🔥 Gone in record time!
Super Early Bird tickets are officially sold out, but Early Bird tickets are still up for grabs. 🎟️
Don’t wait too long. Get yours before they’re gone too 👉https://t.co/G4HXQKrwz4
#vb2026#vbconference#cybersecurity#seville
⏰ Last chance to save €200!
The #VB2026 Early Bird rate is flying away today. Secure your place in Seville before the offer ends.
Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking.
🎟️https://t.co/Ul4DkqBvNJ
The #VB2026 call for last-minute papers - presenting 'hot' research and up-to-the-minute material - is now open. To share your research with an international audience of security experts submit your proposal now! https://t.co/kuqcPhZi3J
Elastic Security Labs is tracking Golden Gh0st RAT targeting Western companies, expanding beyond its previously documented targeting of financial organizations in the Asia-Pacific region.
Same TTPs as @ExpelSecurity CylindricalCanine research post: https://t.co/1HwpJUx1eY
The initial payload was delivered as a fake screenshot with a .pif extension, signed with a revoked certificate and hosted on myphotos[.]s[.]gy.
Follow-on payloads were staged in a public Google Cloud Storage bucket at storage[.]googleapis[.]com/nikeupdat/.
Multiple stages, and every one is either validly code-signed or never exists on disk as an executable.
Abused code-signing certificates, all valid at time of use.
Two are EV, same CA, both dated 2026-07, issued to two different "Private Organization" subjects:
- 杭州思维宇宙科技有限公司 (Hangzhou Siwei Yuzhou Technology), thumbprint: 14E0FCA3F0F656D1AF6EA66E1B2B7C6B4ACD8E2D
- Dongguan Jieshan Technology Co., Ltd, thumbprint: C29C3C494A348EA879ABFF50DD56B85E9CB6366A
IOCs:
api[.]probref[.]com:5188 (C2)
storage[.]googleapis[.]com/nikeupdat/
myphotos[.]s[.]gy
5ef6019fb6ee1db1201ee479a68669b47eb0d5d82770dbd30b05f46ccbc68f4f
b6cb6d5de2c62aa1351b1b240dc223c3d6fa95083cf43b2866d84a8a6c4d0446
Slides from my today's talk at #BlackHatUSA2026 : "Breaking the Seal: Static Deobfuscation of Compiled #V8 JavaScript Bytecode #Malware" : https://t.co/g4YeOvKMJy // #BHUSA#BlackHat2026
We're tracking a new EDR killer using a #BYOVD driver that isn't in Microsoft's block lists / #LOLDrivers and enumerates 140+ security products, including: Crowdstrike, SentinelOne, Microsoft Defender / Sentinel, Carbon Black, Cybereason, Cylance, Symantec, Sophos, FortiEDR, Elastic, Kaspersky, ESET, Avast / AVG, Bitdefender, McAfee / Trellix, Malwarebytes, Webroot, Trend Micro, Avira, Dr. Web, F-Protect / F-Secure, G-Data, Panda Security, and more.
All credits to @jgajek for finding it in the wild 🔥
It only activates if the payload being loaded contains ScreenConnect-related strings, uses IOCTL control code 0x2205c0, and passes each security product PID to terminate via input buffer to the driver via DeviceIOControl, which terminates the specified PID via ZwTerminateProcess.
BYOVD: https://t.co/qqhDFhFKiq
Blog coming soon on the loader, after Defcon of course!
A new Shai-Hulud campaign deployed a self-propagating worm across the npm supply chain.
Our supply chain monitor caught it yesterday, August 4th. The campaign targeted keyv: 600 million monthly downloads.
CHAINDROP activates on stolen npm tokens with write permissions, then backdoors every package the victim controls.
Over 400 npm packages compromised.
Full research and IOCs in the blog: https://t.co/ADYaOU6L0X
Microsoft researchers spotted a macOS ClickFix campaign spreading infostealers like MacSync & Atomic Stealer via lookalike domains. The campaign uses server-side browser fingerprinting, showing the lure mainly to visitors resembling genuine macOS browsers. https://t.co/AcKxvjwLoQ
Point Wild's LAT61 team analysed Vanta Stealer, a Python-based cross-platform infostealer targeting many apps & digital assets. A notable characteristic is its use of multiple PyArmor protection layers, combined with a PyInstaller-packaged executable. https://t.co/DSdXXSjRFN
We uncovered #DOUBLECUP, a ClickFix loader using steganography & IP-based environmental keying to deliver #CountLoader and #DeviceManager. DeviceManager is a novel RAT using #EtherHiding & DNS tunneling for covert C2.
https://t.co/W9jOhVCIfi
Adversaries are targeting the macOS developer community through open-source repositories. The latest XCSSET variant spreads by injecting code into Xcode projects, turning developer systems into supply chain vectors: https://t.co/wsK8VvJoAm
🚨 July’s major attacks put cloud accounts, financial activity, and data at risk.
Attackers abused 20+ government portals, fake AI invites, and M365 device code flows across the US, Europe, Brazil, and beyond.
How your SOC can detect & respond faster 👇
https://t.co/110LSRwPfs
Has anyone ever been so excited to get a spam email?
When someone purporting to be Bank of America emailed our honeytrap account, Huntress got a firsthand look at a phishing campaign.
Microsoft researchers describe ChainDrop, a largescale npm supply chain attack. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload https://t.co/ahOXIOUI8n
FortiGuard Labs details a campaign associated with a long-standing supply chain attack on the QuickFox application. QuickFox is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources. https://t.co/mC7eMajeW4
Netskope Threat Labs exposed a multi-stage SmartLoader chain targeting AI developers via impersonated GitHub repositories hosting popular AI resources, the lures including Claude, ComfyUI, AI coding assistants, Python security guides, and Rust frameworks. https://t.co/JvSfsKCh3R
Securonix researchers analyse SMOKE#SCREEN, a multi-wave campaign where attackers use rotating social engineering lures - fake Zoom updates, document reviews, and system maintenance tools - to deliver silent ScreenConnect RMM agent installations. https://t.co/mqY8fZ8Xsl
Larva-24009 공격자가 기업 대상 피싱 공격을 지속하고 있습니다.
문서로 위장한 LNK 파일을 실행하면 PowerShell 백도어와 Quasar RAT, UltraVNC가 설치돼 화면, 키 입력, 브라우저 저장 자격 증명이 탈취될 수 있습니다.
메일 첨부 파일뿐만 아니라 출처가 불분명한 실행 파일을 각별히 주의하시기 바랍니다.
🔗https://t.co/PFgWtA9Be4
🚨 The CrowdStrike 2026 Threat Hunting Report is here.
🤖 2.5X: CrowdStrike OverWatch has observed significant growth in AI agent-triggered detection leads, now tracking at 2.5x the rate of human-triggered leads.
⚡ 24 hours: China-nexus adversaries rapidly exploit vulnerabilities after effective PoC disclosure. Frontier AI is likely to collapse that window even further.
🔗 300+ software dependencies compromised by ALTERED SPIDER in a single day, demonstrating the automated, scalable nature of modern supply chain attacks.
The time to know your adversary is now.
Download the full report and get the latest frontline threat intelligence: https://t.co/n6Y90cGky8
Bitdefender researchers look into a malware campaign disguised as an undetected Xeno Roblox script executor variant. Promoted through various gaming forums & Discord communities, the fake cheat launches a multi-stage Java infection chain. https://t.co/gzn9sWgd0f