BlueMoon chains Chrome V8 flaws with a Windows kernel exploit to deploy GemStone, ShadowPad, and Rust-based malware in ...
China-linked threat actors combine automated tools with hands-on hacking techniques to steal sensitive data in targeted cyber ...
Suspected TraderTraitor actors abuse a trojanized Terraform provider to deploy cross-platform malware targeting credentials ...
Compromised TensorLake npm SDK v0.5.144 deploys a credential-stealing worm targeting GitHub, AWS, Kubernetes, and AI ...
ClickFix abuses browser cache smuggling, VBScript, PowerShell, and .NET payloads to bypass Windows Run limits and steal ...
NetScaler zero-days enable RCE, memory corruption, web shell deployment, log poisoning, and persistence on vulnerable ADC and Gateway systems ...
Attackers exploit Citrix NetScaler zero-days CVE-2026-88772 and CVE-2026-88771 to gain root access, deploy web shells, and ...
GlassWorm-linked VS Code extensions abuse theme packages, obfuscated JavaScript, AES-256-CBC, and Solana dead drops to ...
Threat actors abuse Action1 RMM via phishing PDFs, VBS, and MSI packages to establish persistence and unauthorized remote access ...
Prerequisite: The Telemetry & Baseline Pre-flight Check must have passed. Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule.
Only days after Citrix addressed actively exploited NetScaler flaws CVE-2026-88771 and CVE-2026-88772, defenders faced another urgent security issue. A newly disclosed vulnerability tracked as ...
Threat actors are leveraging phishing campaigns to deliver a legitimate MSP360 RMM installer disguised as trusted software. Once launched, the installer establishes persistence and subsequently ...