Black Discord Malware: XWorm

PC Security Channel·37K views · 3 months ago

I stumbled across a Malware named "Black Discord", turned out to be an interesting XWorm trojan that can act as both infostealer and ransomware.

MalwareBitdefender Labs·3 months ago

Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows

Microsoft's MSHTA utility, a legacy Windows tool that executes VBScript and JavaScript, remains an active attack vector despite its age, with security researchers at Bitdefender documenting ongoing malware campaigns leveraging the default-available application. Attackers continue to abuse MSHTA's capability to run scripts from both local and remote sources, demonstrating the persistent threat posed by legacy Windows components that lack built-in protections against modern exploitation techniques.

Policy & LegalWeLiveSecurity·3 months ago

The quest for greater tech independence

A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies

VulnerabilityCloudflare Blog·3 months ago

Project Glasswing: what Mythos showed us

In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.

HackTheBox - Pterodactyl

IppSec·7.1K views · 3 months ago

01:05 - Start of nmap 04:00 - Using ffuf to find the panel subdomain, which shows pterodactyl.htb 06:30 - Discovering the version of pterodactyl running by looking at the GitHub Releases and looking for the js bundle name 10:00 - Searching CVE's finding the Pterodactyl CVE-2025-49132 POC, and running an exploit script 17:00 - Finding PHP PEAR directory which allows our exploit to run 19:05 - Looking at the source code, and running through the exploit manually 36:00 - Shell on the box dump the database, crack a cred to get an account 43:40 - Looking at CVE-2025-6018 which lets us impersonate a physical logged in user in policy kit 46:25 - Exploiting CVE-2025-6019 which is a CVE in UDISKS, when it does the resize it mounts a partition without the NOSUID flag 52:55 - Starting a script to execute bash in our malicious mount, then telling udisks to resize it and getting a shell

VulnerabilityZero Day Initiative·3 months ago

Pwn2Own Berlin 2026: Day Three Results and Master of Pw

Pwn2Own Berlin 2026 concluded with Day Three results, awarding a total of $1,298,250 across 47 unique zero-day vulnerabilities discovered throughout the three-day competition. DEVCORE dominated the event to claim Master of Pwn honors with 50.5 points and $505,000, followed by STARLabs SG in second place and Out Of Bounds in third. Day Three featured nine exploit attempts targeting enterprise systems including Windows 11, Red Hat Linux, VMware ESXi, Microsoft SharePoint, and AI platforms, with notable successes including a $200,000 award for cross-tenant code execution in VMware ESXi and a $100,000 win for a SharePoint exploit chain.

VulnerabilityZero Day Initiative·3 months ago

Pwn2Own Berlin 2026 - Day Two Results

Day Two of Pwn2Own Berlin 2026 concluded with researchers demonstrating 15 unique zero-day vulnerabilities across enterprise targets including Microsoft Exchange, Cursor, and Red Hat Enterprise Linux, with Orange Tsai of DEVCORE earning the day's top prize of $200,000 for a three-bug chain achieving remote code execution on Exchange. The competition has now awarded $908,750 total for 39 unique 0-days across two days, with DEVCORE maintaining a commanding lead at 40.5 Master of Pwn points and $405,000 in winnings heading into the final day.

VulnerabilityZero Day Initiative·3 months ago

Pwn2Own Berlin 2026 - Day One Results

Day One of Pwn2Own Berlin 2026 saw 22 security research teams compete across AI databases, coding agents, local inference systems, and NVIDIA products, with successful exploits earning $523,000 in total payouts for 24 unique zero-days. DEVCORE currently leads the Master of Pwn leaderboard after Orange Tsai's team demonstrated a four-bug chain for a Microsoft Edge sandbox escape worth $175,000, though multiple other teams achieved significant breakthroughs targeting LiteLLM, NVIDIA Megatron Bridge, and various Windows privilege escalation vectors. Several entries failed to execute within time limits or were withdrawn, while a handful of successful exploits were marked as collisions after vendors disclosed the researchers had used previously known vulnerabilities.

VulnerabilityGoogle Project Zero·3 months ago

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Google Project Zero disclosed a 0-click exploit chain for the Pixel 10 that chains a Dolby audio decoder vulnerability (CVE-2025-54957) with a critical flaw in the VPU driver to achieve kernel code execution from an unprivileged context. The VPU vulnerability, discovered during a 2-hour audit, allows unbounded physical memory mapping through an insufficient bounds check in the mmap handler, enabling arbitrary kernel memory read-write access with minimal exploit complexity and patched within 71 days of disclosure in the February security bulletin.

RansomwareThe DFIR Report·3 months ago

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

EtherRAT malware, which emerged in December 2025 with initial Linux exploitation via CVE-2025-55182, evolved to target Windows systems by March 2026 with activity traceable back to its discovery. The threat culminated in April when EtherRAT and TukTuk C2 infrastructure were leveraged in campaigns deploying The Gentleman ransomware. This progression demonstrates the rapid weaponization and expansion of the malware family across multiple platforms and attack stages.

HackTheBox - Overwatch

IppSec·8.8K views · 3 months ago

00:00 - Introduction 00:45 - Start of nmap 03:00 - Null Authentication lets us list open shares 05:30 - Using SMBClient and downloading the overwatch binary and config from the fileshare 08:40 - Using ilSpycmd to decompile the dotnet from Linux 10:04 - Looking at the overwatch source, which is a WCF (Windows Communication Foundation) Binary 14:00 - Taking nmap allports output, doing some bashful to get a list of open ports to do our normal nmap against the open ports 17:40 - Finding MSSQL on port 6520, we can login. The Enum_Links shows an SQL Server, it hangs and says the host SQL07 doesn't exist 21:45 - Using BloodyAD to show AD Attributes we can write to, discover we can create DNS Entries, then creating a DNS Entry for SQL07 to point back to us and then getting the SQLMGMT user credentials 25:00 - Looking at the WCF Endpoint, examining the WSDL and explaining it a little bit 26:30 - Executing endpoints in the WCF Endpoint from PowerShell with New-WebServiceProxy and getting RCE on the server 33:00 - Showing how we could have enumerated services from our first shell

VulnerabilityCloudflare Blog·3 months ago

How Cloudflare responded to the “Copy Fail” Linux vulnerability

When a critical Linux kernel privilege escalation vulnerability became public, Cloudflare's security and engineering teams rapidly detected and investigated the threat across their infrastructure. The company confirmed that the vulnerability resulted in zero customer impact and no evidence of malicious exploitation in their global fleet.

MalwareWeLiveSecurity·3 months ago

Fake call logs, real payments: How CallPhantom tricks Android users

ESET researchers discovered a malicious campaign called CallPhantom consisting of fraudulent apps on Google Play that deceived users by claiming to display call history for any number while actually facilitating unauthorized payments. The deceptive apps accumulated over seven million downloads before Google removed them from the platform. This threat demonstrates how sophisticated social engineering combined with fake utility claims can compromise Android users at scale.

Supply ChainWeLiveSecurity·3 months ago

A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

ESET researchers have uncovered a supply-chain attack in which the ScarCruft APT group compromised a gaming platform to distribute backdoor-infected games targeting the Yanbian region. The attack leveraged both Windows and Android gaming applications as vectors to deliver malicious payloads to victims. This campaign demonstrates how threat actors continue to exploit legitimate software distribution channels to establish persistent access in geographically targeted operations.

Load more