Skip to content
tag — attribution

grep -rl "attribution" ./articles

#attribution

7 articles

The attribution came from commit emails across 84 GitHub accounts

2026-09-09Security

The DFIR Report traced a decade-old Bing poisoning operation — fake activation portals, tech support scams, a custom bot and a Monero miner — to two named companies in Rajasthan, using email addresses left in GitHub commit history. That is a far stronger evidentiary chain than most attribution, and it is worth saying so.

PEEP forges Chromium's own integrity values. It also needs you to be compromised first

2026-09-08Security

SOCRadar documented a post-exploitation toolkit that installs itself into Chrome and Edge profiles as an extension called Smart Bookmarks, forges the signatures Chromium uses to detect exactly that, and reaches the operating system through native messaging. It cannot get onto a machine by itself, which is the part the headlines drop.

The backdoor was compiled into HAProxy. That is not an HAProxy vulnerability

2026-09-06Security

Rapid7 found a Linux implant built into the HAProxy binaries of two South Korean organisations, intercepting traffic and erasing its own requests from the proxy's own logs. Every headline calls it an HAProxy backdoor. Installing it requires already owning the host, which makes patching HAProxy the one response that changes nothing.

A state-linked backdoor for diplomats, written as a Windows batch file

2026-08-31Security

HOOKEDGE polls webhook.site for command files, runs them, and posts the output back as HTML. No custom infrastructure, no compiled binary, no exotic protocol — a .cmd script and a free service anyone can sign up for. Recorded Future ties it to APT28 with moderate confidence, and says so.

A 2023 flaw with a 2023 fix was used to take nuclear-material records this year

2026-08-31Security

CVE-2023-49105 lets anyone read, change or delete files on an ownCloud server without authenticating, if they know a username and the default configuration is in place. It was fixed in November 2023. It has now been used against a Philippine nuclear research body, and CISA added it to its exploited-vulnerabilities list on 27 August.

The US has sanctioned the same Iranian hacking institute twice in eight years — and it still does not tell you who stopped a British power plant

2026-08-29World

Treasury designated nearly 60 Iran-linked entities, individuals and vessels under Operation Economic Outcast, including six people tied to the Mabna Institute — the outfit sanctioned in 2018 for stealing 31 terabytes from 320 universities. The designations concern US infrastructure. They do not name the UK attack, and the attribution there remains unconfirmed.

A UK power plant was down for four days — and almost nothing in the headline is confirmed

2026-08-25Security

The Telegraph reported on 22 August that a small British generator was shut down for four days in July, and the coverage that followed called it Iran-linked. Neither the government nor the NCSC has confirmed that, the plant has not been named, and the CEO of Dragos is publicly warning that this is exactly the situation false flags are built for.