> Field Notes_

Organic writeups, analysis, and research straight from the lab. My own words, my own work.

Building an Autonomous Malware Triage Stack

I ended my Kinsing post with an uncomfortable admission about an agent doing in two hours what took us a week. This is what happened when I stopped just thinking about it.

read more →

Agent Analysis: asgardprotector — IExpress SFX Dropper Repackaging AutoIt

Picked up by the deep tier overnight — six minutes of agent time to produce a full report with footnoted evidence. Worth publishing because the technique is dead simple to reproduce and the detection story isn't great.

read more →

Agent Analysis: acrstealer — Signed Go 1.26 with Randomized Module Path

A signed Go PE32 with the trimpath + randomized module name + obfuscated main combo. The C2 came from the OpenCTI label, not the binary — consistent with runtime-decoded configuration.

read more →

Agent Analysis: chacha8 — Tiny ChaCha20 File Encryptor With No C2

A 53 KB binary masquerading as svchost.exe that encrypts files in-place with ChaCha20 and leaves no ransom note, no C2, no kill switch. Completely offline. The agent flagged the cipher from the key-expansion constant in strings.

read more →

Was My Honeypot Part of a Loader-as-a-Service Operation?

When RondoDox hit our honeypot and Kinsing followed six hours later from a different C2, I had a theory. Turns out the research backs it up.

read more →

Dissecting a Mirai Variant: From Honeynet Capture to Ghidra

Walkthrough of capturing a RondoDox/Mirai IoT botnet variant in our honeynet deployment, extracting the binary, and performing static analysis in Ghidra to map C2 infrastructure.

read more →

Kinsing Crypto Miner: Catching a Live One

The first indicator wasn't one thing. It was a cascade of alerts, invisible files, and a file manager that contradicted everything the terminal was telling me.

read more →

Home Lab v3: Network Segmentation with pfSense

Latest iteration of the home lab network architecture. VLANs, firewall rules, and isolated zones for safe malware detonation and ongoing research.

read more →

> Threat Watch_

Current events in cybersecurity, summarized and posted as they happen. Threat intel, malware campaigns, supply chain attacks, new CVEs, AI security, anything worth paying attention to. Updated every two to five days via automated Cowork pipeline.

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

CISA added CVE-2026-28318, a high-severity SolarWinds Serv-U denial-of-service bug, to its Known Exploited Vulnerabilities catalog this week after spotting active exploitation in the wild.

read more →

Eight Federal Agencies Warn on Internet-Exposed Tank Gauges

A joint advisory from eight federal agencies warns that internet-exposed automatic tank gauge systems are under active malicious targeting across energy, chemical, and transportation sectors. The recommended fixes are basic but urgent: remove them from the public internet and enforce strong authentication.

read more →

SolarWinds Serv-U CVE-2026-28318 Added to CISA KEV Under Active Exploitation

CISA added SolarWinds Serv-U CVE-2026-28318 to the KEV catalog this week. The uncontrolled resource consumption flaw is under active exploitation, and file-transfer edge systems remain a reliable target for attackers.

read more →

Magento Cache Warmer Deserialization Flaw CVE-2026-45247 Added to CISA KEV

CISA added CVE-2026-45247 to its KEV catalog. The deserialization flaw in Mirasvit's Magento Full Page Cache Warmer is actively exploited and carries a CVSS score of 9.8.

read more →

CISA Adds 2022 Linux Kernel Bug and Android Zero-Day to KEV

CISA added two vulnerabilities to its KEV catalog this week: a four-year-old Linux kernel bug and an actively exploited Android Framework zero-day. Both are under active attack and should be prioritized immediately.

read more →

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog

CISA added CVE-2024-21182 to the KEV catalog. The two-year-old Oracle WebLogic flaw allows unauthenticated server takeover and is still being actively exploited in the wild.

read more →

CISA KEVs Palo Alto GlobalProtect Auth Bypass Under Active Exploitation

CISA added CVE-2026-0257 to the KEV catalog this week. An authentication bypass in Palo Alto PAN-OS GlobalProtect is being actively exploited to establish unauthorized VPN tunnels into enterprise networks.

read more →

North Korean Actor UNC1069 Backdoors Axios NPM Package in Supply Chain Attack

UNC1069 compromised the widely used axios NPM package to distribute the WAVESHAPER.V2 backdoor. If your builds pulled versions 1.14.1 or 0.30.4 on March 31, you need to hunt your dependency trees this week.

read more →

Google Tracks AI Distillation and Accelerated Adversarial Attack Tooling

Google Threat Intelligence Group reports threat actors are increasingly using AI to speed up reconnaissance, social engineering, and malware development, while also mounting model extraction distillation attacks against AI services.

read more →

Poisoned Nx Console VS Code Extension Used to Breach GitHub Employee and Repositories

CISA warns that a compromised Nx Console VS Code extension auto-updated to poisoned version 18.95.0, granting threat actors access to a GitHub employee device and internal repositories. Developer tooling is now a primary supply chain attack vector.

read more →

Mandiant Refreshes Destructive Attack Guidance as Geopolitical Tensions Rise

Mandiant released updated hardening guidance for destructive attacks, adding endpoint and MDM platform abuse to the watch list as global instability drives more wiper and ransomware activity.

read more →

DarkSword iOS Zero-Day Chain Spreads Across Surveillance and State Actors

GTIG's DarkSword report details six iOS zero-days already spreading across commercial surveillance vendors and suspected state-sponsored actors. The same exploit proliferation pipeline we watched with Coruna is repeating on modern iPhones.

read more →

Mandiant: Ransomware Profits Drop as Actor TTPs Shift Under Pressure

Mandiant's latest analysis shows ransomware profitability is declining due to better defenses and faster recovery. The real risk is how financially motivated actors adapt their tactics when margins shrink.

read more →

Iran's Back in U.S. OT, and They Didn't Need a Zero-Day

CISA's AA26-097A warns that Iran-linked APTs, likely CyberAv3ngers, are abusing internet-exposed Rockwell/Allen-Bradley PLCs to disrupt U.S. water, energy, and local government. No zero-day required, just bad exposure.

read more →

CVE-2024-3400: PAN-OS Command Injection, Patch Now

Critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect gateway. Active exploitation confirmed. CVSS 10.0.

read more →

APT29 Targets Energy Sector with Spear-Phishing Campaign

CISA advisory warns of renewed APT29 activity targeting U.S. energy infrastructure with sophisticated spear-phishing lures impersonating regulatory bodies.

read more →

Ivanti Connect Secure Auth Bypass Under Active Exploitation

CVE-2024-21887 authentication bypass in Ivanti Connect Secure being actively exploited in the wild. Chained with SSRF for remote code execution.

read more →

New Kinsing Campaign Targets Misconfigured Docker Hosts

Updated Kinsing variant scanning for exposed Docker API endpoints. Deploys XMRig miner and establishes persistence via cron jobs and rootkit modules.

read more →