Microsoft Details Kazuar Botnet Used by Secret Blizzard
Microsoft published a technical analysis of Kazuar, a modular Secret Blizzard botnet with P2P routing, staging directories, IPC messages, and selectable C2 bridges.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 24, 2026
Microsoft published a technical analysis of Kazuar, a modular Secret Blizzard botnet with P2P routing, staging directories, IPC messages, and selectable C2 bridges.
Malicious node-ipc versions 9.1.6, 9.2.3, and 12.0.1 were published to npm with a credential-stealing CommonJS payload. Check lockfiles, CI logs, and egress for the…
KongTuke moved from web-based ClickFix lures into external Microsoft Teams chats, using fake help-desk messages to push ModeloRAT and layered persistence on Windows hosts.
Fragnesia is a separate Linux kernel flaw in the Dirty Frag class. It can turn local access into root on unpatched systems, but the…
West Pharmaceutical disclosed a material cyberattack involving data exfiltration, encrypted systems, and global operational disruption. The important part is the overlap between breach response…
A public YellowKey proof-of-concept claims a BitLocker bypass path on Windows 11 systems that rely on TPM-only unlock. Here is where the risk sits…
Microsoft patched two critical Word RCE bugs where the Preview Pane is an attack vector, making Office updates urgent for Outlook and Microsoft 365…
Fortinet patched critical unauthenticated RCE flaws in FortiAuthenticator and FortiSandbox, making exposure review and fast version checks a priority for security appliance admins.
RubyGems disabled new account registration after reports of hundreds of malicious packages, making recent Ruby dependency changes and CI caches worth immediate review.