§ Category
Category

AU

AC

UNC6508 Exfiltrated Through a Gmail Compliance Rule. The Audit Event Your Detection Uses Retires After August

A PRC-nexus actor exfiltrated years of medical and defense research by creating a single domain-level Gmail content compliance rule that silently BCC’d matching mail to an attacker Gmail account. It produced no endpoint telemetry and no user-visible forwarding setting, and the admin audit event family that authoritatively records it is mid-migration, with the legacy events retiring after August 2026.

·
AU

ESXi Can Write Its Logs to a RAM Disk. Ransomware Counts on It

On an ESXi host without persistent scratch, /var/run/log lives on an in-memory ramdisk and evaporates at the next boot. Ransomware crews get the same effect for free — they power off, kill, or reboot the workloads before encrypting — which means your entire forensic timeline had to be forwarded off-box before the incident or it never existed at all.

·
AU

Bring Your Own Installer: When the EDR Bypass Ships Inside the EDR

Attackers don’t need a vulnerable driver to blind an EDR — they need the agent’s own installer and a window. The durable detection isn’t the kill command, it’s the silence that follows. Here is what that detection looks like the first time you deploy it, and why it floods the SOC before it works.

·