Sliver Toolkit Scripts Credential Theft and Persistent Domain Access
A recovered Sliver kit shows how one operator scripted Domain Admin access, disabled defenses, stole credentials, and hid rotating command servers behind Ethereum.
Read article →Reader view
Choose the default article length.
Page 2 of 10
A recovered Sliver kit shows how one operator scripted Domain Admin access, disabled defenses, stole credentials, and hid rotating command servers behind Ethereum.
Read article →The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →Google observed attackers move from cloud compromise to agent-enabled mass credential harvesting in under six hours, shrinking the time defenders have to respond.
Read article →Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →A public Telerik UI exploit chains two cryptographic oracles to unsafe type loading. Upgrade ASP.NET AJAX to 2026.2.708 and check IIS for post-exploit activity.
Read article →Every on-premises build before 2026.3.1.14 needs Hotfix 4. N-able's records conflict on exploitation, so MSPs should patch and review RMM activity.
Read article →Ten malicious OpenAPI React Query Codegen releases ran on install and carried credential-stealing code with valid provenance. Teams must scope lockfiles, rebuild hosts and rotate credentials.
Read article →Forescout ported a pre-auth PLC exploit with Claude, then bricked the device during an implant attempt. Restrict FTP and monitor crashes and outbound traffic.
Read article →Two factory firmware implants expose white-label ZBT routers through an open WAN service and an unauthenticated phone-home channel.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →CERT Polska confirms attacks through internet-exposed SSH. Install a fixed build, restrict management access, and investigate the published log and account indicators.
Read article →StyleSmuggler turns poisoned Magento logs into server-side code execution, then hides a persistent implant outside the shop's webroot. Adobe has not issued a fix.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Unit 42 traced an AI-assisted ransom intrusion across web, repository, secrets, CI/CD and cloud systems in less than 10 hours. These behaviors can reveal the loop.
Read article →D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Read article →