top of page
Work Overview
LATEST PROJECTS
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque

Blog
Search


PasteSwitch ClickFix: Hunt the Paste That Turns a Brand Ad Into a Stealer
A trusted-looking brand ad can lead to a dangerous paste. Learn how PasteSwitch ClickFix works, what to hunt across four security platforms, and how to contain endpoint and identity exposure.
7 min read


Is AI Putting Your Business at Risk? 10 Things SMBs Need to Do Now
A helpful AI tool can become a data exposure risk when access and rules are unclear. Follow these 10 AI security steps for small businesses, plus a practical 30-day plan for protecting data and managing compliance.
8 min read


Sogou CVE-2026-51990: How to Hunt for GRAYRABBIT
ACTION BRIEF • WINDOWS ENDPOINTS If your organization uses Sogou Input Method for Windows, verify its version and investigate suspicious activity from before it was patched. A malicious link can exploit a vulnerable installation to deliver GRAYRABBIT, a backdoor that gives an attacker access in the signed-in user’s context. Your first three actions: identify affected devices, update the software, and check whether attackers used it before the update. Patching closes the repor
7 min read


JFrog Artifactory: How Tokens Become Admin and How to Hunt the Abuse
A software repository sits between the people who build software and the systems that run it. When that repository is compromised, the investigation needs to answer more than whether someone accessed a server. It needs to establish whether the company can still trust the identities, credentials, and artifacts passing through it. Recent Artifactory exploitation illustrates why. Two vulnerabilities allow an attacker to obtain a token and escalate its authority. A separate vulne
8 min read


Hunt the commits POST that reads the GitLab box
Hunt GitLab CVE-2026-85706: unauth commits API path traversal. POST /repository/commits with file.path. watchTowr ITW Sep 11. CISA KEV due Sep 14.
7 min read


Hunt the Chrome-to-curl BlueMoon chain
The process tree still sitting on the box is not a closed Chrome patch ticket. It is chrome.exe (or msedge.exe / brave.exe) spawning cmd.exe, which spawns curl.exe, which writes %TEMP%\msgbox.exe or %TEMP%\ChromeUpdate.exe and runs it. Proofpoint tracks that default BlueMoon breakout, and the follow-on loaders are what operators actually keep. A hot stable build does not rewrite a curl stub that already ran from the broker. This hunt shop is not a second CVSS recap, and it is
8 min read


Hunt the FMC shell that opens AD for Qilin
The traces still on the management plane are not a closed patch ticket. They are a Tomcat JSP named home.jsp that Base64-decodes F6C1F0E7, a package_info.pl line that runs /var/tmp/license.tmp --lsm as root, and a Python socks5.py reverse-SSH tunnel that forwards LDAP, Kerberos, SMB, and WinRM out of Secure Firewall Management Center into Active Directory. Cisco Secure Firewall Management Center centrally manages your Secure Firewall estate. CVE-2026-20079 is a critical authe
4 min read


Hunt the Magento payment email that runs PHP for you
The leftover is not a failed checkout ticket. It is a process that looks like time sync, a cron line that restarts twice an hour, and a Payment Transaction Failed Reminder that already ran PHP while Magento rendered it. Nobody needed to open the message. Delivery can fail, and the planted code still executes. That is StyleSmuggler after the styles poison, not another Magento zero-day recap. Here is the plain version before the product jargon. An unauthenticated attacker poiso
4 min read


Hunt the ScreenConnect Guest that runs your scripts: 1.vbs through 4.vbs
The alert is wscript.exe, four short script names, and a Run key that looks like a Windows service helper. ScreenConnect is already on the box. Someone says helpdesk has a session. There is no ransomware family on the page, and the brand name on the client is the same one your techs use every day. That is when this chain wants you to call it a rogue RMM install and move on. Here is the plain version before the product jargon. A modified ScreenConnect client on one host watche
7 min read


Hunt the MP4 that never plays: NetSupport in an ISO-BMFF uuid box
You know the ticket. Someone downloaded a video. The ticket says media. The player refuses to open it. Antivirus already shrugged and called it an MP4. There is no ransomware family name on the alert, and the user swears they never watched anything. That unfair case is when this chain wants you to close it and move on. Here is the plain version before the box jargon. The file is a fake video shell. It is stuffed with a script. It is not a clip you failed to open. It is a carr
7 min read


Spring Ring: hunt the Teams helpdesk that never hits email
Unit 42 published Spring Ring today, 31 August 2026. The activity in the report is from January through April. This is leftover tradecraft, not a weekend outbreak. If you are hunting it because the write-up is new, you are hunting a gap that has been sitting in Teams since winter. The gap is Chat with anyone plus a voice call that never hits the mail gateway. They are not phish-mailing IT. A throwaway .onmicrosoft.com tenant named like a helpdesk opens a Teams chat. Then a 10
5 min read


PaperCut CVE-2026-81578: hunt the emergency patch that did not stay a patch
You have seen this ticket. Print is still working. Someone applied the first emergency PaperCut patch when it dropped, the queue came back, and they closed it. The Application Server web UI is still on the internet because print admins do not like taking that box down twice in one week. That is the hunt. Not the CVE number. The hunt is the emergency patch that did not stay a patch. CISA put CVE-2026-81578 and CVE-2026-82078 on KEV on 31 August 2026. If you only ran Patch 1, y
5 min read


NetScaler CVE-2026-8452 KEV: hunt the nsppe crash that did not stay a crash
Citrix NetScaler Gateway after a quiet nsppe crash. Hunt PHP under /var/vpn/theme. You have seen this ticket. VPN died, VPN came back, someone closed it as a blip. Citrix sold CVE-2026-8452 as a crash. CISA put it on KEV Monday. The federal clock is Saturday, 29 August. Builds with a fix: 13.1-63.21 or later, 14.1-73.32 or later. 12.1 and 13.0 have no fix. Patch is not the hunt. A patched box that already had a quiet respawn still needs the directory check. The hunt is not th
4 min read


SynkLoader: the lock screen plus the tunnel
PhishLocker is a fake Windows lock screen. The password plus the tunnel is the prize. On 18 August, Expel caught SynkLoader off a scheduled-task EDR hit that started in Microsoft Teams and ended in a fake lock screen. The EDR alert was the first clean look at a loader nobody had published yet. File times and compile stamps ran back to about 28 July. They named it SynkLoader. No crew name came with it. How SynkLoader arrives in Microsoft Teams The user had already been talked
3 min read


Major Entra ID Actor Tokens Vulnerability: How Actor Tokens Could Hand Over Global Admin Access to Anyone
Look, in the world of cloud security, things move fast, and sometimes the cracks in big systems like Microsoft's Entra ID show up in ways...
3 min read


CVE-2025-53786: The Hidden Privilege Escalation Threat in Microsoft Exchange Hybrid Deployments What SMBs Need to Know
In the ever-evolving world of cybersecurity, new vulnerabilities emerge that can turn a seemingly secure setup into a hacker's...
4 min read


Secure Employee Access in the Age of AI Without Hiring a Big Security Team — Backed by Microsoft’s 2025 Report
The Access Problem Every SMB is Facing Identity and access management is no longer just an enterprise challenge. With hybrid work, cloud...
3 min read


7 Azure Security Gaps Most Companies Overlook (And How to Fix Them)
Misconfigurations in Microsoft 365 and Azure remain one of the biggest cybersecurity risks. Inception Security explains how to close...
6 min read


Understanding the Latest Clickjacking Vulnerability in Password Managers: A Technical Deep Dive
Image of the Kill Chain In the ever-evolving landscape of cybersecurity threats, a new zero-day vulnerability has emerged that targets...
5 min read


How Hackers Bypass MFA in Microsoft 365 — and How to Detect and Stop Them
Learn how hackers use Microsoft 365 MFA bypass to gain access, add persistence, and exfiltrate data. Detect attacks with KQL queries and stop them fast.
5 min read
bottom of page
