The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency…
AFD.sys is a Windows kernel driver that provides Winsock functionality. It contains the privilege escalation vulnerability CVE-2026-68820, which was exploited by Lazarus…
Three independent research efforts presented at Black Hat USA 2026 and in subsequent disclosures have demonstrated practical attacks against passkey implementations, undermining…
Attackers breached an organization's Oracle database via a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit named…
GoFlyDrv.sys is a vulnerable driver abused by Cruciferra as part of bring-your-own-vulnerable-driver (BYOVD) attacks to terminate security processes on Windows systems.
The operators of the DevMan ransomware-as-a-service (RaaS) scheme maintain a dedicated web platform that offers affiliates the ability to build payloads, oversee…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…