TrickBot Uses DNS Tunneling to Hide Windows C2 Traffic
A current TrickBot variant hides C2 data in DNS queries and persists through a disguised Windows task. Check westurn.in, task actions, ADS streams, and sample hashes.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 4, 2026
A current TrickBot variant hides C2 data in DNS queries and persists through a disguised Windows task. Check westurn.in, task actions, ADS streams, and sample hashes.
HOLLOWGRAPH uses Microsoft 365 calendar events dated 2050 for command-and-control and file theft. Check Graph activity, logAzure.txt, and DNS telemetry.
CVE-2026-42533 affects NGINX map directives with regex captures. Check the exposure pattern and update to 1.30.4 or 1.31.3.
CERT-UA says UAC-0145 is using ClickFix pages, fake security tools, Signal lures, and Android malware against Ukrainian targets. Check the exact files, paths, and…
CVE-2026-63030 (wp2shell) gives anonymous attackers a route to code execution in WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Verify and update now.
Fake coding-test repositories hide OTTERCOOKIE fragments in SVG flags. Here is what executes, what it steals, and what to check after running one.
Grok Build 0.2.93 was observed uploading tracked repositories and Git history. Here is how to scope exposure, rotate secrets, review logs, and harden future…
Microsoft tracked ACR Stealer ClickFix chains using WebDAV, MSHTA and PowerShell. Check scheduled tasks, browser sessions, exposed passwords and cleanup steps.
Symantec documented a Spirals ransomware attack that moved from an exposed IIS server to network-wide encryption in under 24 hours. Check the confirmed indicators…