cyberresearch.bsky.social
@cyberresearch.bsky.social
Originally from Unit 42: VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731) ( :-{ı▓ #unit42 #threathunting #cyberresearch
VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)
CVE-2026-1731 is an RCE vulnerability in identity platform BeyondTrust. This flaw allows attackers control of systems without login credentials. The post VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731) appeared first on Unit 42.
unit42.paloaltonetworks.com
February 20, 2026 at 8:03 AM
Originally from DataDog: Kubernetes project issues warning on Ingress NGINX retirement ( :-{ı▓ #cloudsecurity #datadog #cyberresearch
Kubernetes project issues warning on Ingress NGINX retirement
The Kubernetes project is urging organizations to migrate away from Ingress NGINX before its retirement in March 2026, with new high-severity CVEs underscoring the urgency.
securitylabs.datadoghq.com
February 20, 2026 at 7:59 AM
Originally from TrustedSec: Notepad++ Plugins: Plug and Payload ( :-{ı▓ #trustedsec #pentesting #cyberresearch
Notepad++ Plugins: Plug and Payload
Notepad++ has been in the news recently for a breach of infrastructure associated with the Notepad++ updater. This attack may have allowed an adversary to deliver backdoored updates which could allow arbitrary code…
trustedsec.com
February 19, 2026 at 2:20 PM
Originally from Unit 42: Critical Vulnerabilities in Ivanti EPMM Exploited ( :-{ı▓ #unit42 #threathunting #cyberresearch
Critical Vulnerabilities in Ivanti EPMM Exploited
We discuss widespread exploitation of Ivanti EPMM zero-day vulns CVE-2026-1281 and CVE-2026-1340. Attackers are deploying web shells and backdoors. The post Critical Vulnerabilities in Ivanti EPMM Exploited appeared first on Unit 42.
unit42.paloaltonetworks.com
February 18, 2026 at 8:09 AM
Originally from TrustedSec: Updated GSA Contractor CUI Protection Requirements ( :-{ı▓ #trustedsec #pentesting #cyberresearch
Updated GSA Contractor CUI Protection Requirements
CMMC has been getting much of the Controlled Unclassified Information (CUI) attention lately due to the size of the defense industrial base, but General Services Administration (GSA) requirements for protecting CUI are…
trustedsec.com
February 17, 2026 at 2:51 PM
Originally from Unit 42: Phishing on the Edge of the Web and Mobile Using QR Codes ( :-{ı▓ #unit42 #threathunting #cyberresearch
Phishing on the Edge of the Web and Mobile Using QR Codes
We discuss the extensive use of malicious QR codes using URL shorteners, in-app deep links and direct APK downloads to bypass mobile security. The post Phishing on the Edge of the Web and Mobile Using QR Codes appeared first on Unit 42.
unit42.paloaltonetworks.com
February 14, 2026 at 8:21 AM
Originally from Red Canary: A masterclass in agentic security operations ( :-{ı▓ #threatintel #redcanary #cyberresearch
A masterclass in agentic security operations
Read our miniseries recap and watch every episode of “AI in the SOC: From hype to outcomes” on demand now.
redcanary.com
February 13, 2026 at 10:24 AM
Originally from BHIS: BHIS - Talkin' Bout [infosec] News 2026-02-11 ( :-{ı▓ #BlackHillsInfoSec #cybersecurity #cyberresearch
BHIS - Talkin' Bout [infosec] News 2026-02-11
We are live from WWHF Mile High 2026 https://wildwesthackinfest.com/ Join us LIVE on Mondays, 4:30pm EST. (Except for this Special Wednesday Episode!) A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://bhisnews.transistor.fm 01:43 - PreShow Banter™ — LIVE from WWHF Denver 2026!! 03:41 - BHIS - Talkin' Bout [infosec] News 2026-02-11 04:44 - Story # 1: Critical Notepad vulnerability reignites criticism of Microsoft’s forced AI features https://cybernews.com/security/windows-notepad-vulnerable-to-remote-attacks-feature-creep-blamed/ 09:40 - Story #2: Discord will require a face scan or ID for full access next month https://www.theverge.com/tech/875309/discord-age-verification-global-roll-out 12:19 - Story #3: 2026-01-14: The Day the telnet Died https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/ 17:02 - Story #4: BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code Execution https://cybersecuritynews.com/beyondtrust-remote-access-products-0-day-vulnerability/ 18:29 - Story #5: GRITREP: 0APT and the Victims Who Weren’t https://www.guidepointsecurity.com/blog/gritrep-0apt-and-the-victims-who-werent/ 22:18 - Open Discussion 35:08 - Announcements Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat This episode breaks down recent reports of sensitive information being shared with AI tools and what that means for security and operations. The discussion covers OPSEC failures, common misuse of ChatGPT in professional environments, how data actually flows through AI systems, and what organizations should (and shouldn’t) worry about. The hosts focus on practical risk, realistic threat models, and actionable lessons for security teams navigating AI adoption. 🔗 Register for FREE webcasts, summits, and workshops - https://poweredbybhis.com
www.youtube.com
February 12, 2026 at 8:42 AM
Originally from Unit 42: Nation-State Actors Exploit Notepad++ Supply Chain ( :-{ı▓ #unit42 #threathunting #cyberresearch
Nation-State Actors Exploit Notepad++ Supply Chain
Unit 42 reveals new infrastructure associated with the Notepad++ attack. This expands understanding of threat actor operations and malware delivery. The post Nation-State Actors Exploit Notepad++ Supply Chain appeared first on Unit 42.
unit42.paloaltonetworks.com
February 12, 2026 at 8:28 AM
Originally from Red Canary: Take back control: A modern guide to mastering application control ( :-{ı▓ #threatintel #redcanary #cyberresearch
Take back control: A modern guide to mastering application control
Learn how a robust app control policy can have a meaningful, measurable impact on your organization’s security posture.
redcanary.com
February 11, 2026 at 10:29 AM