Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
WSL Containers Goes GA: Securing Linux Containers on Windows Endpoints Against Developer-Targeted Abuse
Introduction Microsoft has moved Windows Subsystem for Linux well beyond its original scope of simply running Linux distributions on Windows...
Star Blizzard Fake Event Invite Campaign: Detecting and Blocking Spear-Phishing Malware Delivery Against Ukraine-Linked Organizations
Introduction Microsoft has disclosed an ongoing campaign by Star Blizzard — the Russian state-sponsored threat actor also tracked as SEABORG...
EDR Evasion via Process Parameter Poisoning: Detecting API-Less Process Injection on Windows Endpoints
Introduction Security researchers have disclosed a process injection technique — and an accompanying evasion stack — that poisons process in...
ChainScript RAT Deployed via ClickFix Lures with Polygon Blockchain C2 Rotation — Detection and Response Guide
Introduction Blackpoint's Adversary Pursuit Group (APG) has documented a campaign that fuses two of the most operationally effective tradecr...
UNC3569 Exploits Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — Detection and Remediation Guide
Introduction Gen Digital published research this week documenting an active campaign by the China-linked intrusion set tracked as UNC3569, i...
ValleyRAT Delivered via Legitimate Adware: Detecting DLL Sideloading and Silver Fox Intrusion Activity
ValleyRAT Doesn't Need a Crack — It Needs Your Trust A newly documented ValleyRAT campaign illustrates a shift defenders need to internalize...
DOUBLECUP PNG Payloads: Detect Fake Steganography and Image-Embedded Malware
DOUBLECUP PNG Payloads: Detect Fake Steganography and Image-Embedded Malware The SANS Internet Storm Center diary entry on DOUBLECUP calls o...