#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
New.
"The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."
Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/ @Rapid7Official #infosec #threatresearch #Linux
-
New.
"The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."
Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/ @Rapid7Official #infosec #threatresearch #Linux
-
New.
"The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."
Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/ @Rapid7Official #infosec #threatresearch #Linux
-
New.
"The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."
Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/ @Rapid7Official #infosec #threatresearch #Linux
-
New.
Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX https://socket.dev/blog/glassworm-vscode-themes @SocketSecurity #infosec #threatresearch #JavaScript #Git
-
New.
Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX https://socket.dev/blog/glassworm-vscode-themes @SocketSecurity #infosec #threatresearch #JavaScript #Git
-
New.
Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX https://socket.dev/blog/glassworm-vscode-themes @SocketSecurity #infosec #threatresearch #JavaScript #Git
-
New.
Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX https://socket.dev/blog/glassworm-vscode-themes @SocketSecurity #infosec #threatresearch #JavaScript #Git
-
New.
Zscaler: Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims https://www.zscaler.com/blogs/security-research/ransomware-data-theft-surged-275-2026-schools-hospitals-and-government
Speaking of ransomware, here are the latest targets:
US - Associated Gastroenterologists of Central New York https://ransomware.live/id/QVNTT0NJQVRFRCBHQVNUUk9FTlRFUk9MT0dJU1RTIE9GIENFTlRSQUwgTkVXIFlPUkssIFAuQ0BCb29iYSBQcm9qZWN0
Graybar Electric Company, Inc. https://ransomware.live/id/R3JheWJhciBFbGVjdHJpYyBDb21wYW55LCBJbmMuQFJlZGFjdA
Guardian Pharmacy LLC https://ransomware.live/id/R3VhcmRpYW4gUGhhcm1hY3kgTExDQGluY3JhbnNvbQ
Northern Counties Health Care https://ransomware.live/id/Tm9ydGhlcm4gQ291bnRpZXMgSGVhbHRoIENhcmVAaW5jcmFuc29t
UK: Parkdental.com https://ransomware.live/id/cGFya2RlbnRhbC5jb21AY2hhb3M
A lot more: https://ransomware.live/ #infosec #ransomware #threatresearch
-
New.
Zscaler: Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims https://www.zscaler.com/blogs/security-research/ransomware-data-theft-surged-275-2026-schools-hospitals-and-government
Speaking of ransomware, here are the latest targets:
US - Associated Gastroenterologists of Central New York https://ransomware.live/id/QVNTT0NJQVRFRCBHQVNUUk9FTlRFUk9MT0dJU1RTIE9GIENFTlRSQUwgTkVXIFlPUkssIFAuQ0BCb29iYSBQcm9qZWN0
Graybar Electric Company, Inc. https://ransomware.live/id/R3JheWJhciBFbGVjdHJpYyBDb21wYW55LCBJbmMuQFJlZGFjdA
Guardian Pharmacy LLC https://ransomware.live/id/R3VhcmRpYW4gUGhhcm1hY3kgTExDQGluY3JhbnNvbQ
Northern Counties Health Care https://ransomware.live/id/Tm9ydGhlcm4gQ291bnRpZXMgSGVhbHRoIENhcmVAaW5jcmFuc29t
UK: Parkdental.com https://ransomware.live/id/cGFya2RlbnRhbC5jb21AY2hhb3M
A lot more: https://ransomware.live/ #infosec #ransomware #threatresearch
-
New.
Zscaler: Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims https://www.zscaler.com/blogs/security-research/ransomware-data-theft-surged-275-2026-schools-hospitals-and-government
Speaking of ransomware, here are the latest targets:
US - Associated Gastroenterologists of Central New York https://ransomware.live/id/QVNTT0NJQVRFRCBHQVNUUk9FTlRFUk9MT0dJU1RTIE9GIENFTlRSQUwgTkVXIFlPUkssIFAuQ0BCb29iYSBQcm9qZWN0
Graybar Electric Company, Inc. https://ransomware.live/id/R3JheWJhciBFbGVjdHJpYyBDb21wYW55LCBJbmMuQFJlZGFjdA
Guardian Pharmacy LLC https://ransomware.live/id/R3VhcmRpYW4gUGhhcm1hY3kgTExDQGluY3JhbnNvbQ
Northern Counties Health Care https://ransomware.live/id/Tm9ydGhlcm4gQ291bnRpZXMgSGVhbHRoIENhcmVAaW5jcmFuc29t
UK: Parkdental.com https://ransomware.live/id/cGFya2RlbnRhbC5jb21AY2hhb3M
A lot more: https://ransomware.live/ #infosec #ransomware #threatresearch
-
New.
Zscaler: Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims https://www.zscaler.com/blogs/security-research/ransomware-data-theft-surged-275-2026-schools-hospitals-and-government
Speaking of ransomware, here are the latest targets:
US - Associated Gastroenterologists of Central New York https://ransomware.live/id/QVNTT0NJQVRFRCBHQVNUUk9FTlRFUk9MT0dJU1RTIE9GIENFTlRSQUwgTkVXIFlPUkssIFAuQ0BCb29iYSBQcm9qZWN0
Graybar Electric Company, Inc. https://ransomware.live/id/R3JheWJhciBFbGVjdHJpYyBDb21wYW55LCBJbmMuQFJlZGFjdA
Guardian Pharmacy LLC https://ransomware.live/id/R3VhcmRpYW4gUGhhcm1hY3kgTExDQGluY3JhbnNvbQ
Northern Counties Health Care https://ransomware.live/id/Tm9ydGhlcm4gQ291bnRpZXMgSGVhbHRoIENhcmVAaW5jcmFuc29t
UK: Parkdental.com https://ransomware.live/id/cGFya2RlbnRhbC5jb21AY2hhb3M
A lot more: https://ransomware.live/ #infosec #ransomware #threatresearch
-
New, and an excellant timeline for this gang's activities and various shenanigans.
Sekoia: Gotta breach 'em all! The journey of ShinyHunters https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters @sekoia_io #infosec #ransomware #cybercrime #threatresearch
-
New, and an excellant timeline for this gang's activities and various shenanigans.
Sekoia: Gotta breach 'em all! The journey of ShinyHunters https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters @sekoia_io #infosec #ransomware #cybercrime #threatresearch
-
New, and an excellant timeline for this gang's activities and various shenanigans.
Sekoia: Gotta breach 'em all! The journey of ShinyHunters https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters @sekoia_io #infosec #ransomware #cybercrime #threatresearch
-
New, and an excellant timeline for this gang's activities and various shenanigans.
Sekoia: Gotta breach 'em all! The journey of ShinyHunters https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters @sekoia_io #infosec #ransomware #cybercrime #threatresearch
-
New.
Zscaler: 2CLoader: A New Malware Loader Delivering Vidar and Remus https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus #infosec #malware #threatresearch
-
New.
Zscaler: 2CLoader: A New Malware Loader Delivering Vidar and Remus https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus #infosec #malware #threatresearch
-
New.
Zscaler: 2CLoader: A New Malware Loader Delivering Vidar and Remus https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus #infosec #malware #threatresearch
-
New.
Zscaler: 2CLoader: A New Malware Loader Delivering Vidar and Remus https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus #infosec #malware #threatresearch
-
New.
Microsoft: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ #Microsoft #threatresearch #infosec #vulnerability
-
New.
Microsoft: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ #Microsoft #threatresearch #infosec #vulnerability
-
New.
Microsoft: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ #Microsoft #threatresearch #infosec #vulnerability
-
New.
Microsoft: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ #Microsoft #threatresearch #infosec #vulnerability
-
New.
Microsoft: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ #Microsoft #threatresearch #infosec #vulnerability