Counterfeit Installer Campaign Shows Why Download Telemetry Matters Microsoft's latest campaign analysis is a useful reminder that initial access does not alway...
Lucas Oliveira
Research
TrueConf KEV Flaws: When a Video Server Becomes a Malware Distribution Point CISA has added two exploited TrueConf Server vulnerabilities to its Known Exploited...
Lucas Oliveira
Research
Russian Zimbra Campaign Turns Email Preview Into an Exfiltration Path The latest joint warning on Zimbra is worth treating as more than another [phishing](https...
Lucas Oliveira
Research
Iran-linked PLC attacks show why internet-exposed OT is now an incident-response priority U.S. agencies have updated their warning on Iran-affiliated cyber acti...
Lucas Oliveira
Research
Oracle PeopleSoft alert follows breach claims at 100+ organizations Claims of mass compromise across Oracle PeopleSoft environments were already serious on June...
Lucas Oliveira
Research
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure | 2026 Executive Summary Push Security disclosed a live campaign it tracks as LLMShare, w...
Lucas Oliveira
Research
GlassWorm takedown shows how developer malware becomes supply-chain risk Executive Summary The coordinated disruption of GlassWorm on May 26, 2026 is useful bec...
Lucas Oliveira
Research
AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking Executive Summary Microsoft disclosed an active campaign on May 26, 2026 in which attackers push...
Lucas Oliveira
Research
Kazuar’s redesign turns a familiar backdoor into a harder-to-hunt botnet Microsoft’s latest research on Kazuar matters because it reframes the malware from a we...
Lucas Oliveira
Research
TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels The most important detail in Elastic's new TCLBANKER research is not just that a Bra...
Lucas Oliveira
Research
DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path The most important part of the DAEMON Tools incident is not that malware...
Lucas Oliveira
Research
CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets CVE-2026-41940 is a critical authentication bypass in cPanel and WHM, an...
Lucas Oliveira
Research