How to find out if your servers have been attacked
New malware uses MQTT and Matrix protocols to talk to C2
A user with minimal privileges can gain control over the domain
Schools and universities are hacked through stolen accounts and outdated software
Guts of ransomware, Bitlocker abuse, and a workshop on investigative skills
Command & control addresses are transmitted in BNB Smart Chain and Solana transactions
Incidents in Latin America show how secure configuration could prevent encryption
Our Compromise Assessment service report features such a hidden threat as generative AI
Users receive attackers’ remote access tool along with popular freeware
How to detect malware that runs on Linux systems without writing on disk
Some stats on threats found in backups during compromise assessment
New attacks use .vbs droppers, .com droppers, and .com stealer written in Rust
Registration of a malicious provider can be detected in ProviderOrder and ProviderPath parameters
Detecting privilege escalation in Linux through TOCTOU vulnerability
A 2020 vulnerability still allows a local user to elevate privileges to SYSTEM
Vulnerability CVE-2025-47179 allows for full control over SCCM
Catching exploitation of a vulnerability that antiviruses don’t see
How to prevent exploitation of a vulnerability in a popular image editing tool
A chain of events 4023 and 4021 from the same IP address means an attack
Severe vulnerability allows an unprivileged user to gain root