Kaspersky Securelist (GReAT)
kaspersky-securelist · B · active
Kaspersky GReAT research. RSS at https://securelist.com/feed/ is a usable backup. 2026-05-08 audit: 5 dated articles latest 2026-05-07 on xrdp RCE, OceanLotus. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://securelist.com/feed/ 5 (then webfetch per-article URL for body). AVOID: WebFetch on the HTML index renders the article list but strips publication dates — use the /feed/ RSS for clean dates, then webfetch the article for the body.. | 2026-07-05 admiralty audit: B — GReAT original APT/malware research from own telemetry; use /feed/ for clean dates. HIGH->B, stays active.
Cited in 13 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 10).
- The week's tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS2026-07-05
- This week AI crossed from attack target to attack operator — agentic ransomware, coerced coding agents, and LLM-output poisoning2026-07-05
- Kaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT2026-07-02
- Kaspersky: community AI-agent "skills" are an emerging supply-chain surface — OpenClaw marketplace still distributing malicious skills2026-07-02
- Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse2026-07-01
- Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters2026-06-29
- Kaspersky GReAT: "StrikeShark" loader deploys Cobalt Strike via "Perfect DLL Hijacking" against government targets2026-06-27
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control2026-06-24
- Kaspersky GReAT documents Kimsuky's Rust-based HelloDoor and TryCloudflare-tunnel C2 added to the PebbleDash toolkit2026-05-17
- CVE-2025-68670 — xrdp pre-authentication stack overflow, arbitrary code execution2026-05-09
- Kaspersky Q1 2026 Exploits and Vulnerabilities Report: document-based exploits resurge; RaaS acquires zero-days2026-05-08
- Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)2026-05-08
- Kaspersky Q1 2026 Exploits and Vulnerabilities Report2026-05-04