
Category: Tacklebox
The Tacklebox is your one-stop reference guide to unraveling the intricate world of scams and fraudulent schemes. This comprehensive resource is designed to equip you with the knowledge and insights needed to recognize, understand, and protect yourself against various types of scams and social engineering tactics.
-
Progress LoadMaster Command Injection Exploitation: Real-World Campaign Analysis
Delve into the exploitation of a command injection vulnerability in Progress LoadMaster appliances, based on CISA’s exploited vulnerabilities catalog.
-
Inside the keyv/cacheable npm Worm: A Supply-Chain Attack Case Study
A deep dive into the recent keyv/cacheable npm worm incident, revealing its mechanisms and unexplored attack patterns on the software supply chain.
-
22 Seconds to Compromise: Automated SSH Actors and Fast-Paced Attacks
Explore how automated SSH actors leverage compromised credentials for rapid attack progression, achieving persistence in just 22 seconds.
-
Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm
Explore the unique dynamics of the keyv/cacheable npm worm, where revoking tokens could be counterproductive in managing this supply chain threat.
-
keyv/cacheable NPM Worm: When Revoking Tokens Backfires
Explore the keyv/cacheable npm worm’s unique twist on supply-chain security incidents and why immediate token revocation can worsen the situation.
-
Phishing Campaigns Targeting AI Solutions Providers: Latest Developments
Explore the latest phishing campaigns targeting AI solution providers, with insights into methods, impersonation tactics, and targeted services like ChatGPT.
-
Atomic MacOS (AMOS) Stealer: In-Depth Analysis of Recent Infection Patterns
Explore the sophisticated AMOS Stealer campaign: its infection techniques, target profiles, and the vulnerabilities exploited in MacOS systems.
-
SSH Bot Reconnaissance: Sizing Up Hardware for Crypto Mining
Exploring a novel SSH bot campaign that assesses hardware capabilities before deploying cryptocurrency mining software.
-
SSH Bot Campaign: Reconnaissance First, Mining Next
A case study of an SSH bot campaign that conducts reconnaissance before deploying a cryptocurrency miner, maximizing illegal profits by targeting capable hosts.
-
Rondo Malware Campaign: Intersection with GeoServer Installations
Explore the Rondo malware campaign aligning with GeoServer installations, detailing threat actor techniques and implications for GeoServer security.
-
Rondo Malware Campaign Targeting GeoServer Implementations
Dive into the Rondo malware campaign targeting GeoServer implementations, revealing tactics, impact, and red team takeaways.
-
Active Exploitation of WordPress Vulnerabilities: CVE-2026-60137 and CVE-2026-63030
In-depth analysis of active exploits on WordPress vulnerabilities CVE-2026-60137 & CVE-2026-63030 leveraging SQL Injection for RCE.
-
WordPress Exploitation Campaign: wp2shell Vulnerability CVE-2026-63030
Breakdown of a campaign leveraging the wp2shell vulnerability in WordPress installations for remote code execution.
-
SonicWall SMA1000 Exploitation: Active Campaign Using CVE-2026-15409 and CVE-2026-15410
Explore the active exploitation of SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in phishing campaigns for unauthenticated system compromise.
-
Exploiting Fortinet FortiSandbox via OS Command Injection: CVE-2026-39808
Explore the exploitation of Fortinet FortiSandbox OS Command Injection vulnerability impacting systems via crafted HTTP requests.
-
Exploiting SonicWall SMA1000 Vulnerabilities for Phishing Campaigns: CVE-2026-15409 and CVE-2026-15410
Analysis of SonicWall SMA1000 vulnerabilities being exploited in phishing campaigns, detailing how these vulnerabilities allow for unauthenticated system compromise.




















