MikroTrick: hai lỗi SSH nối lại thành quyền admin không cần mật khẩu trên RouterOSOct 6, 2026·12 min read
MacSync: Giấu payload vào iCloud Calendar trộm dữ liệu macOSBiến thể mới của dòng mã độc MacSync xuất hiện trên macOS với chuỗi lây nhiễm phức tạp, lợi dụng tệp lịch .ics trên dịch vụ public iCloud Calendar để chuyển tải payload vào trình thông dịch zsh -s. ChOct 6, 2026·16 min read
Khi mod game trở thành worm: hai lần Steam Workshop phát tán malware cho cùng một tựa gameOct 6, 2026·11 min read
MikroTrick: Two SSH Bugs Chained into Passwordless Admin on RouterOSSummary MikroTrick is CERT Polska's name for a two-vulnerability chain in RouterOS that gives an attacker full access to the administrative console with no password and no SSH key. Two things make thiOct 6, 2026·9 min read
CLOSEDQUORUM: When 4 AI models turn into C2 servers for MalwareOverview Imagine a system intrusion where the mastermind is not sitting in front of the screen, is not typing any C2 control commands, and is even... sleeping. Instead, the four leading commercial artOct 6, 2026·11 min read
Cyber Security Warning: Lunex Stealer Malware Abuses AMD Drivers to Steal Business AccountsOverview Have you ever thought that attackers do not need to write complex lines of code to bypass EDR signatures? Instead, they apply the BYOVD (Bring Your Own Vulnerable Driver>) technique - carryinOct 5, 2026·12 min read
SparroWocky & SilentMoonwalk Technique: When Backdoor Spoofs Call Stack Disables EDROverview When cybersecurity researchers analyzed the memory of a compromised government server in Latin America, they found Lewis Carroll's nonsense poem Jabberwocky sitting quietly inside a sophisticOct 5, 2026·13 min read
SparroWocky & Kỹ Thuật SilentMoonwalk: Khi Backdoor Giả Mạo Call Stack Vô Hiệu Hóa EDRTổng Quan Khi các nhà nghiên cứu an ninh mạng phân tích bộ nhớ của một máy chủ chính phủ bị xâm nhập tại Mỹ La-tinh, họ tìm thấy vần thơ vô nghĩa Jabberwocky của Lewis Carroll nằm lặng lẽ bên trong mộOct 5, 2026·16 min read
Bypassing Chrome & Edge's integrity checking mechanism: Technical analysis of KREMLIN banking malwareCampaign Summary What will happen if a malicious code can arbitrarily load an extension into Chrome or Edge but the browser still believes that it is the standard configuration of the system? The KREMOct 5, 2026·11 min read