BINDCLOAK Duplicates Windows Tokens to Run Modules as Another User
BINDCLOAK collects Windows user and process tokens, duplicates them, and starts modular malware components inside more privileged security contexts.
Read article →Reader view
Choose the default article length.
Endpoint security, malware, device controls, and host visibility.
BINDCLOAK collects Windows user and process tokens, duplicates them, and starts modular malware components inside more privileged security contexts.
Read article →SpecterOps shows how relayed WSUS machine-account access can forge targeted updates and bypass payload signature checks when SUSDB runs on a separate SQL Server.
Read article →Langflow, N-central, and Tomcat flaws entered CISA's exploited catalog. One gives unauthenticated callers Python execution by default.
Read article →A targeted npm cluster split its downloader across ordinary-looking modules, then escaped Node.js vm isolation to install a cross-platform RAT on developer systems using Alibaba tools.
Read article →Flare found that BTMOB's official operation now sits among resellers, source-code buyers, private servers, and offers of uncertain authenticity, weakening infrastructure-only detection.
Read article →The service preloads a payload-bearing PNG, copies a browser-specific command, and keys the final in-memory stage to the victim's public IP address.
Read article →Unit 42 showed three post-compromise paths from Chrome's local passkey state to silent assertions, substituted verification keys, or the master secret protecting synced credentials.
Read article →Chrome fixed more security bugs in two milestones than in the previous 23 while using AI across discovery, triage and fix preparation.
Read article →N-central operators need Hotfix 2 build 2026.3.1.10 and a downstream endpoint hunt because the new release supersedes the first hotfix.
Read article →A ServiceWorker and SharedWorker combine a clean Bun runtime, delivered PE sections, and locally generated bytes before a same-origin download.
Read article →A poisoned build can start a memory-resident loader, re-arm through macOS preferences, and seed more projects, Git hooks, and archives.
Read article →Kaspersky found BridgeHead using Windows SSO to cross corporate proxies before relaying server-selected TCP traffic through compromised hosts.
Read article →The botnet spread through developer extensions and packages, then used stolen credentials to force-push malicious code into default branches.
Read article →