Kernel Exploit Lets Local Users Gain Root on Every Major Linux Distribution On 2026-05-06 a new, high‑severity local privilege escalation flaw, identified as CVE-2026-31431, was disclosed by CODERED_VTA. The vulnerability affects virtually every mainstream Linux distribution
Continue ReadingBlog
Multi stage Code Of Conduct Phishing Campaign Exposes AiTM Token Compromise
Introduction Microsoft Security Research unveiled a sophisticated multi‑stage phishing operation in early May 2026 that leveraged a “code of conduct” narrative to lure victims into a seemingly legitimate sign‑in flow. Attackers then hijacked that flow in
Continue ReadingSupply Chain Attack on SAP CAP and Cloud MTA Packages
The latest supply‑chain breach discovered on 29 April 2026 targets critical npm packages used across the SAP Cloud Application Programming Model (CAP) ecosystem. Four packages – [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected] – were compromised with a
Continue ReadingPolish Energy Sector Cyberattack Incident Report
On December 29, 2025, a coordinated series of destructive cyberattacks struck Poland’s energy sector during a period of severe winter weather. The attackers targeted a mix of renewable energy farms, a manufacturing company, and a combined
Continue ReadingPhone Fraud International Revenue Share Scheme Exploits Fake CAPTCHA
Executive Summary This report explains how a coordinated fraud operation uses fake CAPTCHA pages to generate international revenue share fraud (IRSF) by forcing users to send bulk SMS messages to phone numbers across multiple high‑fee countries.
Continue ReadingUntangling Linux Incident OpenAI Twist Part Two
In the second installment of the Codex Red series, the Huntress SOC uncovered a complex Linux breach that involved three distinct threat actors, a malicious cryptominer, a multi‑revenue botnet, and a credential‑harvesting campaign. The incident was
Continue ReadingBissa Scanner Exposed AI Assisted Mass Exploitation Credential Harvesting Threat Report
Executive Summary The Bissa Scanner platform demonstrates a highly organized, AI‑driven campaign that leveraged mass exploitation, credential harvesting, and post‑compromise triage to target high‑value organizations across finance, cryptocurrency, and retail sectors. The operation exploited publicly known
Continue ReadingRedSun ZeroDay Privilege Escalation Exploit
The latest threat report from AlienVault, published on 2026-04-21, reveals a critical zero‑day vulnerability in Microsoft Defender that enables local privilege escalation from a standard user to SYSTEM level on Windows systems. The exploit, named RedSun.exe,
Continue ReadingIncreased Bomgar RMM Exploitation Alert
Uptick in Bomgar RMM Exploitation Published by Tr1sa111 on 2026-04-21T04:23:44.949Z A new threat report from Huntress SOC highlights a recent surge in incidents exploiting a critical flaw in Bomgar remote monitoring and management (RMM) software, now
Continue ReadingPhantomCLR Operation Stealth Execution Via AppDomain Hijacking And InMemory DotNet Abuse
On 2026-04-18, AlienVault released a comprehensive threat report titled "Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse." The report details a highly sophisticated multi‑stage post‑exploitation framework that has been actively targeting organizations within
Continue Reading