Skip to content
category — security

ls ./category/security --page 6

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 6 of 9 — 211 articles

This backdoor never phones home — it waits for a packet, and everything hunting for beacons misses it

2026-08-26

Sleepwalker is a Windows backdoor with a 23-instruction custom bytecode language, AES-256-CCM, and no outbound connections at all. It sits dormant until a specially crafted packet arrives. It loads by side-loading through a security vendor's own management agent while pretending to be Microsoft's dpapi.dll — and the researcher who found it says plainly that he cannot name a single victim.

The fake GTA VI download is 113GB of nothing wrapped around a 50KB payload

2026-08-26

Days after the leak, an ISO began circulating claiming to be the leaked build. Testers report it is 99.99% empty zeroes padded around roughly 50KB of malware, and that the installer whitelists the entire C: drive in Windows Defender before it runs. The file size was the disguise: 113GB is what a real game looks like.

They phoned a security company, used real employees' names, and got in

2026-08-25

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.

Exploited since January, added to CISA's list in August, due in three days

2026-08-25

CVE-2026-21962 is a CVSS 10.0 flaw in Oracle's HTTP Server and WebLogic proxy plug-in. Oracle patched it on 20 January. Exploit code appeared on 22 January and a honeypot logged attacks the same day. CISA added it to the Known Exploited Vulnerabilities catalog on 24 August with a due date of 27 August — and under a directive nobody noticed replacing the old one, agencies now have to check whether they were already breached.

The AI picked 170,000 targets — every break-in used a bug from years ago

2026-08-24

Cisco Talos found an exposed directory belonging to UAT-10147 and pulled out target lists of roughly 170,000 URLs, AI tooling across the whole attack lifecycle, and a cross-platform implant called SPECTRE that unlinks EDR callbacks in the kernel using two vulnerable drivers from 2019 and 2021.

The malware reads its orders out of an FTP welcome message, before it even logs in

2026-08-23

MalwareHunterTeam spotted the technique in July and SOCRadar says it is still running. A phishing ZIP drops a shortcut file, the shortcut connects to an FTP server and takes commands from the greeting banner, and either E4del or PINHOLE lands. Novel — and SOCRadar notes that being novel is also what makes it visible.