Not Every Fox is Silver: Inside an AtlasRAT loader chain

Not Every Fox is Silver: Inside an AtlasRAT loader chain

Summary AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into

July 28, 2026

July 28, 2026 Hash 1df973a446369ff6e8bf1fff254b1976c 2782ee3516d6b7e59be4ff75661a541f0 326bdff6fa3c359d65820474f780e4b3b URL 1http[:]//192[.]3[.]136[.]217/zFgsXkEzsWQLZkIw240[.]bin 2https[:]//hotm[.]io/CgnNkk 3http[:]//qi1i[.]94xo[.]cc/ IP 191[.]92[.]47[.]53 280[.]94[.]92[.]55 3103[.]125[.]103[.]201...

Fortinet Product Security Update Advisory (CVE-2025-68686)

Fortinet Product Security Update Advisory (CVE-2025-68686)

Overview Fortinet has released a security update addressing CVE-2025-68686, a vulnerability in FortiOS. Vulnerability Details This vulnerability is described as a symbolic link-based persistence block patch bypass vulnerability. A symbolic link is a method of linking a file or Path to another location, and a persistence block patch can be

Arista Networks Product Security Update Advisory (CVE-2026-16812)

Arista Networks Product Security Update Advisory (CVE-2026-16812)

An OS command injection vulnerability (CVE-2026-16812) has been identified in VeloCloud Orchestrator (VCO), a product of Arista Networks. Affected Versions include VeloCloud Orchestrator (VCO) versions prior to 5.2.3.14, Prior to 6.1.3.4, Prior to 6.4.2.4, And prior to 7.0.0.1. Arista Networks has released a security update to address this vulnerability. The

Ubuntu Security Update Advisory (CVE-2026-8933)

Ubuntu Security Update Advisory (CVE-2026-8933)

A security update has been released to address a vulnerability in Ubuntu products. The vulnerability addressed is a local privilege escalation vulnerability (CVE-2026-8933) in snap-confine of Ubuntu’s snapd. The affected systems are as follows: Ubuntu 22.04 LTS: snapd package versions 2.76+Ubuntu22.04.1 And earlier. Ubuntu 24.04 LTS: snapd package versions 2.76+Ubuntu24.04.1

Security Update Advisory for NVIDIA (Networking Bluefield ConnectX) Products—July 2026

Security Update Advisory for NVIDIA (Networking Bluefield ConnectX) Products—July 2026

Overview NVIDIA has released a security update to address vulnerabilities in its products. Users of these products should update to the latest version. Affected Products DCGM Exporter 0.0 Through 4.5.2. DCGM Exporter 0.0 Through 4.8.2. Networking Bluefield ConnectX versions earlier than 1.7.21. Networking Bluefield ConnectX versions prior to 24.10.50. Networking