- VS Code (9)
- VS Code tunnels (1)
- Vshell (1)
- VShell (1)
- VSIX (1)
- vSphere (2)
- vSphere Foundation (1)
- vssvc.exe (1)
- VU#213560 (1)
- VulnCheck (7)
- vulnerability (26)
- vulnerability database pollution (1)
- vulnerability disclosure (2)
- vulnerability exploitation (2)
- vulnerability management (3)
- vulnerability research (4)
- vulnerability-research (1)
- vulnerable appliances (1)
- VXLAN (1)
- w3wp.exe (1)
- wallet address replacement (1)
- wallet drainer (2)
- wallet infrastructure (1)
- wallet replacement (1)
- wallet theft (8)
- wallet-drainer (1)
- wallet-theft (4)
- WAPF (1)
- Wasabi (3)
- wastewater (1)
- watch_queue (1)
- watchdog (1)
- watchTowr (7)
- watchTowr Labs (1)
- water and wastewater (1)
- water sector (1)
- watering hole (2)
- watering-hole (2)
- WAV (1)
- weak authentication (1)
- weak credentials (1)
- weak entropy (2)
- weak passwords (2)
- weak RNG (1)
- weapons shipments (1)
- web application (6)
- web application compromise (1)
- web hosting (2)
- web IDE (1)
- web injection (1)
- web injector (1)
- web management interface (1)
- web page (1)
- web player (1)
- web proxy (1)
- web RCE (1)
- web server (3)
- web shell (11)
- web shell hunting (1)
- web shells (3)
- web supply chain (2)
- web-shells (1)
- WebAssembly (1)
- WebAuthn (1)
- WebDAV (6)
- webhook.site (1)
- WebHost Manager (1)
- WebKit (1)
- WebLogic (1)
- Weblogic Server Proxy Plug-in (1)
- webmail (4)
- WebRTC (3)
- webshell (1)
- webshells (1)
- website-compromise (1)
- WebSocket (7)
- WebSocket C2 (10)
- WebSocket session hijacking (1)
- websocket-sharp (1)
- WebView (1)
- WebView2 C2 (1)
- Webworm (1)
- Weedhack (1)
- WEEVILPROXY (1)
- Werkbit (1)
- WhatsApp (5)
- WhatsApp phishing (1)
- white-label (1)
- WHM (5)
- Wi-Fi credential theft (1)
- Widget Factory (1)
- Wiflyer (1)
- wiki (1)
- WILDDAY (2)
- WildFire (1)
- Windchill (1)
- Windchill PDMLink (1)
- WinDirStat (1)
- Windmill (1)
- Windows (53)
- Windows 11 25H2 (1)
- Windows Defender (1)
- Windows Defender exclusions (2)
- Windows Defender impairment (1)
- Windows filesystem (1)
- Windows Forms (1)
- Windows Installer (2)
- Windows malware (12)
- Windows persistence (1)
- Windows Run dialog (1)
- Windows Script Host (2)
- Windows Server 2025 (1)
- Windows servers (1)
- Windows service (1)
- Windows service persistence (1)
- Windows Terminal (1)
- Windows Update (1)
- Winnti Group (2)
- WinOS (1)
- Winos 4.0 (1)
- Winos4.0 (1)
- WinPython (1)
- WinRAR (4)
- WinRing0 (1)
- WinRM (1)
- WinSock (1)
- wiper (3)
- wiper-adjacent (1)
- WireGuard (2)
- Wiz (1)
- Wiz Research (2)
- WLDR agent (2)
- WM_COPYDATA IPC (1)
- WMI (1)
- Woodgnat (1)
- WordlistLoader (1)
- WordPress (15)
- WordPress 7.0.4 (1)
- WordPress credential theft (1)
- workerd (1)
- workflow backdoor (1)
- workflow injection (1)
- workflow orchestration (1)
- workflow-abuse (1)
- working-directory hijacking (1)
- workspace trust (3)
- World Cup (1)
- worm (17)
- worm-like propagation (1)
- WP Maps Pro (1)
- WP Squared (1)
- WP-SHELLSTORM (1)
- wp2shell (1)
- WPMU DEV Dashboard (1)
- write-what-where (1)
- WScript (1)
- WSS (1)
- X-Grafana-URL (1)
- X-Secret (1)
- X-WEBAUTH-USER (1)
- X25519 (1)
- X3D MINER (1)
- X_TRADER (1)
- xAI (1)
- XChaCha20 (2)
- XChaCha20-Poly1305 (1)
- Xcode (2)
- XCSSET (2)
- XCSSET v40 (2)
- Xecurify (1)
- XenoRAT (2)
- XFRM (1)
- Xiaomi Redmi A5 (1)
- xinference (1)
- xlabs_v1 (1)
- XML-RPC brute force (1)
- XMLDecoder (1)
- XMRig (9)
- XOR (3)
- XOR obfuscation (1)
- xorshift32 (1)
- XPIA (1)
- Xray (1)
- XSLT SSRF (1)
- XSS (4)
- XSS injection (1)
- XSS.is (1)
- XWorm (1)
- XXE (1)
- xz (2)
- Yahoo Mail (1)
- Yanbian (1)
- YARA (3)
- Yasmarang (1)
- YesWeHack (1)
- Yinhu (1)
- YouTube (2)
- YouTube abuse (1)
- ysoserial (1)
- Yuechi Shared Technology (1)
- yuze (2)
- Yx Technology (1)
- ZAPiXDESK (1)
- ZBT (1)
- Zbtlink (2)
- ZCS (1)
- Zendesk (1)
- Zephyr RTOS (1)
- Zero Trust (1)
- zero-balance (1)
- zero-click (2)
- zero-day (12)
- zero-day exploitation (1)
- zero-reputation infrastructure (1)
- zero-width (1)
- ZeroBEC (1)
- Zerologon (1)
- Zimbra (5)
- Zimbra Collaboration Suite (2)
- Zimperium (2)
- ZimReaper (1)
- ZIP import (1)
- zLabs (2)
- zlib (1)
- Zoho Assist (2)
- Zoho WorkDrive (2)
- ZOHOMURK (2)
- Zoom (1)
- ZoomEye (1)
- Zscaler ThreatLabz (1)
.NET
- Braintree.Net NuGet payment skimmer
- FDMTP
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Sicoob.Sdk NuGet banking certificate stealer
- SilkParasite
- STOCKSTAY
- TinyRCT
- Umbrij
.NET deserialization
.NET downloaders
.NET malware
- Avalon / CrownX malware framework
- Cavern
- Cavern Manticore
- HOLLOWGRAPH
- Silent Swap Google Notes crypto clipper
- ToddyCat Umbrij Gmail OAuth operation
- Turla STOCKSTAY backdoor operations
.NET reflection
.pth
.vu TLD
/accessv2
/api/session/reset_password
/dev/kvm
/proc/1/environ
0-day
0.14.3
0x50594d
146.70.139.154
158.220.87.79
192.42.116.105
192.42.116.58
1H 2026 State of Exploitation
2FA bypass
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
2FA harvesting
2FA recovery codes
3CX
404 TDS
43.228.157.68
4sync
@gl_introduced
@marketfront
@tqm-mfe
.bin
<all_urls>
AA26-231A
AA26-237A
AAA virtual server
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
Ababil of Minab
ABRT
abuse response
academia
academic research
academic sector
- Brazilian education LockBit, DragonForce, and insider incidents
- UNK_MassTraction Roundcube university mailserver campaign
Accellion
access as a service
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
access broker
access brokers
access control
access control bypass
access keys
access optionality
access token abuse
access token theft
Accessibility Service
account abuse
account hijacking
account lockout
account takeover
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- O-UNC-066 Entra passkey vishing
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- Russian intelligence commercial-messaging backup-key phishing
- Synced passkey theft after endpoint compromise
account-takeover
ACR Stealer
AcridRain
Acronis
Acronis TRU
act_pedit
ACTINIUM
Activator.CreateInstance
Active Directory
- Cavern
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
active exploitation
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- C0XMO Gafgyt DD-WRT botnet
- Check Point VPN CVE-2026-50751 exploitation
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- CL-STA-1114 Zimbra webmail espionage
- COLDCARD predictable-RNG Bitcoin theft risk
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Fastjson CVE-2026-16723 active exploitation
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- Gitea Docker CVE-2026-20896 probing
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- Gravity SMTP CVE-2026-4020 exploitation
- Ill Bloom CryptoJS wallet-drain campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Metabase unauthenticated SQL-injection zero-day
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- MiniPlasma Windows Cloud Filter LPE exploitation
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- PraisonAI CVE-2026-44338 rapid exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
- Windmill CVE-2026-29059 active exploitation
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
active probing
active threat
- OkoBot cryptocurrency-wallet malware framework
- Progress ShareFile Storage Zone Controller security threat
- Water-sector PLC configuration-tampering campaign
active-exploitation
ActiveCampaign
actively-exploited
ActiveX
activism
actor
actors
- Armored Likho
- Cavern Manticore
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
- Fox Tempest
- JINX-0163 / FulcrumSec
- JINX-0164
- Mustang Panda
- OP-512
- TA4922
- ToddyCat
- UAT-10147
- UAT-11795
- Webworm
ad blocker
AD CS
ad fraud
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet via TWCore updaters
- StegoAd Edge extension steganography campaign
adaptive identity management
adaptive identity phishing
Adaptix C2
AdaptixC2
ADB TCP/5555
Adblock for YouTube
add/add collision
addon domain
Adform
ADFS
Admin API key theft
admin takeover
administrator account creation
Adobe ColdFusion
Adobe Commerce
ADP vs vendor CVSS divergence
ADS
Adspect
Advanced IP Scanner
advanced persistent threat
Advanced Protection
Adversa
Adversa AI
adversary-in-the-middle
- AI-brand impersonation phishing and malvertising
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
advertising technology
adware
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Chrome live-wallpaper extension ad-fraud network
- Fake Corepack site infostealer and proxyware campaign
- ModHeader browser-extension surveillance capability
- Operation FlutterBridge FlutterShell macOS malvertising
- TamperedChef-style productivity malware clusters
adware history
aerospace
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- TA488 OWAReaper and CVE-2026-42897 exploitation
AES encrypted payload
AES-128-CBC
AES-256-CTR
AES-256-GCM
AES-CTR
AES-GCM
- CrashStealer macOS notarized-dropper campaign
- macOS.Gaslight Rust backdoor
- ModHeader browser-extension surveillance capability
AES-GCM C2
Aeternum
AFD.sys
affiliate hijacking
Afghan telecom
Afghanistan
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
AFP
Africa
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
agent containment
agent frameworks
- Agent localhost control-plane RCE
- MCP stdio command-execution boundary
- PraisonAI CVE-2026-44338 rapid exploitation
agent hooks
agent logs
agent memory
agent monitoring
agent platforms
agent polling protocol
agent skills
agent state
agent-to-agent
AgentBaiting
agentic AI
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Patriot Bait AI-assisted C2 botnet
- SHADOW-AETHER AI-augmented Latin America intrusions
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
agentic botnets
agentic browser
agentic browsers
agentic evaluation
agentic execution
agentic IDE
agentic malware
agentic pipeline
agentic ransomware
agentic threat actor
Agentjacking
AGENTPSD
AgentWorm
agetty
AI
- AI token-jacking transfer-station abuse
- AI-augmented adversary operations
- GREYVIBE
- Patriot Bait AI-assisted C2 botnet
- Vertex AI staging-bucket squatting
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
- Xinference PyPI compromise
AI agent
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JADEPUFFER Langflow agentic ransomware
AI agent security
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Benchmaxxing: when a benchmark becomes the target
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
AI agent tooling
AI agents
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- AI browser-extension confused deputy
- AI-agent memory poisoning
- Amazon Q CVE-2026-12957 MCP auto-execution
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- GuardFall AI-agent shell-guard bypass
- Internet-exposed unauthenticated MCP servers
- Langflow CVE-2025-34291 exploitation
- LangGraph checkpointer and namespace trust boundaries
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NATS-as-C2 KeyHunter credential-harvesting operation
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
- Phantom squatting: AI-hallucinated domains
- PraisonAI CVE-2026-44338 rapid exploitation
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Sentry MCP Agentjacking
- Unit 42 NOVA: frontier-AI autonomous zero-day discovery collapses the patch window
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
AI anti-analysis
AI application infrastructure
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- Hugging Face autonomous-agent production intrusion
- Internet-exposed unauthenticated MCP servers
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- ServiceNow AI Platform CVE-2026-6875 exploitation
AI assistant credentials
AI assistants
- binding.gyp npm CI/CD worm
- Claude Code GitHub Action prompt-injection boundary
- Developer-tool config auto-execution
- Immobiliare Labs Backstage plugins npm compromise
AI benchmarks
AI brand impersonation
- AI-brand impersonation phishing and malvertising
- Perplexity AI-spoofing Chromium extension search hijacker
AI browsers
AI chatbot abuse
AI coding agents
- Azure DevOps MCP pull-request prompt injection
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- Coding-agent-parented tunnels and persistence
AI credential theft
AI data exfiltration
AI developer tooling
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- Cursor Windows workspace-path binary hijack
- jscrambler npm preinstall stealer
AI framework
AI gateway
AI IDE
AI infrastructure
- ENCFORGE
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
AI infrastructure hijacking
AI memory poisoning
AI model encryption
AI model evaluation
AI Now Institute
AI pentesting
AI search poisoning
AI security
- AI scanner anti-analysis
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
AI services
AI supply chain
AI tooling
- @withgoogle/stitch-sdk scope squat
- Amazon Q CVE-2026-12957 MCP auto-execution
- AsyncAPI generator / specs Miasma compromise
- codexui-android OpenAI token stealer
- JetBrains AI plugin API-key theft
- LangGraph checkpointer and namespace trust boundaries
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Malware-Slop Claude user-data npm infostealer
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- Ollama P2P cryptominer RAT campaign
- Phantom squatting: AI-hallucinated domains
- Polymarket npm wallet-drainer packages
- PraisonAI CVE-2026-44338 rapid exploitation
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- TrapDoor crypto-stealer cross-ecosystem campaign
AI tools
AI trust boundary
AI vishing
AI vulnerability consumption
AI vulnerability discovery
AI website builder
AI workflow
ai-abuse
ai-agent
AI-assisted
AI-assisted C2
AI-assisted development
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
- SilkParasite
AI-assisted exploit
AI-assisted intrusion
AI-assisted malware
- Avalon / CrownX malware framework
- Evilginx and device-code phishing open-directory cluster
- Patriot Bait AI-assisted C2 botnet
AI-assisted malware development
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- TuxBot v3 Evolution IoT botnet framework
- Ulej / Flowerbed
AI-assisted phishing
AI-assisted vulnerability discovery
AI-augmented operations
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Hugging Face autonomous-agent production intrusion
- SHADOW-AETHER AI-augmented Latin America intrusions
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
AI-enabled malware
AI-enhanced malware
AI-generated advisory
AI-generated exploit
AI-generated finding
AI-generated malware
AI-generated narrator
Aider
Aikido
- Gogs CVE-2026-52813 path-traversal RCE (and CVE-2026-52810 push bypass, GHSA-6vxv-wg6j-5qwp XSS)
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
AISURU
AiTM
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- UNC6671 / BlackFile multi-brand vishing extortion operation
AitM
Ajax.NET Professional
AjaxPro
Albania
alert fatigue
algorithm confusion
Alibaba
Alibaba OSS
Allen-Bradley
allowed_classes
Alternate Data Stream
Amadey
Amatera Stealer
Amazon Kiro
Amazon Q Developer
Amazon S3
Amazon SES
Amcache
AMOS
- @copilot-mcp/apex macOS infostealer campaign
- macOS ClickFix fingerprinting-gate campaign
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
AMSI bypass
- ClickFix CPaaS API-driven payload delivery
- Flooding Dropper npm campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- TELEPUZ
- Vidar / XMRig Factory-v3 malvertising campaign
AMSI patch
AmsiScanBuffer
Ancillary Function Driver
Android
- Android Framework CVE-2025-48595 exploitation
- codexui-android OpenAI token stealer
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Kimwolf v7
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- NetNut / Popa residential proxy network disruption
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
- ScarCruft Yanbian game-platform supply-chain attack
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Android Accessibility Service
Android ADB
Android automotive
Android Debug Bridge
Android kernel
Android malware
- Flying Eagle and Night Dragon Android RAT ecosystem
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
Android RAT
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- Flying Eagle and Night Dragon Android RAT ecosystem
Android spyware
Android TV
Anthropic
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- AI browser-extension confused deputy
- Anthropic cyber-evaluation real-world intrusions
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
anthropickit
anti-analysis
- AI scanner anti-analysis
- CrashStealer macOS notarized-dropper campaign
- Flooding Dropper npm campaign
- jscrambler npm preinstall stealer
- macOS ClickFix fingerprinting-gate campaign
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- TELESHIM
- TELESHIM Middle East government espionage campaign
anti-bot
anti-distillation
anti-forensics
anti-sandbox
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
Anubis ransomware
ANY.RUN
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
AnyDesk
- Brazilian education LockBit, DragonForce, and insider incidents
- GodDamn ransomware PoisonX BYOVD activity
AOL Mail
Aone
Apache Tomcat
Apache Zeppelin
APC EarlyBird
Apex One
API abuse
API enumeration
API exposure
API key exposure
API key theft
API keys
API-driven payloads
apintergrationpost
app-bound encryption
App-Bound Encryption bypass
AppDomainManager
AppDomainManager injection
Apple
Apple Sign-In
Apple threat notification
AppleJeus
AppleScript
AppleSeed
appliance
application database
application delivery controller
application token
AppRemover
APSB26-68
APT
- Armored Likho
- Armored Likho BusySnake campaign
- Cloud Atlas
- Gamaredon
- Ghostwriter
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- HelloNet ViPNet update-system campaign
- Screening Serpens
- ToddyCat
APT simulation
APT-C-08
APT27
APT28
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- APT28-linked HOOKEDGE backdoor targets European government and diplomatic organizations
APT29
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- ROADtools
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
APT32
APT36
- Operation XENOFISCAL SideCopy XenoRAT campaign
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- SideCopy
APT37
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- ScarCruft Yanbian game-platform supply-chain attack
APT42
APT43
APT44
APT45
Aptos
Aquatic Panda
AquilaRAT
arbitrary code execution
arbitrary file deletion
arbitrary file disclosure
arbitrary file read
- Adobe ColdFusion APSB26-68 CVE bonanza
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- Windmill CVE-2026-29059 active exploitation
arbitrary file upload
- Joomla extension KEV exploitation cluster
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
arbitrary file write
- Adobe ColdFusion APSB26-68 CVE bonanza
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
arbitrary JavaScript
arbitrary SQL execution
ArcBridge
Arch Linux
Arctic Wolf
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
ardrv.sys
ArduPilot
Argo CD
- Argo CD repo-server unauthenticated RCE
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
ArgoCD
argocd-mcp
Arista
Arista EOS
ARL
Armageddon
ArmCorp
Armored Likho
- Armored Likho
- Armored Likho BusySnake campaign
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- BusySnake Stealer
arrayref
arrest
Artem Dinaburg
Artifact Signing
Artifactory
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
arXiv
AryStinger
AS32167
ASA
ASCII smuggling
ASHX
Asia targeting
ASLR bypass
ASNs
ASP.NET
ASP.NET machineKey
ASPX web shells
assume-breach
Astra
Astro
ASUS AiCloud routers
ASUS router
AsyncAPI
AsyncRAT
- Operation Muck and Load GitHub lure network
- Pakistani law enforcement espionage convergence
- ScreenConnect freeware / AsyncRAT SEO campaign
atd
Atlas RAT
Atlassian
Atomic Stealer
attack-rate
attribution
audio surveillance
AUDIOFIX
audit logging
audit telemetry
auditd disabling
AUR
Aura
Australia
authenticated RCE
authenticated remote code execution
authentication bypass
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Gitea Docker CVE-2026-20896 probing
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- Ivanti Sentry CVE-2026-10520 exploitation
- Metabase unauthenticated SQL-injection zero-day
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Oracle E-Business Suite CVE-2026-46817 exploitation
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- PraisonAI CVE-2026-44338 rapid exploitation
- Progress ShareFile Storage Zone Controller security threat
- ServiceNow AI Platform CVE-2026-6875 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
authentication coercion
authentication laundering
authentication stack
authentication-coercion
Authenticode impersonation
authorization
authorization bypass
auto-execution
AUTODYN
AutoGen Studio
AutoHotKey
AutoJack
automotive
automotive sector
autonomous agents
- Anthropic cyber-evaluation real-world intrusions
- Hugging Face autonomous-agent production intrusion
- Phantom squatting: AI-hallucinated domains
autonomous AI
autonomous attack
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
autonomous attacks
autonomous exploitation
autonomous scanning
autonomous vulnerability discovery
autorun=1
AV killer
Avada
Avalon
aviation
AVIF
AWS
- @copilot-mcp/apex macOS infostealer campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- CircleCI 2023 customer secret exposure incident
- JINX-0163 / FulcrumSec
- MrMustard PyPI credential-stealer compromise
- NATS-as-C2 KeyHunter credential-harvesting operation
- vpmdhaj OpenSearch npm cloud-secret stealer
AWS CloudTrail
AWS S3
AWS Secrets Manager
axios
Azure
Azure Active Directory
Azure CLI
Azure Cosmos DB
Azure DevOps
Azure Storage
Babuk
back-end
Backblaze
backdoor
- BINDCLOAK
- DAEMON Tools Lite supply-chain compromise
- FDMTP
- GigaWiper
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- macOS.Gaslight Rust backdoor
- MODBEACON
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- NightLedger
- OctLurk
- Ollama P2P cryptominer RAT campaign
- Operation FlutterBridge FlutterShell macOS malvertising
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- PostGREShell: PostgreSQL 12-year-old logical-decoding flaw turns a REPLICATION account into server code execution — CVE-2026-6471
- QuickFox FDMTP software supply-chain compromise
- shopsprint/decimal Go typosquat DNS backdoor
- Showboat
- SilkLurk
- SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- SprySOCKS
- STOCKSTAY
- TELESHIM
- Telnyx PyPI TeamPCP compromise
- TinyRCT
Backdoor.Mistic
Backdoor.Turn
Backstage
backup disruption
backup recovery keys
backup targeting
backups
Bad Epoll
BadBlocker
BADBOX
Badbox 2.0
BadIIS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
BadPotato
Baileys
balance-overflow
Balbooa Forms
Balochistan Police
Balonx
Balonx Sistema
Banana RAT
Banco de Infects
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
bandcampro
Bandook
banking
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Sicoob.Sdk NuGet banking certificate stealer
banking fraud
banking malware
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
banking trojan
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
Baron Samedit
Barracuda
Base64
BaseZipInstaller
Bash Uploader
batch loader
batch script
Bayesian scoring
BCS
BCSAllowedTypeNames
BCU key
BDC
BDCM
Bearlyfy
Beast ransomware
BeaverTail
Bedrock
behavioral detection
- State of AI-enabled malware, August 2026 (Unit 42)
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
behavioral integrity verification
Behinder
Belarus
BELQI
benchmark integrity
Berlin
better-auth
Bexo Wallet
BeyondTrust
bin entry
Binance Smart Chain
binary execution
binary squatting
BinaryFormatter
BINDCLOAK
binding.gyp
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- binding.gyp npm CI/CD worm
- Immobiliare Labs Backstage plugins npm compromise
biometric records
BIOPASS RAT
BioShocking
BIP-39
BirdCall
Bitbucket
Bitcoin
- Adform Trackpoint JavaScript supply-chain crypto clipper
- COLDCARD predictable-RNG Bitcoin theft risk
- Ill Bloom CryptoJS wallet-drain campaign
- Kairos data-extortion government payment
Bitcoin Libre
BitMiner
bitsadmin
Bitter
Bitwarden
BKA
Black Hat USA 2026
BlackFile
Blackpoint Cyber
- Avalon / CrownX malware framework
- CrownX
- Djinn Stealer
- LabubaRAT
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- TaskWeaver
Bleacher Report
blind prompt injection
blockchain
- Cosmos EVM vesting-account balance overflow exploited across six chains (GHSA-7g4w-cg88-2cq2, Aug 20–25, 2026)
- State divergence enables unauthorized access: Provenance marker module anyone-can-pass check
blockchain C2
- Aeternum
- Astro config blockchain C2 PR injection
- DeadLock ransomware
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Joyfill npm blockchain-RAT compromise
- Kimwolf v7
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
- ViteVenom / ChainVeil npm campaign
blockchain dead drop
- ACR Stealer
- Dysphoria IoT botnet
- FakeGit AgentBaiting and SmartLoader campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
- Silent Swap Google Notes crypto clipper
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
blockchain RPC
blockchain-dead-drop
Blogger abuse
blogspot staging
BLOODALCHEMY
BLUEBEAM
BlueDelta
bluemonday
Blueprints
Bluetooth LE
Boatnet
BOD 26-04
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
body hash
BOF
BookStack
Boot Bus Extender
Boot Time Removal Tool
botnet
- Aeternum
- C0XMO Gafgyt DD-WRT botnet
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- Glassworm developer supply-chain botnet
- JDY SOHO / IoT reconnaissance botnet
- Kimwolf v7
- Lucide Proxy npm browser DDoS botnet
- NadMesh AI-service and cloud-credential botnet
- NetNut / Popa residential proxy network disruption
- Patriot Bait AI-assisted C2 botnet
- RustDuck
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
botnet framework
BPFDoor
Braintree
branch-compromise
branch-name-injection
brand impersonation
- DCloud Uni-App scam infrastructure ecosystem
- Fake Corepack site infostealer and proxyware campaign
- GHOST STADIUM FIFA World Cup ticket phishing
- State of AI-enabled malware, August 2026 (Unit 42)
brand-impersonation
BraZetsu
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
Brazil
- Armored Likho
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Brazilian education LockBit, DragonForce, and insider incidents
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- SHADOW-AETHER AI-augmented Latin America intrusions
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
Brazilian banking malware
BreachForums
Breeze Cache Cleaner
Brian Fox
BRICKSTORM
BridgeHead
Broadcom
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- GodDamn ransomware PoisonX BYOVD activity
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
browser assembly
browser automation
browser cookie theft
browser credential theft
- @copilot-mcp/apex macOS infostealer campaign
- ACR Stealer
- Armored Likho BusySnake campaign
- Avalon / CrownX malware framework
- BusySnake Stealer
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- GREYVIBE
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- macOS.Gaslight Rust backdoor
- PamStealer
- Seedworm / MuddyWater
- Silent Swap Google Notes crypto clipper
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0226 / SHADOW-EARTH-066
- Vidar / XMRig Factory-v3 malvertising campaign
- Void Dokkaebi
- VPN Go browser-extension clipboard stealer
browser data theft
- Fake Corepack site infostealer and proxyware campaign
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
browser extension
- Adblock for YouTube BadBlocker remote-script injection risk
- AI browser-extension confused deputy
- Forg365 Microsoft 365 PhaaS
- ModHeader browser-extension surveillance capability
- Perplexity AI-spoofing Chromium extension search hijacker
- Silent Swap Google Notes crypto clipper
- StegoAd Edge extension steganography campaign
- UNC6692 SNOW malware social-engineering campaign
- VPN Go browser-extension clipboard stealer
browser extension loader
browser extension malware
browser extension sideloading
browser fingerprint spoofing
browser fingerprinting
browser hijacking
- Operation FlutterBridge FlutterShell macOS malvertising
- Perplexity AI-spoofing Chromium extension search hijacker
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
browser malware
browser memory
browser security
- Adform Trackpoint JavaScript supply-chain crypto clipper
- AI browser-extension confused deputy
- ModHeader browser-extension surveillance capability
browser session abuse
browser session hijacking
browser session risk
- Adblock for YouTube BadBlocker remote-script injection risk
- Perplexity AI-spoofing Chromium extension search hijacker
- VPN Go browser-extension clipboard stealer
browser zero-day
browser-based attack
browser-credential-theft
browser-extensions
browser-resident malware
browser-security
browser-session risk
browsing history
brute-force credentials
BSC
BTMOB
BTR Reforged
BTR.sys
BTR_CLI
bucket hijacking
bucket squatting
buffer overflow
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
bug bounty
Bugcrowd
build pipeline
build server
build-time compromise
build-time execution
build.rs
building automation
builtin wildcard
bulletproof hosting
Bun
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- actions-cool GitHub Actions tag compromise
- ChainDrop keyv / cacheable npm worm
- codfish semantic-release-action tag compromise
- SourTrade browser-assembled malware malvertising
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
Bun runtime abuse
Burkina Faso
business email compromise
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Microsoft Q2 2026 email and Teams phishing landscape
business intelligence
BusinessDataCatalog
BusySnake Stealer
Bybit
BYOVD
- GodDamn ransomware PoisonX BYOVD activity
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- Storm-2603 parallel SharePoint ransomware intrusion
- The Gentlemen ransomware
BYOVD alternative
bypass2fa
bytecode
C backdoor
C
C++
C++/CLI
C0XMO
C2
- BINDCLOAK
- DAEMON Tools Lite supply-chain compromise
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet via TWCore updaters
- Glassworm developer supply-chain botnet
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Malicious infrastructure provider concentration
- NATS-as-C2 KeyHunter credential-harvesting operation
- Oman government Iranian-nexus webshell C2
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- Patriot Bait AI-assisted C2 botnet
- Quest KACE SMA CVE-2025-32975 exploitation
- QuimaRAT
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- RemotePE
- Showboat
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- WLDR agent
C2 fallback
C2 framework
C2 panel
C2 tasking
C2Looper
CageFS
Caixa Entradas
calendar dead drop
calendar invitation
Calendly abuse
call forwarding
callback URL
CallFlow
Cambodia
- Operation Phnom Penh MODBEACON activity
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
campaign
- CL-STA-1114 Zimbra webmail espionage
- Gunra ransomware-as-a-service activity
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Toy Ghouls GenieLocker ransomware activity
- UNK_MassTraction Roundcube university mailserver campaign
Canada
canary
CANFAIL
CanisterWorm
canonicalization
CAP_NET_ADMIN
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
CAPTCHA OCR
captive portal
CaptiveCrunch
capture the flag
cargo
Casbaneiro
CastleStealer
Catalyst SD-WAN Manager
Catcher
Cav3rn
Cavern
Cavern Manticore
CCleaner
CCTV
CDN
CDN abuse
cdn.jsdelivr.net
CDP
Cellebrite
cellular modem
census
Censys
Censys ARC
Central Asia
CERT Polska
CERT-In
CERT/CC
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
Certbot
certificate pinning
certificate template
certificate theft
Certighost
certutil
CFIDE
ChaCha20
chain-of-thought
ChainDrop
- ChainDrop keyv / cacheable npm worm
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
chainlit
ChainVeil
Chaos ransomware
Chaotic Eclipse
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
charging
Charming Kitten
chat-template poisoning
ChatGPT
chattr
Chatty Spider
CHAVECLOAK
Check Point
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
Check Point Research
- BTR Reforged: weaponizing Microsoft Defender's BTR.sys remediation driver as a kernel primitive
- LangGraph checkpointer and namespace trust boundaries
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
Checkmarx
Checkmarx KICS
checkpointers
China
China nexus
China-linked
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- FishMonger
- GHOST STADIUM FIFA World Cup ticket phishing
- OP-512
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- SprySOCKS
China-nexus
- FDMTP
- JDY SOHO / IoT reconnaissance botnet
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Pakistani law enforcement espionage convergence
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- QuickFox FDMTP software supply-chain compromise
- SilkParasite
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UAT-7810 LONGLEASH ORB network expansion
- UNC6508
- UNK_MassTraction Roundcube university mailserver campaign
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
China-speaking ecosystem
Chinese-language cybercrime
- Chinese-language PhaaS wallet-tokenization ecosystem
- Flying Eagle and Night Dragon Android RAT ecosystem
Chinese-language fraud ecosystem
Chinese-speaking
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GHOST STADIUM FIFA World Cup ticket phishing
- HelloNet ViPNet update-system campaign
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- OctLurk and SilkLurk Central Asia espionage campaign
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
Chinese-speaking cybercrime
Chinese-speaking operator
Chisel
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Oman government Iranian-nexus webshell C2
- PCPJack cloud SMTP relay network
- SHADOW-AETHER AI-augmented Latin America intrusions
ChocoPoC
ChocoShell
ChromaDB
Chrome
Chrome App-Bound Encryption
Chrome DevTools Protocol
Chrome extension
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- ModHeader browser-extension surveillance capability
- PolinRider cross-ecosystem supply-chain campaign
Chrome renderer sandbox
Chrome Web Store
- Adblock for YouTube BadBlocker remote-script injection risk
- Chrome live-wallpaper extension ad-fraud network
- ModHeader browser-extension surveillance capability
- Perplexity AI-spoofing Chromium extension search hijacker
- VPN Go browser-extension clipboard stealer
chrome_settings_overrides
ChromElevator
Chromium
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- Perplexity AI-spoofing Chromium extension search hijacker
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
Chromium extension
chunked exfiltration
CI secrets
CI-CD
- Atomic Arch AUR package hijack
- Dependabot cross-ecosystem malware advisory alerts
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- npm install explicit-trust controls
CI/CD
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @marketfront / @tqm-mfe dependency-confusion stealer
- actions-cool GitHub Actions tag compromise
- Argo CD repo-server unauthenticated RCE
- Astro config blockchain C2 PR injection
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChainDrop keyv / cacheable npm worm
- CircleCI 2023 customer secret exposure incident
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- codfish semantic-release-action tag compromise
- Crypto supply-chain path to transaction authority
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- GuardFall AI-agent shell-guard bypass
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Immobiliare Labs Backstage plugins npm compromise
- JetBrains TeamCity CVE-2026-63077 active exploitation
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Laravel-Lang Composer tag-rewrite compromise
- Leo Platform npm Miasma-style compromise
- LiteLLM compromise
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- npm publish-time malware scanning and dual-use declarations
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation DangerousPassword axios npm compromise
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- SANDWORM_MODE AI-toolchain npm worm
- simonecorsi/mawesome GitHub Action compromise
- TeamPCP
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- Telnyx PyPI TeamPCP compromise
- tj-actions and reviewdog compromise
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- vpmdhaj OpenSearch npm cloud-secret stealer
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
CI/CD abuse
CI/CD credential theft
CI/CD pipeline abuse
CircleCI
CIS
CISA
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- FortiBleed Fortinet credential exposure
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- Gunra ransomware-as-a-service activity
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
CISA ADP
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
CISA KEV
- Android Framework CVE-2025-48595 exploitation
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- C0XMO Gafgyt DD-WRT botnet
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- Ivanti Sentry CVE-2026-10520 exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Trend Micro Apex One CVE-2026-34926 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
Cisco
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on 10 Silicon One-based switches — plus a 7-CVE IOS XR hardening release
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
Cisco IOS
Cisco IOS 12.4
Cisco Nexus
Cisco Talos
Cisco Unified CM
Cisco Unified Communications Manager
Citizen Lab
citizen portal compromise
Citrine Sleet
Citrix
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- CitrixBleed session-hijack wave
Citrix NetScaler
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- knaithe Hermes/DeepSeek autonomous exploitation campaign
CitrixBleed
CitrixBleed 2
City Forum
CKEditor file manager
CL-CRI-1089
CL-CRI-1131
CL-CRI-1147
CL-CRI-1163
CL-STA-1062
CL-STA-1114
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
Clash proxy
Claude
- AI-brand impersonation phishing and malvertising
- Anthropic cyber-evaluation real-world intrusions
- Malware-Slop Claude user-data npm infostealer
Claude Code
- @withgoogle/stitch-sdk scope squat
- Azure DevOps MCP pull-request prompt injection
- Claude Code GitHub Action prompt-injection boundary
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- Coding-agent-parented tunnels and persistence
- GuardFall AI-agent shell-guard bypass
- Sentry MCP Agentjacking
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Claude for Chrome
Claude Mythos 5
Claude Opus 4.7
Clawdbot
ClawWorm
ClearFake
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
cleartext credentials
Clever Cloud
click interception
clicker
ClickFake
ClickFix
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- ACR Stealer
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Backdoor.Mistic / KongTuke ModeloRAT activity
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- ClickFix CPaaS API-driven payload delivery
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Exposed WebDAV malware delivery lab and CURP campaign
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GREYVIBE
- JINX-0164 crypto developer infrastructure campaign
- macOS ClickFix fingerprinting-gate campaign
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- Starland RAT
- StealC / Amadey infrastructure disruption
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795
- UAT-11795 Starland / WLDR campaign
ClickFix social engineering
ClickOnce
ClickUp
client installer poisoning
client-side exploitation
Cline
clipboard hijacker
clipboard hijacking
clipboard injection
clipboard manipulation
clipboard stealer
clipboard theft
- BusySnake Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto Clipper Tor / USB worm
- PamStealer
- Silent Swap Google Notes crypto clipper
- VPN Go browser-extension clipboard stealer
clipjacking
clipper
Cloaked Ursa
- Microsoft Teams external-chat phishing
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
cloaking
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- macOS ClickFix fingerprinting-gate campaign
- SourTrade browser-assembled malware malvertising
ClOd-ViEw
cloud
- APT29
- JINX-0163 / FulcrumSec
- PCPJack cloud SMTP relay network
- ROADtools
- Vertex AI staging-bucket squatting
- Webworm
- Xinference PyPI compromise
cloud C2
cloud compromise
cloud credential hunting
cloud credential risk
cloud credential theft
- AI-augmented adversary operations
- Djinn Stealer
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Hugging Face autonomous-agent production intrusion
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
cloud credentials
- Amazon Q CVE-2026-12957 MCP auto-execution
- Internet-exposed unauthenticated MCP servers
- jscrambler npm preinstall stealer
- wshu.net npm credential-stealer campaign
cloud exploitation
Cloud Files Mini Filter Driver
Cloud Filter driver
Cloud Foundation
cloud IAM
cloud identity
cloud identity abuse
cloud infrastructure
cloud keys exfiltration
cloud logging
cloud metadata
cloud metadata service
cloud secrets
- @marketfront / @tqm-mfe dependency-confusion stealer
- JINX-0164 crypto developer infrastructure campaign
- oob.moika.tech dependency-confusion environment stealer
- vpmdhaj OpenSearch npm cloud-secret stealer
cloud security
- Cloud bucket namespace hijacking
- Cloud logging control-plane tampering
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- PraisonAI CVE-2026-44338 rapid exploitation
cloud service abuse
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Stock exchange executive mailbox espionage
cloud storage
cloud storage exfiltration
cloud transcoding
Cloudflare
- Forg365 Microsoft 365 PhaaS
- GHOST STADIUM FIFA World Cup ticket phishing
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Okta support-system compromise
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
Cloudflare gate
Cloudflare R2
Cloudflare Tunnel
- Coding-agent-parented tunnels and persistence
- Evilginx and device-code phishing open-directory cluster
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Storm-2603 parallel SharePoint ransomware intrusion
Cloudflare tunnels
Cloudflare Turnstile
Cloudflare Workers
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- Polymarket npm wallet-drainer packages
- StegoAd Edge extension steganography campaign
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
cloudflared
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
CloudLinux
CloudSEK
cluster compromise
CMS
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Gravity SMTP CVE-2026-4020 exploitation
- Joomla JCE CVE-2026-48907 exploitation
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
CMS exploitation
CNAB
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
CNABHunter
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
CNCERT
Cobalt Strike
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - FishMonger
- Ghostwriter
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Malicious infrastructure provider concentration
- Pakistani law enforcement espionage convergence
- StrikeShark SharkLoader / Cobalt Strike campaign
code execution
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
code generation
code injection
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
Code Mode
code sandbox scraping
code signing
- AI-brand impersonation phishing and malvertising
- Fox Tempest
- TamperedChef-style productivity malware clusters
code signing abuse
Codecov
codegen injection
codemado
CodeQL
Codex
Codex CLI
coding agents
coding challenge
Coinbase
Coinkite
COLDCARD
ColdFusion
collaboration platforms
collaboration-tool phishing
COM-hijacking
ComfyUI
command and control
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- Direct-to-IP malware communications
- ENDLESSDOORS implant in Zbtlink router firmware
- Malicious infrastructure provider concentration
- Patriot Bait AI-assisted C2 botnet
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
command execution
- Agent localhost control-plane RCE
- Alibaba developer-targeted distributed npm RAT campaign
- Argo CD repo-server unauthenticated RCE
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Fake Corepack site infostealer and proxyware campaign
- GuardFall AI-agent shell-guard bypass
- Internet-exposed unauthenticated MCP servers
- MCP stdio command-execution boundary
- Ollama P2P cryptominer RAT campaign
command injection
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019)
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Ivanti Sentry CVE-2026-10520 exploitation
- Lantronix EDS5000 CVE-2025-67038 exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Siemens ROX II zero-day exploit chain
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
command-execution
command-injection
commercial LLM abuse
commercial messaging applications
commit farming
communications infrastructure
Composer
- Famous Chollima Packagist dev-branch loader
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Laravel-Lang Composer tag-rewrite compromise
- PolinRider cross-ecosystem supply-chain campaign
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
compromised accounts
compromised credentials
compromised infrastructure
compromised websites
compromised WordPress
computer name
computer vision
Conditional Access
configuration exposure
configuration tampering
configuration theft
Confluence
confused deputy
- Agent localhost control-plane RCE
- AI browser-extension confused deputy
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
ConfuserEx
conhost
connected apps
ConnectWise
- ConnectWise ScreenConnect exploitation wave
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
ConnectWise advisory
ConnectWise ScreenConnect
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- ScreenConnect freeware / AsyncRAT SEO campaign
construction
consumer devices
consumer IoT
consumer software
Contagious Interview
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
- StegaBin Pastebin-steganography npm campaign
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
container
container escape
- ENCFORGE
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
container escape pre-check
content compliance rules
contentPolicy
context flooding
Continue
continuous visibility
control flow flattening
control panel compromise
control plane
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- ServiceNow instance unauthenticated table-query exploitation
control-flow hijacking
conversation theft
cookie theft
- Armored Likho BusySnake campaign
- BusySnake Stealer
- StegoAd Edge extension steganography campaign
- Vidar / XMRig Factory-v3 malvertising campaign
CookiETagRAT
Copilot
Copilot CLI
Copy-on-Write
copycat
Corepack
CornFlake
CORS
CORS bypass
Cortex XDR
Coruna
- art-template Coruna-style iOS watering-hole compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
cosign
Cosmos
Cosmos EVM
Cosmos SDK
CosmosEscape
CoSnitch
counterfeit software
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Operation Phnom Penh MODBEACON activity
COW
COWARDDUCK
CPaaS
cPanel
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
CPUID
CRA
cracked software
CrackMapExec
CrashFix
CrashStealer
crates.io
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
Crates.io
credential attack
credential attacks
- Kairos data-extortion government payment
- NetNut / Popa residential proxy network disruption
- Patriot Bait AI-assisted C2 botnet
credential cracking
credential dumping
credential exfiltration
credential exposure
- Coding-agent-parented tunnels and persistence
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- FortiBleed Fortinet credential exposure
- Progress ShareFile Storage Zone Controller security threat
- Sentry MCP Agentjacking
credential harvesting
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GodDamn ransomware PoisonX BYOVD activity
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC6508
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
credential interception
credential leakage
credential rotation
credential spraying
credential stealer
credential stuffing
credential theft
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- @copilot-mcp/apex macOS infostealer campaign
- @withgoogle/stitch-sdk scope squat
- Aeternum
- Agent skill marketplace poisoning
- AI token-jacking transfer-station abuse
- AI-brand impersonation phishing and malvertising
- Alibaba developer-targeted distributed npm RAT campaign
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- Amazon Q CVE-2026-12957 MCP auto-execution
- Anthropic cyber-evaluation real-world intrusions
- AsyncAPI generator / specs Miasma compromise
- Avalon / CrownX malware framework
- Braintree.Net NuGet payment skimmer
- Browser-based developer IDE OAuth token theft
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Cursor Windows workspace-path binary hijack
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- FakeGit AgentBaiting and SmartLoader campaign
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- GHOST STADIUM FIFA World Cup ticket phishing
- Injective SDK npm wallet stealer
- JINX-0163 / FulcrumSec
- Joyfill npm blockchain-RAT compromise
- jscrambler npm preinstall stealer
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2025-34291 exploitation
- Lazarus-linked Rollup polyfill npm malware
- LiteLLM compromise
- macOS ClickFix fingerprinting-gate campaign
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- NadMesh AI-service and cloud-credential botnet
- nodemon-sudo / tslint-conf runtime npm backdoor
- NullReceiver DPRK-linked npm blockchain-loader wave
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation Highland Velvet Ant authentication-stack backdoors
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- PCPJack cloud SMTP relay network
- PolinRider cross-ecosystem supply-chain campaign
- QuimaRAT
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- ScreenConnect freeware / AsyncRAT SEO campaign
- Seedworm / MuddyWater
- Solana FakeFix npm / PyPI developer stealer
- Starland RAT
- StealC / Amadey infrastructure disruption
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Synced passkey theft after endpoint compromise
- TA488 OWAReaper and CVE-2026-42897 exploitation
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
- Trusted collaboration-channel identity abuse
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- UAT-11795
- UAT-11795 Starland / WLDR campaign
- Umbrij
- UNC6692 SNOW malware social-engineering campaign
- UNK_MassTraction Roundcube university mailserver campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- ViteVenom / ChainVeil npm campaign
- Webmail CSS trust-boundary attacks
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
credential-theft
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @marketfront / @tqm-mfe dependency-confusion stealer
- actions-cool GitHub Actions tag compromise
- APT29
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChainDrop keyv / cacheable npm worm
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- DAEMON Tools Lite supply-chain compromise
- Developer-tool config auto-execution
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- forge-jsxy
- GitHub / Packagist postinstall hook campaign
- Glassworm developer supply-chain botnet
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hunt.io global smishing infrastructure campaign
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- JetBrains AI plugin API-key theft
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- JWR phishing framework (likely The Outsider variant)
- Kali365 device-code phishing expansion
- Laravel-Lang Composer tag-rewrite compromise
- Leo Platform npm Miasma-style compromise
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- node-ipc 2026 npm maintainer-account compromise
- Nx Console VS Code extension compromise
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Operation GriefLure Southeast Asia LNK dropper
- Outsider Enterprise smishing PhaaS
- postcss-minify-selector-parser npm RAT
- SANDWORM_MODE AI-toolchain npm worm
- Sicoob.Sdk NuGet banking certificate stealer
- simonecorsi/mawesome GitHub Action compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- Storm-2603 parallel SharePoint ransomware intrusion
- TA4922
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
- UNK_DeadDrop developer repository phishing
- vpmdhaj OpenSearch npm cloud-secret stealer
- wshu.net npm credential-stealer campaign
- Xinference PyPI compromise
credit card theft
criminal infrastructure
critical
Critical cyber capability
critical framing
critical infrastructure
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Operation Highland Velvet Ant authentication-stack backdoors
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- Siemens ROX II zero-day exploit chain
- Velvet Ant
- Water-sector PLC configuration-tampering campaign
critical vulnerability
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
critical-infrastructure
CRM data theft
cron
cron persistence
- C0XMO Gafgyt DD-WRT botnet
- Langflow CVE-2026-33017 cryptominer SSH worm
- NadMesh AI-service and cloud-credential botnet
crond
cross-ecosystem
cross-origin requests
cross-platform
- Djinn Stealer
- Flooding Dropper npm campaign
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
cross-platform malware
cross-project access
cross-session
cross-site request forgery
cross-tenant
cross-tenant access
cross-tenant isolation
cross-tenant leakage
Crossplane
crossplane-runtime
Crosswork
Crosswork Data Gateway
Crosswork Network Controller
Crosswork Planning
CrowdStrike
CrowdStrike Counter Adversary Operations
CrowdStrike Falcon
CrownX
Crucio
crypto
crypto clipboard theft
crypto clipper
crypto draining
crypto wallets
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- wshu.net npm credential-stealer campaign
crypto-js
crypto-wallets
cryptocurrency
- Crypto Clipper Tor / USB worm
- Crypto supply-chain path to transaction authority
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Mastra
easy-day-jsnpm scope compromise - Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Polymarket npm wallet-drainer packages
- QuickFox FDMTP software supply-chain compromise
- RemotePE
- SANDWORM_MODE AI-toolchain npm worm
- Solana FakeFix npm / PyPI developer stealer
- SourTrade browser-assembled malware malvertising
- UNK_DeadDrop developer repository phishing
cryptocurrency miner
cryptocurrency mining
cryptocurrency scam
cryptocurrency theft
- @copilot-mcp/apex macOS infostealer campaign
- Adform Trackpoint JavaScript supply-chain crypto clipper
- COLDCARD predictable-RNG Bitcoin theft risk
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake-reputation crypto clipboard hijacker
- Funnull RingH23 and MacCMS supply-chain attacks
- Ill Bloom CryptoJS wallet-drain campaign
- OkoBot cryptocurrency-wallet malware framework
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- Silent Swap Google Notes crypto clipper
- Starland RAT
- UAT-11795
- UAT-11795 Starland / WLDR campaign
- Void Dokkaebi
cryptocurrency wallet theft
- Aeternum
- Avalon / CrownX malware framework
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- jscrambler npm preinstall stealer
- macOS ClickFix fingerprinting-gate campaign
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
- Vidar / XMRig Factory-v3 malvertising campaign
cryptocurrency wallets
- Djinn Stealer
- Lazarus-linked Rollup polyfill npm malware
- OkoBot cryptocurrency-wallet malware framework
- PamStealer
cryptographic context injection
cryptojacking
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
CryptoJS
cryptominer
- Ollama P2P cryptominer RAT campaign
- Pirated media SilentCryptoMiner RAT campaign
- State of AI-enabled malware, August 2026 (Unit 42)
cryptomining
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2026-33017 cryptominer SSH worm
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
CSCwt95997
CSI token theft
CSP stripping
CSRF
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
CSRF token theft
CSS
CSS sanitization
CSSOM
ctfmon.exe
Curious Serpens
CurlRAT
CURP
Cursor
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- Coding-agent-parented tunnels and persistence
- Cursor Windows workspace-path binary hijack
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Sentry MCP Agentjacking
- UNK_DeadDrop developer repository phishing
Curve25519
Curve25519-XSalsa20-Poly1305
custody APIs
custom instruction set
custom map
CVE
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
CVE-2008-4128
CVE-2013-3307
CVE-2015-3246
CVE-2015-5287
CVE-2016-5681
CVE-2019-1068
CVE-2020-17103
CVE-2020-22653
CVE-2020-22658
CVE-2021-23758
CVE-2021-27137
CVE-2021-29441
CVE-2021-33044
CVE-2021-33045
CVE-2022-0492
CVE-2022-0995
CVE-2023-24932
CVE-2023-25717
CVE-2023-2868
CVE-2023-4346
CVE-2023-49105
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
CVE-2023-4966
CVE-2024-1708
CVE-2024-1709
CVE-2024-20399
CVE-2024-21182
CVE-2024-28000
CVE-2024-3094
CVE-2024-37014
CVE-2024-42009
CVE-2025-11371
CVE-2025-11837
CVE-2025-24054
CVE-2025-2492
CVE-2025-3248
- ENCFORGE
- JADEPUFFER Langflow agentic ransomware
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
CVE-2025-32975
CVE-2025-33053
CVE-2025-34291
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2025-34291 exploitation
CVE-2025-40947
CVE-2025-40948
CVE-2025-40949
CVE-2025-48595
CVE-2025-49113
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- UNK_MassTraction Roundcube university mailserver campaign
CVE-2025-49704
CVE-2025-49706
CVE-2025-5777
CVE-2025-62593
CVE-2025-66376
CVE-2025-67038
CVE-2025-68613
CVE-2025-68686
CVE-2025-8088
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
CVE-2026-0257
CVE-2026-0300
CVE-2026-0769
CVE-2026-0770
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2026-0770 exploitation
CVE-2026-10520
CVE-2026-10523
CVE-2026-11405
CVE-2026-11645
CVE-2026-12569
CVE-2026-12957
CVE-2026-12958
CVE-2026-14494
CVE-2026-14894
CVE-2026-15409
CVE-2026-15410
CVE-2026-15583
CVE-2026-15981
CVE-2026-16232
CVE-2026-16723
CVE-2026-16812
CVE-2026-18431
CVE-2026-18556
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
CVE-2026-18577
CVE-2026-18885
CVE-2026-18886
CVE-2026-18963
CVE-2026-19478
CVE-2026-19489
CVE-2026-19490
CVE-2026-19516
CVE-2026-19598
CVE-2026-19632
CVE-2026-19650
CVE-2026-19912
CVE-2026-19913
CVE-2026-20127
CVE-2026-20182
CVE-2026-20212
CVE-2026-20230
CVE-2026-20245
CVE-2026-20253
CVE-2026-20262
CVE-2026-20274
CVE-2026-20279
CVE-2026-20316
CVE-2026-20349
CVE-2026-20896
CVE-2026-21445
CVE-2026-21513
CVE-2026-21858
CVE-2026-21962
CVE-2026-23111
CVE-2026-24301
CVE-2026-25895
CVE-2026-26980
CVE-2026-2699
CVE-2026-2701
CVE-2026-28318
CVE-2026-29059
CVE-2026-3055
CVE-2026-32475
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
CVE-2026-3300
CVE-2026-33017
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2026-33017 cryptominer SSH worm
- NATS-as-C2 KeyHunter credential-harvesting operation
CVE-2026-33497
CVE-2026-33691
CVE-2026-33824
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- knaithe Hermes/DeepSeek autonomous exploitation campaign
CVE-2026-34486
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- knaithe Hermes/DeepSeek autonomous exploitation campaign
CVE-2026-34908
CVE-2026-34909
CVE-2026-34910
CVE-2026-34926
CVE-2026-35273
CVE-2026-35616
CVE-2026-36425
CVE-2026-39987
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Marimo CVE-2026-39987 LLM-agent post-exploitation
CVE-2026-40138
CVE-2026-40139
CVE-2026-40140
CVE-2026-40141
CVE-2026-4020
CVE-2026-41091
CVE-2026-41703
CVE-2026-41709
CVE-2026-41940
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
CVE-2026-42271
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
CVE-2026-42533
CVE-2026-42897
CVE-2026-43074
CVE-2026-43284
CVE-2026-43499
CVE-2026-43500
CVE-2026-43503
CVE-2026-44338
CVE-2026-44613
CVE-2026-45018
CVE-2026-45019
CVE-2026-45247
CVE-2026-45498
CVE-2026-45659
CVE-2026-46242
CVE-2026-46300
CVE-2026-46331
CVE-2026-46817
CVE-2026-47876
CVE-2026-47884
CVE-2026-47890
CVE-2026-47891
CVE-2026-47892
CVE-2026-48172
CVE-2026-48276
CVE-2026-48277
CVE-2026-48281
CVE-2026-48282
CVE-2026-48283
CVE-2026-48285
CVE-2026-48307
CVE-2026-48313
CVE-2026-48314
CVE-2026-48315
CVE-2026-48316
CVE-2026-48558
CVE-2026-48710
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
CVE-2026-48907
CVE-2026-48908
CVE-2026-48939
CVE-2026-49869
CVE-2026-5027
CVE-2026-50522
CVE-2026-50656
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
CVE-2026-50751
CVE-2026-50752
CVE-2026-51296
CVE-2026-51297
CVE-2026-51300
CVE-2026-51302
CVE-2026-51303
CVE-2026-51304
CVE-2026-52810
CVE-2026-52813
CVE-2026-53359
- Januscape KVM CVE-2026-53359 guest-to-host escape
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
CVE-2026-53362
CVE-2026-5426
CVE-2026-54420
CVE-2026-54718
CVE-2026-54720
CVE-2026-54721
CVE-2026-55040
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
CVE-2026-55207
CVE-2026-55208
CVE-2026-55212
CVE-2026-55220
CVE-2026-55255
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2026-55255 flow authorization bypass
CVE-2026-55450
CVE-2026-55634
CVE-2026-56290
CVE-2026-56291
CVE-2026-59283
CVE-2026-59285
CVE-2026-59309
CVE-2026-59310
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
CVE-2026-59313
CVE-2026-59318
CVE-2026-59726
CVE-2026-59822
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
CVE-2026-60004
CVE-2026-60137
CVE-2026-61539
CVE-2026-61979
CVE-2026-62144
CVE-2026-62145
CVE-2026-63030
CVE-2026-63077
CVE-2026-63520
CVE-2026-6471
CVE-2026-64849
CVE-2026-65400
CVE-2026-65640
CVE-2026-65643
CVE-2026-66384
CVE-2026-66747
CVE-2026-6682
CVE-2026-6683
CVE-2026-6684
CVE-2026-6685
CVE-2026-6686
CVE-2026-6687
CVE-2026-6688
CVE-2026-67426
CVE-2026-6875
CVE-2026-6876
CVE-2026-68820
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
CVE-2026-69414
CVE-2026-69836
CVE-2026-72529
CVE-2026-72530
CVE-2026-72898
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- Metabase unauthenticated SQL-injection zero-day
CVE-2026-73570
CVE-2026-7473
CVE-2026-74820
CVE-2026-75149
CVE-2026-75604
CVE-2026-76581
CVE-2026-76639
CVE-2026-76640
CVE-2026-77413
CVE-2026-77414
CVE-2026-77415
CVE-2026-80192
CVE-2026-8037
CVE-2026-81578
CVE-2026-82078
CVE-2026-82222
CVE-2026-82329
CVE-2026-82447
CVE-2026-82448
CVE-2026-82450
CVE-2026-82452
CVE-2026-82454
CVE-2026-82456
CVE-2026-83548
CVE-2026-83549
CVE-2026-8451
CVE-2026-8452
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
CVE-2026-8461
CVE-2026-85046
CVE-2026-8732
CVE-2026-9082
CVE-2026-9198
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
CVE-2026-9539
CVE-2026-9586
CVSS
CVSS 10.0
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
CVSS 9.0
cvvform
CWE-22
CWE-259
CWE-284
CWE-287
CWE-306
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
CWE-352
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
CWE-470
CWE-502
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
CWE-640
CWE-77
CWE-78
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
CWE-829
CWE-94
Cybench
cyber AI
cyber evaluation
cyber sanctions
cyber-espionage
- Armored Likho
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- LurkProxy
- OctLurk
- OctLurk and SilkLurk Central Asia espionage campaign
- SilkLurk
CyberAv3ngers
cybercrime
- Dutch Police / NCSC 17-million-device botnet disruption
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
- First VPN
- Fox Tempest
- Funnull RingH23 and MacCMS supply-chain attacks
- Hunt.io global smishing infrastructure campaign
- JINX-0164
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- Operation FlutterBridge FlutterShell macOS malvertising
- Outsider Enterprise smishing PhaaS
- Pirated media SilentCryptoMiner RAT campaign
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- TA4922
- The Gentlemen ransomware
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- UAT-11795
- UAT-11795 Starland / WLDR campaign
cybercrime ecosystem
cyberespionage
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- OWAReaper
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- TA488 OWAReaper and CVE-2026-42897 exploitation
Cyera
Cython
Czech Republic
D-Link
D2IP
Dahua
dangling resources
Dark Caracal
DARKLANTERN
DarkSword
data analytics
data breach
data center
data contamination
data exfiltration
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- AI-agent memory poisoning
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- Atlassian Rovo prompt-to-data exfiltration
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- Cloud bucket namespace hijacking
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- HOLLOWGRAPH
- MCP tool-description poisoning
- ModHeader browser-extension surveillance capability
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- Open VSX evil-twin extension campaign
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- SHADOW-AETHER AI-augmented Latin America intrusions
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
data exposure
- Anthropic cyber-evaluation real-world intrusions
- Internet-exposed unauthenticated MCP servers
- ServiceNow instance unauthenticated table-query exploitation
data extortion
data leak site
data scraping
data theft
- Accellion FTA exploitation campaign
- DeadLock ransomware
- GoSerpent Southeast Asia espionage campaign
- Gunra ransomware-as-a-service activity
- JINX-0163 / FulcrumSec
- Kairos data-extortion government payment
- Malware-Slop Claude user-data npm infostealer
- Metabase unauthenticated SQL-injection zero-day
- ShinyHunters
- UAT-10147
- UNC3753
data-exfiltration
database
database extortion
Datadog Security Labs
DataObject
dataset dead drop
dataset processing
DAYLIGHT
DCIS
DCloud
DCloud Uni-App
DcRAT
DCSync
DD-WRT
DDNS
DDoS
- C0XMO Gafgyt DD-WRT botnet
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- Kimwolf v7
- Lucide Proxy npm browser DDoS botnet
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- RustDuck
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
DDoS botnet
DDoS-for-hire
DDR
DDS
dead drop
dead drop resolver
- ChocoPoC
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
dead-drop
dead-drop resolver
DeadLock
Debian
debugger evasion
debugging detection
DEBULL
declarativeNetRequest
Deed
DeepAudit
DeepSeek
- AI-augmented adversary operations
- AI-brand impersonation phishing and malvertising
- JetBrains AI plugin API-key theft
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Defender Advanced Hunting
Defender evasion
Defender exclusion
defense
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Kimsuky / Emerald Sleet / TA427
- Mirage Kitten
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
defense evasion
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Cloud logging control-plane tampering
- DeadLock ransomware
- GodDamn ransomware PoisonX BYOVD activity
- Ollama P2P cryptominer RAT campaign
- Pirated media SilentCryptoMiner RAT campaign
- ROADtools
- SourTrade browser-assembled malware malvertising
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
defense impairment
defense sector
defense targeting
defense-evasion
DeFi
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- RemotePE
- TrapDoor crypto-stealer cross-ecosystem campaign
delayed execution
- AI-agent memory poisoning
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
denial of service
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- SolarWinds Serv-U CVE-2026-28318 exploitation
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
Deno
Denys Pakizh
Dependabot
dependency confusion
- @marketfront / @tqm-mfe dependency-confusion stealer
- Alibaba developer-targeted distributed npm RAT campaign
- nodemon-sudo / tslint-conf runtime npm backdoor
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- oob.moika.tech dependency-confusion environment stealer
deployment_status
deserialization
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Fastjson CVE-2026-16723 active exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Vertex AI staging-bucket squatting
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
destructive actions
destructive malware
destructive operations
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Iran-linked threat landscape: access optionality and evidence quality
- UAC-0145
detached execution
detached process
detection
detection engineering
detection failure
DEV#POPPER
DEV-0206
developer credential theft
developer credentials
developer endpoints
- Coding-agent-parented tunnels and persistence
- Crypto supply-chain path to transaction authority
- NuGet game-cheat DotnetTool pepesoft campaign
Developer ID abuse
developer identity
developer infrastructure
developer machines
- Agent localhost control-plane RCE
- Astro config blockchain C2 PR injection
- BufferZoneCorp RubyGems / Go module CI poisoning
- GuardFall AI-agent shell-guard bypass
- MCP stdio command-execution boundary
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
developer mode
developer platform
developer targeting
- Alibaba developer-targeted distributed npm RAT campaign
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Fake Corepack site infostealer and proxyware campaign
- FakeGit AgentBaiting and SmartLoader campaign
- Joyfill npm blockchain-RAT compromise
- NullReceiver DPRK-linked npm blockchain-loader wave
- Solana FakeFix npm / PyPI developer stealer
- ViteVenom / ChainVeil npm campaign
- Void Dokkaebi
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
developer tooling
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- AsyncAPI generator / specs Miasma compromise
- Browser-based developer IDE OAuth token theft
- Cursor Windows workspace-path binary hijack
- Fake Corepack site infostealer and proxyware campaign
- ModHeader browser-extension surveillance capability
- Phantom squatting: AI-hallucinated domains
developer workstations
- Lazarus-linked Rollup polyfill npm malware
- Sentry MCP Agentjacking
- SleeperGem RubyGems maintainer-account compromise
developer-machine-fleet
developer-targeting
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- ChainDrop keyv / cacheable npm worm
- codexui-android OpenAI token stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- JetBrains AI plugin API-key theft
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Open VSX evil-twin extension campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- UNK_DeadDrop developer repository phishing
- wshu.net npm credential-stealer campaign
developer-tools
developer-workstations
- Atomic Arch AUR package hijack
- Dependabot cross-ecosystem malware advisory alerts
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- Open VSX evil-twin extension campaign
device identity
device linking
device lockout
device registration
device-code phishing
- APT29
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kali365 device-code phishing expansion
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
DevOps
DevTools
DEWMODE
DGA
DIAMONDBACK
diffpatch
digital forensics
Digital Knowledge
digital wallets
DigitalOcean
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- PraisonAI CVE-2026-44338 rapid exploitation
DigitalOcean Spaces
Dindoor
DingTalk
diplomatic
diplomatic targeting
direct-to-IP
directory traversal
Dirty Pipe
DirtyClone
DirtyFrag
DISCLOSURE
Discord
Discord link abuse
Discord masquerade
discovery
disk wiping
disposable infrastructure
disruption
distributed malware infrastructure
distributed scanning
Djinn Stealer
DLL search-order hijacking
DLL side-loading
- MIXEDKEY
- OceanLotus
- Pirated media SilentCryptoMiner RAT campaign
- SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- SprySOCKS
- TELESHIM
- TELESHIM Middle East government espionage campaign
DLL sideloading
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Cavern
- Exposed WebDAV malware delivery lab and CURP campaign
- FDMTP
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- HelloNet ViPNet update-system campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation Dragon Weave Azure Blob C2 campaign
- Operation GriefLure Southeast Asia LNK dropper
- QuickFox FDMTP software supply-chain compromise
- ScreenConnect freeware / AsyncRAT SEO campaign
- Screening Serpens
- Seedworm / MuddyWater
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- SilkLurk
- SilkParasite
- Storm-2603 parallel SharePoint ransomware intrusion
- StrikeShark SharkLoader / Cobalt Strike campaign
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Trusted collaboration-channel identity abuse
- Umbrij
- Vidar / XMRig Factory-v3 malvertising campaign
dlopen
DMTP
DNS
DNS C2
DNS callback
DNS dead drop
DNS exfiltration
- CL-STA-1114 Zimbra webmail espionage
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
DNS hijack
DNS hijacking
DNS rebinding
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
DNS resolution
DNS threat intelligence
DNS tunneling
DNS-over-HTTPS
Docker
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- NadMesh AI-service and cloud-credential botnet
- Ulej / Flowerbed
Docker cache
Docker Compose
Docker credentials
Docker Hub
Docker images
Docker socket
- ENCFORGE
- JADEPUFFER Langflow agentic ransomware
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
document collection
document exfiltration
document theft
- ACR Stealer
- Gamaredon
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
document-share lure
Docusign
DOE
DoFun
DOGLEASH
DOJ
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
domain squatting
domain verification
DomainTools
domestic espionage
dormant accounts
DotNetNuke
DotnetTool
double extortion
double free
downgrade risk
downloader
downstream blast radius
DPAPI
dpapi.dll
DPAPILoader
DPRK
- AI-augmented adversary operations
- Astro config blockchain C2 PR injection
- Contagious Interview SVG-steganography OtterCookie campaign
- macOS.Gaslight Rust backdoor
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
DPRK APT
DragonForce
drive serial number
driver loading
DriveSilkRAT
DroneLink
Dropbear
Dropbox
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Stock exchange executive mailbox espionage
dropper
Drupal
dual-function malware
dual-use
dual-use tooling
duckdns
Durable Objects
Dutch Police
DWAgent
dynamic DNS
dynamic obfuscation
Dynu
DyPrIs
Dysphoria
e-commerce
E.O. 13224
E.O. 13382
E.O. 13694
E.O. 13902
E4del
Eagle Werewolf
- Armored Likho
- Armored Likho BusySnake campaign
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
Early Bird APC injection
Earth Lusca
East Asia
East Asia-linked
Easy4IP
eBPF
- Atomic Arch AUR package hijack
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
Eclipse
Economic D-Day
Ecuador
Ed25519
edge appliance
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- CitrixBleed session-hijack wave
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ivanti Sentry CVE-2026-10520 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Quest KACE SMA CVE-2025-32975 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
edge appliances
edge application server
edge device
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- FortiBleed Fortinet credential exposure
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
edge devices
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Russian state IP-camera military-logistics espionage
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
edge exploitation
Edge extension
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- ModHeader browser-extension surveillance capability
edge service
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
edge services
edge-service denial of service
editor profile import
EDR
EDR bypass
EDR evasion
- Avalon / CrownX malware framework
- RemotePE
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
EDR killer
EDR/AV bypass
EDR/AV tampering
EDS5000
education
- Brazilian education LockBit, DragonForce, and insider incidents
- HelloNet ViPNet update-system campaign
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Seedworm / MuddyWater
EfsPotato
EggJagger
Egnyte
Egypt
EKZ Infostealer
Elastic Agent
Elastic Security Labs
- Contagious Interview SVG-steganography OtterCookie campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
Elasticsearch
elections
electric power sector
Electron
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- OkoBot cryptocurrency-wallet malware framework
- QuickFox FDMTP software supply-chain compromise
Elementor Pro
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
email exfiltration
email gateway
email infrastructure abuse
email normalization
email security
email subject
email template
email theft
- OctLurk and SilkLurk Central Asia espionage campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
EmailEvents
embedded configuration
embedded Linux
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
embedded systems
Emerald Sleet
emergency patch
ENCFORGE
encrypted C2
encrypted reasoning
EncryptInterceptor
ENDLESSDOORS
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
Endor Labs
endpoint compromise
endpoint detection
endpoint management
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
endpoint management abuse
endpoint response
endpoint security
endpoint-detection
endpoint-security
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
EndpointDlp.dll
energy
energy sector
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- HelloNet ViPNet update-system campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
energy-sector
engineering
engineering software
enterprise AI
enterprise application
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
enterprise application exploitation
enterprise applications
enterprise identity
enterprise intrusion
enterprise proxy
enterprise security
Entra ID
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- HOLLOWGRAPH
- Kali365 device-code phishing expansion
- ROADtools
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
Environment Management Hub
environment variable theft
- Braintree.Net NuGet payment skimmer
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
environment variables
environmental keying
- BINDCLOAK
- LurkProxy
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- MIXEDKEY
- OctLurk
- OctLurk and SilkLurk Central Asia espionage campaign
- RemotePE
- SilkLurk
- TELESHIM Middle East government espionage campaign
EPA
EPFL
epoll
Epsilon Stealer
ERAAgent
ERP
error-message disclosure
ESC1
Escalate with Certify
escrow
eSentire TRU
ESET
ESG
espionage
- APT28-linked HOOKEDGE backdoor targets European government and diplomatic organizations
- APT29
- ArcBridge
- Barracuda ESG zero-day backdoor campaign
- BridgeHead
- Cavern Manticore
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Cloud Atlas
- Dragonfly
- FishMonger
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghostwriter
- GoSerpent Southeast Asia espionage campaign
- GREYVIBE
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- HelloNet ViPNet update-system campaign
- HOLLOWGRAPH
- Iran-linked threat landscape: access optionality and evidence quality
- Kimsuky / Emerald Sleet / TA427
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- NightLedger
- OceanLotus
- Oman government Iranian-nexus webshell C2
- OP-512
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Pakistani law enforcement espionage convergence
- QuickFox FDMTP software supply-chain compromise
- RemotePE
- ROADtools
- Russian state IP-camera military-logistics espionage
- ScarCruft Yanbian game-platform supply-chain attack
- Screening Serpens
- Seedworm / MuddyWater
- Showboat
- SideCopy
- SilkParasite
- SprySOCKS
- Stock exchange executive mailbox espionage
- TELESHIM Middle East government espionage campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Turla
- Turla STOCKSTAY backdoor operations
- UAC-0145
- Ulej / Flowerbed
- UNC6508
- UNC6692 SNOW malware social-engineering campaign
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- Webworm
Espressif ESP-IDF
ESX
ESXi
ES|QL
eth_getStorageAt
Ethereum
- Adform Trackpoint JavaScript supply-chain crypto clipper
- ChainDrop keyv / cacheable npm worm
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Ill Bloom CryptoJS wallet-drain campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Ethereum C2
Ethereum Name Service
EtherHiding
- ACR Stealer
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - ChainDrop keyv / cacheable npm worm
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- Silent Swap Google Notes crypto clipper
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
Ethiopia
ETW
ETW bypass
ETW patching
ETW tampering
Eurojust
- First VPN
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
Europe
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Webworm
Europe targeting
European Union
Europol
- First VPN
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- StealC / Amadey infrastructure disruption
eval injection
evaluation cheating
evaluation containment
evasion
event log clearing
eventpoll
Everest Forms Pro
EveryoneIncludesAnonymous
evidence quality
Evil Corp
EvilAI
Evilginx
EVM
evolutionary optimization
EWS
excessive agency
exec_globals
execution guardrails
exFAT
exfiltration
- codexui-android OpenAI token stealer
- Direct-to-IP malware communications
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- JetBrains AI plugin API-key theft
- js-logger-pack Hugging Face exfiltration campaign
- Malware-Slop Claude user-data npm infostealer
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
Exilware
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
Experience Cloud
exploit chain
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Siemens ROX II zero-day exploit chain
exploit kit
exploit noise
exploit-development
exploit-kit
Exploit.in
exploitation
- Android Framework CVE-2025-48595 exploitation
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Langflow CVE-2025-34291 exploitation
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
exploitation attempts
exploitation telemetry
ExploitBench
ExploitGym
exposed applications
exposed attacker infrastructure
exposed debug page
exposed staging
exposure window
extconf.rb
extension supply-chain
- Adblock for YouTube BadBlocker remote-script injection risk
- StegoAd Edge extension steganography campaign
extension takeover
external federation
extortion
- Accellion FTA exploitation campaign
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- CrownX
- JINX-0163 / FulcrumSec
- Klue Salesforce OAuth token abuse
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- ShinyHunters
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
- UNC3753
- UNC6671 / BlackFile multi-brand vishing extortion operation
F5
F5 BIG-IP
Factory-v3
fail-closed
fake app store
fake CAPTCHA
- ClickFix CPaaS API-driven payload delivery
- GREYVIBE
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
fake certificate
fake Cloudflare
fake crypto exchange
fake dating lures
fake documents
fake gambling
fake graduation invite
fake installers
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Operation Phnom Penh MODBEACON activity
fake lock screen
fake login
fake login screen
fake Microsoft Store
fake Minecraft client
fake plugin
fake PoC
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
fake ransomware
fake recruiting
- Contagious Interview SVG-steganography OtterCookie campaign
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Void Dokkaebi
fake reputation
fake update
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Operation BlueDash multi-RMM workplace phishing
- Pirated media SilentCryptoMiner RAT campaign
fake VPN
FakeCaptcha
FakeGit
Fakeset
faketivism
FakeUpdates
FALCON
Falcon Sensor
FallSpy
false positive
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
false positives
FAMOUS CHOLLIMA
- Famous Chollima Packagist dev-branch loader
- StegaBin Pastebin-steganography npm campaign
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
Famous Chollima
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
Fancy Bear
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- APT28-linked HOOKEDGE backdoor targets European government and diplomatic organizations
Fast16
FastAPI
FastCGI
Fastjson
Fastmail
fat JAR
FAT32
FatFs
FBI
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- First VPN
- Gunra ransomware-as-a-service activity
- NetNut / Popa residential proxy network disruption
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
FBI indictment
fbot
FDMTP
Feiying
FFmpeg
FIDO2
field-level security
FIFA
file encryption
file exfiltration
file infector
file inflation
file operations
file sharing
file theft
File Transmission
file upload
file upload path traversal
file-system filter
FileFiend
FILEIO
fileless execution
fileless malware
filemanager
filename-injection
filestream
filesystem parser
filter API
FilteredObjectInputStream
finance
- oob.moika.tech dependency-confusion environment stealer
- Sicoob.Sdk NuGet banking certificate stealer
finance phishing
financial
financial fraud
- AI token-jacking transfer-station abuse
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- REF6045 / SCMBANKER Mexican banking fraud
financial institutions
financial motivation
financial sector
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- RemotePE
- SHADOW-AETHER AI-augmented Latin America intrusions
- Stock exchange executive mailbox espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
financial services
- Seedworm / MuddyWater
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
- UNC3753
financial theft
financially motivated
FireAnt MetaKit
Firebase
Firecracker
Firefox
Firefox Add-ons
Firefox WebDriver BiDi
Firepower Management Center
firewall
firewall management
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
firmware
- COLDCARD predictable-RNG Bitcoin theft risk
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
firmware backdoor
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
firmware supply chain
firmware update
FishMonger
FlatBuffers
FlexPLM
flight recorder
FlockWiper
Flooding Dropper
flow execution
Flowerbed
Flowise
FLUIDLEECH
Flutter
FlutterShell
Flying Eagle
Flyto2 Core
FMC
FOFA
FofaMap
folderOpen
font1.woff2
forced channel follow
fordmotbvmorcompany.vu
foreign affairs targeting
foreign policy targeting
Forest Blizzard
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- APT28-linked HOOKEDGE backdoor targets European government and diplomatic organizations
ForestTiger
Forg365
ForgCookie
Forgejo
forgot password
FormDigestValue
Forms Authentication
FortiClient EMS
FortiGate
- FortiBleed Fortinet credential exposure
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Gunra ransomware-as-a-service activity
Fortinet
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
FortiOS
- FortiBleed Fortinet credential exposure
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Gunra ransomware-as-a-service activity
FortiSandbox
Fox Tempest
fraud
FREAKYPOLL
FreeBSD
Freedom365
freeware impersonation
Friendly Fire
frontier AI
- Unit 42 NOVA: frontier-AI autonomous zero-day discovery collapses the patch window
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
FruitStone
FSB
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Russian intelligence commercial-messaging backup-key phishing
FSB Center 16
fscan
Fscan
FTA
FTD
FTP banner
ftp.exe
- Operation GriefLure Southeast Asia LNK dropper
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
ftrace
FudModule
Full Disk Access social engineering
Funnull
Fusion Builder
futex PI
FUXA
G1 EDU
gadget chain
Gafgyt
GaiaOS WebUI
GalaxyGato
Gamaredon
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
Gamaredon collaboration
gambling
gambling industry targeting
game cheats
game exploitation
gaming malware
GammaLoad
GammaPhish
GammaSteel
GammaWorm
Garble
Gardener
GateKeeper
Gatekeeper bypass
GCP
GCS
Gemini CLI
Gen Digital
generative AI
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
GenieLocker
GentleKiller
Germany
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- Kratos Microsoft 365 PhaaS and infrastructure disruption
GHETTOVIBE
Ghost
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- MODBEACON
- Operation Phnom Penh MODBEACON activity
ghost accounts
Ghost Calls
Ghost CMS
Ghost Networks
GHOSTBLADE
GhostLock
GHSA-2679-6mx9-h9xc
GHSA-2943-5xfg-gq5f
GHSA-2xp9-vwfh-vxw4
GHSA-66mm-25pp-rfff
GHSA-6rmh-7xcm-cpxj
GHSA-6v3r-4p5c-mrp5
GHSA-6vxv-wg6j-5qwp
GHSA-6whr-xjjm-6pf8
GHSA-78mw-f4q2-924q
GHSA-7g4w-cg88-2cq2
GHSA-864f-rcv7-6rh4
GHSA-8gq3-vp5j-2grp
GHSA-c39w-43gm-34h5
GHSA-c4hm-4h84-2cf3
GHSA-g89c-p67h-r497
GHSA-hvfh-5mj3-5f3j
GHSA-m5w8-4gq2-6f8x
GHSA-mf7q-r4rv-jv94
GHSA-p293-qw3h-jr36
GHSA-qrpv-q767-xqq2
GHSA-rcr6-4jqh-j84m
GHSA-rg76-677x-56q9
GHSA-vwf4-m7j8-wcjf
GHSA-w3fx-mc44-mf6j
GHSA-x2rj-828p-hx9m
GHSA-xhcr-j4j9-3gh7
GIFTEDCROOK
Git
Git hook
Git hosting
git.exe
Gitea
GitHub
- Aeternum
- Astro config blockchain C2 PR injection
- Browser-based developer IDE OAuth token theft
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChocoPoC fake PoC supply-chain campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto supply-chain path to transaction authority
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- FakeGit AgentBaiting and SmartLoader campaign
- GitHub / Packagist postinstall hook campaign
- GitHub API enumeration and access-token abuse
- Glassworm developer supply-chain botnet
- IronWorm npm Rust infostealer campaign
- JiaT75
- JINX-0164 crypto developer infrastructure campaign
- Malware-Slop Claude user-data npm infostealer
- Nx Console VS Code extension compromise
- Operation Muck and Load GitHub lure network
- PolinRider cross-ecosystem supply-chain campaign
- UNK_DeadDrop developer repository phishing
- Webworm
- XCSSET v40 Xcode supply-chain campaign
GitHub abuse
- AI-brand impersonation phishing and malvertising
- Armored Likho BusySnake campaign
- Fake-reputation crypto clipboard hijacker
GitHub Actions
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- actions-cool GitHub Actions tag compromise
- AsyncAPI generator / specs Miasma compromise
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChainDrop keyv / cacheable npm worm
- Claude Code GitHub Action prompt-injection boundary
- codfish semantic-release-action tag compromise
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- Operation Muck and Load GitHub lure network
- SANDWORM_MODE AI-toolchain npm worm
- simonecorsi/mawesome GitHub Action compromise
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- TeamPCP
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- tj-actions and reviewdog compromise
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
GitHub Advisory Database
GitHub API
GitHub App
GitHub CLI
GitHub dead drop
- CrashStealer macOS notarized-dropper campaign
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
GitHub issue spam
GitHub OAuth
GitHub Pages
GitHub Pages abuse
GitHub PAT abuse
GitHub payload delivery
GitHub release assets
GitHub Security Advisories
- Agent localhost control-plane RCE
- Dependabot cross-ecosystem malware advisory alerts
- GitHub Security Advisories August 27, 2026: Crossplane cosign signature-verification bypass and Silverstripe RCE batch
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- LangGraph checkpointer and namespace trust boundaries
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
GitHub tokens
GitHub-hosted runners
GitLab
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- GitLab Oj notebook-diff authenticated RCE chain
- UNK_DeadDrop developer repository phishing
gitleaks
gitnow
GitOps
GiveWP
Gleaming Pisces
gleeze.com
GlobalProtect
Gmail
- AI browser-extension confused deputy
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
- Webmail CSS trust-boundary attacks
Go
- BufferZoneCorp RubyGems / Go module CI poisoning
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Ollama P2P cryptominer RAT campaign
- Operation Muck and Load GitHub lure network
- shopsprint/decimal Go typosquat DNS backdoor
- SilkParasite
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- The Gentlemen ransomware
Go backdoor
Go loader
Go malware
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- GoSerpent Southeast Asia espionage campaign
- NadMesh AI-service and cloud-credential botnet
- Vidar / XMRig Factory-v3 malvertising campaign
Go modules
Go net/http user agent
Go stealer
Go2Tunnel
GoCaracal
GoDaddy federation
GodDamn ransomware
GodPotato
Godzilla
GoEdge
GoFile
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
GoginRAT
Gogs
Golang
Golang malware
GOLD PRELUDE
Golden Pass-ta-key
gomod
Goodhart's law
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
Google account
Google Ads
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Operation FlutterBridge FlutterShell macOS malvertising
Google Analytics telemetry
Google API
Google Calendar
Google Chrome
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- Synced passkey theft after endpoint compromise
Google Cloud
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- Vertex AI staging-bucket squatting
Google Cloud Authenticator
Google Cloud Logging
Google Cloud Storage
Google credential theft
Google Docs
Google Drive
Google Notes
Google OAuth
Google Password Manager
Google Play
Google Play Protect
Google redirect abuse
Google Sheets
Google Sheets C2
Google Stitch
Google Threat Intelligence Group
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- NetNut / Popa residential proxy network disruption
- UNC6508
Google Workspace
Goose
GoSerpent
government
- APT28-linked HOOKEDGE backdoor targets European government and diplomatic organizations
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- Cavern Manticore
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- HelloNet ViPNet update-system campaign
- Kairos data-extortion government payment
- Kimsuky / Emerald Sleet / TA427
- Oman government Iranian-nexus webshell C2
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
government impersonation
government offices
government services and facilities
government targeting
- Armored Likho
- Armored Likho BusySnake campaign
- BINDCLOAK
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Cloud Atlas
- FishMonger
- GoSerpent Southeast Asia espionage campaign
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mustang Panda
- OctLurk and SilkLurk Central Asia espionage campaign
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- Russian intelligence commercial-messaging backup-key phishing
- SHADOW-AETHER AI-augmented Latin America intrusions
- SilkParasite
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TA488 OWAReaper and CVE-2026-42897 exploitation
- TELESHIM Middle East government espionage campaign
government-impersonation
GPT
GPT-5.6 Sol
GPT-5.6-Cyber
GPT-6
Gradio
Grafana MCP Server
Grandoreiro
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
granular access tokens
Graph API
GraphQL
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
GraphQL Composite Data API
GraphSpy
Gravity SMTP
gray market
GRE
Gremlin API
GREYVIBE
Grok
group
Group-IB
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
groups
- APT29
- CL-STA-1062
- CL-STA-1114 / Void Blizzard
- Dragonfly
- Fox Tempest
- JINX-0164
- OP-512
- SilkParasite
- TA4922
- Toy Ghouls
- Turla
- UAT-10147
- UAT-11795
- UNC3753
- UNC6508
- VerdantBamboo
- Void Dokkaebi
- Webworm
gRPC
- Argo CD repo-server unauthenticated RCE
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
gRPC C2
GRU
gs-netcat
GS-Netcat
Gshell
GTIG
GUE
guest access abuse
guest-to-host escape
- Januscape KVM CVE-2026-53359 guest-to-host escape
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
Guildma
Gunra
hack-and-leak
hacked WordPress sites
HackerOne
HackIndex
hacktivist persona
Hades
- AI scanner anti-analysis
- binding.gyp npm CI/CD worm
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
Hajime
half-click exploit
hallucination
HalluSquatting
Halo's Gate
Handala
HappyDoor
HAProxy
HAR files
hard-coded password
hard-coded secrets
HardBreacher
hardcoded key
hardening gap
hardware wallet
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- COLDCARD predictable-RNG Bitcoin theft risk
HarmonyLib
HashiCorp Vault
HavocKiller
HDF5
Head Mare
head unit
HEADLACE
headless browser
- ToddyCat Umbrij Gmail OAuth operation
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- Umbrij
headless Edge
HEADRUSH
healthcare
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Operation GriefLure Southeast Asia LNK dropper
- Thailand healthcare RAR / Python stealer campaign
heap buffer overflow
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
heap overflow
heap pointer disclosure
HEIC
HEIF
HELIX
HelloBackdoor
HelloCleaner
HelloDoor
HelloExecutor
HelloInjector
HelloNet
HelloProxy
HellsGate
Helm
help desk impersonation
Hermes
Hermes Agent
- AI-augmented adversary operations
- GuardFall AI-agent shell-guard bypass
- knaithe Hermes/DeepSeek autonomous exploitation campaign
Hetzner
HexKiller
hidden backdoor
hidden instructions
hidden service
high explosives
higher education
HMI
holiday calendar lure
HOLLOWGRAPH
homoglyph
Honduras
HONESTCUE
honeypot
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
Hong Kong
Hong Kong infrastructure
HOOKEDGE
hospitality
hospitality targeting
host DNS hijacking
Host Radar
host RCE
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
host surveillance
hosting control plane
hosting provider
hosting providers
Hostwinds
hotel targeting
Howling Scorpius
HPC
HR lures
HS256
HTA
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- UAT-11795 Starland / WLDR campaign
HTML comments
HTML email
HTML sanitization
HTML smuggling
html5lib
HTTP C2
HTTP/2
HttpMalice
HTTPS C2
HTTPS exfiltration
HTTPSpy
Hugging Face
- forge-jsxy
- Hugging Face autonomous-agent production intrusion
- js-logger-pack Hugging Face exfiltration campaign
HUMAN Satori
humanoid robot
Hunt.io
- GHOST STADIUM FIFA World Cup ticket phishing
- Malicious infrastructure provider concentration
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- Quest KACE SMA CVE-2025-32975 exploitation
- xlabs_v1 DDoS-for-hire IoT botnet
Huntress
- Azure CLI LSHIY password-spray campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
Huorong
Hyadina
hybrid threat actor
hydropower
Hydropower Cooperation Project Proposal.zip
hypervisor escape
- Januscape KVM CVE-2026-53359 guest-to-host escape
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
Hyunwoo Kim
I-SOON
IAB
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
iACL
IAM
Iberian
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
IBM
iCagenda
ICE
Ice Relic
iCloud theft
ICONICSTEALER
ICS
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Dragonfly
- Iran-linked threat landscape: access optionality and evidence quality
- KNX Protocol CVE-2023-4346 KEV exploitation
IDE extension
IDE plugins
IDE trust boundary
ide.cfm
identity
- 0ktapus phishing campaign
- JINX-0163 / FulcrumSec
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- ROADtools
- UNC6671 / BlackFile multi-brand vishing extortion operation
identity attack
identity attacks
identity compromise
identity infrastructure
identity phishing
identity security
identity theft
identity-first intrusion
IDEs
IFEO persistence
IIOP
IIS
- OP-512
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
IKE
IKEv1
Ill Bloom
image optimization
image proxy bypass
image recognition
ImageMagick
iMessage
- Chinese-language PhaaS wallet-tokenization ecosystem
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
Impacket
- Gunra ransomware-as-a-service activity
- OctLurk and SilkLurk Central Asia espionage campaign
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
Imperial Kitten
impersonation
implant
import-time execution
- Joyfill npm blockchain-RAT compromise
- Lazarus-linked Rollup polyfill npm malware
- MrMustard PyPI credential-stealer compromise
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- Solana FakeFix npm / PyPI developer stealer
- ViteVenom / ChainVeil npm campaign
improper access control
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
improper authentication
improper authorization
improper privilege management
in-memory
in-memory DLL loading
in-memory ELF execution
in-memory malware
in-memory plugins
incident response
- Adform Trackpoint JavaScript supply-chain crypto clipper
- Anthropic cyber-evaluation real-world intrusions
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Brazilian education LockBit, DragonForce, and insider incidents
- Check Point VPN CVE-2026-50751 exploitation
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- COLDCARD predictable-RNG Bitcoin theft risk
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Hugging Face autonomous-agent production intrusion
- Ill Bloom CryptoJS wallet-drain campaign
- Iran-linked threat landscape: access optionality and evidence quality
- Klue Salesforce OAuth token abuse
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Malicious infrastructure provider concentration
- Metabase unauthenticated SQL-injection zero-day
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- ServiceNow instance unauthenticated table-query exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Water-sector PLC configuration-tampering campaign
incident-response
- Dependabot cross-ecosystem malware advisory alerts
- Storm-2603 parallel SharePoint ransomware intrusion
incomplete patch
IndexedDB
- ModHeader browser-extension surveillance capability
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
India
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation DragonReturn India tax-season DcRAT campaign
India-nexus
Indian government
indirect prompt injection
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- AI browser-extension confused deputy
- AI-agent memory poisoning
- AI-augmented adversary operations
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
- MCP tool-description poisoning
- Sentry MCP Agentjacking
- Webmail CSS trust-boundary attacks
indirect syscalls
Indonesia
industrial control
industrial control systems
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Siemens ROX II zero-day exploit chain
- Water-sector PLC configuration-tampering campaign
industrial espionage
industrial targeting
infect[.]online
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
Infected Marketplace
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
inference server
INFINITE NIGHTMARE
INFINITERED
Infoblox Threat Intel
information disclosure
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FortiOS CVE-2025-68686 symlink-persistence bypass
- LangGraph checkpointer and namespace trust boundaries
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
information stealer
infostealer
- @copilot-mcp/apex macOS infostealer campaign
- ACR Stealer
- Armored Likho
- Armored Likho BusySnake campaign
- BusySnake Stealer
- codexui-android OpenAI token stealer
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- Fake Corepack site infostealer and proxyware campaign
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164 crypto developer infrastructure campaign
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Operation Muck and Load GitHub lure network
- PamStealer
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- TamperedChef-style productivity malware clusters
- Telnyx PyPI TeamPCP compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
- wshu.net npm credential-stealer campaign
infotainment
InfoTeCS
infrastructure
- First VPN
- Flying Eagle and Night Dragon Android RAT ecosystem
- Funnull RingH23 and MacCMS supply-chain attacks
- GHOST STADIUM FIFA World Cup ticket phishing
- Hunt.io global smishing infrastructure campaign
- Malicious infrastructure provider concentration
infrastructure churn
infrastructure disruption
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NetNut / Popa residential proxy network disruption
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- StealC / Amadey infrastructure disruption
infrastructure seizure
initial access
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
initial access broker
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
- FortiBleed Fortinet credential exposure
initial-access
- AI-augmented adversary operations
- ClickOnce COM hijacking abuse
- Operation Endgame SocGholish disruption
Injective Labs
Inno Setup
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
input capture
insider threat
install-time execution
- @copilot-mcp/apex macOS infostealer campaign
- Anthropic cyber-evaluation real-world intrusions
- Flooding Dropper npm campaign
- jscrambler npm preinstall stealer
- MYRA RAT
- Solana FakeFix npm / PyPI developer stealer
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
install-time-execution
install.res.1033.dll
integer-overflow
Integration Broker
inter-agent communication
Intercolo
internal secret exfiltration
internal security review
internet exposure
- Internet-exposed unauthenticated MCP servers
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
internet-facing admin surface
internet-facing appliance
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
internet-facing applications
investment scam
invisible prompt injection
InvisibleFerret
invocation logging
iOS
- art-template Coruna-style iOS watering-hole compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
IOS XR
IoT
- Dutch Police / NCSC 17-million-device botnet disruption
- ENDLESSDOORS implant in Zbtlink router firmware
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- JDY SOHO / IoT reconnaissance botnet
- Kimwolf v7
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Russian state IP-camera military-logistics espionage
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
IoT botnet
- AryStinger legacy-router recon proxy network
- C0XMO Gafgyt DD-WRT botnet
- Direct-to-IP malware communications
- Dysphoria IoT botnet
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- RustDuck
- TuxBot v3 Evolution IoT botnet framework
- xlabs_v1 DDoS-for-hire IoT botnet
IP cameras
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Russian state IP-camera military-logistics espionage
IP-in-IP
IPFS
iPhone
IPMODIFY
IPsec
IPv6
- Azure CLI LSHIY password-spray campaign
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- HOLLOWGRAPH
ipynbdiff
Iran
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Cavern
- Cavern Manticore
- Handala
- Iran-linked threat landscape: access optionality and evidence quality
- Langflow CVE-2025-34291 exploitation
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Screening Serpens
- Seedworm / MuddyWater
Iran-nexus
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Oman government Iranian-nexus webshell C2
IRC C2
IRGC
IronWorm
Irregular
ischhfd83
Island Security
Island Security Research
- Adblock for YouTube BadBlocker remote-script injection risk
- FakeGit AgentBaiting and SmartLoader campaign
ISO image
isolated-vm
Israel
IT providers
Italian foreign-policy targeting
Italy targeting
ITCSD
ITRES Labs
Ivanti Sentry
JackSkid
Jackson
JADEPUFFER
Jamf Threat Labs
Januscape
- Januscape KVM CVE-2026-53359 guest-to-host escape
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
Japan
JAR payload
JARLEASH
JarService
Java
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Fastjson CVE-2026-16723 active exploitation
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
Java deserialization
Java malware
java.rmi.MarshalledObject
JavaScript
- Astro config blockchain C2 PR injection
- Flooding Dropper npm campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Injective SDK npm wallet stealer
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- jscrambler npm preinstall stealer
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- Lazarus-linked Rollup polyfill npm malware
- Mastra
easy-day-jsnpm scope compromise - nodemon-sudo / tslint-conf runtime npm backdoor
- npm install explicit-trust controls
- Operation DangerousPassword axios npm compromise
- Operation XENOFISCAL SideCopy XenoRAT campaign
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- SilkParasite
- TaskWeaver
- Ulej / Flowerbed
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- wshu.net npm credential-stealer campaign
JavaScript bridge
JavaScript execution
JavaScript implant
JavaScript injection
JavaScript loader
JavaScript malware
- Contagious Interview SVG-steganography OtterCookie campaign
- Ghostwriter
- NullReceiver DPRK-linked npm blockchain-loader wave
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
JavaScript masquerading
JavaScript runtime
JavaScript tampering
JavaScriptCore
JBoss
JCE
JDY
Jellyfin
Jenkins
JetBrains
- Amazon Q CVE-2026-12957 MCP auto-execution
- JetBrains AI plugin API-key theft
- JetBrains TeamCity CVE-2026-63077 active exploitation
JetBrains Marketplace
JetStream
JFrog
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Lucide Proxy npm browser DDoS botnet
JFrog Artifactory
JFrog Security Research
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- Solana FakeFix npm / PyPI developer stealer
Jinja
Jinja2
JINX-0164
Jira
- Atlassian Rovo prompt-to-data exfiltration
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
Jiří Vinopal
job-offer phishing
job-themed phishing
joblib
Joomla
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- WP-SHELLSTORM webshell access brokerage
Joomla Content Editor
Joomla JCE
Joomlack
JoomShaper
Jordan
journalism
journalists
JPMorgan Chase
JSCEAL
JSCoreRunner
jscrambler
Jscrambler
JScript
JSON
JSON Web Token
JSON-RPC
JSON:API
jsonata
JSONKeeper
JSONL
JSONPing
JSP web shell
JuicyPotato
Jupyter
Jupyter Notebook
JustWatch
JWT
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
JWT alg none
JXA downloader
K1MORPHER
Kairos
Kaitori
Kali365
Kaltura
Kaspersky
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet via TWCore updaters
- MiniPlasma Windows Cloud Filter LPE exploitation
- Pirated media SilentCryptoMiner RAT campaign
Kaspersky detection bypass
Kaspersky GERT
Kaspersky GReAT
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- OkoBot cryptocurrency-wallet malware framework
Kaspersky Securelist
Kazakhstan
KAZUAR
KAZUAR overlap
KB5002893
KeePassXC
Keitaro
Keksec
Kemp LoadMaster
kernel driver
- BTR Reforged: weaponizing Microsoft Defender's BTR.sys remediation driver as a kernel primitive
- Fast16
- FishMonger
- SprySOCKS
kernel instrumentation
kernel R/W
kernel rootkit
kernelCTF
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
Kestra
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
KEV
- Drupal Core CVE-2026-9082 exploitation
- Langflow CVE-2025-34291 exploitation
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
keychain
Keychain theft
keychain theft
- Coding-agent-parented tunnels and persistence
- CrashStealer macOS notarized-dropper campaign
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- macOS.Gaslight Rust backdoor
Keycloak
KeyHunter
keylogger
- Brazilian education LockBit, DragonForce, and insider incidents
- forge-jsxy
- js-logger-pack Hugging Face exfiltration campaign
- OkoBot cryptocurrency-wallet malware framework
- TELEPUZ
keylogging
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Flying Eagle and Night Dragon Android RAT ecosystem
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Operation Highland Velvet Ant authentication-stack backdoors
keyval.org
keyword splitting
Kimi K2.5
Kimsuky
Kimwolf
Kimwolf v7
Kiro Powers
KLCERT-26-057
KLCERT-26-058
Klue
knaithe
knowledge base
KnowledgeDeliver
known exploited vulnerability
KNUCKLEBALL
KNX
KNX Association
KNX Protocol
KnYuan
KongTuke
KORKERDS
Kratos
krbtgt
Kubernetes
- @copilot-mcp/apex macOS infostealer campaign
- Argo CD repo-server unauthenticated RCE
- Crypto supply-chain path to transaction authority
- Hugging Face autonomous-agent production intrusion
- MrMustard PyPI credential-stealer compromise
- NadMesh AI-service and cloud-credential botnet
KV-botnet
KVM
- Januscape KVM CVE-2026-53359 guest-to-host escape
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
KVM escape
kvmCTF
Kyrgyzstan
L2TP/IPSec
LA Metro
Laboo.boo
LabubaPanel
LabubaRAT
Labubu
LangChain
- LangGraph checkpointer and namespace trust boundaries
- MCP stdio command-execution boundary
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
Langflow
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- ENCFORGE
- JADEPUFFER Langflow agentic ransomware
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
LangFlow
LangGraph
Language Servers for AWS
Lantronix
LapDogs
Laravel
Laravel deserialization
LATAM
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
lateral movement
- Alibaba developer-targeted distributed npm RAT campaign
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- GodDamn ransomware PoisonX BYOVD activity
- Hugging Face autonomous-agent production intrusion
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- LurkProxy
- Quest KACE SMA CVE-2025-32975 exploitation
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- The Gentlemen ransomware
lateral-movement
Latin America
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- SHADOW-AETHER AI-augmented Latin America intrusions
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
LaunchAgent
- @copilot-mcp/apex macOS infostealer campaign
- Coding-agent-parented tunnels and persistence
- CrashStealer macOS notarized-dropper campaign
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- macOS.Gaslight Rust backdoor
launchctl
LAUNDRY BEAR
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
law enforcement
- Dutch Police / NCSC 17-million-device botnet disruption
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
law enforcement targeting
- OctLurk and SilkLurk Central Asia espionage campaign
- Pakistani law enforcement espionage convergence
law-enforcement-disruption
LayerX
Lazarus
- Famous Chollima Packagist dev-branch loader
- Lazarus-linked Rollup polyfill npm malware
- NullReceiver DPRK-linked npm blockchain-loader wave
- Operation DangerousPassword axios npm compromise
- RemotePE
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- StegaBin Pastebin-steganography npm campaign
LD_PRELOAD
LDAP
leak site
leaked credentials
leaked exploit
leaked repository
leaked source code
learning cycles
LEASHTEST
least privilege
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- Cloud bucket namespace hijacking
- Internet-exposed unauthenticated MCP servers
Ledger
legacy botnet hijacking
legacy infrastructure
legacy pattern
legacy software
legacy systems
legal sector
LegionRelay
Leo Platform
Level RMM
LevelBlue
Lexfo
libcurl
libheif
liblzma
libmupdf.dll
libp2p
libpeconv
libsignal-node
libslirp
libsodium
libuser
lifecycle hooks
lifecycle-hooks
lighthouse beacon
Lightning Shared Scooter Co.
Lightning Web Runtime
Linksys
Linux
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- Atomic Arch AUR package hijack
- Djinn Stealer
- ENCFORGE
- Flooding Dropper npm campaign
- GenieLocker
- GitHub / Packagist postinstall hook campaign
- IronWorm npm Rust infostealer campaign
- Januscape KVM CVE-2026-53359 guest-to-host escape
- js-logger-pack Hugging Face exfiltration campaign
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- MYRA RAT
- Ollama P2P cryptominer RAT campaign
- Operation DangerousPassword axios npm compromise
- Operation Highland Velvet Ant authentication-stack backdoors
- PCPJack cloud SMTP relay network
- QuimaRAT
- Showboat
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- XZ Utils backdoor
Linux backdoor
Linux kernel
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux pedit COW CVE-2026-46331 local privilege escalation
Linux malware
Linux networking devices
Linux rootkit
LiteLLM
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- Telnyx PyPI TeamPCP compromise
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
LiteSpeed
LiteSpeed Cache
live chat
Live Protect
living off the land
living-off-the-land
living-off-the-land binaries
LLM
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- AI token-jacking transfer-station abuse
- AI-augmented adversary operations
- GREYVIBE
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Ollama P2P cryptominer RAT campaign
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
LLM command execution
LLM gateway
LLM security
LLM slop
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
LLM-assisted malware
- Exposed WebDAV malware delivery lab and CURP campaign
- REF6045 / SCMBANKER Mexican banking fraud
- State of AI-enabled malware, August 2026 (Unit 42)
- TuxBot v3 Evolution IoT botnet framework
LLM-driven intrusion
LLMjacking
- NATS-as-C2 KeyHunter credential-harvesting operation
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
LMS
LNK
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Armored Likho BusySnake campaign
- Avalon / CrownX malware framework
- Crypto Clipper Tor / USB worm
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation GriefLure Southeast Asia LNK dropper
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Photo ZIP hospitality Node.js implant campaign
- SideCopy
- UAC-0226 / SHADOW-EARTH-066
LNK files
LNK Startup persistence
load balancer
loader
- Aeternum
- Famous Chollima Packagist dev-branch loader
- Flooding Dropper npm campaign
- MIXEDKEY
- RustDuck
- StealC / Amadey infrastructure disruption
- TaskWeaver
loadlib2
LoadLibrary
LOADLOOP
local exploit
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
local inference
local LLMs
local privilege escalation
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux pedit COW CVE-2026-46331 local privilege escalation
- MiniPlasma Windows Cloud Filter LPE exploitation
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
local subprocess
local-file-inclusion
localhost
localhost trust bypass
localhost.run
localStorage
LockBit
LockBit 3.0
Lockdown Mode
LockScreen
LockScreenContentServer
log poisoning
log sanitization
Log4j
Log4j 2
Log4j 2.26.1
logging
logging impairment
logical decoding
login item persistence
LOLBAS
LOLBins
- ClickFix CPaaS API-driven payload delivery
- Exposed WebDAV malware delivery lab and CURP campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
long-horizon autonomy
long-lived tokens
long-term access
long-term surveillance
LONGLEASH
LONGSTREAM
LOOKVALJS
LOOKVALPS
loopback
loopback login
Loophole
loose boolean check
LosFormatter
Lovable
low-confidence attribution
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- HOLLOWGRAPH
- WhatsApp VBScript ManageEngine RMM campaign
LPE
LS-DYNA
LSASS
LSHIY
LSN
LSSC
Lua
LuaJIT
Lumen
Lumen Black Lotus Labs
- JDY SOHO / IoT reconnaissance botnet
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
Lumma Stealer
Luna Moth
Luno
LurkProxy
Lyceum
M-RED-TEAM
M365
MaaS
- ACR Stealer
- Flying Eagle and Night Dragon Android RAT ecosystem
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
Mabna Institute
MAC address
MacCMS
Maccy impersonation
Machine Account Quota
machine-learning
machine-speed attack chain
macOS
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- Coding-agent-parented tunnels and persistence
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Flooding Dropper npm campaign
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Operation DangerousPassword axios npm compromise
- Operation FlutterBridge FlutterShell macOS malvertising
- PamStealer
- QuimaRAT
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
macOS malware
macro
macro-enabled Word
MacSync
MaDoO Blaster
Magento
magic packet
MagicYUV
mail server compromise
mail-argenta
mailbox compromise
mailbox permission abuse
mailbox theft
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Stock exchange executive mailbox espionage
MAIN world injection
maintainer compromise
- Injective SDK npm wallet stealer
- Joyfill npm blockchain-RAT compromise
- Mastra
easy-day-jsnpm scope compromise - MrMustard PyPI credential-stealer compromise
- Operation DangerousPassword axios npm compromise
maintainer persona
maintainer-account-compromise
maintainer-compromise
malformed signature
malicious dataset
malicious GPO
malicious package
malicious packages
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Dependabot cross-ecosystem malware advisory alerts
- Flooding Dropper npm campaign
- npm publish-time malware scanning and dual-use declarations
- NullReceiver DPRK-linked npm blockchain-loader wave
- ViteVenom / ChainVeil npm campaign
malicious plugin
malicious releases
malicious signed driver
malvertising
- ACR Stealer
- AI-brand impersonation phishing and malvertising
- Fake Corepack site infostealer and proxyware campaign
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Lucide Proxy npm browser DDoS botnet
- Operation FlutterBridge FlutterShell macOS malvertising
- SourTrade browser-assembled malware malvertising
- StealC / Amadey infrastructure disruption
- TamperedChef-style productivity malware clusters
- Vidar / XMRig Factory-v3 malvertising campaign
malware
- ACR Stealer
- Aeternum
- AI-augmented adversary operations
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BINDCLOAK
- binding.gyp npm CI/CD worm
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- BusySnake Stealer
- CanisterWorm
- Cavern
- ChocoPoC
- CrownX
- Crypto Clipper Tor / USB worm
- DeadLock ransomware
- Direct-to-IP malware communications
- Djinn Stealer
- ENCFORGE
- Fast16
- FDMTP
- forge-jsxy
- GenieLocker
- GigaWiper
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- HOLLOWGRAPH
- IronWorm npm Rust infostealer campaign
- Kimwolf v7
- LabubaRAT
- LurkProxy
- macOS.Gaslight Rust backdoor
- MIXEDKEY
- MODBEACON
- MYRA RAT
- OctLurk
- Operation Endgame SocGholish disruption
- OWAReaper
- PamStealer
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- RedWing
- RemotePE
- RustDuck
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- SCMBANKER
- Showboat
- SilkLurk
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- SprySOCKS
- Starland RAT
- StealC / Amadey infrastructure disruption
- STOCKSTAY
- StrikeShark SharkLoader / Cobalt Strike campaign
- TA4922
- TamperedChef-style productivity malware clusters
- TaskWeaver
- TeamPCP
- TELEPUZ
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Umbrij
- UNC6692 SNOW malware social-engineering campaign
- WLDR agent
- XCSSET
malware analysis
malware delivery
- ClickFix CPaaS API-driven payload delivery
- Fake Corepack site infostealer and proxyware campaign
- FakeGit AgentBaiting and SmartLoader campaign
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Microsoft Q2 2026 email and Teams phishing landscape
- TELEPUZ ClickFix / VIDAR campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
malware framework
- Avalon / CrownX malware framework
- Flying Eagle and Night Dragon Android RAT ecosystem
- OkoBot cryptocurrency-wallet malware framework
malware scanning
Malware-as-a-Service
malware-as-a-service
- LabubaRAT
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- StealC / Amadey infrastructure disruption
malware-signing-as-a-service
MALXMR
man-in-the-middle
managed database
managed file transfer
- Progress ShareFile Storage Zone Controller security threat
- SolarWinds Serv-U CVE-2026-28318 exploitation
managed service provider
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
ManageEngine Endpoint Central
management plane
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Lantronix EDS5000 CVE-2025-67038 exploitation
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Manifest V3
Manifold Security
manufacturing
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Seedworm / MuddyWater
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
Mapbox
marimo
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
Markdown image rendering
marker
MARKETMAKER
marketplace abuse
marketplace trust
MarkiRAT
MarlboroMan
mass disclosure
mass repository cloning
mass scanning
Maven Central
mawesome
Mbed
McAfee Labs
- Silent Swap Google Notes crypto clipper
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
McMx
MCP
- @copilot-mcp/apex macOS infostealer campaign
- Agent localhost control-plane RCE
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019)
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- FakeGit AgentBaiting and SmartLoader campaign
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- Internet-exposed unauthenticated MCP servers
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NadMesh AI-service and cloud-credential botnet
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
MCP configuration
MCP credentials
MCP gateway
MCP stdio command execution
mcp-grafana
MECCHA CHAMELEON
media embed
media processing
media sector
MediaFire
medical research
Mekotio
memfd
memory corruption
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- GitLab Oj notebook-diff authenticated RCE chain
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
memory disclosure
- Citrix NetScaler CVE-2026-8451 memory overread
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
memory implant
memory overflow
memory overread
memory poisoning
- AI-agent memory poisoning
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
memory protection unit
memory-only malware
MEMORY.md
merchant credential theft
mesh VPN
MeshAgent
MeshCentral
Meta Ads
meta-hacking
Metabase
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- Metabase unauthenticated SQL-injection zero-day
MetaMask
Metasploit
METR
MEV bot lure
Mexican banking fraud
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
Mexico
- Exposed WebDAV malware delivery lab and CURP campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SHADOW-AETHER AI-augmented Latin America intrusions
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
MFA
MFA bypass
- 0ktapus phishing campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Azure CLI LSHIY password-spray campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- CitrixBleed session-hijack wave
- Evilginx and device-code phishing open-directory cluster
- Gunra ransomware-as-a-service activity
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- ROADtools
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
MFA fatigue
MFA-bypass
MFT
Miasma
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- AsyncAPI generator / specs Miasma compromise
- binding.gyp npm CI/CD worm
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
MicroLogix 1100
MicroLogix 1400
MicroPython
- COLDCARD predictable-RNG Bitcoin theft risk
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
Microsoft
- Agent localhost control-plane RCE
- AI-agent memory poisoning
- AI-brand impersonation phishing and malvertising
- Azure DevOps MCP pull-request prompt injection
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- CL-STA-1114 / Void Blizzard
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Fox Tempest
- MCP tool-description poisoning
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
Microsoft .NET
Microsoft 365
- Azure CLI LSHIY password-spray campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- HOLLOWGRAPH
- Kali365 device-code phishing expansion
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- O-UNC-066 Entra passkey vishing
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- UNC6671 / BlackFile multi-brand vishing extortion operation
Microsoft 365 Copilot
Microsoft Authentication Broker
Microsoft Azure
Microsoft Copilot Personal
Microsoft Defender
- ASCII smuggling crosses over from AI prompt injection to phishing evasion
- BTR Reforged: weaponizing Microsoft Defender's BTR.sys remediation driver as a kernel primitive
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
Microsoft Defender exclusion
Microsoft Defender Experts
Microsoft Defender Security Research
Microsoft dev tunnels
Microsoft Digital Crimes Unit
Microsoft Edge
Microsoft Edge Add-ons
Microsoft Edge Extensions Security Team
Microsoft Edge masquerade
Microsoft Entra ID
- Azure CLI LSHIY password-spray campaign
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- O-UNC-066 Entra passkey vishing
Microsoft Exchange Server
Microsoft Graph
- HOLLOWGRAPH
- ROADtools
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- Webworm
Microsoft Identity Platform
Microsoft Office SharePoint
Microsoft Security Blog
Microsoft Security Research
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
Microsoft SQL Server
Microsoft Teams
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft Teams external-chat phishing
- Operation BlueDash multi-RMM workplace phishing
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- UNC6692 SNOW malware social-engineering campaign
Microsoft Threat Intelligence
- ACR Stealer
- DeadLock ransomware
- GigaWiper
- macOS ClickFix fingerprinting-gate campaign
- Microsoft Q2 2026 email and Teams phishing landscape
Microsoft typosquat
Microsoft Windows Hardware Compatibility Publisher
Microsoft-signed binary abuse
MicrosoftSystem64
Middle East
- ArcBridge
- BINDCLOAK
- JWR phishing framework (likely The Outsider variant)
- Malicious infrastructure provider concentration
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Showboat
- TELESHIM Middle East government espionage campaign
middleware
Midnight Blizzard
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- ROADtools
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
military logistics
military research
Milo Wallet
Mimikatz
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
- Toy Ghouls GenieLocker ransomware activity
mind virus
Mindgard
Minecraft
Minecraft DDoS
miner dropper
Mini Shai-Hulud
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- AsyncAPI generator / specs Miasma compromise
- Dependabot cross-ecosystem malware advisory alerts
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- npm publish-time malware scanning and dual-use declarations
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
MiniJunk
miniOrange
MiniPlasma
MINIRAT
MINIRECON
Ministry of Finance
- Operation DragonReturn India tax-season DcRAT campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
Ministry of State Security
Ministry of Transport and Communications
MiniUpdate
mint
MIPS embedded devices
Mirage Kitten
- ArcBridge
- BridgeHead
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- NightLedger
Mirage2FA
Mirai
- Malicious infrastructure provider concentration
- NetNut / Popa residential proxy network disruption
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Mirai-derived botnet
missile procurement
missing authentication
Mistic
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Backdoor.Mistic / KongTuke ModeloRAT activity
MISTPEN
MITRE ATLAS
MITRE ATT&CK
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- ASCII smuggling crosses over from AI prompt injection to phishing evasion
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
MITRE ATT&CK T1005
Mitre ATT&CK T1110
MITRE ATT&CK T1562
mixed boolean arithmetic
MIXEDKEY
MLflow
MLTBackdoor
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Backdoor.Mistic / KongTuke ModeloRAT activity
mnemonic theft
mobile
Mobile Access
mobile banking fraud
mobile device management
mobile devices
mobile exploitation
mobile malware
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- RedWing
mobile spyware
MobileIron Sentry
MODAFL
MODBEACON
Model Context Protocol
- Agent localhost control-plane RCE
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019)
- FakeGit AgentBaiting and SmartLoader campaign
- Internet-exposed unauthenticated MCP servers
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NadMesh AI-service and cloud-credential botnet
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
model poisoning
model registry webhooks
model weights
model-level persistence
model-provider abuse
ModeloRAT
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Backdoor.Mistic / KongTuke ModeloRAT activity
modem firmware
ModHeader
modular malware
module-proxy
MOIS
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Cavern
- Cavern Manticore
- Handala
- Iran-linked threat landscape: access optionality and evidence quality
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Seedworm / MuddyWater
Moltbook
Moltbot
Monero
Monero mining
MongoDB
Monster ransomware
monthly security release
MoreQuick
Motorola E13
MoYu
Mozi
MpClient.dll
mpengine
MpEngine.dll
MpExtMs.exe
MPK
MPR network provider
Mr_Rot13
MS-ISAC
Ms36-AcCeSs
msaRAT
MSBuild
msgpack
mshta
- ACR Stealer
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- UAT-11795 Starland / WLDR campaign
MSI
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- StealC / Amadey infrastructure disruption
msiexec
MSNightmare
MSP
- ConnectWise ScreenConnect exploitation wave
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
MSSQL
MSXML2.XMLHTTP
mTLS
MU plugin
Muck and Load
MuddyWater
- Cavern Manticore
- Iran-linked threat landscape: access optionality and evidence quality
- Langflow CVE-2025-34291 exploitation
- Seedworm / MuddyWater
Mullvad VPN
multi-agent
Multi-Domain Security Management
multi-model ensemble
multi-organization PAT campaign
multi-SAN certificate
multi-tenant cloud
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Januscape KVM CVE-2026-53359 guest-to-host escape
multi-tenant isolation
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT
- LangGraph checkpointer and namespace trust boundaries
multiplex queries
Multiply-With-Carry
Mustang Panda
- FDMTP
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- QuickFox FDMTP software supply-chain compromise
Mustard Tempest
mutable tags
mutation attacks
mutex
mwEmbed
mwEmbedLoader.php
Myanmar
MYRA
MySQL
Mysterious Elephant
Mythos
N-able
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
N-central
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
n8n
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- NadMesh AI-service and cloud-credential botnet
Nacos
- JADEPUFFER Langflow agentic ransomware
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- WP-SHELLSTORM webshell access brokerage
NadMesh
named pipes
Named Pipes
namespace recycling
namespace squatting
NanChat
Nanjing Xinjiuwei
NAS targeting
nation-state
national identity records
native addon
native extension
NativeAOT
NATO
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Russian state IP-camera military-logistics espionage
NATS
NCSC-NL
Nebo
Nebula Security
Negotiate
negotiation
NemoClaw
Neo-reGeorg
neocloud
nested virtualization
Neteller
Netherlands
- Dutch Police / NCSC 17-million-device botnet disruption
- Russian state IP-camera military-logistics espionage
NetKeyboard
Netlify
Netlify abuse
NetNut
NetScaler
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- CitrixBleed session-hijack wave
NetScaler ADC
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
NetScaler Gateway
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
NetSetup.log
network access
network detection
network infrastructure
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
network infrastructure exploitation
network isolation bypass
network policies
network switch
network-share exfiltration
NexShield
Next.js
NextChat
Nextcloud
Nextcloud Flow
Nexus 9000
nf_tables
NFS
nftables
NGINX
Nginx
Nginx module
ngrok
Ngrok C2
NIC impersonation
Nigeria-nexus
Night Dragon
NightLedger
Nightmare-Eclipse
Nim
Nimbus Manticore
NirSoft
no active exploitation
no attribution
no C2
no credential theft
no vendor response
no-install-hook delivery
No-IP
node-gyp
node-ipc
node-pty
Node-RED
node.exe
Node.js
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Fake Corepack site infostealer and proxyware campaign
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- Joyfill npm blockchain-RAT compromise
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- nodemon-sudo / tslint-conf runtime npm backdoor
- Seedworm / MuddyWater
- TaskWeaver
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
Node.js implant
Node.js malware
node:zlib
NodeEdgeRAT
NomadRAT
non-standard protocol abuse
North Korea
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- Kimsuky / Emerald Sleet / TA427
- Lazarus-linked Rollup polyfill npm malware
- macOS.Gaslight Rust backdoor
- NullReceiver DPRK-linked npm blockchain-loader wave
- Operation DangerousPassword axios npm compromise
- PolinRider cross-ecosystem supply-chain campaign
- RemotePE
- ScarCruft Yanbian game-platform supply-chain attack
- StegaBin Pastebin-steganography npm campaign
- UNK_DeadDrop developer repository phishing
- Void Dokkaebi
notarized malware
- CrashStealer macOS notarized-dropper campaign
- Operation FlutterBridge FlutterShell macOS malvertising
notebook security
notebookjs
notification interception
NOVA
NovaCookies
NoviSpy
Now Platform
npm
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- Alibaba developer-targeted distributed npm RAT campaign
- art-template Coruna-style iOS watering-hole compromise
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- codexui-android OpenAI token stealer
- Dependabot cross-ecosystem malware advisory alerts
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Flooding Dropper npm campaign
- forge-jsxy
- GitHub / Packagist postinstall hook campaign
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Immobiliare Labs Backstage plugins npm compromise
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- jscrambler npm preinstall stealer
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Lucide Proxy npm browser DDoS botnet
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MYRA RAT
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- node-ipc 2026 npm maintainer-account compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- NullReceiver DPRK-linked npm blockchain-loader wave
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- Solana FakeFix npm / PyPI developer stealer
- StegaBin Pastebin-steganography npm campaign
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- TeamPCP
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
- ViteVenom / ChainVeil npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
- wshu.net npm credential-stealer campaign
npm lifecycle hook
- Mastra
easy-day-jsnpm scope compromise - Operation DangerousPassword axios npm compromise
- procwire / routecraft npm Windows dropper
npm mirrors
npm supply-chain
npm token theft
npm tokens
npm v12
npmmirror
npx
npx confusion
NSA
NSecKrnl.sys
NSO Group
nsppe
NTDS.dit
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Storm-2603 parallel SharePoint ransomware intrusion
NTFS ADS
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAC-0226 / SHADOW-EARTH-066
NTLM
NTLM relay
nuclear procurement
nuclear research
nuclear weapons
NuGet
- Braintree.Net NuGet payment skimmer
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Sicoob.Sdk NuGet banking certificate stealer
Nuitka
null byte truncation
null-byte padding
NullReceiver
NullSessionPipes
NVD
NVD scoring
NVGRE
NVIDIA
NVIDIA impersonation
NX-OS
O-UNC-066
OAST
OAuth
- Azure CLI LSHIY password-spray campaign
- Browser-based developer IDE OAuth token theft
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
OAuth 2.1
OAuth abuse
OAuth client credentials
OAuth device authorization grant
OAuth error redirect
OAuth phishing
OAuth redirect
OAuth token abuse
OAuth token exposure
OAuth token theft
OAuth tokens
- codexui-android OpenAI token stealer
- GitHub API enumeration and access-token abuse
- Klue Salesforce OAuth token abuse
OBF networks
obfuscation
obfuscator.io
ObjectInputStream
Oblivion
obsolete software
OCI registry
OCR content analysis
OctLurk
Octopi365
OFAC
- Funnull RingH23 and MacCMS supply-chain attacks
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
Office macros
official store compromise
Offshore LC
OIDC
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- AsyncAPI generator / specs Miasma compromise
- ChainDrop keyv / cacheable npm worm
- Claude Code GitHub Action prompt-injection boundary
- codfish semantic-release-action tag compromise
- GitHub Actions OIDC subject-claim collisions
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
OilRig
Oj
OkoBot
Okta
- 0ktapus phishing campaign
- JINX-0163 / FulcrumSec
- Kali365 device-code phishing expansion
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- Okta support-system compromise
- UNC6671 / BlackFile multi-brand vishing extortion operation
Okta Threat Intelligence
OKX
Ollama
- NadMesh AI-service and cloud-credential botnet
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
- Ollama P2P cryptominer RAT campaign
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
OLLAMA_HOST
Oman
Omnibox
OmniStealer
Omnivore
one-click
OneDrive
- Stock exchange executive mailbox espionage
- UNC6671 / BlackFile multi-brand vishing extortion operation
- Webworm
OneDrive access
OneDrive C2
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
onion routing
Ontinue
opaque predicates
open directory
Open Interpreter
open registration
Open VSX
Open WebUI
open-source
open-source supply chain
open-source-malware
OpenAI
- Hugging Face autonomous-agent production intrusion
- JetBrains AI plugin API-key theft
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
OpenAI API keys
OpenAI Codex
OpenAI Daybreak
OpenClaw
- Agent localhost control-plane RCE
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
opencode
OpenConnect
OpenHands
OpenSearch
OpenShell
OpenShield
OpenSourceMalware
OpenSSF
OpenSSH
openssl_verify
OpenVPN
OpenVPN-shaped UDP
OpenVSX
- Glassworm developer supply-chain botnet
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
OpenWebUI
OpenWrt
- ENDLESSDOORS implant in Zbtlink router firmware
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
operation
- ChocoPoC fake PoC supply-chain campaign
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- ToddyCat Umbrij Gmail OAuth operation
Operation BlueDash
Operation CameraSwarm
Operation DangerousPassword
Operation Dream Job
Operation Economic Outcast
Operation Endgame
Operation Escaneo
Operation Highland
operational relay box
Operational Relay Box
operational resilience
operational security
operational technology
operations
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- 0ktapus phishing campaign
- 3CX desktop app compromise
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Accellion FTA exploitation campaign
- actions-cool GitHub Actions tag compromise
- Adblock for YouTube BadBlocker remote-script injection risk
- Adobe ColdFusion APSB26-68 CVE bonanza
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI token-jacking transfer-station abuse
- Alibaba developer-targeted distributed npm RAT campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- Anthropic cyber-evaluation real-world intrusions
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Argo CD repo-server unauthenticated RCE
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Armored Likho BusySnake campaign
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- art-template Coruna-style iOS watering-hole compromise
- AryStinger legacy-router recon proxy network
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Avalon / CrownX malware framework
- Azure CLI LSHIY password-spray campaign
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Barracuda ESG zero-day backdoor campaign
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Brazilian education LockBit, DragonForce, and insider incidents
- BTR Reforged: weaponizing Microsoft Defender's BTR.sys remediation driver as a kernel primitive
- BufferZoneCorp RubyGems / Go module CI poisoning
- C0XMO Gafgyt DD-WRT botnet
- CanisterWorm
- CCleaner signed-update compromise
- ChainDrop keyv / cacheable npm worm
- Check Point VPN CVE-2026-50751 exploitation
- Chinese-language PhaaS wallet-tokenization ecosystem
- Chrome live-wallpaper extension ad-fraud network
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- CircleCI 2023 customer secret exposure incident
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- CitrixBleed session-hijack wave
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping
- CL-STA-1062 Southeast Asia government and energy intrusions
- ClickFix CPaaS API-driven payload delivery
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- COLDCARD predictable-RNG Bitcoin theft risk
- ConnectWise ScreenConnect exploitation wave
- Contagious Interview SVG-steganography OtterCookie campaign
- Cosmos EVM vesting-account balance overflow exploited across six chains (GHSA-7g4w-cg88-2cq2, Aug 20–25, 2026)
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- Crypto Clipper Tor / USB worm
- DAEMON Tools Lite supply-chain compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- DCloud Uni-App scam infrastructure ecosystem
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet via TWCore updaters
- Drupal Core CVE-2026-9082 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- ENDLESSDOORS implant in Zbtlink router firmware
- Everest Forms Pro CVE-2026-3300 exploitation
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Fastjson CVE-2026-16723 active exploitation
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Flooding Dropper npm campaign
- Flying Eagle and Night Dragon Android RAT ecosystem
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GHOST STADIUM FIFA World Cup ticket phishing
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- Gitea Docker CVE-2026-20896 probing
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- GitLab Oj notebook-diff authenticated RCE chain
- Glassworm developer supply-chain botnet
- GodDamn ransomware PoisonX BYOVD activity
- Gogs CVE-2026-52813 path-traversal RCE (and CVE-2026-52810 push bypass, GHSA-6vxv-wg6j-5qwp XSS)
- GoSerpent Southeast Asia espionage campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Gravity SMTP CVE-2026-4020 exploitation
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- HelloNet ViPNet update-system campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hugging Face autonomous-agent production intrusion
- Hunt.io global smishing infrastructure campaign
- Ill Bloom CryptoJS wallet-drain campaign
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JADEPUFFER Langflow agentic ransomware
- Januscape KVM CVE-2026-53359 guest-to-host escape
- JDY SOHO / IoT reconnaissance botnet
- JetBrains AI plugin API-key theft
- JetBrains TeamCity CVE-2026-63077 active exploitation
- JINX-0164 crypto developer infrastructure campaign
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- JWR phishing framework (likely The Outsider variant)
- Kairos data-extortion government payment
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- LiteLLM compromise
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Lucide Proxy npm browser DDoS botnet
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Mastra
easy-day-jsnpm scope compromise - MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Megalodon GitHub Actions workflow backdooring
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Mini Shai-Hulud npm/PyPI worm campaign
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- node-ipc 2026 npm maintainer-account compromise
- NullReceiver DPRK-linked npm blockchain-loader wave
- Nx Console VS Code extension compromise
- OctLurk and SilkLurk Central Asia espionage campaign
- Okta support-system compromise
- Ollama P2P cryptominer RAT campaign
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation BlueDash multi-RMM workplace phishing
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Operation DangerousPassword axios npm compromise
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Operation Endgame SocGholish disruption
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation Muck and Load GitHub lure network
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- Outsider Enterprise smishing PhaaS
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- Patriot Bait AI-assisted C2 botnet
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
- Perplexity AI-spoofing Chromium extension search hijacker
- Photo ZIP hospitality Node.js implant campaign
- Pirated media SilentCryptoMiner RAT campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- PraisonAI CVE-2026-44338 rapid exploitation
- procwire / routecraft npm Windows dropper
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- QuickFox FDMTP software supply-chain compromise
- REF6045 / SCMBANKER Mexican banking fraud
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- ScreenConnect freeware / AsyncRAT SEO campaign
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- Siemens ROX II zero-day exploit chain
- Silent Swap Google Notes crypto clipper
- simonecorsi/mawesome GitHub Action compromise
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- SleeperGem RubyGems maintainer-account compromise
- SolarWinds Serv-U CVE-2026-28318 exploitation
- SourTrade browser-assembled malware malvertising
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- Storm-2603 parallel SharePoint ransomware intrusion
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TamperedChef-style productivity malware clusters
- TeamPCP
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Telnyx PyPI TeamPCP compromise
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- Thailand healthcare RAR / Python stealer campaign
- tj-actions and reviewdog compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trend Micro Apex One CVE-2026-34926 exploitation
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
- Turla STOCKSTAY backdoor operations
- TuxBot v3 Evolution IoT botnet framework
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795 Starland / WLDR campaign
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UNC6671 / BlackFile multi-brand vishing extortion operation
- Unisoc VoLTE video-call exploit chain: modem RCE to full Android kernel access
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
- UNK_DeadDrop developer repository phishing
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- VerdantBamboo appliance BRICKSTORM operation
- ViteVenom / ChainVeil npm campaign
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- Water-sector PLC configuration-tampering campaign
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
- WhatsApp VBScript ManageEngine RMM campaign
- Windmill CVE-2026-29059 active exploitation
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- wshu.net npm credential-stealer campaign
- XCSSET v40 Xcode supply-chain campaign
- Xinference PyPI compromise
- XZ Utils backdoor
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
operator lockout
OpFauxSign
opportunistic exploitation
opportunistic scanning
ops
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- 0ktapus phishing campaign
- 3CX desktop app compromise
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Accellion FTA exploitation campaign
- actions-cool GitHub Actions tag compromise
- Adblock for YouTube BadBlocker remote-script injection risk
- Adform Trackpoint JavaScript supply-chain crypto clipper
- Adobe ColdFusion APSB26-68 CVE bonanza
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI token-jacking transfer-station abuse
- Alibaba developer-targeted distributed npm RAT campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- Anthropic cyber-evaluation real-world intrusions
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Argo CD repo-server unauthenticated RCE
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Armored Likho BusySnake campaign
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- art-template Coruna-style iOS watering-hole compromise
- AryStinger legacy-router recon proxy network
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Avalon / CrownX malware framework
- Azure CLI LSHIY password-spray campaign
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Barracuda ESG zero-day backdoor campaign
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Braintree.Net NuGet payment skimmer
- Brazilian education LockBit, DragonForce, and insider incidents
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- BTR Reforged: weaponizing Microsoft Defender's BTR.sys remediation driver as a kernel primitive
- BufferZoneCorp RubyGems / Go module CI poisoning
- C0XMO Gafgyt DD-WRT botnet
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- CCleaner signed-update compromise
- ChainDrop keyv / cacheable npm worm
- Check Point VPN CVE-2026-50751 exploitation
- Chinese-language PhaaS wallet-tokenization ecosystem
- ChocoPoC fake PoC supply-chain campaign
- Chrome live-wallpaper extension ad-fraud network
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- CircleCI 2023 customer secret exposure incident
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on 10 Silicon One-based switches — plus a 7-CVE IOS XR hardening release
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- CitrixBleed session-hijack wave
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping
- CL-STA-1062 Southeast Asia government and energy intrusions
- CL-STA-1114 Zimbra webmail espionage
- ClickFix CPaaS API-driven payload delivery
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- COLDCARD predictable-RNG Bitcoin theft risk
- ConnectWise ScreenConnect exploitation wave
- Contagious Interview SVG-steganography OtterCookie campaign
- Cosmos EVM vesting-account balance overflow exploited across six chains (GHSA-7g4w-cg88-2cq2, Aug 20–25, 2026)
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- CrashStealer macOS notarized-dropper campaign
- Crypto Clipper Tor / USB worm
- DAEMON Tools Lite supply-chain compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- DCloud Uni-App scam infrastructure ecosystem
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet via TWCore updaters
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- Drupal Core CVE-2026-9082 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- ENDLESSDOORS implant in Zbtlink router firmware
- Everest Forms Pro CVE-2026-3300 exploitation
- Evilginx and device-code phishing open-directory cluster
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Fastjson CVE-2026-16723 active exploitation
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Flooding Dropper npm campaign
- Flying Eagle and Night Dragon Android RAT ecosystem
- Forg365 Microsoft 365 PhaaS
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GHOST STADIUM FIFA World Cup ticket phishing
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- Gitea Docker CVE-2026-20896 probing
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub Security Advisories August 27, 2026: Crossplane cosign signature-verification bypass and Silverstripe RCE batch
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- GitLab Oj notebook-diff authenticated RCE chain
- Glassworm developer supply-chain botnet
- GodDamn ransomware PoisonX BYOVD activity
- Gogs CVE-2026-52813 path-traversal RCE (and CVE-2026-52810 push bypass, GHSA-6vxv-wg6j-5qwp XSS)
- GoSerpent Southeast Asia espionage campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Gravity SMTP CVE-2026-4020 exploitation
- Gunra ransomware-as-a-service activity
- HackerBot Claw GitHub Actions exploitation campaign
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- HelloNet ViPNet update-system campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hugging Face autonomous-agent production intrusion
- Hunt.io global smishing infrastructure campaign
- Ill Bloom CryptoJS wallet-drain campaign
- Immobiliare Labs Backstage plugins npm compromise
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JADEPUFFER Langflow agentic ransomware
- Januscape KVM CVE-2026-53359 guest-to-host escape
- JDY SOHO / IoT reconnaissance botnet
- JetBrains AI plugin API-key theft
- JetBrains TeamCity CVE-2026-63077 active exploitation
- JINX-0164 crypto developer infrastructure campaign
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- jscrambler npm preinstall stealer
- JWR phishing framework (likely The Outsider variant)
- Kairos data-extortion government payment
- Kali365 device-code phishing expansion
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- Klue Salesforce OAuth token abuse
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- LiteLLM compromise
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Lucide Proxy npm browser DDoS botnet
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Mastra
easy-day-jsnpm scope compromise - MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Megalodon GitHub Actions workflow backdooring
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Mini Shai-Hulud npm/PyPI worm campaign
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- ModHeader browser-extension surveillance capability
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- node-ipc 2026 npm maintainer-account compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- NuGet game-cheat DotnetTool pepesoft campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
- Nx Console VS Code extension compromise
- O-UNC-066 Entra passkey vishing
- OctLurk and SilkLurk Central Asia espionage campaign
- OkoBot cryptocurrency-wallet malware framework
- Okta support-system compromise
- Ollama P2P cryptominer RAT campaign
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation BlueDash multi-RMM workplace phishing
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Operation DangerousPassword axios npm compromise
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Operation Endgame SocGholish disruption
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation Muck and Load GitHub lure network
- Operation Phnom Penh MODBEACON activity
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- Outsider Enterprise smishing PhaaS
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- Pakistani law enforcement espionage convergence
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- Patriot Bait AI-assisted C2 botnet
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
- Perplexity AI-spoofing Chromium extension search hijacker
- Photo ZIP hospitality Node.js implant campaign
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- Pirated media SilentCryptoMiner RAT campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- PostGREShell: PostgreSQL 12-year-old logical-decoding flaw turns a REPLICATION account into server code execution — CVE-2026-6471
- PraisonAI CVE-2026-44338 rapid exploitation
- procwire / routecraft npm Windows dropper
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
- Quest KACE SMA CVE-2025-32975 exploitation
- QuickFox FDMTP software supply-chain compromise
- RedWing mobile MaaS Android bank-fraud operation
- REF6045 / SCMBANKER Mexican banking fraud
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- ScreenConnect freeware / AsyncRAT SEO campaign
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- Siemens ROX II zero-day exploit chain
- Silent Swap Google Notes crypto clipper
- simonecorsi/mawesome GitHub Action compromise
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- SleeperGem RubyGems maintainer-account compromise
- Solana FakeFix npm / PyPI developer stealer
- SolarWinds Serv-U CVE-2026-28318 exploitation
- SourTrade browser-assembled malware malvertising
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- StegoAd Edge extension steganography campaign
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- Stock exchange executive mailbox espionage
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- Storm-2603 parallel SharePoint ransomware intrusion
- StrikeShark SharkLoader / Cobalt Strike campaign
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TA488 OWAReaper and CVE-2026-42897 exploitation
- TamperedChef-style productivity malware clusters
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Telnyx PyPI TeamPCP compromise
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- Thailand healthcare RAR / Python stealer campaign
- tj-actions and reviewdog compromise
- ToddyCat Umbrij Gmail OAuth operation
- Toy Ghouls GenieLocker ransomware activity
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trend Micro Apex One CVE-2026-34926 exploitation
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
- Turla STOCKSTAY backdoor operations
- TuxBot v3 Evolution IoT botnet framework
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- UAT-11795 Starland / WLDR campaign
- UAT-7810 LONGLEASH ORB network expansion
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
- UNC6671 / BlackFile multi-brand vishing extortion operation
- UNC6692 SNOW malware social-engineering campaign
- Unisoc VoLTE video-call exploit chain: modem RCE to full Android kernel access
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
- UNK_DeadDrop developer repository phishing
- UNK_MassTraction Roundcube university mailserver campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- VerdantBamboo appliance BRICKSTORM operation
- Vidar / XMRig Factory-v3 malvertising campaign
- ViteVenom / ChainVeil npm campaign
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- Water-sector PLC configuration-tampering campaign
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
- WhatsApp VBScript ManageEngine RMM campaign
- Windmill CVE-2026-29059 active exploitation
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- WP-SHELLSTORM webshell access brokerage
- wshu.net npm credential-stealer campaign
- XCSSET v40 Xcode supply-chain campaign
- Xinference PyPI compromise
- XZ Utils backdoor
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
OPSEC failure
opsec failure
OpSec failure
OPSWAT
Oracle
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
Oracle E-Business Suite
Oracle Fusion Middleware
Oracle HTTP Server
Oracle Payments
Oracle PeopleSoft
Oracle WebLogic Server
- Oracle WebLogic CVE-2024-21182 exploitation
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
ORANGETAIL
ORB network
organization username
OS command injection
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
OT
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Iran-linked threat landscape: access optionality and evidence quality
- KNX Protocol CVE-2023-4346 KEV exploitation
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
OT switches
OTA update
OTP interception
OtterCookie
Ousaban
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Exilware: Brazilian IAB operation behind BraZetsu and the "Infected Marketplace"
out-of-bounds read
out-of-bounds write
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- GitLab Oj notebook-diff authenticated RCE chain
outbound C2
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
Outlook
Outlook Web Access
Outsider Enterprise
overfitting
overlay attacks
OWA
OWAReaper
ownCloud
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
OX Security
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- MCP stdio command-execution boundary
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
OxideHarvest
OYSTERBLUES
OYSTERFRESH
OYSTERSHUCK
P2P
P2P botnet
P2P C2
P2P relay
P2P sinkhole
p2pwn
package fork
package hijacking
package masquerading
package name reuse
package registry
- Braintree.Net NuGet payment skimmer
- Flooding Dropper npm campaign
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- Mastra
easy-day-jsnpm scope compromise - Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Operation DangerousPassword axios npm compromise
- Telnyx PyPI TeamPCP compromise
package registry abuse
package registry credentials
package registry proxy
package republishing
package scanning
package takedown
package-cooldowns
package-manager-hardening
package-splitting
package-takeover
Packagist
- Famous Chollima Packagist dev-branch loader
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Laravel-Lang Composer tag-rewrite compromise
- PolinRider cross-ecosystem supply-chain campaign
packet injection
PAExec
Page Builder CK
page cache
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
page poisoning
paired session
Pakistan
- FishMonger
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Pakistani law enforcement espionage convergence
- SprySOCKS
Pakistan-aligned
Pakistan-linked
Palo Alto Networks
PAM
PAM credential validation
PamStealer
PAN-OS
Pandora RC
PaperCut
PaperCut MF
PaperCut NG
parallel agent orchestration
parallel-intrusion
parameter-to-prompt
parked domain
partial encryption
Pass-ta-key
pass-the-cookie
passive backdoor
passkeys
password manager theft
password reset
password spray
password spraying
- Azure CLI LSHIY password-spray campaign
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- FortiBleed Fortinet credential exposure
- Patriot Bait AI-assisted C2 botnet
password-protected archive
passwordless authentication
Pastebin
pastebin C2
PAT theft
patch bypass
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
patch management
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
Patch the Planet
patch window
patch-now
PATCHCORD
patching
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on 10 Silicon One-based switches — plus a 7-CVE IOS XR hardening release
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- PostGREShell: PostgreSQL 12-year-old logical-decoding flaw turns a REPLICATION account into server code execution — CVE-2026-6471
patchstack
Patchstack
path hijacking
path traversal
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Gogs CVE-2026-52813 path-traversal RCE (and CVE-2026-52810 push bypass, GHSA-6vxv-wg6j-5qwp XSS)
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
- Windmill CVE-2026-29059 active exploitation
Patriot Bait
patterns
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- AI browser-extension confused deputy
- AI scanner anti-analysis
- AI-agent memory poisoning
- AI-augmented adversary operations
- AI-brand impersonation phishing and malvertising
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- ASCII smuggling crosses over from AI prompt injection to phishing evasion
- Atlassian Rovo prompt-to-data exfiltration
- Attackers turn the trusted Node.js runtime into a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec, Sep 4, 2026) - Azure DevOps MCP pull-request prompt injection
- Benchmaxxing: when a benchmark becomes the target
- Browser-based developer IDE OAuth token theft
- Claude Code GitHub Action prompt-injection boundary
- ClickOnce COM hijacking abuse
- Cloud bucket namespace hijacking
- Cloud logging control-plane tampering
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- Coding-agent-parented tunnels and persistence
- Crypto supply-chain path to transaction authority
- Cursor Windows workspace-path binary hijack
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Direct-to-IP malware communications
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- GitHub API enumeration and access-token abuse
- GuardFall AI-agent shell-guard bypass
- Internet-exposed unauthenticated MCP servers
- LangGraph checkpointer and namespace trust boundaries
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Malicious infrastructure provider concentration
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- Microsoft Teams external-chat phishing
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- Phantom squatting: AI-hallucinated domains
- Sentry MCP Agentjacking
- State divergence enables unauthorized access: Provenance marker module anyone-can-pass check
- State of AI-enabled malware, August 2026 (Unit 42)
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
- Synced passkey theft after endpoint compromise
- Trusted collaboration-channel identity abuse
- Unit 42 NOVA: frontier-AI autonomous zero-day discovery collapses the patch window
- Vertex AI staging-bucket squatting
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
- Webmail CSS trust-boundary attacks
Paweł Płatek
payload loader
payload staging
payload storage
payload-as-a-service
payment fraud
payment SDK
payment skimmer
payment workflow exposure
payment-card theft
payment-card-theft
- Hunt.io global smishing infrastructure campaign
- JWR phishing framework (likely The Outsider variant)
- Outsider Enterprise smishing PhaaS
PayPal
payroll lures
Paysafe
pc-app.exe
PCM
pe_to_shellcode
pearl-miner
PEB hash
PebbleDash
pedit
peer list
Pegasus
pentesting
people
people and process
PeopleTools
PEP 723
PerfWatson2.exe
Perplexity AI
persistence
- @copilot-mcp/apex macOS infostealer campaign
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- ClickOnce COM hijacking abuse
- Flooding Dropper npm campaign
- forge-jsxy
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Mastra
easy-day-jsnpm scope compromise - MrMustard PyPI credential-stealer compromise
- MYRA RAT
- Nx Console VS Code extension compromise
- Ollama P2P cryptominer RAT campaign
- Operation Highland Velvet Ant authentication-stack backdoors
- OWAReaper
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- ROADtools
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- Showboat
- SleeperGem RubyGems maintainer-account compromise
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- Stock exchange executive mailbox espionage
- TamperedChef-style productivity malware clusters
- TeamPCP
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
- Velvet Ant
- Vidar / XMRig Factory-v3 malvertising campaign
- wshu.net npm credential-stealer campaign
persistent root access
persona operations
personal access tokens
PetitPotam
pfSense
pg_hba.conf
PhaaS
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- Chinese-language PhaaS wallet-tokenization ecosystem
- JWR phishing framework (likely The Outsider variant)
- Kali365 device-code phishing expansion
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
Phantom Gyp
- binding.gyp npm CI/CD worm
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
PhantomClick
PhantomCore
PhantomGraph
PhantomMail
PhantomRelay
Philippines
- Operation GriefLure Southeast Asia LNK dropper
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
phishing
- AI-brand impersonation phishing and malvertising
- Avalon / CrownX malware framework
- Chinese-language PhaaS wallet-tokenization ecosystem
- Cloud Atlas
- Dutch Police / NCSC 17-million-device botnet disruption
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Forg365 Microsoft 365 PhaaS
- GHOST STADIUM FIFA World Cup ticket phishing
- Ghostwriter
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Hunt.io global smishing infrastructure campaign
- JWR phishing framework (likely The Outsider variant)
- Kali365 device-code phishing expansion
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Microsoft Q2 2026 email and Teams phishing landscape
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- O-UNC-066 Entra passkey vishing
- Operation BlueDash multi-RMM workplace phishing
- Outsider Enterprise smishing PhaaS
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- Phantom squatting: AI-hallucinated domains
- Photo ZIP hospitality Node.js implant campaign
- RedWing mobile MaaS Android bank-fraud operation
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- Russian intelligence commercial-messaging backup-key phishing
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- TA4922
- UNK_DeadDrop developer repository phishing
phishing evasion
phishing overlays
phishing-as-a-service
- Chinese-language PhaaS wallet-tokenization ecosystem
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- JWR phishing framework (likely The Outsider variant)
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- Outsider Enterprise smishing PhaaS
Phorpiex
PHP
- Famous Chollima Packagist dev-branch loader
- Laravel-Lang Composer tag-rewrite compromise
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
PHP code execution
PHP code injection
PHP object injection
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
PHP upload
PHP web shell
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
physical systems
physics
PicassoLoader
pickle
pig butchering
pig-butchering
PII
PII exposure
PII theft
Pimcore
Pimcore Studio
PINHOLE
PINK
Pink
Pipedream
pipelines
piracy
Piriform
pitboss
Pix
Pixeldrain
PixelSmash
PKGBUILD
PLA
plaintext HTTP
Plandex
PLC
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Water-sector PLC configuration-tampering campaign
PLENET
plugin architecture
plugin framework
plugin RCE
PlugX
- OctLurk and SilkLurk Central Asia espionage campaign
- Pakistani law enforcement espionage convergence
- SilkLurk
- SilkParasite
PNG shellcode
PoC available
PoC exploit refusal
PocSuite3
Pods
poisoned-branch
PoisonX
police digital services
policy-setting abuse
PolinRider
- Astro config blockchain C2 PR injection
- Joyfill npm blockchain-RAT compromise
- PolinRider cross-ecosystem supply-chain campaign
polkitd
Poly1305
polyfill
Polygon
Polygon blockchain dead drop
Polymarket
polymorphic
polymorphic loader
polymorphic payloads
Popa
portmap
PortSwigger Research
Portugal
Portuguese-speaking
post-authentication RCE
post-exploitation
- AI-augmented adversary operations
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Showboat
- TaskWeaver
- WLDR agent
post-exploitation framework
post-index-change
post-mortem
postal-impersonation
PostCSS
PostgreSQL
- Drupal Core CVE-2026-9082 exploitation
- LangGraph checkpointer and namespace trust boundaries
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- PostGREShell: PostgreSQL 12-year-old logical-decoding flaw turns a REPLICATION account into server code execution — CVE-2026-6471
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
postinstall
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - MYRA RAT
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Polymarket npm wallet-drainer packages
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
- wshu.net npm credential-stealer campaign
Potato
POWER.md
PowerCloud
PowerShell
- ACR Stealer
- Armored Likho BusySnake campaign
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- ClickFix CPaaS API-driven payload delivery
- Cloud Atlas
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Fake Corepack site infostealer and proxyware campaign
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- GREYVIBE
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- Oman government Iranian-nexus webshell C2
- Operation BlueDash multi-RMM workplace phishing
- Operation Muck and Load GitHub lure network
- Patriot Bait AI-assisted C2 botnet
- Photo ZIP hospitality Node.js implant campaign
- postcss-minify-selector-parser npm RAT
- Seedworm / MuddyWater
- StealC / Amadey infrastructure disruption
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- TELEPUZ ClickFix / VIDAR campaign
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
- UAT-11795 Starland / WLDR campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- WLDR agent
PowerShell AMSI bypass
PowerShell execution
PowerShell malware
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
PowerShell RAT
PowerShower
PPPoE credential theft
PPtP
PRA
PraisonAI
PRC
- AI-augmented adversary operations
- QTFY: FBI/DoJ seizure of QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure
PRC-aligned
PRC-nexus
pre-auth RCE
pre-authentication
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
pre-authentication RCE
pre-signed URL
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
Prefetch
preinstall
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @withgoogle/stitch-sdk scope squat
- jscrambler npm preinstall stealer
- procwire / routecraft npm Windows dropper
PreppHint
presigned URLs
primary keys
Primary Refresh Token
Primitive Bear
PrincessClub
priority inheritance
privacy
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- Chrome live-wallpaper extension ad-fraud network
privacy exposure
private key theft
private packages
private registry fallback
private-key theft
privilege escalation
- Android Framework CVE-2025-48595 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- Drupal Core CVE-2026-9082 exploitation
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- Siemens ROX II zero-day exploit chain
- Unisoc VoLTE video-call exploit chain: modem RCE to full Android kernel access
- UTA0533 SonicWall SMA1000 zero-day compromise
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
- WP Maps Pro CVE-2026-8732 exploitation
privileged proxy
Privileged Remote Access
PRNG
proc-macro1
proc-macro2
process discovery
process doppelgänging
process environment scraping
process hollowing
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Exposed WebDAV malware delivery lab and CURP campaign
- Pirated media SilentCryptoMiner RAT campaign
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
process injection
- HelloNet ViPNet update-system campaign
- OceanLotus
- OkoBot cryptocurrency-wallet malware framework
- Operation DragonReturn India tax-season DcRAT campaign
- Operation GriefLure Southeast Asia LNK dropper
- Starland RAT
process lineage
process termination
procurement
product lifecycle management
professional services
profile.d
Program Compatibility Assistant
Progress Kemp LoadMaster
Progress Software
Project Lightwell
Project Proposal.exe
prompt infection
prompt injection
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- AI scanner anti-analysis
- AI-agent memory poisoning
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- ASCII smuggling crosses over from AI prompt injection to phishing evasion
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- Claude Code GitHub Action prompt-injection boundary
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
- GuardFall AI-agent shell-guard bypass
- macOS.Gaslight Rust backdoor
- MCP tool-description poisoning
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
prompt-injection
- AI-augmented adversary operations
- HackerBot Claw GitHub Actions exploitation campaign
- SANDWORM_MODE AI-toolchain npm worm
- TrapDoor crypto-stealer cross-ecosystem campaign
prompt-injection guardrail bypass
PromptArmor
PROMPTFLUX
PROMPTSPY
promptware
proof of deletion
Proofpoint
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- UNK_MassTraction Roundcube university mailserver campaign
protestware
Protobuf
Proton Mail
prototype pollution
provenance
Provenance
proxy
- ArcBridge
- BridgeHead
- First VPN
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- LurkProxy
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- PCPJack cloud SMTP relay network
- Showboat
- TamperedChef-style productivity malware clusters
- VPN Go browser-extension clipboard stealer
- Webworm
proxy botnet
proxy infrastructure
proxy network
proxy obfuscation
ProxyChains
proxyjacking
proxyware
prt-scan
PSEMHUB
pseudorandom number generator
PsExec
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Brazilian education LockBit, DragonForce, and insider incidents
- GodDamn ransomware PoisonX BYOVD activity
- Toy Ghouls GenieLocker ransomware activity
PSIGW
psychological operations
PTC
PteroBox
PteroPaste
PteroPSDoor
PteroSetup
PteroVDoor
public exploit
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- MiniPlasma Windows Cloud Filter LPE exploitation
public file-transfer exfiltration
public proof of concept
public sector
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- Kairos data-extortion government payment
- Seedworm / MuddyWater
Public Security Bureau impersonation
public service abuse
public-service C2
publication bias
publish mode
publish-time scanning
publishing credentials
pull requests
PUP
PureLogs Stealer
PureRAT
pushd
pwn-request
PwPt-sHaRe
PyArmor
- Armored Likho BusySnake campaign
- BusySnake Stealer
- NuGet game-cheat DotnetTool pepesoft campaign
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
PyInstaller
PyPI
- Anthropic cyber-evaluation real-world intrusions
- binding.gyp npm CI/CD worm
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Dependabot cross-ecosystem malware advisory alerts
- Glassworm developer supply-chain botnet
- LiteLLM compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Solana FakeFix npm / PyPI developer stealer
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- Telnyx PyPI TeamPCP compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
- Xinference PyPI compromise
Python
- ACR Stealer
- Aeternum
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- Brazilian education LockBit, DragonForce, and insider incidents
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- macOS.Gaslight Rust backdoor
- MrMustard PyPI credential-stealer compromise
- postcss-minify-selector-parser npm RAT
- Seedworm / MuddyWater
- Starland RAT
- Telnyx PyPI TeamPCP compromise
- UAT-11795 Starland / WLDR campaign
- Ulej / Flowerbed
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
- Xinference PyPI compromise
Python extension modules
Python implant
Python malware
Python stealer
python-snap7
pythonw
QEMU
Qianxin Threat Intelligence Center
QiAnXin XLab
- AryStinger legacy-router recon proxy network
- Dysphoria IoT botnet
- NadMesh AI-service and cloud-credential botnet
- RustDuck
Qihoo 360
Qilin
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Check Point VPN CVE-2026-50751 exploitation
- The Gentlemen ransomware
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
QNAP
QR code
QR code interception
QScan
QTBotnet
QTFY
QTRouter
quantum computing
Quasar
query injection
Quest KACE SMA
QUIC
QUICAgent
Quick Assist
QuickFox
QUICSILVER
QuimaRAT
RaaS
RabbitMQ
race condition
RAGFlow
RainbowEx
RakNet flood
RAM disk
random number generator
ransom
Ransom-ISAC
ransomware
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Avalon / CrownX malware framework
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- Brazilian education LockBit, DragonForce, and insider incidents
- Check Point VPN CVE-2026-50751 exploitation
- CrownX
- DeadLock ransomware
- Direct-to-IP malware communications
- ENCFORGE
- First VPN
- Fox Tempest
- GenieLocker
- GodDamn ransomware PoisonX BYOVD activity
- Gunra ransomware-as-a-service activity
- Kairos data-extortion government payment
- State of AI-enabled malware, August 2026 (Unit 42)
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- Storm-2603 parallel SharePoint ransomware intrusion
- The Gentlemen ransomware
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
ransomware access
ransomware enablement
ransomware-access
rapid exploitation
Rapid7
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Exposed WebDAV malware delivery lab and CURP campaign
RAR archives
RAR staging
RAT
- Armored Likho
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- DAEMON Tools Lite supply-chain compromise
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- FDMTP
- forge-jsxy
- Glassworm developer supply-chain botnet
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- GREYVIBE
- JINX-0164 crypto developer infrastructure campaign
- LabubaRAT
- Mastra
easy-day-jsnpm scope compromise - MYRA RAT
- Ollama P2P cryptominer RAT campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- RemotePE
- Screening Serpens
- SilkParasite
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- SprySOCKS
- Starland RAT
- StegaBin Pastebin-steganography npm campaign
- STOCKSTAY
- TamperedChef-style productivity malware clusters
- TinyRCT
- UAT-11795 Starland / WLDR campaign
raw packet
Ray
RC4
- @marketfront / @tqm-mfe dependency-confusion stealer
- OP-512
- StealC / Amadey infrastructure disruption
- UAC-0226 / SHADOW-EARTH-066
RC4 C2
RC4 encryption
RCE
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Agent localhost control-plane RCE
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- GitHub Security Advisories August 27, 2026: Crossplane cosign signature-verification bypass and Silverstripe RCE batch
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- LangGraph checkpointer and namespace trust boundaries
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Vertex AI staging-bucket squatting
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
Rclone
rclone
RCS
RDP
- Brazilian education LockBit, DragonForce, and insider incidents
- GREYVIBE
- Toy Ghouls GenieLocker ransomware activity
RDP phishing
RDS
reachability
Reactor Core
Reactor Netty
readonly proxy
real-time operator control
Reality
Realme C33
Reaper
reasoning replay
Reco
reconnaissance
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- AryStinger legacy-router recon proxy network
- JDY SOHO / IoT reconnaissance botnet
- Open VSX evil-twin extension campaign
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
recovery denial
- Ababil of Minab MOIS-linked recovery-destruction campaign
- DeadLock ransomware
- GodDamn ransomware PoisonX BYOVD activity
recovery disruption
recovery flow
recovery phrase
recruitment lures
Red Agent
Red Dev 10
Red Hat
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Linux pedit COW CVE-2026-46331 local privilege escalation
Red Menshen
Red Offsec
Red Raindrop Team
red team
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
red teaming
REDACT
RedAlert
RedC2
RedC2 4.0
REDCap
Redis
- Argo CD repo-server unauthenticated RCE
- GigaWiper
- LangGraph checkpointer and namespace trust boundaries
- NadMesh AI-service and cloud-credential botnet
- TeamPCP
Redis backdoor
RediSearch
RedShell
reduced cyber refusals
RedWing
REF6045
REF9403
reflective .NET loading
reflective loading
- BINDCLOAK
- Flooding Dropper npm campaign
- MIXEDKEY
- OctLurk
- OctLurk and SilkLurk Central Asia espionage campaign
- SilkLurk
- TELESHIM Middle East government espionage campaign
refresh token theft
refresh tokens
RegAsm process hollowing
registry controls
registry manipulation
registry metadata
registry persistence
- Flooding Dropper npm campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Photo ZIP hospitality Node.js implant campaign
- SideCopy
- The Gentlemen ransomware
- Turla STOCKSTAY backdoor operations
registry Run key
registry storage
registry-controls
RelayShell
release automation
release tampering
Remcos
Remcos RAT
remote access
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- ConnectWise ScreenConnect exploitation wave
- FortiBleed Fortinet credential exposure
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- Lazarus-linked Rollup polyfill npm malware
- Pirated media SilentCryptoMiner RAT campaign
- WhatsApp VBScript ManageEngine RMM campaign
remote access software
remote access trojan
- Alibaba developer-targeted distributed npm RAT campaign
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- GoSerpent Southeast Asia espionage campaign
- Joyfill npm blockchain-RAT compromise
- LabubaRAT
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
- ViteVenom / ChainVeil npm campaign
Remote Access VPN
remote code execution
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Crypto Clipper Tor / USB worm
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Gogs CVE-2026-52813 path-traversal RCE (and CVE-2026-52810 push bypass, GHSA-6vxv-wg6j-5qwp XSS)
- Hugging Face autonomous-agent production intrusion
- Ivanti Sentry CVE-2026-10520 exploitation
- Joomla JCE CVE-2026-48907 exploitation
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Langflow CVE-2026-0770 exploitation
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- nodemon-sudo / tslint-conf runtime npm backdoor
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- ServiceNow AI Platform CVE-2026-6875 exploitation
- StegoAd Edge extension steganography campaign
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
remote debugging
remote desktop
remote MCP
remote monitoring and management
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- ScreenConnect freeware / AsyncRAT SEO campaign
remote script injection
remote shell
Remote Support
remote support
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
Remote Utilities
remote-access
Remotely
RemotePE
RemotePELoader
removable media
Rentry
replication
REPLICATION attribute
repo-server
repository compromise
repository exfiltration
repository poisoning
- Amazon Q CVE-2026-12957 MCP auto-execution
- Claude Code GitHub Action prompt-injection boundary
- FakeGit AgentBaiting and SmartLoader campaign
request smuggling
research sector
reset-credentials
residential proxies
residential proxy
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet via TWCore updaters
- NetNut / Popa residential proxy network disruption
residential proxy abuse
responsible disclosure
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
REST API
REST C2
restart-triggered execution
retail
retail trading
reverse proxy
reverse SOCKS5
reverse SSH tunnel
reverse SSH tunneling
reverse tunnel
reverse tunneling
reverse tunnels
REVERSE_PROXY_TRUSTED_PROXIES
ReverseSocks
reviewdog
reward hacking
Rewards for Justice
RHBK
Rhysida
Rilide
Ring 0
RingH23
RMM
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- UNC3753
RMM abuse
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Cavern
- Cavern Manticore
- Evilginx and device-code phishing open-directory cluster
- Iran-linked threat landscape: access optionality and evidence quality
- Operation BlueDash multi-RMM workplace phishing
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- ScreenConnect freeware / AsyncRAT SEO campaign
- TaskWeaver
- WhatsApp VBScript ManageEngine RMM campaign
ROADrecon
ROADtools
roadtx
Robbe Van Roey
Rockwell Automation
RoguePlanet
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
Rokarolla
RokRAT
rolling deploy
Rollup
Romania
RomulusLoader
Roo-Code
root
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
root access
root code execution
- Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on 10 Silicon One-based switches — plus a 7-CVE IOS XR hardening release
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
root escalation
root execution
root RCE
root shell
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
rootkit
- Atomic Arch AUR package hijack
- Funnull RingH23 and MacCMS supply-chain attacks
- IronWorm npm Rust infostealer campaign
- MYRA RAT
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
ROOTRUN
Rootstock
ROPC
Rouki obfuscation
Roundcube
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- UNK_MassTraction Roundcube university mailserver campaign
router
router compromise
- Dysphoria IoT botnet
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- UAT-7810 LONGLEASH ORB network expansion
router malware
Rovo
- Atlassian Rovo prompt-to-data exfiltration
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
RovoBlast
ROX II
RRWallet
RSA
RSA public key
RSA-2048
RSA-OAEP
RT-Thread
RTL819X
RTLO
rtmutex
RubyGems
- binding.gyp npm CI/CD worm
- BufferZoneCorp RubyGems / Go module CI poisoning
- SleeperGem RubyGems maintainer-account compromise
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
Ruckus routers
Ruflo
RUGGEDCOM
Run key
Run key persistence
rundll32
- ACR Stealer
- StealC / Amadey infrastructure disruption
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
Runner.Worker
Runspace
runtime execution
runtime mutation
runtime patching
runZero
Russia
- APT29
- Armored Likho
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Cloud Atlas
- Dragonfly
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- HelloNet ViPNet update-system campaign
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- Russian state IP-camera military-logistics espionage
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
Russia targeting
Russia-affiliated
Russia-linked
Russia-linked cybercrime
Russia-nexus
Russia-speaking operator
Russian Intelligence Services
Russian intelligence services
Russian state-supported
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
Russian-speaking ecosystem
Russian-speaking forums
Rust
- Atomic Arch AUR package hijack
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
- macOS.Gaslight Rust backdoor
- Operation Dragon Weave Azure Blob C2 campaign
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- RustDuck
- TrapDoor crypto-stealer cross-ecosystem campaign
- wshu.net npm credential-stealer campaign
Rust loader
Rust malware
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- DeadLock ransomware
- Fake-reputation crypto clipboard hijacker
- HelloNet ViPNet update-system campaign
- LabubaRAT
- MODBEACON
- PamStealer
S3 Browser
S3-compatible storage
- Cloud bucket namespace hijacking
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
s5cmd
S7comm
SaaS
- Klue Salesforce OAuth token abuse
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- ShinyHunters
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- Trusted collaboration-channel identity abuse
- UNC6671 / BlackFile multi-brand vishing extortion operation
SaaS abuse
SaaS connectors
SaaS data access
SaaS exposure
- Adblock for YouTube BadBlocker remote-script injection risk
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping
sabotage
Safari
SafeDep
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- MYRA RAT
- nodemon-sudo / tslint-conf runtime npm backdoor
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
Salesforce
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping
- Klue Salesforce OAuth token abuse
- ShinyHunters
- UNC6671 / BlackFile multi-brand vishing extortion operation
Sality
SAML
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
SAML IdP
Samsung TizenRT
sanctions
sandbox escape
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- Hugging Face autonomous-agent production intrusion
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
sandbox evasion
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
sandboxing
Sandworm
Sangoma
Sapphire Sleet
saroula01
SBA phishing
SCADA
scam infrastructure
scambling
scanner evasion
ScarCruft
SCCM
scheduled task
- APT28-linked HOOKEDGE backdoor targets European government and diplomatic organizations
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Crypto Clipper Tor / USB worm
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- StealC / Amadey infrastructure disruption
- TELESHIM
- TELESHIM Middle East government espionage campaign
- TinyRCT
- Vidar / XMRig Factory-v3 malvertising campaign
scheduled task persistence
- Armored Likho BusySnake campaign
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- BusySnake Stealer
- Flooding Dropper npm campaign
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- ScreenConnect freeware / AsyncRAT SEO campaign
scheduled tasks
- ACR Stealer
- GigaWiper
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Stock exchange executive mailbox espionage
- StrikeShark SharkLoader / Cobalt Strike campaign
- The Gentlemen ransomware
SCMBANKER
scope squatting
scoped package impersonation
scorer manipulation
SCOUTCURL
screen capture
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Flying Eagle and Night Dragon Android RAT ecosystem
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- MYRA RAT
- TinyRCT
Screen Sharing
ScreenConnect
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- ConnectWise ScreenConnect exploitation wave
- Operation BlueDash multi-RMM workplace phishing
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- ScreenConnect freeware / AsyncRAT SEO campaign
Screening Serpens
- Iran-linked threat landscape: access optionality and evidence quality
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
screenshot capture
screenshot theft
script injection
script-injection
SD-WAN
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
search hijacking
search poisoning
search result poisoning
search-ms
Seashell Blizzard
second-order injection
secondary sanctions
Secret Blizzard
secret exfiltration
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- TeamPCP
secret exposure
secrets
- Azure DevOps MCP pull-request prompt injection
- binding.gyp npm CI/CD worm
- CircleCI 2023 customer secret exposure incident
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- GitHub Actions deployment poisoning
secrets harvesting
secrets management
secrets manager compromise
SectopRAT
Secure Annex
Secure Firewall
Secure Firewall Management Center
Secure Preferences
Secure Workload
secure.html
Security Management Server
security operations
security platform
security tool abuse
security-tool discovery
SecurityPDF
seed phrase
seed phrase theft
seed recovery
SeedHunter
Seedworm
- Cavern Manticore
- Iran-linked threat landscape: access optionality and evidence quality
- Seedworm / MuddyWater
segmented networks
Sekoia
self-delete
self-DoS
self-hosted AI services
self-hosted applications
self-hosted Git
self-hosted media
self-hosted runner
self-managed
self-propagating payload
self-propagation
semantic-release
sendit.sh
sensitive information exposure
Sentinel
SentinelOne
Sentry
Sentry abuse
SEO fraud
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
SEO poisoning
- ACR Stealer
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI-brand impersonation phishing and malvertising
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Operation Phnom Penh MODBEACON activity
- ScreenConnect freeware / AsyncRAT SEO campaign
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- StealC / Amadey infrastructure disruption
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
Seqrite
Seqrite Labs
- CL-STA-1114 Zimbra webmail espionage
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
Serbia
serial-number relay
Serialize::unserialize
Serv-U
service accounts
service binding
service DLL persistence
service impairment
service persistence
Service Portal
service providers
service stop
service-agent
ServiceNow
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
ServiceNow AI Platform
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- ServiceNow AI Platform CVE-2026-6875 exploitation
ServiceUrl
ServiceWorker
Session
session cookie theft
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
session hijacking
session secret exposure
session theft
- CircleCI 2023 customer secret exposure incident
- FakeGit AgentBaiting and SmartLoader campaign
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
session token theft
setuid
setup.py
shadow AI
shadow copy
shadow copy deletion
shadow fleet
shadow MMU
SHADOW-AETHER
SHADOW-AETHER-040
SHADOW-AETHER-064
SHADOW-EARTH-066
SHADOW-WATER-063
ShadowPad
- CCleaner signed-update compromise
- FishMonger
- Pakistani law enforcement espionage convergence
- SilkParasite
Shadowserver Foundation
Shai-Hulud
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- ChainDrop keyv / cacheable npm worm
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Mini Shai-Hulud npm/PyPI worm campaign
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- SANDWORM_MODE AI-toolchain npm worm
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
SHARDLOADER
SHARE Foundation
share propagation
shared accounts
shared hosting
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
shared memory
shared secrets
shared-module
shared_preload_libraries
SharedWorker
ShareFile
SharePoint
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Storm-2603 parallel SharePoint ransomware intrusion
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- UNC6671 / BlackFile multi-brand vishing extortion operation
SharePoint Server
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
SharkLoader
sharp
Shattering the Dream
SHEETCORD
shell injection
shellcode
Shenzhen Zhibotong Electronics
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
ShieldBreak
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
Shinobi
ShinyHunters
ShinyHunters-adjacent
shipping lures
Shodan
ShortLeash
Shuckworm
side channel
side-loading
SideCopy
sideloading
Siemens
Siemens S7
Sigma Forms Pro
Signal
- Russian intelligence commercial-messaging backup-key phishing
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Signal interception
signature evasion
signature verification
signed binary abuse
signed executable
signed malware
signed updates
signed-binary
signed-binary abuse
SignedInfo
Silent Ransom Group
Silent Swap
silent-patch
SilentCryptoMiner
SilentRunLoader
Silicon One
SiliconFlow
SilkLurk
SilkParasite
Silver Fox
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- MODBEACON
- Operation Phnom Penh MODBEACON activity
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
Silver Pass-ta-key
Silverstripe
SimpleHelp
- Djinn Stealer
- Evilginx and device-code phishing open-directory cluster
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- TaskWeaver
SimpleHelp RAT
SimpleHTTPServer exposure
simulation tampering
sinkhole
sinkholing
SIP
SIP ALG
Site Member permissions
SiYuan
skb
SkillCloak
SkillDetonate
Skrill
Skyvern
Slack webhook
sleep agent
sleeper packages
SLEEPWALKER
Sliver
SLSA
SLSA provenance
SMA1000
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- UTA0533 SonicWall SMA1000 zero-day compromise
smart building
smart contract
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- State divergence enables unauthorized access: Provenance marker module anyone-can-pass check
smart contracts
smart TVs
SMARTAXE
SmartConsole
SmartLoader
SmartScreen
SMB
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PostGREShell: PostgreSQL 12-year-old logical-decoding flaw turns a REPLICATION account into server code execution — CVE-2026-6471
SMB brute force
SMB egress
SMB/USB worm
smishing
- 0ktapus phishing campaign
- Crypto supply-chain path to transaction authority
- Hunt.io global smishing infrastructure campaign
- JWR phishing framework (likely The Outsider variant)
- Outsider Enterprise smishing PhaaS
SMM
Smoke Sandstorm
SMS interception
SMS phishing
SMS theft
sms-phishing
SMTP
SMTP abuse
Snake
snap7
Sneaky 2FA
- Forg365 Microsoft 365 PhaaS
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
Sneaky2FA
SNMP
Snowflake
SNOWLIGHT
SNWLID-2026-0016
SOAP API abuse
SOC
SoC
SocGholish
social abuse
social engineering
- AI-brand impersonation phishing and malvertising
- Chinese-language PhaaS wallet-tokenization ecosystem
- ClickFix CPaaS API-driven payload delivery
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- macOS ClickFix fingerprinting-gate campaign
- Microsoft Teams external-chat phishing
- Polymarket npm wallet-drainer packages
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- Russian intelligence commercial-messaging backup-key phishing
- Screening Serpens
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- State of AI-enabled malware, August 2026 (Unit 42)
- Trusted collaboration-channel identity abuse
- UNC3753
- UNC6692 SNOW malware social-engineering campaign
- Void Dokkaebi
- WhatsApp VBScript ManageEngine RMM campaign
Social Security Administration
social-engineering
Socket
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- jscrambler npm preinstall stealer
- Operation Muck and Load GitHub lure network
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- VPN Go browser-extension clipboard stealer
Socket Security
- Braintree.Net NuGet payment skimmer
- Injective SDK npm wallet stealer
- NuGet game-cheat DotnetTool pepesoft campaign
Socket Security Research
- Chrome live-wallpaper extension ad-fraud network
- Fake Corepack site infostealer and proxyware campaign
Socket.IO
- Contagious Interview SVG-steganography OtterCookie campaign
- Lazarus-linked Rollup polyfill npm malware
SOCKS tunneling
SOCKS5
- BridgeHead
- Cavern
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- GoSerpent Southeast Asia espionage campaign
- LurkProxy
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation Highland Velvet Ant authentication-stack backdoors
- Seedworm / MuddyWater
- Showboat
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
SOCKS5 proxy
SOCKS5 tunneling
SockTz
SOCRadar
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Evilginx and device-code phishing open-directory cluster
- WP-SHELLSTORM webshell access brokerage
SoftEther VPN
SoftPerfect Network Scanner
software impersonation
software supply chain
software-deployment
SOHO router
SOHO routers
Solana
- Glassworm developer supply-chain botnet
- Solana FakeFix npm / PyPI developer stealer
- SourTrade browser-assembled malware malvertising
Solana Name Service
SolarWinds
Solid PDF Creator
SolidPDFCreator.dll
SolidPDFPcl2Bmp
Sonatype
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- Flooding Dropper npm campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
Sonatype Guide
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
sonatype-2026-005660
sonatype-2026-005899
sonatype-2026-005901
sonatype-2026-006746
SonicWall
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- UTA0533 SonicWall SMA1000 zero-day compromise
Sophos
SOUL.md
source code
source control
- Gitea Docker CVE-2026-20896 probing
- GitHub API enumeration and access-token abuse
- GitLab Oj notebook-diff authenticated RCE chain
source repository compromise
source-code compromise
source-control token theft
source-package drift
source-package mismatch
source-repository abuse
source-repository poisoning
- Astro config blockchain C2 PR injection
- Cursor Windows workspace-path binary hijack
- Developer-tool config auto-execution
- Operation Muck and Load GitHub lure network
- PolinRider cross-ecosystem supply-chain campaign
- XCSSET v40 Xcode supply-chain campaign
source-repository reconnaissance
SourceForge abuse
SourTrade
South Africa
South Asia
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- SideCopy
South Korea
- "ted backdoor": DPRK-linked Linux espionage toolkit — HAProxy 2.8.12 trojan plus CurlRAT and SSH keylogger targeting South Korean media and automotive sectors
- Kimsuky / Emerald Sleet / TA427
- Seedworm / MuddyWater
Southeast Asia
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GoSerpent Southeast Asia espionage campaign
- JWR phishing framework (likely The Outsider variant)
- OceanLotus
- Operation GriefLure Southeast Asia LNK dropper
- Showboat
SP Page Builder
Spain
spam
Spark RAT
SPEAKINGSTONE
spear phishing
- Armored Likho
- Armored Likho BusySnake campaign
- Kimsuky / Emerald Sleet / TA427
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- SideCopy
- SilkParasite
- Thailand healthcare RAR / Python stealer campaign
- UAC-0226 / SHADOW-EARTH-066
spear-phishing
spearphishing
Specter
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
SPECTRALVIPER
SPECTRE
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
Spectre
Sphinx ransomware
SpiceRAT
SpiderLabs
Spikey Scorpius
Splunk
Spreadtrum
Spring
Spring AI
Spring AMQP
Spring Batch
Spring Boot
Spring Cloud Config
Spring Data REST
Spring Framework
Spring Integration
Spring Security
SprySOCKS
Spyroid
spyware
SQL injection
- Anthropic cyber-evaluation real-world intrusions
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Drupal Core CVE-2026-9082 exploitation
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- LangGraph checkpointer and namespace trust boundaries
- Metabase unauthenticated SQL-injection zero-day
- Pimcore Studio: five coordinated flaws (Aug 28, 2026) — DataObject field-name RCE (CVE-2026-55634, 9.9), Hotspotimage PHP object injection (CVE-2026-55220), and a three-item privilege-escalation / SQLi / account-takeover set
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
SQL Server
SQLite
- LangGraph checkpointer and namespace trust boundaries
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
SQLite state
SQLRCE0
SquareShell
SSD Secure Disclosure
SSDP
SSH
- C0XMO Gafgyt DD-WRT botnet
- SHADOW-AETHER AI-augmented Latin America intrusions
- Toy Ghouls GenieLocker ransomware activity
- XZ Utils backdoor
SSH backdoor
SSH bastion
SSH brute force
SSH key exposure
SSH key persistence
SSH keylogger
SSH keys
- @copilot-mcp/apex macOS infostealer campaign
- Djinn Stealer
- Fake Corepack site infostealer and proxyware campaign
- MrMustard PyPI credential-stealer compromise
SSH lateral movement
SSH persistence
SSH pivot
SSH tunnel
SSH tunneling
SSH tunnels
sshd
SSL VPN
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- FortiBleed Fortinet credential exposure
- FortiOS CVE-2025-68686 symlink-persistence bypass
SSO
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
SSRF
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019)
- CISA KEV September 2, 2026 additions: seven exploited flaws across Artifactory, Kestra, SonicWall SMA1000, LiteLLM, Starlette, and Switchvox
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- GitHub Actions deployment poisoning
- Internet-exposed unauthenticated MCP servers
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
SSRF allow-list
STAC4749
stack use-after-free
staged malicious update
staged publishing
staking-precompile
stale access
stale credentials
stale state
Starland RAT
Starlette
Startup folder
Startup folder persistence
- MECCHA CHAMELEON: second delayed RCE via custom map — arbitrary file write, HTA-in-WAV payload, Startup persistence (Aikido, Sep 3, 2026)
- Thailand healthcare RAR / Python stealer campaign
state desynchronization
state divergence
state-linked
state-owned enterprise
static AWS keys
static credentials
Static Kitten
stdio
- Agent localhost control-plane RCE
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
StealC
stealer
Steam profile dead drop
Steam Workshop
steering file
steganographic PNG
steganography
- ACR Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- StegoAd Edge extension steganography campaign
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
StegoAd
StepSecurity
- jscrambler npm preinstall stealer
- MrMustard PyPI credential-stealer compromise
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
Still Audio
Still Sync
Still Toolkit
STM32Cube
stock exchange
STOCKSTAY
StopAndProtect
storage deletion
Storage Zone Controller
stored XSS
Storm-2603
Storm-2697
Storm-2945
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
Storm-3075
Stowaway
STRD
streaming boxes
Stripe OLT
structured Markdown
StubMaker
student targeting
STUN
Stuxnet lineage
subject claim
subscription fraud platform
subscription PhaaS
Subtle Snail
SuccessKey
summarization
SUMMIT
Suo5
Supabase
Super Forms
super peer
SUPERADMIN_SECRET
superuser escalation
supply chain
- Braintree.Net NuGet payment skimmer
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- COLDCARD predictable-RNG Bitcoin theft risk
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub API enumeration and access-token abuse
- GitHub Security Advisories August 27, 2026: Crossplane cosign signature-verification bypass and Silverstripe RCE batch
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- MYRA RAT
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- nodemon-sudo / tslint-conf runtime npm backdoor
- NuGet game-cheat DotnetTool pepesoft campaign
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- Solana FakeFix npm / PyPI developer stealer
- State divergence enables unauthorized access: Provenance marker module anyone-can-pass check
- Stealing reasoning traces from proprietary LLM APIs: cross-session encrypted-reasoning replay
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
supply chain compromise
supply-chain
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- 3CX desktop app compromise
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- actions-cool GitHub Actions tag compromise
- Agent skill marketplace poisoning
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- AI-augmented adversary operations
- Alibaba developer-targeted distributed npm RAT campaign
- Anthropic cyber-evaluation real-world intrusions
- APT29
- art-template Coruna-style iOS watering-hole compromise
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Browser-based developer IDE OAuth token theft
- BufferZoneCorp RubyGems / Go module CI poisoning
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- Cosmos EVM vesting-account balance overflow exploited across six chains (GHSA-7g4w-cg88-2cq2, Aug 20–25, 2026)
- Crypto supply-chain path to transaction authority
- DAEMON Tools Lite supply-chain compromise
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Flooding Dropper npm campaign
- forge-jsxy
- Funnull RingH23 and MacCMS supply-chain attacks
- GitHub / Packagist postinstall hook campaign
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- Glassworm developer supply-chain botnet
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JetBrains AI plugin API-key theft
- JiaT75
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- Klue Salesforce OAuth token abuse
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- LiteLLM compromise
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - MCP stdio command-execution boundary
- MCP tool-description poisoning
- Megalodon GitHub Actions workflow backdooring
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- node-ipc 2026 npm maintainer-account compromise
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- NullReceiver DPRK-linked npm blockchain-loader wave
- Nx Console VS Code extension compromise
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- Phantom squatting: AI-hallucinated domains
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- simonecorsi/mawesome GitHub Action compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- TeamPCP
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- Telnyx PyPI TeamPCP compromise
- tj-actions and reviewdog compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
- Vertex AI staging-bucket squatting
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- Void Dokkaebi
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- wshu.net npm credential-stealer campaign
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
- Xinference PyPI compromise
- XZ Utils backdoor
supply-chain attack
supply-chain attribution
supply-chain integrity
supply-chain risk
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
supply-chain-adjacent
surveillance
surveillance abuse
suspected China-aligned
suspected China-linked
SVG
- CL-STA-1114 Zimbra webmail espionage
- Contagious Interview SVG-steganography OtterCookie campaign
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
SWE-agent
SweetPotato
Switchvox
SWUpdate
Symantec
Symantec Threat Hunter Team
symbolic link
symlink following
Synacktiv
Synacor
SynkLoader
Synology
synthetic commits
synthetic voice
Syria
Sysdig
SYSTEM
system prompt
SystemBC
systemd
systemd-userdbd
T1059
T1078
T1102.001
T1190
T1204.004
T1552
T1555
T1566
T1578
T3
T606
T612
T7250
TA427
TA488
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
TA569
Tactical RMM
tag characters
tag rewrite
tag tampering
- actions-cool GitHub Actions tag compromise
- codfish semantic-release-action tag compromise
- simonecorsi/mawesome GitHub Action compromise
- tj-actions and reviewdog compromise
TAG-124
TAG-179
TAG-182
TAG-22
tag-based install
Taiwan
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- FishMonger
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation Dragon Weave Azure Blob C2 campaign
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Tajikistan
Take Control
takedown
- Dutch Police / NCSC 17-million-device botnet disruption
- First VPN
- Glassworm developer supply-chain botnet
TamperedChef
Tanzania
targeted attack
targeted malware
targeted operations
TartarusGate
task queue
task scheduler abuse
TaskWeaver
Tauri
tax forms
tax-season phishing
tc
TCP 43210
TCP 43211
TCP traffic diversion
tdata
TDS
Team PCP
TeamCity
TeamPCP
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- actions-cool GitHub Actions tag compromise
- AI-augmented adversary operations
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Dependabot cross-ecosystem malware advisory alerts
- Mini Shai-Hulud npm/PyPI worm campaign
- npm publish-time malware scanning and dual-use declarations
- Nx Console VS Code extension compromise
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
- Xinference PyPI compromise
TeamPCP-adjacent
Teams access
Teams TURN relay
TeamViewer
TEASOUP
Tebi
tech support scam
technician session
technique crossover
technology sector
ted backdoor
telecom
telecom-impersonation
telecommunications
- Malicious infrastructure provider concentration
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- TA488 OWAReaper and CVE-2026-42897 exploitation
Telegra.ph
Telegram
- 0ktapus phishing campaign
- Aeternum
- Chinese-language PhaaS wallet-tokenization ecosystem
- Flying Eagle and Night Dragon Android RAT ecosystem
- Forg365 Microsoft 365 PhaaS
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- GREYVIBE
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NovaCookies: Docusign-notification-driven AitM PhaaS stealing Microsoft 365 sessions (Sneaky2FA variant)
- NuGet game-cheat DotnetTool pepesoft campaign
- Starland RAT
- UAC-0226 / SHADOW-EARTH-066
telegram
Telegram bot
Telegram C2
- macOS.Gaslight Rust backdoor
- Solana FakeFix npm / PyPI developer stealer
- TELESHIM
- TELESHIM Middle East government espionage campaign
- wshu.net npm credential-stealer campaign
Telegram dead drop
Telegram exfiltration
Telegram notification
Telegram session theft
telemetry
TELEPUZ
Telerik
TELESHIM
Teletype
Telnet
Telnet brute force
Telnyx
Temp Zagros
template injection
tenant isolation
tenant-project
Tencent
TencShell
Tenda
Tenet Security
TerminalFix
Tesseract
Tetrade
TetrisPhantom
TeviRAT
text/plain request body
Thailand
- FishMonger
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- Thailand healthcare RAR / Python stealer campaign
The Gentlemen
The Hacker News
- Azure CLI LSHIY password-spray campaign
- CrashStealer macOS notarized-dropper campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Gitea Docker CVE-2026-20896 probing
- ModHeader browser-extension surveillance capability
- O-UNC-066 Entra passkey vishing
- OkoBot cryptocurrency-wallet malware framework
- Progress ShareFile Storage Zone Controller security threat
- StegoAd Edge extension steganography campaign
- UAT-7810 LONGLEASH ORB network expansion
- WP-SHELLSTORM webshell access brokerage
The Outsider
The Quarry
ThemeREX Addons
third-party integrations
third-party JavaScript
third-party risk
thought virus
threat hunting
- Operation Highland Velvet Ant authentication-stack backdoors
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
threat intelligence
threat landscape
- Iran-linked threat landscape: access optionality and evidence quality
- State of AI-enabled malware, August 2026 (Unit 42)
threat measurement
threat research
threat telemetry
ThrottleBlood
ThumbcacheService
thumbnail generation
time-of-check time-of-use
timestomping
timing attack
timing check
TinyGo
TinyRCT
tj-actions
TLS certificates
TLS interception
TmcLoader
TmcPayload
TOCTOU
- GitHub Security Advisories August 27, 2026: Crossplane cosign signature-verification bypass and Silverstripe RCE batch
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
ToddyCat
token forgery
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Hugging Face autonomous-agent production intrusion
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
token jacking
token replay
token revocation
token theft
- ACR Stealer
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Evilginx and device-code phishing open-directory cluster
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Forg365 Microsoft 365 PhaaS
- MrMustard PyPI credential-stealer compromise
- Okta support-system compromise
- ROADtools
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- Webmail CSS trust-boundary attacks
token-theft
TONESHELL
TookPS
tool
tool calling
tool execution
tool output injection
tool poisoning
tool use
tool-call logging
tooling
- CanisterWorm
- HackerBot Claw
- LiteLLM compromise
- TeamPCP
- Trivy → TeamPCP → CanisterWorm: compromise timeline
tools
- ACR Stealer
- Aeternum
- ArcBridge
- BINDCLOAK
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- BridgeHead
- BusySnake Stealer
- Cavern
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019)
- CrownX
- DeadLock ransomware
- Djinn Stealer
- ENCFORGE
- Fast16
- FDMTP
- First VPN
- forge-jsxy
- GenieLocker
- GigaWiper
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- HOLLOWGRAPH
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Kimwolf v7
- LabubaRAT
- LurkProxy
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- MIXEDKEY
- MODBEACON
- MYRA RAT
- NightLedger
- OctLurk
- OWAReaper
- PamStealer
- QuimaRAT
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- RedWing
- RemotePE
- ROADtools
- RustDuck
- SCMBANKER
- Showboat
- SilkLurk
- SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- SprySOCKS
- Starland RAT
- STOCKSTAY
- TaskWeaver
- TELEPUZ
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Ulej / Flowerbed
- Umbrij
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- WLDR agent
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
- XCSSET
- Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
Tor
Tortoiseshell
Total Software Deployment
TouchSocket
Toy Ghouls
TPM
Trading Technologies
TradingView
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- SourTrade browser-assembled malware malvertising
traffic broker
traffic control
traffic hijacking
traffic manipulation
traffic-distribution-system
traffic-fraud
Trail of Bits
- State divergence enables unauthorized access: Provenance marker module anyone-can-pass check
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
training data
transaction authority
transcript spoofing
transfer stations
transitive dependency
- Injective SDK npm wallet stealer
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
TranslatePress
translation software
transnational repression
transparent proxy
Transparent Tribe
- Operation XENOFISCAL SideCopy XenoRAT campaign
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- SideCopy
transport
transportation
transportation sector
Trend Micro
- Langflow CVE-2026-33017 cryptominer SSH worm
- SHADOW-AETHER AI-augmented Latin America intrusions
- Trend Micro Apex One CVE-2026-34926 exploitation
TrendAI
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- SHADOW-AETHER AI-augmented Latin America intrusions
Trezor
triage
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
TrickBot
Trident Ursa
Trinitite
Trivy
TRM Labs
trojanized daemons
trojanized installers
trojanized npm
trojanized PDF viewer
Tron
- Adform Trackpoint JavaScript supply-chain crypto clipper
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Ill Bloom CryptoJS wallet-drain campaign
- ViteVenom / ChainVeil npm campaign
Troy
TrueConf
trust boundary
trusted extension risk
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- ModHeader browser-extension surveillance capability
trusted publishing
- AsyncAPI generator / specs Miasma compromise
- GitHub Actions OIDC subject-claim collisions
- npm publish-time malware scanning and dual-use declarations
trusted relationship abuse
trusted runtime
trusted-component weaponization
trusted-domain abuse
trusted-publishing
- @7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow (Aug 28, 2026)
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI (GHSA-93qj-5q5v-3c2h)
tunnel decapsulation
tunnel services
tunneling
Turkey
Turla
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- STOCKSTAY
- Turla
- Turla STOCKSTAY backdoor operations
Turla collaboration
TuxBot
TuxBot v3 Evolution
TWCore
Twilio
Twilio SendGrid
Twill Typhoon
TWINLOOT
two-factor authentication
Tycoon2FA
type confusion
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
TypeConfuseDelegate
TypeScript
typosquat
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Polymarket npm wallet-drainer packages
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
typosquatting
- @withgoogle/stitch-sdk scope squat
- Braintree.Net NuGet payment skimmer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Funnull RingH23 and MacCMS supply-chain attacks
- Hunt.io global smishing infrastructure campaign
- Lazarus-linked Rollup polyfill npm malware
- Microsoft Teams external-chat phishing
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- nodemon-sudo / tslint-conf runtime npm backdoor
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- SANDWORM_MODE AI-toolchain npm worm
- ScreenConnect freeware / AsyncRAT SEO campaign
- shopsprint/decimal Go typosquat DNS backdoor
- StegaBin Pastebin-steganography npm campaign
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
- vpmdhaj OpenSearch npm cloud-secret stealer
U+E0000
U.S. critical infrastructure
UAC
UAC bypass
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- ScreenConnect freeware / AsyncRAT SEO campaign
UAC-0002
UAC-0010
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
UAC-0098
UAC-0145
UAC-0194
UAC-0226
UAT-10147
- CISA KEV August 26, 2026 additions: Citrix NetScaler DoS, Microsoft SQL Server RCE, and four UAT-10147 exploitation CVEs
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
UAT-11795
UAT-5918
UAT-7237
UAT-7810
Ubiquiti
Ubuntu
Udev persistence
UDP C2
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- SprySOCKS
UDP/1900
UI redressing
UI-API
Ukraine
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghostwriter
- GREYVIBE
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- Showboat
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
Ukraine targeting
Ulej
UltraViewer
UltraVNC
Umbrij
unattributed
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- OctLurk and SilkLurk Central Asia espionage campaign
unauthenticated
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019)
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004)
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- ServiceNow AI Platform August 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws and a sandbox escape (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876)
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
unauthenticated access
- Internet-exposed unauthenticated MCP servers
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- ServiceNow instance unauthenticated table-query exploitation
- Wiz Red Agent discovers Snowflake GitHub Actions script injection
unauthenticated admin access
unauthenticated API
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- NemoClaw local Ollama chat-template poisoning (Oasis Security)
unauthenticated HTTP exploitation
unauthenticated RCE
- Argo CD repo-server unauthenticated RCE
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on 10 Silicon One-based switches — plus a 7-CVE IOS XR hardening release
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- ENDLESSDOORS implant in Zbtlink router firmware
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Fastjson CVE-2026-16723 active exploitation
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- SiYuan kernel publish-mode security batch: unauthenticated SQL execution and publish-boundary breakdowns (GHSA-69083/69084/72811 criticals, 2026-09-03)
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
unauthenticated-publish
unauthorized pentest framing
UNC1069
UNC1543
UNC1549
- ArcBridge
- BridgeHead
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- NightLedger
UNC2814
UNC3753
UNC4221
UNC4736
UNC5792
UNC5976
UNC6240
UNC6293
UNC6508
UNC6671
UNC6692
UNC6780
UNC7005
unchecked-subtraction
unclaimed names
unfiltered_upload
unguarded plugin load
Uni-App
UniBLEed
Unicode
UniFi OS
Unified CM SME
uninitialized heap memory
unintended internet access
Unisoc
Unit 42
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- FortiBleed Fortinet credential exposure
- Operation FlutterBridge FlutterShell macOS malvertising
- Phantom squatting: AI-hallucinated domains
- Siemens ROX II zero-day exploit chain
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- State of AI-enabled malware, August 2026 (Unit 42)
- Synced passkey theft after endpoint compromise
- TuxBot v3 Evolution IoT botnet framework
- Unit 42 NOVA: frontier-AI autonomous zero-day discovery collapses the patch window
- Unit 42: CL-CRI-1131 / CL-CRI-1163 — LLM-orchestrated Latin America intrusion campaigns with exposed AI backends (Sep 3, 2026)
- Unit 42: machine-speed agentic intrusion — 50+ ATT&CK techniques executed in under 10 hours (Sep 2, 2026)
- Vidar / XMRig Factory-v3 malvertising campaign
United States
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- Seedworm / MuddyWater
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC3753
Unitree
university targeting
UNK_MassTraction
UNK_PitStop
unpatched
unpatched transitive library
unpatched vulnerability
unpkg
Unreal Engine
unrestricted file upload
unsafe deserialization
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- LangGraph checkpointer and namespace trust boundaries
unsafe reflection
unsanctioned message board
unsigned installer
Unyielding Wasp
UpdateFactory
UPnP
UPS
upstream dependency
UPX
uranium compression
URL pack
URL parameter
URL retrieval
URLPattern
USB exfiltration
USB propagation
USB weaponizer
USB worm
use-after-free
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
user execution
user namespaces
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
user verification
UserAssist
username environmental keying
UserPath
USN Journal
UTA0355
UTA0533
UTG-Q-1000
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- MODBEACON
- Operation Phnom Penh MODBEACON activity
uTLS
Uzbekistan
V2Ray
V4bel
V8
- Chrome V8 CVE-2026-11645 exploitation
- Chrome V8 CVE-2026-85046 type-confusion exploitation
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- workerd / Cloudflare Code Mode: five memory-corruption bugs enable sandbox escape and cross-tenant "heap swipe"
V8 isolate
V8 isolates
valid accounts
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Brazilian education LockBit, DragonForce, and insider incidents
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
ValleyRAT
- MODBEACON
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys driver
- TA4922
Varonis
Varonis Threat Labs
VBCloud
VBE
VBS
VBS loader
VBS spreader
VBScript
- BusySnake Stealer
- Cloud Atlas
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- WhatsApp VBScript ManageEngine RMM campaign
VBScript loader
vCenter
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
vector databases
VEIL#DROP
Velociraptor
VeloCloud
VeloCloud Orchestrator
Velvet Ant
VELVETSHELL
vendor compromise
vendor credentials
Venezuela
VENOMOUS BEAR
Vercel
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- RMM phishing campaign spanning 46 countries: rapidly-rotated Vercel infrastructure and the stable delivery-chain fingerprint (ANY.RUN, Sep 4, 2026)
- StegaBin Pastebin-steganography npm campaign
Vertex AI
vesting-account
VHD
victim-owned relay infrastructure
Vidar
VIDAR
Vidar Stealer
- AI-brand impersonation phishing and malvertising
- Operation Muck and Load GitHub lure network
- Vidar / XMRig Factory-v3 malvertising campaign
video conferencing
video platform
Vietnam
Vietnam-aligned
Views
ViewState
ViewState deserialization
ViPNet
virtual machine escape
virtual patching
virtualization
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Januscape KVM CVE-2026-53359 guest-to-host escape
virtualization targeting
VirusTotal sentiment abuse
vishing
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
- Microsoft Q2 2026 email and Teams phishing landscape
- O-UNC-066 Entra passkey vishing
- REF6045 / SCMBANKER Mexican banking fraud
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- SCMBANKER
- ShinyHunters
- Spring Ring: Microsoft Teams vishing campaigns that escalated to an NTLM-relay domain takeover (Unit 42, Aug 31, 2026)
- UNC3753
- UNC6671 / BlackFile multi-brand vishing extortion operation
Visual Studio
Visual Studio Code Remote SSH
Vite
Vitest
ViteVenom
VLESS
VM escape
vm2
vManage
VMCI
VMSA-2026-0006
VMware
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, and macOS
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
VMware ESXi
VMXNET3
VNC
VNT
VOD
voice phishing
Void Blizzard
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
Void Manticore
Volt Typhoon
VoLTE
volume serial number
VPN
- Berlin state network compromise: Rhysida extortion after August exfiltration of the state administrative network (Aug 28–29, 2026)
- Check Point VPN CVE-2026-50751 exploitation
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- First VPN
- Gunra ransomware-as-a-service activity
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
- VPN Go browser-extension clipboard stealer
VPN credentials
VPN gateway
VPN Go
VPN session hijacking
VS Code
- Amazon Q CVE-2026-12957 MCP auto-execution
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Browser-based developer IDE OAuth token theft
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Nx Console VS Code extension compromise
- Open VSX evil-twin extension campaign
- PolinRider cross-ecosystem supply-chain campaign
- UNK_DeadDrop developer repository phishing
VS Code tunnels
Vshell
VShell
VSIX
vSphere
vSphere Foundation
vssvc.exe
VU#213560
VulnCheck
- ENDLESSDOORS implant in Zbtlink router firmware
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
- Windmill CVE-2026-29059 active exploitation
vulnerability
- Adobe ColdFusion APSB26-68 CVE bonanza
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Joomla extension KEV exploitation cluster
- Kaltura mwEmbed unpatched: unauthenticated file read + RCE via mwEmbedLoader.php (CVE-2026-19912/19913)
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Langflow CVE-2026-55255 flow authorization bypass
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Quest KACE SMA CVE-2025-32975 exploitation
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- Trend Micro Apex One CVE-2026-34926 exploitation
vulnerability database pollution
vulnerability disclosure
- "Reported Log4j RCE" is a hardening gap, not a vulnerability: AI-agent-found FilteredObjectInputStream bypass (Sonatype-2026-006746)
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
vulnerability exploitation
vulnerability management
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- LLM-slop false CVEs: AI-generated vulnerability advisories poisoning NVD / CISA
- Unit 42 NOVA: frontier-AI autonomous zero-day discovery collapses the patch window
vulnerability research
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- GitLab Oj notebook-diff authenticated RCE chain
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
vulnerability-research
vulnerable appliances
VXLAN
w3wp.exe
wallet address replacement
wallet drainer
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- DCloud Uni-App scam infrastructure ecosystem
wallet infrastructure
wallet replacement
wallet theft
- @copilot-mcp/apex macOS infostealer campaign
- COLDCARD predictable-RNG Bitcoin theft risk
- Fake-reputation crypto clipboard hijacker
- Ill Bloom CryptoJS wallet-drain campaign
- Injective SDK npm wallet stealer
- Mastra
easy-day-jsnpm scope compromise - Solana FakeFix npm / PyPI developer stealer
- Void Dokkaebi
wallet-drainer
wallet-theft
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- forge-jsxy
- Polymarket npm wallet-drainer packages
- TrapDoor crypto-stealer cross-ecosystem campaign
WAPF
Wasabi
- DeadLock ransomware
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Seedworm / MuddyWater
wastewater
watch_queue
watchdog
watchTowr
- Adobe ColdFusion APSB26-68 CVE bonanza
- Citrix NetScaler CVE-2026-8451 memory overread
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE chain via SAML canonicalization heap overflow
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
watchTowr Labs
water and wastewater
water sector
watering hole
watering-hole
WAV
weak authentication
weak credentials
weak entropy
weak passwords
weak RNG
weapons shipments
web application
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- Gravity SMTP CVE-2026-4020 exploitation
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
- WP Maps Pro CVE-2026-8732 exploitation
web application compromise
web hosting
web IDE
web injection
web injector
web management interface
web page
web player
web proxy
web RCE
web server
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- UAT-10147
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
web shell
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- Everest Forms Pro CVE-2026-3300 exploitation
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- Joomla extension KEV exploitation cluster
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Oman government Iranian-nexus webshell C2
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- UNC6508
- UTA0533 SonicWall SMA1000 zero-day compromise
web shell hunting
web shells
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- StrikeShark SharkLoader / Cobalt Strike campaign
web supply chain
- Adform Trackpoint JavaScript supply-chain crypto clipper
- Funnull RingH23 and MacCMS supply-chain attacks
web-shells
WebAssembly
WebAuthn
WebDAV
- ACR Stealer
- CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass, Linux kernel IPv6 LPE, and JFrog Artifactory Docker-cache path escape
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Exposed WebDAV malware delivery lab and CURP campaign
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
webhook.site
WebHost Manager
WebKit
WebLogic
Weblogic Server Proxy Plug-in
webmail
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- UNK_MassTraction Roundcube university mailserver campaign
- Webmail CSS trust-boundary attacks
WebRTC
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- Unitree G1 EDU: two independent root-RCE chains (CVE-2026-76639, CVE-2026-76640), one starting over Bluetooth
webshell
webshells
website-compromise
WebSocket
- Agent localhost control-plane RCE
- ArcBridge
- BridgeHead
- Flying Eagle and Night Dragon Android RAT ecosystem
- JWR phishing framework (likely The Outsider variant)
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
WebSocket C2
- "Superior": 19 Chrome/Edge extensions delivering a wallet drainer and credential-stealing framework (Socket)
- Cavern
- GREYVIBE
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- SprySOCKS
- STOCKSTAY
- TELEPUZ
- TerminalFix: ClickFix variant deploys a reverse-tunnel implant through a multi-stage chain (Aug 28, 2026)
- Turla STOCKSTAY backdoor operations
- ulid-xyz transitive delivery chain: a MicrosoftSystem64 RAT three npm dependencies deep (SafeDep, Sep 1, 2026)
WebSocket session hijacking
websocket-sharp
WebView
WebView2 C2
Webworm
Weedhack
WEEVILPROXY
Werkbit
- Agent localhost control-plane RCE
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- GREYVIBE
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking
- WhatsApp VBScript ManageEngine RMM campaign
WhatsApp phishing
white-label
WHM
- cPanel/WHM CVE-2026-65643: parked/addon-domain file write yields root code execution on shared hosting
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
Wi-Fi credential theft
Widget Factory
Wiflyer
wiki
WILDDAY
WildFire
Windchill
Windchill PDMLink
WinDirStat
Windmill
Windows
- 3CX desktop app compromise
- Aeternum
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- ArcBridge
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BINDCLOAK
- BraZetsu: Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB, Sep 3, 2026)
- BridgeHead
- BusySnake Stealer
- CCleaner signed-update compromise
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- ClickOnce COM hijacking abuse
- Crypto Clipper Tor / USB worm
- Cursor Windows workspace-path binary hijack
- DAEMON Tools Lite supply-chain compromise
- DeadLock ransomware
- Djinn Stealer
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- FDMTP
- Flooding Dropper npm campaign
- GenieLocker
- GigaWiper
- GodDamn ransomware PoisonX BYOVD activity
- IronWorm npm Rust infostealer campaign
- js-logger-pack Hugging Face exfiltration campaign
- LabubaRAT
- LurkProxy
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
- MiniPlasma Windows Cloud Filter LPE exploitation
- MIXEDKEY
- Next.js August 2026 security release: two unauthenticated RCEs (libheif/AVIF heap overflow + Windows path traversal)
- NightLedger
- OctLurk
- Operation DangerousPassword axios npm compromise
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- QuimaRAT
- ScarCruft Yanbian game-platform supply-chain attack
- SilkLurk
- Starland RAT
- StrikeShark SharkLoader / Cobalt Strike campaign
- StubMaker: 16 typosquatted RubyGems packages deliver Windows stealer
- Synced passkey theft after endpoint compromise
- TamperedChef-style productivity malware clusters
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
Windows 11 25H2
Windows Defender
Windows Defender exclusions
- Rogue ScreenConnect installations: worm-like VBS propagation across unrelated hosts (Huntress)
- ScreenConnect freeware / AsyncRAT SEO campaign
Windows Defender impairment
Windows filesystem
Windows Forms
Windows Installer
- Counterfeit installers to system compromise: deceptive software-download campaign assessed as Silver Fox / Yinhu (Microsoft, Sep 1, 2026)
- Impersonating IT support: Teams remote-session intrusion via MSI → portable Node.js → JavaScript implant → WinRM lateral movement (Microsoft, Sep 2, 2026)
Windows malware
- Armored Likho BusySnake campaign
- CrownX
- Fake-reputation crypto clipboard hijacker
- MODBEACON
- NuGet game-cheat DotnetTool pepesoft campaign
- OkoBot cryptocurrency-wallet malware framework
- SourTrade browser-assembled malware malvertising
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Thailand healthcare RAR / Python stealer campaign
- WhatsApp VBScript ManageEngine RMM campaign
Windows persistence
Windows Run dialog
Windows Script Host
Windows Server 2025
Windows servers
Windows service
Windows service persistence
Windows Terminal
Windows Update
Winnti Group
WinOS
Winos 4.0
Winos4.0
WinPython
WinRAR
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
WinRing0
WinRM
WinSock
wiper
wiper-adjacent
WireGuard
Wiz
Wiz Research
WLDR agent
WM_COPYDATA IPC
WMI
Woodgnat
WordlistLoader
WordPress
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- Everest Forms Pro CVE-2026-3300 exploitation
- GitHub Security Advisories August 29, 2026: argocd-mcp auth bypass, Sigma Forms Pro RCE, Omnivore Apple-Sign-In bypass, and a 6-item batch
- Gravity SMTP CVE-2026-4020 exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
- Operation Endgame SocGholish disruption
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body (Hunt.io)
- Patriot Bait AI-assisted C2 botnet
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware, data theft, and ransomware
- WordPress batch: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — five critical unauthenticated flaws
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- WP-SHELLSTORM webshell access brokerage
WordPress 7.0.4
WordPress credential theft
workerd
workflow backdoor
workflow injection
workflow orchestration
workflow-abuse
working-directory hijacking
workspace trust
- Amazon Kiro "Power Leak": Kiro Powers prompt-injection data exfiltration
- Amazon Q CVE-2026-12957 MCP auto-execution
- Cursor Windows workspace-path binary hijack
World Cup
worm
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- Crypto Clipper Tor / USB worm
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
- Leo Platform npm Miasma-style compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- PCPJack cloud SMTP relay network
- SANDWORM_MODE AI-toolchain npm worm
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- TeamPCP
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
worm-like propagation
WP Maps Pro
WP Squared
WP-SHELLSTORM
wp2shell
WPMU DEV Dashboard
write-what-where
WScript
WSS
X-Grafana-URL
X-Secret
X-WEBAUTH-USER
X25519
X3D MINER
X_TRADER
xAI
XChaCha20
XChaCha20-Poly1305
Xcode
XCSSET
XCSSET v40
Xecurify
XenoRAT
XFRM
Xiaomi Redmi A5
xinference
xlabs_v1
XML-RPC brute force
XMLDecoder
XMRig
- Aeternum
- GREYVIBE
- Langflow CVE-2026-33017 cryptominer SSH worm
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets
- Ollama P2P cryptominer RAT campaign
- Operation Muck and Load GitHub lure network
- Pirated media SilentCryptoMiner RAT campaign
- Vidar / XMRig Factory-v3 malvertising campaign
- Wiz Threat Research: inside 90 days of attacks on AI infrastructure
XOR
XOR obfuscation
xorshift32
XPIA
Xray
XSLT SSRF
XSS
- GitHub Security Advisories August 27, 2026: Crossplane cosign signature-verification bypass and Silverstripe RCE batch
- Gogs CVE-2026-52813 path-traversal RCE (and CVE-2026-52810 push bypass, GHSA-6vxv-wg6j-5qwp XSS)
- TA488 OWAReaper and CVE-2026-42897 exploitation
- UNK_MassTraction Roundcube university mailserver campaign
XSS injection
XSS.is
XWorm
XXE
xz
Yahoo Mail
Yanbian
YARA
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback
- Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026)
- SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
Yasmarang
YesWeHack
Yinhu
YouTube
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
YouTube abuse
ysoserial
Yuechi Shared Technology
yuze
Yx Technology
ZAPiXDESK
ZBT
Zbtlink
- ENDLESSDOORS implant in Zbtlink router firmware
- SPEAKINGSTONE and DARKLANTERN: two more implants in ZBT / MoreQuick router firmware (VulnCheck supply-chain trace)
ZCS
Zendesk
Zephyr RTOS
Zero Trust
zero-balance
zero-click
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Pegasus zero-click iMessage exploit confirmed on a Serbian student-movement member; 14+ targets since 2026, new Android spyware variant installed during police detention (THN / Citizen Lab / SHARE, Sep 3, 2026)
zero-day
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- FalconFlank: Chaotic Eclipse releases 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor — abuses "Office malicious macros remediation" (THN, Sep 3, 2026)
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
- MiniPlasma Windows Cloud Filter LPE exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- PaperCut NG/MF zero-day: active exploitation of unauthenticated admin-trigger chain (CVE-2026-81578 / CVE-2026-82078)
- Siemens ROX II zero-day exploit chain
- Unit 42 NOVA: frontier-AI autonomous zero-day discovery collapses the patch window
- UTA0533 SonicWall SMA1000 zero-day compromise
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes QEMU/KVM three times
zero-day exploitation
zero-reputation infrastructure
zero-width
ZeroBEC
Zerologon
Zimbra
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- Ulej / Flowerbed
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
Zimbra Collaboration Suite
- CL-STA-1114 Zimbra webmail espionage
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw (August 21, 2026)
Zimperium
ZimReaper
ZIP import
zLabs
zlib
Zoho Assist
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Storm-2603 parallel SharePoint ransomware intrusion