> Field Notes_

Organic writeups, analysis, and research straight from the lab. My own words, my own work.

Inside Two Separate Device-Code Phishing Operations and the Operator Who Told On Himself

Two live phishing kits crossed my desk. I set out to document how they steal Microsoft 365 sessions. I ended up reading one operator's admin panel, walking the other's victim database an integer at a time, and pulling the first kit's operator straight out of Telegram. Both of them made the same mistake: they protected everything except the thing that gave them away.

read more →

Building an Autonomous Malware Triage Stack

I ended my Kinsing post with an uncomfortable admission about an agent doing in two hours what took us a week. This is what happened when I stopped just thinking about it.

read more →

Agent Analysis: asgardprotector — IExpress SFX Dropper Repackaging AutoIt

Picked up by the deep tier overnight — six minutes of agent time to produce a full report with footnoted evidence. Worth publishing because the technique is dead simple to reproduce and the detection story isn't great.

read more →

Agent Analysis: acrstealer — Signed Go 1.26 with Randomized Module Path

A signed Go PE32 with the trimpath + randomized module name + obfuscated main combo. The C2 came from the OpenCTI label, not the binary — consistent with runtime-decoded configuration.

read more →

Agent Analysis: chacha8 — Tiny ChaCha20 File Encryptor With No C2

A 53 KB binary masquerading as svchost.exe that encrypts files in-place with ChaCha20 and leaves no ransom note, no C2, no kill switch. Completely offline. The agent flagged the cipher from the key-expansion constant in strings.

read more →

Was My Honeypot Part of a Loader-as-a-Service Operation?

When RondoDox hit our honeypot and Kinsing followed six hours later from a different C2, I had a theory. Turns out the research backs it up.

read more →

Dissecting a Mirai Variant: From Honeynet Capture to Ghidra

Walkthrough of capturing a RondoDox/Mirai IoT botnet variant in our honeynet deployment, extracting the binary, and performing static analysis in Ghidra to map C2 infrastructure.

read more →

Kinsing Crypto Miner: Catching a Live One

The first indicator wasn't one thing. It was a cascade of alerts, invisible files, and a file manager that contradicted everything the terminal was telling me.

read more →

Home Lab v3: Network Segmentation with pfSense

Latest iteration of the home lab network architecture. VLANs, firewall rules, and isolated zones for safe malware detonation and ongoing research.

read more →

> Threat Watch_

Current events in cybersecurity, summarized and posted as they happen. Threat intel, malware campaigns, supply chain attacks, new CVEs, AI security, anything worth paying attention to. Updated every two to five days via automated Cowork pipeline.

CISA Adds Check Point SmartConsole and SharePoint Flaws to KEV Catalog

CISA confirmed active exploitation of two vulnerabilities this week: an improper authentication bug in Check Point SmartConsole and a deserialization flaw in Microsoft SharePoint. Federal agencies must now patch and hunt for pre-patch compromise under BOD 26-04.

read more →

CISA Adds WordPress Core, Langflow, and DD-WRT to KEV Catalog

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog, including two 2026 WordPress Core bugs, a Langflow flaw, and a four-year-old DD-WRT buffer overflow. Federal agencies now face tiered remediation deadlines under BOD 26-04.

read more →

CISA Adds Actively Exploited SharePoint RCE Zero-Day to KEV Catalog

CISA added CVE-2026-58644, a critical deserialization flaw in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog with a patch deadline of July 19 for federal agencies. If you still have on-prem SharePoint anywhere in your environment, that is your weekend priority.

read more →

CISA: AutomationDirect Productivity Suite Flaws Enable Local Privilege Escalation

CISA issued ICSA-26-197-04 for six vulnerabilities in AutomationDirect Productivity Suite 4.6.2.2 and earlier. Local attackers can exploit kernel memory corruption flaws to escalate privileges on engineering workstations bridging IT and OT.

read more →

Joomla iCagenda and Balbooa Forms Flaws Exploited as CVSS-10 Zero-Days

CISA added two maximum-severity flaws in Joomla extensions iCagenda and Balbooa Forms to its KEV catalog after observing active zero-day exploitation. Arbitrary file upload vulnerabilities allow remote code execution on affected sites.

read more →

FSB Center 16 Targets Critical Infrastructure Through Edge Router Exploitation

CISA, NSA, and international partners warn that Russian FSB Center 16 actors continue to compromise critical infrastructure networks by exploiting poorly configured edge routers and networking devices. Audit your perimeter this week.

read more →

CISA Adds FortiSandbox and SharePoint Vulnerabilities to KEV Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including two OS command injection flaws in FortiSandbox and a deserialization bug in SharePoint. All three are confirmed under active exploitation.

read more →

CISA Adds Actively Exploited KNX Protocol and Oracle EBS Flaws to KEV Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including a building automation protocol flaw and an Oracle E-Business Suite privilege bug. Both are under active exploitation and now carry BOD 26-04 remediation obligations for federal agencies.

read more →

CISA Adds SonicWall and SharePoint Flaws to Known Exploited Vulnerabilities Catalog

CISA added four new vulnerabilities to its KEV catalog, including SSRF and code injection flaws in SonicWall SMA1000 appliances and authentication bypass issues in Microsoft SharePoint and ADFS. All four are confirmed as actively exploited and grant total control of affected assets.

read more →

CISA Flags 18-Year-Old Cisco IOS CSRF Under Active Exploitation

CISA added an 18-year-old Cisco IOS CSRF vulnerability to its KEV catalog. If you still have public-facing web admin on edge routers, this is your Monday morning priority.

read more →

Hydro-Québec EV Charging Backend Hit by 9.8 CVSS Websocket Auth Bypass

CISA advisory ICSA-26-188-01 details CVE-2026-20744 in Hydro-Québec's Le Circuit Electrique charging station backend, where an unauthenticated websocket endpoint allows privilege escalation. Versions prior to June 2026 are affected, and Hydro-Québec has updated the majority of its fleet.

read more →

Microsoft Details GigaWiper Backdoor Combining Wiper and Fake Ransomware

Microsoft analyzed GigaWiper, a destructive Windows backdoor that combines disk wiping, spyware, and fake ransomware into a single operator-controlled platform. The malware lets attackers choose their destruction method from a menu of previously separate tools.

read more →

CISA Adds Joomla iCagenda and Balbooa Forms Upload Flaws to KEV Catalog

CISA has added two unrestricted file upload vulnerabilities in the Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog. If you are running either plugin, patch this week.

read more →

CISA Adds Adobe ColdFusion Path Traversal to KEV Under New BOD Rules

CISA added CVE-2026-48282, an actively exploited Adobe ColdFusion path traversal, to the KEV catalog. The entry comes as BOD 26-04 mandates rapid, risk-based remediation for federal agencies.

read more →

CISA Adds Three KEVs Targeting Joomla Page Builders and Langflow

CISA added three new KEVs on Tuesday, including two Joomla page builder plugins and a Langflow authorization bypass. All three grant total control of the asset and demand immediate patching.

read more →

Siemens SINEC OS Flaws Hit RUGGEDCOM Industrial Switches with CVSS 9.8 Severity

Siemens patched SINEC OS for the RUGGEDCOM RST2428P after CISA disclosed a CVSS 9.8 cluster of memory safety and access control flaws. The advisory reads like a catalog of fundamental security failures in industrial network gear.

read more →

Progress Kemp LoadMaster Pre-Auth RCE Under Active Exploitation

eSentire's TRU says attackers are already exploiting CVE-2026-8037, a pre-authentication OS command injection in Progress Kemp LoadMaster rated CVSS 9.6. If you are running LoadMaster on the edge, this is a patch-now event.

read more →

CISA Adds SharePoint Deserialization RCE CVE-2026-45659 to KEV Under Active Exploitation

CISA confirmed active exploitation of CVE-2026-45659, a CVSS 8.8 deserialization flaw in Microsoft SharePoint Server patched in May. If your farm is still unpatched, this is your Monday morning priority.

read more →

Ransomware Gangs Exploiting Windows Defender BlueHammer Privilege Escalation

CISA confirmed this week that ransomware gangs are actively exploiting the BlueHammer local privilege escalation flaw in Windows Defender, shifting a previously abused zero-day into broad commodity operations.

read more →

Anubis Ransomware Exploits Citrix Bleed 2 via RMM and Credentials

Threat actors linked to Anubis are actively exploiting CVE-2025-5777 to breach networks, then using legitimate RMM tools and stolen credentials for hands-on-keyboard lateral movement and payload deployment.

read more →

Oracle E-Business Suite Payments Bug CVE-2026-46817 Actively Exploited

A critical authentication and privilege flaw in Oracle E-Business Suite Payments is being actively exploited to take over instances. Defused Cyber reports in-the-wild attacks against CVE-2026-46817, rated CVSS 9.8.

read more →

CISA KEVs SharePoint Deserialization Bug Under Active Exploitation

CISA added CVE-2026-45659 to the KEV catalog. A Microsoft SharePoint deserialization flaw is actively exploited, and BOD 26-04 means federal agencies must now hunt for pre-patch compromise.

read more →

CISA Adds SimpleHelp Authentication Bypass to KEV Catalog Under Active Exploitation

CISA added CVE-2026-48558, a SimpleHelp authentication bypass, to the KEV catalog. If you run this remote support tool, assume active exploitation and patch now while checking for pre-patch compromise.

read more →

DirtyClone Linux Kernel Bug Gives Local Attackers Root via Cloned Packets

JFrog Security Research published a working exploit for DirtyClone (CVE-2026-43503), a Linux kernel privilege escalation that lets local users gain root by corrupting file-backed memory through cloned network packets. In containerized environments, local is all an attacker needs.

read more →

Delta Electronics DTM Soft Flaw Allows Arbitrary Code Execution via Project Files

CISA issued an advisory for CVE-2026-12578, a deserialization flaw in Delta Electronics DTM Soft affecting all versions. With no patch available yet, critical manufacturing sectors worldwide are left relying on file-handling workarounds to prevent arbitrary code execution.

read more →

Unauthenticated WebSocket APIs in EVoke Charging System Score CVSS 9.4

CISA issued an advisory for EVoke Systems CSMS, citing a CVSS 9.4 bug and multiple authentication failures that let attackers impersonate charging stations and gain admin control.

read more →

CISA Adds PTC Windchill RCE to KEV Amid Ongoing Web Shell Campaign

CISA confirmed an actively exploited RCE in PTC Windchill PDMLink and FlexPLM, adding it to the KEV catalog as web shell attacks against enterprise PLM systems continue. Manufacturing and critical infrastructure defenders should treat this as an acute, patch-now threat.

read more →

CISA Adds PTC Windchill and Cisco CUCM to KEV Under Active Exploitation

CISA added two enterprise software vulnerabilities to the KEV catalog this week, including a PTC Windchill input validation flaw and a Cisco Unified Communications Manager SSRF. Both are actively exploited and fall under BOD 26-04's new rapid-remediation rules for federal agencies.

read more →

ABB Freelance Security Lock Exposes Underlying OS During Active Operations

CISA warns that ABB Freelance Security Lock allows access to underlying OS functions even when Operations mode is active, affecting all versions across Freelance 2013 through 2024.

read more →

CISA Adds Three Ubiquiti UniFi OS Flaws and Lantronix Bug to KEV Catalog

CISA added four actively exploited vulnerabilities to its KEV catalog, including three Ubiquiti UniFi OS bugs and a Lantronix EDS5000 code injection flaw. Edge network and serial gateway infrastructure continue to be prime targets.

read more →

ShapedPlugin Pro Plugins Backdoored Through Official Update Pipeline

Attackers compromised ShapedPlugin's build pipeline and pushed backdoored code to Pro plugins through official licensed update channels. Paying customers received the malware as part of routine, trusted updates.

read more →

AzeoTech DAQFactory CVE-2026-12390 Allows Code Execution via Malicious .ctl Files

CISA issued an ICS advisory for AzeoTech DAQFactory versions 21.1 and prior. A type-confusion flaw in CVE-2026-12390 lets attackers achieve arbitrary code execution by tricking users into loading malicious .ctl files.

read more →

Rockwell FactoryTalk Historian SE Auth Bypass and Race Condition Disclosed by CISA

CISA disclosed three vulnerabilities in Rockwell FactoryTalk Historian Site Edition, including an authentication bypass that yields valid tokens after repeated login requests. Critical manufacturing sites should isolate and patch these systems immediately.

read more →

Cisco Patches Actively Exploited SD-WAN Manager Flaw

Cisco fixed CVE-2026-20262 in Catalyst SD-WAN Manager after seeing active exploitation. The authenticated web UI bug scores 6.5, but any live fire against your WAN brain is worth treating as critical.

read more →

CISA Adds Splunk Enterprise Missing Auth Bug to KEV as BOD 26-04 Reshapes Patching

CISA added CVE-2026-20253 to its KEV catalog: a missing-authentication flaw in Splunk Enterprise confirmed under active exploitation. The timing underscores how BOD 26-04 is forcing sharper prioritization of publicly exposed assets that grant total control.

read more →

CISA Adds Maximum Severity Joomla JCE Flaw to KEV Catalog

CISA has added CVE-2026-48907, a maximum-severity improper access control flaw in the Widget Factory Joomla Content Editor, to its KEV catalog. Federal agencies face a rapid patching deadline under BOD 26-04.

read more →

Oracle PeopleSoft Zero-Day Actively Exploited by ShinyHunter for Data Theft

Oracle is warning of a critical unauthenticated RCE zero-day in PeopleSoft Suite tracked as CVE-2026-35273. ShinyHunter is actively exploiting the flaw to steal enterprise HR and financial data.

read more →

CISA Adds Cisco SD-WAN and LiteSpeed Flaws to KEV Catalog

CISA added two actively exploited flaws to its KEV catalog alongside BOD 26-04, which directs federal agencies to prioritize patches for publicly exposed assets that grant total control post-exploitation.

read more →

Unpatched Langflow RCE Flaw CVE-2026-5027 Under Active Exploitation

VulnCheck reports active exploitation of CVE-2026-5027, an unpatched path-traversal flaw in the Langflow AI platform that grants unauthenticated attackers arbitrary file write and subsequent remote code execution.

read more →

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Extort Universities

Mandiant and Google report that UNC6240, known as ShinyHunters, actively exploited CVE-2026-35273 in Oracle PeopleSoft as a zero-day. The campaign primarily hit higher education institutions, with most victim organizations notified in the United States.

read more →

Ivanti Sentry Command Injection Lands in KEV as BOD 26-04 Takes Effect

CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog alongside a new federal directive that changes how agencies prioritize patches and prove compromise before remediation.

read more →

CISA Adds Chrome V8, Arista EOS, and Cisco SD-WAN to KEV Catalog Under Active Exploitation

CISA added three actively exploited vulnerabilities to the KEV catalog, spanning Chrome's V8 engine, Arista EOS, and Cisco Catalyst SD-WAN Manager. Federal agencies face binding remediation deadlines, but every organization should treat these as patch-this-week priorities.

read more →

CISA KEVs: LiteLLM Command Injection and Check Point Gateway Auth Bypass Under Active Exploit

CISA added two vulnerabilities to the KEV catalog Monday: command injection in BerriAI LiteLLM and an authentication flaw in Check Point Security Gateways. Both are being actively exploited.

read more →

Unpatched Cisco SD-WAN Manager Zero-Day Actively Exploited for Root Access

Cisco confirmed active exploitation of CVE-2026-20245, a high-severity zero-day in Catalyst SD-WAN Manager that enables root privilege escalation. No patch is available yet, and the flaw affects on-prem, cloud, and FedRAMP deployments.

read more →

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

CISA added CVE-2026-28318, a high-severity SolarWinds Serv-U denial-of-service bug, to its Known Exploited Vulnerabilities catalog this week after spotting active exploitation in the wild.

read more →

Eight Federal Agencies Warn on Internet-Exposed Tank Gauges

A joint advisory from eight federal agencies warns that internet-exposed automatic tank gauge systems are under active malicious targeting across energy, chemical, and transportation sectors. The recommended fixes are basic but urgent: remove them from the public internet and enforce strong authentication.

read more →

SolarWinds Serv-U CVE-2026-28318 Added to CISA KEV Under Active Exploitation

CISA added SolarWinds Serv-U CVE-2026-28318 to the KEV catalog this week. The uncontrolled resource consumption flaw is under active exploitation, and file-transfer edge systems remain a reliable target for attackers.

read more →

Magento Cache Warmer Deserialization Flaw CVE-2026-45247 Added to CISA KEV

CISA added CVE-2026-45247 to its KEV catalog. The deserialization flaw in Mirasvit's Magento Full Page Cache Warmer is actively exploited and carries a CVSS score of 9.8.

read more →

CISA Adds 2022 Linux Kernel Bug and Android Zero-Day to KEV

CISA added two vulnerabilities to its KEV catalog this week: a four-year-old Linux kernel bug and an actively exploited Android Framework zero-day. Both are under active attack and should be prioritized immediately.

read more →

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog

CISA added CVE-2024-21182 to the KEV catalog. The two-year-old Oracle WebLogic flaw allows unauthenticated server takeover and is still being actively exploited in the wild.

read more →

CISA KEVs Palo Alto GlobalProtect Auth Bypass Under Active Exploitation

CISA added CVE-2026-0257 to the KEV catalog this week. An authentication bypass in Palo Alto PAN-OS GlobalProtect is being actively exploited to establish unauthorized VPN tunnels into enterprise networks.

read more →

North Korean Actor UNC1069 Backdoors Axios NPM Package in Supply Chain Attack

UNC1069 compromised the widely used axios NPM package to distribute the WAVESHAPER.V2 backdoor. If your builds pulled versions 1.14.1 or 0.30.4 on March 31, you need to hunt your dependency trees this week.

read more →

Google Tracks AI Distillation and Accelerated Adversarial Attack Tooling

Google Threat Intelligence Group reports threat actors are increasingly using AI to speed up reconnaissance, social engineering, and malware development, while also mounting model extraction distillation attacks against AI services.

read more →

Poisoned Nx Console VS Code Extension Used to Breach GitHub Employee and Repositories

CISA warns that a compromised Nx Console VS Code extension auto-updated to poisoned version 18.95.0, granting threat actors access to a GitHub employee device and internal repositories. Developer tooling is now a primary supply chain attack vector.

read more →

Mandiant Refreshes Destructive Attack Guidance as Geopolitical Tensions Rise

Mandiant released updated hardening guidance for destructive attacks, adding endpoint and MDM platform abuse to the watch list as global instability drives more wiper and ransomware activity.

read more →

DarkSword iOS Zero-Day Chain Spreads Across Surveillance and State Actors

GTIG's DarkSword report details six iOS zero-days already spreading across commercial surveillance vendors and suspected state-sponsored actors. The same exploit proliferation pipeline we watched with Coruna is repeating on modern iPhones.

read more →

Mandiant: Ransomware Profits Drop as Actor TTPs Shift Under Pressure

Mandiant's latest analysis shows ransomware profitability is declining due to better defenses and faster recovery. The real risk is how financially motivated actors adapt their tactics when margins shrink.

read more →

Iran's Back in U.S. OT, and They Didn't Need a Zero-Day

CISA's AA26-097A warns that Iran-linked APTs, likely CyberAv3ngers, are abusing internet-exposed Rockwell/Allen-Bradley PLCs to disrupt U.S. water, energy, and local government. No zero-day required, just bad exposure.

read more →

CVE-2024-3400: PAN-OS Command Injection, Patch Now

Critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect gateway. Active exploitation confirmed. CVSS 10.0.

read more →

APT29 Targets Energy Sector with Spear-Phishing Campaign

CISA advisory warns of renewed APT29 activity targeting U.S. energy infrastructure with sophisticated spear-phishing lures impersonating regulatory bodies.

read more →

Ivanti Connect Secure Auth Bypass Under Active Exploitation

CVE-2024-21887 authentication bypass in Ivanti Connect Secure being actively exploited in the wild. Chained with SSRF for remote code execution.

read more →

New Kinsing Campaign Targets Misconfigured Docker Hosts

Updated Kinsing variant scanning for exposed Docker API endpoints. Deploys XMRig miner and establishes persistence via cron jobs and rootkit modules.

read more →