Tag: detection
-
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the…
-
Daylight Security Launches Detection Program Visibility
Daylight Security adds Detection Program Visibility to unify detections, map coverage to MITRE ATTCK, and help MDR customers spot gaps and improve results. First seen on hackread.com Jump to article: hackread.com/daylight-security-detection-program-visibility/
-
How to Build Application Detection and Response
Tags: detectionFirst seen on scworld.com Jump to article: www.scworld.com/implementation-guides/how-to-build-application-detection-and-response
-
Risk Advisory: Filtering Known-Bad Messages Does Not Prove Detection Readiness
First seen on scworld.com Jump to article: www.scworld.com/risk-advisory/risk-advisory-filtering-known-bad-messages-does-not-prove-detection-readiness
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea,…
-
Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
-
Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation
Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Google’s AI Threat Defense offering. This launch comes as…
-
New TrickBot Malware Variant Uses DNS Tunneling for CommandControl
A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a…
-
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on First seen on thehackernews.com…
-
Sophisticated crypter service Cruciferra evades detection with advanced techniques
First seen on scworld.com Jump to article: www.scworld.com/brief/sophisticated-crypter-service-cruciferra-evades-detection-with-advanced-techniques
-
Cruciferra Crypter Evades Detection to Deliver Malware
Proofpoint found Cruciferra, a sophisticated crypter used to deliver malware through phishing campaigns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cruciferra-crypter-evades-detection-to-deliver-malware/
-
Cruciferra Crypter Evades Detection to Deliver Malware
Proofpoint found Cruciferra, a sophisticated crypter used to deliver malware through phishing campaigns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cruciferra-crypter-evades-detection-to-deliver-malware/
-
Fig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure
Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily. First seen on hackread.com Jump to article: hackread.com/fig-secops-engineering-lifecycle-security-teams-infrastructure/
-
Fig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure
Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily. First seen on hackread.com Jump to article: hackread.com/fig-secops-engineering-lifecycle-security-teams-infrastructure/
-
Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to…
-
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public…
-
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly…
-
PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
-
Cribl buys CardinalOps for detection engineering, edges into SecOps
Tags: detectionErstwhile Splunk nemesis adds a “SIEM-like” experience, with IP and engineering from CardinalOps folded into its “Bring Your Own Agent” pitch to IT buyers. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366645843/Cribl-buys-CardinalOps-for-detection-engineering-edges-into-SecOps
-
Flock Safety kills acoustic system designed to detect ‘human distress’
Tags: detection“Community consultation” is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system. First seen on therecord.media Jump to article: therecord.media/flock-safety-kills-audio-detection-system-human-distress
-
Attackers Combo Up Evasion Tactics for BEC Phishing
The TFF Trap uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/attackers-combo-evasion-tactics-bec-phishing
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…
-
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Tags: detectionCruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/
-
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026. The report, Gen’s first half-yearly threat publication after previously reporting…
-
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover asynchronous I/O operations, BPF inspection and manipulation, EDR evasion techniques,…
-
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake Keylogger variants. The campaign impersonates legitimate businesses and brands in email lures, often using payment-themed…
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
-
CISA urges immediate action on actively exploited Fortinet flaws
CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by-sunday/
-
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed…

