Blog
TELESHIM: East Asia APT Abuses Telegram for C2 to Backdoor Government Systems — How Trusted Apps Become Attack Channels
East Asia APT deploys TELESHIM malware using Telegram Bot API for C2 to backdoor government systems. IOCs, technical breakdown, and zero-trust defences.
Read More →CVE-2026-54121 ‘Certighost’: Any Domain User Can Now Steal Your krbtgt — Working PoC Is Public, Patch AD CS Today
CVE-2026-54121 'Certighost' (CVSS 8.8): a public PoC lets any domain user impersonate a DC, run DCSync, and steal krbtgt. All Windows Server 2012-2025 affected. Patch now.
Read More →CVE-2026-16723 (CVSS 9.0): Fastjson 1.x Zero-Day Is Silently Hacking Spring Boot Apps — No Patch, Active Exploitation
CVE-2026-16723 is a CVSS 9.0 RCE in Fastjson 1.x with no patch available. Attackers are actively exploiting Spring Boot fat-JAR apps. Here's what to do right now.
Read More →CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole Zero-Day Lets Attackers Rewrite Your Firewall Policy
CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole zero-day grants full admin access with no credentials. Exploited in wild, CISA KEV listed — patch steps and IOCs inside.
Read More →No CVE, No Alert: GitLab Exploit Lets Any Authenticated User Hijack Your Server
A working GitLab RCE proof-of-concept released July 24 exploits Oj parser memory bugs. Any user with push access can run commands as git. No CVE assigned — patch to 18.11.5…
Read More →CVE-2026-12569 (CVSS 9.3): Cl0p Is Raiding Manufacturing PLM Systems — Patch PTC Windchill and FlexPLM Before Your IP Is Gone
Cl0p ransomware affiliates are exploiting CVE-2026-12569 (CVSS 9.3) — an unauthenticated RCE in PTC Windchill and FlexPLM — to steal manufacturing IP. Patch now or risk your engineering data ending…
Read More →CVE-2026-56155 (CVSS 7.8): ADFS DKM Zero-Day Hands Attackers Your Identity Signing Keys — CISA Deadline Is July 28
CVE-2026-56155 exploits misconfigured ADFS DKM container ACLs to steal token-signing keys, enabling Golden SAML forgery across every enterprise app. CISA deadline: July 28, 2026.
Read More →TeamPCP Poisoned Trivy, KICS, and LiteLLM to Harvest 500,000 Credentials — Now Vect Ransomware Is Cashing In
TeamPCP compromised Trivy, KICS, and LiteLLM to steal 500,000 CI/CD credentials across 500,000 machines. Now Vect ransomware is deploying against victims — and paying the ransom may not recover your…
Read More →JadePuffer: The World’s First Fully Autonomous AI Ransomware Has Arrived — And It Needs No Human Operator
JADEPUFFER is the first confirmed ransomware campaign executed entirely by a large language model agent — exploiting CVE-2025-3248 (CVSS 9.8) in Langflow to autonomously encrypt 1,342 production configs without any…
Read More →Iran’s CyberAv3ngers Are Inside Your Water and Energy Systems — CISA’s July 22 Update Expands Alert to Siemens and Schneider PLCs
CISA updated AA26-097A on July 22, 2026: Iran-backed CyberAv3ngers now target Siemens & Schneider PLCs. CVE-2021-22681 has no patch — act now.
Read More →