⤷ Title: OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
Daily CyberSecurity
OceanLotus Hijacks PyPI to Deploy "ZiChatBot" via Enterprise Chat APIs
OceanLotus targets Python developers worldwide via PyPI supply chain attacks. New ZiChatBot malware hijacks Zulip APIs for invisible C2 traffic. Patch now!
⤷ Title: Dragon Breath’s Leaked Driver Shatters Windows Security and Neutralizes EDRs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:13:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_Q_27 #APT31 #BYOVD #CrowdStrike #Cyber Espionage #Dragon Breath #dragoncore_k.sys #EDR Bypass #Kernel Driver #Malware 2026 #Microsoft Defender #SentinelOne #Zhengzhou 403
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:13:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_Q_27 #APT31 #BYOVD #CrowdStrike #Cyber Espionage #Dragon Breath #dragoncore_k.sys #EDR Bypass #Kernel Driver #Malware 2026 #Microsoft Defender #SentinelOne #Zhengzhou 403
Penetration Testing Tools
Dragon Breath’s Leaked Driver Shatters Windows Security and Neutralizes EDRs
The Chinese cyber-espionage collective Dragon Breath, also recognized by the designation APT-Q-27, has purportedly acquired a formidable new
⤷ Title: Hunting Advanced Persistent Threats (APT): 13 Years Inside the World of Elite Cyber Adversaries
════════════════════════
𐀪 Author: Vahid Ali CyberSecurity
════════════════════════
ⴵ Time: Fri, 08 May 2026 05:37:56 GMT
════════════════════════
⌗ Tags: #cyber_threat_intelligence #ethical_hacking #apt #threat_hunting #cybersecurity
════════════════════════
𐀪 Author: Vahid Ali CyberSecurity
════════════════════════
ⴵ Time: Fri, 08 May 2026 05:37:56 GMT
════════════════════════
⌗ Tags: #cyber_threat_intelligence #ethical_hacking #apt #threat_hunting #cybersecurity
Medium
Hunting Advanced Persistent Threats (APT): 13 Years Inside the World of Elite Cyber Adversaries
By Vahid Ali — Cybersecurity Professional & Threat Hunter
⤷ Title: 【威脅情資】UAC-0184 攻擊鏈分析
════════════════════════
𐀪 Author: segalee
════════════════════════
ⴵ Time: Tue, 26 May 2026 02:01:03 GMT
════════════════════════
⌗ Tags: #infosec #uac_0184 #apt #blue_team #cybersecurity
════════════════════════
𐀪 Author: segalee
════════════════════════
ⴵ Time: Tue, 26 May 2026 02:01:03 GMT
════════════════════════
⌗ Tags: #infosec #uac_0184 #apt #blue_team #cybersecurity
Medium
【威脅情資】UAC-0184 攻擊鏈分析
本文並非完整還原原始 UAC-0184 樣本,而是根據公開情資整理其攻擊鏈,並透過 Lab 環境模擬其中幾個關鍵可觀察行為
⤷ Title: New Screening Serpens Cyberattacks Target Global Technology Professionals
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 12:54:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppDomain Manager Hijacking #APT group #cyber_espionage #Malware Variants #Screening Serpens #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 12:54:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppDomain Manager Hijacking #APT group #cyber_espionage #Malware Variants #Screening Serpens #threat intelligence #Unit 42
Daily CyberSecurity
New Screening Serpens Cyberattacks Target Global Technology Professionals
Learn about the latest Screening Serpens cyberattacks exposed by Unit 42. Discover their new RAT variants and advanced defensive evasion tactics.
⤷ Title: Breach Files #003: SolarWinds 2020
════════════════════════
𐀪 Author: NullyBlissful
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 12:24:23 GMT
════════════════════════
⌗ Tags: #threat_intelligence #apt #mitre_attack #infosec #cybersecurity
════════════════════════
𐀪 Author: NullyBlissful
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 12:24:23 GMT
════════════════════════
⌗ Tags: #threat_intelligence #apt #mitre_attack #infosec #cybersecurity
Medium
Breach Files #003: SolarWinds 2020
The Attackers Who Were Inside for 14 Months — And Nobody Noticed
⤷ Title: Khmer Shadow Espionage Campaign Targets Cambodian Government
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 07:30:12 +0000
════════════════════════
⌗ Tags: #Malware #Acronis #APT #Cambodia #DLL Sideloading #Espionage #Havoc Demon #Khmer Shadow #NIGHTFORGE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 07:30:12 +0000
════════════════════════
⌗ Tags: #Malware #Acronis #APT #Cambodia #DLL Sideloading #Espionage #Havoc Demon #Khmer Shadow #NIGHTFORGE
Daily CyberSecurity
Khmer Shadow Espionage Campaign Targets Cambodian Government
Acronis reveals Khmer Shadow, a new espionage campaign using NIGHTFORGE loader and DLL sideloading to target Cambodian government entities with Havoc Demon.
⤷ Title: Australian Infrastructure Cyberattack: ASIO Warning
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 04:28:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT groups #ASIO #Australian Infrastructure Cyberattack #Critical Infrastructure #cyber sabotage
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 04:28:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT groups #ASIO #Australian Infrastructure Cyberattack #Critical Infrastructure #cyber sabotage
Information Security News
Australian Infrastructure Cyberattack: ASIO Warning
Cyberattacks against critical infrastructure increasingly resemble strategic positioning rather than isolated breaches. Consequently, threat actors prepare for future disruptions. The Australian S…
⤷ Title: OpenSSL Error Handling Defect Breaks apt HTTPS Access in FIPS Mode
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 13:23:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #Debian #ERR_clear_error #error queue #FIPS mode #openssl #OpenSSL error handling #Secure Coding #tls
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 13:23:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #Debian #ERR_clear_error #error queue #FIPS mode #openssl #OpenSSL error handling #Secure Coding #tls
Daily CyberSecurity
OpenSSL Error Handling Defect Breaks apt HTTPS Access in FIPS Mode
TL;DR A Debian maintainer flagged a widespread OpenSSL error handling problem across the open-source ecosystem. It surfaced when apt failed HTTPS repository access on FIPS-only systems, then trace…
⤷ Title: Armored Likho APT Deploys New BusySnake Stealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 07:11:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Armored Likho #BusySnake Stealer #malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 07:11:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Armored Likho #BusySnake Stealer #malware
Daily CyberSecurity
Armored Likho APT Deploys New BusySnake Stealer
At a Glance Actor or group: Armored Likho APT (suspected) Activity type: Spear-phishing and information theft Targets or victims: Government agencies and the electric power sector Scale: Global op…