Threat Overview A newly discovered kernel vulnerability in CentOS 9, disclosed by CODERED_VTA on 2026‑02‑06, presents a severe risk of local privilege escalation. The flaw resides within the Linux kernel’s networking subsystem, specifically the net‑sched cake
Continue ReadingBlog
GoldenEyeDog Corporate Attack Threat Report
In early February 2026, cybersecurity researchers released a comprehensive threat report detailing a sophisticated campaign attributed to the advanced persistent threat group APT‑Q‑27, popularly known as GoldenEyeDog. The report, published by CODERED_VTA, highlights the group’s relentless
Continue ReadingSonicWall Breach Enables Security Tool Destruction
Threat Overview In early February 2026 Huntress documented a sophisticated intrusion that began with compromised SonicWall SSLVPN credentials. An attacker used these credentials to gain initial access to a target network, then deployed a custom EDR
Continue ReadingChrysalis Backdoor Insights into Lotus Blossom Toolkit
Threat Overview On 2026-02-04, security analyst Tr1sa111 released a comprehensive threat report titled The Chrysalis Backdoor: A Deep Dive into Lotus Blossom's toolkit. With a confidence level of 100 and a reliability rating of C –
Continue ReadingCloud Storage Payment Scam Floods Inboxes With Fake Renewals
Threat Overview On 2026-02-02, the security community was alerted to a new phishing campaign that targets users of popular cloud storage services. The campaign masquerades as legitimate renewal notices, flooding inboxes with emails that appear to
Continue ReadingEnergy Sector Incident Report December 2025
Threat Overview On 29 December 2025 a coordinated wave of destructive cyber‑attacks struck the Polish energy sector, targeting over 30 wind and photovoltaic farms, a private manufacturing firm and a large combined heat and power (CHP)
Continue ReadingGlassWorm Targets Crypto Wallets Using Malicious VS Code Extensions
GlassWorm, a self‑propagating worm that has already infected more than 8.8 million web browsers, has now turned its attention toward macOS users. According to research by DarkSpectre, the malware leverages malicious Visual Studio Code (VS Code) extensions
Continue ReadingCritical WinRAR Vulnerability CVE 2025 8088 Targeted by Multiple Threat Actors
Threat Overview Executive Summary In late January 2026, AlienVault released a comprehensive threat report titled "Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088". The report details how a high‑severity path traversal flaw in WinRAR, identified as
Continue ReadingToxicsnake Threat Intelligence Report
Threat OverviewThe latest intelligence from AlienVault reveals a sophisticated multi-domain traffic distribution system (TDS) operated by the threat actor known as Toxicsnake. The operation centers around the domain toxicsnake-wifes.com and functions as a commodity cybercrime TDS
Continue ReadingMicrosoft Issues Emergency Patch for CVE202621509 Office Zero-Day Exploited Actively
Threat Overview On 28 January 2026 Microsoft released an out-of-band emergency patch for a high‑severity zero‑day vulnerability in Microsoft Office, identified as CVE‑2026‑21509. The flaw, which scores 7.8 on the CVSS scale, is a security feature
Continue Reading