Posts

/../assets/images/featured/libssh2.png
CVE-2026-55200: The Public PoC That Turns Any SSH Client Into the Target

An integer overflow in libssh2 during the SSH handshake allows a malicious server to corrupt the memory of any client that connects to it.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

7 min read
/../assets/images/featured/arystinger_botnet.png
AryStinger — The Botnet Turning Decade-Old Routers Into Covert Reconnaissance Infrastructure for Attackers

AryStinger. A botnet documented by QiAnXin XLab that has compromised at least 4,300 end-of-life Realtek RTL819X routers by exploiting CVEs from 2013 and 2016. Unlike DDoS or mining botnets, it is built for the pre-intrusion footprinting stage, with distributed scanning, traffic tunneling, and obfuscation of the attacker's real origin.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

10 min read
/../assets/images/featured/the_gentlemen_raas.jpg
The Gentlemen: the bespoke ransomware with over 1,500 hidden victims

A cybercriminal group that emerged in 2025 now claims 504 public victims and has reached second place globally by victim count. ESET's analysis of GentleKiller — the group's proprietary EDR-killing framework — reveals 8 variants targeting 400 processes across 48 security tools, with new PoC exploits operationalized within days of release. The group has also attacked Australian sugar producer Mackay Sugar, disrupting critical OT infrastructure, and formalized a recruitment partnership with BreachForums.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

21 min read
CVE-2026-20245: Mandiant Reconstructs the Attack — A Malicious CSV, a 'troot' Account, and a Communications Provider Compromised Months Before Cisco Knew

Google Mandiant published the complete forensic reconstruction of CVE-2026-20245 exploitation. An unknown actor compromised an SD-WAN communications provider's infrastructure at least two months before public disclosure, using a malicious CSV named evil_tenant.csv to create a hidden root account called troot, then erased every trace using automated anti-forensic techniques before administrators could detect the intrusion.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

9 min read
CVE-2026-20245: Mandiant Reconstructs the Attack — A Malicious CSV, a 'troot' Account, and a Communications Provider Compromised Months Before Cisco Knew

Google Mandiant published the complete forensic reconstruction of CVE-2026-20245 exploitation. An unknown actor compromised an SD-WAN communications provider's infrastructure at least two months before public disclosure, using a malicious CSV named evil_tenant.csv to create a hidden root account called troot, then erased every trace using automated anti-forensic techniques before administrators could detect the intrusion.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

9 min read
/../assets/images/featured/USBLiter8.png
USBLiter8: The Unpatchable Hardware Exploit That Breaks the Chain of Trust from Boot

A physical flaw in the USB controller of Apple's A12 and A13 chips allows unsigned code execution within SecureROM, with no possibility of a software fix.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

7 min read