Research
162 articles - malware analysis, major incidents, hardware hacking, threat intelligence, underground history
The Persistence Layer IR Tools Cannot See: LoJax, CosmicStrand, BlackLotus and What It Takes to Find Firmware-Level Implants
LoJax in 2018, CosmicStrand in 2022, BlackLotus in 2023. Each one survives an OS reinstall, a disk wipe, and a complete CrowdStrike scan - b…
Secure Against Whom? The Hardware of Resisting Surveillance, With the Marketing Removed
The companion to the Crypto Wars piece: given that the cypherpunks won strong encryption, what does using it in hardware actually look like …
When Encryption Was a Weapon: The Cypherpunks, the Crypto Wars, and the Book That Beat the Munitions List
For most of the 1990s a strong encryption program was legally a munition, and exporting it was arms trafficking. The people who broke that f…
An Extortion Group With a Reputation to Protect: CVE-2026-35273, ShinyHunters, and the FBI Advisory They Want Deleted
ShinyHunters exploited an unauthenticated RCE in Oracle PeopleSoft against 100-plus organisations, two thirds of them universities, and publ…
Nobody Logged In: How ShinyHunters Emptied Hundreds of Salesforce Tenants Through OAuth Grants Nobody Owned
Three times in ten months, ShinyHunters and associated actors took data out of hundreds of Salesforce tenants without signing in to any of t…
From a Bing Search to Domain-Wide Akira in 44 Hours: SEO Poisoning, wbadmin and the Software Already on the Network
An IT administrator searched Bing for ManageEngine OpManager and installed a trojanized MSI that also installed the real software. Forty-fou…
$159 of Hardware Breaks Confidential Computing: DDRop, Dropped DDR5 Writes, and Why Encryption Is Not Freshness
A $159 board sits between a server's CPU and its DDR5 memory, passes every boot integrity check, then starts silently discarding writes by i…
One Bug, Two Official CVSS Scores: CVE-2025-25249, PivotC2, and the 1.7 Points That Decide Whether Anyone Gets Paged
NVD scored CVE-2025-25249 at 9.8. Fortinet, the CNA that assigned it, scored it 8.1. The whole gap is one metric - attack complexity - and i…
There Is No C2 Server To Block: EtherRAT, TukTuk, and Command and Control Built Entirely on SaaS
An intrusion ending in domain-wide Gentlemen ransomware, where the command and control ran over ClickHouse, Supabase, Ably, Dropbox, GitHub …