<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>HACK/PROJECT — Daily Threat Intelligence — HIGH</title><link>https://spidercivi.github.io/HACK-PROJECT/en/</link><description>Daily Threat Intelligence</description><language>en</language><item><title>The layer that holds identity: the privilege flaw in AD FS</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/adfs-privilege-escalation-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/adfs-privilege-escalation-en.html</guid><pubDate>Fri, 24 Jul 2026 08:00:00 +0100</pubDate><description>Microsoft Active Directory Federation Services — the component that provides single sign-on between an organisation and external services — has an insufficient-granularity access-control flaw: CVE-2026-56155. It lets an already-authenticated attacker elevate privileges locally. The NVD score is 7.8, so it is not the &quot;one click and you are in&quot; kind of flaw; but CISA added it to the Known Exploited Vulnerabilities catalogue, and it sits on the server that decides who is who. It is worth explaining why it matters even at 7.8.</description></item><item><title>Akira, the ransomware that walks in through the door left open</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/akira-raas-2026-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/akira-raas-2026-en.html</guid><pubDate>Fri, 24 Jul 2026 08:00:00 +0100</pubDate><description>Akira is not new: it has operated since March 2023 under the ransomware-as-a-service model and is one of the most prolific groups around. The joint advisory from CISA, the FBI and the Dutch NCSC, updated in November 2025, cites more than 342 organisations hit and roughly 244 million dollars in proceeds. In July 2026 its leak site added new names. The thread that holds the story together is mundane and, for that reason, instructive: Akira almost always enters through poorly protected remote access, not through technical magic.</description></item><item><title>Qilin claims Danone: what the source says, and what remains to be verified</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/qilin-danone-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/qilin-danone-en.html</guid><pubDate>Wed, 22 Jul 2026 08:00:00 +0100</pubDate><description>The Qilin ransomware group listed Danone on its leak site, claiming it stole roughly 221 GB of data and publishing more than 90,000 files. The claim, dated 17 July 2026, is not currently confirmed by the company: as always with leak sites, the assertion should be treated as a claim until verified. The case is still a chance to look at Qilin&#x27;s double-extortion model — one of 2026&#x27;s most active groups — with what the sources actually say and the uncertainties in plain view.</description></item><item><title>How to break the ransomware-as-a-service model: what the official sources actually say</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/ransomware-raas-difesa-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/ransomware-raas-difesa-en.html</guid><pubDate>Mon, 20 Jul 2026 08:00:00 +0100</pubDate><description>Ransomware today is a service industry, not a lone wolf: operators who rent the malware, affiliates who strike, brokers who sell the initial access. This explainer is not the attack of the day: it lines up what official sources say — CISA with #StopRansomware, Europol with the No More Ransom project, ENISA with its Threat Landscape — on how that chain breaks. The takeaway is less spectacular than a ransom and more useful: you hit the model&#x27;s economics, not the single group.</description></item><item><title>No malware, no ransom, no patch: the KNXlock case</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/knxlock-bcu-key-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/knxlock-bcu-key-en.html</guid><pubDate>Fri, 17 Jul 2026 08:00:00 +0100</pubDate><description>On 15 July 2026 CISA added to the KEV catalog a 2023 CVE describing a 2021 attack. There is no malicious code: the attackers purge a building&#x27;s KNX devices, then set the BCU key — the password the protocol provides as a protective feature. Vendors replied that no reset exists. No ransom ever arrived.</description></item><item><title>FortiBleed: there is no patch, because there is no vulnerability</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/fortibleed-inc-lynx-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/fortibleed-inc-lynx-en.html</guid><pubDate>Thu, 16 Jul 2026 08:00:00 +0100</pubDate><description>Roughly half of all internet-facing Fortinet firewalls have their admin credentials in the hands of an access broker. There is no CVE to patch: there are exported config files, SHA-256 hashes cracked offline, and perfectly legitimate logins. In July, SOCRadar tied the operation to the INC and Lynx ransomware brands.</description></item><item><title>Interlock: the ransomware that walks in the front door</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/interlock-clickfix-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/interlock-clickfix-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>Interlock flipped the ransomware script: no phishing, no breached VPN. The victim visits a legitimate compromised site, sees a fake CAPTCHA, and pastes the command that infects them. Anatomy of an attack chain in which the user is the exploit.</description></item><item><title>The QR code that steals your session, not your password</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/kimsuky-quishing-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/kimsuky-quishing-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>Kimsuky stopped fighting corporate email filters. It simply changed channel: a QR code forces the victim onto a personal phone, outside the IT perimeter. And it steals the session token rather than the password — so MFA falls without raising a single alert.</description></item><item><title>Miasma: valid SLSA provenance for malicious packages</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/miasma-redhat-npm-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/miasma-redhat-npm-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>Thirty-two Red Hat npm packages were published with malicious payloads — carrying valid SLSA provenance attestations. The technology built to guarantee build integrity certified the malware, because SLSA attests where a package was built, not whether the build&#x27;s input was legitimate.</description></item><item><title>&quot;Exploitation Less Likely&quot;, then three days to patch</title><link>https://spidercivi.github.io/HACK-PROJECT/en/a/sharepoint-cve-2026-45659-en.html</link><guid>https://spidercivi.github.io/HACK-PROJECT/en/a/sharepoint-cve-2026-45659-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>Microsoft rated it &quot;Exploitation Less Likely&quot;. Five weeks later CISA put it in the KEV catalog with a three-day remediation window. A lesson in what vendor exploitability predictions are actually worth.</description></item></channel></rss>