Agent Data Injection: khi AI agent bị đánh lừa bằng chính dữ liệu nó tin tưởngJul 28, 2026·25 min read
UAT-11795: Trojanized WebEx, Zoom and MobaXterm Installers Deliver Starland RAT and the WLDR ImplantJul 28, 2026·21 min read
Phân tích Spirals Ransomware: Mã độc có thể mã hóa toàn bộ doanh nghiệp trong chưa đầy 24 giờTổng Quan Một chiến dịch tấn công bằng dòng mã độc tống tiền mới mang tên Spirals đã ghi nhận vụ việc đầu tiên mã hóa thành công toàn bộ hệ thống của một công ty dịch vụ IT tại Nam Á chỉ trong vòng chJul 28, 2026·19 min read
UAT-11795: Trojan hóa installer WebEx, Zoom, MobaXterm để phát tán Starland RAT và implant WLDRJul 28, 2026·26 min read
AsyncAPI Under Attack: Khi 2 Triệu Lượt Tải Mỗi Tuần Trở Thành Con Đường Phát Tán MalwareJul 28, 2026·21 min read
AsyncAPI Under Attack: When 2 Million Downloads Per Week Becomes a Way to Spread MalwareCampaign Summary On July 14, 2026, attackers successfully compromised the AsyncAPI organization on npm — one of the most popular open source projects for event-driven APIs, and injected malicious codeJul 28, 2026·16 min read
EvilTokens and "Ghost Phishing": The Microsoft 365 Attack That Only Materializes Inside the BrowserEvilTokens, a phishing-as-a-service (PhaaS) kit that surfaced in mid-February 2026, chains two techniques that together defeat both static URL scanning and multi-factor authentication. The phishing HTJul 28, 2026·9 min read
QuimaRAT: A Cross-Platform Java RAT (Windows/macOS/Linux) Sold as MaaS, 70+ Modules Behind an "Offensive Security" CoverExecutive Summary QuimaRAT is a Java-based remote access trojan (RAT) published by LevelBlue SpiderLabs on June 25, 2026 and further covered by The Hacker News on July 6, 2026. What stands out: it runJul 28, 2026·7 min read
Red Alert for Virtualization Infrastructure: Januscape Vulnerability Allows Attackers to Hijack Host Rights from Guest VM.Risk Summary CVE-2026-53359, dubbed Januscape, is a use-after-free vulnerability in the shadow MMU subsystem of Linux KVM/x86. The vulnerability allows a virtual machine (guest) to perform two actionsJul 28, 2026·20 min read
RedHook Android RAT: A new step in Android device hijacking techniquesCampaign Summary A report from Group-IB Threat Intelligence published on July 9, 2026 confirms the re-emergence of RedHook malware — a remote access Trojan (RAT) on Android with breakthrough improvemeJul 28, 2026·11 min read
HollowGraph: Tin tặc biến Microsoft 365 thành công cụ điều khiển mã độcTổng quan chiến dịch Các chuyên gia bảo mật vừa công bố HollowGraph một loại malware .NET NativeAOT dùng calendar của mailbox Microsoft 365 bị chiếm quyền làm kênh C2 hai chiều. Toàn bộ tasking và exfJul 27, 2026·9 min read