Posts
A novice attacker compromised a French small business and, before his Command and Control server went down, installed Tailscale and OpenSSH to secure his way back in. Access survived 18 days without the C2. Cato Networks documented the operation command by command.
obeedt, OscarRV, LuisZavMen
Anthropic pulled its Mythos-class models, Fable 5 and Mythos 5, offline worldwide just 72 hours after launch, following a U.S. government export-control directive tied to a jailbreak.
obeedt, OscarRV, LuisZavMen
A misplaced exclamation mark (`!`) inside `nft_map_catchall_activate()` inverts the validation logic in nf_tables, allowing any unprivileged local user to trigger a Use-After-Free, corrupt kernel memory, and escalate to root.
obeedt, OscarRV, LuisZavMen
A zero-day exploit released hours after Microsoft's largest Patch Tuesday on record allows any local user to obtain SYSTEM privileges on fully patched Windows 10 and 11 systems by abusing the Microsoft Defender engine itself.
obeedt, OscarRV, LuisZavMen
Researchers at OX Security uncovered "mouse5212-super-formatter," a malicious npm package that exfiltrated files from Claude AI's local directory to GitHub—and that left the attacker's private token sitting in plain sight in its own source code.
obeedt, OscarRV, LuisZavMen
The TeamPCP group (UNC6780) compromised a GitHub employee's device through a trojanized VS Code extension, exfiltrating approximately 3,800 internal repositories from the platform in May 2026.
obeedt, OscarRV, LuisZavMen