We know it’s been a while since our last post.
But we’re back, with great news!
We’re launching our blog, “Purpleshift,” featuring interesting articles, talks, and research for both blue and red teams.
Yeah that’s why it’s purple :)
Remember the early-2000s joke? "Hello! I'm an Albanian virus. I have no high technology, so please delete an important file yourself and forward me to your friends." the joke has become a reality due to massive attacks using the ClickFix technique.
More:
purpleshift.io/articles/2026-…
Certighost (CVE-2026-54121) is a critical ADCS vulnerability that can let low-privileged users take control of the domain.
The best protection is to update all ADCS servers. But how can you find out if your servers were attacked before updating?
Read more
purpleshift.io/articles/2026-…
Attackers don't need fancy tricks to breach schools: stolen accounts, Potato privesc, then PsExec to move around. Outdated unpatched systems make it easy and DragonForce/LockBit 3 hunt the private schools that can pay.
Full breakdown by [@cristianzsh]:
purpleshift.io/purple/2026-08…
Your TURN server exists so employees can join video calls.
Attackers can turn it into an egress proxy that relays traffic anywhere, including their C2.
Here's how the attack works and how to catch it:
purpleshift.io/purple/2026-07…