Tag

#post-exploitation

6 stories taggedpost-exploitation.

Photoreal editorial 16:9 image of a dimly lit server rack with a single monitor showing abstract Python notebook cells, faint blue glow, shallow depth of field,
Threat Intelligence

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows

A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

4 min read
Full-frame photoreal editorial image of a dimly lit server room in an Israeli office building, blue and amber indicator lights reflecting on polished floor, a f
Threat Intelligence

Hackers hid their attack tools inside an Oracle database itself

A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

4 min read
A futuristic digital map of the Middle East with glowing network lines and a shadowy figure symbolizing cyber threats
Threat Intelligence

What Hackers Actually Do After They're Inside Your Network

A Huntress case study shows why cleaning up the malware is only half the job. If you don't find the front door, they walk back in.

4 min read
Macro view of a tangled knot of glowing fiber optic cables pulsing with light, set against a dark server room background, with some cables dimming and flickerin
AI Security

AI Assistant Turned Loose on Thai Finance Ministry Network

An attacker disabled safety prompts on an AI coding agent and let it run reconnaissance and privilege-escalation checks against Thailand's treasury systems on its own.

4 min read
Threat Intelligence

LLM Agent Spotted Driving Post-Exploitation After Marimo Notebook Compromise

An unattributed intrusion set chained CVE-2026-39987 against an exposed Marimo notebook, then handed the keyboard to a language model.

2 min read
Threat Intelligence

Showboat: A Modular Linux Backdoor Quietly Camped in a Middle East Telco Since 2022

Lumen's Black Lotus Labs ties the SOCKS5-capable implant to a years-long intrusion at a regional carrier, with an in-memory loader and ELF payloads that sidestep most host telemetry.

2 min read
© 2026 Threat Vectr