PCPcat Campaign: Mass Exploitation of Server-Side Rendering in Modern JavaScript Stacks
Executive Context PCPcat emerged during mid-December as one of the largest application-layer compromises of modern JavaScript web…
continue reading..
AshTag Espionage: Inside a Stealth Diplomatic Cyber-Intelligence Campaign
Executive Summary AshTag is a long-running, intelligence-focused cyber-espionage campaign attributed to the threat actor commonly tracked as…
continue reading..
Gentlemen Ransomware: A Global Enterprise Disruption Campaign
1. Executive Summary Gentlemen ransomware is a modern, enterprise-focused ransomware operation that emerged in August 2025 and…
continue reading..
Real-world malware families using Boot or Logon Autostart Execution
Below is an operational, SOC-ready expansion of Boot or Logon Autostart Execution (T1547), mapping it to real-world…
continue reading..
Boot or Logon Autostart Execution (MITRE ATT&CK T1547)
Boot or Logon Autostart Execution is a persistence technique where an adversary configures malware or malicious scripts…
continue reading..
Iranian-linked APT known as Infy / Prince of Persia resurfacing after years of apparent silence
After several years of relative silence, the Iran-linked advanced persistent threat group known as APT Infy, also…
continue reading..
CVE-2025-37164: Unauthenticated Remote Code Execution in HPE OneView
Vulnerability Summary High-Level Summary CVE-2025-37164 is a critical security flaw in HPE OneView that allows a remote…
continue reading..
When YouTube Becomes the Vector: Malware Delivered Through Trusted Content
Executive Summary A widespread malware campaign is actively abusing YouTube videos and cracked software downloads to infect…
continue reading..
Process Injection Explained: Techniques, Detection, Defense
Process Injection is a technique where an attacker forces malicious code to execute inside the memory space…
continue reading..
