A large food business in Vietnam was posted on a data leak site by the INC Ransom ransomware groupSep 16, 2026·12 min read
Một doanh nghiệp thực phẩm lớn tại Việt Nam bị nhóm ransomware INC Ransom đưa lên trang rò rỉ dữ liệuTổng Quan Xuất hiện từ tháng 7/2023, nhóm tin tặc INC Ransom (còn được theo dõi dưới định danh GOLD IONIC) đã nhanh chóng trở thành một trong những mối đe dọa Ransomware-as-a-Service (RaaS) nguy hiểm Sep 16, 2026·16 min read
StreamRat: When the Delivery Channel Is Paid Advertising and the Landing Page Coaches Victims Past Their Own Security WarningsSep 16, 2026·22 min read
TerminalFix: Change One Dialog Box, and the Payload Jumps From an Infostealer to a Tunnel Into the NetworkSep 16, 2026·19 min read
When AI Agent Turns Off Sandbox: Control Plane Vulnerability Analysis CVE-2026-82533 on DeepSeek HarnessOverview What would happen if an AI tool that you trusted to write code automatically removed all of its own protection mechanisms, silently opening the door for attackers to take over your computer wSep 16, 2026·11 min read
From an MS Teams Call to a Domain Admin: Analyzing an Impersonating IT Support CampaignOverview Imagine a normal work morning: employees receive a direct message on Microsoft Teams from an account called "IT Helpdesk", informing them that their computer is transmitting malicious trafficSep 16, 2026·12 min read
ZBT: Three Implants, One Supply Chain, and 392 Devices Calling a Forgotten DomainSummary VulnCheck bought an $88 router on Amazon from a small company in New York. The label said Deep Orange. Underneath the shell was a ZBT-WE826-T2 from Shenzhen Zhibotong Electronics, and inside tSep 16, 2026·21 min read
GoCaracal: Dark Caracal and New Advances in the Art of C2 ResilienceExecutive Summary In June 2026, cyber security researchers recorded a sophisticated espionage raid that took down a large telecommunications corporation in Venezuela: the APT Dark Caracal group officiSep 16, 2026·14 min read
TerminalFix Campaign Analysis: Risk of Active Directory Hijacking from Risky Terminal OperationsExecutive Summary Recently, Microsoft Threat Intelligence published analysis of a wide-area attack campaign called TerminalFix — a dangerous evolution from the social engineering technique ClickFix. ISep 16, 2026·13 min read
ASCII smuggling: Ký tự vô hình và cuộc chiến chống Phishing trong kỷ nguyên AI Tổng quan ASCII smuggling, kỹ thuật nổi tiếng trong prompt injection vì giấu chỉ thị khỏi mắt người nhưng vẫn bị phát hiện bởi với AI, cho dù dùng nhiều cách để né bộ lọc email. Hành vi được phát hiệnSep 15, 2026·7 min read