daily cyber × ai intelligence

index

tagged

[oceanlotus]

1 edition · 1 item

July 23, 2026

  • OceanLotus initial-access chain detailed. Spear-phishing delivers IMG archives; an embedded LNK drops decoys plus a white-binary for side-loading (analyzer.exe loading malicious mglobal.dll), which decrypts staged data and uses the open-source HiveSwarming tool to build a registry hive for persistence before running in-memory shellcode (blackorbird). · Threat Activity

in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident