Our mission is simple: stop threats and help organizations #BeEverydayReady. We share the latest analysis, threat research, and findings from #HowlerCell.
New #HowlerCell Threat Research
Hours after @Microsoft shipped June Patch Tuesday fixes, the researcher known as Nightmare-Eclipse resurfaced on GitHub as #MSNightmare, publishing #RougePlanet, the 7th exploit targeting Defender in the cluster.
https://t.co/zeRDmlOlsg
Return of the Eclipse: #MSNightmare and #RoguePlanet
Analysis from @Cyderes#HowlerCell Threat Research team.
Hours after Microsoft shipped June Patch Tuesday fixes, the researcher resurfaced on GitHub as MSNightmare and published RoguePlanet, the seventh exploit in the cluster.
• New handle: MSNightmare (profile lists affiliation as "Microsoft")
• New exploit: RoguePlanet, a Defender zero-day
• Blog quote: "Microsoft cannot unwrite my code"
• Mirrors live on self-hosted Git: git.projectnightcrawler[.]dev/NightmareEclipse
• Blog: deadeclipse666.blogspot[.]com
The researcher is testing a ban-resistant publication model backed by self-hosted mirrors. Account takedowns no longer end the campaign.
#ThreatIntel #ZeroDay #PatchTuesday #VulnerabilityResearch #ThreatResearch
Read: https://t.co/1b3LiHH5En
Howler Cell's recent malware analysis highlighting the fake X-VPN installer deploying STX RAT was featured in @techradar by @monicajwrites.
Read more on TechRadar: https://t.co/QRwkAjMiED
@reegun21#HowlerCell#Cyderes
Credit to @xvpnteam for the fast fix and public acknowledgment of the report. Ten days from disclosure to patch is what responsible vendor response looks like.
@Cyderes#HowlerCell will keep publishing research like these so defenders can move faster than active campaigns.
Read the full analysis: https://t.co/2pfhQeoFRF
X-VPN's official statement: https://t.co/tzokGDoVJe
7/7 Anthropic is not compromised. The brand is being impersonated. The legitimate Claude Code installation path is unaffected.
Read the full breakdown here: https://t.co/Xx82SWhROm
1/7 HOWLER CELL NEWS: A first-time builder searched for "Claude Code install" because they finally believed they could build something, but here's what happened...
One credential. No device. Full tenant exposure.
Howler Cell put a production Microsoft Entra ID environment to the test. Conditional Access blocked the login, but it didn’t stop the attack. Mistrust creates real risk.
Read the full analysis: https://t.co/gUL8qdm7kn
Mythos was breached in hours, not months.
No advanced techniques, just a poisoned library, vendor compromise, and broken trust. It’s not if AI attackers reach you. It’s whether you’ll see them.
Read more from Howler Cell: https://t.co/HnGz3CTo5r
Howler Cell shares their findings on RedSun, a zero-day local privilege escalation exploit that enables standard users to gain SYSTEM-level access across Windows environments.
Our team breaks down how RedSun works and what defenders can do in response.
https://t.co/dqKXEU9gkW
⚠️ Howler Cell has identified a multistage intrusion sequence delivering two new malware families: Direct-Sys Loader and CGrabber Stealer. ⚠️
This is a coordinated malware ecosystem that gives attackers far more than just endpoint access.
Read now: https://t.co/4CXQ4rlPCo
Anthropic’s Mythos release is a clear signal that defenders need to act now.
Brian Hussey shares why this matters, how the existing defensive model is being tested, and why teams need to start now to prepare for the storm to come.
Read more: https://t.co/3JZjU3izlb
Howler Cell uncovered a supply chain compromise of CPUID’s HWMonitor delivering STX RAT through a multi-stage, fileless attack chain. If HWMonitor was downloaded between April 9–10, treat those systems as potentially compromised & take action immediately.
https://t.co/rzYLTaPHGq
🚨 BlueHammer: New Windows zero-day 🚨
Howler Cell has investigated BlueHammer, a Windows zero-day that is currently public, unpatched, and confirmed to work. Read the full breakdown of how the exploit chain operates and recommendations for defenders: https://t.co/0jNXfCNx4c
We're heading to @googlecloud Next 2026!⚡
Find us at Kiosk 4 in the Security Hub to see how we combine context, Google Cloud AI, and Meridian entity fabric to create a unified view, reducing analyst fatigue and identifying critical threats faster, with greater precision.