<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[ - All Forums]]></title>
		<link>https://exetools.net/</link>
		<description><![CDATA[ - https://exetools.net]]></description>
		<pubDate>Tue, 29 Sep 2026 21:29:23 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Browser Translator Privacy Policy]]></title>
			<link>https://exetools.net/thread-15872.html</link>
			<pubDate>Fri, 24 Jul 2026 21:58:06 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-15872.html</guid>
			<description><![CDATA[<span style="font-size: xx-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Browser Translator Privacy Policy</span></span><br />
<span style="font-weight: bold;" class="mycode_b">Effective date: July 25, 2026</span><br />
<br />
Browser Translator respects your privacy. This Privacy Policy explains what information the extension processes, how that information is used, and the choices available to you.<br />
<br />
1. Overview<br />
Browser Translator is a browser extension that translates text selected on a webpage or manually entered by the user. It also supports automatic language detection, text-to-speech, translation history, favorites, right-to-left and left-to-right languages, context-menu translation, and replacing selected text with its translation.<br />
Browser Translator does not require an account and does not contain advertising, analytics, or user-tracking software.<br />
<br />
2. Information Browser Translator Processes<br />
Browser Translator may process the following information:<br />
Text submitted for translation<br />
When you request a translation, the selected or manually entered text is transmitted to Google Translate so that the translation can be generated.<br />
This text may include website content or other information that you choose to select, enter, or translate. Browser Translator does not automatically submit the entire webpage or unrelated page content.<br />
You should avoid translating passwords, payment information, confidential business information, medical information, or other sensitive data.<br />
Translation preferences and locally stored information<br />
Browser Translator may store the following information locally in your browser profile:<ul class="mycode_list"><li>Translation history<br />
</li>
<li>Favorite translations or languages<br />
</li>
<li>Selected destination language<br />
</li>
<li>Floating translation icon preference<br />
</li>
<li>Other extension interface preferences<br />
</li>
</ul>
This information is used only to provide and remember the extension’s features and settings.<br />
Text-to-speech information<br />
When you activate the pronunciation feature, the translated or selected text is passed to the text-to-speech functionality provided by your browser or operating system. The availability of voices and the way speech is processed may depend on your browser, operating system, and installed speech services.<br />
<br />
3. How Information Is Used<br />
Browser Translator processes information only to:<ul class="mycode_list"><li>Translate text requested by the user<br />
</li>
<li>Automatically detect the source language<br />
</li>
<li>Display translation results<br />
</li>
<li>Pronounce selected or translated text<br />
</li>
<li>Replace selected text when requested<br />
</li>
<li>Maintain local translation history and favorites<br />
</li>
<li>Remember the user’s language and interface preferences<br />
</li>
<li>Provide the floating translation icon, context-menu commands, popup, and side panel<br />
</li>
</ul>
Browser Translator does not use your information for advertising, profiling, behavioral tracking, or marketing.<br />
<br />
4. Third-Party Translation Service<br />
Browser Translator uses the Google Translate service to process translation requests.<br />
When you request a translation, the applicable text and language parameters are transmitted over an encrypted HTTPS connection to:<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>https://translate.googleapis.com/</code></div></div>Google may process this information according to its own privacy practices. The developer of Browser Translator does not control Google’s processing, retention, or handling of information submitted to its services.<br />
For more information, review the <a href="https://policies.google.com/privacy" target="_blank" rel="noopener" class="mycode_url">Google Privacy Policy</a>.<br />
Browser Translator does not send translation requests to a server owned or operated by the developer.<br />
<br />
5. Local Storage<br />
Translation history, favorites, and extension preferences are stored locally using the browser’s extension-storage functionality.<br />
The developer does not have access to this locally stored information, and it is not uploaded to a developer-operated database.<br />
You can remove locally stored information by:<ul class="mycode_list"><li>Clearing translation history within Browser Translator, where available<br />
</li>
<li>Removing individual saved items or favorites<br />
</li>
<li>Resetting the extension’s settings<br />
</li>
<li>Clearing Browser Translator’s extension data through your browser<br />
</li>
<li>Uninstalling Browser Translator<br />
</li>
</ul>
Uninstalling the extension normally removes its locally stored data from the applicable browser profile, subject to the browser’s own behavior and policies.<br />
<br />
6. Browser Permissions<br />
Browser Translator requests only the permissions needed to provide its features.<br />
activeTab<br />
Allows Browser Translator to access the current webpage after the user activates the extension. This access is used to obtain selected text, display the floating translation icon, and replace a selection when requested.<br />
contextMenus<br />
Allows Browser Translator to provide right-click menu commands for translating selected text.<br />
scripting<br />
Allows the extension to run its bundled scripts on the active webpage so it can read the current selection, support editable fields and compatible webpage editors, display the floating icon, and replace selected text when requested.<br />
sidePanel<br />
Allows Browser Translator to provide its translation interface in the Microsoft Edge side panel.<br />
storage<br />
Allows the extension to store translation history, favorites, selected language, floating-icon preference, and other settings locally in the browser profile.<br />
tts<br />
Allows Browser Translator to use the browser’s text-to-speech functionality when the user requests pronunciation.<br />
Host access<br />
Browser Translator requires access to ordinary HTTP and HTTPS webpages to detect user-selected text and provide webpage translation features.<br />
It also requires access to <br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>https://translate.googleapis.com/</code></div></div> to submit user-requested translations and receive translation results.<br />
<br />
7. Data Sharing<br />
Browser Translator does not sell, rent, or trade user information.<br />
Text submitted for translation is shared with Google Translate only as necessary to fulfill the user’s translation request.<br />
Browser Translator does not share information with advertisers, data brokers, analytics providers, or social-media platforms.<br />
Information may also be disclosed if required by applicable law, regulation, legal process, or enforceable governmental request.<br />
<br />
8. Data Collection and Tracking<br />
Browser Translator does not include:<ul class="mycode_list"><li>Advertising<br />
</li>
<li>Analytics<br />
</li>
<li>Tracking pixels<br />
</li>
<li>Behavioral monitoring<br />
</li>
<li>Keystroke logging<br />
</li>
<li>Web-history collection<br />
</li>
<li>Location tracking<br />
</li>
<li>User accounts<br />
</li>
<li>Developer-operated user databases<br />
</li>
<li>Remote executable code<br />
</li>
</ul>
All executable extension code is included in the distributed Browser Translator package. Network access is used to request translation results, not to download and execute remote JavaScript or other executable code.<br />
<br />
9. Data Retention<br />
The developer does not retain translation requests on a developer-operated server because Browser Translator does not operate such a server.<br />
Local history, favorites, and preferences remain in the browser profile until the user clears them, resets the extension, clears the extension’s storage, or uninstalls Browser Translator.<br />
Information transmitted to Google Translate may be handled and retained according to Google’s policies and practices.<br />
<br />
10. Security<br />
Browser Translator uses HTTPS when communicating with Google Translate. Reasonable measures have been taken to limit data processing to the functionality requested by the user.<br />
However, no electronic transmission or storage method can be guaranteed to be completely secure. Users should not submit sensitive, confidential, or legally protected information for translation unless they understand and accept the associated risks.<br />
<br />
11. Children’s Privacy<br />
Browser Translator is a general-purpose productivity tool and is not specifically directed toward children.<br />
The developer does not knowingly collect personal information from children. Users who are minors should use the extension only with permission and supervision from a parent, guardian, school, or other authorized adult where required.<br />
<br />
12. International Data Processing<br />
Google may process translation requests in countries other than the user’s country of residence. Data-protection laws in those countries may differ from local laws.<br />
By requesting a translation, the user understands that the submitted text may be processed by Google as described in Google’s Privacy Policy.<br />
<br />
13. User Choices<br />
You control what text is submitted to Browser Translator.<br />
You may:<ul class="mycode_list"><li>Avoid selecting or entering sensitive information<br />
</li>
<li>Disable the floating translation icon<br />
</li>
<li>Clear translation history<br />
</li>
<li>Remove saved favorites<br />
</li>
<li>Stop using text-to-speech<br />
</li>
<li>Remove Browser Translator at any time<br />
</li>
</ul>
Browser Translator does not submit text for translation unless you interact with its translation features, such as opening it with selected text, using the context menu or floating icon, or pressing the Translate button.<br />
<br />
14. Changes to This Privacy Policy<br />
This Privacy Policy may be updated when Browser Translator’s features, permissions, third-party services, or legal obligations change.<br />
Material changes will be reflected by updating the effective date or policy version shown at the top of this page. Users are encouraged to review this page periodically.<br />
Continued use of Browser Translator after an updated policy becomes effective constitutes acknowledgement of the revised policy.]]></description>
			<content:encoded><![CDATA[<span style="font-size: xx-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Browser Translator Privacy Policy</span></span><br />
<span style="font-weight: bold;" class="mycode_b">Effective date: July 25, 2026</span><br />
<br />
Browser Translator respects your privacy. This Privacy Policy explains what information the extension processes, how that information is used, and the choices available to you.<br />
<br />
1. Overview<br />
Browser Translator is a browser extension that translates text selected on a webpage or manually entered by the user. It also supports automatic language detection, text-to-speech, translation history, favorites, right-to-left and left-to-right languages, context-menu translation, and replacing selected text with its translation.<br />
Browser Translator does not require an account and does not contain advertising, analytics, or user-tracking software.<br />
<br />
2. Information Browser Translator Processes<br />
Browser Translator may process the following information:<br />
Text submitted for translation<br />
When you request a translation, the selected or manually entered text is transmitted to Google Translate so that the translation can be generated.<br />
This text may include website content or other information that you choose to select, enter, or translate. Browser Translator does not automatically submit the entire webpage or unrelated page content.<br />
You should avoid translating passwords, payment information, confidential business information, medical information, or other sensitive data.<br />
Translation preferences and locally stored information<br />
Browser Translator may store the following information locally in your browser profile:<ul class="mycode_list"><li>Translation history<br />
</li>
<li>Favorite translations or languages<br />
</li>
<li>Selected destination language<br />
</li>
<li>Floating translation icon preference<br />
</li>
<li>Other extension interface preferences<br />
</li>
</ul>
This information is used only to provide and remember the extension’s features and settings.<br />
Text-to-speech information<br />
When you activate the pronunciation feature, the translated or selected text is passed to the text-to-speech functionality provided by your browser or operating system. The availability of voices and the way speech is processed may depend on your browser, operating system, and installed speech services.<br />
<br />
3. How Information Is Used<br />
Browser Translator processes information only to:<ul class="mycode_list"><li>Translate text requested by the user<br />
</li>
<li>Automatically detect the source language<br />
</li>
<li>Display translation results<br />
</li>
<li>Pronounce selected or translated text<br />
</li>
<li>Replace selected text when requested<br />
</li>
<li>Maintain local translation history and favorites<br />
</li>
<li>Remember the user’s language and interface preferences<br />
</li>
<li>Provide the floating translation icon, context-menu commands, popup, and side panel<br />
</li>
</ul>
Browser Translator does not use your information for advertising, profiling, behavioral tracking, or marketing.<br />
<br />
4. Third-Party Translation Service<br />
Browser Translator uses the Google Translate service to process translation requests.<br />
When you request a translation, the applicable text and language parameters are transmitted over an encrypted HTTPS connection to:<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>https://translate.googleapis.com/</code></div></div>Google may process this information according to its own privacy practices. The developer of Browser Translator does not control Google’s processing, retention, or handling of information submitted to its services.<br />
For more information, review the <a href="https://policies.google.com/privacy" target="_blank" rel="noopener" class="mycode_url">Google Privacy Policy</a>.<br />
Browser Translator does not send translation requests to a server owned or operated by the developer.<br />
<br />
5. Local Storage<br />
Translation history, favorites, and extension preferences are stored locally using the browser’s extension-storage functionality.<br />
The developer does not have access to this locally stored information, and it is not uploaded to a developer-operated database.<br />
You can remove locally stored information by:<ul class="mycode_list"><li>Clearing translation history within Browser Translator, where available<br />
</li>
<li>Removing individual saved items or favorites<br />
</li>
<li>Resetting the extension’s settings<br />
</li>
<li>Clearing Browser Translator’s extension data through your browser<br />
</li>
<li>Uninstalling Browser Translator<br />
</li>
</ul>
Uninstalling the extension normally removes its locally stored data from the applicable browser profile, subject to the browser’s own behavior and policies.<br />
<br />
6. Browser Permissions<br />
Browser Translator requests only the permissions needed to provide its features.<br />
activeTab<br />
Allows Browser Translator to access the current webpage after the user activates the extension. This access is used to obtain selected text, display the floating translation icon, and replace a selection when requested.<br />
contextMenus<br />
Allows Browser Translator to provide right-click menu commands for translating selected text.<br />
scripting<br />
Allows the extension to run its bundled scripts on the active webpage so it can read the current selection, support editable fields and compatible webpage editors, display the floating icon, and replace selected text when requested.<br />
sidePanel<br />
Allows Browser Translator to provide its translation interface in the Microsoft Edge side panel.<br />
storage<br />
Allows the extension to store translation history, favorites, selected language, floating-icon preference, and other settings locally in the browser profile.<br />
tts<br />
Allows Browser Translator to use the browser’s text-to-speech functionality when the user requests pronunciation.<br />
Host access<br />
Browser Translator requires access to ordinary HTTP and HTTPS webpages to detect user-selected text and provide webpage translation features.<br />
It also requires access to <br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>https://translate.googleapis.com/</code></div></div> to submit user-requested translations and receive translation results.<br />
<br />
7. Data Sharing<br />
Browser Translator does not sell, rent, or trade user information.<br />
Text submitted for translation is shared with Google Translate only as necessary to fulfill the user’s translation request.<br />
Browser Translator does not share information with advertisers, data brokers, analytics providers, or social-media platforms.<br />
Information may also be disclosed if required by applicable law, regulation, legal process, or enforceable governmental request.<br />
<br />
8. Data Collection and Tracking<br />
Browser Translator does not include:<ul class="mycode_list"><li>Advertising<br />
</li>
<li>Analytics<br />
</li>
<li>Tracking pixels<br />
</li>
<li>Behavioral monitoring<br />
</li>
<li>Keystroke logging<br />
</li>
<li>Web-history collection<br />
</li>
<li>Location tracking<br />
</li>
<li>User accounts<br />
</li>
<li>Developer-operated user databases<br />
</li>
<li>Remote executable code<br />
</li>
</ul>
All executable extension code is included in the distributed Browser Translator package. Network access is used to request translation results, not to download and execute remote JavaScript or other executable code.<br />
<br />
9. Data Retention<br />
The developer does not retain translation requests on a developer-operated server because Browser Translator does not operate such a server.<br />
Local history, favorites, and preferences remain in the browser profile until the user clears them, resets the extension, clears the extension’s storage, or uninstalls Browser Translator.<br />
Information transmitted to Google Translate may be handled and retained according to Google’s policies and practices.<br />
<br />
10. Security<br />
Browser Translator uses HTTPS when communicating with Google Translate. Reasonable measures have been taken to limit data processing to the functionality requested by the user.<br />
However, no electronic transmission or storage method can be guaranteed to be completely secure. Users should not submit sensitive, confidential, or legally protected information for translation unless they understand and accept the associated risks.<br />
<br />
11. Children’s Privacy<br />
Browser Translator is a general-purpose productivity tool and is not specifically directed toward children.<br />
The developer does not knowingly collect personal information from children. Users who are minors should use the extension only with permission and supervision from a parent, guardian, school, or other authorized adult where required.<br />
<br />
12. International Data Processing<br />
Google may process translation requests in countries other than the user’s country of residence. Data-protection laws in those countries may differ from local laws.<br />
By requesting a translation, the user understands that the submitted text may be processed by Google as described in Google’s Privacy Policy.<br />
<br />
13. User Choices<br />
You control what text is submitted to Browser Translator.<br />
You may:<ul class="mycode_list"><li>Avoid selecting or entering sensitive information<br />
</li>
<li>Disable the floating translation icon<br />
</li>
<li>Clear translation history<br />
</li>
<li>Remove saved favorites<br />
</li>
<li>Stop using text-to-speech<br />
</li>
<li>Remove Browser Translator at any time<br />
</li>
</ul>
Browser Translator does not submit text for translation unless you interact with its translation features, such as opening it with selected text, using the context menu or floating icon, or pressing the Translate button.<br />
<br />
14. Changes to This Privacy Policy<br />
This Privacy Policy may be updated when Browser Translator’s features, permissions, third-party services, or legal obligations change.<br />
Material changes will be reflected by updating the effective date or policy version shown at the top of this page. Users are encouraged to review this page periodically.<br />
Continued use of Browser Translator after an updated policy becomes effective constitutes acknowledgement of the revised policy.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Browser Highlighter Privacy Policy]]></title>
			<link>https://exetools.net/thread-14127.html</link>
			<pubDate>Mon, 13 Jul 2026 13:45:29 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-14127.html</guid>
			<description><![CDATA[<span style="font-weight: bold;" class="mycode_b">Browser Highlighter Privacy Policy</span><br />
Effective date: July 13, 2026<br />
<br />
Browser Highlighter is a Microsoft Edge extension that allows users to highlight selected webpage text and restore saved highlights when webpages are refreshed or revisited.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Information Accessed and Stored</span><br />
When a user creates a highlight, Browser Highlighter may locally store:<br />
<br />
• The URL of the webpage where the highlight was created.<br />
• The text selected by the user.<br />
• Limited surrounding webpage text needed to locate and restore the highlight.<br />
• The highlight position and selected color.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Purpose of the Information</span><br />
This information is used only to create, save, restore, recolor, select, and remove highlights requested by the user.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Local Storage</span><br />
All highlight information is stored locally on the user's device using the Microsoft Edge extension storage API.<br />
Browser Highlighter does not transmit stored highlight information to the developer, an external server, or any third party.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Data Sharing and Selling</span><br />
<br />
<span style="font-weight: bold;" class="mycode_b">Browser Highlighter does not</span>:<br />
• Sell user data.<br />
• Share user data with third parties.<br />
• Transmit data to external servers.<br />
• Use analytics or tracking services.<br />
• Display advertisements.<br />
• Create advertising or behavioral profiles.<br />
• Require a user account or registration.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Remote Code</span><br />
Browser Highlighter does not download or execute remotely hosted code. All executable code and resources are included in the installed extension package.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">User Controls and Data Removal</span><br />
Users can remove an individual highlight, remove all highlights from a webpage, clear the extension's stored data through Microsoft Edge, or uninstall the extension.<br />
<br />
Removing highlights deletes their locally stored records. Uninstalling the extension removes its locally stored extension data according to Microsoft Edge's data-management behavior.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Permissions</span><br />
Browser Highlighter uses the storage permission to save highlight information locally.<br />
It accesses normal webpages only to apply, restore, recolor, select, and remove highlights requested by the user.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Changes to This Privacy Policy</span><br />
This privacy policy may be updated if Browser Highlighter's functionality or data practices change. The effective date will be updated when changes are made.]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;" class="mycode_b">Browser Highlighter Privacy Policy</span><br />
Effective date: July 13, 2026<br />
<br />
Browser Highlighter is a Microsoft Edge extension that allows users to highlight selected webpage text and restore saved highlights when webpages are refreshed or revisited.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Information Accessed and Stored</span><br />
When a user creates a highlight, Browser Highlighter may locally store:<br />
<br />
• The URL of the webpage where the highlight was created.<br />
• The text selected by the user.<br />
• Limited surrounding webpage text needed to locate and restore the highlight.<br />
• The highlight position and selected color.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Purpose of the Information</span><br />
This information is used only to create, save, restore, recolor, select, and remove highlights requested by the user.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Local Storage</span><br />
All highlight information is stored locally on the user's device using the Microsoft Edge extension storage API.<br />
Browser Highlighter does not transmit stored highlight information to the developer, an external server, or any third party.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Data Sharing and Selling</span><br />
<br />
<span style="font-weight: bold;" class="mycode_b">Browser Highlighter does not</span>:<br />
• Sell user data.<br />
• Share user data with third parties.<br />
• Transmit data to external servers.<br />
• Use analytics or tracking services.<br />
• Display advertisements.<br />
• Create advertising or behavioral profiles.<br />
• Require a user account or registration.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Remote Code</span><br />
Browser Highlighter does not download or execute remotely hosted code. All executable code and resources are included in the installed extension package.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">User Controls and Data Removal</span><br />
Users can remove an individual highlight, remove all highlights from a webpage, clear the extension's stored data through Microsoft Edge, or uninstall the extension.<br />
<br />
Removing highlights deletes their locally stored records. Uninstalling the extension removes its locally stored extension data according to Microsoft Edge's data-management behavior.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Permissions</span><br />
Browser Highlighter uses the storage permission to save highlight information locally.<br />
It accesses normal webpages only to apply, restore, recolor, select, and remove highlights requested by the user.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Changes to This Privacy Policy</span><br />
This privacy policy may be updated if Browser Highlighter's functionality or data practices change. The effective date will be updated when changes are made.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[From a VHDX File to a Remcos RAT, (Tue, Jun 16th)]]></title>
			<link>https://exetools.net/thread-4810.html</link>
			<pubDate>Tue, 16 Jun 2026 07:09:13 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4810.html</guid>
			<description><![CDATA[[b]From a VHDX File to a Remcos RAT, (Tue, Jun 16th)[/b]<br />
<br />
<br />
Yesterday, a reader reported to us a malicious ZIP archive (SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094[1]). Once unzipped, it contains a VHDX file that discloses a malicious JavaScript after being mounted (which is automatic on modern Windows OSs):<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://isc.sans.edu/diary/rss/33080]https://isc.sans.edu/diary/rss/33080[/url]<br />
[b]Published:[/b] Today, 07:09 AM]]></description>
			<content:encoded><![CDATA[[b]From a VHDX File to a Remcos RAT, (Tue, Jun 16th)[/b]<br />
<br />
<br />
Yesterday, a reader reported to us a malicious ZIP archive (SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094[1]). Once unzipped, it contains a VHDX file that discloses a malicious JavaScript after being mounted (which is automatic on modern Windows OSs):<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://isc.sans.edu/diary/rss/33080]https://isc.sans.edu/diary/rss/33080[/url]<br />
[b]Published:[/b] Today, 07:09 AM]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[iRhythm discloses data breach, says hackers stole patient info]]></title>
			<link>https://exetools.net/thread-4802.html</link>
			<pubDate>Tue, 16 Jun 2026 06:31:59 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4802.html</guid>
			<description><![CDATA[[b]iRhythm discloses data breach, says hackers stole patient info[/b]<br />
<br />
<br />
Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications. [...]<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/]https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/[/url]<br />
[b]Published:[/b] Today, 06:31 AM<br />
[b]Author:[/b] Sergiu Gatlan]]></description>
			<content:encoded><![CDATA[[b]iRhythm discloses data breach, says hackers stole patient info[/b]<br />
<br />
<br />
Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications. [...]<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/]https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/[/url]<br />
[b]Published:[/b] Today, 06:31 AM<br />
[b]Author:[/b] Sergiu Gatlan]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks]]></title>
			<link>https://exetools.net/thread-4804.html</link>
			<pubDate>Tue, 16 Jun 2026 06:20:18 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4804.html</guid>
			<description><![CDATA[[b]Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks[/b]<br />
<br />
<br />
Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.<br />
<br />
The post [url=https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/]Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks[/url] appeared first on [url=https://www.securityweek.com]SecurityWeek[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/]https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/[/url]<br />
[b]Published:[/b] Today, 06:20 AM<br />
[b]Author:[/b] Eduard Kovacs]]></description>
			<content:encoded><![CDATA[[b]Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks[/b]<br />
<br />
<br />
Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.<br />
<br />
The post [url=https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/]Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks[/url] appeared first on [url=https://www.securityweek.com]SecurityWeek[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/]https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/[/url]<br />
[b]Published:[/b] Today, 06:20 AM<br />
[b]Author:[/b] Eduard Kovacs]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw]]></title>
			<link>https://exetools.net/thread-4803.html</link>
			<pubDate>Tue, 16 Jun 2026 06:05:58 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4803.html</guid>
			<description><![CDATA[[b]Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw[/b]<br />
<br />
[img]https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-vJIadGle0Cre1cNAxZIcD9ktkl1mPnUwtEtF1xuMbeH75BnvGq3twL0W2OowYW7ZZMxvzMjdbU-VMEZfEvV1q2pTIoG8VU_D0d_rpRqwlViZqUyb1WKcL6pM9Nklx_mISZR2BttoBxMq8w6Z87rf3Stm37ZbcRbAYM0SQeEJqg0T8dc2KsrX1a9l95B7/s1600/cisco-flaw.jpg[/img]<br />
<br />
<br />
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.<br />
<br />
The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0.<br />
<br />
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html]https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html[/url]<br />
[b]Published:[/b] Today, 06:05 AM<br />
[b]Author:[/b] info@thehackernews.com (The Hacker News)]]></description>
			<content:encoded><![CDATA[[b]Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw[/b]<br />
<br />
[img]https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-vJIadGle0Cre1cNAxZIcD9ktkl1mPnUwtEtF1xuMbeH75BnvGq3twL0W2OowYW7ZZMxvzMjdbU-VMEZfEvV1q2pTIoG8VU_D0d_rpRqwlViZqUyb1WKcL6pM9Nklx_mISZR2BttoBxMq8w6Z87rf3Stm37ZbcRbAYM0SQeEJqg0T8dc2KsrX1a9l95B7/s1600/cisco-flaw.jpg[/img]<br />
<br />
<br />
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.<br />
<br />
The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0.<br />
<br />
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html]https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html[/url]<br />
[b]Published:[/b] Today, 06:05 AM<br />
[b]Author:[/b] info@thehackernews.com (The Hacker News)]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Inside a malicious infrastructure delivering EtherRAT, phishing pages, and...]]></title>
			<link>https://exetools.net/thread-4807.html</link>
			<pubDate>Mon, 15 Jun 2026 20:17:46 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4807.html</guid>
			<description><![CDATA[[b]Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software [/b]<br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_369ca0.png[/img]<br />
<br />
<br />
During our recent threat hunting activities, we found EtherRAT malware being distributed by a website with a strange homepage. This homepage allowed us to discover a vast malicious infrastructure distributing malware, malicious documents, remote desktop software, and phishing pages. <br />
<br />
EtherRAT is a RAT developed in Node.js which allows an attacker to gain complete control over the machine and execute arbitrary code returned by the Command and Control (C2) server. The malware uses the Etherium blockchain to obtain the C2 server, hence the “Ether” part of the name. EtherRAT is typically distributed via MSI, PowerShell, or JavaScript scripts. <br />
<br />
An open directory that distributes EtherRAT: where it all began <br />
<br />
While threat hunting, we found an open directory that was distributing MSI installers and PowerShell scripts, which ultimately distributed EtherRAT. In the analyzed cases, the PowerShell scripts and MSI installers were distributed from a “/install” folder.  The versions have a progressive number, ranging from v1 to v10. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_369ca0.png[/img][i]Open Directory hosting EtherRAT MSI [/i]<br />
<br />
The returned home page caught our attention and prompted us to further explore the campaign. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_8728d4.png[/img][i]The homepage returned by the EtherRAT distribution website[/i] <br />
<br />
Analyzing domains and associated IPs with the EtherRAT distribution, we detected other similar home pages with a hacking-style theme. They appeared to belong to a larger distribution chain, which also distributes phishing, remote control software, and other malware. These websites usually have several folders with malware and phishing related content, and what is displayed depends on the specific infection chain. <br />
<br />
Different websites that resolve to the same IP addresses have previously returned pages related to fake companies or default templates. The use of these new pages could therefore be a method to make detection more difficult for automated scanners or researchers.  Here are some of the home pages we found:<br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_cc9098.png[/img][i]Some of the malicious websites indexed on Google[/i] <br />
<br />
EtherRAT is an interesting RAT, as it has few lines of code and allows the execution of arbitrary code returned by the C2 server. Furthermore, using the Ethereum blockchain to obtain the C2 server makes it more resilient to infrastructure takedowns. <br />
<br />
Technical analysis of EtherRAT <br />
<br />
The detected websites usually distribute an MSI or PowerShell script with the version name, such as v1.msi, v2.ps1, and so on. <br />
<br />
MSI Loader <br />
<br />
The MSI file “v9.msi” contains three components: <br />
<br />
[b]MSI Filename[/b] [b]Description[/b] KmPuGimn.cmd BAT launcher cDQMlQAru0.xml First Jscript loader MRaQCipBIZeiZNx.log Encrypted EtherRAT <br />
<br />
When the MSI is executed, the “KmPuGimn.cmd” file is started: <br />
<br />
conhost --headless cmd /c "KmPuGimn.cmd" <br />
<br />
This obfuscated BAT file performs different operations: <br />
<br />
Extracts the other files in a random folder in %LOCALAPPDATA%. <br />
<br />
Re-executes itself via: <br />
<br />
%SystemRoot%\System32\conhost.exe –headless %SystemRoot%\System32\cmd.exe /c call “C:\Users\{user}\AppData\Local\{random_path}\KmPuGimn.cmd” nKWa <br />
<br />
Runs the command “where node” to find an existing installation. <br />
<br />
Downloads Node.js if it’s not found <br />
<br />
Uses “curl -sLo” to download Node.js from the official website. <br />
<br />
Extracts to installation directory via “tar -xf”. <br />
<br />
Renames extracted directory to “28Q75h”.<br />
<br />
Loops until both “MRaQCipBIZeiZNx.log” and “cDQMlQAru0.xml” exist, then executes: <br />
<br />
conhost.exe –headless C:\Users\{user}\AppData\Local\{random_path}\{random_path}\node.exe cDQMlQAru0.xml <br />
<br />
The executed “cDQMlQAru0.xml” is a loader that decrypts the embedded code with a XOR function and then executes it with “vm.compileFunction”. <br />
<br />
decrypted[i] = (encrypted[i] - key[i % key.length] - i) &amp; 0xFF <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_851e9c.png[/img][i]The embedded decrypted code[/i] <br />
<br />
The decrypted code: <br />
<br />
Copies node.exe in “C:\Users\{user}\AppData\Local\{random_path}\{random_path}\_MJlLlt5.exe”. <br />
<br />
Adds a registry key for persistence with “conhost.exe –headless”. <br />
<br />
Decrypts “MRaQCipBIZeiZNx.log” and executes it with “_MJlLlt5.exe” stdin. <br />
<br />
The decryption algorithm is a custom stream-like decoding routing based on XOR, byte rotations and an accumulator: <br />
<br />
for e in range(len(data)): <br />
    byte = data[e] <br />
    g = prev <br />
    prev = byte <br />
    byte = (byte - g) &amp; 0xff <br />
    byte = byte ^ n[e % len(n)] ^ ((e &gt;&gt; 8) &amp; 0xff) <br />
    byte = si[byte] <br />
    byte = (byte - k[e % len(k)]) &amp; 0xff<br />
    result[e] = byte <br />
<br />
The final stage is to deploy EtherRAT. EtherRAT allows the attacker to: <br />
<br />
Execute arbitrary JavaScript code received by the C2 server. This allows the attacker to execute new commands, perform operations on files and folders, modify the registry, and exfiltrate data. <br />
<br />
Get a new C2 server using the Ethereum blockchain. <br />
<br />
Reobfuscate itself. <br />
<br />
Save the logs to “svchost.log”. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_d445bb.png[/img][i]Part of decrypted EtherRAT code[/i] <br />
<br />
The EtherRAT uses Ethereum’s “eth_call” JSON-RPC method to retrieve the active C2 URL from a smart contract on the Ethereum mainnet.  <br />
<br />
The blockchain parameters in this case are: <br />
<br />
Contract: 0x88ea8d0bc4146f0a018e989df3fd089ac48f9a58 <br />
<br />
Function selector: 0x7d434425 <br />
<br />
Argument: 0xf6a772e163e64b07f658946f863b5d457d88f9f0 <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_f3c52b.png[/img][i]The decoded C2 from Ethereum blockchain[/i] <br />
<br />
The contacted URLs to obtain the C2 server endpoint are: <br />
<br />
mainnet[.]gateway[.]tenderly[.]co <br />
<br />
rpc[.]flashbots[.]net/fast <br />
<br />
rpc[.]mevblocker[.]io <br />
<br />
eth-mainnet[.]public[.]blastapi[.]io <br />
<br />
ethereum-rpc[.]publicnode[.]com <br />
<br />
eth[.]drpc[.]org <br />
<br />
eth[.]merkle[.]io <br />
<br />
Polling requests use randomized URL patterns based on some parameters defined in the code: <br />
<br />
GET /api///.?= <br />
X-Bot-Server:  <br />
<br />
In the analyzed sample, the parameters are: <br />
<br />
Build ID: “6f816d80-0d6c-4384-9cd6-6b79965fc08f” <br />
<br />
ext: randomly selected from “png”, “jpg”, “gif”, “css”, “ico”, “webp”. <br />
<br />
param: randomly selected from “id”, “token”, “key”, “b”, “q”, “s”, “v”. <br />
<br />
After startup, the RAT sends its own source code to the C2 server. The C2 responds with a newly obfuscated version of the script, which is written back to disk, making each execution generate a new file hash. <br />
<br />
POST /api/[REOBF_PATH]/ <br />
Body: { "code": "", "build": "" } <br />
<br />
After the EtherRAT execution, we observed different post-compromised cmd.exe activities to check the environment. For example: <br />
<br />
powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_VideoController).Name”<br />
<br />
reg query “HKLM\SOFTWARE\Microsoft\Cryptography” /v MachineGuid <br />
<br />
powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).Domain” <br />
<br />
powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).PartOfDomain” <br />
<br />
cmd.exe /d /s /c “net session” <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_ed2136.png[/img][i]EtherRAT logs[/i] <br />
<br />
PowerShell Loader <br />
<br />
The activities performed by the PowerShell loaders are very similar to the last stage of the JS script of the MSI installer: <br />
<br />
Downloads Node.js if it’s not present. <br />
<br />
Create the necessary directories. <br />
<br />
Decode the EtherRAT with a custom decryption algorithm. <br />
<br />
Execute Node.js with conhost.exe and the decrypted EtherRAT payload. <br />
<br />
We detected some variants of the PowerShell loader hosted on these websites; namely that the functions’ names and the decryption functions change in the analyzed PowerShell scripts. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_54aca3.png[/img][i]The decryption of EtherRAT payload with the custom decryption algorithm[/i] <br />
<br />
Tracking the malicious infrastructure <br />
<br />
When we analyzed the different websites with the “hacking-theme” pages, we found that in the past many had hosted multiple phishing pages in some specific paths. For example: <br />
<br />
/zht/sharep-redirect.html <br />
<br />
/bl/me.php <br />
<br />
/t/teams <br />
<br />
/teams/Windows/invite.php <br />
<br />
It seems that these domains and IPs are actually part of a much larger infrastructure that distributes malware, phishing, malicious documents, and remote software. It is possible that these infrastructures are shared by multiple threat actors who activate different URL endpoints based on the specific campaign. <br />
<br />
Interestingly, the majority of the domains related to this malicious infrastructure in the past also returned an HTML page related to a “Bulletproof Infrastructure” service.  <br />
<br />
We found that these phishing campaigns typically start via emails with documents attached, such as PDF or Excel files. These documents ask the user to click a link to view another document. Below are two examples of the phishing documents attached to the emails:<br />
<br />
These phishing pages typically ask the user to enter their email address, then continue the infection chain and distribute phishing or malware pages.  Below are some of the phishing pages detected within the malicious infrastructure:<br />
<br />
Misconfigurations exposed the phishing kits <br />
<br />
While tracking malicious websites, we found one with an open directory containing part of the phishing kit used in the campaigns. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_363c0d.png[/img][i]Open directory hosting part of phishing kits[/i]<br />
<br />
 <br />
<br />
The open directory contained several folders with code and pages related to the phishing campaigns. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_121c58.png[/img][i]Phishing kit code[/i] <br />
<br />
Additionally, some domains were misconfigured and allowed the download of “cl.zip”, which contained the source code for the “URL Cloaker” pages. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_dfc923.png[/img][i]Part of “URL Cloaker” code[/i] <br />
<br />
[b]Indicators of Compromise (IOCs) [/b] <br />
<br />
[b]IPs[/b] <br />
<br />
82[.]165[.]65[.]244: malicious infrastructure  <br />
<br />
185[.]221[.]216[.]121: malicious infrastructure  <br />
<br />
43[.]163[.]233[.]166: malicious infrastructure  <br />
<br />
40[.]160[.]238[.]30: malicious infrastructure  <br />
<br />
159[.]89[.]227[.]204: malicious infrastructure  <br />
<br />
57[.]128[.]31[.]168: malicious infrastructure  <br />
<br />
[b]Domains[/b] <br />
<br />
ivorilla[.]cloud: EtherRAT distribution  <br />
<br />
mx[.]nrlwz[.]com: EtherRAT distribution  <br />
<br />
dn[.]eyqwj[.]com: EtherRAT distribution  <br />
<br />
bi[.]mkrjcsw[.]com: EtherRAT distribution  <br />
<br />
dorqen[.]casa: EtherRAT distribution  <br />
<br />
kelvra[.]club: EtherRAT distribution  <br />
<br />
cambioefectivo[.]com: EtherRAT C2  <br />
<br />
vabelles[.]com: EtherRAT C2  <br />
<br />
tranzed[.]org: EtherRAT C2  <br />
<br />
kibrisarazi[.]com: EtherRAT C2  <br />
<br />
aravisblog[.]com: EtherRAT C2  <br />
<br />
publicspeakingtip[.]org: EtherRAT C2  <br />
<br />
[b]Acknowledgement[/b][b]s[/b][b][/b] <br />
<br />
EtherRAT: [url=https://atos.net/en/lp/cybershield/etherrat-distribution-spoofing-administrative-tools-via-github-facades]https://atos.net/en/lp/cybershield/etherrat-distribution-spoofing-administrative-tools-via-github-facades[/url] <br />
<br />
SharePoint reference: [url=https://ironscales.com/threat-intelligence/no-macro-xlsx-shared-strings-aitm-redirect-credential-harvest]https://ironscales.com/threat-intelligence/no-macro-xlsx-shared-strings-aitm-redirect-credential-harvest[/url] <br />
<br />
[b]Stop threats before they can do any harm.[/b]<br />
<br />
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. [url=https://www.malwarebytes.com/browserguard]Add it to your browser →[/url]<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software]https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software[/url]<br />
[b]Published:[/b] Yesterday, 08:17 PM]]></description>
			<content:encoded><![CDATA[[b]Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software [/b]<br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_369ca0.png[/img]<br />
<br />
<br />
During our recent threat hunting activities, we found EtherRAT malware being distributed by a website with a strange homepage. This homepage allowed us to discover a vast malicious infrastructure distributing malware, malicious documents, remote desktop software, and phishing pages. <br />
<br />
EtherRAT is a RAT developed in Node.js which allows an attacker to gain complete control over the machine and execute arbitrary code returned by the Command and Control (C2) server. The malware uses the Etherium blockchain to obtain the C2 server, hence the “Ether” part of the name. EtherRAT is typically distributed via MSI, PowerShell, or JavaScript scripts. <br />
<br />
An open directory that distributes EtherRAT: where it all began <br />
<br />
While threat hunting, we found an open directory that was distributing MSI installers and PowerShell scripts, which ultimately distributed EtherRAT. In the analyzed cases, the PowerShell scripts and MSI installers were distributed from a “/install” folder.  The versions have a progressive number, ranging from v1 to v10. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_369ca0.png[/img][i]Open Directory hosting EtherRAT MSI [/i]<br />
<br />
The returned home page caught our attention and prompted us to further explore the campaign. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_8728d4.png[/img][i]The homepage returned by the EtherRAT distribution website[/i] <br />
<br />
Analyzing domains and associated IPs with the EtherRAT distribution, we detected other similar home pages with a hacking-style theme. They appeared to belong to a larger distribution chain, which also distributes phishing, remote control software, and other malware. These websites usually have several folders with malware and phishing related content, and what is displayed depends on the specific infection chain. <br />
<br />
Different websites that resolve to the same IP addresses have previously returned pages related to fake companies or default templates. The use of these new pages could therefore be a method to make detection more difficult for automated scanners or researchers.  Here are some of the home pages we found:<br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_cc9098.png[/img][i]Some of the malicious websites indexed on Google[/i] <br />
<br />
EtherRAT is an interesting RAT, as it has few lines of code and allows the execution of arbitrary code returned by the C2 server. Furthermore, using the Ethereum blockchain to obtain the C2 server makes it more resilient to infrastructure takedowns. <br />
<br />
Technical analysis of EtherRAT <br />
<br />
The detected websites usually distribute an MSI or PowerShell script with the version name, such as v1.msi, v2.ps1, and so on. <br />
<br />
MSI Loader <br />
<br />
The MSI file “v9.msi” contains three components: <br />
<br />
[b]MSI Filename[/b] [b]Description[/b] KmPuGimn.cmd BAT launcher cDQMlQAru0.xml First Jscript loader MRaQCipBIZeiZNx.log Encrypted EtherRAT <br />
<br />
When the MSI is executed, the “KmPuGimn.cmd” file is started: <br />
<br />
conhost --headless cmd /c "KmPuGimn.cmd" <br />
<br />
This obfuscated BAT file performs different operations: <br />
<br />
Extracts the other files in a random folder in %LOCALAPPDATA%. <br />
<br />
Re-executes itself via: <br />
<br />
%SystemRoot%\System32\conhost.exe –headless %SystemRoot%\System32\cmd.exe /c call “C:\Users\{user}\AppData\Local\{random_path}\KmPuGimn.cmd” nKWa <br />
<br />
Runs the command “where node” to find an existing installation. <br />
<br />
Downloads Node.js if it’s not found <br />
<br />
Uses “curl -sLo” to download Node.js from the official website. <br />
<br />
Extracts to installation directory via “tar -xf”. <br />
<br />
Renames extracted directory to “28Q75h”.<br />
<br />
Loops until both “MRaQCipBIZeiZNx.log” and “cDQMlQAru0.xml” exist, then executes: <br />
<br />
conhost.exe –headless C:\Users\{user}\AppData\Local\{random_path}\{random_path}\node.exe cDQMlQAru0.xml <br />
<br />
The executed “cDQMlQAru0.xml” is a loader that decrypts the embedded code with a XOR function and then executes it with “vm.compileFunction”. <br />
<br />
decrypted[i] = (encrypted[i] - key[i % key.length] - i) &amp; 0xFF <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_851e9c.png[/img][i]The embedded decrypted code[/i] <br />
<br />
The decrypted code: <br />
<br />
Copies node.exe in “C:\Users\{user}\AppData\Local\{random_path}\{random_path}\_MJlLlt5.exe”. <br />
<br />
Adds a registry key for persistence with “conhost.exe –headless”. <br />
<br />
Decrypts “MRaQCipBIZeiZNx.log” and executes it with “_MJlLlt5.exe” stdin. <br />
<br />
The decryption algorithm is a custom stream-like decoding routing based on XOR, byte rotations and an accumulator: <br />
<br />
for e in range(len(data)): <br />
    byte = data[e] <br />
    g = prev <br />
    prev = byte <br />
    byte = (byte - g) &amp; 0xff <br />
    byte = byte ^ n[e % len(n)] ^ ((e &gt;&gt; 8) &amp; 0xff) <br />
    byte = si[byte] <br />
    byte = (byte - k[e % len(k)]) &amp; 0xff<br />
    result[e] = byte <br />
<br />
The final stage is to deploy EtherRAT. EtherRAT allows the attacker to: <br />
<br />
Execute arbitrary JavaScript code received by the C2 server. This allows the attacker to execute new commands, perform operations on files and folders, modify the registry, and exfiltrate data. <br />
<br />
Get a new C2 server using the Ethereum blockchain. <br />
<br />
Reobfuscate itself. <br />
<br />
Save the logs to “svchost.log”. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_d445bb.png[/img][i]Part of decrypted EtherRAT code[/i] <br />
<br />
The EtherRAT uses Ethereum’s “eth_call” JSON-RPC method to retrieve the active C2 URL from a smart contract on the Ethereum mainnet.  <br />
<br />
The blockchain parameters in this case are: <br />
<br />
Contract: 0x88ea8d0bc4146f0a018e989df3fd089ac48f9a58 <br />
<br />
Function selector: 0x7d434425 <br />
<br />
Argument: 0xf6a772e163e64b07f658946f863b5d457d88f9f0 <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_f3c52b.png[/img][i]The decoded C2 from Ethereum blockchain[/i] <br />
<br />
The contacted URLs to obtain the C2 server endpoint are: <br />
<br />
mainnet[.]gateway[.]tenderly[.]co <br />
<br />
rpc[.]flashbots[.]net/fast <br />
<br />
rpc[.]mevblocker[.]io <br />
<br />
eth-mainnet[.]public[.]blastapi[.]io <br />
<br />
ethereum-rpc[.]publicnode[.]com <br />
<br />
eth[.]drpc[.]org <br />
<br />
eth[.]merkle[.]io <br />
<br />
Polling requests use randomized URL patterns based on some parameters defined in the code: <br />
<br />
GET /api///.?= <br />
X-Bot-Server:  <br />
<br />
In the analyzed sample, the parameters are: <br />
<br />
Build ID: “6f816d80-0d6c-4384-9cd6-6b79965fc08f” <br />
<br />
ext: randomly selected from “png”, “jpg”, “gif”, “css”, “ico”, “webp”. <br />
<br />
param: randomly selected from “id”, “token”, “key”, “b”, “q”, “s”, “v”. <br />
<br />
After startup, the RAT sends its own source code to the C2 server. The C2 responds with a newly obfuscated version of the script, which is written back to disk, making each execution generate a new file hash. <br />
<br />
POST /api/[REOBF_PATH]/ <br />
Body: { "code": "", "build": "" } <br />
<br />
After the EtherRAT execution, we observed different post-compromised cmd.exe activities to check the environment. For example: <br />
<br />
powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_VideoController).Name”<br />
<br />
reg query “HKLM\SOFTWARE\Microsoft\Cryptography” /v MachineGuid <br />
<br />
powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).Domain” <br />
<br />
powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).PartOfDomain” <br />
<br />
cmd.exe /d /s /c “net session” <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_ed2136.png[/img][i]EtherRAT logs[/i] <br />
<br />
PowerShell Loader <br />
<br />
The activities performed by the PowerShell loaders are very similar to the last stage of the JS script of the MSI installer: <br />
<br />
Downloads Node.js if it’s not present. <br />
<br />
Create the necessary directories. <br />
<br />
Decode the EtherRAT with a custom decryption algorithm. <br />
<br />
Execute Node.js with conhost.exe and the decrypted EtherRAT payload. <br />
<br />
We detected some variants of the PowerShell loader hosted on these websites; namely that the functions’ names and the decryption functions change in the analyzed PowerShell scripts. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_54aca3.png[/img][i]The decryption of EtherRAT payload with the custom decryption algorithm[/i] <br />
<br />
Tracking the malicious infrastructure <br />
<br />
When we analyzed the different websites with the “hacking-theme” pages, we found that in the past many had hosted multiple phishing pages in some specific paths. For example: <br />
<br />
/zht/sharep-redirect.html <br />
<br />
/bl/me.php <br />
<br />
/t/teams <br />
<br />
/teams/Windows/invite.php <br />
<br />
It seems that these domains and IPs are actually part of a much larger infrastructure that distributes malware, phishing, malicious documents, and remote software. It is possible that these infrastructures are shared by multiple threat actors who activate different URL endpoints based on the specific campaign. <br />
<br />
Interestingly, the majority of the domains related to this malicious infrastructure in the past also returned an HTML page related to a “Bulletproof Infrastructure” service.  <br />
<br />
We found that these phishing campaigns typically start via emails with documents attached, such as PDF or Excel files. These documents ask the user to click a link to view another document. Below are two examples of the phishing documents attached to the emails:<br />
<br />
These phishing pages typically ask the user to enter their email address, then continue the infection chain and distribute phishing or malware pages.  Below are some of the phishing pages detected within the malicious infrastructure:<br />
<br />
Misconfigurations exposed the phishing kits <br />
<br />
While tracking malicious websites, we found one with an open directory containing part of the phishing kit used in the campaigns. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_363c0d.png[/img][i]Open directory hosting part of phishing kits[/i]<br />
<br />
 <br />
<br />
The open directory contained several folders with code and pages related to the phishing campaigns. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_121c58.png[/img][i]Phishing kit code[/i] <br />
<br />
Additionally, some domains were misconfigured and allowed the download of “cl.zip”, which contained the source code for the “URL Cloaker” pages. <br />
<br />
[img]https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/06/image_dfc923.png[/img][i]Part of “URL Cloaker” code[/i] <br />
<br />
[b]Indicators of Compromise (IOCs) [/b] <br />
<br />
[b]IPs[/b] <br />
<br />
82[.]165[.]65[.]244: malicious infrastructure  <br />
<br />
185[.]221[.]216[.]121: malicious infrastructure  <br />
<br />
43[.]163[.]233[.]166: malicious infrastructure  <br />
<br />
40[.]160[.]238[.]30: malicious infrastructure  <br />
<br />
159[.]89[.]227[.]204: malicious infrastructure  <br />
<br />
57[.]128[.]31[.]168: malicious infrastructure  <br />
<br />
[b]Domains[/b] <br />
<br />
ivorilla[.]cloud: EtherRAT distribution  <br />
<br />
mx[.]nrlwz[.]com: EtherRAT distribution  <br />
<br />
dn[.]eyqwj[.]com: EtherRAT distribution  <br />
<br />
bi[.]mkrjcsw[.]com: EtherRAT distribution  <br />
<br />
dorqen[.]casa: EtherRAT distribution  <br />
<br />
kelvra[.]club: EtherRAT distribution  <br />
<br />
cambioefectivo[.]com: EtherRAT C2  <br />
<br />
vabelles[.]com: EtherRAT C2  <br />
<br />
tranzed[.]org: EtherRAT C2  <br />
<br />
kibrisarazi[.]com: EtherRAT C2  <br />
<br />
aravisblog[.]com: EtherRAT C2  <br />
<br />
publicspeakingtip[.]org: EtherRAT C2  <br />
<br />
[b]Acknowledgement[/b][b]s[/b][b][/b] <br />
<br />
EtherRAT: [url=https://atos.net/en/lp/cybershield/etherrat-distribution-spoofing-administrative-tools-via-github-facades]https://atos.net/en/lp/cybershield/etherrat-distribution-spoofing-administrative-tools-via-github-facades[/url] <br />
<br />
SharePoint reference: [url=https://ironscales.com/threat-intelligence/no-macro-xlsx-shared-strings-aitm-redirect-credential-harvest]https://ironscales.com/threat-intelligence/no-macro-xlsx-shared-strings-aitm-redirect-credential-harvest[/url] <br />
<br />
[b]Stop threats before they can do any harm.[/b]<br />
<br />
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. [url=https://www.malwarebytes.com/browserguard]Add it to your browser →[/url]<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software]https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software[/url]<br />
[b]Published:[/b] Yesterday, 08:17 PM]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[GitHub Copilot CLI for Beginners: Overview of common slash commands]]></title>
			<link>https://exetools.net/thread-4818.html</link>
			<pubDate>Mon, 15 Jun 2026 20:15:31 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4818.html</guid>
			<description><![CDATA[[b]GitHub Copilot CLI for Beginners: Overview of common slash commands[/b]<br />
<br />
<br />
Welcome back to GitHub Copilot CLI for Beginners! In this series (available in [url=https://www.youtube.com/playlist?list=PL0lo9MOBetEHvO-spzKBAITkkTqv4RvNl]video[/url] and [url=https://github.blog/tag/github-copilot-cli-for-beginners/]blog[/url] format), we’ll give you everything you need to get started using [url=https://github.com/features/copilot/cli?utm_source=blog-cli-beginners-ep1-features-cta&amp;utm_medium=blog&amp;utm_campaign=dev-pod-copilot-cli-2026]GitHub Copilot CLI[/url]. So far in this series, we’ve covered [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-getting-started-with-github-copilot-cli/]how to get started[/url] and [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-interactive-v-non-interactive-mode/]when to use interactive and non-interactive modes[/url]. In this edition, we’ll learn what slash commands are, why they matter, and how to use slash commands to control GitHub Copilot efficiently. You can complete tasks like switching models, checking token usage, and resuming past sessions right from your terminal.<br />
<br />
Let’s dive in!<br />
<br />
Understanding slash commands in GitHub Copilot CLI<br />
<br />
When working in Copilot CLI, one of the most powerful concepts to learn early on is [b]slash commands.[/b] Slash commands are built-in controls that you can access directly from the command line. Acting as your control surface within Copilot CLI, slash commands allow you to:<br />
<br />
Guide Copilot’s behavior<br />
<br />
Inspect changes<br />
<br />
Manage context<br />
<br />
Move efficiently across sessions and projects<br />
<br />
Keep permissions tidy<br />
<br />
Slash commands can be thought of as your command center for interacting with Copilot CLI. To look at all of the options available, just type / in the command line for a scrollable list of all currently supported slash commands.<br />
<br />
Let’s take a look at some of the most popular ones.<br />
<br />
Choosing the right model<br />
<br />
Different models are optimized for different kinds of work. If you want to switch models, type /model into the command line. This will display a list of available models, along with key details like:<br />
<br />
[b]Capabilities[/b]: Some are better for quick, lightweight tasks like refactoring, while others more efficiently handle deeper reasoning such as feature planning.<br />
<br />
[b]Availability[/b]: The list may vary depending on your plan or organization’s settings.<br />
<br />
[b]Cost[/b]: Numbers shown on the right of each model indicate cost multiplier, helping you choose the right balance between performance and usage in relation to your plan.<br />
<br />
Choosing the right model can significantly impact both speed and results.<br />
<br />
Managing context and token usage<br />
<br />
Copilot CLI operates within a context window, which determines how much information it can “remember” during a session. If you want to check your current usage, type /context to learn how many tokens you have left, along with system usage and available buffer.<br />
<br />
If you find that you’re running low on space, you can free up space by typing /compact in the command line. This summarizes your current conversation so you can continue without having to start a new session. Copilot CLI will do this automatically when you approach the limit, but you can also do this manually if you want to transition to a new task or clean up context mid-session.<br />
<br />
If you’d rather start fresh and completely reset your environment, you can use /clear to clear the session entirely.<br />
<br />
Working across sessions<br />
<br />
If you want to resume a previous session, you can type /resume. This will bring up a list of previous sessions you’ve had, including both local and remote sessions. Entering a previous session will show you your session history, and you can pick up right where you left off.<br />
<br />
Inspecting changes<br />
<br />
As you work with Copilot to make changes to your project, it’s important to keep track of what’s changed. If you want to see what the changes are, run /diff to see recent updates. This gives you a clear view of what modifications were made during your session, so you can validate changes before moving forward.<br />
<br />
Navigating projects and directories<br />
<br />
If you want to work across repositories or directories, you don’t have to exit Copilot. You can type /cwd to change your working directory to another repository. This allows you to scope Copilot’s work to a specific part of your project and helps you stay efficient while multitasking across codebases.<br />
<br />
Managing tool permissions<br />
<br />
In the past, you might have granted Copilot CLI permission to perform actions like editing files. Say you’re switching to a repository you want to be more careful in and want to reset those permissions: you can do so by running /reset-allowed-tools.<br />
<br />
Take this with you<br />
<br />
Using these slash commands gives you even better control over Copilot CLI—and the more familiar you become with them, the more deliberate your workflow becomes.<br />
<br />
Whether you’re switching models, managing context, or navigating across projects, using slash commands in CLI gives you the tools you need to stay in control. And if you haven’t already: open up your terminal, type /, and explore! There are many more slash commands to discover.<br />
<br />
Happy coding!<br />
<br />
[b]Looking to try GitHub Copilot CLI?[/b] [url=https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli]Read the docs[/url] and [url=https://github.com/features/copilot/cli?utm_source=blog-cli-beginners-ep1-features-cta&amp;utm_medium=blog&amp;utm_campaign=dev-pod-copilot-cli-2026]get started[/url] today.<br />
<br />
[b]More resources to explore:[/b]<br />
<br />
[url=https://www.youtube.com/playlist?list=PL0lo9MOBetEHvO-spzKBAITkkTqv4RvNl]GitHub Copilot CLI for Beginners video series[/url]<br />
<br />
[url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-getting-started-with-github-copilot-cli/?utm_source=blog-announcement-cli-tutorial&amp;utm_medium=blog&amp;utm_campaign=universe25post]GitHub Copilot CLI for Beginners: Getting started with GitHub Copilot CLI[/url]<br />
<br />
[url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-interactive-v-non-interactive-mode/]GitHub Copilot CLI for Beginners: Interactive v. non-interactive mode[/url]<br />
<br />
[url=https://github.blog/ai-and-ml/github-copilot-cli-101-how-to-use-github-copilot-from-the-command-line/?utm_source=blog-announcement-cli-tutorial&amp;utm_medium=blog&amp;utm_campaign=universe25post]GitHub Copilot CLI 101: How to use GitHub Copilot from the command line[/url]<br />
<br />
[url=https://docs.github.com/en/copilot/how-tos/copilot-cli/cli-best-practices?utm_campaign=copilot-brand&amp;utm_medium=sem&amp;utm_source=google&amp;ocid=AIDcmmh2h80ugd_SEM__k_CjwKCAjw-dfOBhAjEiwAq0RwI0TIeyL9bjDmXlY26JKPbDvHGzBcaZUa4LR8u8SJuGbIke6e7U2YXRoCzGQQAvD_BwE_k_]Best practices for GitHub Copilot CLI[/url]<br />
<br />
The post [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-overview-of-common-slash-commands/]GitHub Copilot CLI for Beginners: Overview of common slash commands[/url] appeared first on [url=https://github.blog]The GitHub Blog[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-overview-of-common-slash-commands/]https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-overview-of-common-slash-commands/[/url]<br />
[b]Published:[/b] Yesterday, 08:15 PM<br />
[b]Author:[/b] Natalie Guevara]]></description>
			<content:encoded><![CDATA[[b]GitHub Copilot CLI for Beginners: Overview of common slash commands[/b]<br />
<br />
<br />
Welcome back to GitHub Copilot CLI for Beginners! In this series (available in [url=https://www.youtube.com/playlist?list=PL0lo9MOBetEHvO-spzKBAITkkTqv4RvNl]video[/url] and [url=https://github.blog/tag/github-copilot-cli-for-beginners/]blog[/url] format), we’ll give you everything you need to get started using [url=https://github.com/features/copilot/cli?utm_source=blog-cli-beginners-ep1-features-cta&amp;utm_medium=blog&amp;utm_campaign=dev-pod-copilot-cli-2026]GitHub Copilot CLI[/url]. So far in this series, we’ve covered [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-getting-started-with-github-copilot-cli/]how to get started[/url] and [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-interactive-v-non-interactive-mode/]when to use interactive and non-interactive modes[/url]. In this edition, we’ll learn what slash commands are, why they matter, and how to use slash commands to control GitHub Copilot efficiently. You can complete tasks like switching models, checking token usage, and resuming past sessions right from your terminal.<br />
<br />
Let’s dive in!<br />
<br />
Understanding slash commands in GitHub Copilot CLI<br />
<br />
When working in Copilot CLI, one of the most powerful concepts to learn early on is [b]slash commands.[/b] Slash commands are built-in controls that you can access directly from the command line. Acting as your control surface within Copilot CLI, slash commands allow you to:<br />
<br />
Guide Copilot’s behavior<br />
<br />
Inspect changes<br />
<br />
Manage context<br />
<br />
Move efficiently across sessions and projects<br />
<br />
Keep permissions tidy<br />
<br />
Slash commands can be thought of as your command center for interacting with Copilot CLI. To look at all of the options available, just type / in the command line for a scrollable list of all currently supported slash commands.<br />
<br />
Let’s take a look at some of the most popular ones.<br />
<br />
Choosing the right model<br />
<br />
Different models are optimized for different kinds of work. If you want to switch models, type /model into the command line. This will display a list of available models, along with key details like:<br />
<br />
[b]Capabilities[/b]: Some are better for quick, lightweight tasks like refactoring, while others more efficiently handle deeper reasoning such as feature planning.<br />
<br />
[b]Availability[/b]: The list may vary depending on your plan or organization’s settings.<br />
<br />
[b]Cost[/b]: Numbers shown on the right of each model indicate cost multiplier, helping you choose the right balance between performance and usage in relation to your plan.<br />
<br />
Choosing the right model can significantly impact both speed and results.<br />
<br />
Managing context and token usage<br />
<br />
Copilot CLI operates within a context window, which determines how much information it can “remember” during a session. If you want to check your current usage, type /context to learn how many tokens you have left, along with system usage and available buffer.<br />
<br />
If you find that you’re running low on space, you can free up space by typing /compact in the command line. This summarizes your current conversation so you can continue without having to start a new session. Copilot CLI will do this automatically when you approach the limit, but you can also do this manually if you want to transition to a new task or clean up context mid-session.<br />
<br />
If you’d rather start fresh and completely reset your environment, you can use /clear to clear the session entirely.<br />
<br />
Working across sessions<br />
<br />
If you want to resume a previous session, you can type /resume. This will bring up a list of previous sessions you’ve had, including both local and remote sessions. Entering a previous session will show you your session history, and you can pick up right where you left off.<br />
<br />
Inspecting changes<br />
<br />
As you work with Copilot to make changes to your project, it’s important to keep track of what’s changed. If you want to see what the changes are, run /diff to see recent updates. This gives you a clear view of what modifications were made during your session, so you can validate changes before moving forward.<br />
<br />
Navigating projects and directories<br />
<br />
If you want to work across repositories or directories, you don’t have to exit Copilot. You can type /cwd to change your working directory to another repository. This allows you to scope Copilot’s work to a specific part of your project and helps you stay efficient while multitasking across codebases.<br />
<br />
Managing tool permissions<br />
<br />
In the past, you might have granted Copilot CLI permission to perform actions like editing files. Say you’re switching to a repository you want to be more careful in and want to reset those permissions: you can do so by running /reset-allowed-tools.<br />
<br />
Take this with you<br />
<br />
Using these slash commands gives you even better control over Copilot CLI—and the more familiar you become with them, the more deliberate your workflow becomes.<br />
<br />
Whether you’re switching models, managing context, or navigating across projects, using slash commands in CLI gives you the tools you need to stay in control. And if you haven’t already: open up your terminal, type /, and explore! There are many more slash commands to discover.<br />
<br />
Happy coding!<br />
<br />
[b]Looking to try GitHub Copilot CLI?[/b] [url=https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli]Read the docs[/url] and [url=https://github.com/features/copilot/cli?utm_source=blog-cli-beginners-ep1-features-cta&amp;utm_medium=blog&amp;utm_campaign=dev-pod-copilot-cli-2026]get started[/url] today.<br />
<br />
[b]More resources to explore:[/b]<br />
<br />
[url=https://www.youtube.com/playlist?list=PL0lo9MOBetEHvO-spzKBAITkkTqv4RvNl]GitHub Copilot CLI for Beginners video series[/url]<br />
<br />
[url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-getting-started-with-github-copilot-cli/?utm_source=blog-announcement-cli-tutorial&amp;utm_medium=blog&amp;utm_campaign=universe25post]GitHub Copilot CLI for Beginners: Getting started with GitHub Copilot CLI[/url]<br />
<br />
[url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-interactive-v-non-interactive-mode/]GitHub Copilot CLI for Beginners: Interactive v. non-interactive mode[/url]<br />
<br />
[url=https://github.blog/ai-and-ml/github-copilot-cli-101-how-to-use-github-copilot-from-the-command-line/?utm_source=blog-announcement-cli-tutorial&amp;utm_medium=blog&amp;utm_campaign=universe25post]GitHub Copilot CLI 101: How to use GitHub Copilot from the command line[/url]<br />
<br />
[url=https://docs.github.com/en/copilot/how-tos/copilot-cli/cli-best-practices?utm_campaign=copilot-brand&amp;utm_medium=sem&amp;utm_source=google&amp;ocid=AIDcmmh2h80ugd_SEM__k_CjwKCAjw-dfOBhAjEiwAq0RwI0TIeyL9bjDmXlY26JKPbDvHGzBcaZUa4LR8u8SJuGbIke6e7U2YXRoCzGQQAvD_BwE_k_]Best practices for GitHub Copilot CLI[/url]<br />
<br />
The post [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-overview-of-common-slash-commands/]GitHub Copilot CLI for Beginners: Overview of common slash commands[/url] appeared first on [url=https://github.blog]The GitHub Blog[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-overview-of-common-slash-commands/]https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-for-beginners-overview-of-common-slash-commands/[/url]<br />
[b]Published:[/b] Yesterday, 08:15 PM<br />
[b]Author:[/b] Natalie Guevara]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Copilot 'SearchLeak' Attack Allows 1-Click Data Theft]]></title>
			<link>https://exetools.net/thread-4805.html</link>
			<pubDate>Mon, 15 Jun 2026 19:27:48 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4805.html</guid>
			<description><![CDATA[[b]Copilot 'SearchLeak' Attack Allows 1-Click Data Theft[/b]<br />
<br />
[img]https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltd943e9204f974e51/6a3053a98a78d25c2f29ab90/leaking_faucet-igorwheeler-Getty-511928310.jpg?width=720&amp;quality=80&amp;disable=upscale[/img]<br />
<br />
<br />
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft]https://www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft[/url]<br />
[b]Published:[/b] Yesterday, 07:27 PM<br />
[b]Author:[/b] Alexander Culafi]]></description>
			<content:encoded><![CDATA[[b]Copilot 'SearchLeak' Attack Allows 1-Click Data Theft[/b]<br />
<br />
[img]https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltd943e9204f974e51/6a3053a98a78d25c2f29ab90/leaking_faucet-igorwheeler-Getty-511928310.jpg?width=720&amp;quality=80&amp;disable=upscale[/img]<br />
<br />
<br />
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft]https://www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft[/url]<br />
[b]Published:[/b] Yesterday, 07:27 PM<br />
[b]Author:[/b] Alexander Culafi]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[NIS2 is raising the bar. Here’s how to turn readiness into resilience.]]></title>
			<link>https://exetools.net/thread-4823.html</link>
			<pubDate>Mon, 15 Jun 2026 17:29:15 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4823.html</guid>
			<description><![CDATA[[b]NIS2 is raising the bar. Here’s how to turn readiness into resilience.[/b]<br />
<br />
[img]https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt61632ee7cd1805c5/69fa3eae5ab0e4c3f43c256c/rapid7-nis2-24-hour-rule-infographic-card.webp[/img]<br />
<br />
<br />
The NIS2 directive asks covered organizations to take a more structured approach to risk management, governance, supply chain security, and incident reporting. It expands the scope of who may be covered, raises expectations around management body accountability, introduces clearer and more enforceable requirements, and increases pressure on organizations to show that security is being managed in a consistent, defensible way. Reporting timelines are one of the most visible parts of that shift, with early warning required within 24 hours of awareness for significant incidents, incident notification within 72 hours, and a final report within one month. It also arrived in a landscape that is still uneven, with member states continuing to implement the directive in different ways across the EU.<br />
<br />
That combination has created a familiar challenge for CISOs and security teams, as the questions coming from boards and leadership are no longer just about whether the organization understands the regulation, but whether it can meet the requirements in practice. NIS2 reaches into risk management, reporting, governance, and supply chain oversight, which means readiness depends on how well security works across the business, not just on how well a policy is written.<br />
<br />
That is why the most useful way to think about NIS2 is as an operational resilience exercise. Compliance still matters, of course, and teams need to know what the directive requires. What tends to make the difference over time is whether security leaders can connect those requirements to the real conditions of the environment: what is exposed, where ownership sits, how incident response works in practice, how supply chain risk is monitored, and how quickly the organization can move when something material happens.<br />
<br />
Regulations are easier to absorb than operating model changes. A team may understand that NIS2 raises expectations around governance and incident handling, while still finding it difficult to answer basic questions quickly when pressure rises. Which business services are most critical? Which third parties matter most? Who owns the decision when a serious issue lands? How prepared are we to investigate, communicate, and report inside the timelines the directive expects? Those are the questions that separate a compliance project from a resilience program.<br />
<br />
That is also why we have been building practical content to help teams move from interpretation to action.<br />
<br />
Our [url=https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6e0946b2a5e15d06/6a02fd7a2e7ac04668f9ef22/the-shift-to-continuous-resilience-under-nis2.pdf]ebook[/url] is the best place to start if you want the wider context. It is designed to help security leaders understand what NIS2 means in practical terms, how to think about the directive beyond a narrow checklist, and how to connect compliance obligations to a broader resilience strategy. If your team needs a stronger narrative for internal stakeholders, or a clearer way to explain why NIS2 should influence operational priorities, the ebook is the most useful first read.<br />
<br />
Next, our [url=https://sites.google.com/rapid7.com/n2a/]NIS2 Readiness Toolkit[/url] is built for teams that want to assess where they are and what to do next. iIt is as a way to bridge the gap between NIS2 requirements and operational reality, with a focus on risk, reporting, and governance. It is designed to help teams spot gaps, focus effort, and simplify the path from regulatory complexity to a more defensible security strategy. In other words, it gives you a practical framework for understanding where readiness is strong, where it is uneven, and what deserves attention first.<br />
<br />
Our infographic, seen below, is the quickest asset to use when you need to communicate one of the most tangible parts of NIS2: the 24-hour reporting requirement. Some stakeholders need the long-form explanation. Others need a practical view of what has to happen between incident awareness and early notification. The infographic helps teams bring that operational pressure into planning conversations, leadership updates, and internal alignment without requiring everyone to start with a longer asset first.<br />
<br />
[img]https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc0909ba22dff4f58/6a3039b6a2c8b85460cf1e97/REQ-18355_-_Infographic_The_24-Hour_Rule-1.png[/img]⠀<br />
<br />
Taken together, these assets are useful because they serve different parts of the same problem. The ebook gives you a strategic view, the toolkit helps you assess readiness and prioritize action, and the infographic helps communicate the big picture quickly and clearly.<br />
<br />
Enforcement expectations, reporting maturity, and national interpretation continue to evolve, and security teams are working through those changes at the same time as the wider threat landscape becomes more complex. A stronger response starts with clarity, but it needs to move quickly into coordination, ownership, and repeatable process if it is going to hold up under pressure.<br />
<br />
If your organization is still treating NIS2 as a point-in-time compliance exercise, now is a good moment to widen the lens. The directive is pushing security leaders beyond a comply-once approach and toward a model of being continuously secure. Teams that build better visibility, stronger governance, and clearer response processes for NIS2 will be better prepared not only for regulatory scrutiny, but for the wider operational demands that are already shaping the market.<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.rapid7.com/blog/post/so-nis2-compliance-turn-readiness-into-resilience]https://www.rapid7.com/blog/post/so-nis2-compliance-turn-readiness-into-resilience[/url]<br />
[b]Published:[/b] Yesterday, 05:29 PM<br />
[b]Author:[/b] Sabeen Malik]]></description>
			<content:encoded><![CDATA[[b]NIS2 is raising the bar. Here’s how to turn readiness into resilience.[/b]<br />
<br />
[img]https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt61632ee7cd1805c5/69fa3eae5ab0e4c3f43c256c/rapid7-nis2-24-hour-rule-infographic-card.webp[/img]<br />
<br />
<br />
The NIS2 directive asks covered organizations to take a more structured approach to risk management, governance, supply chain security, and incident reporting. It expands the scope of who may be covered, raises expectations around management body accountability, introduces clearer and more enforceable requirements, and increases pressure on organizations to show that security is being managed in a consistent, defensible way. Reporting timelines are one of the most visible parts of that shift, with early warning required within 24 hours of awareness for significant incidents, incident notification within 72 hours, and a final report within one month. It also arrived in a landscape that is still uneven, with member states continuing to implement the directive in different ways across the EU.<br />
<br />
That combination has created a familiar challenge for CISOs and security teams, as the questions coming from boards and leadership are no longer just about whether the organization understands the regulation, but whether it can meet the requirements in practice. NIS2 reaches into risk management, reporting, governance, and supply chain oversight, which means readiness depends on how well security works across the business, not just on how well a policy is written.<br />
<br />
That is why the most useful way to think about NIS2 is as an operational resilience exercise. Compliance still matters, of course, and teams need to know what the directive requires. What tends to make the difference over time is whether security leaders can connect those requirements to the real conditions of the environment: what is exposed, where ownership sits, how incident response works in practice, how supply chain risk is monitored, and how quickly the organization can move when something material happens.<br />
<br />
Regulations are easier to absorb than operating model changes. A team may understand that NIS2 raises expectations around governance and incident handling, while still finding it difficult to answer basic questions quickly when pressure rises. Which business services are most critical? Which third parties matter most? Who owns the decision when a serious issue lands? How prepared are we to investigate, communicate, and report inside the timelines the directive expects? Those are the questions that separate a compliance project from a resilience program.<br />
<br />
That is also why we have been building practical content to help teams move from interpretation to action.<br />
<br />
Our [url=https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6e0946b2a5e15d06/6a02fd7a2e7ac04668f9ef22/the-shift-to-continuous-resilience-under-nis2.pdf]ebook[/url] is the best place to start if you want the wider context. It is designed to help security leaders understand what NIS2 means in practical terms, how to think about the directive beyond a narrow checklist, and how to connect compliance obligations to a broader resilience strategy. If your team needs a stronger narrative for internal stakeholders, or a clearer way to explain why NIS2 should influence operational priorities, the ebook is the most useful first read.<br />
<br />
Next, our [url=https://sites.google.com/rapid7.com/n2a/]NIS2 Readiness Toolkit[/url] is built for teams that want to assess where they are and what to do next. iIt is as a way to bridge the gap between NIS2 requirements and operational reality, with a focus on risk, reporting, and governance. It is designed to help teams spot gaps, focus effort, and simplify the path from regulatory complexity to a more defensible security strategy. In other words, it gives you a practical framework for understanding where readiness is strong, where it is uneven, and what deserves attention first.<br />
<br />
Our infographic, seen below, is the quickest asset to use when you need to communicate one of the most tangible parts of NIS2: the 24-hour reporting requirement. Some stakeholders need the long-form explanation. Others need a practical view of what has to happen between incident awareness and early notification. The infographic helps teams bring that operational pressure into planning conversations, leadership updates, and internal alignment without requiring everyone to start with a longer asset first.<br />
<br />
[img]https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc0909ba22dff4f58/6a3039b6a2c8b85460cf1e97/REQ-18355_-_Infographic_The_24-Hour_Rule-1.png[/img]⠀<br />
<br />
Taken together, these assets are useful because they serve different parts of the same problem. The ebook gives you a strategic view, the toolkit helps you assess readiness and prioritize action, and the infographic helps communicate the big picture quickly and clearly.<br />
<br />
Enforcement expectations, reporting maturity, and national interpretation continue to evolve, and security teams are working through those changes at the same time as the wider threat landscape becomes more complex. A stronger response starts with clarity, but it needs to move quickly into coordination, ownership, and repeatable process if it is going to hold up under pressure.<br />
<br />
If your organization is still treating NIS2 as a point-in-time compliance exercise, now is a good moment to widen the lens. The directive is pushing security leaders beyond a comply-once approach and toward a model of being continuously secure. Teams that build better visibility, stronger governance, and clearer response processes for NIS2 will be better prepared not only for regulatory scrutiny, but for the wider operational demands that are already shaping the market.<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.rapid7.com/blog/post/so-nis2-compliance-turn-readiness-into-resilience]https://www.rapid7.com/blog/post/so-nis2-compliance-turn-readiness-into-resilience[/url]<br />
[b]Published:[/b] Yesterday, 05:29 PM<br />
[b]Author:[/b] Sabeen Malik]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender email security benchmarking: Key insights from one year of data]]></title>
			<link>https://exetools.net/thread-4809.html</link>
			<pubDate>Mon, 15 Jun 2026 16:00:00 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4809.html</guid>
			<description><![CDATA[[b]Microsoft Defender email security benchmarking: Key insights from one year of data[/b]<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture1.webp[/img]<br />
<br />
<br />
Microsoft publishes [url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365/performance-benchmarking]quarterly email security benchmarking data[/url] comparing [url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365]Microsoft Defender[/url] against secure email gateway (SEG) and integrated cloud email security (ICES) vendors using real-world threat telemetry.<br />
<br />
A year ago, we set out to change how email security effectiveness is measured. With [url=https://www.microsoft.com/en-us/security/blog/2025/07/17/transparency-on-microsoft-defender-for-office-365-email-security-effectiveness/]our first benchmarking report in July 2025[/url], we committed to publishing real-world performance data, not synthetic tests, so security teams could make decisions grounded in evidence. With each quarterly update, we refined our methodology, expanded our analysis, and listened to customer and partner feedback. <br />
<br />
Alongside it, we established the Microsoft Defender ICES vendor ecosystem, designed to enable seamless integration with trusted third-party vendors and streamline security operations center (SOC) workflows for organizations who have chosen a multi-vendor email security strategy. <br />
<br />
[url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365/performance-benchmarking]Read the latest Microsoft benchmarking data for email security[/url]<br />
<br />
Key insights from a year of email benchmarking<br />
<br />
With four consecutive quarters, several findings have proven to be durable insights, highlighting the sustained realities of how layered email security performs in production:<br />
<br />
[b]1. Defender consistently leads in pre-delivery detection. [/b]Across every benchmarking period since July 2025, Defender has missed fewer high-severity cyberthreats than every SEG vendor evaluated, while the next closest SEG vendor had 2.5 times more misses.<br />
<br />
[b]2. ICES vendors add the most value in promotional and bulk email filtering. [/b]Promotional filtering uplift has been the clearest area of ICES value with an average uplift of 15% over the four quarters of evaluation. Meanwhile ICES vendor uplift for malicious catch and spam has consistently remained relatively nominal, averaging at 0.29% and 0.68%, respectively. In addition, over the last three quarters we’ve seen a consistent downward trend in these numbers, as we have continued to drive innovation in post-delivery mail detection.<br />
<br />
[b]3. Defender’s share of post-delivery remediation has grown significantly. [/b]In our second report, we introduced insights on the contribution of Defender to post-delivery malicious catch. Initially, Defender contributed 45% of post-delivery malicious catch, which has since risen to an average of 96%. This trajectory underscores that Microsoft’s post-delivery catch is an increasingly critical backstop, operating even when ICES solutions are in place, and that Defender is delivering the majority of post-delivery remediation.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture1.webp[/img]Figure 1: Malicious catch and spam catch uplift from ICES vendors of the past 12 months.<br />
<br />
SEG vendor benchmarking results<br />
<br />
For SEG vendors, a threat is classified as “missed” if it was not detected prior to delivery. Using this definition, Microsoft Defender once again missed fewer high-severity email threats than all other solutions evaluated, consistent with every prior benchmarking period.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture2.webp[/img]Figure 2: High-severity email threats missed by SEG vendors (February 2026-April 2026), measured as threats missed per 1,000 users protected.<br />
<br />
This quarter, Defender missed 59% fewer high-severity threats than the next-closest SEG vendor, a gap that has remained consistent across all four benchmarking periods.<br />
<br />
ICES vendor benchmarking results<br />
<br />
ICES solutions operating on top of Microsoft Defender continue to provide benefit, particularly in reducing promotional and bulk email, with an average improvement of 16.85% over the last quarter. This helps minimize inbox clutter and improves user productivity in environments where promotional noise is a concern. For malicious messages and spam, the average improvement across vendors was 0.13% for malicious and 0.28% for spam catch, compared to 0.24% and 0.29% in the prior report.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture3-1.webp[/img]Figure 3: ICES vendor catch contribution (February 2026-April 2026).<br />
<br />
Focusing only on malicious messages that reached the inbox, the latest quarter shows Microsoft Defender’s post-delivery catch continues to improve, catching the majority of post‑delivery remediation. It removes an average of 96.03%, up from 70.8% in the previous quarter, highlighting the effectiveness of our continuous investments in this area. Post‑delivery remediation remains a critical backstop when cyberthreats evade initial filtering.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture4-1.webp[/img]Figure 4: Post‑delivery malicious catch by Microsoft Defender (February 2026-April 2026), shown across vendors and overall average.<br />
<br />
Innovation shaped by benchmarking insights<br />
<br />
Benchmarking doesn’t just help customers make better decisions. It shapes what we build. Over the past year we’ve used the insights from our benchmarking reports, as well as insights from the growing ICES vendor ecosystem, to directly shape our innovation and product outcomes. Below are some of the most recent highlights, that we directly attribute to the continued improvements in Microsoft Defender performance.<br />
<br />
[b]Native promotion and bulk mail filtering in Outlook[/b]: A dedicated Promotions folder, natively provisioned in Outlook, now keeps legitimate bulk mail out of the primary inbox. Promotional content is separated from priority emails without being sent to Junk, which means users can still access and browse newsletters and updates at their own pace. The folder appears at the top level of the mailbox for easy discovery and is visible across all Outlook experiences. Once generally available it will be on by default, improving the native promotional filtering. [url=https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/declutter-and-defend-reducing-promotional-mail-noise-with-microsoft-defender/4511732]Learn more[/url].<br />
<br />
[b]System-level AI advancements[/b]: Among other AI enhancements, in November 2025 we introduced an agentic grading system that reduces the reliance on manual review in the submission and analysis pipeline. It helps deliver lower wait times, faster responses, and higher-quality results when emails are submitted to Microsoft for review. That means security teams can investigate reported messages more efficiently, respond more promptly, and act with greater confidence against phishing threats. [url=https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/microsoft-ignite-2025-transforming-phishing-response-with-agentic-innovation/4470791]Learn more[/url].<br />
<br />
[b]Accelerating investigation with AI[/b]: The growing role of post-delivery remediation in our benchmarking data highlights a related challenge: when threats reach users and get reported, SOC teams need to triage those submissions quickly and accurately. The [url=https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot]Microsoft Security Copilot[/url] Alert Triage Agent uses language model-powered reasoning to classify user-reported phishing emails, resolve false positives, and escalate confirmed threats for analyst review. Results show analysts identify 6.5 times more malicious alerts, improve verdict accuracy by 77%, and spend 53% more time investigating real cyberthreats. Security Copilot’s Email Summary further speeds investigations by turning email detection data into clear, actionable insights in the Email entity page. [url=https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/announcing-public-preview-security-copilot%E2%80%99s-email-summary-in-microsoft-defender/4510357]Learn more[/url].<br />
<br />
A year into this effort, our commitment to transparent benchmarking remains unchanged. We’ll continue using these insights to shape product innovation, share real-world performance data with customers, and invest in a strong ecosystem that meets organizations where they are—supporting the layered email security strategies that work best for their environments.<br />
<br />
[url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365/performance-benchmarking]Read the latest Microsoft Defender benchmarking data[/url]<br />
<br />
Learn more<br />
<br />
Learn more about [url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365]Microsoft Defender[/url].<br />
<br />
To learn more about Microsoft Security solutions, visit our [url=https://www.microsoft.com/en-us/security/business]website.[/url] Bookmark the [url=https://www.microsoft.com/security/blog/]Security blog[/url] to keep up with our expert coverage on security matters. Also, follow us on LinkedIn ([url=https://www.linkedin.com/showcase/microsoft-security/]Microsoft Security[/url]) and X ([url=https://twitter.com/@MSFTSecurity]@MSFTSecurity[/url]) for the latest news and updates on cybersecurity.<br />
<br />
The post [url=https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/]Microsoft Defender email security benchmarking: Key insights from one year of data[/url] appeared first on [url=https://www.microsoft.com/en-us/security/blog]Microsoft Security Blog[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/]https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/[/url]<br />
[b]Published:[/b] Yesterday, 04:00 PM<br />
[b]Author:[/b] Jeff Pinkston]]></description>
			<content:encoded><![CDATA[[b]Microsoft Defender email security benchmarking: Key insights from one year of data[/b]<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture1.webp[/img]<br />
<br />
<br />
Microsoft publishes [url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365/performance-benchmarking]quarterly email security benchmarking data[/url] comparing [url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365]Microsoft Defender[/url] against secure email gateway (SEG) and integrated cloud email security (ICES) vendors using real-world threat telemetry.<br />
<br />
A year ago, we set out to change how email security effectiveness is measured. With [url=https://www.microsoft.com/en-us/security/blog/2025/07/17/transparency-on-microsoft-defender-for-office-365-email-security-effectiveness/]our first benchmarking report in July 2025[/url], we committed to publishing real-world performance data, not synthetic tests, so security teams could make decisions grounded in evidence. With each quarterly update, we refined our methodology, expanded our analysis, and listened to customer and partner feedback. <br />
<br />
Alongside it, we established the Microsoft Defender ICES vendor ecosystem, designed to enable seamless integration with trusted third-party vendors and streamline security operations center (SOC) workflows for organizations who have chosen a multi-vendor email security strategy. <br />
<br />
[url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365/performance-benchmarking]Read the latest Microsoft benchmarking data for email security[/url]<br />
<br />
Key insights from a year of email benchmarking<br />
<br />
With four consecutive quarters, several findings have proven to be durable insights, highlighting the sustained realities of how layered email security performs in production:<br />
<br />
[b]1. Defender consistently leads in pre-delivery detection. [/b]Across every benchmarking period since July 2025, Defender has missed fewer high-severity cyberthreats than every SEG vendor evaluated, while the next closest SEG vendor had 2.5 times more misses.<br />
<br />
[b]2. ICES vendors add the most value in promotional and bulk email filtering. [/b]Promotional filtering uplift has been the clearest area of ICES value with an average uplift of 15% over the four quarters of evaluation. Meanwhile ICES vendor uplift for malicious catch and spam has consistently remained relatively nominal, averaging at 0.29% and 0.68%, respectively. In addition, over the last three quarters we’ve seen a consistent downward trend in these numbers, as we have continued to drive innovation in post-delivery mail detection.<br />
<br />
[b]3. Defender’s share of post-delivery remediation has grown significantly. [/b]In our second report, we introduced insights on the contribution of Defender to post-delivery malicious catch. Initially, Defender contributed 45% of post-delivery malicious catch, which has since risen to an average of 96%. This trajectory underscores that Microsoft’s post-delivery catch is an increasingly critical backstop, operating even when ICES solutions are in place, and that Defender is delivering the majority of post-delivery remediation.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture1.webp[/img]Figure 1: Malicious catch and spam catch uplift from ICES vendors of the past 12 months.<br />
<br />
SEG vendor benchmarking results<br />
<br />
For SEG vendors, a threat is classified as “missed” if it was not detected prior to delivery. Using this definition, Microsoft Defender once again missed fewer high-severity email threats than all other solutions evaluated, consistent with every prior benchmarking period.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture2.webp[/img]Figure 2: High-severity email threats missed by SEG vendors (February 2026-April 2026), measured as threats missed per 1,000 users protected.<br />
<br />
This quarter, Defender missed 59% fewer high-severity threats than the next-closest SEG vendor, a gap that has remained consistent across all four benchmarking periods.<br />
<br />
ICES vendor benchmarking results<br />
<br />
ICES solutions operating on top of Microsoft Defender continue to provide benefit, particularly in reducing promotional and bulk email, with an average improvement of 16.85% over the last quarter. This helps minimize inbox clutter and improves user productivity in environments where promotional noise is a concern. For malicious messages and spam, the average improvement across vendors was 0.13% for malicious and 0.28% for spam catch, compared to 0.24% and 0.29% in the prior report.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture3-1.webp[/img]Figure 3: ICES vendor catch contribution (February 2026-April 2026).<br />
<br />
Focusing only on malicious messages that reached the inbox, the latest quarter shows Microsoft Defender’s post-delivery catch continues to improve, catching the majority of post‑delivery remediation. It removes an average of 96.03%, up from 70.8% in the previous quarter, highlighting the effectiveness of our continuous investments in this area. Post‑delivery remediation remains a critical backstop when cyberthreats evade initial filtering.<br />
<br />
[img]https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/06/Picture4-1.webp[/img]Figure 4: Post‑delivery malicious catch by Microsoft Defender (February 2026-April 2026), shown across vendors and overall average.<br />
<br />
Innovation shaped by benchmarking insights<br />
<br />
Benchmarking doesn’t just help customers make better decisions. It shapes what we build. Over the past year we’ve used the insights from our benchmarking reports, as well as insights from the growing ICES vendor ecosystem, to directly shape our innovation and product outcomes. Below are some of the most recent highlights, that we directly attribute to the continued improvements in Microsoft Defender performance.<br />
<br />
[b]Native promotion and bulk mail filtering in Outlook[/b]: A dedicated Promotions folder, natively provisioned in Outlook, now keeps legitimate bulk mail out of the primary inbox. Promotional content is separated from priority emails without being sent to Junk, which means users can still access and browse newsletters and updates at their own pace. The folder appears at the top level of the mailbox for easy discovery and is visible across all Outlook experiences. Once generally available it will be on by default, improving the native promotional filtering. [url=https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/declutter-and-defend-reducing-promotional-mail-noise-with-microsoft-defender/4511732]Learn more[/url].<br />
<br />
[b]System-level AI advancements[/b]: Among other AI enhancements, in November 2025 we introduced an agentic grading system that reduces the reliance on manual review in the submission and analysis pipeline. It helps deliver lower wait times, faster responses, and higher-quality results when emails are submitted to Microsoft for review. That means security teams can investigate reported messages more efficiently, respond more promptly, and act with greater confidence against phishing threats. [url=https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/microsoft-ignite-2025-transforming-phishing-response-with-agentic-innovation/4470791]Learn more[/url].<br />
<br />
[b]Accelerating investigation with AI[/b]: The growing role of post-delivery remediation in our benchmarking data highlights a related challenge: when threats reach users and get reported, SOC teams need to triage those submissions quickly and accurately. The [url=https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot]Microsoft Security Copilot[/url] Alert Triage Agent uses language model-powered reasoning to classify user-reported phishing emails, resolve false positives, and escalate confirmed threats for analyst review. Results show analysts identify 6.5 times more malicious alerts, improve verdict accuracy by 77%, and spend 53% more time investigating real cyberthreats. Security Copilot’s Email Summary further speeds investigations by turning email detection data into clear, actionable insights in the Email entity page. [url=https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/announcing-public-preview-security-copilot%E2%80%99s-email-summary-in-microsoft-defender/4510357]Learn more[/url].<br />
<br />
A year into this effort, our commitment to transparent benchmarking remains unchanged. We’ll continue using these insights to shape product innovation, share real-world performance data with customers, and invest in a strong ecosystem that meets organizations where they are—supporting the layered email security strategies that work best for their environments.<br />
<br />
[url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365/performance-benchmarking]Read the latest Microsoft Defender benchmarking data[/url]<br />
<br />
Learn more<br />
<br />
Learn more about [url=https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365]Microsoft Defender[/url].<br />
<br />
To learn more about Microsoft Security solutions, visit our [url=https://www.microsoft.com/en-us/security/business]website.[/url] Bookmark the [url=https://www.microsoft.com/security/blog/]Security blog[/url] to keep up with our expert coverage on security matters. Also, follow us on LinkedIn ([url=https://www.linkedin.com/showcase/microsoft-security/]Microsoft Security[/url]) and X ([url=https://twitter.com/@MSFTSecurity]@MSFTSecurity[/url]) for the latest news and updates on cybersecurity.<br />
<br />
The post [url=https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/]Microsoft Defender email security benchmarking: Key insights from one year of data[/url] appeared first on [url=https://www.microsoft.com/en-us/security/blog]Microsoft Security Blog[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/]https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/[/url]<br />
[b]Published:[/b] Yesterday, 04:00 PM<br />
[b]Author:[/b] Jeff Pinkston]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[We’re strengthening our presence in Alabama through new investments and...]]></title>
			<link>https://exetools.net/thread-4820.html</link>
			<pubDate>Mon, 15 Jun 2026 15:00:00 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4820.html</guid>
			<description><![CDATA[[b]We’re strengthening our presence in Alabama through new investments and community support.[/b]<br />
<br />
<br />
Google has announced a $1.5 billion investment for 2026 and 2027 to expand its data center campus in Jackson County, Alabama. Operating since 2019 on a repurposed former…<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/alabama-investment-june-2026/]https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/alabama-investment-june-2026/[/url]<br />
[b]Published:[/b] Yesterday, 03:00 PM]]></description>
			<content:encoded><![CDATA[[b]We’re strengthening our presence in Alabama through new investments and community support.[/b]<br />
<br />
<br />
Google has announced a $1.5 billion investment for 2026 and 2027 to expand its data center campus in Jackson County, Alabama. Operating since 2019 on a repurposed former…<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/alabama-investment-june-2026/]https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/alabama-investment-june-2026/[/url]<br />
[b]Published:[/b] Yesterday, 03:00 PM]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[15th June – Threat Intelligence Report]]></title>
			<link>https://exetools.net/thread-4816.html</link>
			<pubDate>Mon, 15 Jun 2026 13:40:44 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4816.html</guid>
			<description><![CDATA[[b]15th June – Threat Intelligence Report[/b]<br />
<br />
<br />
For the latest discoveries in cyber research for the week of 15th June, please download our [url=https://research.checkpoint.com/wp-content/uploads/2026/06/Threat_Intelligence_News_2026-06-15.pdf]Threat Intelligence Bulletin.[/url]<br />
<br />
[b]TOP ATTACKS AND BREACHES[/b]<br />
<br />
The University of Nottingham, a UK research university, has [url=https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/]suffered[/url] a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks [url=https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit]targeting[/url] more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution.<br />
<br />
[i]Check Point IPS provides protection against this threat [/i][i](Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (CVE-2026-35273))[/i]<br />
<br />
Mackay Sugar, Australia’s second-largest sugar producer, has [url=https://therecord.media/cyberattack-shuts-down-major-australian-sugar-producer]been[/url] hit by a cyberattack that disrupted operations and shut down its Farleigh and Racecourse mills in Queensland. The company instructed growers to stop harvesting and suspended cane haulage while temporary measures were deployed to maintain essential operations.<br />
<br />
Danish pharmaceutical giant Novo Nordisk has [url=https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/]disclosed[/url] a breach after attackers accessed internal IT systems and copied pseudonymized clinical trial data from research systems. The exposed information included patient IDs, trial participation details, limited health data, and some healthcare professionals’ contact information.<br />
<br />
[b]AI THREATS[/b]<br />
<br />
Check Point Research has [url=https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/]demonstrated[/url] exploitable flaws in LangGraph, an open-source framework for stateful AI agents. Researchers chained SQL injection and unsafe deserialization issues to achieve remote code execution, with patches issued for SQLite, core, and Redis checkpointer components in affected deployments.<br />
<br />
[i]Check Point IPS provides protection against this threat[/i][i] (LangChain LangGraph SQL Injection (CVE-2026-27022))[/i]<br />
<br />
Researchers [url=https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html]highlighted[/url] a China-based phishing-as-a-service network, Outsider, that allegedly used Gemini to generate fake websites and support SMS phishing campaigns. Google filed a lawsuit after linking the operation to thousands of phishing sites, more than 1.5 million URLs, and large-scale victim targeting.<br />
<br />
Researchers [url=https://cybersecuritynews.com/microsoft-warns-claude-code-github-action/]warned[/url] that prompt-injection attacks against Anthropic’s Claude Code GitHub Action could leak CI/CD workflow secrets. Malicious issue or pull request text can instruct the agent to read environment variables and expose API keys, enabling workflow abuse and impersonation inside software repositories.<br />
<br />
[b]VULNERABILITIES AND PATCHES[/b]<br />
<br />
Check Point Research has [url=https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/]identified[/url] active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. Attacks began in May and increased in early June, affecting a limited number of organizations, with one case tied to Qilin ransomware activity.<br />
<br />
[i]Check Point IPS provides protection against this threat [/i][i](IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751))[/i]<br />
<br />
Microsoft [url=https://therecord.media/microsoft-ships-largest-patch-tuesday-on-record]released[/url] its largest Patch Tuesday update to date, addressing more than 200 Windows and Defender vulnerabilities amid an AI-driven surge in vulnerability discovery. The fixes include CVE-2026-45657, a critical Windows flaw with a CVSS score of 9.8 that could enable network-based propagation, CVE-2026-41091, which has been actively exploited to gain full system control, and CVE-2026-50507, a BitLocker bypass vulnerability.<br />
<br />
Veeam has [url=https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/]released[/url] security updates to fix a critical flaw affecting Backup &amp; Replication. The vulnerability allows an authenticated domain user to execute code remotely on a domain-joined backup server, exposing sensitive backup infrastructure and recovery systems.<br />
<br />
[b]THREAT INTELLIGENCE REPORTS[/b]<br />
<br />
Check Point Research’s May 2026 attack trends report [url=https://blog.checkpoint.com/research/global-cyber-attacks-ease-in-may-2026-but-ransomware-surges-48-as-threats-reorganize/]found[/url] that organizations experienced an average of 2,055 weekly attacks, down 7% month over month, while ransomware incidents increased 48% year over year. The report also highlights continued GenAI exposure across enterprise environments, including risks linked to business-related prompts.<br />
<br />
Researchers [url=https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html]detected[/url] a supply-chain compromise in the Arch User Repository, where attackers seized hundreds of packages and modified build scripts to install credential-stealing malware. The campaign deployed malicious dependencies, a Rust stealer, and, with administrative privileges, an eBPF rootkit on Linux systems.<br />
<br />
Researchers [url=https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/]analyzed[/url] a Brazilian phishing campaign abusing the legitimate NinjaOne remote management agent to gain access to company computers. The campaign uses fake Portuguese business portals and phone-based social engineering to install a signed agent connected to attacker-controlled infrastructure on victim endpoints<br />
<br />
Researchers [url=https://securityaffairs.com/193476/apt/russian-apts-still-exploiting-patched-winrar-flaw-cve-2025-8088.html]described[/url] ongoing exploitation of WinRAR flaw CVE-2025-8088 by Russia-linked groups targeting Ukrainian military and government organizations. Spear-phishing archives plant hidden files that run at login and deploy stealers for browser passwords, cookies, VPN configurations, and other credentials across affected Windows systems.<br />
<br />
The post [url=https://research.checkpoint.com/2026/15th-june-threat-intelligence-report/]15th June – Threat Intelligence Report[/url] appeared first on [url=https://research.checkpoint.com]Check Point Research[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://research.checkpoint.com/2026/15th-june-threat-intelligence-report/]https://research.checkpoint.com/2026/15th-june-threat-intelligence-report/[/url]<br />
[b]Published:[/b] Yesterday, 01:40 PM<br />
[b]Author:[/b] urias]]></description>
			<content:encoded><![CDATA[[b]15th June – Threat Intelligence Report[/b]<br />
<br />
<br />
For the latest discoveries in cyber research for the week of 15th June, please download our [url=https://research.checkpoint.com/wp-content/uploads/2026/06/Threat_Intelligence_News_2026-06-15.pdf]Threat Intelligence Bulletin.[/url]<br />
<br />
[b]TOP ATTACKS AND BREACHES[/b]<br />
<br />
The University of Nottingham, a UK research university, has [url=https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/]suffered[/url] a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks [url=https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit]targeting[/url] more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution.<br />
<br />
[i]Check Point IPS provides protection against this threat [/i][i](Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (CVE-2026-35273))[/i]<br />
<br />
Mackay Sugar, Australia’s second-largest sugar producer, has [url=https://therecord.media/cyberattack-shuts-down-major-australian-sugar-producer]been[/url] hit by a cyberattack that disrupted operations and shut down its Farleigh and Racecourse mills in Queensland. The company instructed growers to stop harvesting and suspended cane haulage while temporary measures were deployed to maintain essential operations.<br />
<br />
Danish pharmaceutical giant Novo Nordisk has [url=https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/]disclosed[/url] a breach after attackers accessed internal IT systems and copied pseudonymized clinical trial data from research systems. The exposed information included patient IDs, trial participation details, limited health data, and some healthcare professionals’ contact information.<br />
<br />
[b]AI THREATS[/b]<br />
<br />
Check Point Research has [url=https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/]demonstrated[/url] exploitable flaws in LangGraph, an open-source framework for stateful AI agents. Researchers chained SQL injection and unsafe deserialization issues to achieve remote code execution, with patches issued for SQLite, core, and Redis checkpointer components in affected deployments.<br />
<br />
[i]Check Point IPS provides protection against this threat[/i][i] (LangChain LangGraph SQL Injection (CVE-2026-27022))[/i]<br />
<br />
Researchers [url=https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html]highlighted[/url] a China-based phishing-as-a-service network, Outsider, that allegedly used Gemini to generate fake websites and support SMS phishing campaigns. Google filed a lawsuit after linking the operation to thousands of phishing sites, more than 1.5 million URLs, and large-scale victim targeting.<br />
<br />
Researchers [url=https://cybersecuritynews.com/microsoft-warns-claude-code-github-action/]warned[/url] that prompt-injection attacks against Anthropic’s Claude Code GitHub Action could leak CI/CD workflow secrets. Malicious issue or pull request text can instruct the agent to read environment variables and expose API keys, enabling workflow abuse and impersonation inside software repositories.<br />
<br />
[b]VULNERABILITIES AND PATCHES[/b]<br />
<br />
Check Point Research has [url=https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/]identified[/url] active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. Attacks began in May and increased in early June, affecting a limited number of organizations, with one case tied to Qilin ransomware activity.<br />
<br />
[i]Check Point IPS provides protection against this threat [/i][i](IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751))[/i]<br />
<br />
Microsoft [url=https://therecord.media/microsoft-ships-largest-patch-tuesday-on-record]released[/url] its largest Patch Tuesday update to date, addressing more than 200 Windows and Defender vulnerabilities amid an AI-driven surge in vulnerability discovery. The fixes include CVE-2026-45657, a critical Windows flaw with a CVSS score of 9.8 that could enable network-based propagation, CVE-2026-41091, which has been actively exploited to gain full system control, and CVE-2026-50507, a BitLocker bypass vulnerability.<br />
<br />
Veeam has [url=https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/]released[/url] security updates to fix a critical flaw affecting Backup &amp; Replication. The vulnerability allows an authenticated domain user to execute code remotely on a domain-joined backup server, exposing sensitive backup infrastructure and recovery systems.<br />
<br />
[b]THREAT INTELLIGENCE REPORTS[/b]<br />
<br />
Check Point Research’s May 2026 attack trends report [url=https://blog.checkpoint.com/research/global-cyber-attacks-ease-in-may-2026-but-ransomware-surges-48-as-threats-reorganize/]found[/url] that organizations experienced an average of 2,055 weekly attacks, down 7% month over month, while ransomware incidents increased 48% year over year. The report also highlights continued GenAI exposure across enterprise environments, including risks linked to business-related prompts.<br />
<br />
Researchers [url=https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html]detected[/url] a supply-chain compromise in the Arch User Repository, where attackers seized hundreds of packages and modified build scripts to install credential-stealing malware. The campaign deployed malicious dependencies, a Rust stealer, and, with administrative privileges, an eBPF rootkit on Linux systems.<br />
<br />
Researchers [url=https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/]analyzed[/url] a Brazilian phishing campaign abusing the legitimate NinjaOne remote management agent to gain access to company computers. The campaign uses fake Portuguese business portals and phone-based social engineering to install a signed agent connected to attacker-controlled infrastructure on victim endpoints<br />
<br />
Researchers [url=https://securityaffairs.com/193476/apt/russian-apts-still-exploiting-patched-winrar-flaw-cve-2025-8088.html]described[/url] ongoing exploitation of WinRAR flaw CVE-2025-8088 by Russia-linked groups targeting Ukrainian military and government organizations. Spear-phishing archives plant hidden files that run at login and deploy stealers for browser passwords, cookies, VPN configurations, and other credentials across affected Windows systems.<br />
<br />
The post [url=https://research.checkpoint.com/2026/15th-june-threat-intelligence-report/]15th June – Threat Intelligence Report[/url] appeared first on [url=https://research.checkpoint.com]Check Point Research[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://research.checkpoint.com/2026/15th-june-threat-intelligence-report/]https://research.checkpoint.com/2026/15th-june-threat-intelligence-report/[/url]<br />
[b]Published:[/b] Yesterday, 01:40 PM<br />
[b]Author:[/b] urias]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[The FCC Wants to Eliminate Burner Phones]]></title>
			<link>https://exetools.net/thread-4822.html</link>
			<pubDate>Mon, 15 Jun 2026 11:01:05 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4822.html</guid>
			<description><![CDATA[[b]The FCC Wants to Eliminate Burner Phones[/b]<br />
<br />
<br />
A proposed FCC rule would [url=https://www.404media.co/fcc-wants-to-kill-burner-phones-by-forcing-telecoms-to-get-all-customers-ids/]kill[/url] burner phones: phones whose accounts are not attached to a particular person.<br />
<br />
The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information about essentially all phone customers, including a government issued identification number and their physical address, alarming privacy advocates and civil rights activists who compare the measures to those from authoritarian countries where it can be difficult to buy a mobile phone plan without giving up your identity.<br />
<br />
The proposed change would drastically shake up how people obtain phone plans in the U.S., and have all sorts of privacy and cybersecurity knock-on effects. The FCC is proposing the data collection partly as a way to combat scammers, with telecoms being required to collect other information on business and foreign customers like the intended use case of their bulk phone plan purchase and their IP address. But the changes would mean telecoms collect data on all new and renewing customers, and the FCC provides a long list of other things that the collected data could help authorities with.<br />
<br />
[url=https://archive.ph/ZwXMG]Alternate link[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.schneier.com/blog/archives/2026/06/the-fcc-wants-to-eliminate-burner-phones.html]https://www.schneier.com/blog/archives/2026/06/the-fcc-wants-to-eliminate-burner-phones.html[/url]<br />
[b]Published:[/b] Yesterday, 11:01 AM<br />
[b]Author:[/b] Bruce Schneier]]></description>
			<content:encoded><![CDATA[[b]The FCC Wants to Eliminate Burner Phones[/b]<br />
<br />
<br />
A proposed FCC rule would [url=https://www.404media.co/fcc-wants-to-kill-burner-phones-by-forcing-telecoms-to-get-all-customers-ids/]kill[/url] burner phones: phones whose accounts are not attached to a particular person.<br />
<br />
The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information about essentially all phone customers, including a government issued identification number and their physical address, alarming privacy advocates and civil rights activists who compare the measures to those from authoritarian countries where it can be difficult to buy a mobile phone plan without giving up your identity.<br />
<br />
The proposed change would drastically shake up how people obtain phone plans in the U.S., and have all sorts of privacy and cybersecurity knock-on effects. The FCC is proposing the data collection partly as a way to combat scammers, with telecoms being required to collect other information on business and foreign customers like the intended use case of their bulk phone plan purchase and their IP address. But the changes would mean telecoms collect data on all new and renewing customers, and the FCC provides a long list of other things that the collected data could help authorities with.<br />
<br />
[url=https://archive.ph/ZwXMG]Alternate link[/url].<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://www.schneier.com/blog/archives/2026/06/the-fcc-wants-to-eliminate-burner-phones.html]https://www.schneier.com/blog/archives/2026/06/the-fcc-wants-to-eliminate-burner-phones.html[/url]<br />
[b]Published:[/b] Yesterday, 11:01 AM<br />
[b]Author:[/b] Bruce Schneier]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Introducing the OpenAI Partner Network]]></title>
			<link>https://exetools.net/thread-4817.html</link>
			<pubDate>Sun, 14 Jun 2026 17:00:00 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exetools.net/member.php?action=profile&uid=1">IREG</a>]]></dc:creator>
			<guid isPermaLink="false">https://exetools.net/thread-4817.html</guid>
			<description><![CDATA[[b]Introducing the OpenAI Partner Network[/b]<br />
<br />
<br />
OpenAI launches the Partner Network, investing $150M to help global partners accelerate enterprise AI adoption, deployment, and transformation.<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://openai.com/index/introducing-openai-partner-network]https://openai.com/index/introducing-openai-partner-network[/url]<br />
[b]Published:[/b] 14-06-26, 05:00 PM]]></description>
			<content:encoded><![CDATA[[b]Introducing the OpenAI Partner Network[/b]<br />
<br />
<br />
OpenAI launches the Partner Network, investing $150M to help global partners accelerate enterprise AI adoption, deployment, and transformation.<br />
<br />
[hr]<br />
[b]Source:[/b] [url=https://openai.com/index/introducing-openai-partner-network]https://openai.com/index/introducing-openai-partner-network[/url]<br />
[b]Published:[/b] 14-06-26, 05:00 PM]]></content:encoded>
		</item>
	</channel>
</rss>