Gunra Steals Cloud Data and Deletes Backups Before Encryption
Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.
Read article →CISA confirms exploitation of a pre-authentication LoadMaster command-injection flaw. API-enabled appliances need a fixed release and an exposure review.
Read article →OVSwrap exploits a 16-bit nested-action limit in the Linux kernel, leaving defenders to verify both the running fix and the earlier exposure window.
Read article →A Microsoft case study traces mshta execution to one isolated QNET host and shows which workstations qualify for the preview action.
Read article →A remote SCTP peer can trigger the kernel flaw, while Tencent separately demonstrated local privilege escalation and container escape. Defenders need both reachability and running-kernel checks.
Read article →An automated npm campaign uses hundreds of disposable packages to launch detached native malware, with DNS TXT records as a fallback delivery channel.
Read article →WordPress 7.0.3 fixes a pre-auth login-page XSS that can turn administrator interaction with a malicious site into PHP execution.
Read article →Remus uses an Ethereum smart contract to resolve changing command infrastructure before stealing browser sessions, credentials, and wallet data.
Read article →BINDCLOAK collects Windows user and process tokens, duplicates them, and starts modular malware components inside more privileged security contexts.
Read article →SpecterOps shows how relayed WSUS machine-account access can forge targeted updates and bypass payload signature checks when SUSDB runs on a separate SQL Server.
Read article →CISA confirms exploitation of a TeamCity flaw that lets an unauthenticated network attacker run commands as the server process, putting secrets and build integrity at risk.
Read article →A targeted npm cluster split its downloader across ordinary-looking modules, then escaped Node.js vm isolation to install a cross-platform RAT on developer systems using Alibaba tools.
Read article →TP-Link TL-WR940N hardware revision 6 can let an unauthenticated attacker turn a LAN client's outbound RTSP session into code execution inside the router kernel.
Read article →