BambooToken: The Malware That Speaks an IoT Protocol to Stay HiddenOverview In September 2026, Lumen Black Lotus Labs published a report on BambooToken — a previously undocumented malware framework that operated undetected from February 2023 through July 2026, targetSep 18, 2026·18 min read
Một doanh nghiệp thực phẩm lớn tại Việt Nam bị nhóm ransomware INC Ransom đưa lên trang rò rỉ dữ liệuSep 16, 2026·16 min read
A large food business in Vietnam was posted on a data leak site by the INC Ransom ransomware groupOverview Appearing since July 2023, the INC Ransom hacker group (also tracked under the identifier GOLD IONIC) has quickly become one of the most dangerous Ransomware-as-a-Service (RaaS) threats to crSep 16, 2026·12 min read
Phantom Deal: When the NDA Is the PayloadSummary It started with an innocuous WhatsApp message: "Hi David, I hope you are well. Are you at the office?" The sender claimed to be a real Gen executive based in Dublin. The profile used his namSep 16, 2026·17 min read
StreamRat: When the Delivery Channel Is Paid Advertising and the Landing Page Coaches Victims Past Their Own Security WarningsSummary On 2 September 2026, ThreatFabric published StreamRat — a new Android banking trojan distributed through Meta and TikTok advertisements impersonating a free TV streaming service, aimed at SpanSep 16, 2026·22 min read
TerminalFix: Change One Dialog Box, and the Payload Jumps From an Infostealer to a Tunnel Into the NetworkSummary Classic ClickFix directs victims to the Windows Run dialog. TerminalFix directs them to Windows Terminal or PowerShell. It sounds like a trivial detail. But the Run dialog accepts a single linSep 16, 2026·19 min read
When AI Agent Turns Off Sandbox: Control Plane Vulnerability Analysis CVE-2026-82533 on DeepSeek HarnessOverview What would happen if an AI tool that you trusted to write code automatically removed all of its own protection mechanisms, silently opening the door for attackers to take over your computer wSep 16, 2026·11 min read
From an MS Teams Call to a Domain Admin: Analyzing an Impersonating IT Support CampaignOverview Imagine a normal work morning: employees receive a direct message on Microsoft Teams from an account called "IT Helpdesk", informing them that their computer is transmitting malicious trafficSep 16, 2026·12 min read