How to find out if your servers have been attacked
New malware uses MQTT and Matrix protocols to talk to C2
Schools and universities are hacked through stolen accounts and outdated software
Guts of ransomware, Bitlocker abuse, and a workshop on investigative skills
Trust relationships between domains facilitate various attacks
Command & control addresses are transmitted in BNB Smart Chain and Solana transactions
Incidents in Latin America show how secure configuration could prevent encryption
Our Compromise Assessment service report features such a hidden threat as generative AI
Users receive attackers’ remote access tool along with popular freeware
Some stats on threats found in backups during compromise assessment
New attacks use .vbs droppers, .com droppers, and .com stealer written in Rust
Registration of a malicious provider can be detected in ProviderOrder and ProviderPath parameters
What if your decompiler doesn’t support some RISC-V instructions
A 2020 vulnerability still allows a local user to elevate privileges to SYSTEM
Vulnerability CVE-2025-47179 allows for full control over SCCM
A chain of events 4023 and 4021 from the same IP address means an attack
We found out which local LLMs are better at finding vulnerabilities
Severe vulnerability allows an unprivileged user to gain root
Fake RPC server can impersonate the security context of the calling client, up to SYSTEM
We found a vulnerabilty in a popular LLM agent