Posts
An integer overflow in libssh2 during the SSH handshake allows a malicious server to corrupt the memory of any client that connects to it.
obeedt, OscarRV, LuisZavMen
AryStinger. A botnet documented by QiAnXin XLab that has compromised at least 4,300 end-of-life Realtek RTL819X routers by exploiting CVEs from 2013 and 2016. Unlike DDoS or mining botnets, it is built for the pre-intrusion footprinting stage, with distributed scanning, traffic tunneling, and obfuscation of the attacker's real origin.
obeedt, OscarRV, LuisZavMen
A cybercriminal group that emerged in 2025 now claims 504 public victims and has reached second place globally by victim count. ESET's analysis of GentleKiller — the group's proprietary EDR-killing framework — reveals 8 variants targeting 400 processes across 48 security tools, with new PoC exploits operationalized within days of release. The group has also attacked Australian sugar producer Mackay Sugar, disrupting critical OT infrastructure, and formalized a recruitment partnership with BreachForums.
obeedt, OscarRV, LuisZavMen
Google Mandiant published the complete forensic reconstruction of CVE-2026-20245 exploitation. An unknown actor compromised an SD-WAN communications provider's infrastructure at least two months before public disclosure, using a malicious CSV named evil_tenant.csv to create a hidden root account called troot, then erased every trace using automated anti-forensic techniques before administrators could detect the intrusion.
obeedt, OscarRV, LuisZavMen
Google Mandiant published the complete forensic reconstruction of CVE-2026-20245 exploitation. An unknown actor compromised an SD-WAN communications provider's infrastructure at least two months before public disclosure, using a malicious CSV named evil_tenant.csv to create a hidden root account called troot, then erased every trace using automated anti-forensic techniques before administrators could detect the intrusion.
obeedt, OscarRV, LuisZavMen
A physical flaw in the USB controller of Apple's A12 and A13 chips allows unsigned code execution within SecureROM, with no possibility of a software fix.
obeedt, OscarRV, LuisZavMen