Featured · 11 min read
Deep technical analysis of the Salt Typhoon APT campaign that breached nine US telecom carriers and accessed CALEA wiretap systems. Covers GhostSpider malware architecture, DEMODEX rootkit, Cisco IOS…
Read Full Post →
APT Analysis
A complete threat hunting guide for detecting Volt Typhoon living-off-the-land techniques. Includes verified KQL queries for Microsoft Sentinel,…
CVE-2026-5158
Blue Team
LegacyHive is an unpatched Windows 0-day (July 2026) targeting the User Profile Service. Full technical analysis of the…
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…