campaign

Winsage
August 17, 2026
A suspected advanced persistent threat (APT) group linked to China exploited a newly patched vulnerability in VMware vCenter (CVE-2026-59310), which has a critical CVSS score of 9.8, allowing for arbitrary code execution and the deployment of Babuk-derived ransomware. A recently patched vulnerability in Apple macOS (CVE-2026-65400) has been exploited to deploy a cryptocurrency miner, granting unauthorized root access. The Lazarus Group from North Korea exploited a zero-day vulnerability in Microsoft Windows, targeting defense and aerospace sectors. GeoServer patched a critical SQL injection vulnerability that was actively exploited. A new macOS malware, Amnesia Stealer, targets users through ClickFix attacks, stealing data and allowing real-time access to authenticated sessions. A novel attack technique named GhostSplice can manipulate AI coding assistants. Research revealed a method exploiting Chromium's DevTools Protocol for data theft. Noteworthy CVEs this week include CVE-2026-68820, CVE-2026-58231, and multiple others across various platforms. A high-severity command injection flaw in FileRun allows remote code execution. An advanced ClickFix attack has been reported, deploying sophisticated malware. A heap overflow vulnerability in Citrix NetScaler was patched after indications of exploitation. A new malware loader targeting Portuguese-speaking users has been identified. A significant reduction in exposed Automatic Tank Gauge systems has been observed. A phishing campaign targeting Brazil has been detected, and an F.B.I. agent faces charges for unauthorized crypto withdrawals. Authorities in Ukraine dismantled fraudulent call centers, and a North Carolina man was sentenced for cyber extortion. Unauthorized access to sensitive data by the ExfilSquad group has been confirmed. LightSpy activity linked to China has been detected in over 13 countries. A supply chain attack exposed over 2,500 companies, and an Azure exfiltration campaign has exposed millions of enterprise records.
AppWizard
August 17, 2026
In 2021, interest in the first-person shooter "Quake" from the '90s surged, leading to discussions about similar games. "Doom II," released in 1994, featured larger levels, new enemies, and enhanced multiplayer options, becoming one of the best PC games of the '90s. "Heretic," also from 1994, allowed players to control Corvus, an elven warrior, and included multiplayer combat, with innovations like an inventory system and secondary fire options. "Duke Nukem 3D," released in 1996, introduced a humorous protagonist and featured cooperative and competitive multiplayer modes, becoming a nostalgic classic. "Turok 2: Seeds of Evil," the 1998 sequel to "Turok: Dinosaur Hunter," included multiplayer modes and showcased advanced graphics and level design, remastered in 2017. "Unreal Tournament," launched in 1999, emphasized multiplayer combat in an arena shooter format, marking a significant moment for Epic Games and showcasing impressive visuals and performance.
AppWizard
August 17, 2026
The Quake community is celebrating the game's 30th birthday with various map jams, including two 'Quickie' speedmapping jams, a 1024 Jam, and a Limits Jam. The Q30 Deathmatch Jam has produced a map-pack with 22 new arenas designed for classic Quake gameplay, featuring contributions from notable designers like Mazu and Makkon. The new maps are compatible with modern Quake sourceports such as Ironwail, Netquake, and Nightdive's Kex port. Additionally, a new episode titled Dawn of the Machine has been released in collaboration with Machine Games, following their previous release, Dimension of the Machine, from 2021.
AppWizard
August 16, 2026
The upcoming Lords of the End Times expansion for Total War: Warhammer was announced, featuring characters like Nagash, Boris Todbringer, the Glottkin, and Grey Seer Thanquol. The expansion will launch on September 24, and players will not need previous Total War: Warhammer titles to access the Immortal Empires campaign. The Immortal Empires content includes 14 factions, 24 legendary lords, numerous Free-LC lords and heroes, and entire free factions like Bretonnia. Total War: Warhammer 3 is available for purchase during a 10th anniversary sale, but investing in the new lords may be more advantageous. The Great Vortex campaign from Total War: Warhammer 2 is integrated into Immortal Empires, making revisiting individual games less appealing for dedicated players.
AppWizard
August 16, 2026
The upcoming Lords of the End Times expansion for Total War: Warhammer 3 will be released on September 24 and will feature characters such as Nagash, Boris Todbringer, the Glottkin, and Grey Seer Thanquol. The Immortal Empires campaign will be accessible without needing previous Total War: Warhammer titles, and it includes 14 distinct factions, 24 legendary lords, various Free-LC lords and heroes, and free factions like Bretonnia. Total War: Warhammer 3 is currently available at a discounted price due to a 10th anniversary sale. The expansion aims to enhance the experience for both new and returning players.
AppWizard
August 16, 2026
Subscribers who opted out of Dune: Awakening due to its multiplayer requirement can access a single-player mode starting September 22, 2026, coinciding with the Xbox console launch. This mode allows players to explore the narrative at their own pace, with adjustable difficulty settings and no multiplayer interaction required. Both Game Pass Ultimate and PC Game Pass subscribers will have access to this feature from day one. Additionally, the confirmed Game Pass lineup for September includes: - Moonlighter 2: The Endless Vault on September 2 for Xbox Series X|S, PS5, Switch 2, and PC. - SpeedRunners 2: King of Speed on September 3 for Xbox Series X|S, PS5, Switch, PC, and Cloud. - Dune: Awakening on September 22 for Xbox Series X|S, PC, and Cloud. - Minecraft Dungeons II on September 29 for Xbox Series X|S, PC, and Cloud. Minecraft Dungeons II will also launch on September 29 across multiple platforms, with Game Pass Ultimate and PC Game Pass subscribers receiving day-one access.
AppWizard
August 15, 2026
Immersive simulations like Dishonored and Deus Ex have traditionally focused on solitary experiences, but some games have introduced multiplayer elements. System Shock 2 included a cooperative mode that was revitalized in its recent remaster, and Deathloop featured an invasion mechanic. In a new development, a mod called Prey Coop allows up to 16 players to explore the Talos 1 space station in Arkane's Prey. This mod, created by null234, synchronizes various gameplay elements among players. To use the mod, players must install it and Chairloader, forward the necessary ports, and ensure they have legitimate copies of the game and the same DLL build of the mod. Installation instructions are available for interested players.
AppWizard
August 15, 2026
The Modern Warfare 4 beta is scheduled to start on August 21 for pre-order customers and will include a campaign mission preview titled "Entrenched," set during North Korea's invasion of South Korea. The beta will feature traditional multiplayer modes and gameplay refinements, including adjustments to muzzle flash, hipfire accuracy, and player movement. The developers aim to enhance the immersive experience while catering to competitive players.
Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
Search