Exploitation attempts for #React2Shell (CVE-2025-55182) have been widespread over the last week. Three resources that outline exploitation are:
https://t.co/rxa4WI7QoD
https://t.co/jQgUM8fnpQ
https://t.co/v84uIceGsg
Recommendation: Deploy patches as soon as possible
A technical analysis reveals that the Kimsuky threat group utilizes a JavaScript dropper to exfiltrate data from compromised systems, utilizing network IOCs and establishing persistence via Windows scheduled tasks. #CyberSecurity#MalwareAnalysis https://t.co/RSemBV1GRx
Community Resource Share: @CuratedIntel's CTI Research Guide
https://t.co/m2om4IwUPD
Start with this guide if you're finding it difficult to consistently and appropriately perform intelligence collection for your stakeholders.
We released Pulsedive 6.3 this week to Pulsedive Community. This scanning infrastructure update benefits all users and customers with better data enrichment and performance.
Details below
Sneak peek of the @BSidesNYC 0x04 badge. It's our first electronic badge, ever!
See it in action: https://t.co/gZ8vHGI95z
⏩ Credits
Photo: Hawkeye
Design: @1dark0ne
Build: @MakeAugusta
We're tracking the new DodgeBox (loader) & MoonWalk (backdoor) tools researched by the @Threatlabz team as related threat pages in our free Community Platform.
DodgeBox: https://t.co/7wA6blnWlH
MoonWalk: https://t.co/DnWh6A1WFS
APT41: https://t.co/0zTRZ4SBxT
New blog published, all about phishing kits: https://t.co/nVuLRZu97C
How do they work, what capabilities do they have, and most importantly - how can we better detect and protect against phishing kits?