CyberOSINT Blog

Deep analysis, threat research, and technical deep dives from our intelligence team
Deep AnalysisSeptember 19, 2026·12 min read
NightEagle (APT-Q-95): GhostContainer, Microsoft Dev Tunnels, and the Expansion to Russia
How a Chinese-linked APT group uses compromised VPN credentials, Cloudflare WARP, and Microsoft dev tunnels to breach Russian enterprises — GhostContainer backdoor on Exchange, VIEWSTATE injection, and AMSI/ETW bypass in a full technical deep-dive.
APTGhostContainerExchangeMicrosoft Dev TunnelsChina
Deep AnalysisSeptember 12, 2026·15 min read
AI Agents as Cyber Weapons: How OpenAI, Claude, and Cursor Are Being Weaponized in Real-World Attacks
Three independent campaigns in one week prove AI agents are autonomously executing supply chain compromises, rebuilding state-sponsored malware, and generating 1M+ phishing emails — a detailed analysis of the AI weaponization era.
AI SecuritySupply ChainState-SponsoredPhishingClaudeOpenAI
Deep AnalysisSeptember 7, 2026·15 min read
ClickFix 2.0: 5,400+ Hacked Sites Use Blockchain Smart Contracts to Deliver Malware
How the EtherHiding technique turned the BNB Smart Chain into an unstoppable malware delivery platform — from fake CAPTCHAs to WebRTC data channels, with a full IOC appendix including 12 payload families.
ClickFixEtherHidingBlockchainInfostealer
Deep AnalysisSeptember 2, 2026·12 min read
When Ransomware Meets AI: Aurora's Use of Cursor in Attacks Against 33 Organizations
Aurora ransomware operators used Cursor AI to plan attacks in Russian, generate cross-platform Zig encryptors, exploit AD CS, and automate the full kill chain — the first documented AI-augmented ransomware campaign.
RansomwareAICursorAD CSZig
Deep AnalysisAugust 27, 2026·12 min read
Gitea RCE (CVE-2026-60004, CVSS 9.8): The diffpatch Attack Chain
How attackers weaponize Gitea's diffpatch endpoint to plant Git hooks, execute arbitrary commands as the Gitea OS user, and deploy cryptominer payloads — now on CISA's KEV with a mandatory patch deadline.
GiteaRCECVE-2026-60004Cryptojacking
Deep AnalysisAugust 23, 2026·12 min read
BTR Reforged: Weaponizing Microsoft Defender's Boot-Time Driver for Kernel-Level Defense Evasion
How a built-in Windows component — present on every system since Windows 7 — can be used to delete security software at boot, bypassing blocklists, WDAC, and tamper protection.
Defense EvasionWindows SecurityKernel
☕ Buy a Coffee