Skip to content
tag — detection

grep -rl "detection" ./articles

#detection

8 articles

France's tax agency learned of the theft from the thief, seven weeks after it started

2026-10-01Security

ANSSI's incident report on the DGFiP, published on 29 September, describes several dozen agent passwords stolen from machines the agency does not manage, sensitive portals with no multi-factor authentication, and a messaging tool scraped on three days in June and July. Nobody noticed until the attacker posted about it on a forum on 12 August.

The backdoor was compiled into HAProxy. That is not an HAProxy vulnerability

2026-09-06Security

Rapid7 found a Linux implant built into the HAProxy binaries of two South Korean organisations, intercepting traffic and erasing its own requests from the proxy's own logs. Every headline calls it an HAProxy backdoor. Installing it requires already owning the host, which makes patching HAProxy the one response that changes nothing.

This backdoor never phones home — it waits for a packet, and everything hunting for beacons misses it

2026-08-26Security

Sleepwalker is a Windows backdoor with a 23-instruction custom bytecode language, AES-256-CCM, and no outbound connections at all. It sits dormant until a specially crafted packet arrives. It loads by side-loading through a security vendor's own management agent while pretending to be Microsoft's dpapi.dll — and the researcher who found it says plainly that he cannot name a single victim.