Skip to content

Tag index

Generated from page-level ## Tags sections. Each tag below links to the pages that currently use it.

All tags

.NET

.pth

3CX

4sync

Ababil of Minab

Accellion

account-takeover

ACTINIUM

active exploitation

active-exploitation

actor

actors

Adaptix C2

Admin API key theft

administrator account creation

Adobe Commerce

Adspect

adversary-in-the-middle

adware

Afghanistan

agent frameworks

agent skills

agent state

agentic AI

agentic malware

Agentjacking

AGENTPSD

AI

AI agents

AI assistants

AI brand impersonation

AI chatbot abuse

AI credential theft

AI data exfiltration

AI gateway

AI search poisoning

AI tooling

ai-abuse

ai-agent

AI-augmented operations

AI-generated malware

AiTM

Albania

Android

Android spyware

Apex One

API abuse

AppDomainManager

AppleJeus

AppleSeed

appliance

APT

APT27

APT28

APT29

APT32

APT36

APT37

APT43

APT45

arbitrary file write

Arch Linux

Arista EOS

Armageddon

Artifact Signing

ASP.NET

ASP.NET machineKey

Astro

Atlas RAT

AUDIOFIX

AUR

authentication bypass

authentication stack

authentication-coercion

AUTODYN

AutoHotKey

AWS

AWS CloudTrail

AWS S3

AWS Secrets Manager

axios

Azure

Backblaze

backdoor

backup disruption

backups

banking

banking malware

Barracuda

Bash Uploader

BeaverTail

Bedrock

behavioral integrity verification

Belarus

BinaryFormatter

binding.gyp

BirdCall

Bitbucket

Bitwarden

BlackFile

blockchain C2

blockchain-dead-drop

BLUEBEAM

botnet

branch-compromise

branch-name-injection

brand-impersonation

Brazil

BreachForums

BRICKSTORM

browser credential theft

browser extension

browser hijacking

browser zero-day

browser-extensions

browser-security

BTMOB

build-time compromise

Bun

Bun runtime abuse

C2

Canada

CANFAIL

Catalyst SD-WAN Manager

CCleaner

CDN

certificate theft

ChatGPT

Chatty Spider

Check Point

Check Point Research

Checkmarx

checkpointers

China

China-linked

China-nexus

China-speaking ecosystem

Chinese-language cybercrime

Chisel

Chrome Web Store

ChromElevator

Chromium

CI-CD

CI/CD

CircleCI

CISA KEV

Cisco

Cisco Nexus

Citrine Sleet

Citrix

CL-CRI-1089

Claude

Claude Code

ClickFix

client-side exploitation

Cloaked Ursa

cloaking

cloud

cloud C2

cloud credential theft

Cloud Files Mini Filter Driver

Cloud Filter driver

cloud IAM

cloud identity

cloud infrastructure

cloud logging

cloud secrets

cloud security

cloud service abuse

Cloudflare

Cloudflare tunnels

Cloudflare Workers

CMS

Cobalt Strike

code sandbox scraping

code signing

Codecov

Codex

Coinbase

collaboration-tool phishing

command execution

command injection

command-execution

command-injection

Composer

compromised accounts

compromised credentials

ConnectWise

consumer devices

Contagious Interview

container

container escape

continuous visibility

control panel compromise

control plane

Coruna

cPanel

CrackMapExec

Crates.io

credential exposure

credential spraying

credential theft

credential-theft

criminal infrastructure

critical infrastructure

critical-infrastructure

crypto

crypto-wallets

cryptocurrency

cryptocurrency theft

cryptojacking

cryptominer

Curious Serpens

Cursor

Curve25519

custody APIs

CVE-2020-17103

CVE-2022-0492

CVE-2023-2868

CVE-2023-4966

CVE-2024-1708

CVE-2024-1709

CVE-2024-20399

CVE-2024-21182

CVE-2024-3094

CVE-2025-32975

CVE-2025-34291

CVE-2025-48595

CVE-2025-8088

CVE-2026-0257

CVE-2026-10520

CVE-2026-10523

CVE-2026-11645

CVE-2026-20127

CVE-2026-20182

CVE-2026-20245

CVE-2026-20253

CVE-2026-23111

CVE-2026-26980

CVE-2026-28318

CVE-2026-3300

CVE-2026-33017

CVE-2026-34926

CVE-2026-35273

CVE-2026-35616

CVE-2026-39987

CVE-2026-41091

CVE-2026-41940

CVE-2026-42271

CVE-2026-44338

CVE-2026-45247

CVE-2026-45498

CVE-2026-48172

CVE-2026-50751

CVE-2026-50752

CVE-2026-5426

CVE-2026-7473

CVE-2026-8732

CVE-2026-9082

CWE-77

CWE-78

cybercrime

cybercrime ecosystem

Cython

Czech Republic

data exfiltration

data exposure

data leak site

data theft

data-exfiltration

DAYLIGHT

DDoS

dead drop resolver

DeepSeek

Defender evasion

defense

defense evasion

DeFi

denial of service

Deno

dependency confusion

deployment_status

deserialization

destructive operations

developer endpoints

developer machines

developer targeting

developer tooling

developer workstations

developer-targeting

developer-tools

developer-workstations

device registration

device-code phishing

DEWMODE

Digital Knowledge

digital wallets

DigitalOcean

Dindoor

diplomatic targeting

Discord

discovery

DLL side-loading

DLL sideloading

DNS C2

DNS tunneling

Docker

document theft

domestic espionage

DotNetNuke

double extortion

DPAPI

DPAPILoader

DPRK

Dropbox

Drupal

Dutch Police

DWAgent

dynamic DNS

Dynu

e-commerce

eBPF

edge appliance

edge appliances

edge application server

edge devices

edge service

EDR evasion

education

Egnyte

EKZ Infostealer

Elasticsearch

email

email gateway

Emerald Sleet

endpoint management

endpoint management abuse

endpoint response

endpoint-security

energy-sector

engineering software

Entra ID

Environment Management Hub

environment variables

environmental keying

Epsilon Stealer

ESG

espionage

ETW patching

Eurojust

Europe

Europol

Everest Forms Pro

EvilAI

exfiltration

exploit-development

exploit-kit

Exploit.in

exploitation

external federation

extortion

F5 BIG-IP

fake CAPTCHA

fake dating lures

fake plugin

fake recruiting

fake update

FakeCaptcha

Fakeset

faketivism

FallSpy

FAMOUS CHOLLIMA

Fancy Bear

Fast16

FastCGI

FBI

file-system filter

FileFiend

filemanager

filename-injection

finance

financial fraud

financial sector

financial services

financial theft

FireAnt MetaKit

Flutter

FlutterShell

Forest Blizzard

FortiClient EMS

Fortinet

Fox Tempest

FreeBSD

FSB

FTA

ftp.exe

Funnull

Gamaredon

GammaLoad

GammaPhish

GammaSteel

GammaWorm

Garble

GCS

Ghost CMS

GHSA-6rmh-7xcm-cpxj

GIFTEDCROOK

GitHub

GitHub abuse

GitHub Actions

GitHub API

GitHub App

GitHub issue spam

GitHub OAuth

GitHub Security Advisories

GitHub tokens

GitLab

gitleaks

Gleaming Pisces

gleeze.com

GlobalProtect

Go

Godzilla

GoEdge

Google Chrome

Google Cloud Logging

Google Drive

Google Play

government

government targeting

government-impersonation

Grandoreiro

GRE

GREYVIBE

group

groups

GS-Netcat

GUE

hack-and-leak

hacktivist persona

Hades

HappyDoor

HAR files

hard-coded secrets

HashiCorp Vault

healthcare

HelloDoor

HellsGate

high explosives

higher education

HONESTCUE

hosting provider

HR lures

HTA

HttpMalice

HTTPSpy

Hugging Face

Hunt.io

ICE

ICONICSTEALER

ICS

IDE extension

identity

identity security

IDEs

IFEO persistence

IIOP

IIS

IKEv1

iMessage

Impacket

impersonation

import-time execution

in-memory DLL loading

incident response

indirect prompt injection

industrial control

infostealer

infrastructure

initial-access

install-time execution

InvisibleFerret

iOS

IoT

IP-in-IP

Iran

Iran-nexus

Israel

Ivanti Sentry

Japan

JavaScript

JavaScript bridge

JavaScript injection

JavaScript loader

JavaScript malware

JavaScript tampering

JDY

JetStream

JFrog Security Research

JINX-0164

JSCoreRunner

JSON:API

JSONPing

JSP web shell

Kaspersky

kernel driver

KEV

KeyHunter

keylogger

keylogging

Kimsuky

KnowledgeDeliver

Kubernetes

KV-botnet

L2TP/IPSec

LA Metro

LangChain

Langflow

LangFlow

LangGraph

Laravel

lateral movement

lateral-movement

Latin America

launchctl

law enforcement

Lazarus

LD_PRELOAD

legacy infrastructure

legacy software

LegionRelay

liblzma

libp2p

libpeconv

lifecycle hooks

LinkedIn

Linux

LiteLLM

LiteSpeed

living off the land

living-off-the-land

LLM

LLMjacking

LMS

LNK

LNK files

loader

local LLMs

local privilege escalation

log poisoning

long-lived tokens

long-term access

LONGSTREAM

LOOKVALJS

LOOKVALPS

LPE

LS-DYNA

LSASS

Lua

Lumen Black Lotus Labs

Luna Moth

MacCMS

macOS

Magento

mailbox theft

maintainer compromise

maintainer persona

maintainer-compromise

malicious releases

malvertising

malware

malware delivery

Malware-as-a-Service

malware-signing-as-a-service

managed file transfer

managed service provider

management plane

manufacturing

marimo

marketplace abuse

Maven Central

MCP

memory-only malware

MeshCentral

MEV bot lure

Mexico

MFA bypass

MFA fatigue

MFA-bypass

Miasma

Microsoft

Microsoft .NET

Microsoft 365

Microsoft Defender

Microsoft Graph

Microsoft SQL Server

Microsoft Teams

Middle East

middleware

Midnight Blizzard

MiniJunk

MiniPlasma

MINIRAT

Ministry of Finance

MiniUpdate

MITRE ATT&CK T1005

MITRE ATT&CK T1562

mobile

Mobile Access

mobile device management

mobile devices

mobile malware

MobileIron Sentry

Model Context Protocol

model-provider abuse

module-proxy

MOIS

Monero

MPR network provider

Mr_Rot13

msgpack

mshta

MSP

mTLS

MuddyWater

named pipes

namespace recycling

nation-state

NATS

NCSC-NL

Nebo

Neo-reGeorg

Netherlands

NetScaler

network infrastructure

nf_tables

nftables

Nginx

Nginx module

node-gyp

node-ipc

Node.js

North Korea

notarized malware

npm

npm lifecycle hook

npx

NTFS ADS

NTLM

nuclear weapons

NuGet

NVGRE

OAuth

OAuth tokens

obfuscation

OFAC

OIDC

Okta

Ollama

Oman

OneDrive

OpenAI Codex

OpenConnect

OpenSearch

OpenSSH

OpenVPN

OpenVSX

Operation DangerousPassword

Operation Highland

operational resilience

operations

OpFauxSign

ops

opsec failure

Oracle PeopleSoft

Oracle WebLogic Server

OTP interception

Outlook

OX Security

OYSTERBLUES

OYSTERFRESH

OYSTERSHUCK

P2P

package registry

package-takeover

Packagist

page poisoning

Pakistan-linked

Palo Alto Networks

PAM

PAN-OS

Pastebin

patch management

patterns

payment fraud

payment-card theft

payment-card-theft

payroll lures

pe_to_shellcode

PebbleDash

people

PeopleTools

persistence

pfSense

PhaaS

Phantom Gyp

PhantomClick

PhantomMail

PhantomRelay

Philippines

phishing

phishing-as-a-service

PHP

PHP code injection

PHP object injection

PicassoLoader

pig-butchering

piracy

Piriform

PKGBUILD

PLENET

poisoned-branch

PolinRider

Polymarket

portmap

Portugal

post-exploitation

postal-impersonation

PostgreSQL

postinstall

PowerCloud

PowerShell

PowerShower

PPtP

PraisonAI

PRC

PRC-aligned

pre-authentication

Primitive Bear

PrincessClub

privacy

private-key theft

privilege escalation

process hollowing

process injection

professional services

prompt injection

prompt-injection

PROMPTFLUX

PROMPTSPY

protestware

proxy

ProxyChains

PSEMHUB

psychological operations

public exploit

public file-transfer exfiltration

public sector

pull requests

PUP

pwn-request

PyPI

Python

Python extension modules

Qilin

query injection

Quest KACE SMA

RaaS

RAM disk

ransomware

rapid exploitation

RAT

RC4

RCE

Rclone

RCS

RDP

Reality

Reaper

reconnaissance

recovery denial

recruitment lures

Redis

Redis backdoor

RediSearch

refresh tokens

registry persistence

release tampering

remote access

Remote Access VPN

remote code execution

remote-access

RemotePE

RemotePELoader

repository poisoning

residential proxies

REST C2

ReverseSocks

reviewdog

RingH23

RMM

RMM abuse

ROADrecon

ROADtools

roadtx

RokRAT

RomulusLoader

root execution

rootkit

RSA

RubyGems

Runner.Worker

Russia

Russia-linked cybercrime

Russia-nexus

Russian-speaking forums

Rust

SaaS

sabotage

Safari

Salesforce

ScarCruft

scheduled tasks

ScreenConnect

script-injection

SD-WAN

secret exposure

secrets

secrets management

security platform

Seedworm

segmented networks

self-hosted AI services

self-propagation

sendit.sh

Sentry

Sentry abuse

SEO poisoning

Serv-U

service accounts

ServiceNow

session hijacking

session theft

SHADOW-AETHER-040

SHADOW-AETHER-064

SHADOW-EARTH-066

ShadowPad

Shai-Hulud

share propagation

shared hosting

shared secrets

SharePoint

ShinyHunters

Shuckworm

SideCopy

signed malware

signed updates

signed-binary

Silent Ransom Group

SilentCryptoMiner

SilentRunLoader

simulation tampering

sleeper packages

Sliver

SLSA

SmartScreen

SMB

SMB egress

smishing

sms-phishing

SMTP

social engineering

social-engineering

Socket Security Research

SOCKS5

SOCKS5 tunneling

software impersonation

SOHO routers

Solana

SolarWinds

source-code compromise

source-package drift

source-package mismatch

source-repository poisoning

South Africa

South Asia

South Korea

Southeast Asia

spam

spear phishing

spear-phishing

spearphishing

SPECTRALVIPER

Splunk

SQL injection

SQLite

SSH

SSH bastion

SSH key persistence

SSH persistence

SSH tunnels

SSRF

state-linked

Static Kitten

stdio

stealer

stock exchange

storage deletion

Storm-2697

Storm-3075

STUN

Stuxnet lineage

subject claim

supply chain

supply chain compromise

supply-chain

Synology

SYSTEM

T3

TA427

tag rewrite

tag tampering

Taiwan

takedown

TamperedChef

targeted operations

TartarusGate

TeamPCP

TeamPCP-adjacent

TeamViewer

TEASOUP

telecom

telecom-impersonation

Telegram

telegram

Telegram C2

telemetry

Telnyx

Temp Zagros

Tenet Security

The Gentlemen

threat hunting

tj-actions

token replay

token theft

token-theft

tool output injection

tooling

tools

Tor

Trading Technologies

traffic hijacking

traffic-fraud

transaction authority

transnational repression

Transparent Tribe

Trend Micro

TrendAI

TrickBot

Trident Ursa

trusted publishing

tunnel decapsulation

Twilio

typosquat

typosquatting

UAC

UAC-0010

UAC-0098

UAC-0226

Udev persistence

Ukraine

unauthenticated access

unauthenticated RCE

UNC2814

UNC3753

UNC4736

UNC6240

UNC6671

UNC6692

UNC6780

Unit 42

United States

unsafe deserialization

uranium compression

USB worm

UTA0355

uTLS

V8

ValleyRAT

VBCloud

VBScript

Velvet Ant

VELVETSHELL

vendor credentials

Vercel

Vidar Stealer

Vietnam

Vietnam-aligned

Views

ViewState deserialization

virtualization

vishing

VLESS

vManage

VMware

Volt Typhoon

VPN

VS Code

VS Code tunnels

VSIX

vSphere

vulnerability

vulnerability-research

VXLAN

w3wp.exe

wallet infrastructure

wallet replacement

wallet theft

wallet-drainer

wallet-theft

Wasabi

watchdog

watering-hole

web application

web hosting

web IDE

web shell

web supply chain

web-shells

WebKit

WebLogic

WebRTC

webshell

WebSocket C2

WebView

Webworm

WhatsApp

WHM

Windows

Windows persistence

Winos4.0

WinRAR

wiper

wiper-adjacent

WireGuard

WordPress

workflow backdoor

worm

WP Maps Pro

X_TRADER

XChaCha20

XenoRAT

XMRig

XSS.is

xz

Yanbian

ZAPiXDESK

Zendesk

Zero Trust

zero-click

zero-day