Date Author Title

BITWARDEN CLI

2026-04-27Kenneth HartmanTeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns

BITWARDEN

2026-04-27/a>Kenneth HartmanTeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns

CLI

2026-04-27/a>Kenneth HartmanTeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns
2026-04-17/a>Brad DuncanLumma Stealer infection with Sectop RAT (ArechClient2)
2026-03-25/a>Brad DuncanSmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)
2026-03-14/a>Brad DuncanSmartApeSG campaign uses ClickFix page to push Remcos RAT
2025-12-13/a>Brad DuncanClickFix Attacks Still Using the Finger
2025-11-18/a>Brad DuncanKongTuke activity
2025-11-12/a>Brad DuncanSmartApeSG campaign uses ClickFix page to push NetSupport RAT
2025-10-15/a>Xavier MertensClipboard Pictures Exfiltration in Python Infostealer
2025-07-15/a>Xavier MertensKeylogger Data Stored in an ADS
2024-04-17/a>Xavier MertensMalicious PDF File Used As Delivery Mechanism
2023-03-31/a>Jan KoprivaUse of X-Frame-Options and CSP frame-ancestors security headers on 1 million most popular domains
2022-06-26/a>Didier StevensMy Paste Command
2022-06-25/a>Xavier MertensMalicious Code Passed to PowerShell via the Clipboard
2022-06-22/a>Xavier MertensMalicious PowerShell Targeting Cryptocurrency Browser Extensions
2022-05-23/a>Johannes UllrichAttacker Scanning for jQuery-File-Upload
2022-04-21/a>Xavier MertensMulti-Cryptocurrency Clipboard Swapper
2022-02-14/a>Johannes UllrichReminder: Decoding TLS Client Hellos to non TLS servers
2021-11-15/a>Rob VandenBrinkChanging your AD Password Using the Clipboard - Not as Easy as You'd Think!
2021-10-18/a>Xavier MertensMalicious PowerShell Using Client Certificate Authentication
2021-08-30/a>Xavier MertensCryptocurrency Clipboard Swapper Delivered With Love
2021-02-12/a>Xavier MertensAgentTesla Dropped Through Automatic Click in Microsoft Help File
2020-09-11/a>Rob VandenBrinkWhat's in Your Clipboard? Pillaging and Protecting the Clipboard
2020-02-28/a>Xavier MertensShow me Your Clipboard Data!
2020-01-21/a>Russ McReeDeepBlueCLI: Powershell Threat Hunting
2015-12-10/a>Rob VandenBrinkNew Burp Feature - ClickBandit
2014-08-20/a>Kevin ShorttSocial Engineering Alive and Well
2014-04-11/a>Rob VandenBrinkThe Other Side of Heartbleed - Client Vulnerabilities
2013-11-11/a>Johannes UllrichWhat Happened to the SANS Ads?
2012-06-04/a>Rob VandenBrinkvSphere 5.0 Hardening Guide Officially Released
2012-02-23/a>donald smithDNS-Changer "clean DNS" extension requested
2011-10-21/a>Johannes UllrichNew Flash Click Jacking Exploit
2010-06-27/a>Manuel Humberto Santander PelaezStudy of clickjacking vulerabilities on popular sites
2010-06-02/a>Bojan ZdrnjaClickjacking attacks on Facebook's Like plugin
2010-01-24/a>Pedro BuenoOutdated client applications
2009-09-07/a>Jim ClausingSeclists.org is finally back
2009-04-20/a>Jason LamDigital Content on TV