As someone who enjoys malware and malware accessories, I for one believe this to be incredible news and I applaud Satya Nadella for this
As someone who deals with malware defensively, I for one believe this is terrible news and I hate Satya Nadella so much right now it's unreal
Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
Shai-Hulud, that spoopy Git worm thingy everyones been yapping about, was open-sourced.
Unfortunately, GitHub has removed the repo.
This is terrible news.
It can no longer be studied... unless there was someone who collected this sort of thing and has a local copy...
.LNK files are implemented as COM objects. You need IShellLink + IPersistFile to create, read, or modify them programmatically. New video + write-up, code included, security angle too. https://t.co/rXhnOQSyxd
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
In April, we observed an intrusion that began with a malicious MSI masquerading as Sysinternals RAMMap and ended in domain-wide deployment of The Gentlemen ransomware.
The intrusion featured EtherRAT, Ethereum-based EtherHiding C2 configuration, TryCloudflare tunnels, GoTo Resolve, Rclone exfiltration to Wasabi, and a newer malware framework named TukTuk.
TukTuk stood out for its resilient C2 design, using SaaS and cloud platforms such as ClickHouse and Supabase, with support for Ably, Dropbox, GitHub Issues, direct HTTP, Slack, and Arweave-based dead-drop configuration retrieval.
Detection opportunities included!
➡️ Full report is linked in the replies.
#ThreatIntel #ThreatHunting #DigitalForensics