DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH

VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH

Comments
5 min read
Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover

Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover

Comments
6 min read
Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption

Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption

Comments
6 min read
JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions

JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions

Comments
5 min read
Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment

Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment

Comments
6 min read
Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices

Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices

Comments
5 min read
WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud

WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud

Comments
6 min read
City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search

City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search

Comments
6 min read
Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption

Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption

Comments
11 min read
Kimwolf v7: Android/IoT Botnet with HTTP/2 Browser Spoofing DDoS and ENS/Tor Three-Layer C2

Kimwolf v7: Android/IoT Botnet with HTTP/2 Browser Spoofing DDoS and ENS/Tor Three-Layer C2

Comments
9 min read
BdThemes API-Driven Supply Chain Compromise: Admin XSS to Web Shell and Hidden Admin

BdThemes API-Driven Supply Chain Compromise: Admin XSS to Web Shell and Hidden Admin

Comments
8 min read
Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates

Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates

Comments
9 min read
RovoBlast: One-Click Hijacking of Enterprise AI Permissions for Data Exfiltration

RovoBlast: One-Click Hijacking of Enterprise AI Permissions for Data Exfiltration

Comments
8 min read
VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

Comments
7 min read
Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.