Microsoft Traces Four Ransomware Brands to One Repeating Playbook

The payload name changed across Qilin, DragonForce, Anubis and BERT deployments, but the operator kept returning to the same remote-access and exfiltration tools.
Vulnerabilities, defensive security, architecture and operational security.

The payload name changed across Qilin, DragonForce, Anubis and BERT deployments, but the operator kept returning to the same remote-access and exfiltration tools.

A MacSync downloader feeds a public iCloud calendar into zsh until it reaches commands hidden in the event description.

The AI agent is not the entry point. An unauthenticated Docker API is, and Carbonato turns it into privileged host access and automated post-compromise work.

SolarWinds patched two remote-code paths in its monitoring platform, but each depends on a specific non-default or communication configuration.

An incoming GitLab email address carries account authority. Research shows why a leaked address needs the same response as a leaked access token.

The enforcement decision is smaller than the breach headline, but its reasoning reaches every supplier handling concentrated public-sector data.

A pre-authentication SQL injection in Roundcube's virtuser_query plugin is now being exploited, four months after fixed versions shipped.

A password change can feed the new secret straight back to the attacker if the malicious authentication provider remains registered.

Bitget says unauthorised transfers affected approximately $351.6 million. The attack path remains under investigation.

The extension did not need to persuade the model. It impersonated the channel the browser’s privileged assistant was built to trust.