Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Toggle website search
Search this website

Cyberattacks 2026

  1. Home>
  2. Blog>
  3. Cyberattacks 2026
Read more about the article Living Off Trusted Infrastructure: C2 via Legitimate Services

Living Off Trusted Infrastructure: C2 via Legitimate Services

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Security/Technology

DragonForce’s Backdoor.Turn routes ransomware C2 through Microsoft Teams TURN relays using anonymous visitor tokens — LOTI, living off trusted infrastructure. Why network detection dies and what still works.

Continue ReadingLiving Off Trusted Infrastructure: C2 via Legitimate Services
Read more about the article How AI Is Transforming Ransomware in 2026: Threats & Defense

How AI Is Transforming Ransomware in 2026: Threats & Defense

  • Post author:Prabhu Kalyan Samal
  • Post published:August 22, 2026
  • Post category:Security

Discover how AI is revolutionizing ransomware attacks in 2026 — from automated RaaS platforms to deepfake-powered extortion and actionable defense strategies.

Continue ReadingHow AI Is Transforming Ransomware in 2026: Threats & Defense
Read more about the article Over 400 Arch Linux AUR Packages Hijacked: Inside the Attack

Over 400 Arch Linux AUR Packages Hijacked: Inside the Attack

  • Post author:Prabhu Kalyan Samal
  • Post published:August 22, 2026
  • Post category:Security

Over 400 AUR packages hijacked via maintainer account takeover: poisoned PKGBUILDs ran a Rust credential harvester, with an eBPF rootkit where builds ran as root. Full breakdown and response steps.

Continue ReadingOver 400 Arch Linux AUR Packages Hijacked: Inside the Attack
Read more about the article Device Code Phishing in 2026: How Attackers Bypass MFA with a Simple URL

Device Code Phishing in 2026: How Attackers Bypass MFA with a Simple URL

  • Post author:Prabhu Kalyan Samal
  • Post published:August 22, 2026
  • Post category:Security

Device code phishing surged 37x in 2026. How attackers exploit OAuth 2.0 device authorization grants to turn victims’ own MFA against them — plus detection strategies and defense hardening.

Continue ReadingDevice Code Phishing in 2026: How Attackers Bypass MFA with a Simple URL
Read more about the article Node-IPC: When npm Dependencies Turn Hostile

Node-IPC: When npm Dependencies Turn Hostile

  • Post author:Prabhu Kalyan Samal
  • Post published:August 22, 2026
  • Post category:Security

Three versions of node-ipc (10.1.1-10.1.3) shipped a stealer backdoor - CVE-2026-44338 - harvesting SSH keys, AWS credentials and .npmrc from 1.2M-weekly-download installs via DNS tunneling and HTTPS C2. Technical breakdown and hardening guide.

Continue ReadingNode-IPC: When npm Dependencies Turn Hostile
Read more about the article CVE-2026-41940: cPanel Authentication Bypass Explained

CVE-2026-41940: cPanel Authentication Bypass Explained

  • Post author:Prabhu Kalyan Samal
  • Post published:August 22, 2026
  • Post category:Security

CVE-2026-41940 let unauthenticated attackers bypass cPanel/WHM/Webmail logins entirely — exploits hit before the patch existed. Ports 2082-2096 went dark industry-wide within the hour. Patched versions, response timeline, and audit steps inside.

Continue ReadingCVE-2026-41940: cPanel Authentication Bypass Explained
Read more about the article CVE-2026-2256 to SGLang RCE: The Week AI Infrastructure Went Under Siege

CVE-2026-2256 to SGLang RCE: The Week AI Infrastructure Went Under Siege

  • Post author:Prabhu Kalyan Samal
  • Post published:August 22, 2026
  • Post category:AI & Agent Security/Security

One week in April 2026 delivered a CVSS 9.8 AI-agent flaw, an unauthenticated SGLang RCE, MCP memory poisoning, and a 766-host credential harvest. Here's the full analysis and your patching order.

Continue ReadingCVE-2026-2256 to SGLang RCE: The Week AI Infrastructure Went Under Siege
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (2)
  • Security (358)
  • Technology (63)

Recent Posts

  • Agentic AI Security Cheat Sheet: Threat Models, MCP Hardening Checklist and Detection Hooks
  • Alert Fatigue Is a Design Problem: Building a Detection Engineering Lifecycle That Survives Contact
  • Write Sigma Rules That Actually Fire: A Detection-as-Code Lab with SigmaCLI and splunk-react
  • Why Planes Don’t Get Hacked — And Where the Next Aviation Cyber Risk Really Is
  • What Is Prompt Injection and How to Prevent It: A Complete Exam Prep Guide
  • Pyramid of Pain to Production: How Detection Engineers Prioritize What to Hunt
  • Build a Free Elastic Security SOC: Ingest Sysmon, Create Dashboards and Triage Alerts
  • Testing JWT Security with jwt-cli and Caido: Alg Confusion, Weak Secrets, and Expired Claims
  • Weekly Threat Intel: 30 September 2026 — npm Malware, Typosquat Waves and Autumn CVEs
  • Evilginx3 Lab: Build a Safe AiTM Phishing Lab to Understand Session Cookie Theft (and Why FIDO2 Stops It)
  • MFA Fatigue and Push Bombing: How Attackers Wear Down Your Users
  • Shodan and Censys for Attack Surface Recon: A Hands-On OSINT Lab with Ethics Guardrails
  • Weekly Threat Intel: 27 September 2026 — Agentic Supply Chain Abuse and CVE Trades
  • Abusing GraphQL Introspection and Batching: A Hands-On API Attack Lab with Defenses
  • SQLite Runs the World: Inside the Most Deployed Database Ever

Archives

  • October 2026 (9)
  • September 2026 (272)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact