14K+ Dahua cameras across Ukraine and Russia compromised; Slovakia found backdoor in traffic speed cameras
In the Dahua case, attacks involved a persistent backdoor account named p2pwn, paired with the password p2password.
The indictment expands on a 2018 case and adds new defendants.
In the Dahua case, attacks involved a persistent backdoor account named p2pwn, paired with the password p2password.
TWINLOOT is a modular Python implant that keeps its C&C infrastructure inside trusted Microsoft services like SharePoint Online, Microsoft Graph API and Microsoft Teams TURN servers.
The web shell was found after attackers exploited the CVE-2026-12569 RCE flaw in PTC Windchill.
The infection chain begins with a malicious Windows shortcut (LNK) disguised as a PDF file.
The group exploited a vulnerability at a financial service provider, which was caused by a flawed software update.
The attacker used WinRAR to archive files and the s5cmd tool to upload stolen data to an attacker-controlled S3 bucket.