§ Tag
Tag

Control

AU

Bring Your Own Installer: When the EDR Bypass Ships Inside the EDR

Attackers don’t need a vulnerable driver to blind an EDR — they need the agent’s own installer and a window. The durable detection isn’t the kill command, it’s the silence that follows. Here is what that detection looks like the first time you deploy it, and why it floods the SOC before it works.

·
CM

Win+X Opens Windows Terminal Without Writing to RunMRU

RunMRU is the tidiest endpoint signal for ClickFix, which is exactly why it’s the first thing attackers stopped touching. A look at what the registry detection catches, why it’s already half-blind, and the process-ancestry signal that actually survives.

·
RA

Thirty-One Days of IPv4 Tenure Inside an ORB Network

China-nexus operational relay box networks rotate their egress IPs monthly and pick exit nodes inside the victim’s own region. Blocklists and impossible-travel rules don’t fire. Here’s where the detection actually lives, and what the first round of tuning has to fix.

·
Artificial Intelligence

The Sandbox Config Becomes the Whole Control Surface

Z.ai’s GLM-5.2 is a cheap, MIT-licensed, long-horizon coding agent anyone can self-host with no provider-side refusal, logging, or kill switch. Paired with fresh AISI research on autonomous container-sandbox escape, the lesson is blunt: the model was never your control point. Your runtime hardening is.

·
AC

Ubuntu’s userns Mediation Is a Tripwire, Not a Wall

Ubuntu 24.04 enabled AppArmor mediation of unprivileged user namespaces by default, then Qualys published three ways around it. Here’s what the control actually stops, the audit chain that proves it fired, and how to detect abuse without flooding the SOC.

·