-
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities in the Middle East by an East Asia-linked threat actor tracked as OctLurk. The disclosure follows …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPan…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi‑Fi credentials from travelers connecting to compromised hospitality networks worldwide. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking Ethereum transfers, while still exposing just enough bytes to resolve a live command server. Two trojaniz…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging platform and blocking reinstalls for users who had previously deleted the app. This global d…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open‑source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled ne…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


