Campaigns
A threat actor breached a Jenkins server through its unauthenticated Script Console, then installed a self-healing SSH backdoor: delete the key and a systemd timer disguised as an update checker puts it back within five minutes. They stole the keys that decrypt the entire Jenkins credential store, harvested AWS credentials, and two days later deployed a cryptominer throttled to avoid detection. Full kill chain, IOCs, and Sigma detection rules inside.
2026-09-02
A 2013 dropper for the Skynet ZeuS botnet, distributed via a fake lossless-audio release on Usenet, is still being downloaded today. The packed wrapper was absent from every public malware repository for thirteen years, until it surfaced on VirusTotal in late August 2026. Five packer/anti-analysis layers, full IOCs, and behavioural detection guidance inside.
2026-08-29
Over two days we watched a single operator chain two PAN-OS vulnerabilities in one request to install a custom-compiled, fully-obfuscated Sliver implant that appears in no public malware database and beacons to domains absent from every threat feed. A step-by-step walkthrough of the intrusion, with deployable Sigma and YARA detection.
2026-07-09
Docker exposes a management interface, the Docker daemon API, that lets you create, start, and control containers. When it is accidentally published to the internet with no authentication, anyone who can reach that port can take over the host underneath it. We watched a fully automated toolkit do exactly that in about 45 seconds.
2026-06-29
A skilled operator used CVE-2022-40684 to take over an internet-facing FortiGate through its REST API: six backdoor super-admin accounts, an SSH key for re-entry, the admin account hidden from the GUI, MFA disabled, and the full configuration stolen. No malware.
2026-06-09
Langflow is an open-source tool that lets developers build AI and large-language-model pipelines visually, by dragging and connecting components in a browser.
2026-06-03