Tag index
Generated from page-level ## Tags sections. Each tag below links to the pages that currently use it.
All tags
- .NET (9)
- .NET malware (7)
- .NET reflection (1)
- .pth (1)
- /accessv2 (1)
- /api/session/reset_password (1)
- /dev/kvm (1)
- 146.70.139.154 (1)
- 192.42.116.105 (1)
- 192.42.116.58 (1)
- 2FA recovery codes (1)
- 3CX (1)
- 404 TDS (1)
- 43.228.157.68 (1)
- 4sync (1)
- @marketfront (1)
- @tqm-mfe (1)
.bin(1)<all_urls>(1)- Ababil of Minab (1)
- abuse response (1)
- academic research (1)
- academic sector (2)
- Accellion (1)
- access broker (2)
- access brokers (2)
- access keys (1)
- access optionality (1)
- access token abuse (1)
- access token theft (1)
- Accessibility Service (1)
- account lockout (1)
- account takeover (5)
- account-takeover (1)
- ACR Stealer (1)
- act_pedit (1)
- ACTINIUM (1)
- Active Directory (1)
- active exploitation (61)
- active probing (1)
- active threat (3)
- active-exploitation (1)
- ActiveX (1)
- actor (6)
- actors (11)
- ad blocker (1)
- ad fraud (1)
- Adaptix C2 (1)
- ADB TCP/5555 (2)
- Adblock for YouTube (1)
- Adform (1)
- ADFS (1)
- Admin API key theft (1)
- administrator account creation (2)
- Adobe ColdFusion (1)
- Adobe Commerce (1)
- Adspect (1)
- Advanced IP Scanner (1)
- Adversa AI (1)
- adversary-in-the-middle (6)
- advertising technology (1)
- adware (5)
- adware history (1)
- aerospace (3)
- AES-128-CBC (1)
- AES-256-CTR (1)
- AES-256-GCM (2)
- AES-CTR (1)
- AES-GCM (3)
- AES-GCM C2 (1)
- Aeternum (1)
- affiliate hijacking (1)
- Afghanistan (4)
- Africa (4)
- agent frameworks (3)
- agent memory (1)
- agent monitoring (1)
- agent polling protocol (1)
- agent skills (2)
- agent state (1)
- AgentBaiting (1)
- agentic AI (4)
- agentic botnets (1)
- agentic browser (1)
- agentic browsers (1)
- agentic malware (1)
- agentic ransomware (1)
- agentic threat actor (2)
- Agentjacking (1)
- AGENTPSD (2)
- AI (6)
- AI agent (1)
- AI agents (20)
- AI anti-analysis (1)
- AI application infrastructure (6)
- AI assistant credentials (2)
- AI assistants (4)
- AI brand impersonation (2)
- AI browsers (2)
- AI chatbot abuse (1)
- AI coding agents (2)
- AI credential theft (1)
- AI data exfiltration (1)
- AI developer tooling (2)
- AI framework (1)
- AI gateway (1)
- AI infrastructure (1)
- AI memory poisoning (1)
- AI model encryption (1)
- AI model evaluation (2)
- AI Now Institute (1)
- AI search poisoning (1)
- AI security (1)
- AI services (1)
- AI tooling (16)
- AI tools (1)
- AI vulnerability discovery (1)
- AI workflow (1)
- ai-abuse (1)
- ai-agent (1)
- AI-assisted development (2)
- AI-assisted intrusion (1)
- AI-assisted malware (3)
- AI-assisted malware development (4)
- AI-assisted phishing (1)
- AI-assisted vulnerability discovery (1)
- AI-augmented operations (3)
- AI-generated malware (1)
- AI-generated narrator (1)
- Aider (1)
- AISURU (2)
- AiTM (3)
- Albania (1)
- Alibaba (1)
- Allen-Bradley (1)
- Amadey (1)
- Amatera Stealer (1)
- Amazon Q Developer (1)
- Amazon SES (2)
- Amcache (1)
- AMOS (2)
- AMSI bypass (5)
- AmsiScanBuffer (1)
- Android (10)
- Android Accessibility Service (2)
- Android ADB (3)
- Android Debug Bridge (2)
- Android malware (3)
- Android RAT (1)
- Android spyware (3)
- Android TV (1)
- Anthropic (2)
- anthropickit (1)
- anti-analysis (8)
- anti-bot (1)
- anti-forensics (2)
- Anubis ransomware (1)
- ANY.RUN (1)
- AnyDesk (2)
- AOL Mail (1)
- Aone (1)
- Apache Tomcat (1)
- Apex One (1)
- API abuse (1)
- API enumeration (1)
- API exposure (1)
- API key exposure (1)
- API key theft (1)
- API keys (2)
- API-driven payloads (1)
- apintergrationpost (1)
- App-Bound Encryption bypass (1)
- AppDomainManager (1)
- AppDomainManager injection (2)
- AppleJeus (1)
- AppleScript (1)
- AppleSeed (1)
- appliance (1)
- application database (1)
- application delivery controller (1)
- application token (1)
- APSB26-68 (1)
- APT (8)
- APT-C-08 (1)
- APT27 (1)
- APT28 (1)
- APT29 (2)
- APT32 (1)
- APT36 (2)
- APT37 (1)
- APT42 (1)
- APT43 (1)
- APT44 (2)
- APT45 (1)
- Aptos (2)
- Aquatic Panda (2)
- AquilaRAT (1)
- arbitrary code execution (1)
- arbitrary file disclosure (1)
- arbitrary file read (2)
- arbitrary file upload (1)
- arbitrary file write (3)
- arbitrary JavaScript (1)
- ArcBridge (2)
- Arch Linux (1)
- Arctic Wolf (1)
- ArduPilot (1)
- Argo CD (1)
- ArgoCD (1)
- Arista (1)
- Arista EOS (1)
- ARL (1)
- Armageddon (1)
- ArmCorp (1)
- Armored Likho (3)
- Artifact Signing (1)
- AryStinger (1)
- AS32167 (1)
- Asia targeting (1)
- ASLR bypass (1)
- ASNs (1)
- ASP.NET (2)
- ASP.NET machineKey (1)
- ASPX web shells (2)
- Astro (1)
- ASUS AiCloud routers (1)
- ASUS router (1)
- AsyncAPI (1)
- AsyncRAT (3)
- Atlas RAT (1)
- Atlassian (1)
- Atomic Stealer (2)
- AUDIOFIX (2)
- audit logging (1)
- AUR (1)
- authenticated RCE (1)
- authenticated remote code execution (1)
- authentication bypass (19)
- authentication laundering (1)
- authentication stack (2)
- authentication-coercion (1)
- Authenticode impersonation (1)
- authorization bypass (1)
- auto-execution (1)
- AUTODYN (1)
- AutoGen Studio (1)
- AutoHotKey (1)
- AutoJack (1)
- autonomous agents (3)
- autonomous attacks (1)
- autonomous exploitation (1)
- autonomous scanning (1)
- AV killer (1)
- Avalon (2)
- aviation (2)
- AWS (7)
- AWS CloudTrail (1)
- AWS S3 (2)
- AWS Secrets Manager (1)
- axios (1)
- Azure (4)
- Azure CLI (1)
- Azure Cosmos DB (1)
- Azure DevOps (1)
- Azure Storage (1)
- Babuk (1)
- Backblaze (1)
- backdoor (21)
- Backdoor.Mistic (1)
- Backstage (1)
- backup disruption (3)
- backup recovery keys (1)
- backup targeting (1)
- backups (1)
- Bad Epoll (1)
- BadBlocker (1)
- Badbox 2.0 (1)
- BadPotato (1)
- Balbooa Forms (1)
- Balochistan Police (1)
- Banana RAT (1)
- bandcampro (1)
- banking (1)
- banking malware (4)
- banking trojan (3)
- Barracuda (1)
- Base64 (1)
- BaseZipInstaller (1)
- Bash Uploader (1)
- batch loader (1)
- BCU key (1)
- Bearlyfy (2)
- Beast ransomware (1)
- BeaverTail (1)
- Bedrock (1)
- behavioral integrity verification (1)
- Behinder (1)
- Belarus (2)
- BELQI (1)
- Bexo Wallet (1)
- BeyondTrust (1)
- Binance Smart Chain (1)
- binary execution (1)
- BinaryFormatter (1)
- BINDCLOAK (3)
- binding.gyp (2)
- biometric records (1)
- BIOPASS RAT (1)
- BioShocking (1)
- BIP-39 (2)
- BirdCall (1)
- Bitbucket (1)
- Bitcoin (4)
- Bitcoin Libre (1)
- BitMiner (1)
- bitsadmin (1)
- Bitter (1)
- Bitwarden (1)
- BKA (1)
- BlackFile (1)
- Blackpoint Cyber (6)
- Bleacher Report (1)
- blockchain C2 (9)
- blockchain dead drop (5)
- blockchain RPC (1)
- blockchain-dead-drop (1)
- Blogger abuse (1)
- blogspot staging (1)
- BLUEBEAM (1)
- Boatnet (1)
- body hash (1)
- botnet (13)
- botnet framework (1)
- Braintree (1)
- branch-compromise (1)
- branch-name-injection (1)
- brand impersonation (3)
- brand-impersonation (1)
- Brazil (5)
- Brazilian banking malware (1)
- BreachForums (1)
- Breeze Cache Cleaner (1)
- BRICKSTORM (2)
- BridgeHead (2)
- Broadcom (3)
- browser assembly (1)
- browser automation (1)
- browser cookie theft (1)
- browser credential theft (23)
- browser data theft (1)
- browser extension (9)
- browser extension loader (1)
- browser fingerprint spoofing (1)
- browser fingerprinting (1)
- browser hijacking (4)
- browser malware (1)
- browser memory (1)
- browser security (3)
- browser session abuse (2)
- browser session risk (3)
- browser zero-day (1)
- browser-credential-theft (1)
- browser-extensions (2)
- browser-resident malware (3)
- browser-security (1)
- browser-session risk (1)
- browsing history (1)
- brute-force credentials (1)
- BSC (1)
- BTMOB (1)
- bucket hijacking (1)
- bucket squatting (1)
- Bugcrowd (1)
- build server (1)
- build-time compromise (2)
- building automation (1)
- bulletproof hosting (1)
- Bun (4)
- Bun runtime abuse (1)
- Burkina Faso (1)
- business email compromise (2)
- business intelligence (1)
- BusySnake Stealer (3)
- Bybit (1)
- BYOVD (3)
- bypass2fa (1)
- C# (1)
- C++ (3)
- C++/CLI (1)
- C0XMO (1)
- C2 (12)
- C2 framework (2)
- C2 panel (1)
- C2 tasking (1)
- CageFS (1)
- calendar dead drop (1)
- calendar invitation (1)
- Calendly abuse (1)
- call forwarding (2)
- callback URL (1)
- Cambodia (1)
- campaign (6)
- Canada (1)
- CANFAIL (1)
- CAP_NET_ADMIN (2)
- captive portal (2)
- capture the flag (1)
- Casbaneiro (1)
- CastleStealer (1)
- Catalyst SD-WAN Manager (1)
- Catcher (1)
- Cav3rn (1)
- Cavern (2)
- Cavern Manticore (3)
- CCleaner (1)
- CDN (1)
- cellular modem (1)
- Censys ARC (1)
- Central Asia (1)
- CERT-In (1)
- CERT/CC (1)
- Certbot (1)
- certificate pinning (1)
- certificate theft (1)
- certutil (1)
- CFIDE (1)
- ChaCha20 (1)
- ChainDrop (1)
- ChainVeil (1)
- ChatGPT (1)
- chattr (1)
- Chatty Spider (1)
- CHAVECLOAK (1)
- Check Point (2)
- Check Point Research (1)
- Checkmarx (2)
- checkpointers (1)
- China (3)
- China-linked (8)
- China-nexus (16)
- China-speaking ecosystem (1)
- Chinese-language cybercrime (2)
- Chinese-language fraud ecosystem (1)
- Chinese-speaking (6)
- Chinese-speaking cybercrime (1)
- Chinese-speaking operator (2)
- Chisel (3)
- ChocoPoC (1)
- ChocoShell (1)
- Chrome (3)
- Chrome App-Bound Encryption (1)
- Chrome DevTools Protocol (1)
- Chrome extension (2)
- Chrome renderer sandbox (1)
- Chrome Web Store (5)
- chrome_settings_overrides (1)
- ChromElevator (1)
- Chromium (5)
- Chromium extension (1)
- CI secrets (1)
- CI-CD (3)
- CI/CD (41)
- CI/CD abuse (1)
- CircleCI (1)
- CIS (2)
- CISA (6)
- CISA KEV (30)
- Cisco (4)
- Cisco IOS (1)
- Cisco IOS 12.4 (1)
- Cisco Nexus (1)
- Cisco Talos (2)
- Cisco Unified CM (1)
- Cisco Unified Communications Manager (1)
- citizen portal compromise (1)
- Citrine Sleet (1)
- Citrix (2)
- Citrix NetScaler (2)
- CitrixBleed (1)
- CitrixBleed 2 (1)
- CKEditor file manager (1)
- CL-CRI-1089 (1)
- CL-CRI-1147 (1)
- CL-STA-1062 (3)
- CL-STA-1114 (4)
- Claude (3)
- Claude Code (7)
- Claude for Chrome (1)
- Claude Mythos 5 (1)
- Claude Opus 4.7 (1)
- Clever Cloud (1)
- click interception (1)
- ClickFix (19)
- ClickOnce (1)
- ClickUp (1)
- client-side exploitation (1)
- Cline (1)
- clipboard hijacker (1)
- clipboard hijacking (1)
- clipboard injection (1)
- clipboard manipulation (2)
- clipboard stealer (1)
- clipboard theft (6)
- clipper (2)
- Cloaked Ursa (1)
- cloaking (3)
- cloud (7)
- cloud C2 (2)
- cloud compromise (1)
- cloud credential hunting (1)
- cloud credential risk (1)
- cloud credential theft (8)
- cloud credentials (4)
- cloud exploitation (1)
- Cloud Files Mini Filter Driver (1)
- Cloud Filter driver (1)
- Cloud Foundation (1)
- cloud IAM (1)
- cloud identity (2)
- cloud identity abuse (1)
- cloud infrastructure (1)
- cloud logging (1)
- cloud metadata service (1)
- cloud secrets (4)
- cloud security (4)
- cloud service abuse (4)
- cloud storage (1)
- cloud storage exfiltration (1)
- cloud transcoding (1)
- Cloudflare (4)
- Cloudflare Tunnel (5)
- Cloudflare tunnels (2)
- Cloudflare Turnstile (1)
- Cloudflare Workers (5)
- cloudflared (2)
- CloudLinux (1)
- cluster compromise (1)
- CMS (7)
- CMS exploitation (1)
- CNCERT (1)
- Cobalt Strike (6)
- code execution (3)
- code injection (1)
- code sandbox scraping (1)
- code signing (3)
- Codecov (1)
- codemado (1)
- CodeQL (1)
- Codex (2)
- Codex CLI (1)
- coding agents (1)
- coding challenge (1)
- Coinbase (1)
- Coinkite (1)
- COLDCARD (1)
- ColdFusion (1)
- collaboration platforms (1)
- collaboration-tool phishing (1)
- COM-hijacking (1)
- ComfyUI (1)
- command and control (4)
- command execution (9)
- command injection (7)
- command-execution (1)
- command-injection (1)
- commercial messaging applications (1)
- commit farming (1)
- communications infrastructure (1)
- Composer (5)
- compromised accounts (2)
- compromised credentials (1)
- compromised infrastructure (1)
- compromised websites (2)
- compromised WordPress (2)
- computer name (1)
- computer vision (1)
- Conditional Access (1)
- configuration exposure (1)
- configuration tampering (1)
- configuration theft (2)
- Confluence (1)
- confused deputy (4)
- ConfuserEx (2)
- conhost (1)
- connected apps (1)
- ConnectWise (1)
- ConnectWise ScreenConnect (1)
- construction (2)
- consumer devices (1)
- consumer IoT (1)
- Contagious Interview (5)
- container (1)
- container escape (5)
- container escape pre-check (1)
- content compliance rules (1)
- contentPolicy (1)
- context flooding (1)
- Continue (1)
- continuous visibility (1)
- control flow flattening (3)
- control panel compromise (1)
- control plane (3)
- conversation theft (1)
- cookie theft (4)
- Copilot (1)
- Copilot CLI (1)
- Copy-on-Write (1)
- Corepack (1)
- CornFlake (1)
- Coruna (2)
- CosmosEscape (1)
- counterfeit software (1)
- COW (1)
- COWARDDUCK (1)
- CPaaS (1)
- cPanel (4)
- CPUID (1)
- cracked software (1)
- CrackMapExec (1)
- CrashStealer (1)
- Crates.io (1)
- credential attacks (3)
- credential dumping (1)
- credential exposure (5)
- credential harvesting (5)
- credential rotation (1)
- credential spraying (1)
- credential stuffing (2)
- credential theft (74)
- credential-theft (53)
- credit card theft (1)
- criminal infrastructure (1)
- critical infrastructure (6)
- critical-infrastructure (2)
- CRM data theft (1)
- cron (2)
- cron persistence (3)
- cross-platform (2)
- cross-platform malware (2)
- cross-project access (1)
- cross-site request forgery (1)
- cross-tenant access (1)
- cross-tenant isolation (1)
- CrownX (2)
- Crucio (1)
- crypto (2)
- crypto clipper (2)
- crypto wallets (2)
- crypto-js (1)
- crypto-wallets (1)
- cryptocurrency (14)
- cryptocurrency mining (1)
- cryptocurrency scam (1)
- cryptocurrency theft (13)
- cryptocurrency wallet theft (7)
- cryptocurrency wallets (4)
- cryptojacking (1)
- CryptoJS (1)
- cryptominer (2)
- cryptomining (1)
- CSCwt95997 (1)
- CSI token theft (1)
- CSRF (1)
- CSRF token theft (1)
- CSS (1)
- CSS sanitization (1)
- CSSOM (1)
- Curious Serpens (1)
- CURP (1)
- Cursor (5)
- Curve25519 (2)
- Curve25519-XSalsa20-Poly1305 (1)
- custody APIs (1)
- CVE-2008-4128 (1)
- CVE-2013-3307 (1)
- CVE-2016-5681 (1)
- CVE-2020-17103 (1)
- CVE-2020-22653 (1)
- CVE-2020-22658 (1)
- CVE-2021-27137 (1)
- CVE-2021-29441 (1)
- CVE-2022-0492 (1)
- CVE-2023-24932 (1)
- CVE-2023-25717 (1)
- CVE-2023-2868 (1)
- CVE-2023-4346 (1)
- CVE-2023-4966 (1)
- CVE-2024-1708 (1)
- CVE-2024-1709 (1)
- CVE-2024-20399 (1)
- CVE-2024-21182 (1)
- CVE-2024-3094 (2)
- CVE-2024-42009 (1)
- CVE-2025-11371 (1)
- CVE-2025-11837 (1)
- CVE-2025-24054 (1)
- CVE-2025-2492 (1)
- CVE-2025-3248 (2)
- CVE-2025-32975 (1)
- CVE-2025-33053 (1)
- CVE-2025-34291 (1)
- CVE-2025-40947 (1)
- CVE-2025-40948 (1)
- CVE-2025-40949 (1)
- CVE-2025-48595 (1)
- CVE-2025-49113 (1)
- CVE-2025-49704 (1)
- CVE-2025-49706 (1)
- CVE-2025-5777 (1)
- CVE-2025-66376 (3)
- CVE-2025-67038 (1)
- CVE-2025-68613 (1)
- CVE-2025-68686 (1)
- CVE-2025-8088 (4)
- CVE-2026-0257 (1)
- CVE-2026-0300 (1)
- CVE-2026-0770 (1)
- CVE-2026-10520 (1)
- CVE-2026-10523 (1)
- CVE-2026-11405 (1)
- CVE-2026-11645 (1)
- CVE-2026-12569 (1)
- CVE-2026-12957 (1)
- CVE-2026-12958 (1)
- CVE-2026-15409 (1)
- CVE-2026-15410 (1)
- CVE-2026-15583 (1)
- CVE-2026-16232 (1)
- CVE-2026-16723 (1)
- CVE-2026-16812 (1)
- CVE-2026-18556 (2)
- CVE-2026-18577 (1)
- CVE-2026-19516 (1)
- CVE-2026-20127 (1)
- CVE-2026-20182 (1)
- CVE-2026-20230 (1)
- CVE-2026-20245 (1)
- CVE-2026-20253 (1)
- CVE-2026-20262 (1)
- CVE-2026-20316 (1)
- CVE-2026-20896 (1)
- CVE-2026-21513 (1)
- CVE-2026-21858 (1)
- CVE-2026-23111 (1)
- CVE-2026-26980 (1)
- CVE-2026-2699 (1)
- CVE-2026-2701 (1)
- CVE-2026-28318 (1)
- CVE-2026-29059 (1)
- CVE-2026-3055 (1)
- CVE-2026-3300 (1)
- CVE-2026-33017 (3)
- CVE-2026-33691 (1)
- CVE-2026-33824 (1)
- CVE-2026-34486 (2)
- CVE-2026-34908 (1)
- CVE-2026-34909 (1)
- CVE-2026-34910 (1)
- CVE-2026-34926 (1)
- CVE-2026-35273 (2)
- CVE-2026-35616 (1)
- CVE-2026-39987 (2)
- CVE-2026-40138 (1)
- CVE-2026-40139 (1)
- CVE-2026-40140 (1)
- CVE-2026-40141 (1)
- CVE-2026-4020 (1)
- CVE-2026-41091 (1)
- CVE-2026-41703 (1)
- CVE-2026-41709 (1)
- CVE-2026-41940 (2)
- CVE-2026-42271 (1)
- CVE-2026-42533 (1)
- CVE-2026-42897 (2)
- CVE-2026-43074 (1)
- CVE-2026-43284 (1)
- CVE-2026-43499 (1)
- CVE-2026-43500 (1)
- CVE-2026-43503 (1)
- CVE-2026-44338 (1)
- CVE-2026-45247 (1)
- CVE-2026-45498 (1)
- CVE-2026-45659 (1)
- CVE-2026-46242 (1)
- CVE-2026-46300 (1)
- CVE-2026-46331 (1)
- CVE-2026-46817 (1)
- CVE-2026-47876 (1)
- CVE-2026-48172 (1)
- CVE-2026-48276 (1)
- CVE-2026-48277 (1)
- CVE-2026-48281 (1)
- CVE-2026-48282 (1)
- CVE-2026-48283 (1)
- CVE-2026-48285 (1)
- CVE-2026-48307 (1)
- CVE-2026-48313 (1)
- CVE-2026-48314 (1)
- CVE-2026-48315 (1)
- CVE-2026-48316 (1)
- CVE-2026-48558 (3)
- CVE-2026-48907 (2)
- CVE-2026-48908 (1)
- CVE-2026-48939 (1)
- CVE-2026-50522 (1)
- CVE-2026-50751 (1)
- CVE-2026-50752 (1)
- CVE-2026-53359 (1)
- CVE-2026-5426 (1)
- CVE-2026-54420 (1)
- CVE-2026-55255 (1)
- CVE-2026-56290 (1)
- CVE-2026-56291 (1)
- CVE-2026-59309 (1)
- CVE-2026-59310 (1)
- CVE-2026-59726 (1)
- CVE-2026-60137 (1)
- CVE-2026-62144 (1)
- CVE-2026-62145 (1)
- CVE-2026-63030 (1)
- CVE-2026-63077 (1)
- CVE-2026-66747 (1)
- CVE-2026-6682 (1)
- CVE-2026-6683 (1)
- CVE-2026-6684 (1)
- CVE-2026-6685 (1)
- CVE-2026-6686 (1)
- CVE-2026-6687 (1)
- CVE-2026-6688 (1)
- CVE-2026-67426 (1)
- CVE-2026-6875 (1)
- CVE-2026-7473 (1)
- CVE-2026-8037 (1)
- CVE-2026-8451 (1)
- CVE-2026-8461 (1)
- CVE-2026-8732 (1)
- CVE-2026-9082 (1)
- CVE-2026-9198 (1)
- CWE-22 (1)
- CWE-259 (1)
- CWE-306 (1)
- CWE-352 (1)
- CWE-502 (1)
- CWE-77 (1)
- CWE-78 (2)
- CWE-829 (1)
- cyber evaluation (1)
- cyber-espionage (5)
- CyberAv3ngers (1)
- cybercrime (13)
- cybercrime ecosystem (2)
- cyberespionage (5)
- Cython (1)
- Czech Republic (1)
- D-Link (1)
- D2IP (1)
- dangling resources (1)
- DarkSword (1)
- data analytics (1)
- data exfiltration (12)
- data exposure (3)
- data extortion (2)
- data leak site (3)
- data theft (10)
- data-exfiltration (1)
- database extortion (1)
- Datadog Security Labs (1)
- dataset dead drop (1)
- dataset processing (1)
- DAYLIGHT (1)
- DCloud (1)
- DCloud Uni-App (1)
- DcRAT (1)
- DD-WRT (1)
- DDNS (1)
- DDoS (8)
- DDoS botnet (1)
- DDoS-for-hire (3)
- dead drop (1)
- dead drop resolver (4)
- dead-drop resolver (2)
- DeadLock (1)
- Debian (1)
- debugger evasion (1)
- DEBULL (1)
- declarativeNetRequest (1)
- DeepAudit (1)
- DeepSeek (5)
- Defender Advanced Hunting (1)
- Defender evasion (2)
- Defender exclusion (1)
- defense (4)
- defense evasion (9)
- defense targeting (1)
- defense-evasion (1)
- DeFi (4)
- delayed execution (2)
- denial of service (6)
- Deno (2)
- Dependabot (1)
- dependency confusion (4)
- deployment_status (1)
- deserialization (7)
- destructive actions (1)
- destructive malware (3)
- destructive operations (3)
- detached execution (1)
- detached process (1)
- detection engineering (2)
- DEV#POPPER (1)
- DEV-0206 (1)
- developer credential theft (2)
- developer credentials (1)
- developer endpoints (3)
- Developer ID abuse (1)
- developer identity (1)
- developer infrastructure (1)
- developer machines (9)
- developer mode (1)
- developer platform (1)
- developer targeting (12)
- developer tooling (6)
- developer workstations (3)
- developer-machine-fleet (1)
- developer-targeting (22)
- developer-tools (1)
- developer-workstations (5)
- device identity (1)
- device lockout (1)
- device registration (1)
- device-code phishing (5)
- DevOps (1)
- DevTools (1)
- DEWMODE (1)
- DGA (1)
- DIAMONDBACK (2)
- digital forensics (1)
- Digital Knowledge (1)
- digital wallets (1)
- DigitalOcean (1)
- Dindoor (1)
- DingTalk (1)
- diplomatic targeting (3)
- direct-to-IP (1)
- directory traversal (1)
- DirtyClone (1)
- DirtyFrag (1)
- DISCLOSURE (1)
- Discord (2)
- discovery (1)
- disk wiping (1)
- distributed scanning (1)
- Djinn Stealer (3)
- DLL search-order hijacking (2)
- DLL side-loading (6)
- DLL sideloading (23)
- DMTP (1)
- DNS (1)
- DNS C2 (3)
- DNS callback (1)
- DNS dead drop (2)
- DNS exfiltration (4)
- DNS hijacking (1)
- DNS resolution (1)
- DNS threat intelligence (1)
- DNS tunneling (3)
- DNS-over-HTTPS (1)
- Docker (3)
- Docker Compose (1)
- Docker credentials (1)
- Docker images (1)
- Docker socket (2)
- document collection (1)
- document exfiltration (1)
- document theft (4)
- DOGLEASH (1)
- domain squatting (1)
- domestic espionage (1)
- dormant accounts (2)
- DotNetNuke (1)
- DotnetTool (1)
- double extortion (3)
- downgrade risk (1)
- downloader (1)
- downstream blast radius (1)
- DPAPI (3)
- DPAPILoader (1)
- DPRK (6)
- DragonForce (1)
- drive serial number (1)
- driver loading (1)
- DroneLink (1)
- Dropbear (1)
- Dropbox (2)
- dropper (1)
- Drupal (1)
- dual-use (1)
- dual-use tooling (1)
- duckdns (1)
- Dutch Police (1)
- DWAgent (1)
- dynamic DNS (1)
- dynamic obfuscation (1)
- Dynu (1)
- Dysphoria (1)
- e-commerce (1)
- Eagle Werewolf (2)
- Early Bird APC injection (1)
- Earth Lusca (2)
- East Asia (1)
- East Asia-linked (1)
- eBPF (3)
- Eclipse (1)
- Ed25519 (1)
- edge appliance (13)
- edge appliances (2)
- edge application server (1)
- edge device (3)
- edge devices (5)
- edge exploitation (1)
- Edge extension (1)
- edge service (2)
- edge services (1)
- editor profile import (1)
- EDR evasion (2)
- EDR killer (2)
- EDS5000 (1)
- education (3)
- Egnyte (1)
- Egypt (1)
- EKZ Infostealer (1)
- Elastic Security Labs (5)
- Elasticsearch (1)
- electric power sector (2)
- Electron (2)
- email (1)
- email exfiltration (2)
- email gateway (1)
- email infrastructure abuse (1)
- email security (1)
- email theft (4)
- embedded configuration (1)
- embedded Linux (1)
- embedded systems (1)
- Emerald Sleet (1)
- ENCFORGE (2)
- encrypted C2 (4)
- EncryptInterceptor (1)
- ENDLESSDOORS (1)
- endpoint compromise (1)
- endpoint management (2)
- endpoint management abuse (1)
- endpoint response (1)
- endpoint-detection (1)
- endpoint-security (2)
- EndpointDlp.dll (1)
- energy sector (5)
- energy-sector (1)
- engineering (1)
- engineering software (1)
- enterprise AI (1)
- enterprise application (2)
- enterprise application exploitation (1)
- enterprise applications (1)
- enterprise proxy (1)
- Entra ID (3)
- Environment Management Hub (1)
- environment variable theft (2)
- environment variables (1)
- environmental keying (9)
- epoll (1)
- Epsilon Stealer (1)
- ERP (1)
- error-message disclosure (1)
- eSentire TRU (1)
- ESG (1)
- espionage (58)
- Espressif ESP-IDF (1)
- ESX (1)
- ESXi (3)
- Ethereum (5)
- Ethereum Name Service (2)
- EtherHiding (5)
- Ethiopia (1)
- ETW bypass (1)
- ETW patching (2)
- ETW tampering (1)
- Eurojust (1)
- Europe (3)
- Europe targeting (1)
- European Union (1)
- Europol (2)
- evaluation containment (1)
- evasion (1)
- event log clearing (2)
- eventpoll (1)
- Everest Forms Pro (1)
- evidence quality (1)
- Evil Corp (1)
- EvilAI (1)
- Evilginx (1)
- EWS (1)
- excessive agency (1)
- exec_globals (1)
- execution guardrails (1)
- exFAT (1)
- exfiltration (5)
- exploit chain (1)
- exploit kit (1)
- exploit-development (1)
- exploit-kit (1)
- Exploit.in (1)
- exploitation (15)
- exploitation attempts (1)
- ExploitGym (1)
- exposed applications (1)
- exposed attacker infrastructure (1)
- exposed debug page (1)
- extension supply-chain (2)
- external federation (1)
- extortion (10)
- F5 (1)
- F5 BIG-IP (1)
- Factory-v3 (1)
- fake app store (1)
- fake CAPTCHA (5)
- fake certificate (1)
- fake crypto exchange (1)
- fake dating lures (1)
- fake gambling (1)
- fake installers (1)
- fake login (1)
- fake login screen (1)
- fake Microsoft Store (1)
- fake plugin (1)
- fake PoC (2)
- fake ransomware (1)
- fake recruiting (4)
- fake reputation (1)
- fake update (3)
- FakeCaptcha (1)
- FakeGit (1)
- Fakeset (1)
- faketivism (1)
- FakeUpdates (1)
- FALCON (1)
- FallSpy (1)
- FAMOUS CHOLLIMA (2)
- Famous Chollima (2)
- Fancy Bear (1)
- Fast16 (1)
- FastAPI (1)
- FastCGI (1)
- Fastjson (1)
- Fastmail (1)
- fat JAR (1)
- FAT32 (1)
- FatFs (1)
- FBI (3)
- fbot (1)
- FDMTP (2)
- Feiying (1)
- FFmpeg (1)
- FIDO2 (2)
- FIFA (1)
- file encryption (1)
- file exfiltration (1)
- file inflation (1)
- file operations (1)
- file sharing (1)
- file theft (1)
- File Transmission (1)
- file upload path traversal (1)
- file-system filter (1)
- FileFiend (1)
- FILEIO (1)
- fileless execution (3)
- fileless malware (1)
- filemanager (1)
- filename-injection (1)
- filesystem parser (1)
- finance (2)
- financial fraud (6)
- financial sector (7)
- financial services (5)
- financial theft (3)
- financially motivated (2)
- FireAnt MetaKit (1)
- Firebase (1)
- Firefox (1)
- Firefox Add-ons (1)
- Firefox WebDriver BiDi (1)
- Firepower Management Center (1)
- firewall (1)
- firewall management (2)
- firmware (2)
- firmware backdoor (1)
- firmware update (1)
- FishMonger (1)
- FlexPLM (1)
- FlockWiper (1)
- Flooding Dropper (1)
- flow execution (1)
- Flowerbed (3)
- FLUIDLEECH (1)
- Flutter (1)
- FlutterShell (1)
- Flying Eagle (1)
- Flyto2 Core (1)
- FMC (1)
- FOFA (2)
- FofaMap (1)
- folderOpen (1)
- foreign affairs targeting (2)
- foreign policy targeting (1)
- Forest Blizzard (1)
- Forg365 (1)
- ForgCookie (1)
- Forgejo (1)
- FortiClient EMS (1)
- FortiGate (3)
- Fortinet (4)
- FortiOS (3)
- FortiSandbox (1)
- Fox Tempest (2)
- fraud (2)
- FREAKYPOLL (1)
- FreeBSD (2)
- Freedom365 (1)
- freeware impersonation (1)
- Friendly Fire (1)
- FruitStone (1)
- FSB (4)
- FSB Center 16 (2)
- fscan (1)
- Fscan (1)
- FTA (1)
- ftp.exe (1)
- Full Disk Access social engineering (1)
- Funnull (1)
- futex PI (1)
- Gafgyt (1)
- GaiaOS WebUI (1)
- Gamaredon (3)
- Gamaredon collaboration (1)
- gambling (1)
- gambling industry targeting (1)
- game cheats (1)
- GammaLoad (1)
- GammaPhish (1)
- GammaSteel (1)
- GammaWorm (1)
- Garble (2)
- Gardener (1)
- Gatekeeper bypass (1)
- GCP (1)
- GCS (1)
- Gemini CLI (1)
- GenieLocker (3)
- GentleKiller (1)
- Germany (1)
- GHETTOVIBE (1)
- Ghost (2)
- ghost accounts (1)
- Ghost CMS (1)
- Ghost Networks (1)
- GHOSTBLADE (1)
- GhostLock (1)
- GHSA-6rmh-7xcm-cpxj (1)
- GHSA-6v3r-4p5c-mrp5 (1)
- GHSA-c4hm-4h84-2cf3 (1)
- GHSA-qrpv-q767-xqq2 (1)
- GHSA-rg76-677x-56q9 (1)
- GHSA-vwf4-m7j8-wcjf (1)
- GHSA-xhcr-j4j9-3gh7 (1)
- GIFTEDCROOK (1)
- Git (1)
- git.exe (1)
- Gitea (1)
- GitHub (23)
- GitHub abuse (3)
- GitHub Actions (25)
- GitHub Advisory Database (1)
- GitHub API (1)
- GitHub App (1)
- GitHub CLI (1)
- GitHub dead drop (3)
- GitHub issue spam (1)
- GitHub OAuth (1)
- GitHub Pages abuse (2)
- GitHub payload delivery (1)
- GitHub release assets (1)
- GitHub Security Advisories (3)
- GitHub tokens (2)
- GitHub-hosted runners (1)
- GitLab (2)
- gitleaks (1)
- GitOps (1)
- Gleaming Pisces (1)
- gleeze.com (1)
- GlobalProtect (1)
- Gmail (5)
- Go (5)
- Go loader (1)
- Go malware (4)
- Go modules (2)
- Go2Tunnel (1)
- GodDamn ransomware (1)
- GodPotato (1)
- Godzilla (1)
- GoEdge (1)
- GoFile (1)
- Golang (2)
- Golang malware (1)
- GOLD PRELUDE (1)
- Golden Pass-ta-key (1)
- Google Ads (1)
- Google Analytics telemetry (1)
- Google API (3)
- Google Calendar (1)
- Google Chrome (2)
- Google Cloud (1)
- Google Cloud Authenticator (1)
- Google Cloud Logging (1)
- Google Cloud Storage (1)
- Google credential theft (1)
- Google Docs (1)
- Google Drive (1)
- Google Notes (1)
- Google Password Manager (1)
- Google Play (1)
- Google Play Protect (1)
- Google redirect abuse (1)
- Google Sheets (1)
- Google Stitch (1)
- Google Threat Intelligence Group (3)
- Google Workspace (1)
- Goose (1)
- GoSerpent (1)
- government (5)
- government impersonation (1)
- government targeting (19)
- government-impersonation (1)
- GPT (1)
- GPT-5.6 Sol (1)
- Gradio (1)
- Grafana MCP Server (1)
- Grandoreiro (2)
- granular access tokens (1)
- GraphSpy (1)
- Gravity SMTP (1)
- gray market (1)
- GRE (1)
- Gremlin API (1)
- GREYVIBE (1)
- group (5)
- groups (16)
- gRPC (1)
- gRPC C2 (2)
- GRU (2)
- gs-netcat (1)
- GS-Netcat (1)
- Gshell (1)
- GTIG (2)
- GUE (1)
- guest-to-host escape (1)
- Guildma (1)
- Gunra (1)
- hack-and-leak (2)
- HackIndex (1)
- hacktivist persona (1)
- Hades (2)
- Hajime (1)
- half-click exploit (1)
- hallucination (1)
- HalluSquatting (1)
- Handala (1)
- HappyDoor (1)
- HAR files (1)
- hard-coded password (1)
- hard-coded secrets (1)
- hardware wallet (1)
- HarmonyLib (1)
- HashiCorp Vault (1)
- HavocKiller (1)
- HDF5 (1)
- headless browser (2)
- healthcare (3)
- heap buffer overflow (1)
- heap pointer disclosure (1)
- HELIX (1)
- HelloBackdoor (1)
- HelloCleaner (1)
- HelloDoor (1)
- HelloExecutor (1)
- HelloInjector (1)
- HelloNet (1)
- HelloProxy (1)
- HellsGate (1)
- Helm (1)
- Hermes Agent (3)
- HexKiller (1)
- hidden backdoor (1)
- hidden instructions (1)
- hidden service (1)
- high explosives (1)
- higher education (2)
- HOLLOWGRAPH (1)
- Honduras (2)
- HONESTCUE (1)
- Hong Kong (1)
- Hong Kong infrastructure (1)
- hospitality (1)
- hospitality targeting (2)
- Host Radar (1)
- host surveillance (1)
- hosting control plane (1)
- hosting provider (1)
- hosting providers (1)
- hotel targeting (1)
- Howling Scorpius (1)
- HPC (1)
- HR lures (1)
- HTA (5)
- HTML comments (1)
- HTML email (2)
- HTML sanitization (1)
- HTML smuggling (1)
- HTTP C2 (1)
- HTTP/2 (2)
- HttpMalice (1)
- HTTPS C2 (2)
- HTTPS exfiltration (1)
- HTTPSpy (1)
- Hugging Face (3)
- Hunt.io (4)
- Huntress (2)
- Hyadina (1)
- hybrid threat actor (1)
- hydropower (2)
- Hydropower Cooperation Project Proposal.zip (1)
- hypervisor escape (1)
- Hyunwoo Kim (1)
- I-SOON (2)
- IAM (1)
- IBM (1)
- iCagenda (1)
- ICE (1)
- iCloud theft (1)
- ICONICSTEALER (1)
- ICS (3)
- IDE extension (2)
- IDE plugins (1)
- ide.cfm (1)
- identity (4)
- identity attacks (1)
- identity compromise (1)
- identity infrastructure (1)
- identity security (1)
- identity-first intrusion (1)
- IDEs (2)
- IFEO persistence (1)
- IIOP (1)
- IIS (1)
- IKEv1 (1)
- Ill Bloom (1)
- image proxy bypass (1)
- image recognition (1)
- iMessage (1)
- Impacket (4)
- impersonation (1)
- implant (1)
- import-time execution (5)
- improper privilege management (1)
- in-memory DLL loading (1)
- in-memory malware (3)
- in-memory plugins (1)
- incident response (35)
- incident-response (2)
- incomplete patch (1)
- IndexedDB (3)
- India (3)
- India-nexus (1)
- Indian government (1)
- indirect prompt injection (8)
- indirect syscalls (1)
- Indonesia (1)
- industrial control (1)
- industrial control systems (3)
- industrial espionage (1)
- industrial targeting (1)
- INFINITERED (1)
- Infoblox Threat Intel (1)
- information disclosure (4)
- infostealer (25)
- InfoTeCS (1)
- infrastructure (6)
- infrastructure churn (1)
- infrastructure disruption (3)
- initial access broker (2)
- initial-access (3)
- Injective Labs (1)
- input capture (1)
- insider threat (1)
- install-time execution (6)
- install-time-execution (1)
- install.res.1033.dll (1)
- Integration Broker (1)
- Intercolo (1)
- internal secret exfiltration (1)
- internet exposure (1)
- internet-facing admin surface (1)
- internet-facing appliance (2)
- internet-facing applications (1)
- investment scam (1)
- InvisibleFerret (1)
- invocation logging (1)
- iOS (2)
- IoT (6)
- IoT botnet (7)
- IP cameras (1)
- IP-in-IP (1)
- IPFS (1)
- iPhone (1)
- IPsec (1)
- IPv6 (2)
- ipynbdiff (1)
- Iran (8)
- Iran-nexus (3)
- IRGC (1)
- IronWorm (1)
- Irregular (1)
- ischhfd83 (1)
- Island Security Research (2)
- ISO image (2)
- Israel (4)
- IT providers (1)
- Italian foreign-policy targeting (1)
- Italy targeting (1)
- Ivanti Sentry (1)
- JackSkid (1)
- JADEPUFFER (2)
- Jamf Threat Labs (2)
- Januscape (1)
- Japan (1)
- JARLEASH (1)
- Java (1)
- Java malware (1)
- JavaScript (17)
- JavaScript bridge (1)
- JavaScript execution (1)
- JavaScript injection (2)
- JavaScript loader (1)
- JavaScript malware (5)
- JavaScript masquerading (1)
- JavaScript tampering (1)
- JavaScriptCore (1)
- JCE (1)
- JDY (1)
- Jellyfin (1)
- Jenkins (1)
- JetBrains (3)
- JetBrains Marketplace (1)
- JetStream (1)
- JFrog (3)
- JFrog Artifactory (1)
- JFrog Security Research (3)
- Jinja2 (1)
- JINX-0164 (2)
- Jira (1)
- joblib (1)
- Joomla (3)
- Joomla Content Editor (1)
- Joomla JCE (1)
- Joomlack (1)
- JoomShaper (1)
- Jordan (1)
- journalists (1)
- JSCoreRunner (1)
- jscrambler (1)
- Jscrambler (1)
- JScript (1)
- JSON (1)
- JSON-RPC (1)
- JSON:API (1)
- JSONKeeper (1)
- JSONPing (1)
- JSP web shell (1)
- JuicyPotato (2)
- Jupyter Notebook (1)
- JustWatch (1)
- JXA downloader (1)
- K1MORPHER (2)
- Kairos (1)
- Kaitori (1)
- Kali365 (1)
- Kaspersky (2)
- Kaspersky GERT (1)
- Kaspersky GReAT (3)
- Kaspersky Securelist (2)
- Kazakhstan (2)
- KAZUAR (2)
- KAZUAR overlap (1)
- KeePassXC (1)
- Keitaro (1)
- Keksec (1)
- Kemp LoadMaster (1)
- kernel driver (3)
- kernel instrumentation (1)
- kernelCTF (2)
- KEV (3)
- Keychain theft (1)
- keychain theft (4)
- KeyHunter (1)
- keylogger (5)
- keylogging (2)
- Kimsuky (1)
- Kimwolf (1)
- Kimwolf v7 (1)
- Klue (1)
- knaithe (2)
- KnowledgeDeliver (1)
- known exploited vulnerability (1)
- KNUCKLEBALL (1)
- KNX (1)
- KNX Association (1)
- KNX Protocol (1)
- KnYuan (2)
- KongTuke (1)
- KORKERDS (1)
- Kratos (1)
- Kubernetes (6)
- KV-botnet (1)
- KVM (1)
- KVM escape (1)
- kvmCTF (1)
- Kyrgyzstan (1)
- L2TP/IPSec (1)
- LA Metro (1)
- Laboo.boo (2)
- LabubaPanel (1)
- LabubaRAT (1)
- Labubu (2)
- LangChain (2)
- Langflow (10)
- LangFlow (1)
- LangGraph (1)
- Language Servers for AWS (1)
- Lantronix (1)
- LapDogs (1)
- Laravel (2)
- Laravel deserialization (1)
- lateral movement (7)
- lateral-movement (1)
- Latin America (2)
- LaunchAgent (4)
- launchctl (1)
- LAUNDRY BEAR (4)
- law enforcement (2)
- law enforcement targeting (2)
- law-enforcement-disruption (1)
- LayerX (1)
- Lazarus (6)
- LD_PRELOAD (2)
- LDAP (1)
- leaked credentials (1)
- leaked exploit (1)
- leaked source code (1)
- LEASHTEST (1)
- least privilege (4)
- Ledger (1)
- legacy botnet hijacking (1)
- legacy infrastructure (1)
- legacy software (1)
- legacy systems (1)
- legal sector (1)
- LegionRelay (1)
- Leo Platform (1)
- Level RMM (1)
- LevelBlue (1)
- Lexfo (1)
- libcurl (1)
- liblzma (1)
- libp2p (1)
- libpeconv (1)
- libsodium (1)
- lifecycle hooks (1)
- lifecycle-hooks (1)
- Lightning Shared Scooter Co. (1)
- LinkedIn (2)
- Linksys (1)
- Linux (28)
- Linux kernel (5)
- Linux malware (3)
- Linux networking devices (1)
- LiteLLM (3)
- LiteSpeed (2)
- living off the land (1)
- living-off-the-land (1)
- living-off-the-land binaries (1)
- LLM (5)
- LLM security (1)
- LLM-assisted malware (3)
- LLM-driven intrusion (1)
- LLMjacking (1)
- LMS (1)
- LNK (10)
- LNK files (1)
- load balancer (1)
- loader (7)
- LOADLOOP (1)
- local LLMs (1)
- local privilege escalation (6)
- local-file-inclusion (1)
- localhost (1)
- localhost.run (1)
- localStorage (2)
- LockBit (2)
- LockBit 3.0 (1)
- log poisoning (1)
- logging (1)
- logging impairment (1)
- login item persistence (1)
- LOLBins (3)
- long-horizon autonomy (1)
- long-lived tokens (1)
- long-term access (1)
- LONGLEASH (1)
- LONGSTREAM (1)
- LOOKVALJS (1)
- LOOKVALPS (1)
- loopback (1)
- Loophole (1)
- low-confidence attribution (4)
- LPE (1)
- LS-DYNA (1)
- LSASS (1)
- LSHIY (1)
- LSSC (1)
- Lua (1)
- LuaJIT (1)
- Lumen (1)
- Lumen Black Lotus Labs (1)
- Lumma Stealer (1)
- Luna Moth (1)
- Luno (1)
- LurkProxy (2)
- Lyceum (1)
- M-RED-TEAM (1)
- MaaS (7)
- MAC address (1)
- MacCMS (1)
- Maccy impersonation (1)
- machine-learning (1)
- macOS (18)
- macOS malware (2)
- MaDoO Blaster (1)
- Magento (1)
- MagicYUV (1)
- mail server compromise (1)
- mail-argenta (1)
- mailbox compromise (1)
- mailbox permission abuse (2)
- mailbox theft (3)
- MAIN world injection (1)
- maintainer compromise (5)
- maintainer persona (1)
- maintainer-compromise (2)
- malicious dataset (1)
- malicious GPO (1)
- malicious package (1)
- malicious packages (5)
- malicious plugin (1)
- malicious releases (2)
- malicious signed driver (1)
- malvertising (9)
- malware (59)
- malware analysis (2)
- malware delivery (7)
- malware framework (3)
- malware scanning (1)
- Malware-as-a-Service (1)
- malware-as-a-service (5)
- malware-signing-as-a-service (1)
- MALXMR (1)
- managed database (1)
- managed file transfer (2)
- managed service provider (2)
- ManageEngine Endpoint Central (1)
- management plane (5)
- Manifest V3 (1)
- Manifold Security (1)
- manufacturing (3)
- Mapbox (2)
- marimo (2)
- Markdown image rendering (1)
- MARKETMAKER (1)
- marketplace abuse (2)
- marketplace trust (1)
- MarkiRAT (1)
- mass scanning (1)
- Maven Central (1)
- mawesome (1)
- Mbed (1)
- McAfee Labs (1)
- McMx (1)
- MCP (14)
- MCP credentials (1)
- mcp-grafana (1)
- media processing (1)
- medical research (1)
- Mekotio (1)
- memfd (1)
- memory corruption (2)
- memory disclosure (2)
- memory implant (1)
- memory overread (1)
- memory poisoning (1)
- memory-only malware (1)
- merchant credential theft (1)
- mesh VPN (1)
- MeshAgent (1)
- MeshCentral (2)
- Meta Ads (1)
- Metabase (1)
- MetaMask (1)
- MEV bot lure (1)
- Mexican banking fraud (2)
- Mexico (3)
- MFA bypass (9)
- MFA fatigue (1)
- MFA-bypass (1)
- MFT (1)
- Miasma (10)
- MicroLogix 1100 (1)
- MicroLogix 1400 (1)
- MicroPython (2)
- Microsoft (10)
- Microsoft .NET (1)
- Microsoft 365 (8)
- Microsoft 365 Copilot (1)
- Microsoft Authentication Broker (1)
- Microsoft Azure (1)
- Microsoft Defender (1)
- Microsoft Defender Security Research (1)
- Microsoft dev tunnels (2)
- Microsoft Digital Crimes Unit (1)
- Microsoft Edge (2)
- Microsoft Edge Add-ons (2)
- Microsoft Edge Extensions Security Team (1)
- Microsoft Entra ID (5)
- Microsoft Exchange Server (2)
- Microsoft Graph (3)
- Microsoft Identity Platform (1)
- Microsoft Office SharePoint (1)
- Microsoft Security Blog (1)
- Microsoft SQL Server (1)
- Microsoft Teams (4)
- Microsoft Threat Intelligence (5)
- Microsoft Windows Hardware Compatibility Publisher (1)
- Microsoft-signed binary abuse (1)
- Middle East (7)
- middleware (1)
- Midnight Blizzard (2)
- military logistics (1)
- military research (1)
- Milo Wallet (1)
- Mimikatz (6)
- Minecraft DDoS (1)
- Mini Shai-Hulud (5)
- MiniJunk (1)
- MiniPlasma (1)
- MINIRAT (2)
- MINIRECON (2)
- Ministry of Finance (2)
- MiniUpdate (1)
- MIPS embedded devices (1)
- Mirage Kitten (5)
- Mirai (3)
- Mirai-derived botnet (1)
- Mistic (1)
- MITRE ATT&CK T1005 (1)
- MITRE ATT&CK T1562 (1)
- mixed boolean arithmetic (3)
- MIXEDKEY (3)
- MLTBackdoor (1)
- mnemonic theft (1)
- mobile (1)
- Mobile Access (1)
- mobile banking fraud (1)
- mobile device management (1)
- mobile devices (1)
- mobile exploitation (1)
- mobile malware (3)
- MobileIron Sentry (1)
- MODBEACON (2)
- Model Context Protocol (10)
- model poisoning (1)
- model weights (1)
- model-provider abuse (1)
- ModeloRAT (1)
- ModHeader (1)
- modular malware (3)
- module-proxy (1)
- MOIS (6)
- Monero (2)
- Monero mining (1)
- MongoDB (1)
- Monster ransomware (1)
- Mozi (2)
- MpClient.dll (1)
- MpExtMs.exe (1)
- MPR network provider (1)
- Mr_Rot13 (1)
- MSBuild (1)
- msgpack (1)
- mshta (5)
- MSI (1)
- MSP (3)
- MSSQL (1)
- mTLS (1)
- Muck and Load (1)
- MuddyWater (4)
- Mullvad VPN (1)
- Multi-Domain Security Management (1)
- multi-tenant cloud (2)
- multi-tenant isolation (1)
- Multiply-With-Carry (1)
- Mustang Panda (4)
- Mustard Tempest (1)
- mutable tags (2)
- mutation attacks (1)
- mutex (1)
- MYRA (1)
- MySQL (1)
- Mysterious Elephant (1)
- Mythos (1)
- N-able (2)
- N-central (2)
- n8n (2)
- Nacos (2)
- NadMesh (1)
- named pipes (1)
- namespace recycling (1)
- namespace squatting (2)
- NanChat (1)
- NAS targeting (1)
- nation-state (1)
- national identity records (1)
- native addon (1)
- native extension (3)
- NativeAOT (3)
- NATO (3)
- NATS (1)
- NCSC-NL (1)
- Nebo (1)
- Nebula Security (1)
- Negotiate (1)
- negotiation (1)
- Neo-reGeorg (1)
- neocloud (1)
- nested virtualization (1)
- Neteller (1)
- Netherlands (2)
- Netlify abuse (1)
- NetNut (1)
- NetScaler (2)
- NetScaler ADC (2)
- NetScaler Gateway (2)
- NetSetup.log (1)
- network detection (1)
- network infrastructure (2)
- network infrastructure exploitation (1)
- network isolation bypass (1)
- network policies (1)
- network-share exfiltration (1)
- Nextcloud (1)
- Nextcloud Flow (1)
- nf_tables (1)
- nftables (1)
- NGINX (1)
- Nginx (2)
- Nginx module (1)
- ngrok (1)
- Ngrok C2 (1)
- Nigeria-nexus (1)
- Night Dragon (1)
- NightLedger (2)
- Nimbus Manticore (2)
- NirSoft (1)
- no attribution (1)
- No-IP (1)
- node-gyp (2)
- node-ipc (1)
- node-pty (1)
- Node.js (5)
- Node.js implant (1)
- Node.js malware (1)
- North Korea (13)
- notarized malware (2)
- notification interception (1)
- npm (59)
- npm lifecycle hook (3)
- npm supply-chain (1)
- npm token theft (1)
- npm tokens (1)
- npm v12 (1)
- npx (1)
- NSecKrnl.sys (1)
- NTDS.dit (2)
- NTFS ADS (2)
- NTLM (2)
- nuclear weapons (1)
- NuGet (4)
- Nuitka (1)
- null-byte padding (1)
- NullReceiver (1)
- NVGRE (1)
- NVIDIA impersonation (1)
- O-UNC-066 (1)
- OAuth (5)
- OAuth 2.1 (1)
- OAuth abuse (4)
- OAuth client credentials (1)
- OAuth device authorization grant (2)
- OAuth redirect (1)
- OAuth token abuse (1)
- OAuth token exposure (1)
- OAuth token theft (2)
- OAuth tokens (3)
- OBF networks (1)
- obfuscation (1)
- obfuscator.io (1)
- Oblivion (2)
- obsolete software (1)
- OctLurk (2)
- Octopi365 (1)
- OFAC (1)
- official store compromise (1)
- Offshore LC (1)
- OIDC (8)
- OilRig (1)
- Oj (1)
- OkoBot (1)
- Okta (5)
- Okta Threat Intelligence (1)
- OKX (1)
- Ollama (2)
- Oman (1)
- Omnibox (1)
- OmniStealer (1)
- OneDrive (3)
- OneDrive access (1)
- onion routing (1)
- opaque predicates (2)
- open directory (1)
- Open Interpreter (1)
- Open VSX (1)
- Open WebUI (1)
- OpenAI (2)
- OpenAI Codex (1)
- OpenClaw (1)
- opencode (1)
- OpenConnect (1)
- OpenHands (1)
- OpenSearch (1)
- OpenShield (1)
- OpenSSF (1)
- OpenSSH (2)
- OpenVPN (3)
- OpenVPN-shaped UDP (1)
- OpenVSX (1)
- OpenWrt (1)
- operation (3)
- Operation BlueDash (1)
- Operation DangerousPassword (1)
- Operation Endgame (1)
- Operation Highland (2)
- operational relay box (1)
- Operational Relay Box (1)
- operational resilience (1)
- operational security (1)
- operational technology (2)
- operations (261)
- operator lockout (1)
- OpFauxSign (1)
- opportunistic exploitation (1)
- ops (295)
- opsec failure (1)
- Oracle (1)
- Oracle E-Business Suite (1)
- Oracle Payments (1)
- Oracle PeopleSoft (2)
- Oracle WebLogic Server (1)
- ORANGETAIL (1)
- ORB network (1)
- OS command injection (2)
- OT (3)
- OT switches (1)
- OTA update (1)
- OTP interception (1)
- OtterCookie (1)
- out-of-bounds write (1)
- outbound C2 (1)
- Outlook (2)
- Outlook Web Access (2)
- overlay attacks (2)
- OWA (1)
- OWAReaper (2)
- OX Security (1)
- OxideHarvest (1)
- OYSTERBLUES (1)
- OYSTERFRESH (1)
- OYSTERSHUCK (1)
- P2P (1)
- P2P C2 (1)
- package hijacking (1)
- package masquerading (1)
- package registry (9)
- package registry abuse (1)
- package registry credentials (1)
- package registry proxy (1)
- package republishing (1)
- package scanning (1)
- package takedown (1)
- package-cooldowns (1)
- package-manager-hardening (1)
- package-splitting (1)
- package-takeover (1)
- Packagist (5)
- PAExec (1)
- Page Builder CK (1)
- page cache (2)
- page poisoning (1)
- Pakistan (4)
- Pakistan-linked (2)
- Palo Alto Networks (1)
- PAM (2)
- PAM credential validation (1)
- PamStealer (1)
- PAN-OS (1)
- Pandora RC (1)
- parallel-intrusion (1)
- parameter-to-prompt (1)
- partial encryption (1)
- Pass-ta-key (1)
- passkeys (2)
- password manager theft (1)
- password spray (1)
- password spraying (3)
- password-protected archive (2)
- passwordless authentication (1)
- Pastebin (2)
- PAT theft (1)
- patch management (2)
- path hijacking (1)
- path traversal (2)
- Patriot Bait (1)
- patterns (37)
- payload loader (1)
- payload staging (1)
- payload-as-a-service (1)
- payment fraud (1)
- payment SDK (1)
- payment skimmer (1)
- payment workflow exposure (1)
- payment-card theft (2)
- payment-card-theft (2)
- PayPal (1)
- payroll lures (1)
- Paysafe (1)
- pe_to_shellcode (1)
- PebbleDash (1)
- pedit (1)
- pentesting (1)
- people (1)
- PeopleTools (1)
- PerfWatson2.exe (1)
- Perplexity AI (1)
- persistence (32)
- persistent root access (1)
- persona operations (1)
- personal access tokens (2)
- pfSense (1)
- PhaaS (2)
- Phantom Gyp (3)
- PhantomClick (1)
- PhantomMail (1)
- PhantomRelay (1)
- Philippines (1)
- phishing (25)
- phishing overlays (1)
- phishing-as-a-service (5)
- Phorpiex (1)
- PHP (2)
- PHP code execution (1)
- PHP code injection (1)
- PHP object injection (1)
- PHP upload (1)
- PHP web shell (1)
- physical systems (1)
- physics (1)
- PicassoLoader (1)
- pickle (1)
- pig butchering (1)
- pig-butchering (1)
- PINK (1)
- Pink (1)
- Pipedream (1)
- pipelines (1)
- piracy (1)
- Piriform (1)
- Pix (1)
- Pixeldrain (1)
- PixelSmash (1)
- PKGBUILD (1)
- plaintext HTTP (1)
- Plandex (1)
- PLC (1)
- PLENET (2)
- plugin architecture (2)
- plugin framework (1)
- PlugX (3)
- poisoned-branch (1)
- PoisonX (1)
- police digital services (1)
- PolinRider (3)
- Poly1305 (1)
- polyfill (1)
- Polygon (4)
- Polygon blockchain dead drop (2)
- Polymarket (1)
- polymorphic loader (1)
- polymorphic payloads (1)
- Popa (1)
- portmap (1)
- PortSwigger Research (1)
- Portugal (1)
- post-authentication RCE (1)
- post-exploitation (6)
- post-exploitation framework (1)
- postal-impersonation (1)
- PostCSS (1)
- PostgreSQL (4)
- postinstall (10)
- PowerCloud (1)
- PowerShell (25)
- PowerShell execution (1)
- PowerShell malware (3)
- PowerShower (1)
- PPtP (1)
- PRA (1)
- PraisonAI (1)
- PRC (1)
- PRC-aligned (1)
- PRC-nexus (1)
- pre-auth RCE (1)
- pre-authentication (2)
- pre-authentication RCE (1)
- Prefetch (1)
- preinstall (3)
- presigned URLs (1)
- primary keys (1)
- Primitive Bear (1)
- PrincessClub (1)
- priority inheritance (1)
- privacy (1)
- privacy exposure (1)
- private key theft (1)
- private packages (1)
- private registry fallback (1)
- private-key theft (1)
- privilege escalation (10)
- privileged proxy (1)
- Privileged Remote Access (1)
- PRNG (1)
- process discovery (1)
- process doppelgänging (1)
- process environment scraping (1)
- process hollowing (3)
- process injection (6)
- process termination (2)
- product lifecycle management (1)
- professional services (1)
- profile.d (1)
- Program Compatibility Assistant (1)
- Progress Kemp LoadMaster (1)
- Progress Software (1)
- Project Proposal.exe (1)
- prompt injection (8)
- prompt-injection (4)
- PromptArmor (1)
- PROMPTFLUX (1)
- PROMPTSPY (1)
- promptware (1)
- proof of deletion (1)
- Proofpoint (1)
- protestware (1)
- Protobuf (1)
- Proton Mail (1)
- provenance (1)
- proxy (11)
- proxy network (2)
- ProxyChains (1)
- proxyjacking (1)
- proxyware (1)
- prt-scan (1)
- PSEMHUB (1)
- pseudorandom number generator (1)
- PsExec (4)
- PSIGW (1)
- psychological operations (1)
- PTC (1)
- PteroBox (2)
- PteroPaste (2)
- PteroPSDoor (2)
- PteroSetup (2)
- PteroVDoor (2)
- public exploit (3)
- public file-transfer exfiltration (1)
- public proof of concept (1)
- public sector (2)
- Public Security Bureau impersonation (1)
- public service abuse (1)
- public-service C2 (1)
- publish-time scanning (1)
- pull requests (2)
- PUP (1)
- PureLogs Stealer (1)
- PureRAT (1)
- pwn-request (1)
- PyArmor (3)
- PyInstaller (2)
- PyPI (14)
- Python (15)
- Python extension modules (1)
- Python malware (2)
- Python stealer (1)
- Qianxin Threat Intelligence Center (2)
- QiAnXin XLab (4)
- Qilin (3)
- QNAP (1)
- QR code (1)
- QR code interception (1)
- quantum computing (1)
- Quasar (1)
- query injection (1)
- Quest KACE SMA (1)
- QuickFox (1)
- QuimaRAT (1)
- RaaS (2)
- RabbitMQ (1)
- race condition (1)
- RainbowEx (1)
- RakNet flood (1)
- RAM disk (1)
- random number generator (1)
- Ransom-ISAC (1)
- ransomware (18)
- ransomware access (1)
- ransomware enablement (1)
- ransomware-access (1)
- rapid exploitation (2)
- Rapid7 (1)
- RAR archives (1)
- RAR staging (2)
- RAT (31)
- Ray (1)
- RC4 (4)
- RC4 C2 (1)
- RCE (6)
- Rclone (1)
- rclone (1)
- RCS (1)
- RDP (3)
- RDP phishing (1)
- RDS (1)
- Reality (1)
- Reaper (1)
- reconnaissance (3)
- recovery denial (3)
- recovery disruption (2)
- recovery flow (1)
- recovery phrase (1)
- recruitment lures (1)
- Red Dev 10 (2)
- Red Hat (1)
- Red Raindrop Team (2)
- REDACT (1)
- RedAlert (1)
- REDCap (1)
- Redis (5)
- Redis backdoor (1)
- RediSearch (1)
- reduced cyber refusals (1)
- RedWing (2)
- REF6045 (2)
- REF9403 (1)
- reflective .NET loading (1)
- reflective loading (7)
- refresh token theft (1)
- refresh tokens (1)
- RegAsm process hollowing (1)
- registry controls (1)
- registry persistence (6)
- registry storage (1)
- registry-controls (1)
- release automation (1)
- release tampering (1)
- Remcos (2)
- Remcos RAT (1)
- remote access (6)
- remote access software (1)
- remote access trojan (5)
- Remote Access VPN (1)
- remote code execution (21)
- remote debugging (2)
- remote MCP (1)
- remote monitoring and management (2)
- remote script injection (1)
- Remote Support (1)
- remote support (2)
- Remote Utilities (2)
- remote-access (2)
- Remotely (1)
- RemotePE (1)
- RemotePELoader (1)
- removable media (1)
- Rentry (1)
- replication (1)
- repo-server (1)
- repository compromise (1)
- repository exfiltration (1)
- repository poisoning (3)
- research sector (1)
- residential proxies (1)
- residential proxy (1)
- residential proxy abuse (1)
- responsible disclosure (1)
- REST API (1)
- REST C2 (1)
- restart-triggered execution (1)
- retail (2)
- retail trading (1)
- reverse proxy (2)
- reverse SSH tunneling (3)
- reverse tunneling (1)
- reverse tunnels (1)
- REVERSE_PROXY_TRUSTED_PROXIES (1)
- ReverseSocks (1)
- reviewdog (1)
- Rilide (1)
- RingH23 (1)
- RMM (5)
- RMM abuse (10)
- ROADrecon (1)
- ROADtools (1)
- roadtx (1)
- Rockwell Automation (1)
- Rokarolla (2)
- RokRAT (1)
- Rollup (1)
- RomulusLoader (1)
- Roo-Code (1)
- root (2)
- root access (1)
- root escalation (1)
- root execution (2)
- root shell (1)
- rootkit (4)
- ROOTRUN (1)
- Rootstock (1)
- ROPC (1)
- Rouki obfuscation (1)
- Roundcube (1)
- router (1)
- router compromise (3)
- router malware (1)
- Rovo (1)
- ROX II (1)
- RRWallet (1)
- RSA (1)
- RSA-2048 (2)
- RSA-OAEP (1)
- RT-Thread (1)
- RTL819X (1)
- RTLO (1)
- rtmutex (1)
- RubyGems (3)
- Ruckus routers (1)
- Ruflo (1)
- RUGGEDCOM (1)
- Run key (1)
- Run key persistence (1)
- rundll32 (2)
- Runner.Worker (1)
- Runspace (1)
- runtime execution (2)
- runtime mutation (1)
- runtime patching (1)
- runZero (1)
- Russia (13)
- Russia targeting (2)
- Russia-affiliated (2)
- Russia-linked (3)
- Russia-linked cybercrime (1)
- Russia-nexus (2)
- Russia-speaking operator (1)
- Russian Intelligence Services (1)
- Russian intelligence services (1)
- Russian state-supported (4)
- Russian-speaking ecosystem (1)
- Russian-speaking forums (1)
- Rust (8)
- Rust malware (6)
- S3 Browser (1)
- S3-compatible storage (2)
- s5cmd (1)
- SaaS (5)
- SaaS abuse (1)
- SaaS connectors (1)
- SaaS data access (1)
- SaaS exposure (1)
- sabotage (2)
- Safari (1)
- SafeDep (5)
- Salesforce (3)
- SAML IdP (1)
- Samsung TizenRT (1)
- sandbox escape (3)
- sandbox evasion (1)
- sandboxing (1)
- Sandworm (2)
- saroula01 (1)
- scam infrastructure (1)
- scambling (1)
- scanner evasion (1)
- ScarCruft (1)
- scheduled task (6)
- scheduled task persistence (6)
- scheduled tasks (6)
- SCMBANKER (2)
- scope squatting (1)
- scoped package impersonation (1)
- SCOUTCURL (1)
- screen capture (3)
- ScreenConnect (5)
- Screening Serpens (1)
- screenshot capture (2)
- screenshot theft (3)
- script-injection (1)
- SD-WAN (2)
- search hijacking (1)
- search poisoning (1)
- search result poisoning (1)
- search-ms (1)
- Seashell Blizzard (2)
- Secret Blizzard (3)
- secret exposure (1)
- secrets (6)
- secrets management (1)
- SectopRAT (1)
- Secure Firewall Management Center (1)
- Secure Preferences (1)
- Security Management Server (1)
- security platform (1)
- security-tool discovery (1)
- seed phrase theft (2)
- seed recovery (1)
- SeedHunter (1)
- Seedworm (3)
- segmented networks (1)
- Sekoia (1)
- self-delete (1)
- self-hosted AI services (1)
- self-hosted media (1)
- self-hosted runner (1)
- self-propagation (1)
- semantic-release (1)
- sendit.sh (1)
- sensitive information exposure (1)
- Sentinel (1)
- SentinelOne (1)
- Sentry (1)
- Sentry abuse (1)
- SEO poisoning (6)
- Seqrite Labs (1)
- Serv-U (1)
- service accounts (2)
- service impairment (1)
- service persistence (1)
- service providers (1)
- service stop (1)
- service-agent (1)
- ServiceNow (2)
- ServiceNow AI Platform (1)
- ServiceWorker (1)
- Session (1)
- session cookie theft (3)
- session hijacking (2)
- session secret exposure (1)
- session theft (2)
- session token theft (1)
- setuid (1)
- setup.py (1)
- shadow copy deletion (2)
- shadow MMU (1)
- SHADOW-AETHER-040 (1)
- SHADOW-AETHER-064 (1)
- SHADOW-EARTH-066 (1)
- SHADOW-WATER-063 (1)
- ShadowPad (3)
- Shai-Hulud (11)
- SHARDLOADER (2)
- share propagation (1)
- shared accounts (1)
- shared hosting (3)
- shared secrets (1)
- SharedWorker (1)
- ShareFile (1)
- SharePoint (5)
- SharePoint Server (1)
- SharkLoader (1)
- shell injection (1)
- Shenzhen Zhibotong Electronics (1)
- ShinyHunters (2)
- Shodan (1)
- ShortLeash (1)
- Shuckworm (1)
- SideCopy (1)
- sideloading (1)
- Siemens (1)
- Signal (3)
- Signal interception (1)
- signed malware (1)
- signed updates (1)
- signed-binary (1)
- Silent Ransom Group (1)
- Silent Swap (1)
- SilentCryptoMiner (1)
- SilentRunLoader (1)
- SiliconFlow (1)
- SilkLurk (2)
- Silver Fox (2)
- Silver Pass-ta-key (1)
- SimpleHelp (4)
- SimpleHTTPServer exposure (1)
- simulation tampering (1)
- Site Member permissions (1)
- skb (1)
- SkillCloak (1)
- SkillDetonate (1)
- Skrill (1)
- sleeper packages (1)
- Sliver (2)
- SLSA (1)
- SLSA provenance (1)
- SMA1000 (2)
- smart building (1)
- smart contracts (2)
- smart TVs (1)
- SMARTAXE (1)
- SmartConsole (1)
- SmartLoader (1)
- SmartScreen (1)
- SMB (1)
- SMB brute force (1)
- SMB egress (1)
- smishing (4)
- Smoke Sandstorm (2)
- SMS interception (2)
- SMS theft (1)
- sms-phishing (1)
- SMTP (1)
- SMTP abuse (1)
- Snake (1)
- Sneaky 2FA (1)
- Snowflake (1)
- SNOWLIGHT (1)
- SOAP API abuse (1)
- SocGholish (1)
- social engineering (16)
- social-engineering (2)
- Socket (4)
- Socket Security (3)
- Socket Security Research (2)
- Socket.IO (2)
- SOCKS tunneling (1)
- SOCKS5 (9)
- SOCKS5 proxy (1)
- SOCKS5 tunneling (1)
- SOCRadar (2)
- SoftEther VPN (2)
- SoftPerfect Network Scanner (1)
- software impersonation (1)
- software supply chain (2)
- software-deployment (1)
- SOHO router (1)
- SOHO routers (1)
- Solana (3)
- Solana Name Service (1)
- SolarWinds (1)
- Solid PDF Creator (1)
- SolidPDFCreator.dll (1)
- SolidPDFPcl2Bmp (1)
- Sonatype (2)
- sonatype-2026-005660 (1)
- sonatype-2026-005899 (1)
- sonatype-2026-005901 (1)
- SonicWall (2)
- Sophos (1)
- source code (1)
- source control (3)
- source repository compromise (1)
- source-code compromise (1)
- source-control token theft (1)
- source-package drift (1)
- source-package mismatch (2)
- source-repository abuse (1)
- source-repository poisoning (6)
- source-repository reconnaissance (1)
- SourceForge abuse (1)
- SourTrade (1)
- South Africa (1)
- South Asia (1)
- South Korea (2)
- Southeast Asia (6)
- SP Page Builder (1)
- spam (1)
- spear phishing (10)
- spear-phishing (2)
- spearphishing (1)
- SPECTRALVIPER (1)
- Sphinx ransomware (1)
- SpiderLabs (1)
- Spikey Scorpius (1)
- Splunk (1)
- Spring Boot (1)
- SprySOCKS (2)
- spyware (1)
- SQL injection (7)
- SQLite (1)
- SQLite state (1)
- SQLRCE0 (1)
- SquareShell (1)
- SSDP (1)
- SSH (4)
- SSH backdoor (1)
- SSH bastion (1)
- SSH brute force (2)
- SSH key exposure (1)
- SSH key persistence (1)
- SSH keys (4)
- SSH lateral movement (1)
- SSH persistence (1)
- SSH tunnel (1)
- SSH tunneling (1)
- SSH tunnels (1)
- SSL VPN (2)
- SSRF (6)
- stack use-after-free (1)
- staged malicious update (1)
- staged publishing (1)
- stale access (1)
- stale credentials (1)
- Starland RAT (3)
- Startup folder (1)
- Startup folder persistence (1)
- state-linked (2)
- state-owned enterprise (1)
- static credentials (1)
- Static Kitten (1)
- stdio (3)
- StealC (2)
- stealer (3)
- Steam profile dead drop (2)
- steganography (3)
- StegoAd (1)
- StepSecurity (2)
- STM32Cube (1)
- stock exchange (1)
- STOCKSTAY (3)
- storage deletion (1)
- Storage Zone Controller (1)
- stored XSS (1)
- Storm-2603 (1)
- Storm-2697 (1)
- Storm-2945 (1)
- Storm-3075 (1)
- Stowaway (1)
- STRD (3)
- streaming boxes (1)
- Stripe OLT (1)
- student targeting (1)
- STUN (1)
- Stuxnet lineage (1)
- subject claim (1)
- SuccessKey (1)
- SUMMIT (3)
- Suo5 (1)
- Supabase (1)
- SUPERADMIN_SECRET (1)
- supply chain (15)
- supply chain compromise (1)
- supply-chain (99)
- supply-chain attack (1)
- supply-chain attribution (1)
- supply-chain integrity (1)
- supply-chain risk (1)
- supply-chain-adjacent (1)
- surveillance (1)
- suspected China-aligned (1)
- suspected China-linked (1)
- SVG (2)
- SWE-agent (1)
- SweetPotato (1)
- SWUpdate (1)
- Symantec Threat Hunter Team (2)
- symbolic link (1)
- symlink following (1)
- Synacktiv (1)
- Synology (1)
- synthetic commits (1)
- Syria (1)
- Sysdig (2)
- SYSTEM (1)
- SystemBC (1)
- systemd (1)
- systemd-userdbd (1)
- T1204.004 (1)
- T3 (1)
- TA427 (1)
- TA488 (5)
- TA569 (1)
- Tactical RMM (2)
- tag rewrite (1)
- tag tampering (4)
- TAG-124 (1)
- TAG-179 (1)
- TAG-182 (1)
- TAG-22 (2)
- Taiwan (8)
- Tajikistan (1)
- Take Control (1)
- takedown (3)
- TamperedChef (1)
- Tanzania (1)
- targeted malware (1)
- targeted operations (2)
- TartarusGate (1)
- task queue (1)
- task scheduler abuse (1)
- TaskWeaver (3)
- tax-season phishing (1)
- tc (1)
- TCP traffic diversion (1)
- TDS (2)
- TeamCity (1)
- TeamPCP (10)
- TeamPCP-adjacent (1)
- Teams access (1)
- TeamViewer (1)
- TEASOUP (1)
- Tebi (1)
- technician session (1)
- technology sector (2)
- telecom (2)
- telecom-impersonation (1)
- telecommunications (4)
- Telegra.ph (1)
- Telegram (13)
- telegram (1)
- Telegram bot (2)
- Telegram C2 (5)
- Telegram dead drop (2)
- Telegram exfiltration (1)
- Telegram notification (1)
- telemetry (1)
- TELEPUZ (1)
- TELESHIM (4)
- Teletype (1)
- Telnet (1)
- Telnet brute force (3)
- Telnyx (1)
- Temp Zagros (1)
- template injection (1)
- tenant isolation (1)
- tenant-project (1)
- TencShell (1)
- Tenda (1)
- Tenet Security (1)
- Tetrade (1)
- TetrisPhantom (1)
- TeviRAT (1)
- Thailand (4)
- The Gentlemen (1)
- The Hacker News (12)
- The Quarry (1)
- ThemeREX Addons (1)
- third-party integrations (1)
- third-party JavaScript (1)
- third-party risk (1)
- threat hunting (1)
- threat landscape (1)
- ThrottleBlood (1)
- ThumbcacheService (1)
- thumbnail generation (1)
- TinyGo (1)
- TinyRCT (3)
- tj-actions (1)
- TLS certificates (1)
- TmcLoader (1)
- TmcPayload (1)
- ToddyCat (3)
- token forgery (2)
- token jacking (1)
- token replay (3)
- token theft (8)
- token-theft (1)
- TONESHELL (2)
- TookPS (1)
- tool (4)
- tool execution (1)
- tool output injection (1)
- tool poisoning (1)
- tool use (1)
- tooling (5)
- tools (48)
- Tor (4)
- Total Software Deployment (1)
- TouchSocket (1)
- Toy Ghouls (3)
- TPM (1)
- Trading Technologies (1)
- TradingView (1)
- traffic broker (1)
- traffic control (1)
- traffic hijacking (1)
- traffic manipulation (1)
- traffic-distribution-system (1)
- traffic-fraud (1)
- training data (1)
- transaction authority (1)
- transfer stations (1)
- transitive dependency (1)
- translation software (1)
- transnational repression (1)
- transparent proxy (1)
- Transparent Tribe (2)
- transport (1)
- transportation (2)
- Trend Micro (3)
- TrendAI (1)
- Trezor (1)
- TrickBot (1)
- Trident Ursa (1)
- trojanized installers (3)
- Tron (4)
- trusted extension risk (1)
- trusted publishing (3)
- trusted relationship abuse (2)
- tunnel decapsulation (1)
- tunnel services (1)
- tunneling (4)
- Turla (4)
- Turla collaboration (1)
- TuxBot (1)
- TuxBot v3 Evolution (1)
- Twilio (1)
- Twilio SendGrid (1)
- Twill Typhoon (2)
- two-factor authentication (1)
- Tycoon2FA (1)
- TypeScript (2)
- typosquat (1)
- typosquatting (15)
- UAC (1)
- UAC bypass (1)
- UAC-0002 (2)
- UAC-0010 (3)
- UAC-0098 (1)
- UAC-0145 (2)
- UAC-0194 (3)
- UAC-0226 (1)
- UAT-11795 (3)
- UAT-5918 (1)
- UAT-7237 (3)
- UAT-7810 (1)
- Ubiquiti (1)
- Ubuntu (1)
- Udev persistence (1)
- UDP C2 (1)
- UDP/1900 (1)
- UI redressing (1)
- Ukraine (14)
- Ukraine targeting (3)
- Ulej (3)
- UltraVNC (1)
- Umbrij (3)
- unattributed (1)
- unauthenticated access (3)
- unauthenticated admin access (1)
- unauthenticated HTTP exploitation (1)
- unauthenticated RCE (7)
- UNC1543 (1)
- UNC1549 (5)
- UNC2814 (1)
- UNC3753 (1)
- UNC4221 (1)
- UNC4736 (1)
- UNC5792 (1)
- UNC6240 (2)
- UNC6508 (1)
- UNC6671 (1)
- UNC6692 (2)
- UNC6780 (1)
- Uni-App (1)
- UniFi OS (1)
- Unified CM SME (1)
- uninitialized heap memory (1)
- unintended internet access (1)
- Unit 42 (9)
- United States (3)
- university targeting (1)
- UNK_MassTraction (1)
- UNK_PitStop (1)
- unpatched vulnerability (2)
- unsafe deserialization (1)
- unsigned installer (1)
- UpdateFactory (1)
- UPnP (2)
- UPX (1)
- uranium compression (1)
- URL retrieval (1)
- USB exfiltration (1)
- USB propagation (1)
- USB weaponizer (1)
- USB worm (2)
- use-after-free (2)
- user execution (2)
- user namespaces (2)
- user verification (1)
- UserAssist (1)
- username environmental keying (1)
- USN Journal (1)
- UTA0355 (1)
- UTA0533 (1)
- UTG-Q-1000 (2)
- uTLS (1)
- Uzbekistan (1)
- V2Ray (1)
- V4bel (1)
- V8 (1)
- valid accounts (4)
- ValleyRAT (2)
- Varonis Threat Labs (1)
- VBCloud (1)
- VBE (1)
- VBS (1)
- VBScript (7)
- vCenter (1)
- vector databases (1)
- VEIL#DROP (1)
- Velociraptor (1)
- VeloCloud (1)
- VeloCloud Orchestrator (1)
- Velvet Ant (2)
- VELVETSHELL (1)
- vendor compromise (1)
- vendor credentials (1)
- VENOMOUS BEAR (3)
- Vercel (1)
- Vertex AI (1)
- victim-owned relay infrastructure (1)
- VIDAR (2)
- Vidar Stealer (3)
- Vietnam (2)
- Vietnam-aligned (1)
- Views (1)
- ViewState deserialization (1)
- ViPNet (1)
- virtual machine escape (1)
- virtualization (2)
- virtualization targeting (2)
- VirusTotal sentiment abuse (1)
- vishing (7)
- Visual Studio (1)
- Visual Studio Code Remote SSH (1)
- Vite (1)
- Vitest (1)
- ViteVenom (1)
- VLESS (1)
- vManage (1)
- VMSA-2026-0006 (1)
- VMware (3)
- VMware ESXi (2)
- VMXNET3 (1)
- VNC (2)
- VNT (2)
- Void Blizzard (4)
- Void Manticore (1)
- Volt Typhoon (1)
- volume serial number (1)
- VPN (7)
- VPN credentials (2)
- VPN gateway (1)
- VPN Go (1)
- VPN session hijacking (1)
- VS Code (9)
- VS Code tunnels (1)
- Vshell (1)
- VShell (1)
- VSIX (1)
- vSphere (2)
- vSphere Foundation (1)
- VU#213560 (1)
- VulnCheck (2)
- vulnerability (22)
- vulnerability exploitation (2)
- vulnerability research (4)
- vulnerability-research (1)
- vulnerable appliances (1)
- VXLAN (1)
- w3wp.exe (1)
- wallet address replacement (1)
- wallet drainer (1)
- wallet infrastructure (1)
- wallet replacement (1)
- wallet theft (8)
- wallet-drainer (1)
- wallet-theft (3)
- Wasabi (3)
- wastewater (1)
- watchdog (1)
- watchTowr (3)
- watchTowr Labs (1)
- water sector (1)
- watering hole (2)
- watering-hole (2)
- weak credentials (1)
- weak entropy (2)
- weak passwords (2)
- weak RNG (1)
- weapons shipments (1)
- web application (5)
- web application compromise (1)
- web hosting (2)
- web IDE (1)
- web injection (1)
- web injector (1)
- web management interface (1)
- web proxy (1)
- web RCE (1)
- web server (1)
- web shell (8)
- web shell hunting (1)
- web shells (3)
- web supply chain (2)
- web-shells (1)
- WebAssembly (1)
- WebAuthn (1)
- WebDAV (2)
- WebKit (1)
- WebLogic (1)
- webmail (4)
- WebRTC (1)
- webshell (1)
- webshells (1)
- website-compromise (1)
- WebSocket (6)
- WebSocket C2 (7)
- websocket-sharp (1)
- WebView (1)
- WebView2 C2 (1)
- Webworm (1)
- Werkbit (1)
- WhatsApp (3)
- WhatsApp phishing (1)
- WHM (4)
- Wi-Fi credential theft (1)
- Widget Factory (1)
- Wiflyer (1)
- wiki (1)
- WILDDAY (2)
- Windchill (1)
- Windchill PDMLink (1)
- WinDirStat (1)
- Windmill (1)
- Windows (47)
- Windows Defender (1)
- Windows Defender exclusions (1)
- Windows Defender impairment (1)
- Windows Forms (1)
- Windows malware (12)
- Windows persistence (1)
- Windows Run dialog (1)
- Windows Script Host (2)
- Windows servers (1)
- Windows service persistence (1)
- Windows Terminal (1)
- Winnti Group (2)
- WinOS (1)
- Winos4.0 (1)
- WinPython (1)
- WinRAR (4)
- wiper (3)
- wiper-adjacent (1)
- WireGuard (2)
- Wiz Research (2)
- WLDR agent (2)
- WM_COPYDATA IPC (1)
- WMI (1)
- Woodgnat (1)
- WordPress (8)
- WordPress credential theft (1)
- workflow backdoor (1)
- working-directory hijacking (1)
- workspace trust (2)
- World Cup (1)
- worm (16)
- WP Maps Pro (1)
- WP-SHELLSTORM (1)
- wp2shell (1)
- WScript (1)
- WSS (1)
- X-Grafana-URL (1)
- X-Secret (1)
- X-WEBAUTH-USER (1)
- X25519 (1)
- X3D MINER (1)
- X_TRADER (1)
- XChaCha20 (2)
- XChaCha20-Poly1305 (1)
- Xcode (2)
- XCSSET (2)
- XCSSET v40 (2)
- XenoRAT (2)
- XFRM (1)
- xlabs_v1 (1)
- XMLDecoder (1)
- XMRig (7)
- XOR (3)
- XOR obfuscation (1)
- Xray (1)
- XSLT SSRF (1)
- XSS (2)
- XSS.is (1)
- XWorm (1)
- XXE (1)
- xz (2)
- Yahoo Mail (1)
- Yanbian (1)
- Yasmarang (1)
- YesWeHack (1)
- YouTube abuse (1)
- Yuechi Shared Technology (1)
- yuze (2)
- Yx Technology (1)
- ZAPiXDESK (1)
- Zbtlink (1)
- Zendesk (1)
- Zephyr RTOS (1)
- Zero Trust (1)
- zero-click (1)
- zero-day (6)
- zero-day exploitation (1)
- zero-reputation infrastructure (1)
- ZeroBEC (1)
- Zimbra (3)
- Zimbra Collaboration Suite (1)
- Zimperium (2)
- ZimReaper (1)
- zLabs (2)
- zlib (1)
- Zoho Assist (2)
- Zoho WorkDrive (2)
- ZOHOMURK (2)
- Zoom (1)
.NET
- Braintree.Net NuGet payment skimmer
- FDMTP
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Sicoob.Sdk NuGet banking certificate stealer
- STOCKSTAY
- TinyRCT
- Umbrij
.NET malware
- Avalon / CrownX malware framework
- Cavern
- Cavern Manticore
- HOLLOWGRAPH
- Silent Swap Google Notes crypto clipper
- ToddyCat Umbrij Gmail OAuth operation
- Turla STOCKSTAY backdoor operations
.NET reflection
.pth
/accessv2
/api/session/reset_password
/dev/kvm
146.70.139.154
192.42.116.105
192.42.116.58
2FA recovery codes
3CX
404 TDS
43.228.157.68
4sync
@marketfront
@tqm-mfe
.bin
<all_urls>
Ababil of Minab
abuse response
academic research
academic sector
- Brazilian education LockBit, DragonForce, and insider incidents
- UNK_MassTraction Roundcube university mailserver campaign
Accellion
access broker
access brokers
access keys
access optionality
access token abuse
access token theft
Accessibility Service
account lockout
account takeover
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- O-UNC-066 Entra passkey vishing
- Russian intelligence commercial-messaging backup-key phishing
- Synced passkey theft after endpoint compromise
account-takeover
ACR Stealer
act_pedit
ACTINIUM
Active Directory
active exploitation
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- C0XMO Gafgyt DD-WRT botnet
- Check Point VPN CVE-2026-50751 exploitation
- Chrome V8 CVE-2026-11645 exploitation
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- CL-STA-1114 Zimbra webmail espionage
- COLDCARD predictable-RNG Bitcoin theft risk
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Gitea Docker CVE-2026-20896 probing
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Gravity SMTP CVE-2026-4020 exploitation
- Ill Bloom CryptoJS wallet-drain campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Metabase unauthenticated SQL-injection zero-day
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
- Windmill CVE-2026-29059 active exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
active probing
active threat
- OkoBot cryptocurrency-wallet malware framework
- Progress ShareFile Storage Zone Controller security threat
- Water-sector PLC configuration-tampering campaign
active-exploitation
ActiveX
actor
actors
- Armored Likho
- Cavern Manticore
- Fox Tempest
- JINX-0163 / FulcrumSec
- JINX-0164
- Mustang Panda
- OP-512
- TA4922
- ToddyCat
- UAT-11795
- Webworm
ad blocker
ad fraud
Adaptix C2
ADB TCP/5555
Adblock for YouTube
Adform
ADFS
Admin API key theft
administrator account creation
Adobe ColdFusion
Adobe Commerce
Adspect
Advanced IP Scanner
Adversa AI
adversary-in-the-middle
- AI-brand impersonation phishing and malvertising
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
advertising technology
adware
- Chrome live-wallpaper extension ad-fraud network
- Fake Corepack site infostealer and proxyware campaign
- ModHeader browser-extension surveillance capability
- Operation FlutterBridge FlutterShell macOS malvertising
- TamperedChef-style productivity malware clusters
adware history
aerospace
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- TA488 OWAReaper and CVE-2026-42897 exploitation
AES-128-CBC
AES-256-CTR
AES-256-GCM
AES-CTR
AES-GCM
- CrashStealer macOS notarized-dropper campaign
- macOS.Gaslight Rust backdoor
- ModHeader browser-extension surveillance capability
AES-GCM C2
Aeternum
affiliate hijacking
Afghanistan
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Africa
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
agent frameworks
- Agent localhost control-plane RCE
- MCP stdio command-execution boundary
- PraisonAI CVE-2026-44338 rapid exploitation
agent memory
agent monitoring
agent polling protocol
agent skills
agent state
AgentBaiting
agentic AI
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Patriot Bait AI-assisted C2 botnet
- SHADOW-AETHER AI-augmented Latin America intrusions
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
agentic botnets
agentic browser
agentic browsers
agentic malware
agentic ransomware
agentic threat actor
Agentjacking
AGENTPSD
AI
- AI token-jacking transfer-station abuse
- AI-augmented adversary operations
- GREYVIBE
- Patriot Bait AI-assisted C2 botnet
- Vertex AI staging-bucket squatting
- Xinference PyPI compromise
AI agent
AI agents
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI browser-extension confused deputy
- AI-agent memory poisoning
- Amazon Q CVE-2026-12957 MCP auto-execution
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- GuardFall AI-agent shell-guard bypass
- Internet-exposed unauthenticated MCP servers
- Langflow CVE-2025-34291 exploitation
- LangGraph checkpointer and namespace trust boundaries
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NATS-as-C2 KeyHunter credential-harvesting operation
- Phantom squatting: AI-hallucinated domains
- PraisonAI CVE-2026-44338 rapid exploitation
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Sentry MCP Agentjacking
AI anti-analysis
AI application infrastructure
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- Hugging Face autonomous-agent production intrusion
- Internet-exposed unauthenticated MCP servers
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- ServiceNow AI Platform CVE-2026-6875 exploitation
AI assistant credentials
AI assistants
- binding.gyp npm CI/CD worm
- Claude Code GitHub Action prompt-injection boundary
- Developer-tool config auto-execution
- Immobiliare Labs Backstage plugins npm compromise
AI brand impersonation
- AI-brand impersonation phishing and malvertising
- Perplexity AI-spoofing Chromium extension search hijacker
AI browsers
AI chatbot abuse
AI coding agents
AI credential theft
AI data exfiltration
AI developer tooling
AI framework
AI gateway
AI infrastructure
AI memory poisoning
AI model encryption
AI model evaluation
AI Now Institute
AI search poisoning
AI security
AI services
AI tooling
- @withgoogle/stitch-sdk scope squat
- Amazon Q CVE-2026-12957 MCP auto-execution
- AsyncAPI generator / specs Miasma compromise
- codexui-android OpenAI token stealer
- JetBrains AI plugin API-key theft
- LangGraph checkpointer and namespace trust boundaries
- Malware-Slop Claude user-data npm infostealer
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- Ollama P2P cryptominer RAT campaign
- Phantom squatting: AI-hallucinated domains
- Polymarket npm wallet-drainer packages
- PraisonAI CVE-2026-44338 rapid exploitation
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- TrapDoor crypto-stealer cross-ecosystem campaign
AI tools
AI vulnerability discovery
AI workflow
ai-abuse
ai-agent
AI-assisted development
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
AI-assisted intrusion
AI-assisted malware
- Avalon / CrownX malware framework
- Evilginx and device-code phishing open-directory cluster
- Patriot Bait AI-assisted C2 botnet
AI-assisted malware development
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- TuxBot v3 Evolution IoT botnet framework
- Ulej / Flowerbed
AI-assisted phishing
AI-assisted vulnerability discovery
AI-augmented operations
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Hugging Face autonomous-agent production intrusion
- SHADOW-AETHER AI-augmented Latin America intrusions
AI-generated malware
AI-generated narrator
Aider
AISURU
AiTM
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- UNC6671 / BlackFile multi-brand vishing extortion operation
Albania
Alibaba
Allen-Bradley
Amadey
Amatera Stealer
Amazon Q Developer
Amazon SES
Amcache
AMOS
AMSI bypass
- ClickFix CPaaS API-driven payload delivery
- Flooding Dropper npm campaign
- Operation DragonReturn India tax-season DcRAT campaign
- TELEPUZ
- Vidar / XMRig Factory-v3 malvertising campaign
AmsiScanBuffer
Android
- Android Framework CVE-2025-48595 exploitation
- codexui-android OpenAI token stealer
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Kimwolf v7
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- NetNut / Popa residential proxy network disruption
- ScarCruft Yanbian game-platform supply-chain attack
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Android Accessibility Service
Android ADB
Android Debug Bridge
Android malware
- Flying Eagle and Night Dragon Android RAT ecosystem
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
Android RAT
Android spyware
Android TV
Anthropic
anthropickit
anti-analysis
- AI scanner anti-analysis
- CrashStealer macOS notarized-dropper campaign
- Flooding Dropper npm campaign
- jscrambler npm preinstall stealer
- macOS ClickFix fingerprinting-gate campaign
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- TELESHIM
- TELESHIM Middle East government espionage campaign
anti-bot
anti-forensics
Anubis ransomware
ANY.RUN
AnyDesk
- Brazilian education LockBit, DragonForce, and insider incidents
- GodDamn ransomware PoisonX BYOVD activity
AOL Mail
Aone
Apache Tomcat
Apex One
API abuse
API enumeration
API exposure
API key exposure
API key theft
API keys
API-driven payloads
apintergrationpost
App-Bound Encryption bypass
AppDomainManager
AppDomainManager injection
AppleJeus
AppleScript
AppleSeed
appliance
application database
application delivery controller
application token
APSB26-68
APT
- Armored Likho
- Armored Likho BusySnake campaign
- Cloud Atlas
- Gamaredon
- Ghostwriter
- HelloNet ViPNet update-system campaign
- Screening Serpens
- ToddyCat
APT-C-08
APT27
APT28
APT29
APT32
APT36
APT37
APT42
APT43
APT44
APT45
Aptos
Aquatic Panda
AquilaRAT
arbitrary code execution
arbitrary file disclosure
arbitrary file read
arbitrary file upload
arbitrary file write
- Adobe ColdFusion APSB26-68 CVE bonanza
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
arbitrary JavaScript
ArcBridge
Arch Linux
Arctic Wolf
ArduPilot
Argo CD
ArgoCD
Arista
Arista EOS
ARL
Armageddon
ArmCorp
Armored Likho
Artifact Signing
AryStinger
AS32167
Asia targeting
ASLR bypass
ASNs
ASP.NET
ASP.NET machineKey
ASPX web shells
Astro
ASUS AiCloud routers
ASUS router
AsyncAPI
AsyncRAT
- Operation Muck and Load GitHub lure network
- Pakistani law enforcement espionage convergence
- ScreenConnect freeware / AsyncRAT SEO campaign
Atlas RAT
Atlassian
Atomic Stealer
AUDIOFIX
audit logging
AUR
authenticated RCE
authenticated remote code execution
authentication bypass
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Gitea Docker CVE-2026-20896 probing
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- Metabase unauthenticated SQL-injection zero-day
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Progress ShareFile Storage Zone Controller security threat
- ServiceNow AI Platform CVE-2026-6875 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
authentication laundering
authentication stack
authentication-coercion
Authenticode impersonation
authorization bypass
auto-execution
AUTODYN
AutoGen Studio
AutoHotKey
AutoJack
autonomous agents
- Anthropic cyber-evaluation real-world intrusions
- Hugging Face autonomous-agent production intrusion
- Phantom squatting: AI-hallucinated domains
autonomous attacks
autonomous exploitation
autonomous scanning
AV killer
Avalon
aviation
AWS
- @copilot-mcp/apex macOS infostealer campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- CircleCI 2023 customer secret exposure incident
- JINX-0163 / FulcrumSec
- MrMustard PyPI credential-stealer compromise
- NATS-as-C2 KeyHunter credential-harvesting operation
- vpmdhaj OpenSearch npm cloud-secret stealer
AWS CloudTrail
AWS S3
AWS Secrets Manager
axios
Azure
Azure CLI
Azure Cosmos DB
Azure DevOps
Azure Storage
Babuk
Backblaze
backdoor
- BINDCLOAK
- DAEMON Tools Lite supply-chain compromise
- FDMTP
- GigaWiper
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- macOS.Gaslight Rust backdoor
- MODBEACON
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- NightLedger
- OctLurk
- Ollama P2P cryptominer RAT campaign
- Operation FlutterBridge FlutterShell macOS malvertising
- QuickFox FDMTP software supply-chain compromise
- shopsprint/decimal Go typosquat DNS backdoor
- Showboat
- SilkLurk
- SprySOCKS
- STOCKSTAY
- TELESHIM
- Telnyx PyPI TeamPCP compromise
- TinyRCT
Backdoor.Mistic
Backstage
backup disruption
backup recovery keys
backup targeting
backups
Bad Epoll
BadBlocker
Badbox 2.0
BadPotato
Balbooa Forms
Balochistan Police
Banana RAT
bandcampro
banking
banking malware
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
banking trojan
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
Barracuda
Base64
BaseZipInstaller
Bash Uploader
batch loader
BCU key
Bearlyfy
Beast ransomware
BeaverTail
Bedrock
behavioral integrity verification
Behinder
Belarus
BELQI
Bexo Wallet
BeyondTrust
Binance Smart Chain
binary execution
BinaryFormatter
BINDCLOAK
binding.gyp
biometric records
BIOPASS RAT
BioShocking
BIP-39
BirdCall
Bitbucket
Bitcoin
- Adform Trackpoint JavaScript supply-chain crypto clipper
- COLDCARD predictable-RNG Bitcoin theft risk
- Ill Bloom CryptoJS wallet-drain campaign
- Kairos data-extortion government payment
Bitcoin Libre
BitMiner
bitsadmin
Bitter
Bitwarden
BKA
BlackFile
Blackpoint Cyber
- Avalon / CrownX malware framework
- CrownX
- Djinn Stealer
- LabubaRAT
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- TaskWeaver
Bleacher Report
blockchain C2
- Aeternum
- Astro config blockchain C2 PR injection
- DeadLock ransomware
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Joyfill npm blockchain-RAT compromise
- Kimwolf v7
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
- ViteVenom / ChainVeil npm campaign
blockchain dead drop
- ACR Stealer
- Dysphoria IoT botnet
- FakeGit AgentBaiting and SmartLoader campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
- Silent Swap Google Notes crypto clipper
blockchain RPC
blockchain-dead-drop
Blogger abuse
blogspot staging
BLUEBEAM
Boatnet
body hash
botnet
- Aeternum
- C0XMO Gafgyt DD-WRT botnet
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- Glassworm developer supply-chain botnet
- JDY SOHO / IoT reconnaissance botnet
- Kimwolf v7
- Lucide Proxy npm browser DDoS botnet
- NadMesh AI-service and cloud-credential botnet
- NetNut / Popa residential proxy network disruption
- Patriot Bait AI-assisted C2 botnet
- RustDuck
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
botnet framework
Braintree
branch-compromise
branch-name-injection
brand impersonation
- DCloud Uni-App scam infrastructure ecosystem
- Fake Corepack site infostealer and proxyware campaign
- GHOST STADIUM FIFA World Cup ticket phishing
brand-impersonation
Brazil
- Armored Likho
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Brazilian education LockBit, DragonForce, and insider incidents
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- SHADOW-AETHER AI-augmented Latin America intrusions
Brazilian banking malware
BreachForums
Breeze Cache Cleaner
BRICKSTORM
BridgeHead
Broadcom
- Backdoor.Mistic / KongTuke ModeloRAT activity
- GodDamn ransomware PoisonX BYOVD activity
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
browser assembly
browser automation
browser cookie theft
browser credential theft
- @copilot-mcp/apex macOS infostealer campaign
- ACR Stealer
- Armored Likho BusySnake campaign
- Avalon / CrownX malware framework
- BusySnake Stealer
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- GREYVIBE
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- macOS.Gaslight Rust backdoor
- PamStealer
- Seedworm / MuddyWater
- Silent Swap Google Notes crypto clipper
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0226 / SHADOW-EARTH-066
- Vidar / XMRig Factory-v3 malvertising campaign
- Void Dokkaebi
- VPN Go browser-extension clipboard stealer
browser data theft
browser extension
- Adblock for YouTube BadBlocker remote-script injection risk
- AI browser-extension confused deputy
- Forg365 Microsoft 365 PhaaS
- ModHeader browser-extension surveillance capability
- Perplexity AI-spoofing Chromium extension search hijacker
- Silent Swap Google Notes crypto clipper
- StegoAd Edge extension steganography campaign
- UNC6692 SNOW malware social-engineering campaign
- VPN Go browser-extension clipboard stealer
browser extension loader
browser fingerprint spoofing
browser fingerprinting
browser hijacking
- Operation FlutterBridge FlutterShell macOS malvertising
- Perplexity AI-spoofing Chromium extension search hijacker
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
browser malware
browser memory
browser security
- Adform Trackpoint JavaScript supply-chain crypto clipper
- AI browser-extension confused deputy
- ModHeader browser-extension surveillance capability
browser session abuse
browser session risk
- Adblock for YouTube BadBlocker remote-script injection risk
- Perplexity AI-spoofing Chromium extension search hijacker
- VPN Go browser-extension clipboard stealer
browser zero-day
browser-credential-theft
browser-extensions
browser-resident malware
browser-security
browser-session risk
browsing history
brute-force credentials
BSC
BTMOB
bucket hijacking
bucket squatting
Bugcrowd
build server
build-time compromise
building automation
bulletproof hosting
Bun
- actions-cool GitHub Actions tag compromise
- ChainDrop keyv / cacheable npm worm
- codfish semantic-release-action tag compromise
- SourTrade browser-assembled malware malvertising
Bun runtime abuse
Burkina Faso
business email compromise
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Microsoft Q2 2026 email and Teams phishing landscape
business intelligence
BusySnake Stealer
Bybit
BYOVD
- GodDamn ransomware PoisonX BYOVD activity
- Storm-2603 parallel SharePoint ransomware intrusion
- The Gentlemen ransomware
bypass2fa
C
C++
C++/CLI
C0XMO
C2
- BINDCLOAK
- DAEMON Tools Lite supply-chain compromise
- Glassworm developer supply-chain botnet
- Malicious infrastructure provider concentration
- NATS-as-C2 KeyHunter credential-harvesting operation
- Oman government Iranian-nexus webshell C2
- Patriot Bait AI-assisted C2 botnet
- Quest KACE SMA CVE-2025-32975 exploitation
- QuimaRAT
- RemotePE
- Showboat
- WLDR agent
C2 framework
C2 panel
C2 tasking
CageFS
calendar dead drop
calendar invitation
Calendly abuse
call forwarding
callback URL
Cambodia
campaign
- CL-STA-1114 Zimbra webmail espionage
- Gunra ransomware-as-a-service activity
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Toy Ghouls GenieLocker ransomware activity
- UNK_MassTraction Roundcube university mailserver campaign
Canada
CANFAIL
CAP_NET_ADMIN
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
captive portal
capture the flag
Casbaneiro
CastleStealer
Catalyst SD-WAN Manager
Catcher
Cav3rn
Cavern
Cavern Manticore
CCleaner
CDN
cellular modem
Censys ARC
Central Asia
CERT-In
CERT/CC
Certbot
certificate pinning
certificate theft
certutil
CFIDE
ChaCha20
ChainDrop
ChainVeil
ChatGPT
chattr
Chatty Spider
CHAVECLOAK
Check Point
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
Check Point Research
Checkmarx
checkpointers
China
China-linked
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- FishMonger
- GHOST STADIUM FIFA World Cup ticket phishing
- OP-512
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- SprySOCKS
China-nexus
- FDMTP
- JDY SOHO / IoT reconnaissance botnet
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Pakistani law enforcement espionage convergence
- QuickFox FDMTP software supply-chain compromise
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UAT-7810 LONGLEASH ORB network expansion
- UNC6508
- UNK_MassTraction Roundcube university mailserver campaign
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
China-speaking ecosystem
Chinese-language cybercrime
- Chinese-language PhaaS wallet-tokenization ecosystem
- Flying Eagle and Night Dragon Android RAT ecosystem
Chinese-language fraud ecosystem
Chinese-speaking
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GHOST STADIUM FIFA World Cup ticket phishing
- HelloNet ViPNet update-system campaign
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- OctLurk and SilkLurk Central Asia espionage campaign
Chinese-speaking cybercrime
Chinese-speaking operator
Chisel
- Oman government Iranian-nexus webshell C2
- PCPJack cloud SMTP relay network
- SHADOW-AETHER AI-augmented Latin America intrusions
ChocoPoC
ChocoShell
Chrome
Chrome App-Bound Encryption
Chrome DevTools Protocol
Chrome extension
- ModHeader browser-extension surveillance capability
- PolinRider cross-ecosystem supply-chain campaign
Chrome renderer sandbox
Chrome Web Store
- Adblock for YouTube BadBlocker remote-script injection risk
- Chrome live-wallpaper extension ad-fraud network
- ModHeader browser-extension surveillance capability
- Perplexity AI-spoofing Chromium extension search hijacker
- VPN Go browser-extension clipboard stealer
chrome_settings_overrides
ChromElevator
Chromium
- Chrome V8 CVE-2026-11645 exploitation
- Perplexity AI-spoofing Chromium extension search hijacker
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
Chromium extension
CI secrets
CI-CD
- Atomic Arch AUR package hijack
- Dependabot cross-ecosystem malware advisory alerts
- npm install explicit-trust controls
CI/CD
- @marketfront / @tqm-mfe dependency-confusion stealer
- actions-cool GitHub Actions tag compromise
- Argo CD repo-server unauthenticated RCE
- Astro config blockchain C2 PR injection
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChainDrop keyv / cacheable npm worm
- CircleCI 2023 customer secret exposure incident
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- codfish semantic-release-action tag compromise
- Crypto supply-chain path to transaction authority
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- GuardFall AI-agent shell-guard bypass
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Immobiliare Labs Backstage plugins npm compromise
- JetBrains TeamCity CVE-2026-63077 active exploitation
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Laravel-Lang Composer tag-rewrite compromise
- Leo Platform npm Miasma-style compromise
- LiteLLM compromise
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- npm publish-time malware scanning and dual-use declarations
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation DangerousPassword axios npm compromise
- SANDWORM_MODE AI-toolchain npm worm
- simonecorsi/mawesome GitHub Action compromise
- TeamPCP
- Telnyx PyPI TeamPCP compromise
- tj-actions and reviewdog compromise
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- vpmdhaj OpenSearch npm cloud-secret stealer
CI/CD abuse
CircleCI
CIS
CISA
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- FortiBleed Fortinet credential exposure
- Gunra ransomware-as-a-service activity
- JetBrains TeamCity CVE-2026-63077 active exploitation
CISA KEV
- Android Framework CVE-2025-48595 exploitation
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- C0XMO Gafgyt DD-WRT botnet
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ivanti Sentry CVE-2026-10520 exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Trend Micro Apex One CVE-2026-34926 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Cisco
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
Cisco IOS
Cisco IOS 12.4
Cisco Nexus
Cisco Talos
Cisco Unified CM
Cisco Unified Communications Manager
citizen portal compromise
Citrine Sleet
Citrix
Citrix NetScaler
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- knaithe Hermes/DeepSeek autonomous exploitation campaign
CitrixBleed
CitrixBleed 2
CKEditor file manager
CL-CRI-1089
CL-CRI-1147
CL-STA-1062
CL-STA-1114
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
Claude
- AI-brand impersonation phishing and malvertising
- Anthropic cyber-evaluation real-world intrusions
- Malware-Slop Claude user-data npm infostealer
Claude Code
- @withgoogle/stitch-sdk scope squat
- Azure DevOps MCP pull-request prompt injection
- Claude Code GitHub Action prompt-injection boundary
- Coding-agent-parented tunnels and persistence
- GuardFall AI-agent shell-guard bypass
- Sentry MCP Agentjacking
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Claude for Chrome
Claude Mythos 5
Claude Opus 4.7
Clever Cloud
click interception
ClickFix
- ACR Stealer
- Backdoor.Mistic / KongTuke ModeloRAT activity
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- ClickFix CPaaS API-driven payload delivery
- Exposed WebDAV malware delivery lab and CURP campaign
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GREYVIBE
- JINX-0164 crypto developer infrastructure campaign
- macOS ClickFix fingerprinting-gate campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- Starland RAT
- StealC / Amadey infrastructure disruption
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795
- UAT-11795 Starland / WLDR campaign
ClickOnce
ClickUp
client-side exploitation
Cline
clipboard hijacker
clipboard hijacking
clipboard injection
clipboard manipulation
clipboard stealer
clipboard theft
- BusySnake Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto Clipper Tor / USB worm
- PamStealer
- Silent Swap Google Notes crypto clipper
- VPN Go browser-extension clipboard stealer
clipper
Cloaked Ursa
cloaking
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- macOS ClickFix fingerprinting-gate campaign
- SourTrade browser-assembled malware malvertising
cloud
- APT29
- JINX-0163 / FulcrumSec
- PCPJack cloud SMTP relay network
- ROADtools
- Vertex AI staging-bucket squatting
- Webworm
- Xinference PyPI compromise
cloud C2
cloud compromise
cloud credential hunting
cloud credential risk
cloud credential theft
- AI-augmented adversary operations
- Djinn Stealer
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Hugging Face autonomous-agent production intrusion
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
cloud credentials
- Amazon Q CVE-2026-12957 MCP auto-execution
- Internet-exposed unauthenticated MCP servers
- jscrambler npm preinstall stealer
- wshu.net npm credential-stealer campaign
cloud exploitation
Cloud Files Mini Filter Driver
Cloud Filter driver
Cloud Foundation
cloud IAM
cloud identity
cloud identity abuse
cloud infrastructure
cloud logging
cloud metadata service
cloud secrets
- @marketfront / @tqm-mfe dependency-confusion stealer
- JINX-0164 crypto developer infrastructure campaign
- oob.moika.tech dependency-confusion environment stealer
- vpmdhaj OpenSearch npm cloud-secret stealer
cloud security
- Cloud bucket namespace hijacking
- Cloud logging control-plane tampering
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- PraisonAI CVE-2026-44338 rapid exploitation
cloud service abuse
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Stock exchange executive mailbox espionage
cloud storage
cloud storage exfiltration
cloud transcoding
Cloudflare
- Forg365 Microsoft 365 PhaaS
- GHOST STADIUM FIFA World Cup ticket phishing
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Okta support-system compromise
Cloudflare Tunnel
- Coding-agent-parented tunnels and persistence
- Evilginx and device-code phishing open-directory cluster
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Storm-2603 parallel SharePoint ransomware intrusion
Cloudflare tunnels
Cloudflare Turnstile
Cloudflare Workers
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Polymarket npm wallet-drainer packages
- StegoAd Edge extension steganography campaign
cloudflared
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
CloudLinux
cluster compromise
CMS
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Gravity SMTP CVE-2026-4020 exploitation
- Joomla JCE CVE-2026-48907 exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
CMS exploitation
CNCERT
Cobalt Strike
- FishMonger
- Ghostwriter
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Malicious infrastructure provider concentration
- Pakistani law enforcement espionage convergence
- StrikeShark SharkLoader / Cobalt Strike campaign
code execution
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- JetBrains TeamCity CVE-2026-63077 active exploitation
code injection
code sandbox scraping
code signing
- AI-brand impersonation phishing and malvertising
- Fox Tempest
- TamperedChef-style productivity malware clusters
Codecov
codemado
CodeQL
Codex
Codex CLI
coding agents
coding challenge
Coinbase
Coinkite
COLDCARD
ColdFusion
collaboration platforms
collaboration-tool phishing
COM-hijacking
ComfyUI
command and control
- Direct-to-IP malware communications
- ENDLESSDOORS implant in Zbtlink router firmware
- Malicious infrastructure provider concentration
- Patriot Bait AI-assisted C2 botnet
command execution
- Agent localhost control-plane RCE
- Alibaba developer-targeted distributed npm RAT campaign
- Argo CD repo-server unauthenticated RCE
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Fake Corepack site infostealer and proxyware campaign
- GuardFall AI-agent shell-guard bypass
- Internet-exposed unauthenticated MCP servers
- MCP stdio command-execution boundary
- Ollama P2P cryptominer RAT campaign
command injection
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Ivanti Sentry CVE-2026-10520 exploitation
- Lantronix EDS5000 CVE-2025-67038 exploitation
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Siemens ROX II zero-day exploit chain
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
command-execution
command-injection
commercial messaging applications
commit farming
communications infrastructure
Composer
- Famous Chollima Packagist dev-branch loader
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Laravel-Lang Composer tag-rewrite compromise
- PolinRider cross-ecosystem supply-chain campaign
compromised accounts
compromised credentials
compromised infrastructure
compromised websites
compromised WordPress
computer name
computer vision
Conditional Access
configuration exposure
configuration tampering
configuration theft
Confluence
confused deputy
- Agent localhost control-plane RCE
- AI browser-extension confused deputy
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
ConfuserEx
conhost
connected apps
ConnectWise
ConnectWise ScreenConnect
construction
consumer devices
consumer IoT
Contagious Interview
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
- StegaBin Pastebin-steganography npm campaign
container
container escape
- ENCFORGE
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
container escape pre-check
content compliance rules
contentPolicy
context flooding
Continue
continuous visibility
control flow flattening
control panel compromise
control plane
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- ServiceNow instance unauthenticated table-query exploitation
conversation theft
cookie theft
- Armored Likho BusySnake campaign
- BusySnake Stealer
- StegoAd Edge extension steganography campaign
- Vidar / XMRig Factory-v3 malvertising campaign
Copilot
Copilot CLI
Copy-on-Write
Corepack
CornFlake
Coruna
- art-template Coruna-style iOS watering-hole compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
CosmosEscape
counterfeit software
COW
COWARDDUCK
CPaaS
cPanel
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
CPUID
cracked software
CrackMapExec
CrashStealer
Crates.io
credential attacks
- Kairos data-extortion government payment
- NetNut / Popa residential proxy network disruption
- Patriot Bait AI-assisted C2 botnet
credential dumping
credential exposure
- Coding-agent-parented tunnels and persistence
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- FortiBleed Fortinet credential exposure
- Progress ShareFile Storage Zone Controller security threat
- Sentry MCP Agentjacking
credential harvesting
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GodDamn ransomware PoisonX BYOVD activity
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC6508
credential rotation
credential spraying
credential stuffing
credential theft
- @copilot-mcp/apex macOS infostealer campaign
- @withgoogle/stitch-sdk scope squat
- Aeternum
- Agent skill marketplace poisoning
- AI token-jacking transfer-station abuse
- AI-brand impersonation phishing and malvertising
- Alibaba developer-targeted distributed npm RAT campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Anthropic cyber-evaluation real-world intrusions
- AsyncAPI generator / specs Miasma compromise
- Avalon / CrownX malware framework
- Braintree.Net NuGet payment skimmer
- Browser-based developer IDE OAuth token theft
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- Cursor Windows workspace-path binary hijack
- Exposed WebDAV malware delivery lab and CURP campaign
- FakeGit AgentBaiting and SmartLoader campaign
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- GHOST STADIUM FIFA World Cup ticket phishing
- Injective SDK npm wallet stealer
- JINX-0163 / FulcrumSec
- Joyfill npm blockchain-RAT compromise
- jscrambler npm preinstall stealer
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Lazarus-linked Rollup polyfill npm malware
- LiteLLM compromise
- macOS ClickFix fingerprinting-gate campaign
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Q2 2026 email and Teams phishing landscape
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- NadMesh AI-service and cloud-credential botnet
- nodemon-sudo / tslint-conf runtime npm backdoor
- NullReceiver DPRK-linked npm blockchain-loader wave
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation Highland Velvet Ant authentication-stack backdoors
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- PCPJack cloud SMTP relay network
- PolinRider cross-ecosystem supply-chain campaign
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- ScreenConnect freeware / AsyncRAT SEO campaign
- Seedworm / MuddyWater
- Solana FakeFix npm / PyPI developer stealer
- Starland RAT
- StealC / Amadey infrastructure disruption
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Synced passkey theft after endpoint compromise
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
- UAT-11795
- UAT-11795 Starland / WLDR campaign
- Umbrij
- UNC6692 SNOW malware social-engineering campaign
- UNK_MassTraction Roundcube university mailserver campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- ViteVenom / ChainVeil npm campaign
- Webmail CSS trust-boundary attacks
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
credential-theft
- @marketfront / @tqm-mfe dependency-confusion stealer
- actions-cool GitHub Actions tag compromise
- APT29
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChainDrop keyv / cacheable npm worm
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- DAEMON Tools Lite supply-chain compromise
- Developer-tool config auto-execution
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- forge-jsxy
- GitHub / Packagist postinstall hook campaign
- Glassworm developer supply-chain botnet
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hunt.io global smishing infrastructure campaign
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- JetBrains AI plugin API-key theft
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- Kali365 device-code phishing expansion
- Laravel-Lang Composer tag-rewrite compromise
- Leo Platform npm Miasma-style compromise
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- node-ipc 2026 npm maintainer-account compromise
- Nx Console VS Code extension compromise
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Operation GriefLure Southeast Asia LNK dropper
- Outsider Enterprise smishing PhaaS
- postcss-minify-selector-parser npm RAT
- SANDWORM_MODE AI-toolchain npm worm
- Sicoob.Sdk NuGet banking certificate stealer
- simonecorsi/mawesome GitHub Action compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- Storm-2603 parallel SharePoint ransomware intrusion
- TA4922
- TrapDoor crypto-stealer cross-ecosystem campaign
- UNK_DeadDrop developer repository phishing
- vpmdhaj OpenSearch npm cloud-secret stealer
- wshu.net npm credential-stealer campaign
- Xinference PyPI compromise
credit card theft
criminal infrastructure
critical infrastructure
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Operation Highland Velvet Ant authentication-stack backdoors
- Siemens ROX II zero-day exploit chain
- Velvet Ant
- Water-sector PLC configuration-tampering campaign
critical-infrastructure
CRM data theft
cron
cron persistence
- C0XMO Gafgyt DD-WRT botnet
- Langflow CVE-2026-33017 cryptominer SSH worm
- NadMesh AI-service and cloud-credential botnet
cross-platform
cross-platform malware
cross-project access
cross-site request forgery
cross-tenant access
cross-tenant isolation
CrownX
Crucio
crypto
crypto clipper
crypto wallets
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- wshu.net npm credential-stealer campaign
crypto-js
crypto-wallets
cryptocurrency
- Crypto Clipper Tor / USB worm
- Crypto supply-chain path to transaction authority
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Mastra
easy-day-jsnpm scope compromise - Polymarket npm wallet-drainer packages
- QuickFox FDMTP software supply-chain compromise
- RemotePE
- SANDWORM_MODE AI-toolchain npm worm
- Solana FakeFix npm / PyPI developer stealer
- SourTrade browser-assembled malware malvertising
- UNK_DeadDrop developer repository phishing
cryptocurrency mining
cryptocurrency scam
cryptocurrency theft
- @copilot-mcp/apex macOS infostealer campaign
- Adform Trackpoint JavaScript supply-chain crypto clipper
- COLDCARD predictable-RNG Bitcoin theft risk
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake-reputation crypto clipboard hijacker
- Funnull RingH23 and MacCMS supply-chain attacks
- Ill Bloom CryptoJS wallet-drain campaign
- OkoBot cryptocurrency-wallet malware framework
- Silent Swap Google Notes crypto clipper
- Starland RAT
- UAT-11795
- UAT-11795 Starland / WLDR campaign
- Void Dokkaebi
cryptocurrency wallet theft
- Aeternum
- Avalon / CrownX malware framework
- Contagious Interview SVG-steganography OtterCookie campaign
- CrashStealer macOS notarized-dropper campaign
- jscrambler npm preinstall stealer
- macOS ClickFix fingerprinting-gate campaign
- Vidar / XMRig Factory-v3 malvertising campaign
cryptocurrency wallets
- Djinn Stealer
- Lazarus-linked Rollup polyfill npm malware
- OkoBot cryptocurrency-wallet malware framework
- PamStealer
cryptojacking
CryptoJS
cryptominer
cryptomining
CSCwt95997
CSI token theft
CSRF
CSRF token theft
CSS
CSS sanitization
CSSOM
Curious Serpens
CURP
Cursor
- Coding-agent-parented tunnels and persistence
- Cursor Windows workspace-path binary hijack
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Sentry MCP Agentjacking
- UNK_DeadDrop developer repository phishing
Curve25519
Curve25519-XSalsa20-Poly1305
custody APIs
CVE-2008-4128
CVE-2013-3307
CVE-2016-5681
CVE-2020-17103
CVE-2020-22653
CVE-2020-22658
CVE-2021-27137
CVE-2021-29441
CVE-2022-0492
CVE-2023-24932
CVE-2023-25717
CVE-2023-2868
CVE-2023-4346
CVE-2023-4966
CVE-2024-1708
CVE-2024-1709
CVE-2024-20399
CVE-2024-21182
CVE-2024-3094
CVE-2024-42009
CVE-2025-11371
CVE-2025-11837
CVE-2025-24054
CVE-2025-2492
CVE-2025-3248
CVE-2025-32975
CVE-2025-33053
CVE-2025-34291
CVE-2025-40947
CVE-2025-40948
CVE-2025-40949
CVE-2025-48595
CVE-2025-49113
CVE-2025-49704
CVE-2025-49706
CVE-2025-5777
CVE-2025-66376
CVE-2025-67038
CVE-2025-68613
CVE-2025-68686
CVE-2025-8088
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
CVE-2026-0257
CVE-2026-0300
CVE-2026-0770
CVE-2026-10520
CVE-2026-10523
CVE-2026-11405
CVE-2026-11645
CVE-2026-12569
CVE-2026-12957
CVE-2026-12958
CVE-2026-15409
CVE-2026-15410
CVE-2026-15583
CVE-2026-16232
CVE-2026-16723
CVE-2026-16812
CVE-2026-18556
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
CVE-2026-18577
CVE-2026-19516
CVE-2026-20127
CVE-2026-20182
CVE-2026-20230
CVE-2026-20245
CVE-2026-20253
CVE-2026-20262
CVE-2026-20316
CVE-2026-20896
CVE-2026-21513
CVE-2026-21858
CVE-2026-23111
CVE-2026-26980
CVE-2026-2699
CVE-2026-2701
CVE-2026-28318
CVE-2026-29059
CVE-2026-3055
CVE-2026-3300
CVE-2026-33017
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Langflow CVE-2026-33017 cryptominer SSH worm
- NATS-as-C2 KeyHunter credential-harvesting operation
CVE-2026-33691
CVE-2026-33824
CVE-2026-34486
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- knaithe Hermes/DeepSeek autonomous exploitation campaign
CVE-2026-34908
CVE-2026-34909
CVE-2026-34910
CVE-2026-34926
CVE-2026-35273
CVE-2026-35616
CVE-2026-39987
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Marimo CVE-2026-39987 LLM-agent post-exploitation
CVE-2026-40138
CVE-2026-40139
CVE-2026-40140
CVE-2026-40141
CVE-2026-4020
CVE-2026-41091
CVE-2026-41703
CVE-2026-41709
CVE-2026-41940
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
CVE-2026-42271
CVE-2026-42533
CVE-2026-42897
CVE-2026-43074
CVE-2026-43284
CVE-2026-43499
CVE-2026-43500
CVE-2026-43503
CVE-2026-44338
CVE-2026-45247
CVE-2026-45498
CVE-2026-45659
CVE-2026-46242
CVE-2026-46300
CVE-2026-46331
CVE-2026-46817
CVE-2026-47876
CVE-2026-48172
CVE-2026-48276
CVE-2026-48277
CVE-2026-48281
CVE-2026-48282
CVE-2026-48283
CVE-2026-48285
CVE-2026-48307
CVE-2026-48313
CVE-2026-48314
CVE-2026-48315
CVE-2026-48316
CVE-2026-48558
CVE-2026-48907
CVE-2026-48908
CVE-2026-48939
CVE-2026-50522
CVE-2026-50751
CVE-2026-50752
CVE-2026-53359
CVE-2026-5426
CVE-2026-54420
CVE-2026-55255
CVE-2026-56290
CVE-2026-56291
CVE-2026-59309
CVE-2026-59310
CVE-2026-59726
CVE-2026-60137
CVE-2026-62144
CVE-2026-62145
CVE-2026-63030
CVE-2026-63077
CVE-2026-66747
CVE-2026-6682
CVE-2026-6683
CVE-2026-6684
CVE-2026-6685
CVE-2026-6686
CVE-2026-6687
CVE-2026-6688
CVE-2026-67426
CVE-2026-6875
CVE-2026-7473
CVE-2026-8037
CVE-2026-8451
CVE-2026-8461
CVE-2026-8732
CVE-2026-9082
CVE-2026-9198
CWE-22
CWE-259
CWE-306
CWE-352
CWE-502
CWE-77
CWE-78
- LiteLLM CVE-2026-42271 MCP stdio command injection
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
CWE-829
cyber evaluation
cyber-espionage
CyberAv3ngers
cybercrime
- Dutch Police / NCSC 17-million-device botnet disruption
- First VPN
- Fox Tempest
- Funnull RingH23 and MacCMS supply-chain attacks
- Hunt.io global smishing infrastructure campaign
- JINX-0164
- Operation FlutterBridge FlutterShell macOS malvertising
- Outsider Enterprise smishing PhaaS
- Pirated media SilentCryptoMiner RAT campaign
- TA4922
- The Gentlemen ransomware
- UAT-11795
- UAT-11795 Starland / WLDR campaign
cybercrime ecosystem
cyberespionage
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
Cython
Czech Republic
D-Link
D2IP
dangling resources
DarkSword
data analytics
data exfiltration
- Ababil of Minab MOIS-linked recovery-destruction campaign
- AI-agent memory poisoning
- Atlassian Rovo prompt-to-data exfiltration
- Cloud bucket namespace hijacking
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- HOLLOWGRAPH
- MCP tool-description poisoning
- ModHeader browser-extension surveillance capability
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- Open VSX evil-twin extension campaign
- SHADOW-AETHER AI-augmented Latin America intrusions
data exposure
- Anthropic cyber-evaluation real-world intrusions
- Internet-exposed unauthenticated MCP servers
- ServiceNow instance unauthenticated table-query exploitation
data extortion
data leak site
data theft
- Accellion FTA exploitation campaign
- DeadLock ransomware
- GoSerpent Southeast Asia espionage campaign
- Gunra ransomware-as-a-service activity
- JINX-0163 / FulcrumSec
- Kairos data-extortion government payment
- Malware-Slop Claude user-data npm infostealer
- Metabase unauthenticated SQL-injection zero-day
- ShinyHunters
- UNC3753
data-exfiltration
database extortion
Datadog Security Labs
dataset dead drop
dataset processing
DAYLIGHT
DCloud
DCloud Uni-App
DcRAT
DD-WRT
DDNS
DDoS
- C0XMO Gafgyt DD-WRT botnet
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- Kimwolf v7
- Lucide Proxy npm browser DDoS botnet
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- RustDuck
DDoS botnet
DDoS-for-hire
dead drop
dead drop resolver
- ChocoPoC
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
dead-drop resolver
DeadLock
Debian
debugger evasion
DEBULL
declarativeNetRequest
DeepAudit
DeepSeek
- AI-augmented adversary operations
- AI-brand impersonation phishing and malvertising
- JetBrains AI plugin API-key theft
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Defender Advanced Hunting
Defender evasion
Defender exclusion
defense
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Kimsuky / Emerald Sleet / TA427
- Mirage Kitten
defense evasion
- Cloud logging control-plane tampering
- DeadLock ransomware
- GodDamn ransomware PoisonX BYOVD activity
- Ollama P2P cryptominer RAT campaign
- Pirated media SilentCryptoMiner RAT campaign
- ROADtools
- SourTrade browser-assembled malware malvertising
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
defense targeting
defense-evasion
DeFi
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- RemotePE
- TrapDoor crypto-stealer cross-ecosystem campaign
delayed execution
denial of service
- Citrix NetScaler CVE-2026-8451 memory overread
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- SolarWinds Serv-U CVE-2026-28318 exploitation
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
Deno
Dependabot
dependency confusion
- @marketfront / @tqm-mfe dependency-confusion stealer
- Alibaba developer-targeted distributed npm RAT campaign
- nodemon-sudo / tslint-conf runtime npm backdoor
- oob.moika.tech dependency-confusion environment stealer
deployment_status
deserialization
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Fastjson CVE-2026-16723 active exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Vertex AI staging-bucket squatting
destructive actions
destructive malware
destructive operations
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Iran-linked threat landscape: access optionality and evidence quality
- UAC-0145
detached execution
detached process
detection engineering
DEV#POPPER
DEV-0206
developer credential theft
developer credentials
developer endpoints
- Coding-agent-parented tunnels and persistence
- Crypto supply-chain path to transaction authority
- NuGet game-cheat DotnetTool pepesoft campaign
Developer ID abuse
developer identity
developer infrastructure
developer machines
- Agent localhost control-plane RCE
- Astro config blockchain C2 PR injection
- BufferZoneCorp RubyGems / Go module CI poisoning
- GuardFall AI-agent shell-guard bypass
- MCP stdio command-execution boundary
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
developer mode
developer platform
developer targeting
- Alibaba developer-targeted distributed npm RAT campaign
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Fake Corepack site infostealer and proxyware campaign
- FakeGit AgentBaiting and SmartLoader campaign
- Joyfill npm blockchain-RAT compromise
- NullReceiver DPRK-linked npm blockchain-loader wave
- Solana FakeFix npm / PyPI developer stealer
- ViteVenom / ChainVeil npm campaign
- Void Dokkaebi
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
developer tooling
- AsyncAPI generator / specs Miasma compromise
- Browser-based developer IDE OAuth token theft
- Cursor Windows workspace-path binary hijack
- Fake Corepack site infostealer and proxyware campaign
- ModHeader browser-extension surveillance capability
- Phantom squatting: AI-hallucinated domains
developer workstations
- Lazarus-linked Rollup polyfill npm malware
- Sentry MCP Agentjacking
- SleeperGem RubyGems maintainer-account compromise
developer-machine-fleet
developer-targeting
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- ChainDrop keyv / cacheable npm worm
- codexui-android OpenAI token stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- JetBrains AI plugin API-key theft
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Open VSX evil-twin extension campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- UNK_DeadDrop developer repository phishing
- wshu.net npm credential-stealer campaign
developer-tools
developer-workstations
- Atomic Arch AUR package hijack
- Dependabot cross-ecosystem malware advisory alerts
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- Open VSX evil-twin extension campaign
device identity
device lockout
device registration
device-code phishing
- APT29
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kali365 device-code phishing expansion
DevOps
DevTools
DEWMODE
DGA
DIAMONDBACK
digital forensics
Digital Knowledge
digital wallets
DigitalOcean
Dindoor
DingTalk
diplomatic targeting
direct-to-IP
directory traversal
DirtyClone
DirtyFrag
DISCLOSURE
Discord
discovery
disk wiping
distributed scanning
Djinn Stealer
DLL search-order hijacking
DLL side-loading
- MIXEDKEY
- OceanLotus
- Pirated media SilentCryptoMiner RAT campaign
- SprySOCKS
- TELESHIM
- TELESHIM Middle East government espionage campaign
DLL sideloading
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Cavern
- Exposed WebDAV malware delivery lab and CURP campaign
- FDMTP
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- HelloNet ViPNet update-system campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation Dragon Weave Azure Blob C2 campaign
- Operation GriefLure Southeast Asia LNK dropper
- QuickFox FDMTP software supply-chain compromise
- ScreenConnect freeware / AsyncRAT SEO campaign
- Screening Serpens
- Seedworm / MuddyWater
- SilkLurk
- Storm-2603 parallel SharePoint ransomware intrusion
- StrikeShark SharkLoader / Cobalt Strike campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
- Vidar / XMRig Factory-v3 malvertising campaign
DMTP
DNS
DNS C2
DNS callback
DNS dead drop
DNS exfiltration
- CL-STA-1114 Zimbra webmail espionage
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
DNS hijacking
DNS resolution
DNS threat intelligence
DNS tunneling
DNS-over-HTTPS
Docker
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- NadMesh AI-service and cloud-credential botnet
- Ulej / Flowerbed
Docker Compose
Docker credentials
Docker images
Docker socket
document collection
document exfiltration
document theft
- ACR Stealer
- Gamaredon
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
DOGLEASH
domain squatting
domestic espionage
dormant accounts
DotNetNuke
DotnetTool
double extortion
downgrade risk
downloader
downstream blast radius
DPAPI
DPAPILoader
DPRK
- AI-augmented adversary operations
- Astro config blockchain C2 PR injection
- Contagious Interview SVG-steganography OtterCookie campaign
- macOS.Gaslight Rust backdoor
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
DragonForce
drive serial number
driver loading
DroneLink
Dropbear
Dropbox
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Stock exchange executive mailbox espionage
dropper
Drupal
dual-use
dual-use tooling
duckdns
Dutch Police
DWAgent
dynamic DNS
dynamic obfuscation
Dynu
Dysphoria
e-commerce
Eagle Werewolf
Early Bird APC injection
Earth Lusca
East Asia
East Asia-linked
eBPF
- Atomic Arch AUR package hijack
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
Eclipse
Ed25519
edge appliance
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Check Point VPN CVE-2026-50751 exploitation
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- CitrixBleed session-hijack wave
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Ivanti Sentry CVE-2026-10520 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Quest KACE SMA CVE-2025-32975 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
edge appliances
edge application server
edge device
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- FortiBleed Fortinet credential exposure
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
edge devices
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Russian state IP-camera military-logistics espionage
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
edge exploitation
Edge extension
edge service
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
edge services
editor profile import
EDR evasion
EDR killer
EDS5000
education
- Brazilian education LockBit, DragonForce, and insider incidents
- HelloNet ViPNet update-system campaign
- Seedworm / MuddyWater
Egnyte
Egypt
EKZ Infostealer
Elastic Security Labs
- Contagious Interview SVG-steganography OtterCookie campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
Elasticsearch
electric power sector
Electron
email exfiltration
email gateway
email infrastructure abuse
email security
email theft
- OctLurk and SilkLurk Central Asia espionage campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
embedded configuration
embedded Linux
embedded systems
Emerald Sleet
ENCFORGE
encrypted C2
EncryptInterceptor
ENDLESSDOORS
endpoint compromise
endpoint management
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
endpoint management abuse
endpoint response
endpoint-detection
endpoint-security
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
EndpointDlp.dll
energy sector
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- HelloNet ViPNet update-system campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
energy-sector
engineering
engineering software
enterprise AI
enterprise application
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow AI Platform CVE-2026-6875 exploitation
enterprise application exploitation
enterprise applications
enterprise proxy
Entra ID
Environment Management Hub
environment variable theft
- Braintree.Net NuGet payment skimmer
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
environment variables
environmental keying
- BINDCLOAK
- LurkProxy
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- MIXEDKEY
- OctLurk
- OctLurk and SilkLurk Central Asia espionage campaign
- RemotePE
- SilkLurk
- TELESHIM Middle East government espionage campaign
epoll
Epsilon Stealer
ERP
error-message disclosure
eSentire TRU
ESG
espionage
- APT29
- ArcBridge
- Barracuda ESG zero-day backdoor campaign
- BridgeHead
- Cavern Manticore
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- Cloud Atlas
- Dragonfly
- FishMonger
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghostwriter
- GoSerpent Southeast Asia espionage campaign
- GREYVIBE
- HelloNet ViPNet update-system campaign
- HOLLOWGRAPH
- Iran-linked threat landscape: access optionality and evidence quality
- Kimsuky / Emerald Sleet / TA427
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- NightLedger
- OceanLotus
- Oman government Iranian-nexus webshell C2
- OP-512
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Pakistani law enforcement espionage convergence
- QuickFox FDMTP software supply-chain compromise
- RemotePE
- ROADtools
- Russian state IP-camera military-logistics espionage
- ScarCruft Yanbian game-platform supply-chain attack
- Screening Serpens
- Seedworm / MuddyWater
- Showboat
- SideCopy
- SprySOCKS
- Stock exchange executive mailbox espionage
- TELESHIM Middle East government espionage campaign
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Turla
- Turla STOCKSTAY backdoor operations
- UAC-0145
- Ulej / Flowerbed
- UNC6508
- UNC6692 SNOW malware social-engineering campaign
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- Webworm
Espressif ESP-IDF
ESX
ESXi
Ethereum
- Adform Trackpoint JavaScript supply-chain crypto clipper
- ChainDrop keyv / cacheable npm worm
- Ill Bloom CryptoJS wallet-drain campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Ethereum Name Service
EtherHiding
- ACR Stealer
- ChainDrop keyv / cacheable npm worm
- Silent Swap Google Notes crypto clipper
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Ethiopia
ETW bypass
ETW patching
ETW tampering
Eurojust
Europe
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Webworm
Europe targeting
European Union
Europol
evaluation containment
evasion
event log clearing
eventpoll
Everest Forms Pro
evidence quality
Evil Corp
EvilAI
Evilginx
EWS
excessive agency
exec_globals
execution guardrails
exFAT
exfiltration
- codexui-android OpenAI token stealer
- Direct-to-IP malware communications
- JetBrains AI plugin API-key theft
- js-logger-pack Hugging Face exfiltration campaign
- Malware-Slop Claude user-data npm infostealer
exploit chain
exploit kit
exploit-development
exploit-kit
Exploit.in
exploitation
- Android Framework CVE-2025-48595 exploitation
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Langflow CVE-2025-34291 exploitation
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
exploitation attempts
ExploitGym
exposed applications
exposed attacker infrastructure
exposed debug page
extension supply-chain
- Adblock for YouTube BadBlocker remote-script injection risk
- StegoAd Edge extension steganography campaign
external federation
extortion
- Accellion FTA exploitation campaign
- CrownX
- JINX-0163 / FulcrumSec
- Klue Salesforce OAuth token abuse
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- ShinyHunters
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
- UNC3753
- UNC6671 / BlackFile multi-brand vishing extortion operation
F5
F5 BIG-IP
Factory-v3
fake app store
fake CAPTCHA
- ClickFix CPaaS API-driven payload delivery
- GREYVIBE
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
fake certificate
fake crypto exchange
fake dating lures
fake gambling
fake installers
fake login
fake login screen
fake Microsoft Store
fake plugin
fake PoC
fake ransomware
fake recruiting
- Contagious Interview SVG-steganography OtterCookie campaign
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Void Dokkaebi
fake reputation
fake update
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Operation BlueDash multi-RMM workplace phishing
- Pirated media SilentCryptoMiner RAT campaign
FakeCaptcha
FakeGit
Fakeset
faketivism
FakeUpdates
FALCON
FallSpy
FAMOUS CHOLLIMA
Famous Chollima
- NullReceiver DPRK-linked npm blockchain-loader wave
- PolinRider cross-ecosystem supply-chain campaign
Fancy Bear
Fast16
FastAPI
FastCGI
Fastjson
Fastmail
fat JAR
FAT32
FatFs
FBI
fbot
FDMTP
Feiying
FFmpeg
FIDO2
FIFA
file encryption
file exfiltration
file inflation
file operations
file sharing
file theft
File Transmission
file upload path traversal
file-system filter
FileFiend
FILEIO
fileless execution
fileless malware
filemanager
filename-injection
filesystem parser
finance
- oob.moika.tech dependency-confusion environment stealer
- Sicoob.Sdk NuGet banking certificate stealer
financial fraud
- AI token-jacking transfer-station abuse
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- REF6045 / SCMBANKER Mexican banking fraud
financial sector
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- RemotePE
- SHADOW-AETHER AI-augmented Latin America intrusions
- Stock exchange executive mailbox espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
financial services
- Seedworm / MuddyWater
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
- UNC3753
financial theft
financially motivated
FireAnt MetaKit
Firebase
Firefox
Firefox Add-ons
Firefox WebDriver BiDi
Firepower Management Center
firewall
firewall management
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
firmware
- COLDCARD predictable-RNG Bitcoin theft risk
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
firmware backdoor
firmware update
FishMonger
FlexPLM
FlockWiper
Flooding Dropper
flow execution
Flowerbed
FLUIDLEECH
Flutter
FlutterShell
Flying Eagle
Flyto2 Core
FMC
FOFA
FofaMap
folderOpen
foreign affairs targeting
foreign policy targeting
Forest Blizzard
Forg365
ForgCookie
Forgejo
FortiClient EMS
FortiGate
- FortiBleed Fortinet credential exposure
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Gunra ransomware-as-a-service activity
Fortinet
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
FortiOS
- FortiBleed Fortinet credential exposure
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Gunra ransomware-as-a-service activity
FortiSandbox
Fox Tempest
fraud
FREAKYPOLL
FreeBSD
Freedom365
freeware impersonation
Friendly Fire
FruitStone
FSB
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Russian intelligence commercial-messaging backup-key phishing
FSB Center 16
fscan
Fscan
FTA
ftp.exe
Full Disk Access social engineering
Funnull
futex PI
Gafgyt
GaiaOS WebUI
Gamaredon
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
Gamaredon collaboration
gambling
gambling industry targeting
game cheats
GammaLoad
GammaPhish
GammaSteel
GammaWorm
Garble
Gardener
Gatekeeper bypass
GCP
GCS
Gemini CLI
GenieLocker
GentleKiller
Germany
GHETTOVIBE
Ghost
ghost accounts
Ghost CMS
Ghost Networks
GHOSTBLADE
GhostLock
GHSA-6rmh-7xcm-cpxj
GHSA-6v3r-4p5c-mrp5
GHSA-c4hm-4h84-2cf3
GHSA-qrpv-q767-xqq2
GHSA-rg76-677x-56q9
GHSA-vwf4-m7j8-wcjf
GHSA-xhcr-j4j9-3gh7
GIFTEDCROOK
Git
git.exe
Gitea
GitHub
- Aeternum
- Astro config blockchain C2 PR injection
- Browser-based developer IDE OAuth token theft
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChocoPoC fake PoC supply-chain campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- Crypto supply-chain path to transaction authority
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- FakeGit AgentBaiting and SmartLoader campaign
- GitHub / Packagist postinstall hook campaign
- GitHub API enumeration and access-token abuse
- Glassworm developer supply-chain botnet
- IronWorm npm Rust infostealer campaign
- JiaT75
- JINX-0164 crypto developer infrastructure campaign
- Malware-Slop Claude user-data npm infostealer
- Nx Console VS Code extension compromise
- Operation Muck and Load GitHub lure network
- PolinRider cross-ecosystem supply-chain campaign
- UNK_DeadDrop developer repository phishing
- Webworm
- XCSSET v40 Xcode supply-chain campaign
GitHub abuse
- AI-brand impersonation phishing and malvertising
- Armored Likho BusySnake campaign
- Fake-reputation crypto clipboard hijacker
GitHub Actions
- actions-cool GitHub Actions tag compromise
- AsyncAPI generator / specs Miasma compromise
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- ChainDrop keyv / cacheable npm worm
- Claude Code GitHub Action prompt-injection boundary
- codfish semantic-release-action tag compromise
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- Operation Muck and Load GitHub lure network
- SANDWORM_MODE AI-toolchain npm worm
- simonecorsi/mawesome GitHub Action compromise
- TeamPCP
- tj-actions and reviewdog compromise
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
GitHub Advisory Database
GitHub API
GitHub App
GitHub CLI
GitHub dead drop
- CrashStealer macOS notarized-dropper campaign
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
GitHub issue spam
GitHub OAuth
GitHub Pages abuse
GitHub payload delivery
GitHub release assets
GitHub Security Advisories
- Agent localhost control-plane RCE
- Dependabot cross-ecosystem malware advisory alerts
- LangGraph checkpointer and namespace trust boundaries
GitHub tokens
GitHub-hosted runners
GitLab
gitleaks
GitOps
Gleaming Pisces
gleeze.com
GlobalProtect
Gmail
- AI browser-extension confused deputy
- ToddyCat
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
- Webmail CSS trust-boundary attacks
Go
- BufferZoneCorp RubyGems / Go module CI poisoning
- Ollama P2P cryptominer RAT campaign
- Operation Muck and Load GitHub lure network
- shopsprint/decimal Go typosquat DNS backdoor
- The Gentlemen ransomware
Go loader
Go malware
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- GoSerpent Southeast Asia espionage campaign
- NadMesh AI-service and cloud-credential botnet
- Vidar / XMRig Factory-v3 malvertising campaign
Go modules
Go2Tunnel
GodDamn ransomware
GodPotato
Godzilla
GoEdge
GoFile
Golang
Golang malware
GOLD PRELUDE
Golden Pass-ta-key
Google Ads
Google Analytics telemetry
Google API
Google Calendar
Google Chrome
Google Cloud
Google Cloud Authenticator
Google Cloud Logging
Google Cloud Storage
Google credential theft
Google Docs
Google Drive
Google Notes
Google Password Manager
Google Play
Google Play Protect
Google redirect abuse
Google Sheets
Google Stitch
Google Threat Intelligence Group
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- NetNut / Popa residential proxy network disruption
- UNC6508
Google Workspace
Goose
GoSerpent
government
- Cavern Manticore
- HelloNet ViPNet update-system campaign
- Kairos data-extortion government payment
- Kimsuky / Emerald Sleet / TA427
- Oman government Iranian-nexus webshell C2
government impersonation
government targeting
- Armored Likho
- Armored Likho BusySnake campaign
- BINDCLOAK
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Cloud Atlas
- FishMonger
- GoSerpent Southeast Asia espionage campaign
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mustang Panda
- OctLurk and SilkLurk Central Asia espionage campaign
- Russian intelligence commercial-messaging backup-key phishing
- SHADOW-AETHER AI-augmented Latin America intrusions
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TA488 OWAReaper and CVE-2026-42897 exploitation
- TELESHIM Middle East government espionage campaign
government-impersonation
GPT
GPT-5.6 Sol
Gradio
Grafana MCP Server
Grandoreiro
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
granular access tokens
GraphSpy
Gravity SMTP
gray market
GRE
Gremlin API
GREYVIBE
group
groups
- APT29
- CL-STA-1062
- CL-STA-1114 / Void Blizzard
- Dragonfly
- Fox Tempest
- JINX-0164
- OP-512
- TA4922
- Toy Ghouls
- Turla
- UAT-11795
- UNC3753
- UNC6508
- VerdantBamboo
- Void Dokkaebi
- Webworm
gRPC
gRPC C2
GRU
gs-netcat
GS-Netcat
Gshell
GTIG
GUE
guest-to-host escape
Guildma
Gunra
hack-and-leak
HackIndex
hacktivist persona
Hades
Hajime
half-click exploit
hallucination
HalluSquatting
Handala
HappyDoor
HAR files
hard-coded password
hard-coded secrets
hardware wallet
HarmonyLib
HashiCorp Vault
HavocKiller
HDF5
headless browser
healthcare
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation GriefLure Southeast Asia LNK dropper
- Thailand healthcare RAR / Python stealer campaign
heap buffer overflow
heap pointer disclosure
HELIX
HelloBackdoor
HelloCleaner
HelloDoor
HelloExecutor
HelloInjector
HelloNet
HelloProxy
HellsGate
Helm
Hermes Agent
- AI-augmented adversary operations
- GuardFall AI-agent shell-guard bypass
- knaithe Hermes/DeepSeek autonomous exploitation campaign
HexKiller
hidden backdoor
hidden instructions
hidden service
high explosives
higher education
HOLLOWGRAPH
Honduras
HONESTCUE
Hong Kong
Hong Kong infrastructure
hospitality
hospitality targeting
Host Radar
host surveillance
hosting control plane
hosting provider
hosting providers
hotel targeting
Howling Scorpius
HPC
HR lures
HTA
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- UAT-11795 Starland / WLDR campaign
HTML comments
HTML email
HTML sanitization
HTML smuggling
HTTP C2
HTTP/2
HttpMalice
HTTPS C2
HTTPS exfiltration
HTTPSpy
Hugging Face
- forge-jsxy
- Hugging Face autonomous-agent production intrusion
- js-logger-pack Hugging Face exfiltration campaign
Hunt.io
- GHOST STADIUM FIFA World Cup ticket phishing
- Malicious infrastructure provider concentration
- Quest KACE SMA CVE-2025-32975 exploitation
- xlabs_v1 DDoS-for-hire IoT botnet
Huntress
- Azure CLI LSHIY password-spray campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
Hyadina
hybrid threat actor
hydropower
Hydropower Cooperation Project Proposal.zip
hypervisor escape
Hyunwoo Kim
I-SOON
IAM
IBM
iCagenda
ICE
iCloud theft
ICONICSTEALER
ICS
- Dragonfly
- Iran-linked threat landscape: access optionality and evidence quality
- KNX Protocol CVE-2023-4346 KEV exploitation
IDE extension
IDE plugins
ide.cfm
identity
- 0ktapus phishing campaign
- JINX-0163 / FulcrumSec
- ROADtools
- UNC6671 / BlackFile multi-brand vishing extortion operation
identity attacks
identity compromise
identity infrastructure
identity security
identity-first intrusion
IDEs
IFEO persistence
IIOP
IIS
IKEv1
Ill Bloom
image proxy bypass
image recognition
iMessage
Impacket
- Gunra ransomware-as-a-service activity
- OctLurk and SilkLurk Central Asia espionage campaign
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
impersonation
implant
import-time execution
- Joyfill npm blockchain-RAT compromise
- Lazarus-linked Rollup polyfill npm malware
- MrMustard PyPI credential-stealer compromise
- Solana FakeFix npm / PyPI developer stealer
- ViteVenom / ChainVeil npm campaign
improper privilege management
in-memory DLL loading
in-memory malware
in-memory plugins
incident response
- Adform Trackpoint JavaScript supply-chain crypto clipper
- Anthropic cyber-evaluation real-world intrusions
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Brazilian education LockBit, DragonForce, and insider incidents
- Check Point VPN CVE-2026-50751 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- COLDCARD predictable-RNG Bitcoin theft risk
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Hugging Face autonomous-agent production intrusion
- Ill Bloom CryptoJS wallet-drain campaign
- Iran-linked threat landscape: access optionality and evidence quality
- Klue Salesforce OAuth token abuse
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Malicious infrastructure provider concentration
- Metabase unauthenticated SQL-injection zero-day
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Water-sector PLC configuration-tampering campaign
incident-response
- Dependabot cross-ecosystem malware advisory alerts
- Storm-2603 parallel SharePoint ransomware intrusion
incomplete patch
IndexedDB
- ModHeader browser-extension surveillance capability
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
India
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation DragonReturn India tax-season DcRAT campaign
India-nexus
Indian government
indirect prompt injection
- AI browser-extension confused deputy
- AI-agent memory poisoning
- AI-augmented adversary operations
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- MCP tool-description poisoning
- Sentry MCP Agentjacking
- Webmail CSS trust-boundary attacks
indirect syscalls
Indonesia
industrial control
industrial control systems
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Siemens ROX II zero-day exploit chain
- Water-sector PLC configuration-tampering campaign
industrial espionage
industrial targeting
INFINITERED
Infoblox Threat Intel
information disclosure
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FortiOS CVE-2025-68686 symlink-persistence bypass
- LangGraph checkpointer and namespace trust boundaries
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
infostealer
- @copilot-mcp/apex macOS infostealer campaign
- ACR Stealer
- Armored Likho
- Armored Likho BusySnake campaign
- BusySnake Stealer
- codexui-android OpenAI token stealer
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- Fake Corepack site infostealer and proxyware campaign
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164 crypto developer infrastructure campaign
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Operation Muck and Load GitHub lure network
- PamStealer
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- TamperedChef-style productivity malware clusters
- Telnyx PyPI TeamPCP compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- wshu.net npm credential-stealer campaign
InfoTeCS
infrastructure
- First VPN
- Flying Eagle and Night Dragon Android RAT ecosystem
- Funnull RingH23 and MacCMS supply-chain attacks
- GHOST STADIUM FIFA World Cup ticket phishing
- Hunt.io global smishing infrastructure campaign
- Malicious infrastructure provider concentration
infrastructure churn
infrastructure disruption
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NetNut / Popa residential proxy network disruption
- StealC / Amadey infrastructure disruption
initial access broker
initial-access
- AI-augmented adversary operations
- ClickOnce COM hijacking abuse
- Operation Endgame SocGholish disruption
Injective Labs
input capture
insider threat
install-time execution
- @copilot-mcp/apex macOS infostealer campaign
- Anthropic cyber-evaluation real-world intrusions
- Flooding Dropper npm campaign
- jscrambler npm preinstall stealer
- MYRA RAT
- Solana FakeFix npm / PyPI developer stealer
install-time-execution
install.res.1033.dll
Integration Broker
Intercolo
internal secret exfiltration
internet exposure
internet-facing admin surface
internet-facing appliance
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
internet-facing applications
investment scam
InvisibleFerret
invocation logging
iOS
- art-template Coruna-style iOS watering-hole compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
IoT
- Dutch Police / NCSC 17-million-device botnet disruption
- ENDLESSDOORS implant in Zbtlink router firmware
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- JDY SOHO / IoT reconnaissance botnet
- Kimwolf v7
- Russian state IP-camera military-logistics espionage
IoT botnet
- AryStinger legacy-router recon proxy network
- C0XMO Gafgyt DD-WRT botnet
- Direct-to-IP malware communications
- Dysphoria IoT botnet
- RustDuck
- TuxBot v3 Evolution IoT botnet framework
- xlabs_v1 DDoS-for-hire IoT botnet
IP cameras
IP-in-IP
IPFS
iPhone
IPsec
IPv6
ipynbdiff
Iran
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Cavern
- Cavern Manticore
- Handala
- Iran-linked threat landscape: access optionality and evidence quality
- Langflow CVE-2025-34291 exploitation
- Screening Serpens
- Seedworm / MuddyWater
Iran-nexus
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Oman government Iranian-nexus webshell C2
IRGC
IronWorm
Irregular
ischhfd83
Island Security Research
- Adblock for YouTube BadBlocker remote-script injection risk
- FakeGit AgentBaiting and SmartLoader campaign
ISO image
Israel
IT providers
Italian foreign-policy targeting
Italy targeting
Ivanti Sentry
JackSkid
JADEPUFFER
Jamf Threat Labs
Januscape
Japan
JARLEASH
Java
Java malware
JavaScript
- Astro config blockchain C2 PR injection
- Flooding Dropper npm campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Mastra
easy-day-jsnpm scope compromise - nodemon-sudo / tslint-conf runtime npm backdoor
- npm install explicit-trust controls
- Operation DangerousPassword axios npm compromise
- Operation XENOFISCAL SideCopy XenoRAT campaign
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- TaskWeaver
- Ulej / Flowerbed
- wshu.net npm credential-stealer campaign
JavaScript bridge
JavaScript execution
JavaScript injection
JavaScript loader
JavaScript malware
- Contagious Interview SVG-steganography OtterCookie campaign
- Ghostwriter
- NullReceiver DPRK-linked npm blockchain-loader wave
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
JavaScript masquerading
JavaScript tampering
JavaScriptCore
JCE
JDY
Jellyfin
Jenkins
JetBrains
- Amazon Q CVE-2026-12957 MCP auto-execution
- JetBrains AI plugin API-key theft
- JetBrains TeamCity CVE-2026-63077 active exploitation
JetBrains Marketplace
JetStream
JFrog
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Lucide Proxy npm browser DDoS botnet
JFrog Artifactory
JFrog Security Research
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- Solana FakeFix npm / PyPI developer stealer
Jinja2
JINX-0164
Jira
joblib
Joomla
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- WP-SHELLSTORM webshell access brokerage
Joomla Content Editor
Joomla JCE
Joomlack
JoomShaper
Jordan
journalists
JSCoreRunner
jscrambler
Jscrambler
JScript
JSON
JSON-RPC
JSON:API
JSONKeeper
JSONPing
JSP web shell
JuicyPotato
Jupyter Notebook
JustWatch
JXA downloader
K1MORPHER
Kairos
Kaitori
Kali365
Kaspersky
Kaspersky GERT
Kaspersky GReAT
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- OkoBot cryptocurrency-wallet malware framework
Kaspersky Securelist
Kazakhstan
KAZUAR
KAZUAR overlap
KeePassXC
Keitaro
Keksec
Kemp LoadMaster
kernel driver
kernel instrumentation
kernelCTF
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
KEV
- Drupal Core CVE-2026-9082 exploitation
- Langflow CVE-2025-34291 exploitation
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
Keychain theft
keychain theft
- Coding-agent-parented tunnels and persistence
- CrashStealer macOS notarized-dropper campaign
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- macOS.Gaslight Rust backdoor
KeyHunter
keylogger
- Brazilian education LockBit, DragonForce, and insider incidents
- forge-jsxy
- js-logger-pack Hugging Face exfiltration campaign
- OkoBot cryptocurrency-wallet malware framework
- TELEPUZ
keylogging
- Flying Eagle and Night Dragon Android RAT ecosystem
- Operation Highland Velvet Ant authentication-stack backdoors
Kimsuky
Kimwolf
Kimwolf v7
Klue
knaithe
KnowledgeDeliver
known exploited vulnerability
KNUCKLEBALL
KNX
KNX Association
KNX Protocol
KnYuan
KongTuke
KORKERDS
Kratos
Kubernetes
- @copilot-mcp/apex macOS infostealer campaign
- Argo CD repo-server unauthenticated RCE
- Crypto supply-chain path to transaction authority
- Hugging Face autonomous-agent production intrusion
- MrMustard PyPI credential-stealer compromise
- NadMesh AI-service and cloud-credential botnet
KV-botnet
KVM
KVM escape
kvmCTF
Kyrgyzstan
L2TP/IPSec
LA Metro
Laboo.boo
LabubaPanel
LabubaRAT
Labubu
LangChain
Langflow
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- ENCFORGE
- JADEPUFFER Langflow agentic ransomware
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
LangFlow
LangGraph
Language Servers for AWS
Lantronix
LapDogs
Laravel
Laravel deserialization
lateral movement
- Alibaba developer-targeted distributed npm RAT campaign
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- GodDamn ransomware PoisonX BYOVD activity
- Hugging Face autonomous-agent production intrusion
- LurkProxy
- Quest KACE SMA CVE-2025-32975 exploitation
- The Gentlemen ransomware
lateral-movement
Latin America
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- SHADOW-AETHER AI-augmented Latin America intrusions
LaunchAgent
- @copilot-mcp/apex macOS infostealer campaign
- Coding-agent-parented tunnels and persistence
- CrashStealer macOS notarized-dropper campaign
- macOS.Gaslight Rust backdoor
launchctl
LAUNDRY BEAR
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
law enforcement
- Dutch Police / NCSC 17-million-device botnet disruption
- Kratos Microsoft 365 PhaaS and infrastructure disruption
law enforcement targeting
- OctLurk and SilkLurk Central Asia espionage campaign
- Pakistani law enforcement espionage convergence
law-enforcement-disruption
LayerX
Lazarus
- Famous Chollima Packagist dev-branch loader
- Lazarus-linked Rollup polyfill npm malware
- NullReceiver DPRK-linked npm blockchain-loader wave
- Operation DangerousPassword axios npm compromise
- RemotePE
- StegaBin Pastebin-steganography npm campaign
LD_PRELOAD
LDAP
leaked credentials
leaked exploit
leaked source code
LEASHTEST
least privilege
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- Cloud bucket namespace hijacking
- Internet-exposed unauthenticated MCP servers
Ledger
legacy botnet hijacking
legacy infrastructure
legacy software
legacy systems
legal sector
LegionRelay
Leo Platform
Level RMM
LevelBlue
Lexfo
libcurl
liblzma
libp2p
libpeconv
libsodium
lifecycle hooks
lifecycle-hooks
Lightning Shared Scooter Co.
Linksys
Linux
- Atomic Arch AUR package hijack
- Djinn Stealer
- ENCFORGE
- Flooding Dropper npm campaign
- GenieLocker
- GitHub / Packagist postinstall hook campaign
- IronWorm npm Rust infostealer campaign
- Januscape KVM CVE-2026-53359 guest-to-host escape
- js-logger-pack Hugging Face exfiltration campaign
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- MYRA RAT
- Ollama P2P cryptominer RAT campaign
- Operation DangerousPassword axios npm compromise
- Operation Highland Velvet Ant authentication-stack backdoors
- PCPJack cloud SMTP relay network
- QuimaRAT
- Showboat
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
- Velvet Ant
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- XZ Utils backdoor
Linux kernel
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux pedit COW CVE-2026-46331 local privilege escalation
Linux malware
Linux networking devices
LiteLLM
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- Telnyx PyPI TeamPCP compromise
LiteSpeed
living off the land
living-off-the-land
living-off-the-land binaries
LLM
- AI token-jacking transfer-station abuse
- AI-augmented adversary operations
- GREYVIBE
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Ollama P2P cryptominer RAT campaign
LLM security
LLM-assisted malware
- Exposed WebDAV malware delivery lab and CURP campaign
- REF6045 / SCMBANKER Mexican banking fraud
- TuxBot v3 Evolution IoT botnet framework
LLM-driven intrusion
LLMjacking
LMS
LNK
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Armored Likho BusySnake campaign
- Avalon / CrownX malware framework
- Crypto Clipper Tor / USB worm
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation GriefLure Southeast Asia LNK dropper
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Photo ZIP hospitality Node.js implant campaign
- SideCopy
- UAC-0226 / SHADOW-EARTH-066
LNK files
load balancer
loader
- Aeternum
- Famous Chollima Packagist dev-branch loader
- Flooding Dropper npm campaign
- MIXEDKEY
- RustDuck
- StealC / Amadey infrastructure disruption
- TaskWeaver
LOADLOOP
local LLMs
local privilege escalation
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux pedit COW CVE-2026-46331 local privilege escalation
- MiniPlasma Windows Cloud Filter LPE exploitation
local-file-inclusion
localhost
localhost.run
localStorage
LockBit
LockBit 3.0
log poisoning
logging
logging impairment
login item persistence
LOLBins
- ClickFix CPaaS API-driven payload delivery
- Exposed WebDAV malware delivery lab and CURP campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
long-horizon autonomy
long-lived tokens
long-term access
LONGLEASH
LONGSTREAM
LOOKVALJS
LOOKVALPS
loopback
Loophole
low-confidence attribution
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- HOLLOWGRAPH
- WhatsApp VBScript ManageEngine RMM campaign
LPE
LS-DYNA
LSASS
LSHIY
LSSC
Lua
LuaJIT
Lumen
Lumen Black Lotus Labs
Lumma Stealer
Luna Moth
Luno
LurkProxy
Lyceum
M-RED-TEAM
MaaS
- ACR Stealer
- Flying Eagle and Night Dragon Android RAT ecosystem
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
MAC address
MacCMS
Maccy impersonation
machine-learning
macOS
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- Coding-agent-parented tunnels and persistence
- CrashStealer macOS notarized-dropper campaign
- Djinn Stealer
- Flooding Dropper npm campaign
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- js-logger-pack Hugging Face exfiltration campaign
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Operation DangerousPassword axios npm compromise
- Operation FlutterBridge FlutterShell macOS malvertising
- PamStealer
- QuimaRAT
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
macOS malware
MaDoO Blaster
Magento
MagicYUV
mail server compromise
mail-argenta
mailbox compromise
mailbox permission abuse
mailbox theft
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Stock exchange executive mailbox espionage
MAIN world injection
maintainer compromise
- Injective SDK npm wallet stealer
- Joyfill npm blockchain-RAT compromise
- Mastra
easy-day-jsnpm scope compromise - MrMustard PyPI credential-stealer compromise
- Operation DangerousPassword axios npm compromise
maintainer persona
maintainer-compromise
malicious dataset
malicious GPO
malicious package
malicious packages
- Dependabot cross-ecosystem malware advisory alerts
- Flooding Dropper npm campaign
- npm publish-time malware scanning and dual-use declarations
- NullReceiver DPRK-linked npm blockchain-loader wave
- ViteVenom / ChainVeil npm campaign
malicious plugin
malicious releases
malicious signed driver
malvertising
- ACR Stealer
- AI-brand impersonation phishing and malvertising
- Fake Corepack site infostealer and proxyware campaign
- Lucide Proxy npm browser DDoS botnet
- Operation FlutterBridge FlutterShell macOS malvertising
- SourTrade browser-assembled malware malvertising
- StealC / Amadey infrastructure disruption
- TamperedChef-style productivity malware clusters
- Vidar / XMRig Factory-v3 malvertising campaign
malware
- ACR Stealer
- Aeternum
- AI-augmented adversary operations
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BINDCLOAK
- binding.gyp npm CI/CD worm
- BusySnake Stealer
- CanisterWorm
- Cavern
- ChocoPoC
- CrownX
- Crypto Clipper Tor / USB worm
- DeadLock ransomware
- Direct-to-IP malware communications
- Djinn Stealer
- ENCFORGE
- Fast16
- FDMTP
- forge-jsxy
- GenieLocker
- GigaWiper
- HOLLOWGRAPH
- IronWorm npm Rust infostealer campaign
- Kimwolf v7
- LabubaRAT
- LurkProxy
- macOS.Gaslight Rust backdoor
- MIXEDKEY
- MODBEACON
- MYRA RAT
- OctLurk
- Operation Endgame SocGholish disruption
- OWAReaper
- PamStealer
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- RedWing
- RemotePE
- RustDuck
- SCMBANKER
- Showboat
- SilkLurk
- SprySOCKS
- Starland RAT
- StealC / Amadey infrastructure disruption
- STOCKSTAY
- StrikeShark SharkLoader / Cobalt Strike campaign
- TA4922
- TamperedChef-style productivity malware clusters
- TaskWeaver
- TeamPCP
- TELEPUZ
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Umbrij
- UNC6692 SNOW malware social-engineering campaign
- WLDR agent
- XCSSET
malware analysis
malware delivery
- ClickFix CPaaS API-driven payload delivery
- Fake Corepack site infostealer and proxyware campaign
- FakeGit AgentBaiting and SmartLoader campaign
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- Microsoft Q2 2026 email and Teams phishing landscape
- TELEPUZ ClickFix / VIDAR campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
malware framework
- Avalon / CrownX malware framework
- Flying Eagle and Night Dragon Android RAT ecosystem
- OkoBot cryptocurrency-wallet malware framework
malware scanning
Malware-as-a-Service
malware-as-a-service
- LabubaRAT
- QuimaRAT
- RedWing
- RedWing mobile MaaS Android bank-fraud operation
- StealC / Amadey infrastructure disruption
malware-signing-as-a-service
MALXMR
managed database
managed file transfer
- Progress ShareFile Storage Zone Controller security threat
- SolarWinds Serv-U CVE-2026-28318 exploitation
managed service provider
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
ManageEngine Endpoint Central
management plane
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Lantronix EDS5000 CVE-2025-67038 exploitation
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Manifest V3
Manifold Security
manufacturing
Mapbox
marimo
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Marimo CVE-2026-39987 LLM-agent post-exploitation
Markdown image rendering
MARKETMAKER
marketplace abuse
marketplace trust
MarkiRAT
mass scanning
Maven Central
mawesome
Mbed
McAfee Labs
McMx
MCP
- @copilot-mcp/apex macOS infostealer campaign
- Agent localhost control-plane RCE
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- Internet-exposed unauthenticated MCP servers
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NadMesh AI-service and cloud-credential botnet
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
MCP credentials
mcp-grafana
media processing
medical research
Mekotio
memfd
memory corruption
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- GitLab Oj notebook-diff authenticated RCE chain
memory disclosure
- Citrix NetScaler CVE-2026-8451 memory overread
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
memory implant
memory overread
memory poisoning
memory-only malware
merchant credential theft
mesh VPN
MeshAgent
MeshCentral
Meta Ads
Metabase
MetaMask
MEV bot lure
Mexican banking fraud
Mexico
- Exposed WebDAV malware delivery lab and CURP campaign
- REF6045 / SCMBANKER Mexican banking fraud
- SHADOW-AETHER AI-augmented Latin America intrusions
MFA bypass
- 0ktapus phishing campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Azure CLI LSHIY password-spray campaign
- Chinese-language PhaaS wallet-tokenization ecosystem
- CitrixBleed session-hijack wave
- Evilginx and device-code phishing open-directory cluster
- Gunra ransomware-as-a-service activity
- ROADtools
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
MFA fatigue
MFA-bypass
MFT
Miasma
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- AsyncAPI generator / specs Miasma compromise
- binding.gyp npm CI/CD worm
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
MicroLogix 1100
MicroLogix 1400
MicroPython
- COLDCARD predictable-RNG Bitcoin theft risk
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
Microsoft
- Agent localhost control-plane RCE
- AI-agent memory poisoning
- AI-brand impersonation phishing and malvertising
- Azure DevOps MCP pull-request prompt injection
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- CL-STA-1114 / Void Blizzard
- Fox Tempest
- MCP tool-description poisoning
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
Microsoft .NET
Microsoft 365
- Azure CLI LSHIY password-spray campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- HOLLOWGRAPH
- Kali365 device-code phishing expansion
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- O-UNC-066 Entra passkey vishing
- UNC6671 / BlackFile multi-brand vishing extortion operation
Microsoft 365 Copilot
Microsoft Authentication Broker
Microsoft Azure
Microsoft Defender
Microsoft Defender Security Research
Microsoft dev tunnels
Microsoft Digital Crimes Unit
Microsoft Edge
Microsoft Edge Add-ons
Microsoft Edge Extensions Security Team
Microsoft Entra ID
- Azure CLI LSHIY password-spray campaign
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- O-UNC-066 Entra passkey vishing
Microsoft Exchange Server
Microsoft Graph
Microsoft Identity Platform
Microsoft Office SharePoint
Microsoft Security Blog
Microsoft SQL Server
Microsoft Teams
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft Teams external-chat phishing
- Operation BlueDash multi-RMM workplace phishing
- UNC6692 SNOW malware social-engineering campaign
Microsoft Threat Intelligence
- ACR Stealer
- DeadLock ransomware
- GigaWiper
- macOS ClickFix fingerprinting-gate campaign
- Microsoft Q2 2026 email and Teams phishing landscape
Microsoft Windows Hardware Compatibility Publisher
Microsoft-signed binary abuse
Middle East
- ArcBridge
- BINDCLOAK
- Malicious infrastructure provider concentration
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Showboat
- TELESHIM Middle East government espionage campaign
middleware
Midnight Blizzard
military logistics
military research
Milo Wallet
Mimikatz
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
- Toy Ghouls GenieLocker ransomware activity
Minecraft DDoS
Mini Shai-Hulud
- AsyncAPI generator / specs Miasma compromise
- Dependabot cross-ecosystem malware advisory alerts
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
- npm publish-time malware scanning and dual-use declarations
MiniJunk
MiniPlasma
MINIRAT
MINIRECON
Ministry of Finance
- Operation DragonReturn India tax-season DcRAT campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
MiniUpdate
MIPS embedded devices
Mirage Kitten
- ArcBridge
- BridgeHead
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- NightLedger
Mirai
- Malicious infrastructure provider concentration
- NetNut / Popa residential proxy network disruption
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Mirai-derived botnet
Mistic
MITRE ATT&CK T1005
MITRE ATT&CK T1562
mixed boolean arithmetic
MIXEDKEY
MLTBackdoor
mnemonic theft
mobile
Mobile Access
mobile banking fraud
mobile device management
mobile devices
mobile exploitation
mobile malware
- Flying Eagle and Night Dragon Android RAT ecosystem
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- RedWing
MobileIron Sentry
MODBEACON
Model Context Protocol
- Agent localhost control-plane RCE
- Amazon Q CVE-2026-12957 MCP auto-execution
- Azure DevOps MCP pull-request prompt injection
- FakeGit AgentBaiting and SmartLoader campaign
- Internet-exposed unauthenticated MCP servers
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- NadMesh AI-service and cloud-credential botnet
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
model poisoning
model weights
model-provider abuse
ModeloRAT
ModHeader
modular malware
module-proxy
MOIS
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Cavern
- Cavern Manticore
- Handala
- Iran-linked threat landscape: access optionality and evidence quality
- Seedworm / MuddyWater
Monero
Monero mining
MongoDB
Monster ransomware
Mozi
MpClient.dll
MpExtMs.exe
MPR network provider
Mr_Rot13
MSBuild
msgpack
mshta
- ACR Stealer
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- UAT-11795 Starland / WLDR campaign
MSI
MSP
- ConnectWise ScreenConnect exploitation wave
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
MSSQL
mTLS
Muck and Load
MuddyWater
- Cavern Manticore
- Iran-linked threat landscape: access optionality and evidence quality
- Langflow CVE-2025-34291 exploitation
- Seedworm / MuddyWater
Mullvad VPN
Multi-Domain Security Management
multi-tenant cloud
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Januscape KVM CVE-2026-53359 guest-to-host escape
multi-tenant isolation
Multiply-With-Carry
Mustang Panda
- FDMTP
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- QuickFox FDMTP software supply-chain compromise
Mustard Tempest
mutable tags
mutation attacks
mutex
MYRA
MySQL
Mysterious Elephant
Mythos
N-able
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
N-central
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
n8n
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- NadMesh AI-service and cloud-credential botnet
Nacos
NadMesh
named pipes
namespace recycling
namespace squatting
NanChat
NAS targeting
nation-state
national identity records
native addon
native extension
NativeAOT
NATO
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Russian state IP-camera military-logistics espionage
NATS
NCSC-NL
Nebo
Nebula Security
Negotiate
negotiation
Neo-reGeorg
neocloud
nested virtualization
Neteller
Netherlands
- Dutch Police / NCSC 17-million-device botnet disruption
- Russian state IP-camera military-logistics espionage
Netlify abuse
NetNut
NetScaler
NetScaler ADC
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Citrix NetScaler CVE-2026-8451 memory overread
NetScaler Gateway
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Citrix NetScaler CVE-2026-8451 memory overread
NetSetup.log
network detection
network infrastructure
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
network infrastructure exploitation
network isolation bypass
network policies
network-share exfiltration
Nextcloud
Nextcloud Flow
nf_tables
nftables
NGINX
Nginx
Nginx module
ngrok
Ngrok C2
Nigeria-nexus
Night Dragon
NightLedger
Nimbus Manticore
NirSoft
no attribution
No-IP
node-gyp
node-ipc
node-pty
Node.js
- Fake Corepack site infostealer and proxyware campaign
- Joyfill npm blockchain-RAT compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- Seedworm / MuddyWater
- TaskWeaver
Node.js implant
Node.js malware
North Korea
- Contagious Interview SVG-steganography OtterCookie campaign
- Famous Chollima Packagist dev-branch loader
- Kimsuky / Emerald Sleet / TA427
- Lazarus-linked Rollup polyfill npm malware
- macOS.Gaslight Rust backdoor
- NullReceiver DPRK-linked npm blockchain-loader wave
- Operation DangerousPassword axios npm compromise
- PolinRider cross-ecosystem supply-chain campaign
- RemotePE
- ScarCruft Yanbian game-platform supply-chain attack
- StegaBin Pastebin-steganography npm campaign
- UNK_DeadDrop developer repository phishing
- Void Dokkaebi
notarized malware
- CrashStealer macOS notarized-dropper campaign
- Operation FlutterBridge FlutterShell macOS malvertising
notification interception
npm
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- Alibaba developer-targeted distributed npm RAT campaign
- art-template Coruna-style iOS watering-hole compromise
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- codexui-android OpenAI token stealer
- Dependabot cross-ecosystem malware advisory alerts
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Flooding Dropper npm campaign
- forge-jsxy
- GitHub / Packagist postinstall hook campaign
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Immobiliare Labs Backstage plugins npm compromise
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- jscrambler npm preinstall stealer
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Lucide Proxy npm browser DDoS botnet
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MYRA RAT
- node-ipc 2026 npm maintainer-account compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- NullReceiver DPRK-linked npm blockchain-loader wave
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- SANDWORM_MODE AI-toolchain npm worm
- Sentry MCP Agentjacking
- Solana FakeFix npm / PyPI developer stealer
- StegaBin Pastebin-steganography npm campaign
- TeamPCP
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- ViteVenom / ChainVeil npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
- wshu.net npm credential-stealer campaign
npm lifecycle hook
- Mastra
easy-day-jsnpm scope compromise - Operation DangerousPassword axios npm compromise
- procwire / routecraft npm Windows dropper
npm supply-chain
npm token theft
npm tokens
npm v12
npx
NSecKrnl.sys
NTDS.dit
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Storm-2603 parallel SharePoint ransomware intrusion
NTFS ADS
NTLM
nuclear weapons
NuGet
- Braintree.Net NuGet payment skimmer
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Sicoob.Sdk NuGet banking certificate stealer
Nuitka
null-byte padding
NullReceiver
NVGRE
NVIDIA impersonation
O-UNC-066
OAuth
- Azure CLI LSHIY password-spray campaign
- Browser-based developer IDE OAuth token theft
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
OAuth 2.1
OAuth abuse
OAuth client credentials
OAuth device authorization grant
OAuth redirect
OAuth token abuse
OAuth token exposure
OAuth token theft
OAuth tokens
- codexui-android OpenAI token stealer
- GitHub API enumeration and access-token abuse
- Klue Salesforce OAuth token abuse
OBF networks
obfuscation
obfuscator.io
Oblivion
obsolete software
OctLurk
Octopi365
OFAC
official store compromise
Offshore LC
OIDC
- AsyncAPI generator / specs Miasma compromise
- ChainDrop keyv / cacheable npm worm
- Claude Code GitHub Action prompt-injection boundary
- codfish semantic-release-action tag compromise
- GitHub Actions OIDC subject-claim collisions
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
OilRig
Oj
OkoBot
Okta
- 0ktapus phishing campaign
- JINX-0163 / FulcrumSec
- Kali365 device-code phishing expansion
- Okta support-system compromise
- UNC6671 / BlackFile multi-brand vishing extortion operation
Okta Threat Intelligence
OKX
Ollama
Oman
Omnibox
OmniStealer
OneDrive
- Stock exchange executive mailbox espionage
- UNC6671 / BlackFile multi-brand vishing extortion operation
- Webworm
OneDrive access
onion routing
opaque predicates
open directory
Open Interpreter
Open VSX
Open WebUI
OpenAI
OpenAI Codex
OpenClaw
opencode
OpenConnect
OpenHands
OpenSearch
OpenShield
OpenSSF
OpenSSH
OpenVPN
OpenVPN-shaped UDP
OpenVSX
OpenWrt
operation
- ChocoPoC fake PoC supply-chain campaign
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- ToddyCat Umbrij Gmail OAuth operation
Operation BlueDash
Operation DangerousPassword
Operation Endgame
Operation Highland
operational relay box
Operational Relay Box
operational resilience
operational security
operational technology
operations
- 0ktapus phishing campaign
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Accellion FTA exploitation campaign
- actions-cool GitHub Actions tag compromise
- Adblock for YouTube BadBlocker remote-script injection risk
- Adobe ColdFusion APSB26-68 CVE bonanza
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI token-jacking transfer-station abuse
- Alibaba developer-targeted distributed npm RAT campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- Anthropic cyber-evaluation real-world intrusions
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Argo CD repo-server unauthenticated RCE
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Armored Likho BusySnake campaign
- art-template Coruna-style iOS watering-hole compromise
- AryStinger legacy-router recon proxy network
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Avalon / CrownX malware framework
- Azure CLI LSHIY password-spray campaign
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Barracuda ESG zero-day backdoor campaign
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Brazilian education LockBit, DragonForce, and insider incidents
- BufferZoneCorp RubyGems / Go module CI poisoning
- C0XMO Gafgyt DD-WRT botnet
- CanisterWorm
- CCleaner signed-update compromise
- ChainDrop keyv / cacheable npm worm
- Check Point VPN CVE-2026-50751 exploitation
- Chinese-language PhaaS wallet-tokenization ecosystem
- Chrome live-wallpaper extension ad-fraud network
- Chrome V8 CVE-2026-11645 exploitation
- CircleCI 2023 customer secret exposure incident
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- CitrixBleed session-hijack wave
- CL-STA-1062 Southeast Asia government and energy intrusions
- ClickFix CPaaS API-driven payload delivery
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- COLDCARD predictable-RNG Bitcoin theft risk
- ConnectWise ScreenConnect exploitation wave
- Contagious Interview SVG-steganography OtterCookie campaign
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Crypto Clipper Tor / USB worm
- DAEMON Tools Lite supply-chain compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- DCloud Uni-App scam infrastructure ecosystem
- Drupal Core CVE-2026-9082 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- ENDLESSDOORS implant in Zbtlink router firmware
- Everest Forms Pro CVE-2026-3300 exploitation
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Fastjson CVE-2026-16723 active exploitation
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Flooding Dropper npm campaign
- Flying Eagle and Night Dragon Android RAT ecosystem
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GHOST STADIUM FIFA World Cup ticket phishing
- Gitea Docker CVE-2026-20896 probing
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitLab Oj notebook-diff authenticated RCE chain
- Glassworm developer supply-chain botnet
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Gravity SMTP CVE-2026-4020 exploitation
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- HelloNet ViPNet update-system campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hugging Face autonomous-agent production intrusion
- Hunt.io global smishing infrastructure campaign
- Ill Bloom CryptoJS wallet-drain campaign
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JADEPUFFER Langflow agentic ransomware
- Januscape KVM CVE-2026-53359 guest-to-host escape
- JDY SOHO / IoT reconnaissance botnet
- JetBrains AI plugin API-key theft
- JetBrains TeamCity CVE-2026-63077 active exploitation
- JINX-0164 crypto developer infrastructure campaign
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- Kairos data-extortion government payment
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- LiteLLM compromise
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Lucide Proxy npm browser DDoS botnet
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mini Shai-Hulud npm/PyPI worm campaign
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- node-ipc 2026 npm maintainer-account compromise
- NullReceiver DPRK-linked npm blockchain-loader wave
- Nx Console VS Code extension compromise
- OctLurk and SilkLurk Central Asia espionage campaign
- Okta support-system compromise
- Ollama P2P cryptominer RAT campaign
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation BlueDash multi-RMM workplace phishing
- Operation DangerousPassword axios npm compromise
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation Endgame SocGholish disruption
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation Muck and Load GitHub lure network
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Outsider Enterprise smishing PhaaS
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Patriot Bait AI-assisted C2 botnet
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Perplexity AI-spoofing Chromium extension search hijacker
- Photo ZIP hospitality Node.js implant campaign
- Pirated media SilentCryptoMiner RAT campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- PraisonAI CVE-2026-44338 rapid exploitation
- procwire / routecraft npm Windows dropper
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- QuickFox FDMTP software supply-chain compromise
- REF6045 / SCMBANKER Mexican banking fraud
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- ScreenConnect freeware / AsyncRAT SEO campaign
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- Siemens ROX II zero-day exploit chain
- Silent Swap Google Notes crypto clipper
- simonecorsi/mawesome GitHub Action compromise
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SleeperGem RubyGems maintainer-account compromise
- SolarWinds Serv-U CVE-2026-28318 exploitation
- SourTrade browser-assembled malware malvertising
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Storm-2603 parallel SharePoint ransomware intrusion
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TamperedChef-style productivity malware clusters
- TeamPCP
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Telnyx PyPI TeamPCP compromise
- Thailand healthcare RAR / Python stealer campaign
- tj-actions and reviewdog compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trend Micro Apex One CVE-2026-34926 exploitation
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Turla STOCKSTAY backdoor operations
- TuxBot v3 Evolution IoT botnet framework
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795 Starland / WLDR campaign
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UNC6671 / BlackFile multi-brand vishing extortion operation
- UNK_DeadDrop developer repository phishing
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- VerdantBamboo appliance BRICKSTORM operation
- ViteVenom / ChainVeil npm campaign
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- Water-sector PLC configuration-tampering campaign
- WhatsApp VBScript ManageEngine RMM campaign
- Windmill CVE-2026-29059 active exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- wshu.net npm credential-stealer campaign
- XCSSET v40 Xcode supply-chain campaign
- Xinference PyPI compromise
- XZ Utils backdoor
operator lockout
OpFauxSign
opportunistic exploitation
ops
- 0ktapus phishing campaign
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Accellion FTA exploitation campaign
- actions-cool GitHub Actions tag compromise
- Adblock for YouTube BadBlocker remote-script injection risk
- Adform Trackpoint JavaScript supply-chain crypto clipper
- Adobe ColdFusion APSB26-68 CVE bonanza
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI token-jacking transfer-station abuse
- Alibaba developer-targeted distributed npm RAT campaign
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- Anthropic cyber-evaluation real-world intrusions
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Argo CD repo-server unauthenticated RCE
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Armored Likho BusySnake campaign
- art-template Coruna-style iOS watering-hole compromise
- AryStinger legacy-router recon proxy network
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- Avalon / CrownX malware framework
- Azure CLI LSHIY password-spray campaign
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Barracuda ESG zero-day backdoor campaign
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Braintree.Net NuGet payment skimmer
- Brazilian education LockBit, DragonForce, and insider incidents
- BufferZoneCorp RubyGems / Go module CI poisoning
- C0XMO Gafgyt DD-WRT botnet
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- CCleaner signed-update compromise
- ChainDrop keyv / cacheable npm worm
- Check Point VPN CVE-2026-50751 exploitation
- Chinese-language PhaaS wallet-tokenization ecosystem
- ChocoPoC fake PoC supply-chain campaign
- Chrome live-wallpaper extension ad-fraud network
- Chrome V8 CVE-2026-11645 exploitation
- CircleCI 2023 customer secret exposure incident
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- CitrixBleed session-hijack wave
- CL-STA-1062 Southeast Asia government and energy intrusions
- CL-STA-1114 Zimbra webmail espionage
- ClickFix CPaaS API-driven payload delivery
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- COLDCARD predictable-RNG Bitcoin theft risk
- ConnectWise ScreenConnect exploitation wave
- Contagious Interview SVG-steganography OtterCookie campaign
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- CrashStealer macOS notarized-dropper campaign
- Crypto Clipper Tor / USB worm
- DAEMON Tools Lite supply-chain compromise
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- DCloud Uni-App scam infrastructure ecosystem
- Drupal Core CVE-2026-9082 exploitation
- Dutch Police / NCSC 17-million-device botnet disruption
- Dysphoria IoT botnet
- ENDLESSDOORS implant in Zbtlink router firmware
- Everest Forms Pro CVE-2026-3300 exploitation
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Fastjson CVE-2026-16723 active exploitation
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Flooding Dropper npm campaign
- Flying Eagle and Night Dragon Android RAT ecosystem
- Forg365 Microsoft 365 PhaaS
- FortiBleed Fortinet credential exposure
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Funnull RingH23 and MacCMS supply-chain attacks
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- GHOST STADIUM FIFA World Cup ticket phishing
- Gitea Docker CVE-2026-20896 probing
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitLab Oj notebook-diff authenticated RCE chain
- Glassworm developer supply-chain botnet
- GodDamn ransomware PoisonX BYOVD activity
- GoSerpent Southeast Asia espionage campaign
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Gravity SMTP CVE-2026-4020 exploitation
- Gunra ransomware-as-a-service activity
- HackerBot Claw GitHub Actions exploitation campaign
- HelloNet ViPNet update-system campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Hugging Face autonomous-agent production intrusion
- Hunt.io global smishing infrastructure campaign
- Ill Bloom CryptoJS wallet-drain campaign
- Immobiliare Labs Backstage plugins npm compromise
- Injective SDK npm wallet stealer
- IronWorm npm Rust infostealer campaign
- Ivanti Sentry CVE-2026-10520 exploitation
- JADEPUFFER Langflow agentic ransomware
- Januscape KVM CVE-2026-53359 guest-to-host escape
- JDY SOHO / IoT reconnaissance botnet
- JetBrains AI plugin API-key theft
- JetBrains TeamCity CVE-2026-63077 active exploitation
- JINX-0164 crypto developer infrastructure campaign
- Joomla extension KEV exploitation cluster
- Joomla JCE CVE-2026-48907 exploitation
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- jscrambler npm preinstall stealer
- Kairos data-extortion government payment
- Kali365 device-code phishing expansion
- Klue Salesforce OAuth token abuse
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- KNX Protocol CVE-2023-4346 KEV exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Langflow CVE-2025-34291 exploitation
- Langflow CVE-2026-0770 exploitation
- Langflow CVE-2026-33017 cryptominer SSH worm
- Langflow CVE-2026-55255 flow authorization bypass
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- LiteLLM compromise
- LiteLLM CVE-2026-42271 MCP stdio command injection
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Lucide Proxy npm browser DDoS botnet
- macOS ClickFix fingerprinting-gate campaign
- macOS.Gaslight Rust backdoor
- Malware-Slop Claude user-data npm infostealer
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Mastra
easy-day-jsnpm scope compromise - Megalodon GitHub Actions workflow backdooring
- Metabase unauthenticated SQL-injection zero-day
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Microsoft Q2 2026 email and Teams phishing landscape
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Mini Shai-Hulud npm/PyPI worm campaign
- MiniPlasma Windows Cloud Filter LPE exploitation
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- ModHeader browser-extension surveillance capability
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- MrMustard PyPI credential-stealer compromise
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- NadMesh AI-service and cloud-credential botnet
- NATS-as-C2 KeyHunter credential-harvesting operation
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- node-ipc 2026 npm maintainer-account compromise
- nodemon-sudo / tslint-conf runtime npm backdoor
- NuGet game-cheat DotnetTool pepesoft campaign
- NullReceiver DPRK-linked npm blockchain-loader wave
- Nx Console VS Code extension compromise
- O-UNC-066 Entra passkey vishing
- OctLurk and SilkLurk Central Asia espionage campaign
- OkoBot cryptocurrency-wallet malware framework
- Okta support-system compromise
- Ollama P2P cryptominer RAT campaign
- Oman government Iranian-nexus webshell C2
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation BlueDash multi-RMM workplace phishing
- Operation DangerousPassword axios npm compromise
- Operation Dragon Weave Azure Blob C2 campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation Endgame SocGholish disruption
- Operation FlutterBridge FlutterShell macOS malvertising
- Operation GriefLure Southeast Asia LNK dropper
- Operation Highland Velvet Ant authentication-stack backdoors
- Operation Muck and Load GitHub lure network
- Operation Phnom Penh MODBEACON activity
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Oracle E-Business Suite CVE-2026-46817 exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Outsider Enterprise smishing PhaaS
- Pakistani law enforcement espionage convergence
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- Patriot Bait AI-assisted C2 botnet
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Perplexity AI-spoofing Chromium extension search hijacker
- Photo ZIP hospitality Node.js implant campaign
- Pirated media SilentCryptoMiner RAT campaign
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- PraisonAI CVE-2026-44338 rapid exploitation
- procwire / routecraft npm Windows dropper
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
- QuickFox FDMTP software supply-chain compromise
- RedWing mobile MaaS Android bank-fraud operation
- REF6045 / SCMBANKER Mexican banking fraud
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- ScreenConnect freeware / AsyncRAT SEO campaign
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- SHADOW-AETHER AI-augmented Latin America intrusions
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- Siemens ROX II zero-day exploit chain
- Silent Swap Google Notes crypto clipper
- simonecorsi/mawesome GitHub Action compromise
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- SleeperGem RubyGems maintainer-account compromise
- Solana FakeFix npm / PyPI developer stealer
- SolarWinds Serv-U CVE-2026-28318 exploitation
- SourTrade browser-assembled malware malvertising
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- StealC / Amadey infrastructure disruption
- StegaBin Pastebin-steganography npm campaign
- StegoAd Edge extension steganography campaign
- Stock exchange executive mailbox espionage
- Storm-2603 parallel SharePoint ransomware intrusion
- StrikeShark SharkLoader / Cobalt Strike campaign
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- TA488 OWAReaper and CVE-2026-42897 exploitation
- TamperedChef-style productivity malware clusters
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Telnyx PyPI TeamPCP compromise
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- Thailand healthcare RAR / Python stealer campaign
- tj-actions and reviewdog compromise
- ToddyCat Umbrij Gmail OAuth operation
- Toy Ghouls GenieLocker ransomware activity
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trend Micro Apex One CVE-2026-34926 exploitation
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Turla STOCKSTAY backdoor operations
- TuxBot v3 Evolution IoT botnet framework
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAT-11795 Starland / WLDR campaign
- UAT-7810 LONGLEASH ORB network expansion
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- UNC6671 / BlackFile multi-brand vishing extortion operation
- UNC6692 SNOW malware social-engineering campaign
- UNK_DeadDrop developer repository phishing
- UNK_MassTraction Roundcube university mailserver campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- VerdantBamboo appliance BRICKSTORM operation
- Vidar / XMRig Factory-v3 malvertising campaign
- ViteVenom / ChainVeil npm campaign
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- Water-sector PLC configuration-tampering campaign
- WhatsApp VBScript ManageEngine RMM campaign
- Windmill CVE-2026-29059 active exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- WP-SHELLSTORM webshell access brokerage
- wshu.net npm credential-stealer campaign
- XCSSET v40 Xcode supply-chain campaign
- Xinference PyPI compromise
- XZ Utils backdoor
opsec failure
Oracle
Oracle E-Business Suite
Oracle Payments
Oracle PeopleSoft
Oracle WebLogic Server
ORANGETAIL
ORB network
OS command injection
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
OT
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Iran-linked threat landscape: access optionality and evidence quality
- KNX Protocol CVE-2023-4346 KEV exploitation
OT switches
OTA update
OTP interception
OtterCookie
out-of-bounds write
outbound C2
Outlook
Outlook Web Access
overlay attacks
OWA
OWAReaper
OX Security
OxideHarvest
OYSTERBLUES
OYSTERFRESH
OYSTERSHUCK
P2P
P2P C2
package hijacking
package masquerading
package registry
- Braintree.Net NuGet payment skimmer
- Flooding Dropper npm campaign
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- Mastra
easy-day-jsnpm scope compromise - Newtonsoftt.Json.Net NuGet betting-rigging trojan
- NuGet game-cheat DotnetTool pepesoft campaign
- Operation DangerousPassword axios npm compromise
- Telnyx PyPI TeamPCP compromise
package registry abuse
package registry credentials
package registry proxy
package republishing
package scanning
package takedown
package-cooldowns
package-manager-hardening
package-splitting
package-takeover
Packagist
- Famous Chollima Packagist dev-branch loader
- GitHub / Packagist postinstall hook campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- Laravel-Lang Composer tag-rewrite compromise
- PolinRider cross-ecosystem supply-chain campaign
PAExec
Page Builder CK
page cache
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
page poisoning
Pakistan
- FishMonger
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Pakistani law enforcement espionage convergence
- SprySOCKS
Pakistan-linked
Palo Alto Networks
PAM
PAM credential validation
PamStealer
PAN-OS
Pandora RC
parallel-intrusion
parameter-to-prompt
partial encryption
Pass-ta-key
passkeys
password manager theft
password spray
password spraying
- Azure CLI LSHIY password-spray campaign
- FortiBleed Fortinet credential exposure
- Patriot Bait AI-assisted C2 botnet
password-protected archive
passwordless authentication
Pastebin
PAT theft
patch management
path hijacking
path traversal
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- Windmill CVE-2026-29059 active exploitation
Patriot Bait
patterns
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI browser-extension confused deputy
- AI scanner anti-analysis
- AI-agent memory poisoning
- AI-augmented adversary operations
- AI-brand impersonation phishing and malvertising
- Atlassian Rovo prompt-to-data exfiltration
- Azure DevOps MCP pull-request prompt injection
- Browser-based developer IDE OAuth token theft
- Claude Code GitHub Action prompt-injection boundary
- ClickOnce COM hijacking abuse
- Cloud bucket namespace hijacking
- Cloud logging control-plane tampering
- Coding-agent-parented tunnels and persistence
- Crypto supply-chain path to transaction authority
- Cursor Windows workspace-path binary hijack
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Direct-to-IP malware communications
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- GitHub API enumeration and access-token abuse
- GuardFall AI-agent shell-guard bypass
- Internet-exposed unauthenticated MCP servers
- LangGraph checkpointer and namespace trust boundaries
- Malicious infrastructure provider concentration
- MCP stdio command-execution boundary
- MCP tool-description poisoning
- Microsoft Teams external-chat phishing
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- Phantom squatting: AI-hallucinated domains
- Sentry MCP Agentjacking
- Synced passkey theft after endpoint compromise
- Vertex AI staging-bucket squatting
- Webmail CSS trust-boundary attacks
payload loader
payload staging
payload-as-a-service
payment fraud
payment SDK
payment skimmer
payment workflow exposure
payment-card theft
payment-card-theft
PayPal
payroll lures
Paysafe
pe_to_shellcode
PebbleDash
pedit
pentesting
people
PeopleTools
PerfWatson2.exe
Perplexity AI
persistence
- @copilot-mcp/apex macOS infostealer campaign
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- ClickOnce COM hijacking abuse
- Flooding Dropper npm campaign
- forge-jsxy
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Mastra
easy-day-jsnpm scope compromise - MrMustard PyPI credential-stealer compromise
- MYRA RAT
- Nx Console VS Code extension compromise
- Ollama P2P cryptominer RAT campaign
- Operation Highland Velvet Ant authentication-stack backdoors
- OWAReaper
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- ROADtools
- Showboat
- SleeperGem RubyGems maintainer-account compromise
- Stock exchange executive mailbox espionage
- TamperedChef-style productivity malware clusters
- TeamPCP
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Velvet Ant
- Vidar / XMRig Factory-v3 malvertising campaign
- wshu.net npm credential-stealer campaign
persistent root access
persona operations
personal access tokens
pfSense
PhaaS
Phantom Gyp
- binding.gyp npm CI/CD worm
- Immobiliare Labs Backstage plugins npm compromise
- Leo Platform npm Miasma-style compromise
PhantomClick
PhantomMail
PhantomRelay
Philippines
phishing
- AI-brand impersonation phishing and malvertising
- Avalon / CrownX malware framework
- Chinese-language PhaaS wallet-tokenization ecosystem
- Cloud Atlas
- Dutch Police / NCSC 17-million-device botnet disruption
- Evilginx and device-code phishing open-directory cluster
- Exposed WebDAV malware delivery lab and CURP campaign
- Fake Corepack site infostealer and proxyware campaign
- Forg365 Microsoft 365 PhaaS
- GHOST STADIUM FIFA World Cup ticket phishing
- Ghostwriter
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- Hunt.io global smishing infrastructure campaign
- Kali365 device-code phishing expansion
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Microsoft Q2 2026 email and Teams phishing landscape
- O-UNC-066 Entra passkey vishing
- Operation BlueDash multi-RMM workplace phishing
- Outsider Enterprise smishing PhaaS
- Phantom squatting: AI-hallucinated domains
- Photo ZIP hospitality Node.js implant campaign
- RedWing mobile MaaS Android bank-fraud operation
- Russian intelligence commercial-messaging backup-key phishing
- TA4922
- UNK_DeadDrop developer repository phishing
phishing overlays
phishing-as-a-service
- Chinese-language PhaaS wallet-tokenization ecosystem
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Outsider Enterprise smishing PhaaS
Phorpiex
PHP
PHP code execution
PHP code injection
PHP object injection
PHP upload
PHP web shell
physical systems
physics
PicassoLoader
pickle
pig butchering
pig-butchering
PINK
Pink
Pipedream
pipelines
piracy
Piriform
Pix
Pixeldrain
PixelSmash
PKGBUILD
plaintext HTTP
Plandex
PLC
PLENET
plugin architecture
plugin framework
PlugX
- OctLurk and SilkLurk Central Asia espionage campaign
- Pakistani law enforcement espionage convergence
- SilkLurk
poisoned-branch
PoisonX
police digital services
PolinRider
- Astro config blockchain C2 PR injection
- Joyfill npm blockchain-RAT compromise
- PolinRider cross-ecosystem supply-chain campaign
Poly1305
polyfill
Polygon
Polygon blockchain dead drop
Polymarket
polymorphic loader
polymorphic payloads
Popa
portmap
PortSwigger Research
Portugal
post-authentication RCE
post-exploitation
- AI-augmented adversary operations
- FortiOS CVE-2025-68686 symlink-persistence bypass
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Showboat
- TaskWeaver
- WLDR agent
post-exploitation framework
postal-impersonation
PostCSS
PostgreSQL
- Drupal Core CVE-2026-9082 exploitation
- LangGraph checkpointer and namespace trust boundaries
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
postinstall
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - MYRA RAT
- oob.moika.tech dependency-confusion environment stealer
- Operation DangerousPassword axios npm compromise
- Polymarket npm wallet-drainer packages
- wshu.net npm credential-stealer campaign
PowerCloud
PowerShell
- ACR Stealer
- Armored Likho BusySnake campaign
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- ClickFix CPaaS API-driven payload delivery
- Cloud Atlas
- Fake Corepack site infostealer and proxyware campaign
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- GREYVIBE
- Oman government Iranian-nexus webshell C2
- Operation BlueDash multi-RMM workplace phishing
- Operation Muck and Load GitHub lure network
- Patriot Bait AI-assisted C2 botnet
- Photo ZIP hospitality Node.js implant campaign
- postcss-minify-selector-parser npm RAT
- Seedworm / MuddyWater
- StealC / Amadey infrastructure disruption
- TELEPUZ ClickFix / VIDAR campaign
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
- UAT-11795 Starland / WLDR campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- WLDR agent
PowerShell execution
PowerShell malware
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
PowerShower
PPtP
PRA
PraisonAI
PRC
PRC-aligned
PRC-nexus
pre-auth RCE
pre-authentication
- Citrix NetScaler CVE-2026-8451 memory overread
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
pre-authentication RCE
Prefetch
preinstall
- @withgoogle/stitch-sdk scope squat
- jscrambler npm preinstall stealer
- procwire / routecraft npm Windows dropper
presigned URLs
primary keys
Primitive Bear
PrincessClub
priority inheritance
privacy
privacy exposure
private key theft
private packages
private registry fallback
private-key theft
privilege escalation
- Android Framework CVE-2025-48595 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Drupal Core CVE-2026-9082 exploitation
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Siemens ROX II zero-day exploit chain
- UTA0533 SonicWall SMA1000 zero-day compromise
- WP Maps Pro CVE-2026-8732 exploitation
privileged proxy
Privileged Remote Access
PRNG
process discovery
process doppelgänging
process environment scraping
process hollowing
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Exposed WebDAV malware delivery lab and CURP campaign
- Pirated media SilentCryptoMiner RAT campaign
process injection
- HelloNet ViPNet update-system campaign
- OceanLotus
- OkoBot cryptocurrency-wallet malware framework
- Operation DragonReturn India tax-season DcRAT campaign
- Operation GriefLure Southeast Asia LNK dropper
- Starland RAT
process termination
product lifecycle management
professional services
profile.d
Program Compatibility Assistant
Progress Kemp LoadMaster
Progress Software
Project Proposal.exe
prompt injection
- Agent localhost control-plane RCE
- Agent skill marketplace poisoning
- AI scanner anti-analysis
- AI-agent memory poisoning
- Claude Code GitHub Action prompt-injection boundary
- GuardFall AI-agent shell-guard bypass
- macOS.Gaslight Rust backdoor
- MCP tool-description poisoning
prompt-injection
- AI-augmented adversary operations
- HackerBot Claw GitHub Actions exploitation campaign
- SANDWORM_MODE AI-toolchain npm worm
- TrapDoor crypto-stealer cross-ecosystem campaign
PromptArmor
PROMPTFLUX
PROMPTSPY
promptware
proof of deletion
Proofpoint
protestware
Protobuf
Proton Mail
provenance
proxy
- ArcBridge
- BridgeHead
- First VPN
- GoSerpent Southeast Asia espionage campaign
- HelloNet ViPNet update-system campaign
- LurkProxy
- PCPJack cloud SMTP relay network
- Showboat
- TamperedChef-style productivity malware clusters
- VPN Go browser-extension clipboard stealer
- Webworm
proxy network
ProxyChains
proxyjacking
proxyware
prt-scan
PSEMHUB
pseudorandom number generator
PsExec
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Brazilian education LockBit, DragonForce, and insider incidents
- GodDamn ransomware PoisonX BYOVD activity
- Toy Ghouls GenieLocker ransomware activity
PSIGW
psychological operations
PTC
PteroBox
PteroPaste
PteroPSDoor
PteroSetup
PteroVDoor
public exploit
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- MiniPlasma Windows Cloud Filter LPE exploitation
public file-transfer exfiltration
public proof of concept
public sector
Public Security Bureau impersonation
public service abuse
public-service C2
publish-time scanning
pull requests
PUP
PureLogs Stealer
PureRAT
pwn-request
PyArmor
PyInstaller
PyPI
- Anthropic cyber-evaluation real-world intrusions
- binding.gyp npm CI/CD worm
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Dependabot cross-ecosystem malware advisory alerts
- Glassworm developer supply-chain botnet
- LiteLLM compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Solana FakeFix npm / PyPI developer stealer
- Telnyx PyPI TeamPCP compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Xinference PyPI compromise
Python
- ACR Stealer
- Aeternum
- Brazilian education LockBit, DragonForce, and insider incidents
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- macOS.Gaslight Rust backdoor
- MrMustard PyPI credential-stealer compromise
- postcss-minify-selector-parser npm RAT
- Seedworm / MuddyWater
- Starland RAT
- Telnyx PyPI TeamPCP compromise
- UAT-11795 Starland / WLDR campaign
- Ulej / Flowerbed
- Xinference PyPI compromise
Python extension modules
Python malware
Python stealer
Qianxin Threat Intelligence Center
QiAnXin XLab
- AryStinger legacy-router recon proxy network
- Dysphoria IoT botnet
- NadMesh AI-service and cloud-credential botnet
- RustDuck
Qilin
- Backdoor.Mistic / KongTuke ModeloRAT activity
- Check Point VPN CVE-2026-50751 exploitation
- The Gentlemen ransomware
QNAP
QR code
QR code interception
quantum computing
Quasar
query injection
Quest KACE SMA
QuickFox
QuimaRAT
RaaS
RabbitMQ
race condition
RainbowEx
RakNet flood
RAM disk
random number generator
Ransom-ISAC
ransomware
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Avalon / CrownX malware framework
- Brazilian education LockBit, DragonForce, and insider incidents
- Check Point VPN CVE-2026-50751 exploitation
- CrownX
- DeadLock ransomware
- Direct-to-IP malware communications
- ENCFORGE
- First VPN
- Fox Tempest
- GenieLocker
- GodDamn ransomware PoisonX BYOVD activity
- Gunra ransomware-as-a-service activity
- Kairos data-extortion government payment
- Storm-2603 parallel SharePoint ransomware intrusion
- The Gentlemen ransomware
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
ransomware access
ransomware enablement
ransomware-access
rapid exploitation
Rapid7
RAR archives
RAR staging
RAT
- Armored Likho
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- Contagious Interview SVG-steganography OtterCookie campaign
- DAEMON Tools Lite supply-chain compromise
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- FDMTP
- forge-jsxy
- Glassworm developer supply-chain botnet
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- GREYVIBE
- JINX-0164 crypto developer infrastructure campaign
- LabubaRAT
- Mastra
easy-day-jsnpm scope compromise - MYRA RAT
- Ollama P2P cryptominer RAT campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- QuimaRAT
- RemotePE
- Screening Serpens
- SprySOCKS
- Starland RAT
- StegaBin Pastebin-steganography npm campaign
- STOCKSTAY
- TamperedChef-style productivity malware clusters
- TinyRCT
- UAT-11795 Starland / WLDR campaign
Ray
RC4
- @marketfront / @tqm-mfe dependency-confusion stealer
- OP-512
- StealC / Amadey infrastructure disruption
- UAC-0226 / SHADOW-EARTH-066
RC4 C2
RCE
- Agent localhost control-plane RCE
- LangGraph checkpointer and namespace trust boundaries
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Vertex AI staging-bucket squatting
Rclone
rclone
RCS
RDP
- Brazilian education LockBit, DragonForce, and insider incidents
- GREYVIBE
- Toy Ghouls GenieLocker ransomware activity
RDP phishing
RDS
Reality
Reaper
reconnaissance
- AryStinger legacy-router recon proxy network
- JDY SOHO / IoT reconnaissance botnet
- Open VSX evil-twin extension campaign
recovery denial
- Ababil of Minab MOIS-linked recovery-destruction campaign
- DeadLock ransomware
- GodDamn ransomware PoisonX BYOVD activity
recovery disruption
recovery flow
recovery phrase
recruitment lures
Red Dev 10
Red Hat
Red Raindrop Team
REDACT
RedAlert
REDCap
Redis
- Argo CD repo-server unauthenticated RCE
- GigaWiper
- LangGraph checkpointer and namespace trust boundaries
- NadMesh AI-service and cloud-credential botnet
- TeamPCP
Redis backdoor
RediSearch
reduced cyber refusals
RedWing
REF6045
REF9403
reflective .NET loading
reflective loading
- BINDCLOAK
- Flooding Dropper npm campaign
- MIXEDKEY
- OctLurk
- OctLurk and SilkLurk Central Asia espionage campaign
- SilkLurk
- TELESHIM Middle East government espionage campaign
refresh token theft
refresh tokens
RegAsm process hollowing
registry controls
registry persistence
- Flooding Dropper npm campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Photo ZIP hospitality Node.js implant campaign
- SideCopy
- The Gentlemen ransomware
- Turla STOCKSTAY backdoor operations
registry storage
registry-controls
release automation
release tampering
Remcos
Remcos RAT
remote access
- Citrix NetScaler CVE-2026-8451 memory overread
- ConnectWise ScreenConnect exploitation wave
- FortiBleed Fortinet credential exposure
- Lazarus-linked Rollup polyfill npm malware
- Pirated media SilentCryptoMiner RAT campaign
- WhatsApp VBScript ManageEngine RMM campaign
remote access software
remote access trojan
- Alibaba developer-targeted distributed npm RAT campaign
- GoSerpent Southeast Asia espionage campaign
- Joyfill npm blockchain-RAT compromise
- LabubaRAT
- ViteVenom / ChainVeil npm campaign
Remote Access VPN
remote code execution
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Crypto Clipper Tor / USB worm
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- Hugging Face autonomous-agent production intrusion
- Ivanti Sentry CVE-2026-10520 exploitation
- Joomla JCE CVE-2026-48907 exploitation
- Langflow CVE-2026-0770 exploitation
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- nodemon-sudo / tslint-conf runtime npm backdoor
- Progress ShareFile Storage Zone Controller security threat
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- ServiceNow AI Platform CVE-2026-6875 exploitation
- StegoAd Edge extension steganography campaign
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
remote debugging
remote MCP
remote monitoring and management
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- ScreenConnect freeware / AsyncRAT SEO campaign
remote script injection
Remote Support
remote support
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
Remote Utilities
remote-access
Remotely
RemotePE
RemotePELoader
removable media
Rentry
replication
repo-server
repository compromise
repository exfiltration
repository poisoning
- Amazon Q CVE-2026-12957 MCP auto-execution
- Claude Code GitHub Action prompt-injection boundary
- FakeGit AgentBaiting and SmartLoader campaign
research sector
residential proxies
residential proxy
residential proxy abuse
responsible disclosure
REST API
REST C2
restart-triggered execution
retail
retail trading
reverse proxy
reverse SSH tunneling
reverse tunneling
reverse tunnels
REVERSE_PROXY_TRUSTED_PROXIES
ReverseSocks
reviewdog
Rilide
RingH23
RMM
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- UNC3753
RMM abuse
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Cavern
- Cavern Manticore
- Evilginx and device-code phishing open-directory cluster
- Iran-linked threat landscape: access optionality and evidence quality
- Operation BlueDash multi-RMM workplace phishing
- ScreenConnect freeware / AsyncRAT SEO campaign
- TaskWeaver
- WhatsApp VBScript ManageEngine RMM campaign
ROADrecon
ROADtools
roadtx
Rockwell Automation
Rokarolla
RokRAT
Rollup
RomulusLoader
Roo-Code
root
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
root access
root escalation
root execution
root shell
rootkit
- Atomic Arch AUR package hijack
- Funnull RingH23 and MacCMS supply-chain attacks
- IronWorm npm Rust infostealer campaign
- MYRA RAT
ROOTRUN
Rootstock
ROPC
Rouki obfuscation
Roundcube
router
router compromise
- Dysphoria IoT botnet
- ENDLESSDOORS implant in Zbtlink router firmware
- UAT-7810 LONGLEASH ORB network expansion
router malware
Rovo
ROX II
RRWallet
RSA
RSA-2048
RSA-OAEP
RT-Thread
RTL819X
RTLO
rtmutex
RubyGems
- binding.gyp npm CI/CD worm
- BufferZoneCorp RubyGems / Go module CI poisoning
- SleeperGem RubyGems maintainer-account compromise
Ruckus routers
Ruflo
RUGGEDCOM
Run key
Run key persistence
rundll32
Runner.Worker
Runspace
runtime execution
runtime mutation
runtime patching
runZero
Russia
- APT29
- Armored Likho
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Cloud Atlas
- Dragonfly
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- HelloNet ViPNet update-system campaign
- Russian state IP-camera military-logistics espionage
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
Russia targeting
Russia-affiliated
Russia-linked
Russia-linked cybercrime
Russia-nexus
Russia-speaking operator
Russian Intelligence Services
Russian intelligence services
Russian state-supported
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
Russian-speaking ecosystem
Russian-speaking forums
Rust
- Atomic Arch AUR package hijack
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
- macOS.Gaslight Rust backdoor
- Operation Dragon Weave Azure Blob C2 campaign
- RustDuck
- TrapDoor crypto-stealer cross-ecosystem campaign
- wshu.net npm credential-stealer campaign
Rust malware
- DeadLock ransomware
- Fake-reputation crypto clipboard hijacker
- HelloNet ViPNet update-system campaign
- LabubaRAT
- MODBEACON
- PamStealer
S3 Browser
S3-compatible storage
- Cloud bucket namespace hijacking
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
s5cmd
SaaS
- Klue Salesforce OAuth token abuse
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
- ShinyHunters
- UNC6671 / BlackFile multi-brand vishing extortion operation
SaaS abuse
SaaS connectors
SaaS data access
SaaS exposure
sabotage
Safari
SafeDep
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- MYRA RAT
- nodemon-sudo / tslint-conf runtime npm backdoor
Salesforce
- Klue Salesforce OAuth token abuse
- ShinyHunters
- UNC6671 / BlackFile multi-brand vishing extortion operation
SAML IdP
Samsung TizenRT
sandbox escape
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- Hugging Face autonomous-agent production intrusion
- ServiceNow AI Platform CVE-2026-6875 exploitation
sandbox evasion
sandboxing
Sandworm
saroula01
scam infrastructure
scambling
scanner evasion
ScarCruft
scheduled task
- Crypto Clipper Tor / USB worm
- StealC / Amadey infrastructure disruption
- TELESHIM
- TELESHIM Middle East government espionage campaign
- TinyRCT
- Vidar / XMRig Factory-v3 malvertising campaign
scheduled task persistence
- Armored Likho BusySnake campaign
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- BusySnake Stealer
- Flooding Dropper npm campaign
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- ScreenConnect freeware / AsyncRAT SEO campaign
scheduled tasks
- ACR Stealer
- GigaWiper
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Stock exchange executive mailbox espionage
- StrikeShark SharkLoader / Cobalt Strike campaign
- The Gentlemen ransomware
SCMBANKER
scope squatting
scoped package impersonation
SCOUTCURL
screen capture
ScreenConnect
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- ConnectWise ScreenConnect exploitation wave
- Operation BlueDash multi-RMM workplace phishing
- ScreenConnect freeware / AsyncRAT SEO campaign
Screening Serpens
screenshot capture
screenshot theft
script-injection
SD-WAN
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
search hijacking
search poisoning
search result poisoning
search-ms
Seashell Blizzard
Secret Blizzard
secret exposure
secrets
- Azure DevOps MCP pull-request prompt injection
- binding.gyp npm CI/CD worm
- CircleCI 2023 customer secret exposure incident
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- GitHub Actions deployment poisoning
secrets management
SectopRAT
Secure Firewall Management Center
Secure Preferences
Security Management Server
security platform
security-tool discovery
seed phrase theft
seed recovery
SeedHunter
Seedworm
- Cavern Manticore
- Iran-linked threat landscape: access optionality and evidence quality
- Seedworm / MuddyWater
segmented networks
Sekoia
self-delete
self-hosted AI services
self-hosted media
self-hosted runner
self-propagation
semantic-release
sendit.sh
sensitive information exposure
Sentinel
SentinelOne
Sentry
Sentry abuse
SEO poisoning
- ACR Stealer
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- AI-brand impersonation phishing and malvertising
- Operation Phnom Penh MODBEACON activity
- ScreenConnect freeware / AsyncRAT SEO campaign
- StealC / Amadey infrastructure disruption
Seqrite Labs
Serv-U
service accounts
service impairment
service persistence
service providers
service stop
service-agent
ServiceNow
- ServiceNow AI Platform CVE-2026-6875 exploitation
- ServiceNow instance unauthenticated table-query exploitation
ServiceNow AI Platform
ServiceWorker
Session
session cookie theft
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Kratos Microsoft 365 PhaaS and infrastructure disruption
session hijacking
session secret exposure
session theft
session token theft
setuid
setup.py
shadow copy deletion
shadow MMU
SHADOW-AETHER-040
SHADOW-AETHER-064
SHADOW-EARTH-066
SHADOW-WATER-063
ShadowPad
Shai-Hulud
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- ChainDrop keyv / cacheable npm worm
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Mini Shai-Hulud npm/PyPI worm campaign
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- SANDWORM_MODE AI-toolchain npm worm
SHARDLOADER
share propagation
shared accounts
shared hosting
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
shared secrets
SharedWorker
ShareFile
SharePoint
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22, 2026 additions
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Storm-2603 parallel SharePoint ransomware intrusion
- UNC6671 / BlackFile multi-brand vishing extortion operation
SharePoint Server
SharkLoader
shell injection
Shenzhen Zhibotong Electronics
ShinyHunters
Shodan
ShortLeash
Shuckworm
SideCopy
sideloading
Siemens
Signal
- Russian intelligence commercial-messaging backup-key phishing
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
Signal interception
signed malware
signed updates
signed-binary
Silent Ransom Group
Silent Swap
SilentCryptoMiner
SilentRunLoader
SiliconFlow
SilkLurk
Silver Fox
Silver Pass-ta-key
SimpleHelp
- Djinn Stealer
- Evilginx and device-code phishing open-directory cluster
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- TaskWeaver
SimpleHTTPServer exposure
simulation tampering
Site Member permissions
skb
SkillCloak
SkillDetonate
Skrill
sleeper packages
Sliver
SLSA
SLSA provenance
SMA1000
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- UTA0533 SonicWall SMA1000 zero-day compromise
smart building
smart contracts
smart TVs
SMARTAXE
SmartConsole
SmartLoader
SmartScreen
SMB
SMB brute force
SMB egress
smishing
- 0ktapus phishing campaign
- Crypto supply-chain path to transaction authority
- Hunt.io global smishing infrastructure campaign
- Outsider Enterprise smishing PhaaS
Smoke Sandstorm
SMS interception
SMS theft
sms-phishing
SMTP
SMTP abuse
Snake
Sneaky 2FA
Snowflake
SNOWLIGHT
SOAP API abuse
SocGholish
social engineering
- AI-brand impersonation phishing and malvertising
- Chinese-language PhaaS wallet-tokenization ecosystem
- ClickFix CPaaS API-driven payload delivery
- Fake-reputation crypto clipboard hijacker
- FakeGit AgentBaiting and SmartLoader campaign
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- macOS ClickFix fingerprinting-gate campaign
- Microsoft Teams external-chat phishing
- Polymarket npm wallet-drainer packages
- Russian intelligence commercial-messaging backup-key phishing
- Screening Serpens
- UNC3753
- UNC6692 SNOW malware social-engineering campaign
- Void Dokkaebi
- WhatsApp VBScript ManageEngine RMM campaign
social-engineering
Socket
- jscrambler npm preinstall stealer
- Operation Muck and Load GitHub lure network
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- VPN Go browser-extension clipboard stealer
Socket Security
- Braintree.Net NuGet payment skimmer
- Injective SDK npm wallet stealer
- NuGet game-cheat DotnetTool pepesoft campaign
Socket Security Research
- Chrome live-wallpaper extension ad-fraud network
- Fake Corepack site infostealer and proxyware campaign
Socket.IO
- Contagious Interview SVG-steganography OtterCookie campaign
- Lazarus-linked Rollup polyfill npm malware
SOCKS tunneling
SOCKS5
- BridgeHead
- Cavern
- GoSerpent Southeast Asia espionage campaign
- LurkProxy
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- OctLurk and SilkLurk Central Asia espionage campaign
- Operation Highland Velvet Ant authentication-stack backdoors
- Seedworm / MuddyWater
- Showboat
SOCKS5 proxy
SOCKS5 tunneling
SOCRadar
SoftEther VPN
SoftPerfect Network Scanner
software impersonation
software supply chain
software-deployment
SOHO router
SOHO routers
Solana
- Glassworm developer supply-chain botnet
- Solana FakeFix npm / PyPI developer stealer
- SourTrade browser-assembled malware malvertising
Solana Name Service
SolarWinds
Solid PDF Creator
SolidPDFCreator.dll
SolidPDFPcl2Bmp
Sonatype
sonatype-2026-005660
sonatype-2026-005899
sonatype-2026-005901
SonicWall
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- UTA0533 SonicWall SMA1000 zero-day compromise
Sophos
source code
source control
- Gitea Docker CVE-2026-20896 probing
- GitHub API enumeration and access-token abuse
- GitLab Oj notebook-diff authenticated RCE chain
source repository compromise
source-code compromise
source-control token theft
source-package drift
source-package mismatch
source-repository abuse
source-repository poisoning
- Astro config blockchain C2 PR injection
- Cursor Windows workspace-path binary hijack
- Developer-tool config auto-execution
- Operation Muck and Load GitHub lure network
- PolinRider cross-ecosystem supply-chain campaign
- XCSSET v40 Xcode supply-chain campaign
source-repository reconnaissance
SourceForge abuse
SourTrade
South Africa
South Asia
South Korea
Southeast Asia
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- GoSerpent Southeast Asia espionage campaign
- OceanLotus
- Operation GriefLure Southeast Asia LNK dropper
- Showboat
SP Page Builder
spam
spear phishing
- Armored Likho
- Armored Likho BusySnake campaign
- Kimsuky / Emerald Sleet / TA427
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Operation DragonReturn India tax-season DcRAT campaign
- Operation XENOFISCAL SideCopy XenoRAT campaign
- SideCopy
- Thailand healthcare RAR / Python stealer campaign
- UAC-0226 / SHADOW-EARTH-066
spear-phishing
spearphishing
SPECTRALVIPER
Sphinx ransomware
SpiderLabs
Spikey Scorpius
Splunk
Spring Boot
SprySOCKS
spyware
SQL injection
- Anthropic cyber-evaluation real-world intrusions
- Drupal Core CVE-2026-9082 exploitation
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- LangGraph checkpointer and namespace trust boundaries
- Metabase unauthenticated SQL-injection zero-day
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
SQLite
SQLite state
SQLRCE0
SquareShell
SSDP
SSH
- C0XMO Gafgyt DD-WRT botnet
- SHADOW-AETHER AI-augmented Latin America intrusions
- Toy Ghouls GenieLocker ransomware activity
- XZ Utils backdoor
SSH backdoor
SSH bastion
SSH brute force
SSH key exposure
SSH key persistence
SSH keys
- @copilot-mcp/apex macOS infostealer campaign
- Djinn Stealer
- Fake Corepack site infostealer and proxyware campaign
- MrMustard PyPI credential-stealer compromise
SSH lateral movement
SSH persistence
SSH tunnel
SSH tunneling
SSH tunnels
SSL VPN
SSRF
- CISA KEV: Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
- Cisco Unified CM CVE-2026-20230 file-write exploitation
- GitHub Actions deployment poisoning
- Internet-exposed unauthenticated MCP servers
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
stack use-after-free
staged malicious update
staged publishing
stale access
stale credentials
Starland RAT
Startup folder
Startup folder persistence
state-linked
state-owned enterprise
static credentials
Static Kitten
stdio
- Agent localhost control-plane RCE
- LiteLLM CVE-2026-42271 MCP stdio command injection
- MCP stdio command-execution boundary
StealC
stealer
Steam profile dead drop
steganography
- ACR Stealer
- Contagious Interview SVG-steganography OtterCookie campaign
- StegoAd Edge extension steganography campaign
StegoAd
StepSecurity
STM32Cube
stock exchange
STOCKSTAY
storage deletion
Storage Zone Controller
stored XSS
Storm-2603
Storm-2697
Storm-2945
Storm-3075
Stowaway
STRD
streaming boxes
Stripe OLT
student targeting
STUN
Stuxnet lineage
subject claim
SuccessKey
SUMMIT
Suo5
Supabase
SUPERADMIN_SECRET
supply chain
- Braintree.Net NuGet payment skimmer
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- COLDCARD predictable-RNG Bitcoin theft risk
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- GitHub API enumeration and access-token abuse
- Injective SDK npm wallet stealer
- jscrambler npm preinstall stealer
- MYRA RAT
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- nodemon-sudo / tslint-conf runtime npm backdoor
- NuGet game-cheat DotnetTool pepesoft campaign
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Solana FakeFix npm / PyPI developer stealer
supply chain compromise
supply-chain
- 3CX desktop app compromise
- @copilot-mcp/apex macOS infostealer campaign
- @marketfront / @tqm-mfe dependency-confusion stealer
- @withgoogle/stitch-sdk scope squat
- actions-cool GitHub Actions tag compromise
- Agent skill marketplace poisoning
- AI scanner anti-analysis
- AI token-jacking transfer-station abuse
- AI-augmented adversary operations
- Alibaba developer-targeted distributed npm RAT campaign
- Anthropic cyber-evaluation real-world intrusions
- APT29
- art-template Coruna-style iOS watering-hole compromise
- Astro config blockchain C2 PR injection
- AsyncAPI generator / specs Miasma compromise
- Atomic Arch AUR package hijack
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Browser-based developer IDE OAuth token theft
- BufferZoneCorp RubyGems / Go module CI poisoning
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- Claude Code GitHub Action prompt-injection boundary
- Codecov Bash Uploader compromise
- codexui-android OpenAI token stealer
- codfish semantic-release-action tag compromise
- Crypto supply-chain path to transaction authority
- DAEMON Tools Lite supply-chain compromise
- Dependabot cross-ecosystem malware advisory alerts
- Developer-tool config auto-execution
- Famous Chollima Packagist dev-branch loader
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Flooding Dropper npm campaign
- forge-jsxy
- Funnull RingH23 and MacCMS supply-chain attacks
- GitHub / Packagist postinstall hook campaign
- GitHub Actions deployment poisoning
- GitHub Actions OIDC subject-claim collisions
- Glassworm developer supply-chain botnet
- HackerBot Claw
- HackerBot Claw GitHub Actions exploitation campaign
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- JetBrains AI plugin API-key theft
- JiaT75
- JINX-0164
- JINX-0164 crypto developer infrastructure campaign
- Joyfill npm blockchain-RAT compromise
- js-logger-pack Hugging Face exfiltration campaign
- Klue Salesforce OAuth token abuse
- Laravel-Lang Composer tag-rewrite compromise
- Lazarus-linked Rollup polyfill npm malware
- Leo Platform npm Miasma-style compromise
- LiteLLM compromise
- Malware-Slop Claude user-data npm infostealer
- Mastra
easy-day-jsnpm scope compromise - MCP stdio command-execution boundary
- MCP tool-description poisoning
- Megalodon GitHub Actions workflow backdooring
- Mini Shai-Hulud npm/PyPI worm campaign
- MrMustard PyPI credential-stealer compromise
- node-ipc 2026 npm maintainer-account compromise
- npm install explicit-trust controls
- npm publish-time malware scanning and dual-use declarations
- NullReceiver DPRK-linked npm blockchain-loader wave
- Nx Console VS Code extension compromise
- oob.moika.tech dependency-confusion environment stealer
- Open VSX evil-twin extension campaign
- Operation DangerousPassword axios npm compromise
- Operation Muck and Load GitHub lure network
- Phantom squatting: AI-hallucinated domains
- PolinRider cross-ecosystem supply-chain campaign
- Polymarket npm wallet-drainer packages
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- SANDWORM_MODE AI-toolchain npm worm
- ScarCruft Yanbian game-platform supply-chain attack
- shopsprint/decimal Go typosquat DNS backdoor
- Sicoob.Sdk NuGet banking certificate stealer
- simonecorsi/mawesome GitHub Action compromise
- SleeperGem RubyGems maintainer-account compromise
- StegaBin Pastebin-steganography npm campaign
- TeamPCP
- Telnyx PyPI TeamPCP compromise
- tj-actions and reviewdog compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- Trivy compromise
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- Vertex AI staging-bucket squatting
- Void Dokkaebi
- vpmdhaj OpenSearch npm cloud-secret stealer
- VPN Go browser-extension clipboard stealer
- wshu.net npm credential-stealer campaign
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
- Xinference PyPI compromise
- XZ Utils backdoor
supply-chain attack
supply-chain attribution
supply-chain integrity
supply-chain risk
supply-chain-adjacent
surveillance
suspected China-aligned
suspected China-linked
SVG
SWE-agent
SweetPotato
SWUpdate
Symantec Threat Hunter Team
symbolic link
symlink following
Synacktiv
Synology
synthetic commits
Syria
Sysdig
SYSTEM
SystemBC
systemd
systemd-userdbd
T1204.004
T3
TA427
TA488
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- OWAReaper
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
TA569
Tactical RMM
tag rewrite
tag tampering
- actions-cool GitHub Actions tag compromise
- codfish semantic-release-action tag compromise
- simonecorsi/mawesome GitHub Action compromise
- tj-actions and reviewdog compromise
TAG-124
TAG-179
TAG-182
TAG-22
Taiwan
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- FishMonger
- Mustang Panda
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Operation Dragon Weave Azure Blob C2 campaign
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
Tajikistan
Take Control
takedown
- Dutch Police / NCSC 17-million-device botnet disruption
- First VPN
- Glassworm developer supply-chain botnet
TamperedChef
Tanzania
targeted malware
targeted operations
TartarusGate
task queue
task scheduler abuse
TaskWeaver
tax-season phishing
tc
TCP traffic diversion
TDS
TeamCity
TeamPCP
- actions-cool GitHub Actions tag compromise
- AI-augmented adversary operations
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Dependabot cross-ecosystem malware advisory alerts
- Mini Shai-Hulud npm/PyPI worm campaign
- npm publish-time malware scanning and dual-use declarations
- Nx Console VS Code extension compromise
- Telnyx PyPI TeamPCP compromise
- Trivy compromise
- Xinference PyPI compromise
TeamPCP-adjacent
Teams access
TeamViewer
TEASOUP
Tebi
technician session
technology sector
telecom
telecom-impersonation
telecommunications
- Malicious infrastructure provider concentration
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- TA488 OWAReaper and CVE-2026-42897 exploitation
Telegra.ph
Telegram
- 0ktapus phishing campaign
- Aeternum
- Chinese-language PhaaS wallet-tokenization ecosystem
- Flying Eagle and Night Dragon Android RAT ecosystem
- Forg365 Microsoft 365 PhaaS
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- GREYVIBE
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- NuGet game-cheat DotnetTool pepesoft campaign
- Starland RAT
- UAC-0226 / SHADOW-EARTH-066
telegram
Telegram bot
Telegram C2
- macOS.Gaslight Rust backdoor
- Solana FakeFix npm / PyPI developer stealer
- TELESHIM
- TELESHIM Middle East government espionage campaign
- wshu.net npm credential-stealer campaign
Telegram dead drop
Telegram exfiltration
Telegram notification
telemetry
TELEPUZ
TELESHIM
Teletype
Telnet
Telnet brute force
Telnyx
Temp Zagros
template injection
tenant isolation
tenant-project
TencShell
Tenda
Tenet Security
Tetrade
TetrisPhantom
TeviRAT
Thailand
- FishMonger
- SprySOCKS
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- Thailand healthcare RAR / Python stealer campaign
The Gentlemen
The Hacker News
- Azure CLI LSHIY password-spray campaign
- CrashStealer macOS notarized-dropper campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- Gitea Docker CVE-2026-20896 probing
- ModHeader browser-extension surveillance capability
- O-UNC-066 Entra passkey vishing
- OkoBot cryptocurrency-wallet malware framework
- Progress ShareFile Storage Zone Controller security threat
- StegoAd Edge extension steganography campaign
- UAT-7810 LONGLEASH ORB network expansion
- WP-SHELLSTORM webshell access brokerage
The Quarry
ThemeREX Addons
third-party integrations
third-party JavaScript
third-party risk
threat hunting
threat landscape
ThrottleBlood
ThumbcacheService
thumbnail generation
TinyGo
TinyRCT
tj-actions
TLS certificates
TmcLoader
TmcPayload
ToddyCat
token forgery
- Hugging Face autonomous-agent production intrusion
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
token jacking
token replay
token theft
- ACR Stealer
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Evilginx and device-code phishing open-directory cluster
- Forg365 Microsoft 365 PhaaS
- MrMustard PyPI credential-stealer compromise
- Okta support-system compromise
- ROADtools
- Webmail CSS trust-boundary attacks
token-theft
TONESHELL
TookPS
tool
tool execution
tool output injection
tool poisoning
tool use
tooling
- CanisterWorm
- HackerBot Claw
- LiteLLM compromise
- TeamPCP
- Trivy → TeamPCP → CanisterWorm: compromise timeline
tools
- ACR Stealer
- Aeternum
- ArcBridge
- BINDCLOAK
- BridgeHead
- BusySnake Stealer
- Cavern
- CrownX
- DeadLock ransomware
- Djinn Stealer
- ENCFORGE
- Fast16
- FDMTP
- First VPN
- forge-jsxy
- GenieLocker
- GigaWiper
- HOLLOWGRAPH
- Kimwolf v7
- LabubaRAT
- LurkProxy
- MIXEDKEY
- MODBEACON
- MYRA RAT
- NightLedger
- OctLurk
- OWAReaper
- PamStealer
- QuimaRAT
- RedWing
- RemotePE
- ROADtools
- RustDuck
- SCMBANKER
- Showboat
- SilkLurk
- SprySOCKS
- Starland RAT
- STOCKSTAY
- TaskWeaver
- TELEPUZ
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Ulej / Flowerbed
- Umbrij
- WLDR agent
- XCSSET
Tor
Total Software Deployment
TouchSocket
Toy Ghouls
TPM
Trading Technologies
TradingView
traffic broker
traffic control
traffic hijacking
traffic manipulation
traffic-distribution-system
traffic-fraud
training data
transaction authority
transfer stations
transitive dependency
translation software
transnational repression
transparent proxy
Transparent Tribe
transport
transportation
Trend Micro
- Langflow CVE-2026-33017 cryptominer SSH worm
- SHADOW-AETHER AI-augmented Latin America intrusions
- Trend Micro Apex One CVE-2026-34926 exploitation
TrendAI
Trezor
TrickBot
Trident Ursa
trojanized installers
Tron
- Adform Trackpoint JavaScript supply-chain crypto clipper
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Ill Bloom CryptoJS wallet-drain campaign
- ViteVenom / ChainVeil npm campaign
trusted extension risk
trusted publishing
- AsyncAPI generator / specs Miasma compromise
- GitHub Actions OIDC subject-claim collisions
- npm publish-time malware scanning and dual-use declarations
trusted relationship abuse
tunnel decapsulation
tunnel services
tunneling
Turla
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- STOCKSTAY
- Turla
- Turla STOCKSTAY backdoor operations
Turla collaboration
TuxBot
TuxBot v3 Evolution
Twilio
Twilio SendGrid
Twill Typhoon
two-factor authentication
Tycoon2FA
TypeScript
typosquat
typosquatting
- @withgoogle/stitch-sdk scope squat
- Braintree.Net NuGet payment skimmer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- Funnull RingH23 and MacCMS supply-chain attacks
- Hunt.io global smishing infrastructure campaign
- Lazarus-linked Rollup polyfill npm malware
- Microsoft Teams external-chat phishing
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- nodemon-sudo / tslint-conf runtime npm backdoor
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- SANDWORM_MODE AI-toolchain npm worm
- ScreenConnect freeware / AsyncRAT SEO campaign
- shopsprint/decimal Go typosquat DNS backdoor
- StegaBin Pastebin-steganography npm campaign
- vpmdhaj OpenSearch npm cloud-secret stealer
UAC
UAC bypass
UAC-0002
UAC-0010
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
UAC-0098
UAC-0145
UAC-0194
UAC-0226
UAT-11795
UAT-5918
UAT-7237
UAT-7810
Ubiquiti
Ubuntu
Udev persistence
UDP C2
UDP/1900
UI redressing
Ukraine
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Ghostwriter
- GREYVIBE
- Russian intelligence commercial-messaging backup-key phishing
- Russian state IP-camera military-logistics espionage
- Showboat
- UAC-0145
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0226 / SHADOW-EARTH-066
Ukraine targeting
Ulej
UltraVNC
Umbrij
unattributed
unauthenticated access
- Internet-exposed unauthenticated MCP servers
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- ServiceNow instance unauthenticated table-query exploitation
unauthenticated admin access
unauthenticated HTTP exploitation
unauthenticated RCE
- Argo CD repo-server unauthenticated RCE
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- ENDLESSDOORS implant in Zbtlink router firmware
- Fastjson CVE-2026-16723 active exploitation
- JetBrains TeamCity CVE-2026-63077 active exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
UNC1543
UNC1549
- ArcBridge
- BridgeHead
- Mirage Kitten
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- NightLedger
UNC2814
UNC3753
UNC4221
UNC4736
UNC5792
UNC6240
UNC6508
UNC6671
UNC6692
UNC6780
Uni-App
UniFi OS
Unified CM SME
uninitialized heap memory
unintended internet access
Unit 42
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- FortiBleed Fortinet credential exposure
- Operation FlutterBridge FlutterShell macOS malvertising
- Phantom squatting: AI-hallucinated domains
- Siemens ROX II zero-day exploit chain
- Synced passkey theft after endpoint compromise
- TuxBot v3 Evolution IoT botnet framework
- Vidar / XMRig Factory-v3 malvertising campaign
United States
- Seedworm / MuddyWater
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC3753
university targeting
UNK_MassTraction
UNK_PitStop
unpatched vulnerability
unsafe deserialization
unsigned installer
UpdateFactory
UPnP
UPX
uranium compression
URL retrieval
USB exfiltration
USB propagation
USB weaponizer
USB worm
use-after-free
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
user execution
user namespaces
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux pedit COW CVE-2026-46331 local privilege escalation
user verification
UserAssist
username environmental keying
USN Journal
UTA0355
UTA0533
UTG-Q-1000
uTLS
Uzbekistan
V2Ray
V4bel
V8
valid accounts
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Brazilian education LockBit, DragonForce, and insider incidents
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
ValleyRAT
Varonis Threat Labs
VBCloud
VBE
VBS
VBScript
- BusySnake Stealer
- Cloud Atlas
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- WhatsApp VBScript ManageEngine RMM campaign
vCenter
vector databases
VEIL#DROP
Velociraptor
VeloCloud
VeloCloud Orchestrator
Velvet Ant
VELVETSHELL
vendor compromise
vendor credentials
VENOMOUS BEAR
Vercel
Vertex AI
victim-owned relay infrastructure
VIDAR
Vidar Stealer
- AI-brand impersonation phishing and malvertising
- Operation Muck and Load GitHub lure network
- Vidar / XMRig Factory-v3 malvertising campaign
Vietnam
Vietnam-aligned
Views
ViewState deserialization
ViPNet
virtual machine escape
virtualization
- Ababil of Minab MOIS-linked recovery-destruction campaign
- Januscape KVM CVE-2026-53359 guest-to-host escape
virtualization targeting
VirusTotal sentiment abuse
vishing
- Microsoft Q2 2026 email and Teams phishing landscape
- O-UNC-066 Entra passkey vishing
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- ShinyHunters
- UNC3753
- UNC6671 / BlackFile multi-brand vishing extortion operation
Visual Studio
Visual Studio Code Remote SSH
Vite
Vitest
ViteVenom
VLESS
vManage
VMSA-2026-0006
VMware
- VerdantBamboo
- VerdantBamboo appliance BRICKSTORM operation
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
VMware ESXi
VMXNET3
VNC
VNT
Void Blizzard
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Ulej / Flowerbed
Void Manticore
Volt Typhoon
volume serial number
VPN
- Check Point VPN CVE-2026-50751 exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- First VPN
- Gunra ransomware-as-a-service activity
- PAN-OS GlobalProtect CVE-2026-0257 exploitation
- UTA0533 SonicWall SMA1000 zero-day compromise
- VPN Go browser-extension clipboard stealer
VPN credentials
VPN gateway
VPN Go
VPN session hijacking
VS Code
- Amazon Q CVE-2026-12957 MCP auto-execution
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Browser-based developer IDE OAuth token theft
- Glassworm developer supply-chain botnet
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- Nx Console VS Code extension compromise
- Open VSX evil-twin extension campaign
- PolinRider cross-ecosystem supply-chain campaign
- UNK_DeadDrop developer repository phishing
VS Code tunnels
Vshell
VShell
VSIX
vSphere
vSphere Foundation
VU#213560
VulnCheck
vulnerability
- Adobe ColdFusion APSB26-68 CVE bonanza
- Amazon Q CVE-2026-12957 MCP auto-execution
- Android Framework CVE-2025-48595 exploitation
- BeyondTrust RS / PRA CVE-2026-40138 and CVE-2026-40139 authentication bypass
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Citrix NetScaler CVE-2026-8451 memory overread
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Joomla extension KEV exploitation cluster
- Langflow CVE-2026-55255 flow authorization bypass
- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Linux GhostLock CVE-2026-43499 container escape
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Linux nftables CVE-2026-23111 public LPE exploits
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
- Quest KACE SMA CVE-2025-32975 exploitation
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- Trend Micro Apex One CVE-2026-34926 exploitation
vulnerability exploitation
vulnerability research
- ChocoPoC
- ChocoPoC fake PoC supply-chain campaign
- GitLab Oj notebook-diff authenticated RCE chain
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
vulnerability-research
vulnerable appliances
VXLAN
w3wp.exe
wallet address replacement
wallet drainer
wallet infrastructure
wallet replacement
wallet theft
- @copilot-mcp/apex macOS infostealer campaign
- COLDCARD predictable-RNG Bitcoin theft risk
- Fake-reputation crypto clipboard hijacker
- Ill Bloom CryptoJS wallet-drain campaign
- Injective SDK npm wallet stealer
- Mastra
easy-day-jsnpm scope compromise - Solana FakeFix npm / PyPI developer stealer
- Void Dokkaebi
wallet-drainer
wallet-theft
Wasabi
- DeadLock ransomware
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Seedworm / MuddyWater
wastewater
watchdog
watchTowr
- Adobe ColdFusion APSB26-68 CVE bonanza
- Citrix NetScaler CVE-2026-8451 memory overread
- Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
watchTowr Labs
water sector
watering hole
watering-hole
weak credentials
weak entropy
weak passwords
weak RNG
weapons shipments
web application
- Drupal Core CVE-2026-9082 exploitation
- Everest Forms Pro CVE-2026-3300 exploitation
- Fastjson CVE-2026-16723 active exploitation
- Gravity SMTP CVE-2026-4020 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
web application compromise
web hosting
web IDE
web injection
web injector
web management interface
web proxy
web RCE
web server
web shell
- Everest Forms Pro CVE-2026-3300 exploitation
- Joomla extension KEV exploitation cluster
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Oman government Iranian-nexus webshell C2
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- UNC6508
- UTA0533 SonicWall SMA1000 zero-day compromise
web shell hunting
web shells
- CL-STA-1062
- CL-STA-1062 Southeast Asia government and energy intrusions
- StrikeShark SharkLoader / Cobalt Strike campaign
web supply chain
- Adform Trackpoint JavaScript supply-chain crypto clipper
- Funnull RingH23 and MacCMS supply-chain attacks
web-shells
WebAssembly
WebAuthn
WebDAV
WebKit
WebLogic
webmail
- CL-STA-1114 / Void Blizzard
- CL-STA-1114 Zimbra webmail espionage
- UNK_MassTraction Roundcube university mailserver campaign
- Webmail CSS trust-boundary attacks
WebRTC
webshell
webshells
website-compromise
WebSocket
- Agent localhost control-plane RCE
- ArcBridge
- BridgeHead
- Flying Eagle and Night Dragon Android RAT ecosystem
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- UTA0533 SonicWall SMA1000 zero-day compromise
WebSocket C2
- Cavern
- GREYVIBE
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- SprySOCKS
- STOCKSTAY
- TELEPUZ
- Turla STOCKSTAY backdoor operations
websocket-sharp
WebView
WebView2 C2
Webworm
Werkbit
WhatsApp phishing
WHM
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- LiteSpeed cPanel CVE-2026-48172 exploitation
- LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
Wi-Fi credential theft
Widget Factory
Wiflyer
wiki
WILDDAY
Windchill
Windchill PDMLink
WinDirStat
Windmill
Windows
- 3CX desktop app compromise
- Aeternum
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- ArcBridge
- Backdoor.Mistic / KongTuke ModeloRAT activity
- BINDCLOAK
- BridgeHead
- BusySnake Stealer
- CCleaner signed-update compromise
- ClickOnce COM hijacking abuse
- Crypto Clipper Tor / USB worm
- Cursor Windows workspace-path binary hijack
- DAEMON Tools Lite supply-chain compromise
- DeadLock ransomware
- Djinn Stealer
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- FDMTP
- Flooding Dropper npm campaign
- GenieLocker
- GigaWiper
- GodDamn ransomware PoisonX BYOVD activity
- IronWorm npm Rust infostealer campaign
- js-logger-pack Hugging Face exfiltration campaign
- LabubaRAT
- LurkProxy
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- MiniPlasma Windows Cloud Filter LPE exploitation
- MIXEDKEY
- NightLedger
- OctLurk
- Operation DangerousPassword axios npm compromise
- Pirated media SilentCryptoMiner RAT campaign
- postcss-minify-selector-parser npm RAT
- procwire / routecraft npm Windows dropper
- QuickFox FDMTP software supply-chain compromise
- QuimaRAT
- ScarCruft Yanbian game-platform supply-chain attack
- SilkLurk
- Starland RAT
- StrikeShark SharkLoader / Cobalt Strike campaign
- Synced passkey theft after endpoint compromise
- TamperedChef-style productivity malware clusters
- TELESHIM
- The Gentlemen ransomware
- TinyRCT
- Toy Ghouls
- Toy Ghouls GenieLocker ransomware activity
Windows Defender
Windows Defender exclusions
Windows Defender impairment
Windows Forms
Windows malware
- Armored Likho BusySnake campaign
- CrownX
- Fake-reputation crypto clipboard hijacker
- MODBEACON
- NuGet game-cheat DotnetTool pepesoft campaign
- OkoBot cryptocurrency-wallet malware framework
- SourTrade browser-assembled malware malvertising
- TELEPUZ
- TELEPUZ ClickFix / VIDAR campaign
- TELESHIM Middle East government espionage campaign
- Thailand healthcare RAR / Python stealer campaign
- WhatsApp VBScript ManageEngine RMM campaign
Windows persistence
Windows Run dialog
Windows Script Host
Windows servers
Windows service persistence
Windows Terminal
Winnti Group
WinOS
Winos4.0
WinPython
WinRAR
- Gamaredon
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- UAC-0226 / SHADOW-EARTH-066
wiper
wiper-adjacent
WireGuard
Wiz Research
WLDR agent
WM_COPYDATA IPC
WMI
Woodgnat
WordPress
- Everest Forms Pro CVE-2026-3300 exploitation
- Gravity SMTP CVE-2026-4020 exploitation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Operation Endgame SocGholish disruption
- Patriot Bait AI-assisted C2 botnet
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- WP Maps Pro CVE-2026-8732 exploitation
- WP-SHELLSTORM webshell access brokerage
WordPress credential theft
workflow backdoor
working-directory hijacking
workspace trust
World Cup
worm
- binding.gyp npm CI/CD worm
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- CanisterWorm
- ChainDrop keyv / cacheable npm worm
- Crypto Clipper Tor / USB worm
- Immobiliare Labs Backstage plugins npm compromise
- IronWorm npm Rust infostealer campaign
- jscrambler npm preinstall stealer
- Leo Platform npm Miasma-style compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- PCPJack cloud SMTP relay network
- SANDWORM_MODE AI-toolchain npm worm
- TeamPCP
- Trivy → TeamPCP → CanisterWorm: compromise timeline
- XCSSET
- XCSSET v40 Xcode supply-chain campaign
WP Maps Pro
WP-SHELLSTORM
wp2shell
WScript
WSS
X-Grafana-URL
X-Secret
X-WEBAUTH-USER
X25519
X3D MINER
X_TRADER
XChaCha20
XChaCha20-Poly1305
Xcode
XCSSET
XCSSET v40
XenoRAT
XFRM
xlabs_v1
XMLDecoder
XMRig
- Aeternum
- GREYVIBE
- Langflow CVE-2026-33017 cryptominer SSH worm
- Ollama P2P cryptominer RAT campaign
- Operation Muck and Load GitHub lure network
- Pirated media SilentCryptoMiner RAT campaign
- Vidar / XMRig Factory-v3 malvertising campaign
XOR
XOR obfuscation
Xray
XSLT SSRF
XSS
- TA488 OWAReaper and CVE-2026-42897 exploitation
- UNK_MassTraction Roundcube university mailserver campaign
XSS.is
XWorm
XXE
xz
Yahoo Mail
Yanbian
Yasmarang
YesWeHack
YouTube abuse
Yuechi Shared Technology
yuze
Yx Technology
ZAPiXDESK
Zbtlink
Zendesk
Zephyr RTOS
Zero Trust
zero-click
zero-day
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Metabase unauthenticated SQL-injection zero-day
- MiniPlasma Windows Cloud Filter LPE exploitation
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- Siemens ROX II zero-day exploit chain
- UTA0533 SonicWall SMA1000 zero-day compromise
zero-day exploitation
zero-reputation infrastructure
ZeroBEC
Zimbra
Zimbra Collaboration Suite
Zimperium
ZimReaper
zLabs
zlib
Zoho Assist
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Storm-2603 parallel SharePoint ransomware intrusion