BlueMoon chains Chrome V8 flaws with a Windows kernel exploit to deploy GemStone, ShadowPad, and Rust-based malware in ...
China-linked threat actors combine automated tools with hands-on hacking techniques to steal sensitive data in targeted cyber ...
Suspected TraderTraitor actors abuse a trojanized Terraform provider to deploy cross-platform malware targeting credentials ...
Compromised TensorLake npm SDK v0.5.144 deploys a credential-stealing worm targeting GitHub, AWS, Kubernetes, and AI ...
ClickFix abuses browser cache smuggling, VBScript, PowerShell, and .NET payloads to bypass Windows Run limits and steal ...
NetScaler zero-days enable RCE, memory corruption, web shell deployment, log poisoning, and persistence on vulnerable ADC and Gateway systems ...
Attackers exploit Citrix NetScaler zero-days CVE-2026-88772 and CVE-2026-88771 to gain root access, deploy web shells, and ...
GlassWorm-linked VS Code extensions abuse theme packages, obfuscated JavaScript, AES-256-CBC, and Solana dead drops to ...
Threat actors abuse Action1 RMM via phishing PDFs, VBS, and MSI packages to establish persistence and unauthorized remote access ...
Prerequisite: The Telemetry & Baseline Pre-flight Check must have passed. Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule.
Only days after Citrix addressed actively exploited NetScaler flaws CVE-2026-88771 and CVE-2026-88772, defenders faced another urgent security issue. A newly disclosed vulnerability tracked as ...
Threat actors are leveraging phishing campaigns to deliver a legitimate MSP360 RMM installer disguised as trusted software. Once launched, the installer establishes persistence and subsequently ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results