top of page


Nice Extension You’ve Got There… Shame If It Updated
A long-running malicious browser-extension ecosystem (“ShadyPanda”) that used trusted marketplace distribution and silent updates to enable large-scale surveillance (URLs, searches, clicks, fingerprints) and, in some cases, hourly remote code execution via downloaded JavaScript, affecting millions of Chrome and Edge users.
Dec 15, 202517 min read


FAIR INTEL Weekly RASE Report 12-15-2025
Resilience, Attack Surface, and Exposure (RASE)
Dec 15, 202514 min read


Repo Roulette: Spin the Wheel, Win a Credential
A security researcher used automated TruffleHog scans across all 5.6 million public GitLab Cloud repositories and found 17,430 live secrets tied to 2,804 domains—including cloud, database, messaging, and OpenAI keys—showing that many organizations still expose long-lived credentials in public code despite some revocations after notification.
Dec 10, 202514 min read


BRICKSTORM: Because Your Hypervisor Needed a Midlife Crisis
PRC state-sponsored cyber actors are deploying the BRICKSTORM backdoor to maintain long-term, stealthy access to VMware vSphere and related Windows infrastructure in government and IT organizations, enabling persistent control, lateral movement, and data exfiltration.
Dec 9, 202518 min read


When Your Endpoint Says “New Remote Tool Installed” and You Didn’t Hire Anyone
Iran-aligned MuddyWater is running a focused cyberespionage campaign against Israeli and Egyptian organizations, deploying new custom tools such as the Fooder loader, MuddyViper backdoor, credential stealers, and reverse tunnels to improve stealth, persistence, and credential theft against government and critical infrastructure networks.
Dec 9, 202522 min read


Weekly RASE Report
Resilience, Attack Surface, and Exposure (RASE)
Dec 8, 20255 min read


Ferrets
Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malware
Nov 26, 202515 min read
bottom of page