C2Looper Backdoor Uses GitHub to Control Infected Windows PCs
C2Looper shifted from one-second HTTP beacons to GitHub C2. Hunt its OneDrive DLL, JSON control files, debug marker, commands, hashes, and two IPs.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
C2Looper shifted from one-second HTTP beacons to GitHub C2. Hunt its OneDrive DLL, JSON control files, debug marker, commands, hashes, and two IPs.
Read article →Gambit observed Claude Code inside six intrusions. Hunt the test VPN account, rogue LDAP listeners, backup discovery, SQL staging, and firewall restores.
Read article →Attackers are exploiting a Zimbra SNMP flaw through crafted SMTP requests. Version 10.1.20 fixes it; exposed servers need log and file review.
Read article →A blank file entry bypasses Elementor Pro upload checks on exposed forms. Version 4.2.2 fixes the flaw, but patched sites still need to hunt for PHP left behind.
Read article →CISA now ties CVE-2025-60710 to ransomware. The local Windows flaw needs an existing foothold, then lets an attacker elevate to SYSTEM.
Read article →Pantheon counted 45 million wp2shell attempts in one week. Defenders should verify current WordPress builds and review exposed sites for persistent access.
Read article →A compromised crates.io account poisoned three Rust packages. Builds ran a downloader; 2,285 arrayref downloads now require cache, lockfile, and host checks.
Read article →CISA now links CVE-2026-45659 to ransomware. Check exact SharePoint builds, then investigate whether low-privilege access reached the farm before patching.
Read article →A signed ClickOnce app delivered two stealers and an hVNC RAT after a fake Web3 interview. Hunt per-user ClickOnce records, then rotate every secret reachable from affected hosts.
Read article →Microsoft's August updates close an AFD.sys race used in attacks; defenders must verify fixed builds and investigate pre-patch privilege escalation.
Read article →Customer contact data is public after a social-engineering breach; defenders should harden support and identity checks against targeted impersonation.
Read article →August Windows updates close a public registry-hive privilege escalation; defenders can hunt its staging files, virtual paths, and unusual DLL loads.
Read article →Exposed ASA and FTD remote-access services need release-specific hot fixes; Cisco offers no workaround for the exploited denial-of-service flaw.
Read article →