MedusaHVNC: "Màn hình Windows vô hình" đang giúp tin tặc qua mặt mọi ánh mắt giám sátAug 6, 2026·16 min read
MedusaHVNC: "Invisible Windows screen" is helping hackers bypass all surveillance eyesAug 6, 2026·14 min read
OctLurk và SilkLurk: hai backdoor tùy biến trong chiến dịch gián điệp mạng nhắm vào Trung ÁTừ tháng 1/2025, một nhóm tấn công chưa xác định danh tính đã duy trì hoạt động gián điệp mạng nhắm vào các cơ quan chính phủ tại Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan và Syria, Aug 10, 2026·21 min read
Bạn Kết Nối Wi-Fi Khách Sạn, Kẻ Tấn Công Đã Vào Tài Khoản Microsoft 365 — Mà Bạn Không Nhấp Gì CảTổng Quan Hãy hình dung kịch bản này: bạn vừa check-in khách sạn sau chuyến bay dài, mở laptop, bật Wi-Fi, mở Chrome và Chrome tự mở trang đăng nhập Microsoft 365. Trông quen thuộc. Bạn gõ mật khẩu, bAug 6, 2026·18 min read
You Connect to Hotel Wi-Fi, Attacker Logs into Microsoft 365 Account — Without You Clicking AnythingOverview Imagine this scenario: you just checked in to your hotel after a long flight, opened your laptop, turned on Wi-Fi, opened Chrome, and Chrome automatically opened the Microsoft 365 sign-in pagAug 6, 2026·16 min read
Chaos Ransomware and msaRAT: When C2 Lives Inside the Victim's Own BrowserSummary In April 2025, FBI Dallas seized 20.2891382 BTC from the wallet of an affiliate of the Chaos ransomware group — roughly two months after the group began operating. That is an unusual pace: lawAug 6, 2026·22 min read
A consolidated analysis of five Russian actor clusters across a fake Notepad++ plugin chain, cloud-service dead dropsSummary Six publications from CERT-UA, ESET, Unit 42, Proofpoint and StrikeReady, spanning 2023 to July 2026, describe five separate Russian actor clusters. Read together, they reveal a shared patternAug 6, 2026·27 min read
Agent Data Injection: Fooling AI Agents With the Data They Already TrustRisk Summary You ask a web agent to summarize the reviews on a product page. A fake review planted by an attacker makes it click "Buy Now" instead, and an order goes through. No malware, no phishing, Aug 6, 2026·20 min read
14 Million Downloads. No One Suspects. This Is How FakeGit Works.Campaign Summary More than 7,600 malicious GitHub repositories, maintained by approximately 6,600 fake profiles, accumulated more than 14 million downloads before Island Security published a comprehenAug 6, 2026·15 min read