Home/ Blog/ Topics/ Detection & threat hunting
Topic

Detection & threat hunting

Detection engineering, threat hunting, and the SIEM and endpoint signals that catch attacks the network can't see.

Security news

TerminalFix moves ClickFix into the terminal to slip past the defenses built for the Run box

Microsoft documented TerminalFix, a ClickFix variant that pastes PowerShell into Windows Terminal to plant a reverse-tunnel backdoor. Here is what to detect.

Security news

Fire Ant compromised Cisco routers and TACACS servers, stole admin credentials, and rewrote logs to hide

China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, stole live admin credentials, and rewrote logs to stay invisible. How to detect it.

Security news

Thousands of leaked AWS keys still work, and 768 give attackers full account control

Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.

Security news

Defender's own signed driver can delete your security tools at boot, and Microsoft won't patch it

Check Point turned Microsoft Defender's built-in BTR.sys driver into a kernel tool that deletes security software at boot.

Security news

TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen

TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.

Security news

Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it

CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.

Deep dive

Command execution was the week's most common bug. Self-hosted software is why.

Command injection and RCE led our threat desk's triage this week at 370, more than any other class.

Security news

Mustang Panda's kernel rootkit hides its backdoor from host tools

Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.

Security news

Akira ransomware reboots Windows into Safe Mode to shut off security tools

An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.

Security news

China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor

Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.

Security news

Malware can use Windows Hello keys to sign into Entra ID as you

Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.

Security news

A signed ScreenConnect installer becomes a backdoor after malware turns Defender off

The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.

Security news

Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA

Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.

Security news

N-able N-central auth bypass grants admin; first fix failed

N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.

Security news

Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on

Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.

Security news

Cisco's firewall management software has a hardcoded password, and attackers are already using it

Cisco Secure Firewall Management Center ships a static password (CVE-2026-20316) that lets unauthenticated attackers log in. Now in CISA KEV. Patch and hunt.

Deep dive

For this week's most-exploited bugs, the patch was the easy part

This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.

Security news

Any domain user can now DCSync your forest. Certighost is why.

CVE-2026-54121 lets a standard Active Directory user impersonate a domain controller through AD CS and run DCSync.

Security news

You patched SharePoint three times this month. The key attackers want is still in the lock.

CVE-2026-50522, a CVSS 9.8 SharePoint RCE, went from public PoC to active exploitation in hours.

Security news

HollowGraph turns Microsoft 365 into a C2 channel with no patch

HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.

Security news

ACR Stealer steals live sessions. A password reset won't help.

ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.

Security news

A booby-trapped code repository can hijack a Windows PC the moment you open it in Cursor

A malicious repository can run code when opened in Cursor on Windows through a planted git.exe. CVE-2026-63093 has no patch yet. How to detect and contain it.

Security news

SharePoint's new RCE is live, and patching alone won't clean it

CVE-2026-58644, a SharePoint deserialization RCE, is in CISA's KEV catalog and exploited as a zero-day. Patching alone won't evict an attacker who stole keys.

Security news

AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.

Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.

Security news

A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.

An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.

Security news

Ghost accounts are mapping your GitHub org. The recon is invisible; the stolen token is not.

Datadog found 50+ dormant GitHub accounts enumerating corporate orgs through the public API, some escalating to private-repo clones with stolen tokens.

Security news

Three attacks in one week turned AI coding agents into an unmonitored way onto your network

HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer's privileges. No CVE, no patch. Here is the detection posture.

Security news

A Google chatbot 'edit' permission was really a code-execution grant

Google's Dialogflow CX let one edit permission run code across every chatbot in a project.

Explainers

How to Use the Wazuh API: Authenticate, Query Agents, and Automate

How to use the Wazuh API: authenticate on port 55000 for a JWT token, then query your agents and automate with copy-pasteable curl commands and a worked

Security news

Scattered Spider keeps winning because your help desk, not a CVE, is the way in

An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.

Security news

Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it

ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.

Explainers

How to Use Wazuh: A Practitioner's Guide to Agents, the Dashboard, and Detection

How to use Wazuh: install the server, enroll an agent, reach the dashboard, and write and test a detection rule with wazuh-logtest.

Security news

This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.

A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.

Explainers

What is MITRE ATT&CK? Tactics, techniques, and how defenders actually use it

A plain-English guide to MITRE ATT&CK: what it is, how its tactics and techniques are organized, a real intrusion mapped step by step, and how defenders use it.

Explainers

What is a SIEM, in plain terms (and how it differs from a SOC and EDR)

What a SIEM is, what it actually does, and how it differs from a SOC, an EDR, and plain log management - explained by a team that runs one.

Security news

Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them

Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.

Security news

PixelSmash: a video your server opens by itself can run an attacker's code

PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.

Security news

Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can't see it.

Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.

Security news

Prinz Eugen ransomware hits your newest files first and never leaves a note

Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.

Security news

Your AI agent trusts your own computer. One web page turns that into a takeover.

Microsoft's AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.

Security news

EDR evasion is now a shipped product. Your agent's silence is the only alarm left.

The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.

Security news

DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.

DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.

Security news

Your Splunk box runs a database sidecar you never configured. Attackers use it for root.

CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.

Security news

ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect

Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.

Security news

FortiBleed isn't a Fortinet bug. It's every password you never rotated.

FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.

Security news

A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load

SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.

Security news

Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.

OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.

Thought leadership

Why we built Suriq on Wazuh instead of writing our own detection engine

Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.