Nation-StateWeLiveSecurity·8 months ago

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ESET researchers have identified LongNosedGoblin, a China-aligned APT group conducting cyberespionage operations against governmental institutions in Southeast Asia and Japan. The threat actor leverages Group Policy mechanisms to deploy cyberespionage tools across compromised networks, enabling persistent access to sensitive government systems in the region.

RansomwareThe DFIR Report·8 months ago

Cat’s Got Your Files: Lynx Ransomware

An intrusion involving Lynx ransomware began in early March 2025 through a single successful RDP logon to an internet-exposed system, with no evidence of credential stuffing or brute force attempts preceding the successful access. This suggests the attacker may have obtained valid credentials through other means before gaining initial access to the target environment.

VulnerabilityGoogle Project Zero·8 months ago

Welcome to the new Project Zero Blog

While on Project Zero, we aim for our research to be leading-edge, our blog design was … not so much. We welcome readers to our shiny new blog! For the occasion, we asked members of Project Zero to dust off old blog posts that never quite saw the light of day. And while we wish we could say the techniques they cover are no longer relevant, there is still a lot of work that needs to be done to protect users against zero days. Our new blog will continue to shine a light on the capabilities of attackers and the many opportunities that exist to protect against them. From 2016: Windows Exploitation Techniques: Race conditions with path lookups by James Forshaw Thinking Outside The Box by Jann Horn

OtherWeLiveSecurity·8 months ago

ESET Threat Report H2 2025

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

OtherF5 Labs·8 months ago

2026 Cybersecurity Predictions

Whatever you think will happen… will happen faster and with more acronyms than ever before.

VulnerabilityCybereason Blog·8 months ago

CVE-2025-55182: Critical Vulnerability, React2Shell, Allows for Unauthenticated RCE

A critical vulnerability in React discovered on December 3, 2025 allows unauthenticated remote code execution through improper validation of user-supplied identifiers, with researchers noting it is trivial to exploit. A working proof of concept is already public, and servers exposed to the internet before the patch release may have been compromised by Chinese threat actors. Organizations should immediately update to patched versions and investigate systems for signs of compromise.

Nation-StateWeLiveSecurity·8 months ago

MuddyWater: Snakes by the riverbank

MuddyWater has targeted critical infrastructure operators in Israel and Egypt using custom malware and refined attack techniques. The threat actor's operations follow a recognizable pattern, suggesting organizations in these regions should anticipate similar tactics in future campaigns.

13Cubed AMA - Answering Your Questions!

13Cubed·1.4K views · 8 months ago

In this special 13Cubed episode, I answer questions collected from the community! *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** #Forensics #DigitalForensics #DFIR #ComputerForensics

Load more