Category: CTI & OSINT

Threat analyses, actor profiles and case studies drawn from threat intelligence and open sources. Threat modelling, indicators of compromise, adversary analysis, OSINT, APT and ransomware campaigns.

Oracle’s September 2026 CSPU: 673 security patches

Oracle released 673 security patches on 15 September 2026, 247 of them for vulnerabilities that are remotely exploitable without authentication. Six carry the maximum score of 10.0, five of those in Fusion Middleware. TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use. Published 16 September 2026 Subject Oracle, September 2026 CSPU Distribution Public Confidence…

GreatXML: Technical and Defensive Analysis of a BitLocker Bypass via WinRE

1. Executive summary GreatXML is a public proof-of-concept, released on 10 June 2026 by the researcher Nightmare Eclipse / Chaotic Eclipse / MSNightmare, claiming a BitLocker bypass. The technique abuses the Windows Recovery Environment (WinRE), the state left behind by Microsoft Defender’s Offline Scan feature, and the legitimate processing of unattended setup answer files (unattend.xml).…

RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday

RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday Threat Intelligence · Vulnerability June 10, 2026 · Marc-Frédéric Gomez · 6 min read Just hours after the June 2026 fixes shipped, the researcher Nightmare Eclipse published a new exploit targeting Microsoft Defender. It works against Windows systems that are already up…

MiniPlasma: Chaotic Eclipse Reopens cldflt.sys 

CTI Analysis · Unpatched Windows Vulnerability MiniPlasma: Chaotic Eclipse Reopens cldflt.sys and Revives the Question of Microsoft Patch Durability A fifth uncoordinated public disclosure in six weeks, a PoC targeting the Windows Cloud Files Mini Filter Driver, and an extraordinary claim: the CVE-2020-17103 patch would not be present on fully patched Windows 11 and Windows…

What AI Is Changing in Responsible Disclosure

CTI Analysis · Disclosure Doctrine The Embargo Is No Longer a Protection: What AI Is Changing in Responsible Disclosure Six dnsmasq CVEs, a maintainer exhausted by the tsunami of AI-generated bug reports, and the public admission of a major doctrinal pivot. Reading a weak signal that could foreshadow the end of a model thirty years…

Two Windows zero-days disclosed without coordination

CTI Analysis · Critical Vulnerability BitLocker Is No Longer a Promise: What the YellowKey Case Reveals Two Windows zero-days disclosed without coordination, a researcher openly challenging Microsoft, and a phantom component in the Windows Recovery Environment whose true nature, bug or backdoor, no one can yet determine. Published May 14, 2026 Reading time 15 minutes…

CVE-2026-40361: zero-click use-after-free vulnerability in the Outlook rendering engine (wwlib.dll)

Remote code execution via the Reading Pane, without user interaction Executive summary On May 12, 2026, as part of the monthly Patch Tuesday cycle, Microsoft released a fix for CVE-2026-40361, a critical use-after-free vulnerability (CWE-416) officially classified by the vendor as a “Microsoft Office Word Remote Code Execution Vulnerability” (1) (2). Researcher Haifei Li, founder…

INTELLIGENCE REPORT : AGRIUS (Agonizing Serpens)

TLP:CLEAR | CTI Team | Updated: March 2026 1. IDENTIFICATION & ATTRIBUTION Designations (vendor aliases) The group is tracked under the following designations: Agrius (SentinelLabs), Agonizing Serpens (Palo Alto Networks Unit 42), Pink Sandstorm (Microsoft, formerly Americium), Marshtreader (Security.com), BlackShadow (public hack-and-leak persona), DEV-0022 (Microsoft pre-attribution). Additional alias: G1030 (MITRE ATT&CK). Origin Iran. Presumed sponsor…