SysScan Giả Mạo Microsoft: Máy Quét Bảo Mật "Phát Hiện" Lỗi Ảo, Dụ Nạn Nhân Gỡ Antivirus Rồi Dẫn Vào Bẫy Lừa Đảo Hoàn TiềnAug 25, 2026·24 min read
UAT-10147: Cybercrime Group Uses Agentic AI to Scale Server Attacks, Deploys SPECTRE Backdoor With Linux Rootkit and Vulnerable-Driver EDR BypassAug 25, 2026·30 min read
Fake Microsoft "SysScan": Bogus Security Scanner Invents Problems, Tricks Victims Into Uninstalling Their Antivirus, Then Funnels Them Into a Refund ScamOverview On August 24, 2026, Malwarebytes disclosed a wave of websites calling themselves "SysScan," carrying Microsoft branding, claiming to check whether your antivirus (AV) software is working. EveAug 25, 2026·17 min read
UAT-10147: Nhóm tội phạm mạng dùng AI Agentic mở rộng quy mô tấn công máy chủ, triển khai backdoor SPECTRE với rootkit Linux và kỹ thuật qua mặt EDR bằng driver độc hạiAug 25, 2026·38 min read
HoneyMyte Takes CoolClient Into the Kernel: When a Rootkit Changes What Windows Lets You SeeAug 25, 2026·22 min read
HoneyMyte đưa CoolClient xuống kernel: khi rootkit thay đổi thứ Windows cho phép bạn nhìn thấyTóm tắt CoolClient vốn đã là một backdoor gián điệp đầy đủ chức năng: keylogging, đánh cắp clipboard, thu thập thông tin xác thực, quản lý file, trinh sát hệ thống, và kiến trúc mở rộng bằng plugin. BAug 25, 2026·27 min read
Evooo1Bot: When an Infected Router Stops Being Disposable Ammunition and Becomes Rentable InfrastructureSummary Evooo1Bot reuses the DDoS engine from the publicly leaked Mirai source code verbatim. That part is nothing new after ten years. What is new is everything bolted onto it: encrypted C2 communicaAug 25, 2026·21 min read
Evooo1Bot: khi router bị nhiễm không còn là đạn dùng một lần mà trở thành hạ tầng cho thuêTóm tắt Evooo1Bot dùng lại nguyên engine DDoS từ mã nguồn Mirai bị rò rỉ công khai. Phần đó không có gì mới sau mười năm. Cái mới nằm ở những thứ được gắn thêm vào: giao tiếp C2 mã hóa, scanner brute-Aug 25, 2026·25 min read
600.000 Website WordPress Trước Nguy Cơ RCE: Lỗ Hổng Forminator Nguy Hiểm Đến Đâu?Tổng Quan Hãy hình dung một kịch bản tưởng chừng bất khả thi: Một kẻ tấn công hoàn toàn xa lạ, không có tài khoản quản trị, không cần đăng nhập, và cũng chẳng cần đánh lừa bất kỳ ai nhấp vào đường dẫnAug 25, 2026·14 min read
600,000 WordPress Websites At Risk RCE: How Dangerous Is Forminator Vulnerability?Overview Imagine a seemingly impossible scenario: A completely unknown attacker with no admin account, no need to log in, and no need to trick anyone into clicking on a malicious link. With just a sinAug 25, 2026·11 min read
13 Minutes to Lose Money: How WindRelay Turned Android Phones into NFC Fraud Tools?Overview Did you know that it only takes 13 short minutes from the moment the victim picks up the phone to receive the support call from the "bank employee" until all the money in the account is evapoAug 20, 2026·12 min read