ESET researchers have identified LongNosedGoblin, a China-aligned APT group conducting cyberespionage operations against governmental institutions in Southeast Asia and Japan. The threat actor leverages Group Policy mechanisms to deploy cyberespionage tools across compromised networks, enabling persistent access to sensitive government systems in the region.
An intrusion involving Lynx ransomware began in early March 2025 through a single successful RDP logon to an internet-exposed system, with no evidence of credential stuffing or brute force attempts preceding the successful access. This suggests the attacker may have obtained valid credentials through other means before gaining initial access to the target environment.
While on Project Zero, we aim for our research to be leading-edge, our blog design was … not so much. We welcome readers to our shiny new blog! For the occasion, we asked members of Project Zero to dust off old blog posts that never quite saw the light of day. And while we wish we could say the techniques they cover are no longer relevant, there is still a lot of work that needs to be done to protect users against zero days. Our new blog will continue to shine a light on the capabilities of attackers and the many opportunities that exist to protect against them. From 2016: Windows Exploitation Techniques: Race conditions with path lookups by James Forshaw Thinking Outside The Box by Jann Horn
Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.
A critical vulnerability in React discovered on December 3, 2025 allows unauthenticated remote code execution through improper validation of user-supplied identifiers, with researchers noting it is trivial to exploit. A working proof of concept is already public, and servers exposed to the internet before the patch release may have been compromised by Chinese threat actors. Organizations should immediately update to patched versions and investigate systems for signs of compromise.
MuddyWater has targeted critical infrastructure operators in Israel and Egypt using custom malware and refined attack techniques. The threat actor's operations follow a recognizable pattern, suggesting organizations in these regions should anticipate similar tactics in future campaigns.
In this special 13Cubed episode, I answer questions collected from the community!
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
#Forensics #DigitalForensics #DFIR #ComputerForensics
From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into trouble.
Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month's cybersecurity news