Tag

#living-off-the-land

8 stories taggedliving-off-the-land.

A Thai office environment with servers humming in the background, a remote access management tool interface open on a technician's monitor showing active sessio
Threat Intelligence

Intruder Sat Inside Thai Broadband Giant 3BB, Using Off-the-Shelf Admin Tool to Stay Hidden

A hacker held remote control of internal machines at one of Thailand's biggest internet providers by piggybacking on MeshCentral, a legitimate IT management tool, according to researchers at Hunt.io.

4 min read
A cybersecurity operations center with security analysts viewing multiple decoy systems and honeypot alerts on large displays, with trap tripwires and fake cred
Policy & Regulation

CISA Tells Defenders to Plant Fake Systems and Wait

New federal guidance walks security teams through using decoys, tripwires and fake credentials to spot attackers who look like legitimate users.

4 min read
A network diagram showing Node
Threat Intelligence

Hackers Are Hiding Malware Inside Node.js, and Windows Sees Nothing Wrong

Symantec says attackers have been abusing the legitimate Node.js runtime since February 2026 to slip past defences at governments, tech firms and hotel chains.

3 min read
Multiple computer workstations in a network showing real-time system monitoring dashboards, with one screen displaying Adobe file icons being deployed across co
Threat Intelligence

Phishing crews hijacked a legitimate IT tool to take over more than 450 computers

Attackers pushed fake Adobe files that quietly enrolled victim PCs into Faronics Deploy, then used it to install ScreenConnect for hands-on remote control.

3 min read
A computer booting up with system files and registry entries visible in technical monitoring software, with security software components displayed on screen
Vulnerabilities

Microsoft's Own Antivirus Driver Can Be Turned Into a Weapon at Boot

Check Point researchers show how BTR.sys, the trusted cleanup tool inside Microsoft Defender, can be steered to wipe files and registry keys before Windows even finishes starting.

4 min read
Close-up of a computer screen displaying system security software with warning alerts and red error indicators flooding the interface, while in the background a
Vulnerabilities

Weekly Roundup: Trusted Software Turned Against Defenders, Plus a Critical Gogs Flaw

Signed drivers hijacked to kill antivirus, a code-execution bug in the Gogs source-code platform, and AI shortening the gap between disclosure and working exploit: this week's threats run on tools defenders already trust.

4 min read
A security operations center with multiple detection screens showing successful blocks of known attack patterns highlighted in green, while subtle, unusual netw
Threat Intelligence

Your security tools stopped the obvious attack. They missed the sneaky one.

Picus Security's Blue Report 2026 finds defenses catch famous techniques reliably but let quieter variants walk straight through.

3 min read
Vulnerabilities

Non-Admin macOS Accounts Can Chain Native OS Features to Blind Endpoint Security Tools

No exploit required. Researchers found that standard user privileges are enough to chain macOS weaknesses and silently kill endpoint security agents without touching a vulnerability.

3 min read
© 2026 Threat Vectr