⤷ Title: Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:20:40 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #Government #malware #phishing #russia #TAG_110 #Tajikistan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:20:40 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #Government #malware #phishing #russia #TAG_110 #Tajikistan
Daily CyberSecurity
Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
Russian-aligned TAG-110 (APT28) is launching a cyber-espionage campaign using macro-enabled Word docs to target Tajikistan's public sector for intelligence.
⤷ Title: GrayAlpha’s Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:02:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:02:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
Daily CyberSecurity
GrayAlpha’s Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
GrayAlpha, linked to FIN7, escalates tactics with fake browser/7-Zip updates and TAG-124 TDS, spreading NetSupport RAT in a multi-pronged infection campaign.
⤷ Title: Pakistan-Aligned APT36 Unleashes DRAT V2: New Delphi RAT Targets Indian Government
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:43:31 +0000
════════════════════════
⌗ Tags: #Malware #APT36 #ClickFix #Cyberespionage #DRAT V2 #Government #India #phishing #RAT #Remote Access Trojan #SideCopy #TAG_140 #Transparent Tribe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:43:31 +0000
════════════════════════
⌗ Tags: #Malware #APT36 #ClickFix #Cyberespionage #DRAT V2 #Government #India #phishing #RAT #Remote Access Trojan #SideCopy #TAG_140 #Transparent Tribe
Penetration Testing Tools
Pakistan-Aligned APT36 Unleashes DRAT V2: New Delphi RAT Targets Indian Government
Pakistan-aligned APT36 (TAG-140) unleashes DRAT V2, a new Delphi-compiled RAT, in a cyber-espionage campaign targeting Indian government entities via ClickFix social engineering.
⤷ Title: Reflected XSS in HTML Context with All Standard Tags Blocked Except Custom Ones
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 11:23:24 GMT
════════════════════════
⌗ Tags: #tag_filter_bypass #xss_in_html_context #reflected_xss #xss_payload #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 11:23:24 GMT
════════════════════════
⌗ Tags: #tag_filter_bypass #xss_in_html_context #reflected_xss #xss_payload #bug_bounty
Medium
Reflected XSS in HTML Context with All Standard Tags Blocked Except Custom Ones
Discover how attackers bypass tag filters using custom HTML elements and event handlers to trigger XSS.
⤷ Title: Blind Eagle’s Expanding Cyber Campaigns: Five Clusters Targeting Colombia’s Government and Beyond
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 04:44:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blind Eagle #Colombia #Cyber Espionage #phishing attacks #RAT malware #Recorded Future #supply chain threats #TAG_144
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 04:44:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blind Eagle #Colombia #Cyber Espionage #phishing attacks #RAT malware #Recorded Future #supply chain threats #TAG_144
Penetration Testing Tools
Blind Eagle’s Expanding Cyber Campaigns: Five Clusters Targeting Colombia’s Government and Beyond
Recorded Future links Blind Eagle to five attack clusters targeting Colombia’s government and critical sectors, exposing cyber espionage and data theft risks.
⤷ Title: Google Patches Actively Exploited Chrome Zero-Day Flaw (CVE-2025-13223) in Emergency Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 23:03:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #chrome #CVE_2025_13223 #cybersecurity #google #patch #Remote Code Execution #tag #Type Confusion #V8 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 23:03:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #chrome #CVE_2025_13223 #cybersecurity #google #patch #Remote Code Execution #tag #Type Confusion #V8 #zero_day
Daily CyberSecurity
Google Patches Actively Exploited Chrome Zero-Day Flaw (CVE-2025-13223) in Emergency Update
Google released an emergency Chrome update (142.0.7444.175) to patch two V8 Type Confusion flaws. One zero-day (CVE-2025-13223) is actively exploited. Update now!
⤷ Title: New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
Daily CyberSecurity
New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
Darktrace exposed TAG-150, a new MaaS operator compromising 469+ US devices in months. The group uses ClickFix to trick victims into running malicious PowerShell that deploys the CastleLoader/CastleRAT backdoor.
⤷ Title: CastleLoader PhaaS: GrayBravo Escalates Attacks on Logistics & Booking.com
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:28:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #CastleLoader #cybercrime #GrayBravo #Logistics #Malware_as_a_Service #PhaaS #phishing #Recorded Future #TAG_160
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:28:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #CastleLoader #cybercrime #GrayBravo #Logistics #Malware_as_a_Service #PhaaS #phishing #Recorded Future #TAG_160
Penetration Testing Tools
CastleLoader PhaaS: GrayBravo Escalates Attacks on Logistics & Booking.com
The cybercriminal group GrayBravo, formerly known as TAG-150, continues to evolve at a rapid pace, demonstrating a high
⤷ Title: The Mutable Tag Trap: Critical 9.4 CVSS Attack on Xygeni GitHub Action Exposes CI/CD Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 04:26:38 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #C2 Backdoor #CI/CD security #CVE_2026_31976 #cybersecurity #DevSecOps #GitHub Actions #infosec #supply chain attack #Tag Poisoning #Xygeni
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 04:26:38 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #C2 Backdoor #CI/CD security #CVE_2026_31976 #cybersecurity #DevSecOps #GitHub Actions #infosec #supply chain attack #Tag Poisoning #Xygeni
Daily CyberSecurity
The Mutable Tag Trap: Critical 9.4 CVSS Attack on Xygeni GitHub Action Exposes CI/CD Pipelines
A critical 9.4 CVSS tag poisoning attack (CVE-2026-31976) hit the xygeni-action GitHub Action, injecting a C2 backdoor into CI/CD pipelines. Update now.
⤷ Title: The Tag Trap: How a Single Commit Swap Turned Xygeni’s GitHub Action into a Clandestine Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:21:26 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Security #DevOps Security #GitHub Actions #GitHub Token Theft #malware #RCE #StepSecurity #supply chain attack #Tag Poisoning #Tech News 2026 #v5 tag #Xygeni
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:21:26 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Security #DevOps Security #GitHub Actions #GitHub Token Theft #malware #RCE #StepSecurity #supply chain attack #Tag Poisoning #Tech News 2026 #v5 tag #Xygeni
Penetration Testing Tools
The Tag Trap: How a Single Commit Swap Turned Xygeni’s GitHub Action into a Clandestine Backdoor
An imperceptible edit to a single tag transformed a ubiquitous security auditing instrument into a clandestine backdoor. A
❤1
⤷ Title: TAG-182 Threat Cluster Spreads MarkiRAT Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 07:58:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Insikt Group #Iran Surveillance #MarkiRAT #Recorded Future #TAG_182
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 07:58:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Insikt Group #Iran Surveillance #MarkiRAT #Recorded Future #TAG_182
Daily CyberSecurity
TAG-182 Threat Cluster Spreads MarkiRAT Malware
At a glance: Actor/Group: TAG-182 threat cluster (suspected Iran-nexus) Activity Type: Cyber surveillance and malware distribution Targets/Victims: Iranian citizens and dissidents worldwide Scale:…
⤷ Title: China and India Cyberespionage Converge on Pakistani Law Enforcement
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 08:03:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Balochistan Police #Chinese Cyberespionage #Cobalt Strike #Pakistani Law Enforcement #PlugX #Remcos #SentinelLABS #ShadowPad #TAG_179
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 08:03:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Balochistan Police #Chinese Cyberespionage #Cobalt Strike #Pakistani Law Enforcement #PlugX #Remcos #SentinelLABS #ShadowPad #TAG_179
Daily CyberSecurity
China and India Cyberespionage Converge on Pakistani Law Enforcement
At a Glance Actors Suspected China-nexus (PlugX, ShadowPad, Cobalt Strike) and India-nexus (Remcos; TAG-179) groups Activity type State-nexus cyberespionage; C2 intrusions; malware implanted in a …
⤷ Title: TAG-150 Attack Chain Deploys DenoRAT Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 08:01:09 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #DenoRAT #malware #NightshadeC2 #TAG_150
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 08:01:09 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #DenoRAT #malware #NightshadeC2 #TAG_150
Daily CyberSecurity
TAG-150 Attack Chain Deploys DenoRAT Malware
A recent cyberattack targeted a financial institution using a ClickFix social engineering lure. This incident revealed an evolving TAG-150 attack chain. Security researchers from eSentire Threat R…
⤷ Title: TAG-195 Deploys ChonkyChicken Modular Malware Framework
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 14:45:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ClickFix #Malware_as_a_Service #TAG_195 #TinyEgg
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 14:45:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ClickFix #Malware_as_a_Service #TAG_195 #TinyEgg
Information Security News
TAG-195 Deploys ChonkyChicken Modular Malware Framework
Evolution of the Golden Chickens Ecosystem Cybercriminals operating within the TAG-195 ecosystem have fundamentally restructured their malware architecture, adopting a highly modular approach. Con…
⤷ Title: Insikt Group Finds Four New Golden Chickens Malware Families
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 08:01:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ChromEggscalator #ClickFix #Golden Chickens #Insikt Group #Malware_as_a_Service #TAG_195 #TinyEgg #Venom Spider
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 08:01:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ChromEggscalator #ClickFix #Golden Chickens #Insikt Group #Malware_as_a_Service #TAG_195 #TinyEgg #Venom Spider
Daily CyberSecurity
Insikt Group Finds Four New Golden Chickens Malware Families
At a glance Actor or group TAG-195, also tracked as Golden Chickens and Venom Spider; deployment observed by an operator tracked as TAG-127 Activity type Malware-as-a-service development; credenti…