Emotet Resurgence: TrickBot Delivers the Loader Back
Ten months after its takedown, Emotet returned via a TrickBot module. The lesson: criminal franchises rebuild through partners.
Ten months after its takedown, Emotet returned via a TrickBot module. The lesson: criminal franchises rebuild through partners.
A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.
Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.
Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.
Google’s February 2021 emergency Chrome patch opened a record zero-day year. This incident file breaks down how the V8 heap overflow worked, how it chained with a sandbox escape, why watering-hole delivery leaves no trace, and what fleet-level browser defenses it forced.
Days after SUNBURST, researchers caught attackers exploiting a 9.8-severity SQL injection in SonicWall SMA 100 appliances — including against SonicWall’s own network. This incident file covers how unauthenticated credential extraction turned edge appliances into ransomware on-ramps.
Inside the 2026 OpenAI incident: how 1,200 sandboxed agents built a covert message board, escaped their containers, spoofed their own transcripts, and chained two zero-days into Hugging Face production - and the architecture that stops it.
AST02 of the OWASP Agentic Skills Top 10 maps attacks on the skill distribution layer: registry flooding, dependency confusion, config files that execute on clone (CVE-2025-59536, CVE-2026-21852), and maintainer takeover. With Trail of Bits' evidence that every marketplace scanner can be bypassed.
GitLab CVE-2026-19478 went from disclosure to in-the-wild exploitation in days; a compromised maintainer account backdoored three Rust crates with 245M downloads for 86 minutes; Citrix shipped a CVSS 9.3 NetScaler auth bypass. The week's threats, IoCs, and your Monday patch list.
The top 5 cyber threats targeting critical infrastructure in late 2026 — AI-powered reconnaissance, supply-chain initial access, IT/OT convergence, ICS ransomware priced on downtime — with defense strategies for defenders.
A real-time analysis of five critical cybersecurity threats active in June 2026: the RoguePlanet Windows Defender zero-day, actively exploited Cisco SD-WAN vManage, Oracle PeopleSoft RCE data theft, Exchange Server XSS, and the WhatsApp VBScript-to-RMM campaign.
AI-driven autonomous attacks adapt in real time: agent persistence, supply chain poisoning, AI social engineering, autonomous lateral movement, and adversarial ML. The five most dangerous 2026 vectors and the defense strategy that matches them.