⤷ Title: Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
Penetration Testing Tools
Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
The compromise of a perimeter network appliance can swiftly shepherd a malefactor toward domain controllers and the enterprise’s
⤷ Title: Signed, Trusted, and Abused: Proxy Execution via WebView2
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
Black Hills Information Security, Inc.
Signed, Trusted, and Abused: Proxy Execution via WebView2 - Black Hills Information Security, Inc.
An offensive security perspective on Microsoft Edge WebView2 Runtime, including architectural weaknesses, existing vulnerabilities, and exploitation methods.
⤷ Title: “Lorem Ipsum” Loader Weaponizing Microsoft Teams via SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
⌗ Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
⌗ Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
Daily CyberSecurity
"Lorem Ipsum" Loader Weaponizing Microsoft Teams via SEO Poisoning
BlueVoyant unmasks "Lorem Ipsum": a well-funded campaign using SEO poisoning and signed MS Teams installers to deploy stealthy backdoors via image files.
⤷ Title: KongTuke Abandoning “ClickFix” to Launch Direct Microsoft Teams Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
Daily CyberSecurity
KongTuke Abandoning "ClickFix" to Launch Direct Microsoft Teams Attacks
ReliaQuest warns Initial Access Broker "KongTuke" is abusing external Microsoft Teams chats to deploy the highly resilient ModeloRAT. Audit tenants now!
⤷ Title: The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
Information Security News
The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
North Korea’s adversarial presence within the digital theater has transcended the legacy paradigm of isolated, decentralized hacking collectives. Per comprehensive threat intelligence compiled by …
⤷ Title: Romanian Hacker Sentenced to Prison Following Government Cyberattacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
Daily CyberSecurity
Romanian Hacker Sentenced to Prison Following Government Cyberattacks
A Romanian hacker sentenced to prison following an identity theft conviction and selling access to a US government network infrastructure.
⤷ Title: DriveSurge Threat Cluster Exploits Thousands of Websites Globally
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 10:54:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #DriveSurge #FakeUpdates #Infrastructure Fingerprinting #initial access broker #malware delivery #social engineering #zTDS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 10:54:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #DriveSurge #FakeUpdates #Infrastructure Fingerprinting #initial access broker #malware delivery #social engineering #zTDS
Daily CyberSecurity
DriveSurge Threat Cluster Exploits Thousands of Websites Globally
The active DriveSurge threat cluster is compromising thousands of websites. Discover how its customized Traffic Distribution System redirects victims.
⤷ Title: FortiBleed Turns Hacked FortiGate Firewalls Into Credential Collectors
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 04:06:14 +0000
════════════════════════
⌗ Tags: #Data Leak #Credential Theft #FortiBleed #FortiGate #FortigateSniffer #Fortinet #Initial Access Broker
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 04:06:14 +0000
════════════════════════
⌗ Tags: #Data Leak #Credential Theft #FortiBleed #FortiGate #FortigateSniffer #Fortinet #Initial Access Broker
Information Security News
FortiBleed Turns Hacked FortiGate Firewalls Into Credential Collectors
FortiBleed began as mass password guessing. Then it grew into an attack chain, where hijacked firewalls gathered fresh credentials for the next breach. A new timeline shows that the published Fort…
⤷ Title: Edgecution Malware Turns a Microsoft Edge Extension Into a Backdoor
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 06:11:32 +0000
════════════════════════
⌗ Tags: #Malware #Edgecution #initial access broker #malicious Edge extension #microsoft edge #Native Messaging #Payouts King ransomware #Python backdoor #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 06:11:32 +0000
════════════════════════
⌗ Tags: #Malware #Edgecution #initial access broker #malicious Edge extension #microsoft edge #Native Messaging #Payouts King ransomware #Python backdoor #Zscaler ThreatLabz
Daily CyberSecurity
Edgecution Malware Turns a Microsoft Edge Extension Into a Backdoor
At a Glance Malware family Edgecution (malicious Microsoft Edge extension plus a Python backdoor) Threat actor Initial access broker assessed as tied to Payouts King ransomware Targets / victims E…
⤷ Title: GoGRPC Backdoor Spreads Through Microsoft Teams Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 08:09:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlindDoor #GoGRPC #initial access broker #Microsoft Teams vishing #Quick Assist #ransomware #RSOX #Vishing #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 08:09:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlindDoor #GoGRPC #initial access broker #Microsoft Teams vishing #Quick Assist #ransomware #RSOX #Vishing #Zscaler ThreatLabz
Daily CyberSecurity
GoGRPC Backdoor Spreads Through Microsoft Teams Vishing
At a glance Actor Unnamed threat actor, likely a ransomware initial access broker Activity Vishing-led intrusion and custom backdoor deployment Targets Corporate and enterprise Windows environment…