
Mustang Panda CoolClient Kernel Rootkit: Detect & Defend
Mustang Panda CoolClient kernel rootkit hides government backdoors in 4 countries. Hunt these file hashes before your tools fail silently.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
14 results for “Nation-State”

Mustang Panda CoolClient kernel rootkit hides government backdoors in 4 countries. Hunt these file hashes before your tools fail silently.

Red Menshen BPFDoor implants are active inside telecom networks in 10 countries. Here's how the sleeper cells work and what to hunt for now.

FSB Center 16 steals router configs from energy, finance, and government networks globally using default SNMP strings and CVE-2018-0171.

CISA patch deadlines for 4 actively exploited products expire June 1-4. PAN-OS CVE-2026-0257 deadline is today. Here is what to fix first this week.

CVE-2026-32202 Windows Shell spoofing lets APT28 steal NTLMv2 hashes via zero-click LNK files, patch now or block outbound SMB.

CyberAv3ngers: Iran's IRGC-linked APT inside US water, energy and government PLCs, CVE-2021-22681 CVSS 9.8 has no patch and they are escalating.

Socket Security has documented 1,700+ malicious packages tied to North Korea's Contagious Interview campaign across five package ecosystems. Separately, UNC1069 compromised the Axios npm maintainer via social engineering, injecting a backdoor into a library present in an estimated 80% of cloud environments. Here's the full attack chain, WAVESHAPER.V2 IOCs, and what to do now.

CVE-2024-20353 and CVE-2024-20359 are two Cisco ASA and FTD zero-day vulnerabilities exploited in the ArcaneDoor espionage campaign by a suspected Chinese state-sponsored actor. The flaws enabled persistent backdoor implants (Line Dancer and Line Runner) on perimeter VPN devices protecting government and critical infrastructure networks across multiple countries. First exploitation observed in November 2023, five months before public disclosure.

CVE-2023-22515 is a maximum-severity broken access control vulnerability in Atlassian Confluence Data Center and Server. An unauthenticated external attacker can reach Confluence's setup endpoint on a fully configured instance and create a new administrator account, gaining complete control without credentials. Microsoft attributed active exploitation to Storm-0062 (a Chinese state-sponsored threat actor) beginning September 14, 2023, three weeks before Atlassian's advisory.

CVE-2023-36884 is a remote code execution vulnerability in Windows Search and Microsoft Office exploited as a zero-day by Russian-nexus group Storm-0978 (RomCom) during the July 2023 NATO summit. Malicious Office documents triggered the flaw without macros or Protected View bypass, targeting NATO member governments. Microsoft disclosed it without a same-day patch, the fix arrived a month later.
CVE-2022-47966 is a CVSS 9.8 unauthenticated RCE vulnerability affecting up to 24 Zoho ManageEngine products. It exploits a vulnerable Apache Santuario (XML Security for Java) component in the SAML SSO implementation, allowing an attacker to execute arbitrary code on any ManageEngine server where SAML-based single sign-on is or was enabled. Exploited by APT41 and other nation-state actors within weeks of the January 2023 disclosure. Affects products widely deployed in enterprise IT management: ServiceDesk Plus, Desktop Central, OpManager, and more.

CVE-2021-26084 is a server-side template injection vulnerability in Atlassian Confluence Server and Data Center. An unauthenticated attacker can inject OGNL expressions via query parameters, achieving remote code execution on the Confluence server. The vulnerability was exploited at mass scale within hours of public PoC release, with ransomware groups and nation-state actors among the first adopters.

CVE-2020-14882 is a critical authentication bypass in the Oracle WebLogic Server web-based administration console. Chained with CVE-2020-14883, it enables unauthenticated remote code execution on one of the most widely deployed Java EE application servers in enterprise environments. Exploitation began within days of Oracle's October 2020 Critical Patch Update and was adopted by nation-state actors and ransomware operators.

CVE-2019-19781 is a pre-authentication path traversal vulnerability in Citrix ADC (NetScaler ADC) and Citrix Gateway that allows unauthenticated attackers to execute arbitrary OS commands. Exploited at mass scale before patches were released, it was used by nation-state APT groups and ransomware operators to compromise enterprise and government VPN gateways worldwide.