Detection & threat hunting
Detection engineering, threat hunting, and the SIEM and endpoint signals that catch attacks the network can't see.
TerminalFix moves ClickFix into the terminal to slip past the defenses built for the Run box
Microsoft documented TerminalFix, a ClickFix variant that pastes PowerShell into Windows Terminal to plant a reverse-tunnel backdoor. Here is what to detect.
Fire Ant compromised Cisco routers and TACACS servers, stole admin credentials, and rewrote logs to hide
China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, stole live admin credentials, and rewrote logs to stay invisible. How to detect it.
Thousands of leaked AWS keys still work, and 768 give attackers full account control
Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.
Defender's own signed driver can delete your security tools at boot, and Microsoft won't patch it
Check Point turned Microsoft Defender's built-in BTR.sys driver into a kernel tool that deletes security software at boot.
TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen
TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.
Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it
CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.
Command execution was the week's most common bug. Self-hosted software is why.
Command injection and RCE led our threat desk's triage this week at 370, more than any other class.
Mustang Panda's kernel rootkit hides its backdoor from host tools
Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.
Akira ransomware reboots Windows into Safe Mode to shut off security tools
An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.
China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor
Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.
Malware can use Windows Hello keys to sign into Entra ID as you
Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.
A signed ScreenConnect installer becomes a backdoor after malware turns Defender off
The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.
Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA
Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.
N-able N-central auth bypass grants admin; first fix failed
N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.
Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on
Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.
Cisco's firewall management software has a hardcoded password, and attackers are already using it
Cisco Secure Firewall Management Center ships a static password (CVE-2026-20316) that lets unauthenticated attackers log in. Now in CISA KEV. Patch and hunt.
For this week's most-exploited bugs, the patch was the easy part
This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.
Any domain user can now DCSync your forest. Certighost is why.
CVE-2026-54121 lets a standard Active Directory user impersonate a domain controller through AD CS and run DCSync.
You patched SharePoint three times this month. The key attackers want is still in the lock.
CVE-2026-50522, a CVSS 9.8 SharePoint RCE, went from public PoC to active exploitation in hours.
HollowGraph turns Microsoft 365 into a C2 channel with no patch
HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.
ACR Stealer steals live sessions. A password reset won't help.
ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.
A booby-trapped code repository can hijack a Windows PC the moment you open it in Cursor
A malicious repository can run code when opened in Cursor on Windows through a planted git.exe. CVE-2026-63093 has no patch yet. How to detect and contain it.
SharePoint's new RCE is live, and patching alone won't clean it
CVE-2026-58644, a SharePoint deserialization RCE, is in CISA's KEV catalog and exploited as a zero-day. Patching alone won't evict an attacker who stole keys.
AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.
Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.
A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.
An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.
Ghost accounts are mapping your GitHub org. The recon is invisible; the stolen token is not.
Datadog found 50+ dormant GitHub accounts enumerating corporate orgs through the public API, some escalating to private-repo clones with stolen tokens.
Three attacks in one week turned AI coding agents into an unmonitored way onto your network
HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer's privileges. No CVE, no patch. Here is the detection posture.
A Google chatbot 'edit' permission was really a code-execution grant
Google's Dialogflow CX let one edit permission run code across every chatbot in a project.
How to Use the Wazuh API: Authenticate, Query Agents, and Automate
How to use the Wazuh API: authenticate on port 55000 for a JWT token, then query your agents and automate with copy-pasteable curl commands and a worked
Scattered Spider keeps winning because your help desk, not a CVE, is the way in
An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.
Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it
ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.
How to Use Wazuh: A Practitioner's Guide to Agents, the Dashboard, and Detection
How to use Wazuh: install the server, enroll an agent, reach the dashboard, and write and test a detection rule with wazuh-logtest.
This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.
A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.
What is MITRE ATT&CK? Tactics, techniques, and how defenders actually use it
A plain-English guide to MITRE ATT&CK: what it is, how its tactics and techniques are organized, a real intrusion mapped step by step, and how defenders use it.
What is a SIEM, in plain terms (and how it differs from a SOC and EDR)
What a SIEM is, what it actually does, and how it differs from a SOC, an EDR, and plain log management - explained by a team that runs one.
Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them
Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.
PixelSmash: a video your server opens by itself can run an attacker's code
PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.
Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can't see it.
Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.
Prinz Eugen ransomware hits your newest files first and never leaves a note
Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.
Your AI agent trusts your own computer. One web page turns that into a takeover.
Microsoft's AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.
EDR evasion is now a shipped product. Your agent's silence is the only alarm left.
The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.
DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.
DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.
Your Splunk box runs a database sidecar you never configured. Attackers use it for root.
CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.
ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect
Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.
FortiBleed isn't a Fortinet bug. It's every password you never rotated.
FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.
A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load
SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.
Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.
OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.
Why we built Suriq on Wazuh instead of writing our own detection engine
Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.