https://github.com/marktsec
hackers-arise.com/network-espi...
hackers-arise.com/network-espi...
Fix ensuring reliable Steam token theft, a major overhaul of the worker panel (multi-build support, cookie restore, build editing), more stable admin sessions via cookies, and expanded API permissions.
#ThreatIntel #infosec
Fix ensuring reliable Steam token theft, a major overhaul of the worker panel (multi-build support, cookie restore, build editing), more stable admin sessions via cookies, and expanded API permissions.
#ThreatIntel #infosec
The offer includes a full RaaS ecosystem:
• Windows locker (C++)
• Linux locker (Golang)
• ESXi locker (pure C, daemonized)
• File stealer
• Advert & affiliate panels
#ThreatIntel #infosec
The offer includes a full RaaS ecosystem:
• Windows locker (C++)
• Linux locker (Golang)
• ESXi locker (pure C, daemonized)
• File stealer
• Advert & affiliate panels
#ThreatIntel #infosec
🔑Claimed capabilities:
Native C stub (~100KB), x64 + ARM64, macOS Sierra → Tahoe
#ThreatIntel #infosec
🔑Claimed capabilities:
Native C stub (~100KB), x64 + ARM64, macOS Sierra → Tahoe
#ThreatIntel #infosec
🔧Claimed functionality:
Works with HVCI/VBS/Memory Integrity
Persistence by killing security tools on launch
Optional silent UAC bypass and kernel rootkit
Compatible with C2 frameworks
#ThreatIntel #infosec
🔧Claimed functionality:
Works with HVCI/VBS/Memory Integrity
Persistence by killing security tools on launch
Optional silent UAC bypass and kernel rootkit
Compatible with C2 frameworks
#ThreatIntel #infosec
portal.magicsword.io/blog/poortry...
portal.magicsword.io/blog/poortry...
cyberdom.blog/entra-id-log...
cyberdom.blog/entra-id-log...
www.koi.ai/blog/urban-v...
www.koi.ai/blog/urban-v...
specterops.io/blog/2025/12...
specterops.io/blog/2025/12...
Windows PowerShell 5.1 now displays a security confirmation prompt when using the Invoke-WebRequest command to fetch web pages without special parameters.
support.microsoft.com/en-us/topic/...
Windows PowerShell 5.1 now displays a security confirmation prompt when using the Invoke-WebRequest command to fetch web pages without special parameters.
support.microsoft.com/en-us/topic/...
www.gdatasoftware.com/blog/2025/11...
www.gdatasoftware.com/blog/2025/11...
flare.io/learn/resour...
flare.io/learn/resour...
mazinahmed.net/blog/publish...
mazinahmed.net/blog/publish...
Nova operators announced locker rewritten in ADA/SPARK and targeting Windows, Linux, and ESXi.
The group boasts Rust-like techniques, enhanced evasion, and even a so-called “safe mode.”
#ThreatIntel #Ransomware #MalwareAnalysis
Nova operators announced locker rewritten in ADA/SPARK and targeting Windows, Linux, and ESXi.
The group boasts Rust-like techniques, enhanced evasion, and even a so-called “safe mode.”
#ThreatIntel #Ransomware #MalwareAnalysis
www.greynoise.io/blog/cve-202...
www.greynoise.io/blog/cve-202...
xbz0n.sh/blog/living-...
xbz0n.sh/blog/living-...
• Steam token collection restored, now pulled directly from local files (no process injection), enabling multi-account token harvesting.
• New data targets: Perplexity “Comet” browser & IndexedDB for all MetaMask versions.
#infosec #threatintel
• Steam token collection restored, now pulled directly from local files (no process injection), enabling multi-account token harvesting.
• New data targets: Perplexity “Comet” browser & IndexedDB for all MetaMask versions.
#infosec #threatintel
www.intrinsec.com/hide-the-thr...
www.intrinsec.com/hide-the-thr...
www.zscaler.com/blogs/securi...
www.zscaler.com/blogs/securi...
redcanary.com/blog/threat-...
redcanary.com/blog/threat-...
krebsonsecurity.com/2025/11/meet...
krebsonsecurity.com/2025/11/meet...
www.validin.com/blog/inside_...
www.validin.com/blog/inside_...
www.picussecurity.com/resource/blo...
www.picussecurity.com/resource/blo...