Today's feed follows attacks on the systems we trust most: developer packages, identity flows, password vaults, code sandboxes, ground-control software and even Defender itself.
Today’s edition focuses on collapsing trust boundaries: exploited infrastructure, browsers turned into pivots, Microsoft services used as covert C2, stolen enterprise identities, and engineering platforms that can expose far more than ordinary business data.
Today we revisit the Nightmare-Eclipse saga after RoguePlanet’s patch, an eighth exploit, a canceled disclosure threat, and another round of reporting that turns an anonymous researcher’s self-authored mythology into apparent fact.
Glassworm botnet dismantled by CrowdStrike/Google/Shadowserver; SRG escalates to physical law firm intrusions; MuddyWater abuses signed EDR binaries across 9 countries; two Defender zero-days patched after six weeks of live exploitation; Ghost CMS flaw hijacks 700+ domains for ClickFix delivery.