China's Ransomware Groups Are Using Zero-Days Now. That Changes the Math.

Microsoft links China-based Storm-1175 to Medusa ransomware using zero-day exploits, while Qilin deploys EDR-killing techniques before encryption.

Read More

BRICKSTORM Hides Where Your EDR Can't See It

A suspected China-nexus espionage operation targets VMware vCenter and ESXi hypervisors, persisting at the virtualization layer where endpoint security is blind.

Read More

Searching for Tax Forms? Malicious Google Ads Want to Kill Your Antivirus First

A malvertising campaign running since January targets W2 and W9 searchers with a kill chain that disables endpoint security at the kernel level before installing remote access malware. Your antivirus can't stop it once it's running.

Read More

BlackSanta Kills Your EDR Before You Even Know You're Hit — and It's Coming Through HR

New malware called BlackSanta disables your endpoint detection, and it's getting in through HR inboxes. That combo is nastier than it sounds.

Read More