Tag: detection
-
Iran-linked MuddyWater espionage campaign targets organisations across four continents
A new threat intelligence report from WatchGuard is warning organisations worldwide to strengthen behavioural detection capabilities after uncovering an espionage campaign by the Iran-linked threat group MuddyWater that successfully targeted high-value organisations across four continents. The report details how the group, also known as Seedworm, targeted organisations across manufacturing, aviation, financial services, education, professional services…
-
SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection
SindriKit 1.3.0 introduces a significant advancement in evading Endpoint Detection and Response (EDR) systems by exploiting dynamic call stack spoofing. This method defeats telemetry that inspects kernel-transition call chains, going beyond just user-mode hooks. Previously, SindriKit 1.2.0 had already separated syscall invocations via indirect syscalls, redirecting to legitimate syscall return instructions in ntdll.dll to evade…
-
SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection
SindriKit 1.3.0 introduces a significant advancement in evading Endpoint Detection and Response (EDR) systems by exploiting dynamic call stack spoofing. This method defeats telemetry that inspects kernel-transition call chains, going beyond just user-mode hooks. Previously, SindriKit 1.2.0 had already separated syscall invocations via indirect syscalls, redirecting to legitimate syscall return instructions in ntdll.dll to evade…
-
4 Best Email Security Solutions to Keep Employee Inboxes Safe
Compare leading and best email security solutions with AI threat detection, phishing defense, malware blocking, and DLP features for teams. First seen on hackread.com Jump to article: hackread.com/best-email-security-solutions-employee-inboxes-safe/
-
Kazuar Backdoor Uses DLL Side-Loading and PowerShell Loaders for Stealthy Execution
Turla’s Kazuar backdoor has re-emerged as a technically sophisticated persistence and reconnaissance tool that combines DLL side-loading with PowerShell-based loaders to achieve stealthy execution and resilient command-and-control. This side-loading technique minimizes disk activity tied to novel executables and leverages trusted host processes to bypass naive allowlists and detection heuristics. The delivery chain frequently uses multi-layered,…
-
Cavern Manticore Malware Uses Low-Detection .NET Modules for Reconnaissance and Lateral Movement
A newly identified Iran-linked threat group, tracked as Cavern Manticore, is deploying a sophisticated modular command-and-control (C2) framework built on a shared .NET foundation to conduct stealthy reconnaissance and lateral movement against Israeli government and IT organizations. The group’s custom C2 components exhibit extremely low detection rates on public sandboxes, enabling persistent access while evading…
-
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, triage, investigation, and response on their own data…
-
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, triage, investigation, and response on their own data…
-
SilverFox Campaign Turns ValleyRAT Into Multi-Stage Malware With Rootkit Capabilities
The SilverFox advanced persistent threat (APT) group has escalated its offensive toolkit by transforming ValleyRAT from a conventional remote access trojan into an eight-stage malware chain culminating in a kernel-mode rootkit. This evolution marks a significant shift in post-exploitation persistence, blending user-mode orchestration with deep kernel control to evade detection and maintain long-term access. The…
-
ModSecurity Security Flaws Enable WAF Rule Evasion With Crafted HTTP Requests
ModSecurity, a widely used open-source web application firewall (WAF), has multiple security vulnerabilities that allow attackers to bypass detection with specially crafted HTTP requests. These vulnerabilities, identified as CVE-2026-52761 and CVE-2026-52747, affect ModSecurity versions up to 3.0.15. They have been addressed in version 3.0.16. These issues reveal significant inconsistencies in input transformation and request parsing,…
-
Wo sich wertvolle Metriken für das Security-Operations-Center finden lassen
Wie effizient ein Security-Operations-Center (SOC) arbeitet, ist durchaus messbar. Leider lassen sich Unternehmen oft von nichtssagenden Metriken blenden. Ontinue, Experte für Managed-Extended-Detection and Response (MXDR), erklärt anhand von drei Personas, wie Unternehmen maßgeschneiderte KPIs definieren. Schließt ein Security-Operations-Center täglich hunderte Tickets von Security-Incidents, ist das erst einmal beeindruckend. Diese Zahl kann allerdings trügen, denn in…
-
Ransomware-Gruppe schaltet Sicherheitssoftware mit EDR-Killer aus
Die Betreiber der Ransomware-Gruppe Gentlemen stellen ihren Partnern nicht nur Verschlüsselungswerkzeuge zur Verfügung, sondern entwickeln auch eigene Programme zur gezielten Umgehung und Abschaltung von Sicherheitssoftware. Besonders betroffen sind die in Netzwerken oft eingesetzten ‘Endpoint-Detection and Response”-Lösungen. Das zeigt eine aktuelle Analyse des IT-Sicherheitsherstellers ESET. Demnach pflegt die Gruppe ein eigenes Portfolio sogenannter EDR-Killer und integriert…
-
TimbreStealer Malware Targets Mexico Companies With Advanced Evasion Techniques
A new campaign linked to the TimbreStealer information stealer that specifically targets Mexican companies, employing layered evasion and sophisticated runtime tricks to frustrate detection and analysis. Researchers Euler Neto and Cristóbal Tárraga detail behaviors that echo a 2024 Cisco Talos report while highlighting a notable variant: the use of DLL side”‘loading with unusually large malicious…
-
Alibaba Reportedly Bans Claude Code Over Alleged Backdoor Risk in AI Coding Tool
Alibaba is reportedly preparing to ban the use of Anthropic’s Claude Code across its internal environments starting July 10. This decision comes in light of allegations that the AI-powered coding assistant has a covert detection mechanism resembling a backdoor. The news, first reported by the Chinese financial outlet Yicai and later confirmed by Reuters, has…
-
ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth
A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. First named by Proofpoint in 2023, ValleyRAT continues to evolve: LevelBlue’s telemetry shows a marked increase in successful detections beginning May 2025 and accelerating into 2026. The threat now presents through two primary…
-
Attackers Downgrade WDigest Protection to Dump Plaintext Credentials With Mimikatz
An incident that began with innocuous enumeration commands but quickly escalated into a focused, multi-stage effort to impair detection and extract credentials. The intruder uploaded a steganographic webshell to an IIS server, used the process w3wp.exe to run OS reconnaissance such as whoami, and then deployed an extensive defence-impairment script (i.bat) that prefaced a credential-dump…
-
Webinar: Why traditional email security is no longer enough
Modern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for traditional email defenses to detect. This webinar explores how behavioral AI can help organizations automate detection and response. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-why-traditional-email-security-is-no-longer-enough/
-
AI is breaking the case for detection-first security
First seen on scworld.com Jump to article: www.scworld.com/perspective/ai-is-breaking-the-case-for-detection-first-security
-
How Agentic AI Is Reshaping the Modern SOC
Agentic AI is redefining security operations by embedding intelligence across detection, investigation and response. Optiv’s Ben Spencer and Google Cloud’s Wayne Kearns explain how AI-powered SOCs strengthen defense, why human expertise is essential and how MSSPs can accelerate enterprise adoption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/interviews/how-agentic-ai-reshaping-modern-soc-i-5554
-
Rubrik CEO: Why Frontier AI Is A ‘Reckoning For The Cybersecurity Industry’
While it’s been evident for years that prevention and detection alone are not enough for effective cybersecurity, the arrival of ultra-powerful frontier AI models is making this plainer than ever, according to Rubrik co-founder and CEO Bipul Sinha. First seen on crn.com Jump to article: www.crn.com/news/security/2026/rubrik-ceo-why-frontier-ai-is-a-reckoning-for-the-cybersecurity-industry
-
Bluekit Phishing Kit Uses Browserthe-Middle Attacks to Evade Detection
A new phishing-as-a-service (PHaaS) platform called Bluekit is letting cybercriminals steal user accounts using a tricky method. While… First seen on hackread.com Jump to article: hackread.com/bluekit-phishing-uses-browser-in-the-middle-attacks/
-
AI-Generated Mythic Agents Challenge Static Signatures and Traditional Implant Detection
The emergence of LLM-driven >>disposable tooling<< is reshaping offensive tradecraft and forcing defenders to rethink detection models that rely on static signatures and known implant behaviors. Recent experiments demonstrating the automated generation of Mythic agents from prompt to deployment reveal a new threat class: ephemeral, single-use implants tailor-made by large language models and orchestration harnesses.…
-
China’s Zhipu AI Model GLM-5.2 Detects Software Vulnerabilities Like Claude Mythos
Zhipu AI’s newly released GLM-5.2 model is attracting significant attention from the cybersecurity community due to its vulnerability detection capabilities, which are comparable to those of Anthropic’s restricted Claude Mythos system. This development raises new concerns about the effectiveness of U.S. export control policies on advanced artificial intelligence. Released on June 13, 2026, under a…
-
New License Plate Reader Tech Could Track Phones, AirPods, and Smartwatches
Leonardo’s SignalTrace adds wireless device detection to ALPR systems, raising new questions about roadside surveillance, privacy, and security. The post New License Plate Reader Tech Could Track Phones, AirPods, and Smartwatches appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-leonardo-signaltrace-alpr-device-tracking/
-
New License Plate Reader Tech Could Track Phones, AirPods, and Smartwatches
Leonardo’s SignalTrace adds wireless device detection to ALPR systems, raising new questions about roadside surveillance, privacy, and security. The post New License Plate Reader Tech Could Track Phones, AirPods, and Smartwatches appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-leonardo-signaltrace-alpr-device-tracking/
-
Comparing Antivirus Software 2026: Avast vs. AVG
Compare Avast and AVG antivirus software in 2026. We assess features like malware detection, real-time protection, pricing, customer support, and more. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/avast-vs-avg-antivirus/
-
Norton vs McAfee: Compare Antivirus Software in 2026
Compare Norton and McAfee antivirus software in 2026. We assess features like malware detection, real-time protection, pricing, customer support, and more. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/norton-vs-mcafee-antivirus/
-
LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity
LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) configuration stored inside the binary. The result is a compact, stealthy loader that reconstructs and executes a traditional LokiBot payload while limiting observable…
-
Webinar: Why email security teams are drowning in alerts
Phishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral AI can help automate detection and response workflows, reducing alert fatigue and improving operational efficiency. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-why-email-security-teams-are-drowning-in-alerts/
-
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations
Cybercriminals are increasingly abusing traffic distribution systems (TDSs) to evade defenses, conceal malicious destinations, and funnel victims into phishing, fraud, and malware campaigns. Once considered a legitimate marketing tool to route visitors to different content or offers, TDS infrastructure is now being repurposed as a stealthy redirection layer that complicates detection and response for network…

