SilkParasite campaign targets Central Asian governments
The malware appears to have been developed mainly by human operators, but shows signs of AI-assisted development.
In brief: Threat actors are actively exploiting flaws in Apple, Microsoft, Zimbra, and other software; Russian hackers target defense and aerospace sectors in Europe and the US; and more.
The malware appears to have been developed mainly by human operators, but shows signs of AI-assisted development.
The indictment expands on a 2018 case and adds new defendants.
In the Dahua case, attacks involved a persistent backdoor account named p2pwn, paired with the password p2password.
TWINLOOT is a modular Python implant that keeps its C&C infrastructure inside trusted Microsoft services like SharePoint Online, Microsoft Graph API and Microsoft Teams TURN servers.
The web shell was found after attackers exploited the CVE-2026-12569 RCE flaw in PTC Windchill.
The infection chain begins with a malicious Windows shortcut (LNK) disguised as a PDF file.