Product
Local Privilege Escalation Vulnerability in Windows 11 Secure Kernel Mode
1 TTPA vulnerability in the Secure Kernel Mode of Microsoft Windows 11 allows a local attacker to perform privilege escalation on the affected system.
Active Exploitation of Google Chromium V8 Type Confusion Vulnerability
1 TTP 2 CVEsA type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.
Public Proof-of-Concept for CVE-2023-21768 Local Privilege Escalation
1 TTP 1 CVEPublic availability of multiple proof-of-concept exploits for CVE-2023-21768, a local privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD), increases the risk of local users elevating processes to SYSTEM privileges.
Secret Blizzard Upgrades Kazuar Backdoor to Modular P2P Botnet
2 rules 4 TTPsThe Russian hacker group Secret Blizzard has evolved the Kazuar backdoor into a modular P2P botnet designed for persistence, stealth, and data collection, utilizing kernel, bridge, and worker modules for command and control and data exfiltration.
CloudZ RAT Abuses Microsoft Phone Link to Steal SMS and OTPs
2 rules 1 TTPA new version of the CloudZ RAT utilizes the Pheno plugin to hijack Microsoft Phone Link connections, enabling the theft of SMS messages and one-time passwords (OTPs) from victims' mobile devices.
CloudZ RAT Abusing Windows Phone Link to Steal OTPs
2 rules 6 TTPsAn unknown attacker is using the CloudZ RAT and its Pheno plugin to hijack the Microsoft Phone Link application and intercept SMS and OTP messages from connected mobile devices, active since at least January 2026.
Windows HTTP.sys Local Privilege Escalation Vulnerability (CVE-2026-21250)
2 rules 1 TTP 1 CVEA local privilege escalation vulnerability exists in Windows 11 24H2, Windows 11 25H2, and Windows Server 2022 23H2 due to improper handling of untrusted pointers in HTTP.sys via strcat truncation.