Vendor
high
threat
HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit
1 rule 3 TTPsThe HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.
Endpoint Secure
HoneyMyte
backdoor
rootkit
apt
windows
espionage
1r
3t
high
advisory
Remote Command Injection in Sangfor Operation and Maintenance Security Management System
1 rule 2 TTPs 1 CVEAn unauthenticated remote OS command injection vulnerability in the Sangfor Operation and Maintenance Security Management System allows attackers to execute arbitrary system commands via the /fort/portal_login endpoint.
Operation and Maintenance Security Management System
cve-2026-18641
remote-code-execution
command-injection
sangfor
1r
2t
1c