Recovered tooling shows how forged WebDAV requests exposed nuclear records and credentials, with specific version, request-pattern, and signing-key checks for defenders.
Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
SonicWall confirmed active attacks against two SMA1000 flaws and told customers to hotfix, seek an IoC review, and rebuild systems when compromise is found.
Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.
Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
CISA confirms exploitation of a critical Artifactory flaw and requires federal forensic triage. Self-hosted operators have six fixed-version floors to verify.
A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts support checks of routers, authentication servers, and Linux hosts.
PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.