Hunting OpenClaw: Detection and Containment Guidance for Defenders
Hunting OpenClaw: Detection and Containment Guidance for Defenders

Shai-Hulud: Miasma - When a Supply-Chain Worm Learned to Hijack AI Coding Agents
Hunting OpenClaw: Detection and Containment Guidance for Defenders
The Defender Domino: How a DigiCert Breach Turned Microsoft into an Unwitting Proxy for APT-Q-27
LazarOps: APT Tactics Targeting the Developers Supply Chain [PART 1]
On Friday, Silicon Valley Bank, a prominent lender to the technology industry, collapsed, causing panic among its customers and investors. The California Department of Financial Protection and Innovation shut down the bank and appointed the Federal Deposit Insurance Corporation (FDIC) as the receiver, resulting in nearly $175 billion in customer deposits being put under the control of the FDIC. The collapse of Silicon Valley Bank is the largest U.S. bank failure since the 2008 financial crisis,
A victim called the incident response teams of Global Threat Center, reporting a seeminglynew stream of ransomware attack. Upon investigation, we determined the extension of theencrypted files was certainly new, but the malware displayed significant similarities withseveral ransomware families—a combination that made attribution an interesting and difficultriddle. The attack’s signature was a Music folder containing an arsenal of tools, which themalware dropped and executed on each of the encryp
Our investigation has revealed an innovative approach that leverages executables commonly found in the trusted WinSxS folder and exploits them via the classic DLL Search Order Hijacking technique. This method allows threat actors to circumvent high privilege requirements to execute malicious code in applications within the Windows folder, specifically WinSxS, and eliminates the need for additional binaries in the attack chain. Furthermore, it facilitates the execution of malicious code from any
New research, real incidents, zero noise.
Your work email: