August 24, 2026
- SilkParasite's toolset is larger than first reported — the China-nexus operation against Central Asian governments is now tied to seven RAT families (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT among them), with DLL sideloading as core tradecraft and targeting across Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan and Georgia. Bitdefender assesses the China nexus at medium confidence (@DailyDarkWeb) (earlier coverage).
· Nation-State & Critical Infrastructure
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
July 20, 2026
- bindutil-toolset — Bitdefender's code and test scenarios for the "Silo-Binding" Windows activation-key research presented at InsomniHack 2026 (GitHub).
· New Tools & Releases
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 16, 2026
- Bitdefender showed Windows bind links (
bindflt.sys) can create conflicting filesystem views that hide malware from EDR. Redirecting a trusted path to attacker-controlled content leaves few artifacts, defeating path-based detection and application control. Bitdefender, SecurityWeek
· Offensive Tradecraft
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
June 25, 2026
- Operation Endgame dismantled the shared infrastructure behind the Amadey and StealC infostealers, with Microsoft's DCU, Europol, Bitdefender, Bitsight, and ESET taking down 300+ servers and 200+ domains, recovering ~27M stolen credentials, and seizing over $47M; Microsoft also leaned on AI to link the operations in a racketeering suit. Microsoft, The Record, The Register
· Threat Intelligence
in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC