ChocoPoC is distributed through manipulated Python packages in seemingly legitimate GitHub exploits, gaining access to infected systems across multiple dependency levels.
TencShell backdoor obfuscates C2 traffic as Tencent API requests to evade detection and enables remote access, data theft, and lateral network movement.
Russia-aligned APTs conduct first-known attacks on NATO energy infrastructure using wiper malware, while AI-enabled malware and North Korea cooperation establish new threat vectors.
Unauthorized administrator activities in isolated environments require defense-in-depth beyond the authentication layer, as compromises of the auth system can remain undetected for decades.
A China-linked hacker group infiltrated fundamental Linux authentication systems PAM and OpenSSH over many years, evading conventional detection methods.
A China-linked hacker group operated undetected for nearly a decade through backdoors in Linux authentication components where standardized security tools do not look.
An unknown espionage actor exfiltrated the complete email mailbox of a stock exchange executive over five months using disguised malware and cloud services without detection.