Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Portal Drop — TryHackMe Write Up
20+ min ago (786+ words) A spoiler free SOC investigation using web access logs EDR telemetry and MITRE ATTACK By Emir Kılıçer A WAF alert reports a scan against a public CRM portal …...
Dissecting the “Mammoth” PhaaS Framework: From SaaS Hijacking to Real-Time Socket C2 and Financial…
3+ hour, 19+ min ago (23+ words) Dissecting the “Mammoth” PhaaS Framework: From SaaS Hijacking to Real-Time Socket C2 and Financial Profiling Threat actors targeting European peer-to-peer e-commerce platforms (specifically …...
One Click Away from Account Compromise: What a Recent Microsoft 365 Phishing Campaign Teaches Us
8+ hour, 43+ min ago (352+ words) Phishing is still one of the simplest ways to target an employee. A message does not always look …...
WeWorm: The Zero-Click WeChat Worm That Hijacks Accounts With Just a Phone Call
9+ hour, 1+ min ago (34+ words) WeWorm: The Zero-Click WeChat Worm That Hijacks Accounts With Just a Phone Call Imagine your phone rings. You let it go …...
Solana Mobile warns users of phishing risks after Brevo breach
21+ hour, 6+ min ago (387+ words) A SAML SSO vulnerability gave attackers access to 138 customer accounts, with phishing emails reaching hundreds of thousands of crypto users Email marketing platforms are the quiet infrastructure of the internet, the unglamorous pipes that move newsletters and alerts from companies…...
Phishing To Trick AI And How To Defend Against It
10+ hour, 4+ min ago (28+ words) CYBERSECURITY Phishing To Trick AI And How To Defend Against It Indirect prompt injection repurposes the content AI assistants ingest as an attack vector. Layered disciplines form the …...
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
1+ day, 18+ hour ago (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...
Are threat feeds masking your biggest security blind spot?
4+ mon, 2+ week ago (474+ words) Security teams that subscribe to threat feeds get lists of known malicious domains, IPs, and file signatures that they can leverage to blacklist and prevent attacks from those sources. Using network... Are threat feeds masking your biggest security blind spot?...
FakeAgent, MacSync, and AMOS Distribution via Legitimate AI Sharing Pages
1+ day, 4+ hour ago (1540+ words) 1. Basic Information Original Title: How threat actors are turning trusted AI platforms into an attack surface Source: BleepingComputer, Huntress Publication Date: 2026-09-11 Severity: High Basis for Severity: Trusted AI sharing pages are being used to distribute malware via ads and SEO,…...
Kimsuky LNK Malware Uses Multi-Channel C2
2+ day, 14+ hour ago (121+ words) SOC Prime Bias: Critical We are still updating this part. Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim…...