Posts
- Six permission bypasses in Mistral Vibe (September 11, 2026)
- GreatXML: Technical and Defensive Analysis of a BitLocker Bypass via WinRE (June 12, 2026)
- RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday (June 10, 2026)
- Project Glasswing (May 27, 2026)
- Microsoft Patch Tuesday May 2026 (May 16, 2026)
- MiniPlasma: Chaotic Eclipse Reopens cldflt.sys (May 16, 2026)
- Reading Root-Owned Files Without Privilege (May 16, 2026)
- A vulnerability in the opcode cache of Zen 2 processors (May 15, 2026)
- What AI Is Changing in Responsible Disclosure (May 15, 2026)
- Two Windows zero-days disclosed without coordination (May 15, 2026)
- CVE-2026-40361: zero-click use-after-free vulnerability in the Outlook rendering engine (wwlib.dll) (May 15, 2026)
- Dirty Frag (CVE-2026-43284 and CVE-2026-43500) (May 9, 2026)
- Microsoft Patch Tuesday April 2026 (April 14, 2026)
- INTELLIGENCE REPORT : AGRIUS (Agonizing Serpens) (March 21, 2026)
- INTELLIGENCE REPORT : APT42 (March 21, 2026)
- INTELLIGENCE REPORT : MERCURY (MuddyWater) (March 21, 2026)
- INTELLIGENCE REPORT — APT39 (March 21, 2026)
- Russian Intelligence Services Espionage Campaign Targeting Signal Accounts and Encrypted Messaging Applications (March 21, 2026)
- INTELLIGENCE REPORT — APT35 (March 17, 2026)
- INTELLIGENCE REPORT - APT33 (March 16, 2026)
- INTELLIGENCE REPORT — HANDALA / HANDALA HACK TEAM (March 16, 2026)
- INTELLIGENCE REPORT — APT34 (March 15, 2026)
- Microsoft OOB hotpatch KB5084597 addresses three RCE vulnerabilities in RRAS MMC snap-in (March 15, 2026)
- Microsoft Patch Tuesday March 2026: 79 Vulnerabilities, Two Zero-Days, First CVE Credited to an AI Agent (March 12, 2026)
- Full CTI analysis of the ANSSI 2025 Cyber Threat Panorama (CERTFR-2026-CTI-002) (March 12, 2026)
- RESURGE: In-Depth Analysis of a Persistent Implant on Ivanti Connect Secure (February 27, 2026)
- Azul: Large-Scale Open-Source Malware Analysis Framework Released by ASD (February 24, 2026)
- Generative Artificial Intelligence and Cyber Attacks (February 4, 2026)
- UAC-0001 (APT28) Actively Exploits CVE-2026-21509 via Microsoft Office to Target Ukraine and EU Countries (February 3, 2026)
- Fortinet Releases Patches Following Active Exploitation of CVE-2026-24858 (January 28, 2026)
- January 2026 Patch Tuesday (January 14, 2026)
- UAC-0190 Targeted Attacks Against Ukraine’s Defense Forces Using the PLUGGYAPE Malware (January 12, 2026)
- NIST IR 8597: Publication of Interagency Report on Cloud Token and Assertion Protection (December 22, 2025)
- Top 25 CWE 2025 – Technical Analysis (December 11, 2025)
- Pro-Russia Hacktivists: Opportunistic Attacks Against US and Global Critical Infrastructure (December 10, 2025)
- Microsoft Patch Tuesday, December 2025. (December 9, 2025)
- Spyware Targeting Secure Mobile Messaging Applications (November 28, 2025)
- Shai-Hulud worm infects over 800 npm packages and leaks developer secrets on GitHub (November 24, 2025)
- CERT-UA Alert about UAC-0241 (November 24, 2025)
- From Diplomatic Tension to Critical Incident (November 24, 2025)
- Mitigating Risks from Bulletproof Hosting Providers (November 23, 2025)
- DNS4EU: Towards a Sovereign, Secure, and Privacy-Respecting European DNS (November 16, 2025)
- Technical Analysis of FortiWeb Vulnerability CVE-2025-64446 (November 16, 2025)
- Microsoft Patch Tuesday – November 2025 (November 11, 2025)
- Comparative review of cybersecurity taxonomies used by CSIRTs, CERTs, and SOCs (November 9, 2025)
- Microsoft Exchange Server On-Premises: Security Best Practices (October 31, 2025)
- The Ideal Workstation for a CERT Analyst: Incident Response, Forensics, and CTI (October 24, 2025)
- Governance Issues Related to Adopting Open Source in Financial (October 24, 2025)
- F5 Breach: BIG-IP Source Code and Vulnerabilities Stolen by Sophisticated Nation-State Actor (October 18, 2025)
- October 2025 Patch Tuesday – 172 flaws fixed including 6 zero-days (Windows 10 end-of-support) (October 17, 2025)
- UAC-0239 Conducts Cyberattacks in Ukraine Using the OrcaC2 Framework and FILEMESS Stealer (October 15, 2025)
- Generative AI in the Enterprise: Anatomy of a Silent Catastrophe (October 12, 2025)
- RFC 9794: Terminology for Post-Quantum Traditional Hybrid Schemes (October 4, 2025)
- Red Hat data breach: analysis for CISOs, CERTs, CSIRTs and SOC teams (October 2, 2025)
- RPM 6.0.0: how I actually secure my open-source supply chain (September 28, 2025)
- CISA Case Study: Preparation, Monitoring, and Remediation in the Face of Compromise (September 24, 2025)
- U.S. Secret Service Dismantles an Imminent Telecommunications Threat in the New York Tristate Area (September 23, 2025)
- Threat Report on Node Package Manager (NPM) Repository Attacks (September 20, 2025)
- Analysis of the Compromise of Ivanti Endpoint Manager Mobile Systems (EPMM) – CISA MAR AR25-261A (September 19, 2025)
- FBI Alert: Malicious Activities by UNC6040 and UNC6395 Targeting Salesforce (September 14, 2025)
- Microsoft September 2025 Patch Tuesday (September 10, 2025)
- APT-C-53 (Gamaredon): Attack Campaign Targeting Ukrainian Government Entities (September 9, 2025)
- Massive npm Package Compromise Aimed at Stealing Cryptocurrency (September 9, 2025)
- Scattered Spider: Profile, Techniques, and Impact of a Cybercriminal Group (September 3, 2025)
- Salesloft Breach: More Than 700 Companies Impacted by the Attack (September 2, 2025)
- CVE-2025-7775 – Memory Overflow Vulnerability in Citrix NetScaler (August 26, 2025)
- APT29 — Factual Brief (August 23, 2025)
- Secret Messengers (NSA/GCHQ, 2025) (August 17, 2025)
- ShinyHunters, Scattered Spider and sp1d3rhunters Malware (August 16, 2025)
- Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments (August 7, 2025)
- CISA Vulnerability Summary – Week of July 21, 2025 (July 29, 2025)
- The Pomodoro Technique in a CERT/CSIRT Environment: My Field Experience (July 26, 2025)
- How the MIKRONET Toolkit Compromises MikroTik Routers (July 25, 2025)
- The Interlock Ransomware and the Joint Cybersecurity Advisory of July 22, 2025 (July 23, 2025)
- The XSS Cybercrime Forum and the Arrest of Its Administrator (July 23, 2025)
- CISA Weekly Vulnerability Summary – Week of July 14, 2025 (July 22, 2025)
- Cyberattacks by Group UAC-0001 (APT28) Targeting Government Institutions – BEARDSHELL and COVENANT (June 23, 2025)



