Sogou's Link Handler Let UNC3569 Install GRAYRABBIT
A crafted Sogou URI reached an old, unsandboxed Chromium renderer. Verify the fixed build, then hunt the process, file, and network chain.
Read article →Reader view
Choose the default article length.
Endpoint security, malware, device controls, and host visibility.
A crafted Sogou URI reached an old, unsandboxed Chromium renderer. Verify the fixed build, then hunt the process, file, and network chain.
Read article →Four espionage groups used a shared Chrome-to-Windows exploit chain. Build checks show current exposure; campaign artifacts support a separate compromise hunt.
Read article →CISA confirms exploitation of CVE-2026-84869. ScreenConnect clients before 26.6.5 can transfer and run files through active sessions without authorization or host confirmation.
Read article →AOMEI Backupper 8.4.0 exposes physical-disk writes to local users. Without Secure Boot, attackers can plant UEFI code that runs before Windows defenses.
Read article →Chrome 153 fixes exploited V8 out-of-bounds write CVE-2026-87491 across desktop and Android. Fleet owners should verify running builds; Google published no attack indicators.
Read article →A recovered Sliver kit shows how one operator scripted Domain Admin access, disabled defenses, stole credentials, and hid rotating command servers behind Ethereum.
Read article →The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Read article →Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Read article →Chrome 152.0.7977.82/.83 fixes an exploited V8 type-confusion flaw. Google has not disclosed the attackers, targets, exploit chain, or scale.
Read article →A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Read article →Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
Read article →