Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:trend_micro
tags: report:trend_micro
tags: report:trend_micro
tags: report:trend_micro
tags: report:trend_micro
tags: report:trend_micro
tags: report:trend_micro
tags: report:trend_micro
Title/body text match only.
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Webworm: New burrowing techniques ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal Webworm: New burrowing techniques Award-winning news, views, and insight from the ESET security community English Español Deutsch Portug
FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness FishMonger’s arsenal upgraded: SprySOCKS for Windows Award-winning news, views, and insight f
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achie
AutoJack: How a single page can RCE the host running your AI agent AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authenticatio
When prompts become shells: RCE vulnerabilities in AI agent frameworks New research exposes how prompt injection in AI agent frameworks can lead to remote code execution. Learn how these vulnerabilities work, what’s impacted, and how to secure your agents. The post When prompts
Deduped connector weight from graph context.