⤷ Title: Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:13:12 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2018_0802 #cybersecurity #Excel Malware #Fileless Malware #FortiGuard Labs #phishing #powershell #Process Hollowing #rat #steganography #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:13:12 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2018_0802 #cybersecurity #Excel Malware #Fileless Malware #FortiGuard Labs #phishing #powershell #Process Hollowing #rat #steganography #XWorm
Daily CyberSecurity
Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
Phishing emails use malicious Excel files to deploy XWorm RAT. The fileless attack exploits CVE-2018-0802 to steal data & control systems.
⤷ Title: Process Injection’ın Evrimi: Reflective DLL’den Mockingjay’e EDR Atlatma Sanatı
════════════════════════
𐀪 Author: Melih Yusuf Ercan
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 17:49:28 GMT
════════════════════════
⌗ Tags: #dll_injection #defence_evasion #process_injection #dll_hijacking #hacking
════════════════════════
𐀪 Author: Melih Yusuf Ercan
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 17:49:28 GMT
════════════════════════
⌗ Tags: #dll_injection #defence_evasion #process_injection #dll_hijacking #hacking
Medium
Process Injection’ın Evrimi: Reflective DLL’den Mockingjay’e EDR Atlatma Sanatı
Siber güvenlik dünyasında artık klasik ‘dosya tabanlı’ zararlı yazılımların geçerliliği azaldı. Bugün EDR sistemlerini atlatabilmenin yolu…
⤷ Title: Encrypted Deception: Cisco Talos Unmasks “Dohdoor” and the Stealthy UAT-10027 Campaign Targeting Healthcare
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 04:20:07 +0000
════════════════════════
⌗ Tags: #Malware #Cisco Talos #Cloudflare #DLL Sideloading #DNS over HTTPS #Dohdoor #EDR Bypass #healthcare cybersecurity #Lazarus Group #Process Hollowing #Tech News 2026 #UAT_10027
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 04:20:07 +0000
════════════════════════
⌗ Tags: #Malware #Cisco Talos #Cloudflare #DLL Sideloading #DNS over HTTPS #Dohdoor #EDR Bypass #healthcare cybersecurity #Lazarus Group #Process Hollowing #Tech News 2026 #UAT_10027
Penetration Testing Tools
Encrypted Deception: Cisco Talos Unmasks "Dohdoor" and the Stealthy UAT-10027 Campaign Targeting Healthcare
Since the twilight of 2025, Cisco Talos has been vigilantly tracking a malicious campaign directed against educational and
⤷ Title: Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:02:53 +0000
════════════════════════
⌗ Tags: #Malware #Bincrypter #ClipXDaemon #Cryptocurrency Hijacker #cybersecurity #Cyble Research #infosec #Linux Malware #Process Masquerading #threat intelligence #X11 Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:02:53 +0000
════════════════════════
⌗ Tags: #Malware #Bincrypter #ClipXDaemon #Cryptocurrency Hijacker #cybersecurity #Cyble Research #infosec #Linux Malware #Process Masquerading #threat intelligence #X11 Security
Daily CyberSecurity
Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
Cyble Research unmasks ClipXDaemon, a C2-less Linux malware that silently hijacks cryptocurrency wallet addresses in X11 clipboard environments.
⤷ Title: The Invisible Thread: Inside the Multi-Stage Python Injection Powering VioletRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET CLR Hosting #AMSI Bypass #Cyber Security 2026 #malware analysis #Process Hollowing #Python injection #RAT #shellcode #SonicWall #VioletRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET CLR Hosting #AMSI Bypass #Cyber Security 2026 #malware analysis #Process Hollowing #Python injection #RAT #shellcode #SonicWall #VioletRAT
Information Security News
The Invisible Thread: Inside the Multi-Stage Python Injection Powering VioletRAT
Security vanguards at SonicWall have unmasked a nascent campaign disseminating the VioletRAT malware. This offensive orchestrates a multi-tiered delivery sequence and a sophisticated Python-based …
⤷ Title: The End of the Static Era: Trellix Uncovers Fully Fileless Remcos RAT Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 06:03:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #Remcos RAT #Remote Access Trojan #threat intelligence #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 06:03:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #Remcos RAT #Remote Access Trojan #threat intelligence #Trellix
Daily CyberSecurity
The End of the Static Era: Trellix Uncovers Fully Fileless Remcos RAT Campaign
Trellix uncovers a stealthy, fileless Remcos RAT campaign utilizing process hollowing to execute entirely in memory and evade traditional security.
⤷ Title: The Complete Penetration Testing Process: Step-by-Step Guide (Beginner to Pro)
════════════════════════
𐀪 Author: Tejas Kamble
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 11:18:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #pentesting #process #ethical_hacking
════════════════════════
𐀪 Author: Tejas Kamble
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 11:18:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #pentesting #process #ethical_hacking
Medium
The Complete Penetration Testing Process: Step-by-Step Guide (Beginner to Pro)
Imagine a hacker trying to break into your system right now. Would they succeed? … In today’s digital world, cyberattacks are not just…
⤷ Title: The Stealthy Evolution of the DesckVB RAT Infection Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:34:25 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #C2 #cybersecurity #DesckVB RAT #Fileless Malware #In_Memory Attack #JavaScript Trojan #Lat61 #malware #powershell #Process Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:34:25 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #C2 #cybersecurity #DesckVB RAT #Fileless Malware #In_Memory Attack #JavaScript Trojan #Lat61 #malware #powershell #Process Hijacking
Daily CyberSecurity
The Stealthy Evolution of the DesckVB RAT Infection Chain
Lat61 Team uncovers DesckVB RAT, a stealthy 2026 Trojan using in-memory .NET loaders & JS obfuscation to hijack systems and evade AV. Learn how it works.
⤷ Title: PureRAT Unmasked: The Stealthy, Multi-Stage “Dynamic Loader” Targeting Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
Daily CyberSecurity
PureRAT Unmasked: The Stealthy, Multi-Stage "Dynamic Loader" Targeting Windows
Trellix uncovers PureRAT, a modular Trojan hiding malware in PNG images. Learn how it uses steganography and fileless delivery to bypass Windows security.
⤷ Title: Cisco Talos Unveils “Living-off-the-Land” Tactics Threatening macOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 07:03:52 +0000
════════════════════════
⌗ Tags: #Malware #Apple #Cisco Talos #cybersecurity #DevOps #Enterprise Security #infosec #LotL #macOS #Process Monitoring #Spotlight Metadata #Threat Hunting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 07:03:52 +0000
════════════════════════
⌗ Tags: #Malware #Apple #Cisco Talos #cybersecurity #DevOps #Enterprise Security #infosec #LotL #macOS #Process Monitoring #Spotlight Metadata #Threat Hunting
Daily CyberSecurity
Cisco Talos Unveils "Living-off-the-Land" Tactics Threatening macOS
Cisco Talos reveals how attackers use native macOS features like Spotlight and SNMP to hijack enterprise workstations. Secure your DevOps environment today.
⤷ Title: Locked in eBPF: Meet Jailer, the Next-Gen Process Jailing System for Linux Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 08:06:41 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BPF task_storage #Cybersecurity 2026 #eBPF #Jailer #Linux Kernel #Linux Security #mac #Mandatory Access Control #Process Isolation #System Administration
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 08:06:41 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BPF task_storage #Cybersecurity 2026 #eBPF #Jailer #Linux Kernel #Linux Security #mac #Mandatory Access Control #Process Isolation #System Administration
Penetration Testing Tools
Locked in eBPF: Meet Jailer, the Next-Gen Process Jailing System for Linux Security
Jailer is an eBPF-powered Mandatory Access Control (MAC) system for Linux. It enforces ultra-granular policies on files, networks, and execution via BPF maps.
⤷ Title: Deep Diagnostics: Microsoft Supercharges Sysinternals with AI-Era Process Tracking and Linux Support
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 03:21:06 +0000
════════════════════════
⌗ Tags: #Microsoft #Autoruns #Debian 13 #DebugView #IT Administration #Linux Security #Powertoys #ProcDump #Process Explorer #RHEL 10 #Sysinternals #Sysmon #Windows Troubleshooting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 03:21:06 +0000
════════════════════════
⌗ Tags: #Microsoft #Autoruns #Debian 13 #DebugView #IT Administration #Linux Security #Powertoys #ProcDump #Process Explorer #RHEL 10 #Sysinternals #Sysmon #Windows Troubleshooting
Penetration Testing Tools
Deep Diagnostics: Microsoft Supercharges Sysinternals with AI-Era Process Tracking and Linux Support
Microsoft has modernized several quintessential utilities within the Sysinternals Suite, a collection frequently utilized by system administrators, support
⤷ Title: By Design No More: Microsoft Edge Vv148.0 to Block Plaintext Password Scrapes from Process Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:39:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #App_Bound Encryption #Chromium Architecture #Cleartext Credentials #Edge v148.0 Stable #Local Privilege Escalation #Memory Dump #microsoft edge #Process Memory Scraping #Threat Intelligence 2026 #Tom Jøran Sønstebyseter Rønning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:39:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #App_Bound Encryption #Chromium Architecture #Cleartext Credentials #Edge v148.0 Stable #Local Privilege Escalation #Memory Dump #microsoft edge #Process Memory Scraping #Threat Intelligence 2026 #Tom Jøran Sønstebyseter Rønning
Daily CyberSecurity
By Design No More: Microsoft Edge Vv148.0 to Block Plaintext Password Scrapes from Process Memory
Microsoft pivots on its "by design" stance, updating Edge to version 148.0 to stop caching your entire plaintext password vault in active volatile memory.
⤷ Title: PureLogs Info Stealer Campaign Exploits Trusted Windows Process
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:02:45 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #FortiGuard Labs #info_stealer #Phishing Campaign #Process Hollowing #PureLogs #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:02:45 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #FortiGuard Labs #info_stealer #Phishing Campaign #Process Hollowing #PureLogs #threat intelligence
Daily CyberSecurity
PureLogs Info Stealer Campaign Exploits Trusted Windows Process
FortiGuard Labs exposes a highly evasive PureLogs info stealer campaign utilizing process hollowing and fileless execution.
⤷ Title: Sophisticated GPU Cryptojacking Campaign Surfaced by Microsoft Experts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 07:11:24 +0000
════════════════════════
⌗ Tags: #Malware #AI Search Poisoning #GPU Cryptojacking #malware #Microsoft Defender #Process Hollowing #ScreenConnect #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 07:11:24 +0000
════════════════════════
⌗ Tags: #Malware #AI Search Poisoning #GPU Cryptojacking #malware #Microsoft Defender #Process Hollowing #ScreenConnect #threat intelligence
Daily CyberSecurity
Sophisticated GPU Cryptojacking Campaign Surfaced by Microsoft Experts
A stealthy GPU cryptojacking campaign leverages AI search poisoning and process hollowing injection to hijack high-end rigs. Read the Microsoft report.
⤷ Title: Reimage Downloader PUP Analysis
════════════════════════
𐀪 Author: Justin C.
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 20:08:41 GMT
════════════════════════
⌗ Tags: #infosec_write_ups #process #cybersecurity #infosec #computer_science
════════════════════════
𐀪 Author: Justin C.
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 20:08:41 GMT
════════════════════════
⌗ Tags: #infosec_write_ups #process #cybersecurity #infosec #computer_science
Medium
Reimage Downloader PUP Analysis
What do an Authenticode-signed executable, browser cookie harvesting, regsvr32 abuse, and filenames like invoice.exe and 不需要.exe have in…