Exploiting a 13-years old bug on QEMU – kqx
https://kqx.io/post/qemu-nday/
Chinese Malware Delivery Domains Part IV - DomainTools Investigations | DTI
https://dti.domaintools.com/chinese-malware-delivery-domains-part-iv/
Release Ghidra 12.0 · NationalSecurityAgency/ghidra · GitHub
https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_12.0_build
Ransomware gangs turn to Shanya EXE packer to hide EDR killers
https://www.bleepingcomputer.com/news/security/ransomware-gangs-turn-to-shanya-exe-packer-to-hide-edr-killers/
Ivanti warns of critical Endpoint Manager code execution flaw
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-critical-endpoint-manager-code-execution-flaw/
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data
https://thehackernews.com/2025/12/researchers-find-malicious-vs-code-go.html
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware
https://thehackernews.com/2025/12/stac6565-targets-canada-in-80-of.html
An analysis of a shadow Telegram channel’s lifespan | Securelist
https://securelist.com/goodbye-dark-telegram/118286/
Spain arrests teen who stole 64 million personal data records
https://www.bleepingcomputer.com/news/security/spain-arrests-teen-who-stole-64-million-personal-data-records/
【附IOC】Next.js RCE漏洞在野利用事件分析
https://mp.weixin.qq.com/s/a0uB8-dr25TSdeIb2Towrw
Fortinet warns of critical FortiCloud SSO login auth bypass flaws
https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-forticloud-sso-login-auth-bypass-flaws/
Security Update Guide - Microsoft
https://msft.it/6018SZEg0
New 'Broadside' Botnet Poses Risk to Shipping Companies - SecurityWeek
https://www.securityweek.com/new-broadside-botnet-poses-risk-to-shipping-companies/
Ransomware IAB abuses EDR for stealthy malware execution
https://www.bleepingcomputer.com/news/security/ransomware-iab-abuses-edr-for-stealthy-malware-execution/
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
https://www.recordedfuture.com/research/graybravos-castleloader-activity-clusters-target-multiple-industries
North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks
https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-react2shell-flaw-in-etherrat-malware-attacks/