msaRAT lets ransomware operators hide command-and-control traffic inside Chrome, using headless browsing, WebRTC, and TURN relays to make a malicious implant appear almost network-silent.
Attackers reached an SD-WAN control plane before its fix, a telecom cyberattack disrupted service across Angola, and a FortiOS patch bypass challenged the meaning of “remediated.” Today’s feed follows the systems that sit beneath ordinary trust.
Fastjson exploitation, a public GitLab command-execution chain and an exposed Check Point management flaw lead today’s feed. Malware also disrupted health services, halted food production and turned calendars and browsers into covert channels.
Cl0p-linked actors exploit CVE-2026-12569 against internet-exposed PTC Windchill and FlexPLM, staging engineering data for extortion. Fastjson 1.x RCE confirmed exploitable under default configs. GitLab PoC published. Router credential theft continues from Russian FSB Center 16.