Arcane Werewolf and the Stealth Infiltration of Russian Manufacturing
Arcane Werewolf, sometimes discussed alongside the “Mythic Likho” campaign name, is a threat cluster reported by security…
continue reading..
Goffee Cyberespionage Campaign: Technical Analysis of a Targeted Operation Against Russian Military and Defense Organizations
The Goffee cyberespionage group has conducted a targeted espionage campaign against Russian military personnel and defense-industry organizations.…
continue reading..
M365 Device Code Phishing : When MFA Works Against You
UNK_AcademicFlare is a Russia-linked threat actor (the “UNK” prefix usually means unattributed / newly tracked) observed abusing…
continue reading..
WebRAT via GitHub: Proof-of-Concepts as a Malware Delivery Channel
Fake Exploit Code as an Active Malware Distribution Channel (Dec 23) The security research ecosystem is increasingly…
continue reading..
Shai-Hulud: When npm Installs Became a Worm
Shai-Hulud Campaign: Why This Attack Is Different The Shai-Hulud campaign marks a turning point in how supply…
continue reading..
CVE-2025-11419: Red Hat Keycloak TLS Client-Initiated Renegotiation DoS
Vulnerability Header Attribute Details CVE ID CVE-2025-11419 CVSS Score 7.5 (High) Severity High / Important Published December…
continue reading..
CVE-2025-61882: Critical Oracle E-Business Suite Vulnerability Being Actively Exploited by Cl0p Ransomware Group
What’s Going On Right Now On December 23, 2024, Oracle issued a critical security advisory for a…
continue reading..
Stealka Infostealer: The Windows Malware Stealing Your Cryptocurrency and Passwords Right Now
What’s Actually Going On There’s a piece of malware called Stealka that’s been actively spreading since December…
continue reading..
Malicious npm Package “lotusbail” Discovered: WhatsApp Credential Theft and Backdoor Installation
Package Overview Aspect Details Package Name lotusbail Package Registry npm Package Type Malicious Library Masquerade Target WhatsApp…
continue reading..
