RTF Document - Hwangstice
https://hwangstice.github.io/blog/rtf-document/
GitHub - crixpwn/CVE-2026-8389 · GitHub
https://github.com/crixpwn/CVE-2026-8389
FSB’s matryoshka #3/3: Gamaredon's Gammasteel Infostealer
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
All the passwords were stored in Active Directory description fields
https://www.theregister.com/security/2026/06/04/all-the-passwords-were-stored-in-active-directory-description-fields/5250820
X - The Everything App / X
http://x.com/i/article/2062538153626578944
Lazarus Group's Latest: Brandjacking Campaign on npm
https://www.sonatype.com/blog/lazarus-groups-latest-brandjacking-campaign-on-npm
'Please do not vibe f--- up this software': Broken backups spark AI coding row in rsync project
https://www.theregister.com/software/2026/06/04/please-do-not-vibe-f-up-this-software-broken-backups-spark-ai-coding-row-in-rsync-project/5251189
Trump considers Palantir exec to lead CISA | The Record from Recorded Future News
https://therecord.media/trump-considers-palantir-exec-to-lead-cisa
Async PICOs and Custom Beacon Wakeups in Cobalt Strike | NCC Group
https://www.nccgroup.com/research/async-picos-and-custom-beacon-wakeups-in-cobalt-strike/
PoisonXドライバを用いた日本組織への攻撃キャンペーン | LAC WATCH
https://www.lac.co.jp/lacwatch/report/20260604_004759.html
From bootloader to kernel
https://0xax.dev/books/linux-inside
VS Code Vulnerability Allows One-Click GitHub Token Theft - SecurityWeek
https://www.securityweek.com/vs-code-vulnerability-allows-one-click-github-token-theft/
GitHub - googleprojectzero/0days-in-the-wild: Repository for information about 0-days exploited in-the-wild. · GitHub
https://github.com/googleprojectzero/0days-in-the-wild
Police dismantles fake ID marketplace used by migrant smugglers
https://www.bleepingcomputer.com/news/security/police-dismantles-fake-id-marketplace-used-by-migrant-smugglers/
Cisco warns of critical Unified CM flaw with PoC exploit code
https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/
Gemini Voice Assistant Hijacked via Messaging Notifications - SecurityWeek
https://www.securityweek.com/gemini-voice-assistant-hijacked-via-messaging-notifications/
Hexacon - Register
https://www.hexacon.fr/register/
ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security
https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html