SynkLoader: Malware mới phát tán qua Teams sử dụng màn hình login Windows FAKE để lừa chiếm quyền truy cậpSep 3, 2026·10 min read
Kaido Panel: Dịch vụ MaaS giấu sau domain giả Adobe Acrobat, nhắm vào tài chínhTổng quan Ngày 23/08/2026, các chuyên gia bảo mật phát hiện acrobatreaderonline[.]com không phải website cung cấp Adobe Acrobat Reader như tên miền này gợi ý. Thực tế, phía sau website là Kaido Panel,Sep 3, 2026·8 min read
Gần 2.000 Website WordPress Bị Chiếm Dụng: Bí Mật Phía Sau Chiến Dịch StopAndProtectSep 3, 2026·12 min read
Nearly 2,000 WordPress Websites Taken Over: The Secret Behind the StopAndProtect CampaignDo you believe that just one click on the familiar "I'm not a robot" (CAPTCHA) verification box can empty your cryptocurrency wallet and turn your computer into a "slave" in a global criminal network?Sep 3, 2026·10 min read
ValleyRAT and the Cost of a Valid Signature: When the Payload Has No Magic Bytes Left to CatchSummary The victim extracts a ZIP archive and sees exactly one file: 07.30Document details.exe. That file is a genuine Overwolf Ltd executable with a valid digital signature, simply renamed. The otherSep 3, 2026·19 min read
ValleyRAT và cái giá của một chữ ký hợp lệ: khi payload không còn cả magic byte để mà bắtTóm tắt Nạn nhân giải nén một file ZIP và thấy đúng một file: 07.30Document details.exe. File đó là executable thật của Overwolf Ltd, có chữ ký số hợp lệ, chỉ bị đổi tên. Hai file còn lại trong archivSep 3, 2026·23 min read
SLEEPWALKER: A Passive Backdoor That Wakes Up for Exactly One Packet, Carries Its Own Bytecode Language, and Hides Inside ESET Management AgentOverview On August 24, 2026, independent malware researcher Dominik Reichel (former Palo Alto Networks Unit 42) published an exceptionally detailed analysis on his personal blog (r136a1.dev) of SLEEPWAug 31, 2026·29 min read
SLEEPWALKER: Backdoor Thụ Động Chỉ "Thức Giấc" Trước Đúng Một Gói Tin, Mang Ngôn Ngữ Bytecode Riêng, Ẩn Mình Trong ESET Management AgentTổng Quan Ngày 24/08/2026, nhà nghiên cứu malware độc lập Dominik Reichel (cựu nhà nghiên cứu tại Palo Alto Networks Unit 42) công bố trên blog cá nhân (r136a1.dev) một phân tích cực kỳ chi tiết về SLAug 31, 2026·38 min read
TWINLOOT: When Microsoft Cloud Becomes a Hacker's "Control Center"Imagine a nightmare scenario for every SOC team: An attacker lies deep inside the internal network for weeks, silently opening up to 128 administrative connection streams (SMB, RDP, WinRM) to move latAug 31, 2026·11 min read