THE RESEARCH DESK / NEWS & ANALYSIS
Security news.
Research first.
Digital forensics, malware analysis, mobile security and cryptography. Read the findings, examine the evidence, understand the limits.
Primary sources. Research briefs and attributed source updates.
Our editorial method ↗
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Microsoft Security feed excerpt: “Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS…”

Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
SANS Internet Storm Center feed excerpt: “We just did a major update to FOR577 and added a…”

Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
Cisco Talos feed excerpt: ““AI-analysis evasion” encapsulates the real-world techniques malware authors are developing…”

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Cisco Talos feed excerpt: “Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The…”

Android's Next-Gen Enclave for On-Device AI
Google Security feed excerpt: “Enabling the Next-Gen Enclave Architecture for On-Device AI on Android”

Microsoft, Adobe, Apple, and Foxit vulnerabilities
Cisco Talos feed excerpt: “Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The…”

3 lessons from frontier AI vulnerability research
Microsoft Security feed excerpt: “Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel.”

Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
SANS Internet Storm Center feed excerpt: “On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589].…”

CISO perspectives on managing vulnerability risks in the age of AI
Microsoft Security feed excerpt: “Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age…”

More RMM Tools In the Wild, (Tue, Oct 6th)
SANS Internet Storm Center feed excerpt: “It seems that a trend started… I continue my journey discovering more RMM ("Remote Management…”

User Agent Strings Curiosities, (Sun, Oct 4th)
SANS Internet Storm Center feed excerpt: “Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings…”

YARA-X 1.21.0 Release, (Sat, Oct 3rd)
SANS Internet Storm Center feed excerpt: “YARA-X's 1.21.0 release brings 5 improvements and 4 bugfixes.
”

6 ways Advanced Protection on Android keeps you safe
Google Security feed excerpt: “A woman with Advanced Protection on Android enabled on her phone”

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
SANS Internet Storm Center feed excerpt: “Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks.…”

This month in security with Tony Anscombe – September 2026 edition
ESET / WeLiveSecurity feed excerpt: “Autonomous AI agents go on a hacking spree, and Microsoft ships what used…”

Vulnerability Discovery and Exploitation Trends in the AI Era
Google Threat Intelligence / Mandiant feed excerpt: “Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines…”

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Security feed excerpt: “Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and…”

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos feed excerpt: “Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting…”

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Google Threat Intelligence / Mandiant feed excerpt: “Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG)…”

Star Blizzard refines phishing and malware delivery with the RedFlick technique
Microsoft Security feed excerpt: “Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve…”

Phishing Abuses RMM Tools for Persistent Access
Microsoft Security feed excerpt: “Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on…”

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft Security feed excerpt: “Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions…”

The devil is still in the email – but wears a new mask
ESET / WeLiveSecurity feed excerpt: “When phishing can increasingly pass familiar checks, avoiding or limiting the…”

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
SANS Internet Storm Center feed excerpt: “Apple today released patches for all of its operating systems. However, only…”

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Google Threat Intelligence / Mandiant feed excerpt: “Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft…”

Is that vibe coded app safe? 5 checks before you download
ESET / WeLiveSecurity feed excerpt: “As AI lets anyone build software, here’s how to vet that shiny new…”

Storm-3168: cloud identities at the center of destructive activity
Microsoft's new Azure investigation highlights compromised service principals, credential exposure and the importance of protecting recovery resources.

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure
Google Threat Intelligence / Mandiant feed excerpt: “Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate…”

Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
Google Security feed excerpt: “Security landscape in 2026The application of Large Language Models (LLMs) to security scanning has revolutionized the…”

Trust and the enticing consultancy offer
Cisco Talos feed excerpt: “In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value…”

Storm-2570: follow the intrusion, not just the ransomware label
New Microsoft research connects recurring behavior across incidents involving different ransomware families.

MacSync evolves: native macOS modules change the evidence trail
Kaspersky documents a September MacSync infection chain with Objective-C and Swift components, a backdoor module and delivery through disk images.

The Closed Quorum: Inside the first reported autonomous AI C2 implant
Cisco Talos feed excerpt: “CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous…”

EvilTokens research puts device-code phishing under the microscope
Microsoft documents token-focused phishing and explains why a familiar sign-in page does not make an unsolicited authentication request safe.

CAIRN research organizes AI-related malware evidence without executing samples
Cisco Talos introduces CAIRN, a metadata-based research toolkit for classifying and relating AI-associated malware artifacts.

The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
ESET / WeLiveSecurity feed excerpt: “As AI opens new paths to company data while making familiar attacks…”

PAYLOAD incident: extortion evidence inside Active Directory
Kaspersky GERT reports an April manufacturing-sector incident in which Group Policy changes disrupted Windows workstations and displayed ransom demands without encrypting their files.

SparroWocky research follows a backdoor lineage across campaigns
ESET documents SparroWocky, a modular C++ backdoor that its researchers associate with FamousSparrow.

Microsoft's September guidance returns to identity and endpoint fundamentals
Recent incident examples connect phishing-resistant authentication, least privilege and control of remote-support tools.

MovieReaper research traces a shared distribution dependency
Kaspersky reconstructs a multistage malware campaign discovered during August research into blockchain-related command infrastructure.

Japan ransomware study: distinguish incidents from leak-site claims
Cisco Talos reports 90 observed ransomware incidents affecting Japanese organizations from January through July 2026, compared with 86 in the corresponding earlier period.

NightEagle investigation connects identity, Exchange and network evidence
Kaspersky describes several incidents involving valid VPN credentials, the GhostContainer backdoor on Exchange and network-tunneling tools.

CISA publishes guidance on cyber decoys for detection and response
New guidance explains how carefully governed decoys can reveal activity that blends into normal administration.
Pixel's September bulletin flags possible targeted exploitation
Google notes indications of limited, targeted exploitation of CVE-2026-58704 in its September Pixel bulletin.

Firefox 156 security advisory covers high-impact browser flaws
Mozilla's September 15 advisory lists fixes and clarifies that internally identified memory-safety issues now receive individual entries.

Apple's September security releases span iPhone, iPad and Mac
Apple's release register lists September 14 updates across current and older supported operating-system branches.

PuzzleMask study tests the limits of fast AI policy checks
Check Point Research evaluates a small set of crafted inputs against resource-constrained AI policy checks and a stronger downstream model.

Invoice-fraud research joins message evidence with payment verification
Microsoft investigates a large email campaign impersonating executives and a supplier, with fabricated invoices and indicators consistent with generative-AI-assisted template creation.

Passkey-themed lures show why identity timelines need more than sign-ins
Microsoft reports cloud intrusions in which unusual sign-ins were followed by added authentication methods, Microsoft Graph activity and access to collaboration data.

Mantax Otax combines mobile surveillance with conditional encryption
Zimperium describes Android malware that combines surveillance capabilities with ransomware behavior.

GTIG examines evidence of adversarial AI use and theft of AI assets
Google Threat Intelligence Group reports a shift toward AI-assisted automation in observed campaigns and growing interest in model assets, source code and API credentials.

ClearFake analysis reconstructs two related evidence chains
Cisco Talos investigates unusual WebDAV-related endpoint activity and reconstructs two related delivery chains involving Amatera.

Chrome's September 8 release addresses an exploited vulnerability
Google's Chrome 153 release note acknowledges in-the-wild exploitation of CVE-2026-87491.

Browser-focused ClickFix puts extensions and session evidence in focus
Cisco Talos documents a cryptocurrency-theft campaign centered on browser-session manipulation and abuse of a legitimate hosted service.

Android's September bulletin: verify the installed patch level
The September Android bulletin identifies 2026-09-05 or later as the patch level addressing all issues it describes.

Toy Ghouls backdoors complicate trust in ordinary network services
Kaspersky GERT identifies two custom backdoor variants associated with Toy Ghouls: one communicates through an MQTT broker, while another uses a Matrix-based messaging service.

Gambling Goblin research links web-server integrity and search abuse
Check Point Research tracks a sustained campaign affecting Brazilian organizations, including government and educational sites.

NodeRabbit and PollCat bring developer evidence into incident response
Kaspersky reports NodeRabbit and PollCat, two cross-platform malware families encountered while investigating Mirage Kitten activity.

ValleyRAT case shows why an initial adware label needs review
A file initially classified as adware led Kaspersky researchers to a ValleyRAT delivery chain after they noticed unexpected network activity.

JSCeal research advances static analysis of compiled JavaScript
Check Point Research presents a static approach to recovering readable representations of JSCeal’s compiled V8 bytecode.

Industrial security telemetry: reading the Q2 2026 denominator
Kaspersky ICS CERT reports malicious objects blocked on 19.15% of monitored industrial-control-system computers in Q2 2026.

Q2 vulnerability research adds AI frameworks to the measurement problem
Kaspersky’s quarterly analysis combines vulnerability registrations, exploitation observations and a new view of flaws in AI agents and frameworks.

Android head-unit malware expands the mobile forensic perimeter
Kaspersky reconstructs an Android malware chain delivered through built-in updaters on automotive head units.

BTR research questions how much trust a signed component should receive
Check Point Research examines the Windows Defender Boot-Time Removal component after an incident-response observation prompted a deeper study.

ToxicPanda 2.0 analysis tracks a widening mobile-fraud target set
Zimperium analyzes an updated ToxicPanda Android variant and documents a larger set of targeted financial applications and additional remote-control capabilities.

Mandiant research makes validation central to AI-assisted security review
Mandiant describes an internal approach to AI-assisted source review that combines structured analysis, validation and human expertise.

CoolClient research highlights the limits of a single endpoint view
Kaspersky describes a newer CoolClient variant with a Windows kernel-mode component, attributed by the researchers to HoneyMyte.

Still Toolkit links account-session evidence with audio surveillance
Kaspersky identifies a Rust-based toolkit in an Armored Likho campaign.

JWR research examines interactive phishing as a session
Cisco Talos analyzes JWR, a phishing framework with real-time operator interaction, rather than only static form collection.

Head Mare case makes conferencing-client provenance an incident question
Kaspersky’s investigation describes compromised TrueConf infrastructure serving altered client installers associated with PhantomCore and PhantomGraph.

Talos studies prompt logs as a new class of forensic artifact
Cisco Talos examines a corpus of artifacts left by adversarial AI use, including local prompt logs.

Network anomaly research: baselines matter as much as signatures
Kaspersky explains a network-anomaly approach using Kerberos and DNS traffic as examples.

Supply-chain research connects dependency records to incident scope
Google Threat Intelligence Group and Mandiant summarize observed growth in open-source supply-chain compromise.

NightLedger investigation separates observed tooling from attribution
Kaspersky reports a previously undocumented Windows backdoor and two tunneling tools associated with Mirage Kitten.

Mandiant outlines security boundaries for AI-assisted code review
Mandiant examines architectural risks introduced when AI agents enter development and vulnerability-management workflows.

Forgotten UEFI shims show why Secure Boot needs current revocation data
ESET identifies 11 older signed UEFI shim bootloaders that weakened Secure Boot trust.

SymCrypt research connects Rust implementations to machine-checked proofs
Microsoft Research describes verification of Rust cryptographic implementations using Aeneas and Lean.

Public-sector incident research puts retention and trust relationships first
Mandiant’s public-sector discussion draws on its 2025 investigations to examine persistent intrusions, virtualization management and interconnected cloud services.

GoldPickaxe research links mobile compromise to biometric exposure
Zimperium reports a GoldPickaxe variant identified in customer environments and analyzes 19 observed samples across five countries.

ESET H1 report tracks changes in a measured threat population
ESET’s H1 2026 report combines detection telemetry with malware research.

RedWing research examines the commercial packaging of Android spyware
Zimperium’s zLabs analyzes RedWing, an Android spyware offering distributed as a subscription service.

Ghost Tapped
Tracking the Rise of Chinese Tap-to-pay Android Malware

Predator iOS Malware:
Building a Surveillance Framework - Part 1

WhatsApp Silent Fix of Device Fingerprinting Privacy Issue Assessment
The Good, The (Not So) Bad, and The (Somewhat) Ugly

DNGerousLINK
A Deep Dive into WhatsApp 0-Click Exploits on iOS and Samsung Devices

Choose Your Fighter: A New Stage in the Evolution of Android SMS Stealers in Uzbekistan
Group-IB analyzes the evolution of Android malware in Uzbekistan, revealing advanced droppers, encrypted payload delivery, anti-analysis techniques, and Wonderland’s bidirectional SMS-stealing capabilities driving large-scale financial fraud.

CVE-2025-38352 (Part 1)
In-the-wild Android Kernel Vulnerability Analysis + PoC

Google Project Zero breaks down a 0-click Android exploit that hijacked Samsung phones via a malicious DNG image—originally flagged by Unit
Google Project Zero breaks down a 0-click Android exploit that hijacked Samsung phones via a malicious DNG image—originally flagged by Unit 42. Patched in April 2025 (CVE-2025-21042)

CVE-2025-31200 & CVE-2025-31201 | iMessage Zero‑Click RCE Chain
CVE-2025-31200 & CVE-2025-31201 | iMessage Zero‑Click RCE Chain Summary This repository documents research into a zero‑click remote exploit chain affecting iOS 18.x. A malformed MP4 audio file delivered via iMessage triggers:

CVE-2025-38352 - In-the-wild Android Kernel Vulnerability Analysis + PoC
CVE-2025-38352 was a race condition use-after-free vulnerability in the Linux kernel's POSIX CPU timers implementation that was reported to have been under limited, targeted exploitation in the wild: September 2025 Android Bulletin An analysis of this vulnerability was already posted by @streypaws. Their blog post does a good job explaining how POSIX CPU timers work, and the

RelayNFC: The New NFC Relay Malware Targeting Brazil
RelayNFC: The New NFC Relay Malware Targeting Brazil

Plug, Play, Pwn: Hacking with Evil Crow Cable Wind
Plug, Play, Pwn: Hacking with Evil Crow Cable Wind

Google Project Zero breaks down a 0-click Android exploit that hijacked Samsung phones via a malicious DNG image—originally flagged by Unit
Google Project Zero breaks down a 0-click Android exploit that hijacked Samsung phones via a malicious DNG image—originally flagged by Unit 42. Patched in April 2025 (CVE-2025-21042

Mobile Forensics: Extracting Data from WhatsApp
Mobile Forensics: Extracting Data from WhatsApp

To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware

DroidLock Hijacks Your Device
Total Takeover: DroidLock Hijacks Your Device
No matching articles. Try another topic or month.