Sogou's Link Handler Let UNC3569 Install GRAYRABBIT
A crafted Sogou URI reached an old, unsandboxed Chromium renderer. Verify the fixed build, then hunt the process, file, and network chain.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
A crafted Sogou URI reached an old, unsandboxed Chromium renderer. Verify the fixed build, then hunt the process, file, and network chain.
Read article →Four espionage groups used a shared Chrome-to-Windows exploit chain. Build checks show current exposure; campaign artifacts support a separate compromise hunt.
Read article →More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
Read article →CISA confirms exploitation of CVE-2026-84869. ScreenConnect clients before 26.6.5 can transfer and run files through active sessions without authorization or host confirmation.
Read article →CloudSEK found BigBear 2.0 stealing Microsoft 365 session cookies after MFA. Revoke sessions, rotate credentials and require phishing-resistant sign-in.
Read article →Two certificate-processing flaws reach gateways and management servers. Fixed takes and LivePatch output give operators a direct protection check.
Read article →Attackers used Cisco Secure FMC flaws to reach root, steal credentials, tunnel into networks, deploy Cyclops Blink, and encrypt selected endpoints with Qilin.
Read article →Kestra OSS versions through 1.3.20 let unauthenticated requests create workflows and run commands as root inside workers. CISA confirms exploitation.
Read article →Chrome 153 fixes exploited V8 out-of-bounds write CVE-2026-87491 across desktop and Android. Fleet owners should verify running builds; Google published no attack indicators.
Read article →CISA confirmed exploitation of CVE-2025-25249 across FortiOS, FortiSwitchManager and FortiSASE, with federal remediation due September 12.
Read article →CISA now links CVE-2025-14733 to ransomware. Patch exposed Fireboxes, check WatchGuard's indicators, and rotate locally stored secrets after confirmed activity.
Read article →A recovered Sliver kit shows how one operator scripted Domain Admin access, disabled defenses, stole credentials, and hid rotating command servers behind Ethereum.
Read article →The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →