Skip to main content

Threats Tagged 't1609'

View all threats tagged with 't1609'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1609

Threats Tagged 't1609'

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-46316 is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM on ARM64 platforms. It is caused by a race condition in the vgic_its_invalidate_cache() function leading to a double-put use-after-free, which allows execution of code in the host kernel context. This flaw resides in the in-kernel KVM module, enabling successful exploitation to gain host kernel privileges. The vulnerability affects multi-tenant ARM64 cloud environments and can be chained with local privilege escalation when guest root access is unavailable. A patch fixing this vulnerability was applied in the Linux kernel at commit 13031fb6b835. Two YARA rules have been developed to detect exploitation attempts based on specific constants and behavioral patterns. There are no known exploits in the wild as of the latest information.

Join the discussion

A sophisticated phishing campaign targets Colombian users by impersonating the Attorney General's Office with judicial notification lures. The attack uses a multi-stage infection chain starting with a malicious . SVG file attachment that triggers HTA, VBS, and PowerShell scripts, ultimately injecting the AsyncRAT malware into MSBuild.exe. AsyncRAT establishes command and control (C2) communications, steals data, and can dynamically load plugins. The campaign employs anti-virtual machine (VM) techniques, persistence mechanisms, and heavy obfuscation to evade detection. Although primarily focused on Colombia, the advanced tactics and malware capabilities pose risks to any organization exposed to similar phishing vectors. The threat demonstrates extensive use of MITRE ATT&CK techniques, including execution, persistence, defense evasion, credential access, and command and control. No known exploits or CVEs are associated, and the severity is assessed as medium based on current information.

Join the discussion

This investigation delves into information operations conducted by Russian actors known as Doppelgänger, focusing on their activities from early June to late-July 2024. It examines their tactics, associated infrastructure, and motivations, particularly in relation to the unexpected snap general election in France during this period. The analysis reveals a persistent and complex effort to disseminate disinformation through social media, impersonating legitimate news websites and employing intricate redirection chains. The operations primarily target conservative and nationalist sentiments, aiming to destabilize Western democracies by exploiting existing societal and political divisions.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: t1609
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses